Skip to main content
Important: We do not provide financial advice or custody funds. All transactions occur on third-party platforms.

Operational Security: Habits for Long-Term Safety

The day-to-day practices that keep crypto safe over years — exchange selection, account security, threat models, and inheritance planning.

10 min · intermediate · part of Security Mastery: Protecting Your Assets

Threat Modeling: What Are You Defending Against?

Effective security is not an absolute. It is calibrated against specific threats. Trying to defend against everything wastes resources; not defending against likely threats is negligent. The right starting point is a threat model — a clear picture of what kinds of attacks you actually need to defend against. For most retail crypto users, the relevant threat model includes: • **Phishing and social engineering.** By far the most likely threat. Affects everyone with internet access. • **Malware on personal devices.** Common; affects users who download sketchy software, click email attachments, or use compromised browser extensions. • **Exchange compromise.** Happens periodically. Mitigated by not keeping more than necessary on exchanges. • **Lost or destroyed seed phrases.** Common; mitigated by backup planning. • **SIM swapping.** Targeted, but happens. Mitigated by not using SMS 2FA and by carrier security PINs. • **Physical theft or coercion.** Rare for most users but real for high-net-worth holders or those who publicly disclose holdings. Mitigated by not disclosing, by passphrases (BIP-39 25th word for plausible deniability), and by cold storage. Threats less relevant for most users: • **Sophisticated targeted attacks (state actors).** Real for high-profile dissidents and journalists, less so for ordinary investors. • **Quantum computing breaks of cryptography.** Theoretical for now; will require migration before quantum computers become relevant. Probably 10+ years away. • **Network-level attacks.** Bitcoin and Ethereum have not been successfully attacked at the protocol level. Very unlikely for major chains. Tailor your defenses to your actual threats. Spending hours on quantum-resistant key management while still using SMS 2FA on Coinbase is a misallocation. Get the basics right first, then layer additional defenses as your holdings grow.

Also in this lesson

  • Exchange Selection and Account Hygiene
  • Inheritance Planning: The Most Overlooked Security Issue
  • Ongoing Monitoring and Periodic Review
  • For Deeper Reading

Key terms

Threat model
A specific picture of what attacks you need to defend against, calibrated to your circumstances. Effective security defends against likely threats, not all conceivable threats.
Whitelisted withdrawal addresses
An exchange security feature restricting withdrawals to pre-approved addresses, often with a 24-hour cooling period for new additions. Limits damage if account is compromised.
Coinbase Vault
A Coinbase product requiring multiple signers and time delays for withdrawals. Designed for long-term holdings on the platform.
Casa Inheritance
A multisig custody service with built-in inheritance protocols. Holds one key in a multisig setup and releases it to designated beneficiaries upon proof of death.
Sarcophagus
A decentralized dead-man's-switch protocol on Ethereum, designed to release secrets to designated parties if the user fails to "renew" within a deadline.
Dead man's switch
An automated release of information or assets if a user fails to demonstrate continued life within a defined window. Used in inheritance planning.
Bearer property
Property whose ownership transfers by physical possession of an instrument (cash, gold, cryptocurrency seed phrases). No registration of ownership; whoever holds it owns it.
YubiKey / U2F hardware token
A physical USB security key for phishing-resistant 2FA. Verifies the actual domain it is communicating with, so cannot be tricked by phishing sites.
TOTP (Time-based One-Time Password)
The standard for authenticator apps (Google Authenticator, Authy). Generates 6-digit codes that change every 30 seconds. Stronger than SMS but weaker than hardware tokens.
Mt. Gox
Once the largest Bitcoin exchange (~70% of global volume); collapsed February 2014 with ~850,000 BTC stolen. Trustee began creditor repayments July 2024 with deadline now October 2026.
Bybit hack 2025
Theft of ~400,000 ETH (~$1.5B) from Bybit exchange on February 21, 2025. Largest crypto heist in history. Attributed to Lazarus Group/DPRK by FBI on February 26, 2025.
Hal Finney
The second person ever to run Bitcoin (after Satoshi); recipient of the first Bitcoin transaction in January 2009. Died in 2014. Documented inheritance carefully — exemplary planning.

Continue this lesson — 4 more sections in the CryptoBipto app.

Open lesson

Educational only — not financial advice.