Privacy as Operational Security
Reframe crypto privacy as operational security: identify the actual adversaries who care about your wallet, score your exposure, defend against doxxing and wrench attacks, and learn the layered opsec discipline that protects ordinary holders in 2026.
27 min · advanced · part of Privacy in Crypto
What you'll learn
- Privacy as Opsec, Not Ideology
- Threat Actors and Their Real Capabilities
- A Personal Risk-Scoring Framework
- Doxxing Attack Vectors and Defenses
- Practical Opsec Layers
- Wrench Attacks and Physical Security
- For Deeper Reading
Key terms
- Operational security (opsec)
- A discipline of identifying, prioritizing, and defending the specific information adversaries could use against you. Distinct from privacy as ideology: opsec starts with a list of adversaries and what each one can do.
- Personal exposure inventory
- A periodic written exercise listing each wallet you operate, what identity links it has (KYC, public posts, ENS, NFT mints), its visible balance and behavior, and a 1-5 exposure score. The starting point for any opsec investment.
- Wrench attack
- A physical attack — kidnapping, home invasion, extortion under threat of violence — used to coerce a crypto holder into surrendering keys. Documented systematically in Jameson Lopp's public registry; risk rises sharply when holdings, identities, and locations are simultaneously knowable.
- Jameson Lopp's tracker
- The "Known Physical Bitcoin Attacks" registry maintained by Casa co-founder Jameson Lopp on GitHub. Catalogues dozens of documented incidents per year through 2024-2026, the canonical public reference on wrench-attack frequency and patterns.
- Compartmentalization
- The practice of using separate wallets for separate purposes — KYC-touch, operational, savings, public-facing — so that a deanonymization event in one does not propagate to the others. The single most powerful opsec lever for ordinary users.
- Address clustering propagation
- The phenomenon by which a wallet you considered private gets attached to your identity through a chain of routine transactions. Often the dominant deanonymization path even when no individual transaction is identifying.
- RPC IP correlation
- The cross-wallet linking that occurs when your wallet queries the same RPC provider (Infura, Alchemy, etc.) from the same IP address for multiple wallets. Defeated by Tor, VPN, or self-hosted nodes; different wallets should see different network paths.
- Doxxed CEO tradeoff
- The structural tension faced by public crypto founders whose professional success requires visibility but whose personal safety requires privacy. The mainstream response: make the role public while keeping personal life, holdings, and home location private.
- Duress wallet
- A passphrase-protected hidden wallet on a hardware device, paired with a "decoy" wallet containing a small visible balance. Under coercion, the holder reveals the decoy; the main holdings remain hidden.
- Bitcoin City
- El Salvador's announced (November 2021) tax-free, geothermal-powered city around the Conchagua volcano, marketed as a haven for Bitcoin holders. A real-world test of whether concentrated Bitcoin wealth can be matched by concentrated physical security.
- Withdrawal whitelist
- A regulated-exchange feature that limits withdrawals to pre-approved destination addresses with a delay before changes take effect. Defeats most account-takeover scenarios and is one of the highest-leverage routine opsec controls.
- Arkham bounty market
- A commercial deanonymization service operated by Arkham Intelligence in which users submit on-chain attributions and earn payment when validated. The bounty design accelerates labeling of high-profile wallets and is a structural reason to assume any visible wallet you publicly attach to your identity will eventually be labeled.
Read the full lesson in the CryptoBipto app.
Open lessonEducational only — not financial advice.
