Listen to this episode

Navigating the Perils of Crypto: Breaches, Security, and Safeguarding Your Digital Assets

0:0043:25

Recorded February 2024. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Blake and Craig Petronella debut a new breach analysis format, examining the 2016 Bitfinex hack in which roughly 120,000 Bitcoins were stolen. Craig explains how IRS special agents and the FBI traced the stolen funds through the public blockchain to a couple in New York, noting that Bitfinex did not require KYC verification in its early days.

Blake points out that the exchange kept two of its three security tokens on a single device, so one compromise exposed millions of dollars. The hosts then share layered security guidance: Craig argues crypto should not be stored on exchanges, recommends cold wallets, urges spreading holdings across multiple vendors, and warns never to store seed phrases digitally. They also cover authenticator apps instead of SMS, the dangers of fake public Wi-Fi networks, multi-signature and Shamir backups for family estate planning, and a software wallet bug that left coins unspendable. Craig and Blake break down pig butchering scams, with Blake recounting how he strung along a scammer, and Craig closes by arguing Bitcoin's fixed supply makes it unique and warning about SIM swap attacks.

Worth remembering

Key takeaways

  1. Craig calls avoiding exchange storage the cardinal rule, urging listeners not to leave crypto on an exchange when trading.
    “the cardinal rule is you shouldn't really store your crypto on an exchange. If you're trading crypto on an exchange, you should avoid storing your crypto there, wherever or whenever possible.”
  2. Craig warns that seed phrases should never be stored digitally or photographed, and should only be written down in a private space.
    “you never want to store your seed phrase and you don't ever want to take a picture of it. You never want to store it online anywhere. Don't put it anywhere digital”
  3. Craig recommends multi-factor authentication through authenticator apps rather than SMS, which he later links to costly SIM swap attacks.
    “Use multi-factor authentication, but do not use SMS for the tokens. Use like Google Authenticator or Microsoft Authenticator. Those apps are much, much more secure.”
  4. Craig spreads his crypto across several wallet makers, arguing that no single vendor should be trusted with everything.
    “So, in my opinion, opposed to just choosing one vendor, I choose all of them. I choose many different ones and kind of spread things around this way.”
  5. Craig advises testing any new wallet with a small transfer first, since a mistake or malware can make funds unrecoverable.
    “always do micro transactions first. I mean, it's not going to hurt to do like a.001 or small, like $20 or $30 of a transfer and then make sure the wallet works and then transfer more.”
  6. Blake and Craig caution against handling crypto on public networks, since hackers imitate legitimate Wi-Fi hotspots to sniff out communications.
    “hackers have been known to Transmit fake cell towers and fake Wi-Fi networks that mimic what you think is real.”
  7. Craig explains the pig butchering scam, where a malicious website disguised as an app shows fictitious returns, then demands a fee to cash out.
    “And then you try to cash out and then they're like oh no, you can't cash out, you have to pay 10% of whatever your balance shows.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Imagine discovering that the very foundations of your financial security have been compromised by one of the most infamous crypto-heists in history. That's the chilling tale we unravel from the 2016 Bitfinex breach, with a staggering $4.5 billion at stake. We join forces with cybersecurity experts and dive into the cutting-edge blockchain forensics that led to the recent arrests, providing a glimmer of hope in the dark abyss of stolen digital assets. As your guide, I share invaluable strategies for fortifying your cryptocurrency investments - think cold wallets and micro-transactions - not just to protect your wealth, but to ensure its rightful transfer to your heirs.

But the perils lurking in the crypto-verse don't end with exchange hacks. Have you ever had the feeling that something's too good to be true? We dissect the 'pig butchering' scams that prey on investors through sophisticated social engineering, and I'll recount a personal brush with these cunning con artists. The episode becomes a stark warning about the craftiness of digital predators, while also equipping you with the armory of knowledge needed to build a fortress around your digital assets - multi-signature wallets, encrypted physical backups, and all.

As we round off our journey, we scrutinize the influence that glitters from the world of crypto influencers, where not all that shines is gold. We question the hype, dissect the endorsements, and underline the importance of due diligence. I emphasize the unique strengths of Bitcoin and the trustless technologies that underpin it, urging listeners to embrace self-reliance in the wake of rampant cyber threats. So, if you're ready to navigate the complex currents of cryptocurrency and cybersecurity, this episode is your beacon in the storm, illuminating the path to safeguarding your digital treasure.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.