Stop pretending technical and human vulnerabilities are separate things  

31 March 2025

Cointelegraph by Andrey Sergeenkov

  ​

Stop pretending technical and human vulnerabilities are separate things

Opinion by: Andrey Sergeenkov, researcher, analyst and writer

Crypto founders love big promises: decentralized finance, banking the unbanked and freedom from intermediaries. Then hacks happen. In some cases, billions vanish overnight. 

On Feb. 21, 2025, the North Korean Lazarus Group stole $1.46 billion from Bybit. They sent phishing emails to staff with cold wallet access. After compromising these accounts, they accessed Bybit’s interface and replaced the multisignature wallet contract with their malicious version. When Bybit attempted a routine transfer, the hackers redirected 499,000 Ether (ETH) to addresses they controlled.

This wasn’t just a human error. This was a design failure. A system that allows human factors to enable a billion-dollar theft isn’t innovative — it’s irresponsible.

People are not protected

In just 10 days, the hackers converted all 499,000 ETH into untraceable funds, using THORChain as their primary channel. The decentralized exchange processed a record $4.66 billion in swaps in a week but implemented no safeguards against suspicious activity.

The crypto industry has created a system that cannot protect users even after they discover a theft. Some services actually profited from this crime, collecting millions in fees while processing the laundering of stolen funds.

Recent: SafeWallet releases Bybit hack post-mortem report

In February 2025, investigators ZachXBT and Tanuki42 revealed that Coinbase users lost over $300 million annually to social engineering attacks. Their report showed $65 million stolen through phishing and other social manipulation techniques in December 2024 and January 2025. According to the investigators, Coinbase failed to address known security vulnerabilities in their API keys and verification systems that make these human-targeted attacks successful. 

ZachXBT directly criticized the exchange for having “useless customer support agents” and failing to properly report theft addresses to blockchain monitoring tools, making stolen funds harder to track. One scammer even admitted to targeting wealthy users, claiming they make at least five figures a week.

These aren’t isolated cases. The US Federal Bureau of Investigation reported that ordinary crypto users lost over $5.6 billion to fraud in 2023, and social engineering drove at least half of these schemes. Americans alone lose approximately $2 billion–$3 billion annually to human vulnerability attacks. With over 600 million crypto users worldwide, conservative estimates put individual losses from social engineering at $6 billion–$15 billion in 2024. 

Barrier to adoption

Security concerns are now recognized as the main barrier to adoption by 37% of crypto users worldwide. Meanwhile, the industry continues to promote high-risk speculative assets like memecoins, where average users typically lose money while insiders profit.

While founders pitch financial freedom, millions of real people lose their savings through vulnerabilities the industry refuses to address. They’re symptoms of a fundamental problem: Crypto builders choose marketing over security.

When disasters happen, and they face pressure about security failures, crypto leaders hide behind blockchain’s “code is law” principle and offer philosophical arguments about self-sovereignty and personal responsibility. The crypto industry loves to blame ordinary users: “Don’t store keys online,” “Check addresses before sending,” “Never open suspicious files.”

Nobody is safe

Even industry leaders themselves fall victim to the same basic attacks. In January 2024, Ripple co-founder Chris Larsen lost 283 million XRP (XRP) due to storing private keys in an online password manager. DeFiance Capital founder Arthur_0x lost $1.6 million in non-fungible tokens (NFTs) and cryptocurrency simply by opening a phishing PDF file. 

These people aren’t naive beginners — they’re creators and experts of the very system that could not protect even them. They know all the security rules, but the human factor is inevitable. If even the system architects lose millions, what chance do ordinary users have?

Knowledge of security rules doesn’t provide complete protection because fever, stress, sleep deprivation or emotional distress severely affect our decision-making abilities. Attackers continuously test different approaches, waiting for moments when users become vulnerable. They evolve their tactics constantly, creating increasingly convincing scenarios, impersonations and urgent situations. 

The unchangeable nature of blockchain transactions demands extraordinary safeguards — not fewer. If users can’t reverse mistakes or thefts, the system must prevent them in the first place. True innovation means building systems that work for real humans, not theoretically perfect users. Banks learned this lesson over centuries. Crypto builders must learn it faster.

Instead, industry leaders seem to have lost touch with reality due to the extreme wealth dumped on them quickly. They’ve bought into their PR narrative, portraying them as geniuses, and started viewing themselves as visionaries.

A call to action

Vitalik Buterin lectures his audience on voting in elections and polishes his manifesto, while Justin Sun spends $6.2 million on a banana for a “unique artistic experience” — all while building an environment that makes dangerous mistakes easy to make. This approach is fundamentally dishonest. You can’t claim to revolutionize finance while providing less security than the systems you’re replacing.

What technical brilliance exists in systems that permit billion-dollar thefts and systematic fraud of ordinary users with such ease? As a core function, true technical excellence would include protecting users from permanent financial loss. A financial system that cannot secure its users’ assets is not technically advanced — it’s fundamentally incomplete.

It’s time to stop writing manifestos and promoting questionable PR stunts designed to attract a broader and more vulnerable audience. Start building genuine protections that match the level of risk your users face. No amount of blockchain innovation matters if ordinary people cannot use these systems without fear of instant, permanent financial loss.

Anything less is just reckless experimentation at users’ expense disguised as a revolution — a scheme that enriches founders and insiders while ordinary people bear all the risks.

If the industry doesn’t solve this problem, regulators will — and you won’t like their solutions. Your philosophical arguments about self-sovereignty won’t matter when licenses are revoked and operations shut down.

This is the choice crypto builders face: Either create truly secure systems that justify your claims about financial innovation or watch as regulators transform your “revolutionary technology” into another heavily regulated financial service. The clock is ticking.

Opinion by: Andrey Sergeenkov, researcher, analyst and writer.

This article is for general information purposes and is not intended to be and should not be taken as legal or investment advice. The views, thoughts, and opinions expressed here are the author’s alone and do not necessarily reflect or represent the views and opinions of Cointelegraph.

 

You might also like

Satoshi Nakamoto turns 50 as Bitcoin becomes US reserve asset  
Satoshi Nakamoto turns 50 as Bitcoin becomes US reserve asset  

Satoshi Nakamoto, the pseudonymous creator of Bitcoin, marks their 50th birthday amid a year of rising institutional and geopolitical adoption of the world’s first cryptocurrency.The identity of Nakamoto remains one of the biggest mysteries in crypto, with speculation ranging from cryptographers like Adam Back and Nick Szabo to broader theories involving government intelligence agencies.While Nakamoto’s identity remains anonymous, the Bitcoin (BTC) creator is believed to have turned 50 on April 5 based on details shared in the past. According to archived data from his P2P Foundation profile, Nakamoto once claimed to be a 37-year-old man living in Japan and listed his birthdate as April 5, 1975.Source: Web.archive.orgNakamoto’s anonymity has played a vital role in maintaining the decentralized nature of the Bitcoin network, which has no central authority or leadership.The Bitcoin wallet associated with Nakamoto, which holds over 1 million BTC, has laid dormant for more than 16 years despite BTC rising from $0 to an all-time high above $109,000 in January.Satoshi Nakamoto statue in Lugano, Switzerland. Source: CointelegraphNakamoto’s 50th birthday comes nearly a month after US President Donald Trump signed an executive order creating a Strategic Bitcoin Reserve and a Digital Asset Stockpile, marking the first major step toward integrating Bitcoin into the US financial system.Related: Bitcoin at 16: From experiment to trillion-dollar assetNakamoto’s legacy: a “cornerstone of economic sovereignty”“At 50, Nakamoto’s legacy is no longer just code; it’s a cornerstone of economic sovereignty,” according to Anndy Lian, author and intergovernmental blockchain expert.“Bitcoin’s reserve status signals trust in its scarcity and resilience,” Lian told Cointelegraph, adding: “What’s fascinating is the timing. Fifty feels symbolic — half a century of life, mirrored by Bitcoin’s journey from a white paper to a trillion-dollar asset. Nakamoto’s vision of trustless, peer-to-peer money has outgrown its cypherpunk roots, entering the halls of power.”However, lingering questions about Nakamoto remain unanswered, including whether they still hold the keys to their wallet, which is “a fortune now tied to US policy,” Lian said.Related: Bitcoin’s next catalyst: End of $36T US debt ceiling suspensionIs Satoshi Nakamoto wealthier than Bill Gates?In February, Arkham Intelligence published findings that attribute 1.096 million BTC — then valued at more than $108 billion — to Nakamoto. That would place him above Microsoft co-founder Bill Gates on the global wealth rankings, according to data shared by Coinbase director Conor Grogan.Satoshi’s new addresses. Source: Conor GroganIf accurate, this would make Nakamoto the world’s 16th richest person.Despite the growing interest in Nakamoto’s identity and holdings, his early decision to remain anonymous and inactive has helped preserve Bitcoin’s decentralized ethos — a principle that continues to define the cryptocurrency to this day.Magazine: 10 crypto theories that missed as badly as ‘Peter Todd is Satoshi’

Wall Street’s one-day loss tops the entire crypto market cap  
Wall Street’s one-day loss tops the entire crypto market cap  

The United States stock market lost more in value over the April 4 trading day than the entire cryptocurrency market is worth, as fears over US President Donald Trump’s tariffs continue to ramp up.On April 4, the US stock market lost $3.25 trillion — around $570 billion more than the entire crypto market’s $2.68 trillion valuation at the time of publication.Nasdaq 100 is now “in a bear market”Among the Magnificent-7 stocks, Tesla (TSLA) led the losses on the day with a 10.42% drop, followed by Nvidia (NVDA) down 7.36% and Apple (AAPL) falling 7.29%, according to TradingView data.The significant decline across the board signals that the Nasdaq 100 is now “in a bear market” after falling 6% across the trading day, trading resource account The Kobeissi Letter said in an April 4 X post. This is the largest daily decline since March 16, 2020.”US stocks have now erased a massive -$11 TRILLION since February 19 with recession odds ABOVE 60%,” it added. The Kobessi Letter said Trump’s April 2 tariff announcement was “historic” and if the tariffs continue, a recession will be “impossible to avoid.”Source: Anthony ScaramucciOn April 2, Trump signed an executive order establishing reciprocal tariffs on trading partners and a 10% baseline tariff on all imports from all countries. Trump said the reciprocal tariffs will be roughly half the rate US trading partners impose on American goods.Related: Bitcoin bulls defend $80K support as ‘World War 3 of trade wars’ crushes US stocksMeanwhile, the crypto industry has pointed out that while the stock market continues to decline, Bitcoin (BTC) remains stronger than most expected.Crypto trader Plan Markus pointed out in an April 4 X post that while the entire stock market “is tanking,” Bitcoin is holding. Source: Jeff DormanEven some crypto skeptics have pointed out the contrast between Bitcoin’s performance and the US stock market during the recent period of macro uncertainty.Stock market commentator Dividend Hero told his 203,200 X followers that he has “hated on Bitcoin in the past, but seeing it not tank while the stock market does is very interesting to me.”Meanwhile, technical trader Urkel said Bitcoin “doesn’t appear to care one bit about tariff wars and markets tanking.” Bitcoin is trading at $83,749 at the time of publication, down 0.16% over the past seven days, according to CoinMarketCap data.Magazine: XRP win leaves Ripple a ‘bad actor’ with no crypto legal precedent set

SEC paints 'a distorted picture' of USD-stablecoin market — Crenshaw  
SEC paints 'a distorted picture' of USD-stablecoin market — Crenshaw  

US Securities and Exchange Commission (SEC) Commissioner and vocal crypto critic Caroline Crenshaw has accused the US regulator of downplaying risks and misrepresenting the US stablecoin market in its newly published guidelines.However, many in the crypto industry see the SEC’s decision as a step in the right direction.In an April 4 statement, Crenshaw, who is widely known for opposing the spot Bitcoin ETFs, said that the SEC’s statement on stablecoins contained “legal and factual errors that paint a distorted picture of the USD-stablecoin market that drastically understates its risks.”Crenshaw disagrees, crypto industry applaudsUnder the new SEC guidelines, stablecoins that meet certain criteria are now considered “non-securities” and are exempt from transaction reporting requirements. Crenshaw disputed the accuracy of the analysis made by the SEC in arriving at that decision. She pushed back on the SEC for reiterating issuer actions “that supposedly stabilize price, ensure redeemability, and otherwise reduce risk.”Source: David SacksThe SEC said that “albeit briefly, that some USD-stablecoins are available to retail purchasers only through an intermediary and not directly from the issuer.”Crenshaw argued this was misleading. She said:”It is the general rule, not the exception, that these coins are available to the retail public only through intermediaries who sell them on the secondary market, such as crypto trading platforms.””Over 90% of USD-stablecoins in circulation are distributed in this way,” Crenshaw added.Meanwhile, many in the crypto industry expressed optimism over the decision.Token Metrics founder Ian Ballina said it “feels like a clear step in focusing on what really matters in the crypto space.” Crypto industry says positive step, just lateVemanti CEO Tan Tran said he wished the SEC reached this point three years ago, while Midnight Network’s head of partnerships Ian Kane said it “feels like progress for crypto folks trying to play by the rules.”Crenshaw said it is “also grossly inaccurate” for the SEC to reassure users that an issuer can handle unlimited redemptions just because its reserves match or exceed the value of the supply.Related: Stablecoins’ in bull market’; Solana sputters: VanEck”The issuer’s overall financial health and solvency cannot be judged by the value of its reserve, which tells us nothing about its liabilities, risk from proprietary financial activities, and so forth,” Crenshaw said.She explained that stablecoins always carry some risk, particularly during market downturns.It comes only weeks after stablecoin issuer Tether was reportedly engaging with a Big Four accounting firm to audit its assets reserve and verify that its USDT stablecoin is backed at a 1:1 ratio.On March 22, Cointelegraph reported that Tether CEO Paolo Ardoino said the audit process would be more straightforward under pro-crypto US President Donald Trump.Magazine: XRP win leaves Ripple a ‘bad actor’ with no crypto legal precedent set

Open chat
1
BlockFo Chat
Hello 👋, How can we help you?
📱 When you've pressed the BlockFo button, we automatically transfer to WhatsApp 🔝🔐
🖥️ Or, if you use a PC or Mac, then we'll open a new window to load your desktop app.
BlockFo
BlockFo