One of the biggest issues plaguing the cryptocurrency world is a wave of scams, with US government figures showing that 46,000 Americans lost a combined $1 billion to criminals last year.
Between pump and dump schemes, romance scams, and “carpet pulling,” crypto scams are becoming more brazen and sophisticated. Perhaps even more worrying is the rash of major heists, in which hackers have been able to steal billions of dollars’ crypto value of people’s digital accounts.
But good cybersecurity habits can minimize the risks, experts say. Here are three mistakes to avoid when buying cryptocurrency.
Receive your login credentials via text message
Some cryptocurrency exchanges use two-factor authentication for online accounts. This requires users to first enter their username and password, and then enter a numeric code that is usually sent to their mobile phone via text message.
The problem? Hackers can use what’s known as a “SIM swap” scam to intercept your incoming texts, warned blockchain scam researcher Joe McGill. It recommends using a third-party service like Google Authenticator or Okta Verify; better yet, buy a “YubiKey”, which must be connected to your computer to unlock your account.
“A YubiKey is just a little thumb drive that you plug into a USB port,” McGill said.
Ignoring the authorization list
One step in setting up a crypto account is something called an “allow list”. This is where a user can enter a list of IP addresses and designate which computers someone can use to withdraw funds from the account.
But users often overlook the list because they’re in a rush to set up their account and focus on other steps in the process. But it’s an easy way to implement an extra layer of security, said McGill, who runs the crypto scam reporting website Chainabuse. Don’t skip the whitelist.
“All these major exchanges now have all the security measures in place, from the simplest options to the most paranoid,” McGill said. So use them all.
Store your sloppy “seed phrase”.
For crypto buyers using a digital wallet, protecting your “seed phrase” is vital. A seed sentence is a random set of words generated once a digital portfolio is created. It allows the user to recover their crypto assets in case something goes wrong.
Too often, people store their opening phrase in their email, in a Google Drive or in an online note, said Paul Sibenik, case manager at blockchain research firm CipherBlade. This makes it an easy target for hackers.
Instead, hide the opening sentence in a safe place that is not connected to the Internet. If you write it down somewhere, make sure you don’t lose it, that can be a big headache too.
“If another party accesses the seed phrase, your funds are gone,” Sibenik said. “This takes some planning. You have to think about it meticulously.”
Add Comment