# [How to Keep Your Cryptocurrency Safe](/content/blog/cryptocurrency-safe/index.html)

Throughout the history of cryptocurrencies, there have been several instances of cryptocurrency exchange hacks. Perhaps you may have even heard of some, such as the infamous Mt. Gox (which is actually an acronym for Magic: The Gathering Online eXchange). We intend to take a look at some of the prominent incidents, identify common patterns, and offer best practices for cryptocurrency traders.

**A Brief History of Cryptocurrency Hacks**

_August 2010, Bitcoin protocol hack_: In August 2010 a hacker exploited a bug in _Bitcoin_’s code, and was able to create a single block in the underlying blockchain with a transaction of 184 billion _Bitcoin_ s! _Bitcoin_ developer Jeff Garzik was able to identify it within a couple of hours. It took 3 hours to patch the bug and deploy a [hard fork](/content/blog/faq-blockchain-forks/index.html). No funds could be stolen.

_March 2014, Mt. Gox hack:_ Perhaps the most infamous of the cryptocurrency exchange hacks, Mt. Got was the largest exchange at the time. The hack was a result of substandard coding practices. The CEO of the _Mt. Gox_ exchange insisted that he be the only person to affect changes to the code. As a result, the code couldn’t be kept up to date with the ever-changing security requirements. Hackers made off with US $473 million worth of _Bitcoin_. The exchange was declared bankrupt after just a few months.

_January 2015, Bitstamp hack_: A ‘hot’ storage wallet, i.e. the kind of cryptocurrency wallets that reside on the central server of the exchange, was hacked, and US $5.1 million in _Bitcoin_ was stolen. This was because an administrator had fallen prey to a phishing attack, which is a form of cyber-attack involving the attacker duping the victim to part with sensitive information such as login credentials.

_June 2016 DAO hack:_ DAO, i.e. Decentralized Autonomous Organization, was an _Ethereum_-based exchange running on smart contracts. A community of coders wrote smart contracts to run the organization and an Initial Coin Offering (ICO) followed to raise necessary funds. With this, the community members could vote to decide which projects the organization would take. Unfortunately, the smart contract code had a weakness, and hackers stole US $3 million in _Ethers_, the digital currency of the Ethereum platform. To recover, the _Ethereum_ foundation implemented a hard fork ( [What is a fork?](/content/blog/faq-blockchain-forks/index.html)) to move the stolen funds to a new address. This divided the _Ethereum_ community into _Ethereum_ and _Ethereum Classic_ which issue two independent currencies today.

_August 2016, Bitfinex hack_: _Bitfinex_’s exchange provided users with multi-signature verification to protect the wallets. _Bitfinex_ partnered with _BitGo_, another major cryptocurrency company. In this arrangement, _Bitfinex_ would hold 2 of the 3 keys for every wallet and _BitGo_ would hold the other key. _Bitfinex’s intention to_ reduce usage of cold storage wallets, i.e. wallets that store the cryptocurrency offline, was a critical error. Hackers managed to make both _Bitfinex_ and _BitGo_ approve the withdrawals, and stole US $72 million in _Bitcoin_.

_July 2017, CoinDash hack:_ Hackers manipulated an address posted on _CoinDash_’s website informing ICO investors where to exchange _Ether_ for _CoinDash_ tokens. US $7 million worth of _Ether_ was stolen.

_January 2018, Coincheck hack:_ Cybercriminals hacked the Japanese cryptocurrency exchange _Coincheck_ and US $530 million worth of cryptocurrencies were stolen. In terms of monetary value, this is the largest cryptocurrency exchange hack thus far.

The above incidents demonstrate that those hacks were of centralized exchanges because funds were stored in hot wallets (wallets stored on the centralized server of the exchange). With only one database to target, the job of the hackers became much easier. Had the users stored their currencies in hard wallets, or had they used separate wallet services, they would likely have their funds today. **_Decentralization is key to the security of cryptocurrencies, and having a vast amount of sensitive information in one centralized server is a recipe for disaster._**

#### So, what can you do to protect your cryptocurrencies?

- **Be adequately prepared and knowledgeable**: If you aren’t reasonably tech-savvy, cryptocurrency trading is not for you. You don’t need to be a mathematical genius, but you should know the difference between hot wallets and cold storage wallets and be able to back up your computer regularly. You also need to be able to encrypt your data and identify good anti-virus solutions, at the minimum. If you aren’t up to par check out classes such as [Byte Academy.](/content/courses/index.html)
- **Backup your machine:** Have multiple backups, and offsite backup is non-negotiable. Get good external hard drives, including good USB drives.
- **Encrypt** your data, and use reliable encryption solutions for this.
- **Invest in cryptocurrency wallets**: We’ve seen how hackers exploited hot wallets, and by now you shouldn’t doubt the importance of cold storage wallets. Before you invest in cryptocurrencies, you need to have a core wallet, and you need to buy a stable one, with a company that is likely to remain in the market. This is because when you want to access your coins later, the wallet should still work with a new version of the operating system. Consider hardware wallets like _Nano Ledger_. Be sure to set a strong password for your wallet, and encrypt it.
- **Use mobile wallets** only for a very small amount of money.
- Consider having a **separate computer** for managing your cryptocurrencies, and invest in a _Linux_ system, running preferably on _VMWare_ Workstation. These are safer than average _Windows_ machines. If you must use _Windows_, use an administrator account only when you install important software, and then demote your access to the regular user. Malware can be installed on your windows machine only when the administrator account is being used, so use that privilege sparingly. Also, do not browse the internet using the machine for managing your cryptocurrencies.
- Invest in **powerful anti-virus software.**
- Use **two-factor authentication.**

In summary, while cryptocurrencies can “free” you from the control of central banks and associated middlemen, you really need to be that much more responsible for the security of your money. It’s imperative that you keep abreast of latest technological developments in the crypto and cyber-security spaces.
