On this page
Back to: Security & Self-Custody Advanced
0
Objective: close the two non-crypto attack paths that drain the most real users: phone-number takeover and history poisoning.
Concept: SIM-swap
Attacker ports your number via carrier social engineering → intercepts SMS 2FA → resets email → resets exchange → withdraws. No malware, no blockchain exploit — pure telecom weakness.
Concept: address poisoning
Attacker sends dust from look-alike addresses (same first/last characters as your contacts) so your history-copy grabs *their* address next time. One lazy paste = full loss.
Hands-on lab (free)
- Carrier lockdown today: set account PIN, enable port-freeze/number-lock, remove SMS 2FA everywhere in favor of authenticator/hardware keys.
- Exchange lockdown: enable withdrawal allowlists + 48h anti-phishing codes; confirm no SMS recovery remains.
- Address-book hygiene: save real addresses as named contacts; never copy from transaction history; verify full strings on hardware screens for size.
Safety checklist
- SMS 2FA anywhere money-adjacent = remove this week.
- Treat unexpected micro-transactions as hostile reconnaissance, not gifts.
- Practice one full “lost phone” drill: how do you recover email, exchange, and wallet without the number?
Related glossary
Next lesson: multisig safe setup lab.
Course: Security & Self-Custody Advanced Lesson 3 of 5