Digital Asset Self-Custody HubGet the App
← Back to Self-Custody Hub

Security Awareness: Vigilant vs. Vulnerable Practices

Most losses in this space don't come from broken cryptography — they come from someone being talked into handing over access. Phishing is a deceptive attempt to trick a user into revealing a private key or approving a malicious transaction, typically through an impersonated website, message, or support contact.

Vulnerable Practices

  • Urgency Pressure: a message manufactures false time pressure to force a fast decision.
  • Unverified Link Click: a link is followed without independently checking its source.
  • Credential Exposure: a private key or recovery phrase gets typed into a website or message.

Vigilant Practices

  • Source Verification: every link and sender is confirmed independently before acting.
  • Isolated Confirmation: transaction details are checked on a separate, trusted device.
  • Zero Disclosure: a private key or recovery phrase is never entered anywhere, ever.

Distributed keys remove a central point of failure on paper. In practice, that protection only lasts as long as the person holding the keys doesn't get tricked into handing them over.

See the glossary for definitions of the terms used on this page.