Turning the page.
Bringing the next chapter into view…
From your first block to the finer details. Explore the ideas, people, and systems behind the market—one useful explanation at a time.
Follow a transaction from a key to a shared ledger.
Begin with BlockchainExplore contracts, liquidity, borrowing and the risks between them.
Begin with Smart contractUnderstand what a price, valuation or sentiment indicator can tell you.
Begin with Market capitalizationLearn custody, permissions and how to assess what you sign.
Begin with Hardware walletConnect the original ideas to the incidents that changed the industry.
Begin with A Cypherpunk's ManifestoSeparate technical standards, issuer claims and legal frameworks.
Begin with Howey testDusting your history with lookalike addresses so you copy the wrong recipient next time.
A signing device that never touches the internet, used with QR or SD transaction flows.
Addresses permitted to mint or trade early. Also a phishing lure word in fake mint sites.
A personal code shown in legitimate exchange emails so fakes are easier to spot.
Prefer limited allowances and periodic revokes over infinite approvals to every new dapp.
Miniscript and descriptor wallets that require several keys to spend.
An attacker who exploits for profit or disruption without disclosure.
Approving a hardware-wallet payload you cannot human-read. Prefer clear-signing when available.
Exploiting validators, contracts, or message verification on a cross-chain bridge. Historically the largest loss class.
The chance a cross-chain lock-and-mint system is hacked or halted, stranding or forging assets.
Paid responsible disclosure for vulnerabilities, often via Immunefi in crypto.
A small watch address used to detect unexpected movements early.
Backlogs during stress. A signal to watch solvency and your own custody choices.
An automatic pause when flows or losses exceed thresholds.
Showing human-readable transaction details on a secure screen before you approve.
Malware that replaces a copied address with an attacker address.
Mobile links that open wallet sheets with malicious payloads.
Multiple controls: audits, monitoring, limits, timelocks, and circuit breakers together.
Deceiving a user into authorizing account delegation to code that can exercise unintended control over the account.
Using a dedicated machine or phone for signing and a different one for browsing CT.
Tiny deposits used to track wallets or poison address histories.
Uniswap's signature-based allowance system that reduces some approval friction and introduces new signing surfaces.
Tricking you into signing a bad transaction or handing over a seed via fake sites, DMs, or ads.
The romance-investment scam pattern that funnels victims into fake crypto platforms.
Research and designs for association-set privacy that try to exclude known illicit funds.
Building a Bitcoin transaction on a hot machine and signing it on cold hardware.
Caps on how fast value can leave a protocol, buying time during exploits.
Fraudsters who claim they can recover hacked funds for an upfront fee.
A contract flaw where an external call re-enters before state updates, used in classic DeFi hacks.
Independent parties can rebuild the same binary from source, raising trust in wallet releases.
Removing a spender's allowance via Etherscan, Revoke.cash, or a wallet tool.
Long social engineering that ends in fake investment apps. A major fiat-to-crypto crime pattern.
Underlying collateral pledged twice off-chain while tokens still trade as if unique.
Dust tokens that lure you to a fake site to 'claim' or 'revoke'. Do not interact.
A multisig that can pause or upgrade an L2 in emergencies. A trust assumption to understand.
Any screenshot, cloud backup, or support scam that exposes the mnemonic. Funds are gone once it is used.
An NFT (and sometimes ERC-20) permission that lets an operator move every token you own in that contract.
Asking you to sign a typed-data message that grants operatorship or transfers assets.
Attackers port your phone number to intercept SMS 2FA. Use app or hardware 2FA for exchanges.
Guardians who can help rotate a smart-wallet key if you lose the primary device.
Compromising a dependency, CDN, or installer to reach many wallets at once.
A delay that lets users exit before a risky upgrade lands.
Permission for a contract to move your ERC-20 or NFT. Unlimited approvals are a common drain vector.
Wallet previews that estimate asset changes before you sign. Helpful, not perfect.
A second step beyond the password. App or hardware keys beat SMS for exchange security.
A malicious contract or site that requests sweeping approvals and empties tokens and NFTs.
The coordinated response channel when a protocol is under active exploit.
A security researcher who reports or sometimes rescues funds under safe-harbor norms.
Exchange feature that restricts withdrawals to pre-approved addresses.
Definitions offer a starting point. Detailed readings include the sources behind the explanation.