On this page
When it's not just you: controls for teams and treasuries
For teams managing digital assets, individual habits are necessary but not sufficient. Layered organizational controls reduce the blast radius of a single mistake or compromise:
- Approval workflows — require a second approver for any outbound transaction above a threshold.
- Multi-sig governance — custody treasury with m-of-n signers (e.g. 3-of-5) so no single person can move funds alone.
- Address allow-listing — restrict outbound payments to pre-approved addresses; new payees require a verified change request.
- Segregation of duties — separate the roles that initiate, approve, and reconcile transactions.
- Out-of-band verification — confirm address changes or large payments through a known, separate channel (not the same email that requested them).
- Role-based access — least-privilege access to wallets, signing devices, and exchange accounts; remove access promptly on role change or exit.
- Training & drills — run periodic phishing simulations and tabletop exercises; refresh onboarding annually.
- Incident & recovery plan — documented steps for suspected compromise, including key rotation and custodian escalation.
Three of five to move the treasury
Controls that are painful to follow get bypassed. The goal is a workflow where the secure option is also the low-friction one — for example, a treasury dashboard that only offers allow-listed recipients by default.
The Multi-sig Vault Simulator lets you configure M-of-N custody and see how a compromised key is contained. The Cold Storage Walkthrough is a guided hardware-wallet setup checklist including the inheritance question.
Go deeper — the smart-contract risk you can't see
On chains like Ethereum, signing a transaction can call a smart contract with near-arbitrary logic. "Infinite approvals" let a contract spend tokens up to an unlimited amount — revisit and revoke approvals with tools like Etherscan’s token approval checker. Blind-signing transactions you don’t understand is a leading cause of loss.
The Major Hacks & Bad Actors reference page collects the documented exchange collapses, DeFi exploits, state-sponsored thefts, and Ponzis — with root causes and aftermath for each.
Key takeaways
A one-page summary of Security & Scams. Print it for quick reference.
- In crypto you are the bank — there’s no fraud department to reverse a mistake.
- Never share your seed phrase with anyone, ever. Any “support” asking for it is a scam.
- Common attacks: phishing, seed-phrase theft, rug pulls, 51% attacks, SIM swaps, address poisoning, social engineering, reentrancy, flash-loan attacks, oracle manipulation.
- Defensive habits: hardware wallet for significant amounts, TOTP/FIDO2 2FA (not SMS), address verification, skepticism toward urgency.
- Organizational controls: multi-sig, approval workflows, address allow-listing, segregation of duties, out-of-band verification, RBAC, training drills, incident plans.
Unit check
80% to complete this unitPass the unit check (4 of 5) to complete this unit.