the cryptocurrency nerds are rambling today about new psychotic best practices they expect every user to follow in the age of AI
this pisses me off to no end. i don’t understand why this industry chooses panic over empathy every single time
the threat is VERY REAL. but the solution is not to teach end users to become cryptography experts whenever a new threat appears (which will happen at least once per quarter from here on out)
the solution is to encourage end users to outsource asset security to trustworthy, proven third parties
ideally just use the ETFs. if not, use trustworthy custodians like Coinbase. if you ABSOLUTELY want to be a self-custody caveman while facing the threat of super intelligent adversaries, AT LEAST pay a 3rd party to implement best practices for you (like bitgo, casa, privy/fomo if you’re an “onchain” degen)
i tweeted about this months ago. enough with the technicalities that nobody understand. crypto users are no longer limited to 300 nerds on a mailing list. get people to safety and stop behaving like cavemen.
the idea of your bitcoin or crypto resting easy in some secret location while you enjoy life not worrying about it is currently unrealistic
it was somewhat realistic before. but the cost of cybersecurity attacks went down exponentially, and continues to go down exponentially on a monthly basis as new, more capable AI models are publicly released
what this means is that your cybersecurity must now be actively managed. it cannot be passive. someone must worry about your shit every day and every night, actively dismiss old assumptions and attempt new approaches on a weekly basis to adapt to a dynamic landscape of new threats
so your options are:
1. be the one who is worried. assess developing threats yourself on a daily/weekly basis, stay up to date with new models and tools as soon as they’re launched, analyze your own security practices ruthlessly day and night. for most people, including most experts, i think this is highly impractical. but you’re welcome to try
2. store your coins with a competent third party service that you trust to do the worrying for you. they should have the resources, skills and incentives to actively manage the cybersecurity risk for you. if you don’t want to worry yourself you need to pay someone else to be worried. it is what it is
i’m not trying to shit on self-custody. technically you can have someone professional actively worry about your self-custody setup, that’s fine too
one day, the threat level will plateau and will stop increasing exponentially on a monthly basis, and then passive security will gradually become acceptable. but today is not that day