Security Through Obscurity: The Window Has Closed

By: bitcoinblock.com.br|10/05/2026 20:00:00

Four things used to be true about being robbed because of your bitcoin. None of them are true today, and none will return. However, almost all the advice that bitcoin holders receive on how to protect themselves has been calibrated for the world in which they were true.

There Was a Time

Think about what needed to go right for you back then. Thus, a key-grip attack simply wouldn’t happen.

Most thieves had no idea what bitcoin was. It’s not that they underestimated it: they had never heard the word. In fact, the category of criminal capable of even forming the intention to steal a private key was minimal.

Those who knew would hardly cross paths with you, because there were few bitcoin holders around. Finding one by chance in the midst of a common robbery was a coincidence. Most of the time, that didn’t happen.

There’s also the condition that people forget, which is that they needed to know it was you. Finding a holder is not the same as identifying one. Moreover, without a way to separate holders from everyone else, knowing what bitcoin is does nothing for the thief. It’s a capability without a target.

And what if all three failed and someone really came after you? The most likely scenario is that you knew more than they did. The holder back then was typically a cypherpunk or cryptographer. They were people who had read the email list. The attacker, on the other hand, was typically an amateur with an improvised plan that week. The technical asymmetry tended to run in favor of the victim.

That was a real window, and inside it was genuinely safe.

Bitcoin Security: What Holders Face Now

The first two need no argument. Everyone knows what bitcoin is, and there are many bitcoin holders today.

The third is what really changed the game, and it gets its own section just below.

The fourth has completely reversed. Those who do this today are not improvising. The French prosecution, for example, has charged 88 people in about a dozen cases related to kidnapping and extortion. This is not a series of opportunists, but rather an organization, with prior recognition, division of labor, and recidivism. Meanwhile, the holder they are looking for is today, statistically, an ordinary person. This person bought bitcoin on an app. The cryptographer-versus-amateur confrontation has turned into something closer to its opposite.

The format of the attacks shows the same turn. In an industry count for the first half of 2026, reported home invasions rose from 1 to 20. This occurred in 52 incidents in the year-over-year comparison. The attack is moving to where people live. This is not the profile of an opportunistic crime.

Regarding counts in general, there are several series available on how many cases happen each year. They disagree with each other on the exact numbers. However, they entirely agree on the direction, which is a handful per year before 2017 and dozens per year now. I prefer to tell you this than to choose the most alarming number and present it as peaceful. The records are compiled from the press. Therefore, they miss everything that is not reported and over-represent what has made headlines.

The Target List is Now Public

For a thief to specifically aim at you, they need a list. It is the loss of this condition that has closed the window for good. For almost the entire history of bitcoin, there was no list. Now there are several, and you did not consent to any of them.

Intelligence reports on the wave of 2026 attribute victim selection to leaked databases, tax records, and exchange data. Additionally, there is internal sale of customer lists and recruitment on the dark web of employees with access to databases. Chain analysis comes on top of that. A decade of people publicly talking about what they have also comes on top of that.

What these things have in common is that they are records in the hands of third parties. You cannot audit them or revoke them. You cannot uncreate a record. You cannot unspill a leak. What the broker knows about you, it knows forever. Whoever one day obtains what it knows will also know.

This means that discretion has a rather unusual cost curve. The two halves run against you. The price of staying discreet accumulates each year that you hold on. It also accumulates with each counterparty you deal with. The benefit shrinks as the pile of already leaked records grows. This happens because your discretion is only worth something if no one has already published you. You pay more, every year, for something that is worth less, every year.

And if you declare taxes, the strategy isn’t even available. Where wealth or gain is declarable, "don’t leave a record" is not discretion, it’s a crime. Therefore, honest bitcoin holders are sent to hide by people who haven’t realized. These people haven’t realized that hiding is something the law does not allow them to do.

I have an entire text coming about the case of the French tax administration. This case puts this out of discussion. For now: the list exists, you are on it, and no one asked you.

-- Price

--
--
--

What kind of statement is this

A fair question at this point: how would you know if this were wrong?

You wouldn’t know, and I prefer to say this rather than sugarcoat.

It’s not a prediction you can falsify by counting. It’s a statement about structure. It deals with what people with these incentives, in light of these constraints, do. The cases and counts in this text are illustrations of the structure, not evidence of it. If the record showed half the attacks next year, not a single sentence above would become false. The incentives would be exactly what they are now.

This sounds like a weakness. There is a longer argument that it is not. There is also a much more uncomfortable argument about why, in this specific area, the evidence that would resolve the issue is systematically unavailable. Both come in a later text. For now, I just signal. This is because an argument that silently relies on data it cannot produce is doing something dishonest. I prefer to say this out loud.

The advice was inherited, not derived

The standard advice is to tell no one, deny if asked, and have a card to hand over. It is perfectly sensible for the world of those four conditions. In a world where almost no one is looking for you and no one can separate you from the crowd, staying quiet is almost a complete defense. This is because the attack generally never starts.

Only it was never derived from a threat model. It was inherited from a time, and that time is over.

After the window closes, it transforms into two separate problems. One is that it has ceased to be a mechanism. A defense whose entire strength is that the attacker does not know something is no defense at all once the attacker knows. In security engineering, this has a name, catalog number, and general agreement that it is a design flaw, until the asset in question is bitcoin. It’s the text after the next.

The other is worse. This is why I ended up writing academic papers about this instead of a list of tips. Under the conditions we actually live in, this advice not only fails to protect. It worsens the situation, during the attack and after it. This does not only affect those who followed the advice. This cannot fit in a post, and it’s where the real argument lies.

There is no version of this where the window reopens. The four conditions have gone in a direction that does not return. Knowledge does not unspread, and bitcoin holders do not become rare again. Furthermore, leaked lists do not un-leak, and organized crime does not forget a business model that works.

However, the good news, if it serves as consolation, is that a defense that never depended on the ignorance of the attacker does not care at all about any of this. Building one, it turns out, is possible. It’s just not what they are telling you to do.

The complete arguments are in two open-access articles: The Deadly Race. This article deals with what follows from the fact that you cannot prove that you forgot. The other is The Denial Spiral, which explains why the advice to hide and deny gets worse for everyone the more people follow it. Both are free and do not require registration.

The incident data comes from the public record of physical attacks by Jameson Lopp. This is a press sample, which loses everything that is not reported and over-represents what has made headlines. New cases that I find go into this record, not into my own database. This is because this information belongs to everyone, including whoever is next.

If this was worth your time. Send it to someone who still follows the old advice. This makes more difference than anything else here. A ? on the Great Wall, in the research or in these texts costs nothing. This makes the work be found. And if you want to fund it, support accepts ? Lightning and on-chain. There is no registration, no levels, and no counterpart whatsoever.

Free to read, translate, and republish. Each number comes from a source record of the press with a survival bias, coded by headline rather than measured. The actions overlap, and the share of fatalities is a floor. A number without its caveat is a mistake. The arguments are developed in The Deadly Race and The Denial Spiral, both open access. Source for this post: great-wall-posts. Self-custody audit · The course · Home


Disclaimer: The opinions, as well as all information shared in this price analysis or articles mentioning projects, are published in good faith. Readers should do their own research and diligence. Any action taken by the reader is detrimental to their account and risk. The Bitcoin Block will not be responsible for any direct or indirect loss or damage.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:[email protected]
VIP Program:[email protected]