# The Only Safe Way to Store Crypto

By [Officer's Blog](https://paragraph.com/@officercia) · 2022-11-16

---

Greetings, dear readers! I am frequently asked what is the best dependable way to keep cryptocurrency, whether it is Bitcoin, Monero, ERC20 tokens, or DOGE. In this essay, I'd like to offer the solution to that question; regrettably, there are no clear and simple answers…

### Check out:

*   [**OpSec Guide (Simplified)**](https://github.com/OffcierCia/Crypto-OpSec-SelfGuard-RoadMap)
    
*   [OpSec Going Smart](https://officercia.mirror.xyz/fsRT9NC29GzeQAl-zvAMJ9L-hYUYvX1CPUkt97Vuuwo)
    
*   [OpSec Going Smarter](https://officercia.mirror.xyz/B9hBom4jGhkV0C-47E4YBz8tBJkb0a7zVwQR0jITIyM)
    
*   [OpSec Going Smarter: Secure Smartphones](https://officercia.mirror.xyz/0tlSSF2LDTOnnMN41R5Uc1kTpo-G-kXljn8pT0a1YLY)
    
*   [Choosing a Reliable VPN Provider for Life & Work](https://officercia.mirror.xyz/x91hTIDFrAL0lgqICRgWU7fLouuCMgvopQ9ZRvRXCLg)
    

I'd also like to thank the authors of all of the services that were used as examples in this essay, as well as the authors of all of the resources that I utilized as references; keep up the fantastic job!

### Summary:

[http://buidlbee.com/binance-ceo-changpeng-zhao-approved-guide-on-how-to-store-the-keys-for-your-crypto-here-are-the-main-points](http://buidlbee.com/binance-ceo-changpeng-zhao-approved-guide-on-how-to-store-the-keys-for-your-crypto-here-are-the-main-points)

* * *

I - Introduction
----------------

So, first of all, we have to decide, what do we need it for? Anyone can use Ethereum securely, same with [Monero](https://telegra.ph/CIA-Officer--Monero-05-08), in which you should keep in mind way [less](https://github.com/OffcierCia/Crypto-OpSec-SelfGuard-RoadMap) security rules.

If you need a bulletproof anonymity or ultra privacy, then read this awesome ultra [hardcore guide](https://anonymousplanet.org). Read my recent article dedicated to a «Timing Attack» or «[Attack via a representative sample](https://officercia.mirror.xyz/WeAilwJ9V4GIVUkYa7WwBwV2II9dYwpdPTp3fNsPFjo)» !

### You must remember the main rule:

> _Your level of OpSec usually depends on your threat model and which adversary you're up against. So it's hard to define how good your OpSec is._

The thing is that if you need a certain crypto-wallet for work, for staking, for paying your employees and so on - it is considered "operational" or "hot", so we will consciously build its protection based on [objective threats](https://t.me/Rekt_HQ/66747), you can learn about this from my articles: [officercia.mirror.xyz](https://officercia.mirror.xyz/)!

But today, I'd like to focus our conversation on the fact that we require a **truly** secure solution. To help us visualize it, let me phrase the topic of today's essay as follows:

**"You suddenly received $1 billion in any cryptocurrency, and you don't want to invest it yet, but you want to securely save the majority of it using cryptocurrencies."**

**_So, what are our options?_**

Cold hardware wallets, brain wallets, plate and paper wallets are the most common. I feel that "designed" techniques have earned the right to exist as well, but let's concentrate on the first one, which is a cold hardware wallet.

### To answer your questions beforehand…

*   [On Operational Security in Web3](https://0xrusowsky.substack.com/p/on-operational-security)
    

Let’s say we deal with a [Duress](https://play.google.com/store/apps/details?id=me.lucky.duress) tool. As such, it can be used _wrong_ (e.g. weak password), or used to do bad things (e.g., exfiltrate intellectual property).

> Check out: [Portable Secret](https://mprimi.github.io/portable-secret)

On the opposite, we can just use Steganography and a small paper, without even touching the computer. Both attitudes has the right to exist, in my honest opinion!

[https://officercia.mirror.xyz/8ecJG-s\_5E6J1t-h8gUNGqV3hbX8If-E5NnrFrOJHUA](https://officercia.mirror.xyz/8ecJG-s_5E6J1t-h8gUNGqV3hbX8If-E5NnrFrOJHUA)

> All of the above refers to the criticism of tools as such and their role in OpSec.

Secondly, regarding big lists. Japan was the first country to invent the work that we do now in the form of [SoKs](https://www.jsys.org/type_SoK/) or [Awesome GitHub lists](https://github.com/OffcierCia/ultimate-defi-research-base)! If anyone is still around, browsers used to be sort of a table or database of websites, many of which were quite…uninspiring.

> _I also really enjoy applying anthropology, particularly when it involves online phenomena._

«Antenna-websites» were created at that time. There, their authors gathered a variety of resources that were related by a common subject to make someone’s life easier! In some ways, the creators of Awesome Lists and [start.me](https://start.me) continue this idea now. And it's fantastically amazing!

Last but not least, everything you do is based on the outcomes you need to achieve! You should be able to select reliable and vetted sources instead of using all the tools and links. Through given routes, you ought to be able to construct your own journey!

Following that, I will tell you about the ways that I deem safe and recommend to my clients!

* * *

II - Cold Wallets
-----------------

I am often asked why in my recent articles: [about secure cryptocurrency storage](https://mirror.xyz/officercia.eth/GtKNkmRDR_hhCqrnSENjqfPDHHb0W1M2SVeXDp4swCQ), about an [attack on old-and-forgotten hard-drives](http://officercia.mirror.xyz/ewfV9-LBnKmgDeTap3FXZ--PNeDzabhQ_5kh1pkKD2A) and on [how hackers are caught](http://mirror.xyz/officercia.eth/WeAilwJ9V4GIVUkYa7WwBwV2II9dYwpdPTp3fNsPFjo)…

[https://officercia.mirror.xyz/VCUaozkvMw1CSaNm3VnafrDLX4dwEjDIQo6qSOIbO8o](https://officercia.mirror.xyz/VCUaozkvMw1CSaNm3VnafrDLX4dwEjDIQo6qSOIbO8o)

> _…in space_ [_no-one can_](https://www.brunel.ac.uk/news-and-events/news/articles/Confirmed-In-space-no-one-can-hear-you-scream) _hear you_ [_scream_](https://www.mentalfloss.com/article/24107/space-can-anyone-hear-you-scream)_…_

If you're using a PC as storage (Windows, Linux, etc.) it should 100% be offline/air-gapped and dedicated (not used for anything else). Paper and hardware wallets still exist for a reason though (most secure options for the majority of users)!

[https://officercia.mirror.xyz/\_nD1Rtxe1PplK-NQzIq9sl-KNtajQG0aKqYsV36RTjA](https://officercia.mirror.xyz/_nD1Rtxe1PplK-NQzIq9sl-KNtajQG0aKqYsV36RTjA)

But there will only be a couple of attempts. That's why I've never recommended popular solutions... Typically, if the device falls into someone's hands, you're screwed. They have different approaches, you can read more about them [here](https://www.kaspersky.com/blog/hardware-wallets-hacked/25315/amp/) and t[here](https://www.freecryptocoinstips.com/article/ledger-trezor-and-others-hack-allegations-are-baseless-lack-proof/amp), but the gist is basically the same. There's a great fresh [video on cold wallet hacking.](https://youtu.be/dT9y-KQbqi4)

> _Check out wallet rating:_ [_walletscrutiny.com_](http://walletscrutiny.com/)

If you own something like this [device](https://www.bitlox.com/pages/only-on-bitlox), it is unlikely that it will be possible to restore anything without his participation. Because there are all sorts of cool, bulletproof features.

Keep in mind that this is not a panacea and that you will be saved from s[ome attacks](https://twitter.com/officer_cia/status/1491920415387574275) [(2)](https://telegra.ph/Clipper-attacks-crypto-08-16) only by diligence and common sense!

> _Check out these rather interesting hardware wallets_ [_gridplus.io/products/grid-lattice1_](https://gridplus.io/products/grid-lattice1) _(_[_2_](https://blog.gridplus.io/run-your-own-lattice1-messaging-router-in-1-click-using-dappnode-833235ec788e)_) & this BitLox_ [_device_](https://www.bitlox.com/pages/only-on-bitlox)_. Keep in mind a good way to hedge against physical attacks on hardware wallets - use BIP39 pass-phrases, because they do not get stored on the device!_

In essence, cold wallet is just a pseudo-[AirGap](https://airgapcomputer.com/) system (100% AirGap is impossible to achieve on Earth by definition, that's why [CubeSat](https://www.cubesat.org/) topic is so interesting) and it can be [cracked](https://github.com/jlopp/physical-bitcoin-attacks/blob/master/README.md).

And you can make a cold wallet out of a regular phone, for example via [airgap.it](http://airgap.it/) - there will be almost no difference from popular models!

> [A new attack is going on right now](https://t.me/officer_cia/694) - it looks like a dusting attack, while this is a phishing scam! Seen at BTC, ETH, BSC, TRX blockchains already.

### Check out:

*   [github.com/starius/logic-bomb/blob/master/logic\_bomb.c](http://github.com/starius/logic-bomb/blob/master/logic_bomb.c)
    
*   [play.google.com/store/apps/details?id=me.lucky.duress](http://play.google.com/store/apps/details?id=me.lucky.duress)
    
*   [mprimi.github.io/portable-secret](http://mprimi.github.io/portable-secret)
    

> I highly recommend to purchase a hardware wallet directly from the manufacturer's website rather than online retailers like Amazon or eBay. It is also advised to use an alternative email address or a virtual office to protect your personal information in case of a data leak. I also don’t like trusting hardware. Therefore, we all [should have physical ciphers!](https://derekbabb.github.io/CyberSecurity/Classic_Cryptography/Physical_Ciphers.html) Once again, study [Steganography](https://officercia.mirror.xyz/8ecJG-s_5E6J1t-h8gUNGqV3hbX8If-E5NnrFrOJHUA)! [Check out physical cryptography as well!](https://eprint.iacr.org/2019/1235.pdf)

Needless to say, with the increase in physical attacks, it is very important to take this into account?

[

physical-bitcoin-attacks/README.md at master · jlopp/physical-bitcoin-attacks
-----------------------------------------------------------------------------

A list of known attacks against Bitcoin / crypto asset owning entities that occurred in meatspace. - physical-bitcoin-attacks/README.md at master · jlopp/physical-bitcoin-attacks

https://github.com

![](https://storage.googleapis.com/papyrus_images/82dc2b7e4a5983224b568cd589c40a97c2d9b642a03401099ba92ac9a7043662.png)

](https://github.com/jlopp/physical-bitcoin-attacks/blob/master/README.md)

* * *

III - Brain Wallet
------------------

It is often chosen because it is easier to remember than the seed or the private key, it is easier to put there some poem that you made up. Or make up your own seed out of the nicknames of all the pets you've had in your life.

[

GitHub - metamarcdw/nowallet: This project is a secure Bitcoin brainwallet app written in Python.
-------------------------------------------------------------------------------------------------

This project is a secure Bitcoin brainwallet app written in Python. - metamarcdw/nowallet

https://github.com

![](https://storage.googleapis.com/papyrus_images/20823754d348e87b52f8a99a8eb93d80008428818f649b8ae09f01f0888cebff.png)

](https://github.com/metamarcdw/nowallet)

> _BrainWallets are basically instantly crackable since the range is tiny_ [_github.com/ryancdotorg/brainflayer_](http://github.com/ryancdotorg/brainflayer)

But the problem was that people didn't want to be creative and just took some lyrics from songs or simple words like "Bitcoin"... But there are dozens of bots with huge tables, where all these options are already turned into private keys and public keys and **mem-pool** is constantly monitored in case one of these wallets is refilled.

*   [badkeys.info](http://badkeys.info/) 
    
*   [playxo.com](http://playxo.com/)
    
*   [keys.lol](http://keys.lol/)
    

At the same time, in my opinion, we should not bury this technology - we just need to collect such a wallet, using natural Entropy, for example, weather data or atmospheric noise to determine words from the dictionary, but that is another issue. With all said, this technology looks old in 2022!

**Also:**

*   [Brainflayer: The Best Brainwallet Cracking Tool - ForkNerds](https://www.forknerds.com/brainflayer-crack-bitcoin-and-ethereum-private-keys/)
    
*   [Cracking BrainWallets No.1](https://tylermoore.utulsa.edu/fc16.pdf)
    
*   [Cracking BrainWallets No.2](https://rya.nc/files/cracking_cryptocurrency_brainwallets.pdf)
    

### Offline Seed Generation

The most important thing is to realize what you are doing and why. And try to use the basic functions that are built in. Any blockchain client has them and has made them available. **That’s why - secure blockchain address generation must be preformed via a full node only! Or at least - light client / node.**

You can try **using a calculator** even!

[

Generating a Seed Phrase using a Calculator.
--------------------------------------------

Using an offline calculator to generate a BIP39 seed phrase is one way to establish a very high level of confidence in the randomness and initial security of seed phrases - especially compared to the default wallet approach.

https://vault12.com

![](https://storage.googleapis.com/papyrus_images/ee9eaa03c448fa06cea0729bdc6edb83775a9515083bc60b4ca2c9827a833127.png)

](https://vault12.com/securemycrypto/cryptocurrency-security-how-to/calculator-seed-phrase-generator/)

Finally, [atmospheric noise has a natural Entropy](https://www.random.org/) so you can use its data as a N in function - if you decided to do it manually!

* * *

IV - Paper Wallet
-----------------

The most secure option would be to use a metal card or a "paper wallet."

It's also preferable to store a **private key rather than a seed phrase** on the paper wallet. In case you're wondering what the distinction is between a Private Key and a Seed Phrase. A private key grants access to a single address (account), whereas a seed phrase grants access to the entire wallet, which can contain multiple addresses and private keys.

In general, paper wallets are the most secure item you can imagine. When storing the private key, do not store the seed. [Different machines](https://github.com/OffcierCia/Crypto-OpSec-SelfGuard-RoadMap), separate [wallets](https://alphawallet.com), and correct [multi-sig](https://gnosis-safe.io)...

### Multi-Sig Best Practices & Attack Vectors:

*   [forum.openzeppelin.com/t/multi-signature-wallet-resources/5354](http://forum.openzeppelin.com/t/multi-signature-wallet-resources/5354)
    
*   [blog.gnosis.pm/how-to-securely-manage-company-crypto-funds-with-gnosis-safe-multisig-8b3f67485985](https://blog.gnosis.pm/how-to-securely-manage-company-crypto-funds-with-gnosis-safe-multisig-8b3f67485985)
    
*   [polygon.technology/blog/multsig-best-practices-to-maximize-transaction-security](https://polygon.technology/blog/multsig-best-practices-to-maximize-transaction-security)
    
*   [slowmist.medium.com/gnosis-safe-multisig-user-incident-analysis-9a270b8e1452](https://slowmist.medium.com/gnosis-safe-multisig-user-incident-analysis-9a270b8e1452)
    

### Secure Private Key Management:

*   [info.townsendsecurity.com/definitive-guide-to-encryption-key-management-fundamentals](https://info.townsendsecurity.com/definitive-guide-to-encryption-key-management-fundamentals)
    
*   [github.com/slowmist/Blockchain-dark-forest-selfguard-handbook](https://github.com/slowmist/Blockchain-dark-forest-selfguard-handbook)
    
*   [KeePass](https://keepass.info/) or [KeePassX](https://www.keepassx.org/) or [KeePassXC](https://keepassxc.org/) or [BitWarden](https://bitwarden.com/) or [KeePassDX](https://www.keepassdx.com)
    
*   [KeePass](https://keepass.info/) or [KeePassDX](https://www.keepassdx.com/) or [KeePassXC](https://keepassxc.org/) or BitWarden are good options. I also found [this tutorial](https://forums.linuxmint.com/viewtopic.php?f=42&t=291093) for [integrity check](https://keepass.info/integrity.html) (and other checks) very helpful, be sure to check it out as well: [link](https://forums.linuxmint.com/viewtopic.php?f=42&t=291093).
    

Would also suggest key segregation and key cycling as well. Meaning, don't use the same keys as your hot wallets for multi-sig management, and don't use the same keys forever.

[https://book.cyberyozh.com/veracrypt-veracrypt-vs-truecrypt/](https://book.cyberyozh.com/veracrypt-veracrypt-vs-truecrypt/)

Get in the habit of maybe quarterly or yearly audits of these keys (and their backups) because it's surprisingly easy to lose track of them!

You should RSA-encrypt it or use [Steganography](https://officercia.mirror.xyz/8ecJG-s_5E6J1t-h8gUNGqV3hbX8If-E5NnrFrOJHUA), also hide it like pirates hide treasures. [You can read about it here!](https://www.worldcat.org/title/pirate-hunter-the-true-story-of-captain-kidd/oclc/49801386&referer=brief_results) I also want to remind you about one scam service, which nevertheless occupies the first position in the Google search for "paper wallet generator" and even "paper wallet generator".

> Check out: [Portable Secret](https://mprimi.github.io/portable-secret)!

[

GitHub - kaushalmeena/digi-cloak: A web app that hides secrets in plain sight securely in images with the help of AES encryption and LSB steganography technique.
-----------------------------------------------------------------------------------------------------------------------------------------------------------------

A web app that hides secrets in plain sight securely in images with the help of AES encryption and LSB steganography technique. - kaushalmeena/digi-cloak

https://github.com

![](https://storage.googleapis.com/papyrus_images/b15760f9db2f9db050df48575efee33cd40a04a2516f2efe1ccb28f159a38888.png)

](https://github.com/kaushalmeena/digi-cloak)

The name is not printed intentionally, just look at the screenshot!

In any case, any such service has only one goal - to steal your cryptocurrencies by giving you pre-generated key pairs from the service owner:

![](https://storage.googleapis.com/papyrus_images/8d12a2075ac687c4acd7a1450c5d951d159829adba8873dfda27aaf5ccb4b0f6.jpg)

As a result, never utilize an online service to generate private keys.

**Only Bitcoin Core and** [**Electrum**](https://electrum.org/#home) **can be trusted if they were downloaded from an approved source.** And that condition might alter at any time: someone could hack the core engineers' GitHub accounts or simply pay them for a "damaging" commit. For **Ethereum**, you can check out something like [this script](https://www.quicknode.com/guides/web3-sdks/how-to-generate-a-new-ethereum-address-in-javascript).

> The seed phrases designed in BIP39 by [@Trezor](https://twitter.com/Trezor) are pretty awesome. **Passphrase** is like a password for your seed, meaning that even if your seed gets shot on camera, the wallet that will be created from it wont contain your bitcoin (it can some decoy amount tho). You will then have to enter also passphrase and recover from this!

Also, [bitcoincore.org](https://bitcoincore.org) is the **official** website of the Bitcoin Core project while [bitcoin.org](https://bitcoin.org) is a separate website and project which aims to provide general information about Bitcoin! Keep that in mind!

[

Security and Privacy Encylopedia
--------------------------------

Security and Privacy Encylopedia

https://bitcointalk.org

![](https://storage.googleapis.com/papyrus_images/de5bbfee13e621b708ce676a60cf7334e882ccf91bf701a4a6d647b15dc2ff06.png)

](https://bitcointalk.org/index.php?topic=5239098.0)

Last but not least, there is such a thing as hierarchical determination (**HD**) in the settings of some wallets.

It sounds scary, but it means that every time you get money to an address, a new clean address will be generated from the seed (a private key is = 1 address, but a seed phrase is infinite private keys). And you can accidentally send money to an already inactive wallet.

**It is better to turn this function off (if it will be enabled), because it is easy to get confused with it.**

Lastly, here is my special compilation of four crypto services aimed to help you when you are already a dead man:

*   [safient.io](https://t.co/neLlDhZLFG)
    
*   [sarcophagus.io](https://t.co/3M6juYXEB7)
    
*   [safehaven.io](https://t.co/wxkBDnEooe)
    
*   [killcord.io](https://t.co/GxQxREoHta)
    

Check out [this article](https://steemit.com/death/@jonklinger/be-prepared-how-to-manage-your-digital-assets-when-you-re-gone) for more info on this sensitive topic!

* * *

V - What's for EVM-based Blockchains?
-------------------------------------

For **Ethereum**, you can check out something like [this script](https://www.quicknode.com/guides/web3-sdks/how-to-generate-a-new-ethereum-address-in-javascript) or a [full node](https://ethereum.org/en/developers/docs/nodes-and-clients/) (preferred)! In any case, the variations will be insignificant if we are talking about the level of [protection](https://t.me/Rekt_HQ/66747) that we have specified in the article. [Keep in mind BGP-level](https://www.theverge.com/2018/4/24/17275982/myetherwallet-hack-bgp-dns-hijacking-stolen-ethereum) attacks as well!

### You can also use something like:

[

Release 0.5.4 · iancoleman/bip39
--------------------------------

Add Particl network Add Divi network Add option to turn autocompute on / off Add option to set custom number of pbkdf2 rounds Fix blank mnemonic errors when using only seed -----BEGIN PGP SIGNED M...

https://github.com



](https://github.com/iancoleman/bip39/releases/tag/0.5.4)

The main difference is that hot or "operational" Ethereum wallets must adhere to stricter security guidelines, as I detailed in my [blog](https://officercia.mirror.xyz/)!

However, if we have the amount of money we need to store on hand and it is in tokens, NFTs or ETH, or for example in BSC, Avalanche, or Polygon - the differences with the ones [outlined](https://n00bzunit3d.xyz/blog/intro-to-web3-security) before in the **paper wallet** section will be minor.

It is important to say that cryptography and [natural entropy](http://mudit.blog/wintermute-muted-in-crypto-winter) is a reliable protection. By no means try to make yourself some "[vanity](http://kyrianalex.substack.com/p/vanity-addresses)" address - [no matter](http://bitcointalk.org/index.php?topic=5076779.0) what [network](http://github.com/AngelTs/vanitygen-plusplus-ported-for-VS2019). You can use [Profanity2](http://github.com/1inch/profanity2), but don't [forget](https://coinsbench.com/profanity-clarifications-df3972c8c006) about the history with [Profanity1](http://telegra.ph/Profanity-Clarifications-09-16), let me remind you [about it.](http://blog.1inch.io/a-vulnerability-disclosed-in-profanity-an-ethereum-vanity-address-tool-68ed7455fc8c)

You can even use your cat’s Entropy! 🐈

![proofof.cat](https://storage.googleapis.com/papyrus_images/d493a01eeaef6d429d5f8a242292ce8103f12bb07dc4827e168813866bf11336.jpg)

proofof.cat

If you go for a larger form factor, you could use QR code swapping for the ultimate air-gap solution, but keep in mind:

[https://officercia.mirror.xyz/aN6giRkUsNd0o0bmjZVeZb2htkO\_Ve16gMsARU6RBfM](https://officercia.mirror.xyz/aN6giRkUsNd0o0bmjZVeZb2htkO_Ve16gMsARU6RBfM)

If you are looking for something web3 or GameFi-specific like a [EVM (or Non-EVM) smart-contract wallet](http://blog.makerdao.com/what-are-smart-contract-wallets-and-how-can-they-benefit-defi-users/), check out [frame](https://ethereum.stackexchange.com/questions/73982/alternatives-to-metamask) or [Argent.xyz](https://Argent.xyz) and some web3-ethos aligned non-custodial wallets.

Remember that an average smart wallet is an Ethereum wallet that is governed by a smart contract rather than a private key. At the same time, many multi-cig solutions are inherently such wallets. Account abstraction is one of their key features, so make sure to double-check everything on their website!

### Wallets review:

*   [walletcompare.xyz](https://walletcompare.xyz/)
    
*   [walletscrutiny.com](https://walletscrutiny.com/)
    

![](https://storage.googleapis.com/papyrus_images/ebcba0df6aa6e9a7a4a75f13d69abb06896e05c301c376cbfaa8de957d38d80d.jpg)

To summarize, I **do not recommend** adopting smart-wallet or smart contract wallet techniques for cold storage.

> If you use a wallet for cold storage, never import the seed phrase into hot wallets!

[Metamask](https://metamask.io) (alternatives: [myetherwallet.com](http://myetherwallet.com), [frame.sh](https://frame.sh/), [alphawallet](https://alphawallet.com/) and [this](https://ethereum.stackexchange.com/questions/73982/alternatives-to-metamask) list), which is a non-custodial wallet, combined with [Airgap.it](https://Airgap.it) would be a way better solution! Here is a [nice](https://twitter.com/metamask/status/1494742718425223169) manual on this topic. Check out [this guide](https://metamask.zendesk.com/hc/en-us/articles/5450173968283-User-Guide-How-to-use-a-Hardware-Wallet) as well!

### OpSec for NFT artists:

*   [graph.org/NFT-security-01-28](http://graph.org/NFT-security-01-28)
    
*   [graph.org/All-known-smart-contract-side-and-user-side-attacks-and-vulnerabilities-in-Web30--DeFi-03-31](http://graph.org/All-known-smart-contract-side-and-user-side-attacks-and-vulnerabilities-in-Web30--DeFi-03-31)
    
*   [officercia.mirror.xyz/Y3xDO0XlAvIzJBwNhFZnvPWLiztWxIp1KHqg-B0kKxI](https://officercia.mirror.xyz/Y3xDO0XlAvIzJBwNhFZnvPWLiztWxIp1KHqg-B0kKxI)
    

### Don’t forget to set up a secure RPC provider!

*   [securerpc.com](https://securerpc.com)
    
*   [www-securerpc.netlify.app](https://www-securerpc.netlify.app)
    
*   [zmok.io](http://zmok.io)
    
*   [chainlist.org](http://chainlist.org)
    

Check out [this manual](https://docs.llama.fi/chainlist/how-to-change-ethereums-rpc) for a MetaMask wallet. Always use a reliable VPN provider - [mullvad.net](https://mullvad.net) is a perfect choice!

*   Forked MetaMask: [github.com/0xngmi/metamask-extension/tree/Version-v10.22.23](http://github.com/0xngmi/metamask-extension/tree/Version-v10.22.23)
    

> It is important to mention that the issue with using any third-party RPC provider with MM is that there was no option to remove the default Infura provider for Ethereum main-net so your set of addresses would still get sent to the default Infura RPC. [Thread by 0xngmi that explains the leak! Check it out](https://twitter.com/0xngmi/status/1601750220051984385)!

I am also not asking you to comply with all of this, but you must remember the main rule in this particular case:

*   [Your level of OpSec usually depends on your threat model and which adversary you're up against. So it's hard to define how good your OpSec is.](https://github.com/OffcierCia/Crypto-OpSec-SelfGuard-RoadMap?ref=hackernoon.com#problem-21)
    

If we finally want to give people the opportunity to be their own bank, we must realize that in this case, people must be able to replace all those services and actions for which traditional banks get money.

Yes, it seems like it is a veritable minefield over there. Keep the faith. Learn the latest attack techniques, [white hat cheat sheets](https://telegra.ph/All-known-smart-contract-side-and-user-side-attacks-and-vulnerabilities-in-Web30--DeFi-03-31?ref=hackernoon.com), and [defenses](http://mirror.xyz/officercia.eth/GtKNkmRDR_hhCqrnSENjqfPDHHb0W1M2SVeXDp4swCQ?ref=hackernoon.com).

*   [**OpSec Guide (Simplified)**](https://github.com/OffcierCia/Crypto-OpSec-SelfGuard-RoadMap)
    

Only knowledge can defeat criminal**_s’_** knowledge. In this intellectual boxing match the most prepared wins, and we want that to be you!

* * *

Support is **very** important to me, with it I can spend less time at work and do what I love - educating DeFi & Crypto users!

I don't have as much money as the fictional character in our essay, but your support helps me to exist 🙂

*   [Check out my GitHub](https://github.com/OffcierCia/)
    
*   [Follow my Twitter](https://twitter.com/officer_cia)
    
*   [Track all my activities](https://start.me/p/QRg5ad/officercia)
    
*   [All my Socials](https://linktr.ee/officercia)
    
*   [Join my TG channel](https://t.me/officer_cia)
    

If you want to support my work, you can send me a donation to the address:

*   [**0xB25C5E8fA1E53eEb9bE3421C59F6A66B786ED77A**](https://etherscan.io/address/0xB25C5E8fA1E53eEb9bE3421C59F6A66B786ED77A) or [officercia.eth](https://etherscan.io/enslookup-search?search=officercia.eth) — ETH, BSC, Polygon, Optimism, Zk, Fantom, etc
    
*   [**17Ydx9m7vrhnx4XjZPuGPMqrhw3sDviNTU**](https://blockchair.com/bitcoin/address/17Ydx9m7vrhnx4XjZPuGPMqrhw3sDviNTU) - BTC
    
*   **4AhpUrDtfVSWZMJcRMJkZoPwDSdVG6puYBE3ajQABQo6T533cVvx5vJRc5fX7sktJe67mXu1CcDmr7orn1CrGrqsT3ptfds - Monero XMR**
    

### Stay safe!

---

*Originally published on [Officer's Blog](https://paragraph.com/@officercia/the-only-safe-way-to-store-crypto)*
