Skip to main content
Bankless

Zero Crypto at Home: Bankless in the Age of Wrench Attacks and Phishing | Jameson Lopp and Beau

102 min episode · 3 min read
·
Jameson Lopp

Episode

102 min

Read time

3 min

Topics

Startups, Leadership, Design & UX

AI-Generated Summary

Key Takeaways

  • Threat Prioritization: Physical wrench attacks, while alarming, represent roughly 70 documented incidents globally in 2024 and under a dozen in early 2026. The statistically dominant threats remain custodial failures like exchange collapses and poorly audited smart contracts. Listeners should allocate security effort proportionally: digital hygiene and wallet architecture first, physical hardening second, with wrench-attack mitigation as a third layer rather than the primary concern.
  • Wallet Segregation System: Operate a minimum three-wallet structure: a hot wallet capped at roughly $1,000 for daily transactions, a mid-tier wallet dedicated exclusively to riskier on-chain activity like granting smart contract approvals, and a cold storage vault that never receives approvals and only moves funds deliberately. This architecture ensures that a phishing mistake or malware infection on the active wallet cannot cascade to long-term holdings.
  • Hardware Authentication Stack: Replace SMS two-factor authentication immediately — SIM swapping makes it trivially bypassable. The recommended hierarchy is: FIDO2 passkey on a YubiKey as the gold standard, followed by TOTP codes stored on Yubico Authenticator (which keeps secrets on the hardware device rather than syncing to Google's cloud), then email-based 2FA as a last resort. A password manager adds a critical layer by refusing to autofill credentials on typosquatted phishing domains.
  • Zero Crypto at Home Architecture: Design custody so that no single person, under duress at home, can unilaterally move significant funds. This means distributing multisig keys across geographically separate locations — ideally behind physical access controls like bank safe deposit boxes with business-hours-only access — using hardware devices from different manufacturers. Wrench attacks currently succeed at over 50% of attempts precisely because most victims are single points of failure who can authenticate and transfer funds without leaving the house.
  • Social Engineering Defense: Nearly every communication channel — email, SMS, Telegram, Discord — is unauthenticated and trivially spoofable. The operational rule: never act on an inbound message. Instead, independently navigate directly to the relevant platform by typing the URL manually, log in, and verify the claimed issue there. For voice-based impersonation attacks, use shared insider knowledge — specific private memories — rather than pre-agreed safe words, which are frequently forgotten under duress.

What It Covers

Jameson Lopp (Casa Security cofounder) and Beau (former CIA officer, Pudgy Penguins safety lead) break down the full threat landscape facing crypto holders in 2026 — from sophisticated phishing and malware attacks to physical home invasions — and provide layered, concrete defensive strategies across digital security, physical hardening, and self-custody architecture.

Key Questions Answered

  • Threat Prioritization: Physical wrench attacks, while alarming, represent roughly 70 documented incidents globally in 2024 and under a dozen in early 2026. The statistically dominant threats remain custodial failures like exchange collapses and poorly audited smart contracts. Listeners should allocate security effort proportionally: digital hygiene and wallet architecture first, physical hardening second, with wrench-attack mitigation as a third layer rather than the primary concern.
  • Wallet Segregation System: Operate a minimum three-wallet structure: a hot wallet capped at roughly $1,000 for daily transactions, a mid-tier wallet dedicated exclusively to riskier on-chain activity like granting smart contract approvals, and a cold storage vault that never receives approvals and only moves funds deliberately. This architecture ensures that a phishing mistake or malware infection on the active wallet cannot cascade to long-term holdings.
  • Hardware Authentication Stack: Replace SMS two-factor authentication immediately — SIM swapping makes it trivially bypassable. The recommended hierarchy is: FIDO2 passkey on a YubiKey as the gold standard, followed by TOTP codes stored on Yubico Authenticator (which keeps secrets on the hardware device rather than syncing to Google's cloud), then email-based 2FA as a last resort. A password manager adds a critical layer by refusing to autofill credentials on typosquatted phishing domains.
  • Zero Crypto at Home Architecture: Design custody so that no single person, under duress at home, can unilaterally move significant funds. This means distributing multisig keys across geographically separate locations — ideally behind physical access controls like bank safe deposit boxes with business-hours-only access — using hardware devices from different manufacturers. Wrench attacks currently succeed at over 50% of attempts precisely because most victims are single points of failure who can authenticate and transfer funds without leaving the house.
  • Social Engineering Defense: Nearly every communication channel — email, SMS, Telegram, Discord — is unauthenticated and trivially spoofable. The operational rule: never act on an inbound message. Instead, independently navigate directly to the relevant platform by typing the URL manually, log in, and verify the claimed issue there. For voice-based impersonation attacks, use shared insider knowledge — specific private memories — rather than pre-agreed safe words, which are frequently forgotten under duress.
  • Physical Home Hardening: Replace standard door hardware with hardened striker plates and 3-inch screws (roughly $20) to extend forced-entry time from seconds to minutes. Add professionally installed 3M security film to windows for an additional 30–60 seconds of resistance. Visible cameras, motion-activated floodlights, and a monitored alarm system with a dedicated panic button function as deterrents during the surveillance phase attackers conduct before any attempt. A dog — even a small, vocal one — provides reliable early alerting.
  • On-Chain Privacy Limitations: Public blockchains make true address privacy structurally difficult. The practical minimum: never link ENS names or public-facing NFT profile pictures to wallets holding significant assets, and fund new private wallets through a different centralized exchange than the one used for existing wallets to break the on-chain connection. For strong privacy requirements, Monero and Zcash offer protocol-level privacy rather than requiring complex and error-prone mixing techniques on transparent networks.

Notable Moment

Lopp reveals that duress wallets — a commonly recommended tactic where victims hand over a decoy wallet to satisfy attackers — show no evidence of working. In documented cases, victims who immediately surrendered everything were still subjected to prolonged coercion because attackers assumed the wallet was a decoy. The only reliable defense is architectural: making it structurally impossible to move funds under duress.

Know someone who'd find this useful?

Episode Transcript

We have two security experts on the podcast today. In addition to myself, this is Ryan Sean Adams. David can't be with us today. Let me tell you why I'm doing this episode. There's been an increase in physical attacks on crypto investors. It's It's probably happened over the last year or two in particular. I could share a dozen or more stories. This is causing anxiety in the crypto community. Perhaps as a listener, it's causing you some anxiety as as you've seen some of these in the headlines. So this episode is a way to get back some control. This episode is about tactics. This is ways to harden your physical security against threats attacks and your digital security against phishing attacks. It includes an approach that I like called zero crypto at home. At least that's what I'm calling it. And it pretty much means what it says. It is about designing a system so that you can't access crypto at home using multisigs, time delays, third party verification when needed. And I know this adds some friction in the process. I know in some ways it's not ideal. But it is something I advise and that's important, in particular if you're a doxxed crypto investor. You're not pseudo anonymous and your name is out there. Because one thing I think you'll hear if you've listened to the Bankless podcast for any amount of time is we believe the purpose of crypto is freedom. You want to be your own bank, but you don't want to be your bank security guard. That is not freedom. So let's figure out how to go bankless in the age of wrench attacks. Before we do, wanna thank our friends and sponsors over at Rocket Pool. Speaking of non custodial access, of course, Rocket Pool is a non custodial staking provider. They are now launching their Saturn upgrade. This is the biggest upgrade in Rocket Pool that's ever shipped since its launch. A few key features. It is bringing an RPL fee switch if you're waiting for that. So now staking RPL can earn even more protocol revenue. That's all paid in ETH, of course. Liquid staking also has boosted minting capability. And on the nodes node side, you can now run a node with four ETH validators and mega pools. Those are opening in just a few days, so this lowers the barrier of entry even more. If you are looking for more than just basic staking yield on your ETH, go check out Rocket Pool. There's a link in the show notes. You can stake your ETH and, get ready for those four ETH validators. They're actually launching February 18. It's probably launched by the time you listen to this episode. Let's get right into the episode of Jameson Lop and Bo on security. Bangla Station doing this episode because it feels very timely. And the truth is I've been delaying doing this episode for quite some time because …

Get the full transcript (18,576 words) + summary by email — free

One-time email with the complete transcript and AI summary of this episode. No account needed.

One email, no spam. We’ll also show you what SignalCast does.

Browse all Bankless transcripts →

You just read a 3-minute summary of a 99-minute episode.

Get Bankless summarized like this every Monday — plus up to 2 more podcasts, free.

Pick Your Podcasts — Free

Keep Reading

Books, tools, and gear mentioned in this episode

SignalCast may earn commission on purchases via these links. As an Amazon Associate, SignalCast earns from qualifying purchases.

Tools

  • by Yubico

    TOTP codes stored on Yubico Authenticator (which keeps secrets on the hardware device rather than syncing to Google's cloud)

Gear

  • YubiKeyRecommended

    by Yubico

    The recommended hierarchy is: FIDO2 passkey on a YubiKey as the gold standard, followed by TOTP codes stored on Yubico Authenticator

Products

  • 3M Security FilmRecommended

    by 3M

    Add professionally installed 3M security film to windows for an additional 30–60 seconds of resistance.

company

  • Beau (former CIA officer, Pudgy Penguins safety lead)
  • Jameson Lopp (Casa Security cofounder) and Beau (former CIA officer, Pudgy Penguins safety lead) break down the full threat landscape facing crypto holders in 2026
  • For strong privacy requirements, Monero and Zcash offer protocol-level privacy rather than requiring complex and error-prone mixing techniques on transparent networks.
  • For strong privacy requirements, Monero and Zcash offer protocol-level privacy rather than requiring complex and error-prone mixing techniques on transparent networks.

More from Bankless

We summarize every new episode. Want them in your inbox?

Similar Episodes

Related episodes from other podcasts

Explore Related Topics

This podcast is featured in Best Crypto Podcasts (2026) — ranked and reviewed with AI summaries.

Read this week's Startups & Product Podcast Insights — cross-podcast analysis updated weekly.

You're clearly into Bankless.

Every Monday, we deliver AI summaries of the latest episodes from Bankless and 192+ other podcasts. Free for one show.

Start My Monday Digest

No credit card · Unsubscribe anytime