Unit 3 · Level 1 · Self-custody & security
Opsec for humans
Most people who lose crypto weren't out-hacked; they were out-prepared. Good operational security is a handful of dull habits: app-based 2FA instead of SMS, a unique email just for exchanges, a small test send before any big transfer, and reading full addresses instead of glancing at the first four characters. Dull is the point. Dull is what survives.
Free to play. No ads, no token, no account needed to start.
What you get asked
Why is an authenticator app safer than SMS for exchange 2FA?
In a SIM-swap, a scammer talks your mobile carrier into moving your number to their SIM, and then every SMS code is theirs. Authenticator codes live on your device, not your phone number.
Match each habit to the attack it defends against.
Each habit closes one specific door. None is heroic on its own; together they make you a hard target.
Before a large transfer, send a small ___ transaction to confirm the address and network are right.
Send €10, see it arrive, then send the rest to the exact same address. Crypto transfers can't be reversed, so you pay one extra fee to buy certainty.
An attacker sends you zero-value transfers from an address crafted to match the first and last 4 characters of one you use. What's their play?
This is address poisoning: it plants a near-twin in your transaction history and waits. Beat it by checking more than the first and last 4 characters. Better yet, never copy addresses from history at all.
Why do experienced holders keep quiet about how much crypto they own?
Scammers pick targets who look worth the effort, and there have been real cases of people robbed at home over crypto. Nobody needs to know your numbers. Silence is free armour. 🐜
The rest of this unit
Scams, approvals, cold storage: become hard to rob.