Skip to content
Bitcointalk Academy

Wallet Security Recap

You already covered wallets in Bitcoin Fundamentals. This lesson focuses specifically on the wallet hygiene that protects forum-active members — people who receive BTC in many small chunks and transact with strangers regularly.

The forum-earner threat model

Distinct from a long-term HODLer's threat model:

  • More incoming transactions (campaigns, bounties, services)
  • More known counterparties (campaign managers can see your payment address)
  • More public exposure (your service threads may show payment addresses)
  • More privacy leakage surface (every income source links addresses)

The recommended setup

Earning wallet: A separate wallet used only to receive forum income. Hot wallet on a phone is fine; the balance is small + recent.

Sweeping wallet: Periodically (weekly or monthly) sweep the earning wallet's balance into a hardware wallet for long-term storage.

Cold storage: Hardware wallet (or multisig) for savings. Never touches the forum directly.

This pattern keeps the forum-exposed wallet small + low-stakes. Even if it's compromised, the loss is bounded.

SEC-06 · Academy explanatory diagram
Flow diagram: forum income enters a small hot earning wallet on a phone, which is swept regularly into a hardware wallet used as cold storage that never touches the forum.

Keep a small hot wallet for forum income and sweep it regularly to cold storage, so a compromised phone can only ever lose a week or two of payments.

Academy original

Address management

  • Generate a fresh receive address for every new campaign / client
  • Don't post your seed-generating xpub publicly (it leaks your entire balance history)
  • For service threads, list a static donation address separately from your primary earning address

Wallet software hygiene

  • Verify wallet binaries (covered in the blog post on wallet verification)
  • Update wallet software regularly
  • Don't import seeds across multiple wallet apps simultaneously
  • Don't use wallets that won't tell you their source code license + audits

Phishing-aware wallet UX

The most damaging wallet attacks now are interface-level:

  • Fake wallet apps that mimic real ones
  • Browser extensions that swap clipboard BTC addresses
  • "Recovery" prompts that ask for your seed in the wrong context

Defenses:

  • Install wallet apps only from official sources, verified
  • Never paste your seed into anything you didn't intentionally invoke
  • Cross-check the recipient address character-by-character before any meaningful send
SEC-08 · Academy explanatory diagram
Four-step flow for sending Bitcoin: copy the address, paste it into the wallet, compare it character by character on the signing device, and confirm through a second channel before sending — because clipboard malware can swap a pasted address.

The address shown on the signing device is the only one to trust: verify it character by character and reconfirm any change through a second channel before sending.

Academy original

Backup discipline

  • Seed phrase on metal, in two separated physical locations
  • Don't store seed digitally (no cloud, no screenshots, no password managers)
  • Test recovery once on a fresh wallet install BEFORE depositing significant amounts
  • Document any passphrase ("25th word") in a way the heirs of your estate could eventually find without making it easy for an attacker to find first
SEC-07 · Academy explanatory diagram
Two-column diagram of seed phrase storage: the do column lists metal backup, two separated locations, a test recovery, and a passphrase plan; the don't column lists cloud storage, screenshots, password managers, and sharing.

A seed phrase lives on metal in two separated physical places and nowhere digital — and the backup is only real once you have tested recovery from it.

Academy original

When to upgrade

Move from single-sig hot to single-sig hardware when balance > ~1 month's expenses.

Move from single-sig hardware to multisig when balance > ~6 months' expenses.

This isn't a rule, just a useful default. Costs of upgrade are paid in time + complexity; benefits are paid in catastrophic-loss avoidance.

SEC-09 · Academy explanatory diagram
Ladder diagram with three custody steps: a phone hot wallet for small balances, a single-sig hardware wallet once the balance passes about one month of expenses, and multisig once it passes about six months.

Custody should climb with the balance: hot wallet for pocket money, hardware wallet past about one month's expenses, multisig past about six — a default, not a rule.

Academy original

Quick knowledge check — this quiz needs JavaScript. The lesson above is complete without it.