On-chain security intel, continuously updated · September 2026

Your assets are only
as safe as every detail

Crypto has no bank teller intercepting risks for you. Key management, contract approvals, phishing detection, platform choice — every link is a battleground. This center distills what professional security teams practice into a defense system you can execute today.

Video walkthrough · click to play or pause
10-point self-audit
Covers keys, approvals, and platform risk
6 threat deep dives
Attack techniques and matching defenses
6-step incident response
Keep losses contained to the minimum
Annual on-chain theft total
$3.8 B
+17% YoY, driven by bridge hacks and key compromise
Phishing incidents
12,400+ cases
Fake airdrops and fake support make up two-thirds of reports
Malicious approvals blocked
86,000+ times
Wallet security plugins keep intercepting more attacks
Average loss per victim
$310 K
Large thefts concentrate in addresses without hardware wallets

Figures are illustrative data modeled on public industry reports, shown to convey the scale of risk — not real-time statistics from any platform.

THREAT LANDSCAPE

Six threats, one goal: your keys

Most losses don't come from "breaking cryptography" — they come from exploiting habits and system gaps. Pick a threat to see how it works and how to defend against it.

Phishing

Most frequent

Attackers clone official sites, wallet popups, and airdrop pages to trick you into typing your seed phrase on a fake site — or signing a transaction that drains your funds. The page can look pixel-identical to the real one; your only defense is verifying before every input and every signature.

Common techniques

  • Look-alike domains: swapping l for 1, o for 0, or near-identical Unicode characters
  • Emails and texts claiming "account anomaly," leading to a fake "wallet verification" page
  • Malicious browser extensions hijacking your clipboard to swap copied addresses
  • Search engine ad slots serving fake official sites at the top of results

Defenses

  • Enter official sites only from your own bookmarks — never from ads or chat links
  • Any page asking for your seed phrase is 100% a scam, no exceptions
  • Verify the first and last 6 characters of addresses; test transfers in two small amounts
  • Install your wallet's official security plugin and read every transaction before signing

Key Compromise

Costliest per incident

Your private key and seed phrase are the asset itself. The moment they exist in any digital form — a screenshot, a note, a cloud drive, a chat log — they may already be out of your control without you knowing.

Common leak paths

  • Seed phrase stored in phone notes, photo albums, or input-method cloud sync
  • "Just noting it down temporarily" in cloud drives, email drafts, or collaboration docs
  • Keylogger malware capturing the phrase as you type it
  • Paper backups carelessly discarded, later recovered and swept

Defenses

  • Write the seed phrase only on paper or steel, with at least two copies stored separately
  • Keep large holdings in a hardware wallet so keys never touch a networked device
  • Run reputable endpoint protection; never install software of unknown origin
  • Never photograph backups; store them fireproof, dry, and away from prying eyes

Smart Contract Bugs

Highest technical bar

A flaw in on-chain code lets attackers drain the funds a contract holds. Reentrancy, flash-loan price manipulation, missing access checks — most of these are findable during a proper audit.

Common bug classes

  • Reentrancy: withdrawal state updated too late, allowing repeated "successful" withdrawals
  • Flash-loan manipulation: instantly borrowed capital distorts an oracle price before the attacker exits
  • Access-control failures: leaked admin keys or hidden backdoors that can drain the pool at any time
  • Unlimited approvals: one signature grants a contract the right to move all your tokens, forever

Defenses

  • Interact only with projects audited by reputable firms whose reports remain valid post-deployment
  • Skip the first 48 hours of any new contract — let early attacks happen on someone else's dime
  • Set approval allowances to what you need; revoke when done and audit old approvals regularly
  • Check the project's multisig and timelock setup; be wary of contracts one person can upgrade

Rug Pulls

Beginner trap

A team launches a token, hypes it up, then yanks the liquidity or simply abandons the project. On paper it looks like a "fair launch"; on-chain, holdings and admin powers are quietly concentrated in the developers' hands.

Common patterns

  • Liquidity pool unlocked or locked only briefly — removable at any moment
  • Team and insider wallets secretly holding over 40% of total supply
  • Hype driven by the same anonymous influencers pushing absurd return claims
  • Blacklist functions in the contract: you can buy, but never sell

Defenses

  • Before buying, check liquidity lock records, holder concentration, and tax/ blacklist powers
  • Anonymous team, no audit, no code repository — hard pass
  • Remember: "guaranteed high returns" is itself the signature of a scam
  • Speculate only with money you can lose entirely — in a wallet isolated from your main stack

Exchange Risk

Systemic risk

Assets on an exchange are, at their core, an IOU from that exchange. Misappropriated customer funds, bank runs, insider wrongdoing, sudden regulatory shifts — these are as lethal as any hack and give you almost no time to react.

Risk sources

  • Customer funds diverted to cover the firm's own trading losses, blowing up when they can't be repaid
  • Under-protected hot wallets — one breach, catastrophic loss
  • No proof of reserves; customer assets commingled with house funds
  • Sudden regulation freezing or restricting withdrawals, or forcing a market exit

Defenses

  • Keep only trading funds on exchanges; move long-term holdings to self-custody
  • Prefer platforms that publish regular proof-of-reserves (PoR) reports
  • Enable the trio: 2FA, anti-phishing codes, and withdrawal allowlists
  • Split assets across 2–3 platforms to avoid a single point of failure

Social Engineering

Hardest to solve with tech

The attacker doesn't hack code — they hack people: impersonating support, faking official DMs, or building months of trust before pitching an "investment." The whole defense rests on one default: distrust anyone who reaches out to you first.

Common scripts

  • "Official support" messaging you first: your account is at risk, share the code or allow screen sharing
  • Fake "trading mentors" posting profit screenshots, funneling victims into fake exchanges
  • Months of romance or friendship, then a "sure-thing" investment platform (pig butchering)
  • Fake community admins DMing about a "compensation airdrop" that requires a wallet signature

Defenses

  • Official teams never DM you first asking for codes, passwords, or screen sharing
  • "Limited time" or "exclusive channel"? Cool off for 24 hours before acting
  • Verify identity only through channels listed on the official site — never links sent in a DM
  • The moment an online acquaintance talks money transfer, assume scam and verify
ASSET RATING

Security ratings for major assets

Ratings weigh network stability, custody ecosystem maturity, contract risk, and the regulatory environment (illustrative model for learning purposes — not investment advice).

Asset Risk level Security score Primary risk surface Custody guidance
BTCBitcoinNative PoW Low 92 Battle-tested protocol; risk sits in custody and fake-fork scams Cold storage in hardware wallets, split across addresses
ETHEthereumSmart contract platform Low 88 Solid base layer, but DeFi contract interactions carry approval risk Main holdings cold; keep small amounts and tight approval limits in hot wallets
USDTTetherFiat-backed stablecoin Medium 75 Centralized issuer risk, reserve transparency, fake USDT contracts on other chains Use only the official on-chain contract; spread across 2–3 major chains
USDCUSD CoinRegulated stablecoin Low–Medium 78 Ties to US regulation and banking; past de-pegs show short-term volatility is possible Follow reserve reports; avoid concentrating in a single stablecoin
SOLSolanaHigh-performance L1 Medium 72 Multiple full-network outages historically; uneven audit coverage in its ecosystem Large amounts cold; treat high-yield ecosystem projects with caution
MEMELong-tail meme assetsHigh-risk speculation High 45 Rampant rug pulls, liquidity manipulation, and pump-and-dump schemes A speculative wallet fully isolated from your main stack; only what you can afford to zero out
Scores come from a teaching model and shift with market and security conditions — defer to the latest reports from professional firms.
SECURITY CHECKUP

A 3-minute checkup: what's your defense grade?

Check off the measures you've already taken across these 10 core items. The panel on the right grades you live and suggests the highest-priority fix.

0 / 10 confirmed
WALLET SECURITY

Four custody setups: different amounts, different answers

"Not your keys, not your coins" doesn't mean cramming everything into one hot wallet. Layered custody by amount is the architecture that actually holds up.

Hot Wallet

Browser extension / mobile app
Security: Basic
  • Instant signing, best transaction experience
  • Right tool for daily small payments and on-chain activity
  • Keys live in a networked environment; malicious scripts can reach them
  • An infected device can mean a drained wallet
Keep here: no more than a month of expenses

Cold Wallet

Keys generated and kept on an offline device
Security: High
  • Keys never touch a networked device — remote attack surface near zero
  • An old phone or laptop works; cost is effectively zero
  • Clunky to operate; wrong fit for frequent trading
  • Demanding operational hygiene; one slip can contaminate everything
Keep here: your mid-to-long-term core holdings

Hardware Wallet

Dedicated signing device + secure element
Security: High
  • Keys sealed inside a secure element; signatures never leave the device
  • Physical button confirmation makes fake screens prohibitively costly
  • Buy only from official channels; second-hand devices are untrustworthy
  • Firmware updates need signature verification — supply-chain attacks have happened
Keep here: large amounts and all core assets

Multisig Vault

M-of-N shared control contract
Security: Highest
  • A single stolen key still can't move the funds
  • Designed for team treasuries and large family holdings
  • The contract itself needs auditing; misconfigurations have caused massive losses
  • Highest daily-use threshold and coordination overhead
Keep here: organizational assets and very long-term reserves
INCIDENT TIMELINE

Major incidents: how the industry learned to walk

Behind every industry security standard is a lesson paid for in real money. All events below are publicly reported; amounts are approximate.

2014~850K BTC lost

Mt. Gox collapse

The world's largest Bitcoin exchange at the time lost around 850,000 BTC through prolonged hot storage and failed internal controls, then filed for bankruptcy — hundreds of thousands of users lost everything.

Lesson learned: "most exchange assets must be in cold storage" became an industry rule; cold/hot separation is now standard at regulated exchanges.
2016~3.6M ETH

The DAO reentrancy attack

The DAO, the first large-scale crowdfunding project, was drained repeatedly through a reentrancy flaw in its smart contract — about 3.6M ETH — ultimately forcing a contentious hard fork.

Lesson learned: the smart contract audit industry was born, and the "checks-effects-interactions" pattern entered development canon.
2018~$523M

Coincheck NEM theft

Japanese exchange Coincheck kept customer assets concentrated in an internet-connected hot wallet with a weak multisig implementation, losing about $523M worth of NEM.

Lesson learned: Japan tightened exchange licensing and cold-storage ratios; concentrated hot-wallet custody was widely abandoned.
2021~$611M

Poly Network bridge hack

An attacker exploited a permission-check flaw in the cross-chain contract to move about $611M; the saga ended with the attacker gradually returning funds — a classic case study in on-chain tracing and negotiation.

Lesson learned: bridges became the most-targeted infrastructure; permission minimization and multisig upgrades got a hard relook.
2022~$625M

Ronin Bridge validator compromise

Axie Infinity's Ronin bridge lost 5 of 9 validator private keys to social-engineering phishing; roughly $625M was moved — and it went unnoticed for months.

Lesson learned: over-concentrated validators + phished node keys = systemic collapse. Cross-chain infrastructure moved to stricter key governance.
2022Customer funds wiped out

FTX collapse

Top-tier exchange FTX was revealed to have diverted customer funds to plug holes at an affiliated trading firm; after a run on withdrawals it went bankrupt within a week, and industry trust shattered overnight.

Lesson learned: the self-custody movement surged, and proof-of-reserves (PoR) became table stakes for exchanges — though PoR remains necessary, not sufficient.
2023~$197M

Euler Finance flash-loan attack

Lending protocol Euler was hit by a flash-loan attack exploiting a donation-function logic flaw, losing about $197M; on-chain negotiation recovered the vast majority of the funds.

Lesson learned: edge cases in complex function combinations are audit blind spots — real-time monitoring and incident response after launch matter just as much.
SCAM RADAR

Six high-frequency scam cards

Scripts keep evolving; the structure never does: manufactured urgency, borrowed authority, and returns too good to be true. Learn each card's tells and you're effectively vaccinated.

Fake airdrops

AIRDROP SCAM

An unknown token shows up in your wallet alongside a "claim your airdrop" site; connecting and signing hands over the right to move your assets.

Red flags
  • Unknown tokens arrive with their own website and support group
  • "Verification" requires entering your seed phrase
Never claim mystery airdrops; just hide the token

Fake support / fake officials

FAKE SUPPORT

Ask a question in a community group and an "admin" DMs you instantly: your account is frozen, download this remote-control tool or hand over the code.

Red flags
  • Unsolicited DMs that mention account or fund problems
  • Requests for screen sharing or one-time codes
Official teams never DM first; use only the site's support channel

Pig butchering

ROMANCE SCAM

Weeks or months of romance or friendship-building, then an "offhand" flash of trading profits, funneling victims into a deposit platform the scammer fully controls.

Red flags
  • Profit screenshots that look printed — always consistent, never losing
  • Small withdrawals go smoothly; large ones trigger "taxes" and "unfreezing fees"
An online match who talks investing is a scam; cut losses, report it

Fake wallets / apps

FAKE WALLET

Knock-off apps imitating well-known wallets slip into app stores and search results; the moment you "create a wallet," the seed phrase ships straight to the attacker's server.

Red flags
  • Download counts and reviews wildly inconsistent with the official app
  • Developer name doesn't match what the official site lists
Reach app stores only via the official site; verify the developer signature

High-yield schemes

YIELD SCAM

"2% a day, capital guaranteed, withdraw anytime" crypto yield programs are Ponzi structures — later deposits pay earlier investors' "interest."

Red flags
  • Returns far above any real market-neutral benchmark
  • Referral bonuses and multi-level recruiting rewards
Double-digit annual returns "guaranteed"? Call it a scam immediately

Malicious / blind signing

BLIND SIGNING

You're talked into signing an opaque message that is actually a permit approval or transfer authorization — while the wallet displays something harmless.

Red flags
  • Signing requests full of hex-gibberish data
  • The signing request doesn't match what you were doing
Decline any signature you don't understand; enable clear signing
INCIDENT RESPONSE

The golden 6 steps after a theft

The first hour after a theft defines the blast radius. The panicked moves — repeatedly sending to the same address, deleting chat logs — are exactly what widens the loss. Work these steps in order.

Emergency response checklist Bookmark or screenshot this page — in an emergency, run it top to bottom
01

Move remaining assets now

If keys are compromised, generate a fresh wallet on a clean device and move everything not yet stolen immediately. There is no "let's watch it a bit longer."

02

Revoke all contract approvals

If it was an approval phishing, use an approval manager to batch-revoke every allowance for that address and cut off the attacker's future withdrawals.

03

Preserve the evidence

Export transaction hashes, attacker addresses, chats, and site screenshots. Delete nothing — they're the backbone of your police report and any recovery.

04

Alert exchanges, flag on-chain

If funds flow into a centralized exchange, contact its risk team to freeze; flag the address on-chain to choke the attacker's cash-out routes.

05

File a police report

Bring your evidence to local law enforcement and get a case receipt; cross-border cases can be coordinated through specialized counsel.

06

Rebuild your defenses

Find the failed layer — device, habit, or supply chain? Rebuild against this center's checklist so you never fall in the same spot twice.

LEARNING CENTER

Learning center: turn defense into muscle memory

Read by topic — every guide ships with an executable checklist. The distance between "knowing it" and "doing it every time" is your real security level.

FAQ

Frequently asked questions

The most-asked questions about keys, platforms, and security habits.

Unfortunately no. The seed phrase is the final control over the assets and there is no "password reset" — that's both the cost and the protection of decentralization. If you still remember some words and their order, safe dictionary-search tools exist, but success rates are limited. What you should actually do: multiple off-site backups, durable media like steel, and where appropriate a multisig or social-recovery setup, so "forgetting" never equals "zero."
They're different risks. Exchanges shield you from "losing my own seed phrase" but introduce misappropriation, bank runs, and regulatory freezes — risks you can't control at all, as FTX showed. The sensible structure is layered: trading funds on a platform, long-term holdings self-custodied, and the larger the amount, the stronger the case for self-custody or institutional-grade custody.
Don't inspect details, don't visit its bundled website, don't try to sell it. These tokens are bait for poisoning-style phishing: luring you to a fake site to connect your wallet, or triggering a malicious contract when you sell. Just hide the token in your wallet. The token itself can't attack you — the danger is every interaction built around it.
No. The device is only a carrier for the keys; the assets live on-chain. With your backed-up seed phrase, buy a new official device (or use any compatible wallet), import, and everything is restored. The actual danger is keeping the device and the written backup in the same drawer — store the two separately, in different places.
Spend ten minutes on four checks before touching it: liquidity lock records and duration, top-ten holder concentration, whether the contract has blacklist or tax powers, and whether the team is doxxed or credibly audited. One failure — walk away. Then remember the iron rule: for any project promising "stable high returns," the returns are your own principal.
If your 2FA relies on SMS, you're at critical risk — the attacker can receive your codes and reset linked accounts. Act now: call your carrier to restore the SIM, switch 2FA on all financial and email accounts to an authenticator app or hardware key, and set unique strong passwords. From now on, never again treat SMS as the second factor for critical accounts.

Security isn't a one-time pass — it's a habit

Come back every three months and run the checkup again; keep tracking new phishing tricks and platform shifts. Attackers keep evolving — your defenses should too.