Crypto Security in Today’s Climate: What Today’s Investors Need to Know

[ad_1]

Crypto users face a near-constant barrage of threats, including widespread phishing schemes, targeted attacks from scammers posing as friends and application support staff, malware seeking insecure private keys and speculative meme coins with the sole purpose of creating market liquidity for early entrants. to dump on retail investors. Fortunately, as attacks become increasingly sophisticated, those aiming to defend against malicious actors are developing advanced tools to educate and protect consumers. Here are some examples of the most common scenarios to protect yourself against, as well as how the crypto space is evolving to stay ahead.

It is important to understand the distinction between holding cryptocurrency on centralized exchanges and holding it in your own wallet via self-custody. The easiest way to access crypto is to create an account on a centralized exchange and purchase tokens. However, there is a significant risk in leaving investments on a centralized exchange. Centralized exchanges often lack transparency in accounting and lead to traditional Web2-style fraud, as we saw with the collapse of FTX, which was taken over by collapses of traditional banking institutions around the world. However, once a crypto user withdraws their tokens to their own self-custody wallet, they are faced with the responsibility of avoiding phishing campaigns, protocol hacks, private key leaks, etc.

Phishing campaigns range from generalized campaigns to targeted attacks. Recently, I came across malicious Google ads that redirect users from legitimate websites to perfect clones that prompt the user to confirm transactions in their wallet that send all their assets to an attacker. There are also scammers posing as benevolent actors warning users that an app they recently used has been compromised and they should withdraw all their funds immediately. The site the crooks send the user to appears identical to the app they are familiar with, which then prompts them to confirm the same style of malicious transactions.

Even when users connect to legitimate applications, they are not immune to protocol vulnerabilities and the accidental introduction of malicious code via protocol updates. Over the past year, there have been network bridges and decentralized exchanges that have introduced unaudited updates to their code base that were quickly exploited by bad actors, draining all user deposits.

A persistent problem with crypto wallets is that transactions are impossible to decipher for the vast majority of users. People have taken to clicking confirm on opaque blobs of hex data, confident that the app is telling them the truth. Wallets are starting to get smarter, and now there are tools people can install on their computers, or networks people can connect their wallets to to help filter out errors and hacks. The Shield3 RPC is a free tool that people can use to filter common hacks and interactions with known bad actors (https://www.shield3.com/transaction-guard).

Also, like in many areas, AI helps. Decentralized finance applications offer unprecedented transparency and data availability to train and adapt models to common developer errors, bad actor attack patterns, and penetration testing by benevolent hackers. For example, one can now visit a blockchain explorer, copy smart contract code from a popular DeFi app, and paste it into ChatGPT, asking it to find potential ways to mine the code. One can also ingest all data on all existing smart contracts and transactions, and identify patterns and transactions that lead to a major hack. Specifically, when someone is about to attack a protocol, there is often a series of transactions where they create a new anonymous wallet using a private transaction service, like Tornado Cash, then prepare his wallet to exploit a protocol. Protocols can defend themselves by detecting these patterns and interrupting the protocol before the exploit can take place, then implementing patches before resuming.

However, although this data is widely available, it is almost impossible for the vast majority of users to understand. AI tools allow us to take information from threat analysis and detection tools and present it in a personalized language that is understandable to everyone, regardless of their level of technical sophistication. We can take highly technical audit reports and data feeds and have great language models summarizing the threat in any language, for any audience.

These tools enable us to both detect threats faster and more effectively than ever before and democratize access to information to make security and risk mitigation widely available.

About the Author

Isaac Patka is a former electrical engineer in the semiconductor industry who became a crypto developer in early 2017; specializing in Web3 security, DAOs and experimental applications of blockchain technology. Isaac is an active contributor to open standards in the areas of web3 governance and security. He entered the Ethereum space in 2017 researching bug bounties for new experimental smart contracts. Since then, he has used his passion for accessible and transparent security to demonstrate both what can go wrong and how to fix it. Last year, he published a white hat exploit of a popular smart contract framework that manages billions of dollars in the crypto space. Citation: https://law.mit.edu/pub/exploitinginattentionandmisconfigurations/release/1

He also offers his efforts to help people recover from losing their private keys and access funds in leaked wallets. Additionally, he collaborates with artists in their exploration and creation of crypto-native art forms, often exploring collective creation, intellectual property and ownership.

Sources

1/ https://Google.com/

2/ https://www.globaltrademag.com/crypto-security-in-the-current-climate-what-todays-investors-should-know/

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts