Attack vectors — and how to disarm them
Self-custody makes you the bank — and banks get attacked. These are the methods actually used against bitcoin holders today, with concrete defenses for each.
Phishing & social engineering
Emails, ads and DMs posing as Ledger/Trezor/support, fake “firmware update required” sites, Discord/Telegram “helpers”, even phone calls from “security teams”. One goal: make you type your seed phrase somewhere.
- Rule zero: seed words are never typed anywhere except a hardware device during recovery
- No legitimate company will ever call, DM or email you first — end the contact, reach out via official channels yourself
- Bookmark official sites; never click ads for wallet software
- Treat urgency (“act within 24h!”) as a red flag by definition
Malware: clipboard hijackers & keyloggers
Viruses watch your clipboard and silently swap copied bitcoin addresses; keyloggers record passwords and passphrases; screen-capture trojans photograph your “hidden” wallet data.
- Verify every address on the hardware wallet’s own screen — the device is the source of truth
- Enter passphrases/PINs on-device whenever the wallet supports it
- Keep the computer you use for transactions minimal: no pirated software, no random browser extensions
- Compare first AND last characters of pasted addresses
USB-based attacks
BadUSB devices and “Rubber Ducky” sticks act as keyboards and execute commands in seconds; malicious charging cables (O.MG) hide Wi-Fi implants; a tampered cable can also attempt to exploit firmware over USB.
- Never plug unknown USB sticks or “found” cables into your machine — the classic bait attack
- Use your own cable, ideally data-blocked adapters for charging
- Prefer fully air-gapped signing (QR or microSD) so the wallet never touches USB data lines at all
- Buy hardware wallets only from the manufacturer and check anti-tamper seals
Fake software & poisoned updates
Typosquatted wallet apps, fake Ledger Live clones, compromised download mirrors and malicious “update” popups replace your wallet software with a version that steals keys or changes addresses.
- Download only from official sites/GitHub releases; verify GPG signatures or checksums when provided
- Let the hardware device verify what the computer shows — never the reverse
- Be suspicious of unsolicited “mandatory security update” messages — check the vendor’s official channel first
- In app stores: verify the publisher name exactly; clones abuse lookalike names
Address poisoning & dusting
Attackers send you tiny transactions from an address that looks almost identical to one in your history (same first/last characters). Later you copy “your” address from the history — and it’s theirs.
- Never copy addresses from transaction history — always generate a fresh receive address
- Verify the full address on the hardware device screen, not just the first/last characters
- Ignore unknown small incoming transactions; don’t spend dust together with your real UTXOs
SIM-swap & account takeover
Attackers port your phone number via social-engineered carrier support, reset your exchange/email passwords via SMS, drain whatever still sits on custodial accounts — then phish deeper.
- Best defense: don’t keep funds where an SMS can reset anything (see: why self-custody)
- Use TOTP or hardware security keys, never SMS 2FA
- Set a carrier PIN / port-out lock with your mobile provider
- Use a dedicated, unpublicized email for financial accounts