Every cat owner learns this the hard way. You can close the front door, lock the back door, and fit the cat flap with a microchip reader — and the cat will still get out, through the bathroom window somebody opened in July and never thought about again.
Security is not decided by your strongest point. It's decided by the one you forgot.
Bitcoin's own security is extraordinary. Your keys are unbreakable by any realistic attacker. Which is precisely why nobody attacks them — they attack the perimeter instead, and the perimeter is your email, your phone number, and the accounts you set up in a hurry three years ago.
1. Your Email Is the Master Key
Take a moment with this one, because it reframes everything.
Almost every account you own can be reset through your email. Exchange, broker, bank, cloud storage, password manager recovery, domain registrar. Whoever controls that inbox can, given an afternoon, become you almost everywhere.
Your email is therefore more security-critical than any individual account it protects. Treat it accordingly:
- A hardware security key on the email account, not just an app code.
- A unique, long password that exists nowhere else and has never been in a breach.
- A separate email address for financial accounts, never used publicly, never posted, never used to sign up for anything else. Compartmentalisation again: the address in your blog footer and the address on your exchange should have nothing to do with each other.
- Check the recovery options. An old phone number or a dead secondary address sitting in your account settings is a back door you forgot you built.
2. SMS Two-Factor Is Broken
If you take one practical action from this article, make it this.
Turn off SMS as a second factor everywhere that allows it. Phone numbers are not secure identifiers. A SIM swap — where an attacker persuades or bribes a carrier employee to move your number to their SIM — transfers every SMS code you receive to a stranger, and the process can take minutes. Victims describe the same thing: the phone goes to "no service", and by the time anyone at the carrier understands the problem, the accounts are gone.
The hierarchy, best to worst:
- Hardware security key (FIDO2/U2F). Phishing-resistant by design, because the key checks the domain and won't sign for a lookalike site. Buy two, register both, keep one somewhere else.
- An authenticator app on a device you control. Good. Vulnerable to a convincing phishing page that relays your code in real time.
- SMS. Better than nothing on accounts that offer nothing else. Assume it will fail if someone targets you.
Also: ask your mobile carrier to put a port-out PIN or account lock on your number. It's free, takes one call, and blocks the cheapest version of the attack.
3. Passwords Are a Solved Problem You Haven't Solved
A password manager, a long unique password per site, and none of them memorised except the vault's own. This is dull, twenty-year-old advice, and the reason it's repeated is that reusing passwords remains the most common way ordinary people lose accounts.
Two specifics for this context:
- Protect the vault with a hardware key too. It holds everything; treat it like the email.
- Security questions are passwords with terrible entropy. Your mother's maiden name is public. Fill those fields with generated nonsense and store the nonsense in the vault.
4. The Device Itself
- Full-disk encryption, on the laptop and the phone. Both offer it; turn it on.
- A separate browser profile — ideally a separate user account — for money. No extensions, no casual browsing. Browser extensions can read pages you have open, and "helpful" ones have been sold to new owners who updated them into malware.
- Update things. Boring, and it closes the exploited holes rather than the theoretical ones.
- Never type a seed phrase into any device, for any reason. It belongs on the hardware wallet's screen and on metal. Nowhere else, ever, including "temporarily".
- Beware the repair shop. A device handed over for service is a device out of your control. Wipe first, or don't send it.
5. The Quiet One: Don't Be Interesting
Everything above is technical. This last one isn't, and for anyone holding a meaningful amount it matters more than the rest combined.
Don't advertise. Not the amount, not the fact that you self-custody, not in a public post, not in a pub, not in a comment section, not in a video. The most sophisticated security stack in the world doesn't help against someone who knows a specific person at a specific address holds a bearer asset and cannot reverse a transfer.
This cuts against a lot of crypto culture, which rewards visible conviction. Be enthusiastic about the technology in public and completely silent about your position. Those are separable, and the people who learned they weren't learned it expensively.
The Point
The bathroom window was open for two months and nobody thought about it, because everyone was busy being pleased about the microchip cat flap. Tuga found it on the first warm evening, as anyone who has ever owned a cat could have predicted.
Your keys are the strong part. They're so strong that nobody will ever bother with them. Go and check the windows.
Attackers don't break the lock. They walk in through the thing you forgot. 🐾⚡
Not financial advice — I feed a cat and write about Bitcoin, which qualifies me for neither profession. Security practices change; check current guidance for your specific services.
Tags: Bitcoin, Security, Self Custody, Two Factor Authentication, Cryptocurrency
See task progress for longer tasks.
thumb-34-high-shelf.pngthumb-33-window-open.pngarticle-34-price-of-the-high-shelf.mdarticle-33-window-left-open.md
Track tools and referenced files used in this task.