Register and share your invite link to earn from video plays and referrals.

Nick Neuman
@Nneuman
Reinventing the Swiss bank for the sovereign individual | CEO & Cofounder of Casa @CasaHODL.
1.5K Following    13.5K Followers
There are 3 really simple things you can do to protect yourself against 90% of social engineering attempts. Most of these operations are casting a big net and just trying to scoop up unsuspecting fish. So make yourself a slightly harder target and they will pass right over you. 1. Don’t ever answer the phone for unknown numbers. Even when the location says Mountain View, CA, or the caller ID says Google. It’s fake! To ensure you don’t get tricked, set your phone setting to Silence unknown numbers automatically. On iPhone it’s Settings ➡️ Phone ➡️ Screen Unknown Callers ➡️ Silence (see screenshot). Many times, bad actors are using fear over the phone to get you to do things you shouldn't - like give them control of your email. 2. Add 2FA to your main email account, and make sure it uses a unique, strong password. Use either an authenticator app or a Yubikey (better) as your 2FA. ➡️ Security & sign-in ➡️ Turn on 2-step verification. Then make sure your password is a unique password that isn't used anywhere else. If you are using the same password in more than one place, it's highly likely that it's been leaked. Just go to put in your email address, and look at how many leaks its been in. 3. If you use Google Authenticator, turn off the cloud sync. When you have cloud sync on, if someone compromises your Google account, they can steal your 2FA. It makes 2FA ➡️ 1FA, and that is bad. These are the basics that you can do to protect yourself against a huge amount of social engineering. And then if you want extra protection for your BTC, check out the next post 👇
Show more
If you have BTC on a Ledger Nano S that you haven’t touched in years (because let’s be honest you’re avoiding it), take 30 min this weekend to make sure it works. We have seen so many ledger nano s screens die over the years. If yours is too dim to read, a hack we found is to try reading it through your phone camera. If that doesn’t work, try restoring your seed on a new device. If that doesn’t work, you can do a screen represent on the ledger with a bit of handiwork and a screen from Amazon. Don’t recommend updating firmware until confirming your seed works, for the reason below. And honestly you really don’t want to be in a position where you are restoring the seed for your single sig device hoping it works. That is just anxiety maxxing. This is why multisig is so important to reduce risk. If you have BTC on a ledger nano s, seriously consider moving it off soon to avoid this problem.
Show more
Tried using booting up old @Ledger for the 1st time in years to move btc to new multisig. Display completely fucked. Updated firmware - bricked. Tried recovering from seed words - checksum incorrect. Currently writing a script to try recover funds. If anyone has exp plz DM me.
Show more
Remember that zero BTC was lost from multisig setups in the Coldcard incident, whether they had a passphrase or not. A passphrase is not necessary in multisig. Adds complexity and a foot gun to your setup that actually makes it less resilient. Without a passphrase you just need the hardware wallet, with it you need both, and it’s a lot easier to lose a passphrase than hardware. Multiple keys gives you enough protection.
Show more
Remember that zero BTC was lost from multisig setups in the Coldcard incident, whether they had a passphrase or not. A passphrase is not necessary in multisig. Adds complexity and a foot gun to your setup that actually makes it less resilient. Without a passphrase you just need the hardware wallet, with it you need both, and it’s a lot easier to lose a passphrase than hardware. Multiple keys gives you enough protection.
Show more
If you're one of the many people who has signed up for a Casa free trial in the last few weeks and want help setting up your vault, join us here! Full walkthrough, just bring your hardware wallet.
Setting up a multi-vendor 3-key vault is easier with someone walking you through it live. Join the Casa team on Thursday, August 27 at 8:00am PT for a hands-on workshop where we will set up your first multi-vendor 3-key vault, step by step, with time for your questions along the way. Bring your own device to follow along in real time, or watch and set yours up afterward. Register free:
Show more
Setting up a multi-vendor 3-key vault is easier with someone walking you through it live. Join the Casa team on Thursday, August 27 at 8:00am PT for a hands-on workshop where we will set up your first multi-vendor 3-key vault, step by step, with time for your questions along the way. Bring your own device to follow along in real time, or watch and set yours up afterward. Register free:
Show more
Why does Casa store one key on your phone? It’s about defense in depth. I’ve personally seen the phone key save ~tens of millions of dollars for people who have messed up with their hardware keys.
Show more
Weigh an 8+ word passphrase and hand-rolled dice entropy against a 3-key vault. Multisig starts looking like the simpler setup. @stephanlivera and Casa's CEO @Nneuman break down why multisig's complexity reputation doesn't hold up.
Show more
If you’re wondering why bitcoin:native is up, here’s your answer
BREAKING: The US Treasury announces it will double the size long-term US government debt buybacks following the rapid surge in US Treasury yields. Repurchases of $2 billion will now be increased to "at least" $4 billion, the US Treasury said. The move is intended to provide "liquidity support" for bonds maturing in 10 to 30 years as total US debt nears $40 trillion. There is the intervention we have been calling for.
Show more
How to build a Casa multi-signature vault with two hardware wallets. - Setup 2 hardware wallets from scratch (preferably, different vendors) - Build a Casa vault using 3 keys - How to receive and send Bitcoin - Optionally: How to export wallet to Sparrow Wallet
Show more
I’ve spent some time looking into @CasaHODL, and I think Casa is one of the most interesting approaches to serious Bitcoin self-custody. Casa isn’t really a hardware wallet. It’s a Bitcoin multisig security service that lets you build a stronger setup around hardware you control. After digging into how it works, I understand the appeal. 🔐 2-of-3 multisig With Casa Standard, your Bitcoin can be protected by three separate keys: • a mobile key on your phone • a hardware key • a Casa Recovery Key Any 2 of the 3 are required to move your Bitcoin. That means Casa cannot move your Bitcoin by itself. Lose your phone or hardware device? You still have a recovery path. One compromised key isn’t enough to steal your Bitcoin. That’s the advantage of multisig. 🔑 You can even use a YubiKey Your hardware key doesn’t have to be a traditional Bitcoin hardware wallet. Casa supports YubiKey as a signing device. So your setup could be: • mobile key • YubiKey • Casa Recovery Key A YubiKey is simple compared with most hardware wallets. Plug it in, enter your PIN and sign. No complicated wallet interface. For someone who wants stronger Bitcoin security without adding complexity, that’s a very interesting option. 🧰 Advanced users get even more control You don’t have to keep the mobile key in your Bitcoin vault. Casa allows advanced users to replace it with a second hardware key. Your setup could then become: • hardware key #1# • hardware key #2# • Casa Recovery Key You’re not forced into one hardware manufacturer or security model. You can build a setup that matches your threat model. 🛟 Casa holds one key, but not your Bitcoin This is the part Bitcoiners will want to understand. Casa controls the Recovery Key, but only has one of the three keys. One key isn’t enough to move your Bitcoin. They still need a second signature from a key you control. So you get recovery without giving Casa unilateral control over your Bitcoin. 🕊️ What happens if Casa disappears? This was one of my biggest questions. If I’m securing Bitcoin I might hold for 10, 20 or 30 years, I don’t want access to depend on Casa still existing. Casa addresses this with Sovereign Recovery. You can recover your Bitcoin vault outside Casa using your wallet information and compatible open-source Bitcoin software. So your Bitcoin isn’t permanently trapped inside Casa’s app or infrastructure. For long-term self-custody, I consider that essential. 👨‍👩‍👧 Bitcoin inheritance Another feature that deserves more attention is inheritance. Securing your Bitcoin against theft is one problem. Making sure your family can recover it if something happens to you is another. Casa has inheritance functionality built around its self-custody architecture. For someone planning to hold Bitcoin for decades, that’s important. 💰 The biggest downside: $250 every year Casa Standard currently costs $250 per year. That’s not cheap, especially because multisig itself is open Bitcoin technology. An experienced Bitcoiner can build a multisig wallet without paying Casa an annual subscription. So you’re not really paying $250 for multisig. You’re paying for: • a much easier user experience • recovery infrastructure • key health checks • inheritance tools • support • guidance through the multisig process • protection against expensive human mistakes That’s where the value proposition becomes interesting. For a small amount of Bitcoin? I would struggle to justify $250 every year. For a serious long-term Bitcoin position? I can absolutely see the appeal. Self-custody sounds simple until losing a backup, forgetting a passphrase or making one stupid mistake could become financially devastating. Casa tries to reduce that risk without taking custody of your Bitcoin. And that leads to my biggest takeaway: Casa doesn’t remove responsibility from Bitcoin self-custody. It tries to remove some of the ways you can screw it up. I really like that philosophy
Show more
@iamdaveparker @CasaHODL I was using a Trezor as a simple single sig wallet. I set up CASA with the same Trezor/seed and can still simultaneously use the Trezor on its own like before (for day to day type use) and CASA for more security depending on what im trying to do.
Show more
Casa handles this for you so you don’t need to think about it for a microsecond
The main “complexity” with multi-signature is the descriptor file. In order to “build” your multi-sig vault, you need the public keys for each wallet involved in that multi-sig. Without the public keys, your wallet coordinator (like Sparrow) can not “access” your funds to build a spending transaction. So if you do a 2/3 multi-signature, you can lose a seed, but you CAN NOT lose the descriptor!
Show more
Turns out he lost the keys to $63B so it’s not quite the win you think it is Don’t be like Satoshi. Use multisig
Satoshi’s Bitcoin is just sitting there. Single-sig. Keys created on a computer connected to the internet. No fancy multisig setup. No elaborate custody architecture. 17 years later, no one has stolen them.
Show more
Casa has always tried to build our product to support a spectrum of needs between simplicity <> security. Want to go simpler and trust Casa more? You can do that with a yubikey as your signer which is literally two taps for all actions. Want to go more hardcore and trust Casa less? Remove the mobile key, use airgapped hardware wallets, roll dice, have a field day. Then we wrap all of that in a clear and straightforward app where you always know what is going on, and have support from a team of experts that are always in your corner. 8 years and counting - building for the long term.
Show more
Important to recognize the resilience that self custody adds to BTC as a network and an asset, as proven by the Coldcard incident.
Even if you had a quorum of Coldcards in your multisig (meaning the hackers COULD have stolen from your multisig) they still didn't do it successfully due to the effort involved in guessing the right combination of keys making up one wallet. Multisig = security & resilience++
Show more
one thing people aren't discussing enough in the wake of coldcard: not one satoshi is documented as being stolen from a multisig the future of self-custody is multisig, and i urge non-technical users who desire self-custody to look into collaborative multisig providers
Show more
What a mess. Unfortunately this Trezor address leak will directly lead to an increase in targeted social engineering and potentially wrench attacks. Here are my recommendations for what to do if you were in this breach (or just want to protect yourself against the result of these breaches in the future). Social engineering protection Scammers will use the combination of having your personal information to both target you (phone, email) and convince you that they are legit (using your name and potentially home address as proof that they know you and are here to help). They will contact you via phone or email with targeted lies meant to scare you into talking to them and taking the actions they want you to, in the name of protecting your bitcoin. Ignore any communication from "Trezor" that doesn't come from their official domains (the @Trezor handle, are the main ones I know of). You should also ignore communication from "Google" or "Apple" pretending like your email is compromised. They trick you into giving them your email credentials, and then once inside your inbox they can do all manner of things to trick you without Google's typical filters stopping them. Generally a company's support team will never call you on the phone without you contacting them. If they reach out proactively and are trying to get you to take any action to "remain safe" - refuse. Social engineers steal much more money on a regular basis than physical attackers. Most people worry about physical attack more because it sounds scarier, but the bigger risk of actual funds loss is social engineering. Get your suspicion antennae up. Phishing Phishing has a lot of overlap with social engineering. The main difference in my mind is that phishers put in less effort than social engineers. Social engineers may use phishing tools to help them. Phishers are just putting their nets out and trying to get you to make a mistake. Be very suspicious of emails directing you to go to Trezor's website or download a new Trezor app. Triple check the URL for Trezor or any hardware wallet website that you visit. Even if you Google Trezor, there are fake Trezor phishing apps running Google ads that will tell you to type in your seed phrase and then steal your money. Be very careful when downloading or using new wallet apps that you are getting the right one. Wrench attacks The one everyone worries about the most, even though it's the least common. Unfortunately since this breach includes physical addresses, it's possible we will see some wrench attack attempts come from it. Unless you are going to move, the best you can do is try to deter attackers and make sure that if it happens, they can't steal all your money. Distribute your keys and use a multisig to ensure that you don't have enough keys to spend bitcoin at your house. Then consider keeping a small-ish amount of BTC in a single sig wallet that you are willing to give up to make someone go away. We don't recommend the type of duress wallet that uses the same device/software as your main wallet, but when you type in a different PIN it brings up the fake wallet. It's too hard to remember the duress PIN when someone is beating you up, and too easy to give in when they ask you for more after you pay them from the duress wallet. You need to make it so you truly can't send them all your money. Casa recently built Guardian Mode to help protect against social engineering and wrench attacks. It requires the Casa key to sign for all transactions you send. We do a video verification call to make sure you are not being tricked or under duress before signing with our key. Available to Premium+ Casa members. You can also check out an old post we did about physical home security, which unfortunately we have to reshare every year or two: Very sorry to all the people who were caught up in this. Rough few weeks for bitcoin security. Reach out to us if you need assistance on any of these points.
Show more
The onchain metrics around the Coldcard incident reinforce how important self custody is to the resilience of Bitcoin as an asset class. In the couple of days around the hack: - 2.1k BTC was stolen - 22k moved to exchanges - 233k moved out of long term holder wallets in on chain transactions We at Casa know (based on actual customer conversations) some of the 233k was people moving from non-Coldcard single sig (ie Ledger, Trezor) to multisig wallets, because they realized single sig wasn’t secure enough for their needs. And other coins were moved from multisig->multisig as people removed Coldcard from their keyset. So somewhere between ~10x-100x the amount of bitcoin stolen was moved to safety as people sounded the alarm. This is a giant flashing neon sign showcasing the resilience that self custody adds to the network. If all that BTC was held at a custodian and the custodian was hacked instead, those numbers would have been flipped. A little bit might have gotten out the door to safety, and most would be stolen. As it was, the thieves had to crack one wallet at a time (and are still going), earning a little BTC each wallet, instead of cracking one wallet and getting a massive payday. And the asset price (and confidence) would have certainly taken a much bigger hit. Self custody is not just good for Bitcoiners, it is good for Bitcoin. H/t to @_Checkmatey_, @intangiblecoins, @SaniExp for the data
Show more
It sounds like Mk4, Q, and Mk5 are also vulnerable in a different way than Mk3. Slightly less problematic than Mk3 but still not great to keep using. If you're using single sig Coldcard at the moment you should move your assets to a different wallet (multisig, exchange, other HWW) to be safe.
Show more