Mistakes that self-custody does not forgive

You will be able to name the common self-custody errors and the habits that prevent them.

Darren decides to move part of his bitcoin from the exchange to a hardware wallet. He copies the receiving address from the wallet's app, pastes it into the exchange's withdrawal page, types in the amount and stops with his finger over the button, because if any character in that address is wrong, or he has picked the wrong option somewhere on the page, there is no bank to call afterwards. This lesson turns that pause into a routine.

Wrong address, wrong network

Lesson 1.1, Bitcoin is a shared ledger that nobody runs, made the point that a confirmed transaction cannot be reversed. In self-custody, that rule lands on you personally. Send coins to an address nobody controls, or to a stranger's address, and they are gone.

A wrong address is the obvious mistake. A wrong network is the one that catches experienced people. Many tokens exist on more than one blockchain. A dollar stablecoin, for example, may be offered on Ethereum and on several other networks, and an exchange's withdrawal page will ask you which one to use, often with address formats that look alike. If you withdraw on one network to a wallet or exchange that only watches another, the coins may arrive somewhere the receiver cannot see or reach. Sometimes they can be recovered with a lot of effort and the receiving firm's cooperation. Often they cannot.

The fix is to confirm, before you send, that the receiving wallet or exchange supports that exact token on that exact network. The deposit page or wallet app usually states it. If it does not, find out before you send anything.

Send a test amount first

The cheapest protection is also the dullest. Before moving a meaningful sum to an address for the first time, send a small amount, wait until it arrives and shows in the receiving wallet with the confirmations the receiver needs, and only then send the rest.

You will pay the network fee twice, which you learned to work out in lesson 1.4, Follow one transaction from wallet to block. That is the price of finding out cheaply whether the address, the network and the receiving setup all work. For Darren, moving S$1,500 of bitcoin, an extra fee of a few dollars is a small price for knowing the rest will land.

Check the address, not just the paste

Some malware watches your clipboard. When it sees you copy something that looks like a crypto address, it quietly swaps in an address belonging to the attacker. You paste, the result looks like a long jumble of characters just as the real one did, and you send your coins to a thief.

A related trick is sometimes called address poisoning. An attacker sends a tiny transaction to your wallet from an address designed to look like one you use often, with the same first and last few characters. Later, when you copy an address from your transaction history, you pick the attacker's lookalike by mistake.

The habit that defeats both is to check the pasted address against the source, character by character at the start and the end, and a few in the middle too. Do it on the device that will sign the transaction. A hardware wallet shows the address on its own screen for this reason, and that screen cannot be altered by malware on your computer. Never copy a destination address from your transaction history.

Read what you approve

The last trap applies when you use your wallet with smart contracts, the programs you met in lesson 2.1, Ethereum runs programs, and ether pays for them. Many applications ask you to sign an approval that lets their contract spend a particular token from your wallet. That is how a token swap or a lending deposit works. But an approval can be unlimited in amount and stays in place until you cancel it.

If you sign an approval for a malicious contract, perhaps on a fake version of a real site, or a site promoted through a link in a chat group, the contract can drain that token from your wallet whenever it likes, without asking you again. People have lost their whole wallet balance this way while believing they were claiming a free token or connecting to a game.

So read what your wallet asks you to sign. If it says the site may spend your tokens and you did not expect that, reject it. Keep the wallet you use with unfamiliar applications separate from the one where you hold most of your coins. Block explorers and some wallets let you see and cancel old approvals, and it is worth reviewing them now and then.

Darren's routine

After thinking it through, Darren wrote himself a routine for every transfer out of the exchange.

Confirm the receiving wallet supports this token on this network. Copy the address from the receiving wallet itself, never from history or a message. Check the first and last characters on the signing device's screen. Send a small test amount and wait until it arrives. Send the rest, then check the balance has landed.

It adds a few minutes to each transfer. Your own version may look different depending on what you hold and how you hold it, but the order matters: a test transfer only helps if it comes before the large one. Draft the steps you will follow, in the order you will follow them.

Write a five-step routine you will follow before sending any crypto, with a test transfer before the full amount.

Course

Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).