Know your adversary

Attack vectors — and how to disarm them

Self-custody makes you the bank — and banks get attacked. These are the methods actually used against bitcoin holders today, with concrete defenses for each.

01

Phishing & social engineering

How it works

Emails, ads and DMs posing as Ledger/Trezor/support, fake “firmware update required” sites, Discord/Telegram “helpers”, even phone calls from “security teams”. One goal: make you type your seed phrase somewhere.

Defense
  • Rule zero: seed words are never typed anywhere except a hardware device during recovery
  • No legitimate company will ever call, DM or email you first — end the contact, reach out via official channels yourself
  • Bookmark official sites; never click ads for wallet software
  • Treat urgency (“act within 24h!”) as a red flag by definition
02

Malware: clipboard hijackers & keyloggers

How it works

Viruses watch your clipboard and silently swap copied bitcoin addresses; keyloggers record passwords and passphrases; screen-capture trojans photograph your “hidden” wallet data.

Defense
  • Verify every address on the hardware wallet’s own screen — the device is the source of truth
  • Enter passphrases/PINs on-device whenever the wallet supports it
  • Keep the computer you use for transactions minimal: no pirated software, no random browser extensions
  • Compare first AND last characters of pasted addresses
03

USB-based attacks

How it works

BadUSB devices and “Rubber Ducky” sticks act as keyboards and execute commands in seconds; malicious charging cables (O.MG) hide Wi-Fi implants; a tampered cable can also attempt to exploit firmware over USB.

Defense
  • Never plug unknown USB sticks or “found” cables into your machine — the classic bait attack
  • Use your own cable, ideally data-blocked adapters for charging
  • Prefer fully air-gapped signing (QR or microSD) so the wallet never touches USB data lines at all
  • Buy hardware wallets only from the manufacturer and check anti-tamper seals
04

Fake software & poisoned updates

How it works

Typosquatted wallet apps, fake Ledger Live clones, compromised download mirrors and malicious “update” popups replace your wallet software with a version that steals keys or changes addresses.

Defense
  • Download only from official sites/GitHub releases; verify GPG signatures or checksums when provided
  • Let the hardware device verify what the computer shows — never the reverse
  • Be suspicious of unsolicited “mandatory security update” messages — check the vendor’s official channel first
  • In app stores: verify the publisher name exactly; clones abuse lookalike names
05

Address poisoning & dusting

How it works

Attackers send you tiny transactions from an address that looks almost identical to one in your history (same first/last characters). Later you copy “your” address from the history — and it’s theirs.

Defense
  • Never copy addresses from transaction history — always generate a fresh receive address
  • Verify the full address on the hardware device screen, not just the first/last characters
  • Ignore unknown small incoming transactions; don’t spend dust together with your real UTXOs
06

SIM-swap & account takeover

How it works

Attackers port your phone number via social-engineered carrier support, reset your exchange/email passwords via SMS, drain whatever still sits on custodial accounts — then phish deeper.

Defense
  • Best defense: don’t keep funds where an SMS can reset anything (see: why self-custody)
  • Use TOTP or hardware security keys, never SMS 2FA
  • Set a carrier PIN / port-out lock with your mobile provider
  • Use a dedicated, unpublicized email for financial accounts