# Are You Vitalik or Are You My Mom? An In Depth Analysis of Wallet Security Set-ups

- Channel: [ETHBerlin](https://streameth.org/ethberlin)
- Date: 2025-06-19
- Duration: 24:39
- Watch: https://streameth.org/watch/68553b0c90bd41297b45a0c1

## Description

An often overlooked element of securing your digital assets is determining how paranoid you should be. Many times users go down rabbit holes of complicated schemes to backup and protect their wallets which ultimately causes complications when they need to access them. However, there are situations where you may be in a position of power or public identification that you need to go deeper. Do you need to secure your assets like Vitalik does or like my Mom does?

## Transcript

Oh, hello. Hi everybody. All right. Oh, I got water. Thank you. I think I'm ready. Hi, everyone. I'm Hudson. I'm here today to ask the question, are you Vitalik or are you my mom? First, I should say I'm either my mother or Vitalik. I'm Hudson, currently at Polygon, worked at banks, worked at the Ethereum Foundation, and do a lot of stuff around security and privacy, and yeah, you can see my website for more info if you're interested in anything about me. So let's jump into what this is going to be about today. So what we're going to be going over is what OPSEC is, what a threat model is, and how paranoid you should be about having your cryptocurrency with you. This stuff is like invisible magic internet money, and you're hearing more and more about people getting kidnapped, about people losing their ledgers, or losing their wallet in a hard drive, and then it's in a dump somewhere, and they're trying to get it out. I think there was another talk that talked about that guy who was trying to get the city to help him excavate the dump just to find this hard drive with all this Bitcoin. So what should you be afraid of? What kind of things are you looking at? So operational security, or OPSEC, is one of the main kind of themes of today, which is identifying critical information, and then develop and implement protective measures to prevent that information from being exploited. So you might want to think to yourself some hypotheticals, some real true hypotheticals, like I'm a weakling. I should learn karate. I should fight my attackers. Will the criminals who are going to kidnap me look cute? Maybe I can win the MOGA romantically. Maybe if I cry a lot, they'll cry too and let me go. These are things that everybody who fears kidnapping has to come through and think about. When you're on an operational security mindset, it can kind of be very overwhelming to hear all these stories of people who did OPSEC incorrectly, who secured their wallets incorrectly, who lost money, lost their life savings or their whole life's wealth on cryptocurrency that was lost in a wallet or a hack. So yeah, like what if I pass away? What happens to my crypto? How will my family know what to do, etc.? So let's create a threat profile. What we're going to do is we're going to just go from the basics of creating a threat profile to make everyone feel more comfortable about where they feel like they stand for who's after them, who's not after them, what they should be worried about. So some people are more at risk than others, and a threat profile can determine who you're protecting against and how paranoid you should be. My mom does not have very much cryptocurrency on her laptop or phone, so she has to take different precautions than Vitalik Buterin, the co-founder of Ethereum, who is likely frequently targeted. So I developed a three-question quiz to figure out what level of paranoid you should be, what type of user you are in this situation to develop your threat model. Do you work in a highly visible role in a Web3 space? So like a community member who's talking about a project all the time and is known as one of the leaders in that project, an employee of a project, someone who's a thought leader in the space. Do you have a large amount of cryptocurrency? For the purposes of this, I'm going to say over $1,000 is a large amount. Maybe over $500 is a large amount. We'll talk about that a little bit later. But do you have what you would consider a large amount of cryptocurrency? And are you a signer for a multi-sig treasury on a crypto project? That would also make you potentially a target. Here's the results. If you answered yes to any of those questions, we're going to call you an advanced crypto user. If you answered no to all three, then you're a general crypto user. Let's go through two profiles. The first is Rhonda Jamison, my mom. That's recently from Mother's Day. She's a retired academic curriculum coordinator in Texas. Significantly less crypto wealth than Vitalik. She isn't a public figure until now. And she opens up her wallet a few times a year to check on it. But the only time I've seen my mom targeted for hacks or scams is getting emails that come from Coinbase, but they're actually not from Coinbase. They're there to send fake links and try to steal her money. And then we have Vitalik. Inventor of Ethereum. Significantly more crypto wealth than my mom. Very public figure, daily crypto user, and a target for advanced threat actors. So we're going to start with the general crypto user. That would be my mom. So on the low end, not targeted by advanced threat actors, but get a hardware wallet. If you have more than $500 in cryptocurrency or any amount of cryptocurrency that you would feel bad losing. I always like this. I really, really like this concept in gambling, which is don't gamble more than you're willing to lose. Because whenever I go to Las Vegas or do any kind of gambling activities, even DeFi related, I think to myself, you know, like this is fun money. I'm expecting this to go to zero immediately. Like this isn't even real to me. That's how I treat my hot wallet at home. Like if I were to wake up and I was hacked and my hot wallet was gone, I need to be comfortable knowing that I won't be kicking myself to a horrendous extent if someone hacks me. So ideally have a hot wallet and a cold wallet, both of them being hardware wallets if possible. Even if you're a general crypto user like my mom, unless you have just such a small amount you can throw a little bit on Coinbase and never look at it again, kind of a thing. Now an advanced crypto user is potentially targeted by advanced threat actors. So you definitely need a hardware wallet even for your hot wallet and day to day transactions. Your hot wallet should have very little crypto wealth on it and then you get a hardware wallet for your cold storage. So this is very similar to the general crypto user. The main difference is that you want to consider advanced wallet and recovery schemes, some of which I'm going to go over as examples in a little bit. And also keep your personal wallet separate from your multi-sig signing wallets. That's a mistake that we see a lot of the time and people get wrecked from having their multi-sig wallet that they use to sign for their projects or for like a security multi-sig for an L2 and then they like mix it up with their personal like hot wallet and then that hot wallet gets hacked because they, you know, join a Zoom call from someone who says that they're looking to hire you and you click on a link and it downloads scam software that then steals your key from MetaMask, et cetera. So before we go forward, I'm going to be talking about a lot of advanced stuff, but this is more for examples and kind of because I think it's really cool and really cool to talk about, but I really love the KISS principle that I see in software and other areas, which is keep it simple, stupid. Especially when you're thinking of things around inheritance, which we're not going to go into as deeply today, but if you were to get hit by a bus and then someone needs to recover your crypto, you don't want it to be impossible for them to go through like six different physical safes and, you know, all these different things and the instructions not written down. You want to be able to keep it simple enough and a hardware wallet really is the definition of that simplicity at any like basic level. Everyone should be using a hardware wallet. Now, here's an example of an advanced scheme, and I know some people who actually implement this for their recovery of their cold storage, their long-term cold storage. So it's Shamir's secret sharing scheme. So you split a wallet into M of N parts, so like two of three, and you have three people, that is the N, and if you get two parts, that's the M, together, you can put the wallet back together. So you can look at that picture to kind of see what I mean here. And someone has a Bitcoin wallet, like let's say seed phrase, let's say that they have a seed phrase that's 12 words. The first, they chop it into three parts, so that is three, four words, four words per part, and they give the part one and part three to the first person, part two and part three to the second, and part one and part two to the third. Now, only two of those people need to collude to get the key back together if you were to pass away. So you would ideally give it to someone you trust. You can also do this as a four of six, a 15 of 15, et cetera. Now this is the part where I'm also going to be going over some solutions and skipping MPC solutions. That's because MPC solutions are newer. They require a lot of cryptographic expertise a lot of the time to really understand what you're doing, and so that increases the attack surface and ability for a user to mess up. And again, we want to keep it simple, stupid. So I'm skipping MPC schemes. I will go into smart contract multi-sigs, which is another way that I think is a really good way to hit that medium if you're wanting to go a little bit more advanced than just the basic hardware wallet. So a multi-sig to require more than one signer to approve transactions before funds move. This is common on project treasuries. It used to be called Gnosis Safe. It is the main multi-sig that people use. It's now called Safe Wallet. And you can create your own with multiple hardware wallets to make it harder to compromise your cold storage. You can maybe make inheritance instructions and put little rules on there about how much can be withdrawn every day or every week, et cetera. I'm now going to go through some hardware devices that are going to be used for an example I'm doing at the end of the presentation. The first is the Grid Plus Lattice Hardware Wallet. This is a desktop hardware wallet. It sits on your desktop, and it has the ability to have multiple Ethereum and Bitcoin accounts, including your staking node, if you have an Ethereum staking node. They have a lot of really cool features I like. I use this as my day-to-day wallet. Inside of the actual machine is a security mesh. And if you're trying to open the Grid Plus, there is an electrical current going through the security mesh on the inside, and if it's interrupted by someone trying to open it, it actually deletes everything in the system. So even if someone grabs this from your desk and runs off, they can't really access anything, which is true of other hardware wallets as well, but I just haven't seen it done and implemented in such a way that is that advanced. Another cool thing is they have these backup safe cards that you can insert into here. I'm going to be using those to be giving to my family for backups, so if, like, I happen to pass away, my family can just take the safe card, plug it in, use the pin, and they don't have to know a lot about what's going on with the device. They can just have that little card with them. And that seems a little bit easier than having all these words on paper. It just feels nicer than having the words on paper that you're having to give your family members. The Ledger Nano X is a popular crypto wallet. Most people here probably know what a Ledger is, but for those who don't, it is a USB device that can be used to hold cryptocurrency. It has a secure chip inside of it, depending on which version of the Ledger you have. And it also now has Bluetooth capability. There's now ones with screens on them that are really nice to use. So the Ledger Nano X is one of the most widely used hardware wallets and one that I recommend a lot of people who are just getting started in crypto to use if they need a wallet, especially for portability. Lastly, there is a series of two apps on your phone called AirGap Vault and AirGap Wallet. So there is something called an AirGap machine that is – or how would you say it? You basically can AirGap a machine, which means you have a machine that is totally offline and is only used to sign transactions. So what this – I guess AirGap, I think, is the company has done is they've made an Android and iPhone app that you can have the AirGap Vault on, and that is the offline component. So once you install it, you put your phone in airplane mode and never connect to the internet again, and then you have the AirGap Wallet. So every time you need to do a transaction, you have to actually physically, like, scan a QR code from one phone to the other. That's the AirGap part. Basically, it doesn't touch the internet. That means hackers can't get to it. And then once it signs the transaction on the Vault phone, you can then do a scan to put it back to the wallet phone. So I thought it was a really neat idea. This has been a thing for years. Parity Technologies did an AirGap – an AirGap dApp – dApp and app solution years ago with MyCrypto that was the kind of de facto AirGap Ethereum case until we have this here. So for this talk, I did an example advanced setup scheme where I had a few different devices that I need to find in here. Oh, here. I wanted to kind of be like, in the case where I had, like, the absolute – if I was, like, really, really, really wanting to do, like, the biggest, like, the most advanced scheme I could that I could think of, what would I do? So what I did was a two of three multi-sig smart contract using GnosisSafe, using the safe wallet, and I used three hardware devices. So this is one of them. It is a used Pixel 8a purchased overseas at a really sketchy place on the side of the road with a bunch of used phones. I'll tell you in a second why I did it that way. And it's running GrapheneOS, which is a hardened Android operating system that, like, does a lot to help prevent, like, attackers from getting through weird, like, side channel attacks on an Android phone. And then AirGap Vault is on here. I have a GridPlus Lattice desktop hardware wallet at home, and then I have a fresh Ledger Nano X right here that I also labeled and have used for this experiment. So why did I set it up this way? So I wanted an AirGap wallet because I've never had one before, and I thought that was really cool. Why did I buy it at a sketchy location? Okay, there's something called supply chain attack. If you go to Amazon and you order a hardware wallet, if you're not ordering directly from the manufacturer, there's a chance that it can be intercepted midway through. And actually, no, I should take that back. Even if you are ordering from a manufacturer, depending on what country you're in and what the government's like, they could intercept the package. They could put, like, malware on it. An example would be the U.S. government, the Snowden files revealed that the U.S. government had intercepted Cisco routers that were, like, being shipped from around the world and putting malware on them and then repackaging them and sending them. Now, that's a very paranoid thing. Again, this is overkill for 99% of people, and I'm not even a target for this, but I wanted to do this because I thought it would be a lot of fun, and it actually was. So, I ended up finding a place that sold used phones, and I was like, there's no way that a supply chain attack would be able to predict that I would go to this place at this time and buy a used phone that I would then wipe. So, GridPlus has the security mesh, and I've been using that for a number of years. It's been great. I still need portability and usability, which is why if I was using – I'm not using this for anything, but if I was using this 2 of 3 multisig to sign treasury requests, I would still have the Ledger and the AirGap phone that I could use for – use to sign even if I'm, like, traveling. My GridPlus has to stay at home because it's, you know, like a desktop wallet. So, again, I'll just say one last time, this is overkill. I'm not saying to do this. I just – this was like an excuse for me to, like, live out my cypherpunk dreams of getting AirGap wallet devices from sketchy places and stuff like that, and it was a lot of fun. So, I talked a little bit about inheritance, but not deeply. The reason for that is I could go on an entire new presentation on crypto inheritance. That's something everybody seems to worry about nowadays for good reason. This book by Pamela Morgan, Crypto Asset Inheritance Planning, a Simple Guide for Owners, is one I highly recommend. I believe it's from 2018, so there's some stuff that is a little bit dated, but overall, it's a really, really good book to get your mind in the right place on what to do with crypto asset inheritance and making sure that, you know, even though you're trying to protect yourself from attackers and whatever your threat model says to protect yourself from, you still have, you know, your family and others who might need to recover your stuff in the event that you pass away. So, be always thinking about crypto inheritance. There are new tools coming out all the time that can help with that. And in general, not keeping it too complicated and being realistic about your threat model is really the biggest thing to take away today. Just have a good threat model. Don't overthink everything. Don't do what I did unless you're Vitalik or like someone actually important. And yeah, keep it simple. Thank you. I'll take questions now. Thank you, Hudson. We'll have to do Q&A. Again, if you have other questions, feel free to submit them and I'll put the nicest ones over here. So, the first one, account abstraction is now common and lots of wallets are starting to pop up that take advantage of it. For example, passkey-based wallets. What mechanism for recovery for the mainstream do you suggest here? I haven't dug into that enough to give an intelligent answer, but I would say it's very exciting. Definitely look into that. Passkeys are a very, very good thing and I think it's a good way to, along with other things like social recovery, are a good combination to have your crypto be recoverable in the event that you lose access to it for any reason. Yeah. How do you feel comfortable talking about your own security setup in public? Doesn't this concern you? So, I was looking at how many times I lied to you. Like, I counted because I thought someone was going to ask this question. So, I only lied, like, at least six or seven times to protect some of my stuff, but I will say security through obscurity is not great either. I don't feel yet that I'm an important enough target to actually, like, for this to matter, especially since you can read about all this yourself and the setup that I have, I am going to be recycling and doing something else with. So, it's like, I could have had all this in the first place. Very last thing I'll mention is I do live in Texas and gun laws are very permissible there. No one's going to walk into my house and get my shit. Spending limits. Why, DF, don't we have them yet? What's your opinion on spending limits? Oh, if you use, like, the safe wallet, there are spending limits you can set up even for a one of one. So, you can make a smart wallet and safe app or safe wallet and put a spending limit so you can put, like, a thousand Ether in there and then you can only spend up to 25 Ether a day. So, yeah, it's – there is that ability, but people don't seem to use it. I think it's just they're worried, like, what if they need to take all of it out really quickly. I think I got that question right. Okay. What's the secure rate to purchase a hardware wallet? The most secure way is directly from the manufacturer. If you go to Ledger's website, purchase from Ledger's website. If you go to Grid Plus's website, you can purchase from Grid Plus's website. I will – there are going to be some people in the audience who are like, but wait, didn't Ledger leak, like, everybody who purchased their shit? And yeah, that did happen once or twice or something. I forget. But I believe that they've fixed that, I hope, number one. And number two, with Grid Plus specifically, I can say that they have publicly come out to say that they do not retain customer records after purchase. So, they keep it just so long as – until, like, it basically hits your front porch and the package does, and then they delete the record. So, yeah, that is – that's what I would say about that. It's a tough thing because, you know, on where to trust – oh, I will say, though, if you do get, like, a Ledger and you order it online, go ahead and do a reset on it when you get it. Like, just go through and, like, go through all the default options or put in an old seed or, like, whatever seed you want, and then just do a reset on it. That way, like, just in case someone put a seed on there that they're expecting you to use, you won't be using that immediately, especially if you have to buy it used. But really, don't do that. I'll combine the second and third question. Oh, no, I don't see them. Okay, it's different here. Sorry. Is a zero-state emergency reset actually possible, or are experts able to recover my data? Is a – wait, say that again? Zero-state emergency reset. It's this one. I don't know what a zero-state emergency reset is, but I'm going to guess the definition, and if I'm right, I'm going to be super happy. I'm guessing a zero-state emergency is when you freak out and you zero out all of your electronics in your room. So as someone who worked for years doing, like, data recovery for a computer repair shop, yeah. Like, if you have an emergency where you're needing to clear all your shit, depending on how you clear it – so let's talk about hard drives for a second. When you clear a hard drive and delete it, or, like, let's say you reformat it or do the little format option, all that does is – the data is still on your hard drive. They just put a zero at the very beginning of it, so it says, from here on out, act like all of that is blank. And then as you use your hard drive, it overwrites it. So there is a chance that you can recover things if you do a normal format, if you do zeros and ones, delete of a hard drive. Now, if you use something like DBAN, which is Derek's BAN and NUKE ISO, like, startup disk, then, yeah, you, like, can absolutely wreck your drive enough that you will not be able to recover anything on that. But at the same time, I think that, yeah, for the most part, if you bring it to a professional, they'll be able to help you out for a lot of this stuff. It's crazy what they can do now to, like, take the platters out individually of hard drives and stuff like that. Maybe the last one and a quick one. Why Ledger over Trezor? Why Ledger over Trezor? That's the one that I am more used to. That's the one where I'm more familiar with the team. And Trezor, I feel like, has had more issues, like, if you're counting them, more issues than Ledger has with, once you get physical access, being able to quickly get the pin for a Trezor versus a Ledger. I've seen more attacks happen there. So I generally, just by default, steer more Ledger. But that doesn't mean that, like, Trezor's bad. I just don't feel intelligent enough to speak on it compared to Ledger and GridPlus and some of the ones I'm more familiar with. So don't take that as, like, a knock on any of the other ones, necessarily.
