Transcription
One mistake. Your 3, 5, 10, 100, there, thousands of dollars simply dissolve. Neither the state nor anyone else will help you. >> The victim copies the address and sends about 10 or 15 million dollars. >> There are such teams, they will know that 25 years ago your dog died, where, what its name was. We lost 50,000 dollars because we kept private keys in an Excel table. >> There it is planet Earth, warm, cozy, and blockchain is space, where it's cold. And >> you are alone. This is the most terrible mistake that can be made with a script. When I send a significant amount, well, there always is. [music] Guys, for the third year now, we've been recommending a service that allows you to exchange your stablecoins clearly, safely, and simply. Creptus Exchange. And it's, you know, like your personal doctor, your personal plumber, a clear car service, clear institutions where you understand that you will come and receive a competently provided service without future headaches and risks. In such matters, not only the conditions are important, but also the work process, so that you can get a clear answer in advance about what will happen, why it will be appointed, and so on. Therefore, our subscribers have been choosing this service for the third year, where the process is built. Clear? And without unnecessary steps. The link to Cryptous Exchange will be in the description. Follow it, ask your questions, and clarify all available directions. Talk soon. >> It's not very pleasant to say this, but perhaps crypto will have to be buried for longer than expected. As a consequence, when people store something for a long time, they can forget where it is. I myself am guilty of this. I recently remembered that I have $5,000 worth of staked assets. I swear, I accidentally saw this tab in Google Chrome. Laziness, no accounting, and so on. And everything seems to need to be brought together in one place. Let's differentiate, you as a person who has already been through fire and water and flames with these wallets, [coughs] scams, lost seed phrases. A gradation of what a person should use for $1,000, $10,000, and $100,000 in assets. Well, if we're talking about capital, well, I usually say that everyone has their own understanding. I say, if you have a significant amount, it's advisable to switch to hardware wallets. And naturally, people ask: "What is significant? How much is it?" Yes, so everyone has their own definition. For some, $1,000 is a lot, for others, $100,000 is just pocket change. So, but conditionally, if it's around $1,000, $2,000, $3,000, I think you should start thinking about a hardware wallet above that. For amounts up to $1,000, up to two, up to three, we can generally use a hot wallet. And, well, of course, not a PC, but a smartphone, because there are significantly fewer attack vectors. On a regular computer, we have a lot of applications, games, office stuff, you know. Well, much better, >> no matter how smart you are, you go to torrent and download a movie. I >> Yes, definitely, definitely. And plus, if we're talking about browsers, there are a bunch of extensions, in general, many more risks. Therefore, if the amount is insignificant or approaching significant, then you can quite reasonably use a hot wallet on your smartphone. The only thing, of course, is that it should be as popular as possible. >> Uh-huh. Okay, before we move on to devices, I remember stories, yes, I remember before they used to send seed phrases in chats so that, guys, I left $1,000, a bot took something. Let's talk now about how people actually get scammed in crypto. It's like everyone knows everything, they've taken courses, a lot of videos have been made about hardware wallets, many >> hot wallets. They've become more user-friendly, right, not as clunky as MetaMask, right, how do people lose money, what do these people come with. Usually, usually now, probably the most popular story is when they share their seed phrase, but in reality, this has also moved into a format where the victim is very selectively chosen and worked on for a long time. In general, these are very complex attacks, when they try to understand what phrase it is through social engineering, right? But this is a very long warm-up, right, and an attack on the user. >> I'll add to that, sorry for interrupting. I was talking to a friend, he met a very high-ranking person, and this high-ranking person said: "Phones aren't like ours. They're at least button phones." And in general, the issue with incoming calls is technically very dangerous. He asks: "Well, why?" Well, they'll call, you'll hang up. He says: "No." When you pick up the phone and the person immediately starts talking in a voice, he says: "There are such teams, they will know that 25 years ago your dog died, where and what its name was. And there will be such social engineering that you will completely, you know, they will drive you into stress, into body temperature, that you will give them everything." Question: do you need it or not? >> Yes. Yes. Therefore, here is this type of attack, when you just went to a phishing site, enter your seed phrase, meaning we've moved away from that now, right? So, such attacks are carried out, well, as you said, very expensively, a specific victim, they understand how much money is there, and a serious attack. And there are many cases. And, well, what is happening very often now and has become so widespread is, well, you've probably noticed in your wallet history, right, some scam tokens, when you send Tron or USDT, they appear from similar addresses, right? I just released my last video and talked about this, where, roughly speaking, scammers, they infiltrate our wallet history, right? So they can infiltrate simply by sending money from a similar address to our wallet, right, in the hope that we will then go into the history, copy the address, and send. Or they infiltrate by sending from our wallet, right, here's a very important point, from our wallet they send a scam token. So such a transaction can appear for anyone at all. And this is in EVM networks. There is a special event, right, event logs, where they can do something like this, that it will look like you sent it, but it's a scam token. And this is how very, very many people are losing money now. And on Twitter, Slow Mist and other analytical companies publish many cases where, in the last case, I don't remember very well, I think it was $20 million, right, a person sent $100 test USDT. Following that, a scammer sends him $10 from a similar address, and the victim copies his address and sends about 10 or 15 million dollars. Imagine, so this person with a huge capital. He was scammed like this. And here, victims are chosen not only those with millions of dollars, but there's even a special aggregator site that analyzes all poisoning attacks, right, on addresses. There are $100, $500, $1,000, and so on, they don't care at all, right? So they have a mass attack character, they poison any movements in the blockchain. Based on your experience, if we take Russia, right, some circle, maybe without names, a case from the last 2 years that shocked you, maybe I don't know, well, a real example of how someone lost, maybe it was a stupid case. >> It was a very stupid case, truly outrageous. It wasn't Russia, it was China. A user, and the information about who this person was was not disclosed. But a person from China ordered a Ledger on a marketplace with a discount. The discount was about 30%. And they loaded several million dollars into it, and the money was gone. The attack was on the supply chain. So this wallet was already activated. There was, you know, a protective film attached. You peel it off, and there's the seed phrase and it says: "Enter PIN." A fake instruction. So, maybe it was a targeted attack. Although I doubt it, it's still a marketplace. And such a stupid scam, right? >> A supply chain attack, not on the hardware, but on the instruction, so they replaced it, so the person opens it, oh, they put instructions in the box. Yes. Yes. And a person who is not familiar with crypto at all, not familiar with the product they are going to use and on which they are going to load, I think, $10 million, so a huge amount. And such a person, they just loaded it, the money was gone, it caused a big resonance. Many companies immediately published it. I looked at this case. I just didn't believe it at first. I thought it was some kind of PR stunt, but it actually happened. And here, by the way, is a very important point. I just want to emphasize it because it's very important. If you are acquiring wallets, wherever you acquire them, especially on marketplaces, you still need to know how the device itself works, because a supply chain attack is something you can't protect against at all. So at any moment, when the store ships to the marketplace, for example, sorting centers, many warehouses, many people touch it, and neither the vendor nor the seller can control it. So at any moment, some substitution or introduction can occur. Well, if it's an official distributor, then technically it can happen, >> if, if, yes, the chance is smaller, but it can still happen, >> in short, as soon as it leaves production, right, from the manufacturer's warehouse, then that's it, the risk is there, >> it's there in any case. Therefore, the main protection here is that we just need to know what this product is, what it looks like, what it shows when you turn it on. Like, I don't know, we buy an iPhone, right, some product, we understand that it should display a welcome message, and if there's any strange behavior, a flag goes up, and we can immediately take action. Regarding exchanges, I've noticed myself, we often say this. Don't keep money on exchanges, use them to perform specific operations. We still all keep it. It's convenient, at least not to avoid it. From your paradigm, as someone who has been involved in cold storage for many years, how do you feel about storing funds on exchanges? Because I have some, you know, everyone has their own prism. For example, I think like this. There's an exchange that, even if I get some bad Tether, which can happen, right, they won't block me and it will be possible to resolve the issue with OKX, right, which is a corporation, so many thousands of people work there, for them I'm bureaucracy, half the department can resolve it, or not resolve it. I'm like, I'll leave it like this, I won't go there. Although I understand that I'm making this up. [laughter] It's all hypotheses, >> yes, >> yes, hypothesis. Well, my opinion has been formed for several years now: an exchange for me is an exchange tool. That is, I am not a trader, naturally, right, and I don't have any broad multi-currency. I have a few coins, stablecoins, right, so if I use an exchange, I just deposit, exchange, withdraw. If I have a significant amount, although again, there's nothing criminal, nothing. So if I have a significant amount, I still diversify, deposit, say, 25%, exchange, withdraw, the remaining 25, and so on. Why do I do this? Because there was a case with the BTGE exchange. You know, when you relax, that's when something goes wrong. I don't know if this happens in your life, but it does happen. But once on Bitget, I always follow this principle: I do it at least three times. So if it's a significant amount, deposit, exchange, withdraw, and do this three times. >> So diversification is normal. And once I thought: "Damn, why is all this necessary, right? Nothing has happened." I sent the whole amount and it was blocked. So I communicated with them for 3 months, struggled, and in the end they returned the money, completely blocked the account. In general, the end, yes, but since then I realized that that's it, from now on, strictly, no >> scare, well, it's fear, it's >> well, it's nerves, they generally return it, as a rule, if it's not some kind of serious crime, if it's not sanctions, right, on the list where Tether blocks, blacklists, everything will be unblocked, everything will be returned, they just might not let you use the exchange anymore. Therefore, for me, an exchange is a means of exchange. If I exchange, then I do it this way, and that's it. These are simple rules. >> What do you say? How involved are you in the Tether situation? How aggressive is it, blocking? Yes, for example, I don't know, some Tether that has fallen, for example, from some sanctioned batch, let's call it that, has fallen to some private individual. How present are such cases in Russia? If we're talking about direct sanctions, well, I call it sanctions if an address has a blacklist tag. That's sanctions, >> like Garantex was >> Garantex, yes, is on the list, fact, so there is a document, right, where is the primary source? >> What is the name of that body? I think it's the US Department of the Treasury, right? It has some subordinate organization, and it forms this OFAC list, right, sanctions. It's a large PDF file of about 900 pages. And there are individuals, legal entities with addresses, right, there. And since crypto started appearing, addresses have appeared there, USDT, Tron, Ether, right, and so on. If an address appears there, then 100% we will find this address in the blockchain with a blacklist tag. >> The address itself, not specific tokens, conditionally, right, conditionally, >> not a specific address, right. And speaking about some things that Tether does, I, well, what I've personally encountered, I've encountered it three times. Well, it's a sample, right? So in 7-8 years that I've been in crypto, I've only encountered it three times when subscribers, clients, approached me and said: "I can't spend it, what should I do?" Four times, by the way, in the last 2 weeks, even [coughs] twice, and when you figure out why they can't spend it, it turns out there's a blacklist tag. And the last time was a very interesting story, a multisig wallet on Tron, so multisig, right, two out of two, meaning two signatures are needed to spend crypto. USDT, a very large sum, and one signer, but they can't find him, and they consulted me: "What to do, right, in such a situation? Well, nothing can be done anymore." Then I checked the address where this money is located myself. It's also on the blacklist. That's the story. So one signer disappeared, they can't find him, and the address was immediately added to the blacklist. This is rare. So, >> a large sum. >> A large sum. >> Well, very large, yes. Well, as a rule, by the way, large sums get blacklisted. I haven't seen any sum like $10,000 get blacklisted. So it's likely something serious. >> Well, like, to make it painful, right? So they just close everything, like your millions of dollars, they are now untransportable, like, guys, sorry, but what kind of attack would it take for $10,000? >> Well, of course, >> if it's some kind of sanction, right, damn it, take it, keep it for tea. And I'm getting ahead of myself, we'll talk more about a very interesting topic for me, the security protocol in general in life, right? So I see that we have this >> UBK >> this >> hardware keys. >> These are hardware keys. Yes, this is a very good topic, very important, complicated, tedious, levels of passwords, but damn, it's professionalism. I'm jumping ahead. A very interesting topic. Regarding, you, you continue to do it, I remember you talking about brute-forcing seed phrases. >> Yes. I also get approached for this, because, [sighs][heavy sigh] well, you write down the seed, as a rule, people like to rearrange something, you know, to, you know, they're paranoid, >> handwriting, handwriting, right, like, >> yes, well, handwriting, they forgot letters, words, something is not written. And, I really, so now I've advanced quite a bit in this, but this topic is interesting to me because it's related to wallets, right? So, if there are such cases, I handle them. So, if partially, an important question, the seed phrase is partially lost, then it can be restored by brute force. >> Brute force is just computational power, right, they just iterate through numbers and has it ever happened that you gained access to another wallet? No, no, not like that, of course, because, well, brute force, you know, it's orders of magnitude, for you to understand, it's for what I take on, it's, for example, 10 to the power of 50, right? That's, well, that's a huge >> Explain how it works >> Oh, not 10, 2 to the power of 50, so 2 to the power of 50, right, that's forgetting five words completely. If you come to me and say, five words are lost, it's difficult, it's almost the limit, but it can be brute-forced. If you come and say, "I have eight words lost." That's it. That's 2 to the power of 88. That's a crazy space. So in such spaces, it's practically impossible to get into some wallet, because, well, it's just boundless. How does it work? Explain the process yourself if there's no secret sauce. Is there an immediate brute force, some kind of check, right, opening these >> And I need to know the address, ideally. This speeds it up significantly. So you can brute force without an address, but it's much more difficult because, in general, how it works, I'm given the seed, well, what's left of the seed, right, >> and the address is given. >> And the address is the target address, right, the target address. And I start brute-forcing. And for each valid seed, I generate an address on it, comparing it with the target. That's kind of the method. And if you come and you don't have an address, then here's how you can do it: I take, I brute-force, I have, I don't know, hundreds of billions of addresses that I've generated, and then I take the entire Bitcoin blockchain, parse it. Well, you say, for example, that you have one Bitcoin, I identify all addresses with one Bitcoin. And these two large arrays, there's a special technology, developed, I think, in the sixties, the Bloom filter, roughly speaking, it's a very simple way to compare two huge arrays and answer if there's a match. So, that's the method. It's without an address. So, if there's no address, it can also be done, but it's more tedious. >> Wow. And do you have some software? Is it a powerful computer? >> Yes. PC. I named it Evklit. It's in our office. And powerful PCs, powerful brains, I developed it myself, so low-level language. So >> You mean it's not some Windows, it's Linux? >> It's Windows >> And I >> No, it's Windows, but the brains themselves that do this brute-forcing, right, there are many nuances, you need to make it as fast as possible. And, of course, you need a GPU, a powerful graphics card, because on a processor, it will all be very long. >> Uh-huh. Let's move on to cold storage. It's even useful for me to refresh my memory, what's inside. Let's do this, not inside, in terms of, let's do it from the very beginning. When I started to articulate it, I thought: "Yes, exactly, these two-four words, there are 16 of them, they generate your address." So let's break down this whole chain of interconnections. >> Yes, so what initially, so, >> well, you understood, from what comes from what, what leads to what. There's a private key, there's a seed phrase, there's a public key, public. >> Yes, yes, yes, understood. Well, in general, if we divide it into stages, right, I'll say it simply, so as not to overload too much, right, so initially we need to form a random number. So we have seeds that are 12, 18, 24 words, right? >> And a random number, respectively, 128, 192, and 256 bits. So you can take a coin, flip it 128 times, and you'll have a 128-bit binary number, like 1 1 0 1, and so on for 128 times. This is the seed phrase for twelve words. >> Then there are special hash functions that you pass these 128 bits through special algorithms. They are mixed many times among themselves and form a tree of addresses, master keys, child keys, master, child. And ultimately, in this tree, there is also an index that is responsible for the coin. Zero is Bitcoin, right, then two is Litecoin, and each coin has its own index. This is the standard BIP 32, BIP 44 standard, I think, if I'm not mistaken. >> Or BIP 2. BIP 32 is the structure. It's the structure. BIP 44, I think, doesn't matter. >> Doesn't matter, right? And BIP 39 is precisely the standard that describes the mnemonic phrase to convert this random number into words. And ultimately, we get these indices that allow us to get addresses. An address for Bitcoin, for Ethereum, for Tron. So, one seed phrase is enough to generate a huge number of addresses for different coins. Exhaustive, >> yes? And all this, naturally, is integrated into many hardware wallets, and into hot wallets. This is the industry standard. >> Uh-huh. Let's move on to the devices. I'll say this right away, I have three devices. There are card-like ones and complex ones. And I bought myself an expensive one. Well, an expensive device, yes, such an expensive device. I was pleasantly surprised that it wasn't a phone. Although I thought it was games, well, I understood, you know, when it was on the screen, it felt metallic. [snorts] And in general, a certain consumer taste has formed, or something, right? Why I mentioned it, my favorite wallet, it's actually super simple. Yes, as if simplicity won. Ledgers, on the contrary, I mentioned the most disliked, it's a torture. It's terrible memories. This is it. I'm not a hardware wallet guy, and I'm also like that. We'll move on to the protocol. I like to double-check three or four times. >> Correct. >> It really takes an hour. You sit there and so it's super, you have to be completely focused, catch hyperfocus, you know. And I have this torture a little bit. >> Well, that's correct. I think that's why everything works out for you. >> Well, yes. Mine, knock on wood, I don't know, knock on wood. I've never been scammed. I've never signed any crooked transactions, never sent tokens anywhere. My partners, all of them. I've never, knock on wood, had such a story. I always remember when I send, I look at the address, I look at the address, I look, and I'm like, I have OCD from hardware wallets, you know, it's a disorder, right, anxiety. I look and until it clicks somewhere in my head after a minute that it's it, then I transfer, >> yes. >> Yes. OCD in crypto can actually be very good for security. Regarding devices, let's talk, let's start with the basic level. I advise everyone, I don't know, I don't like hot storage now, especially since it's all still a chimera. I advised guys to install it. They asked me: "Where to store it?" I brought guys into crypto, advised them, you know, what to do. They say: "And where to store it?" I say, Trustlet, they say, I downloaded it myself. It doesn't give out a seed phrase anymore, right, at the initial level. How does it do it, how does it store it? Lost the phone, forgot iCloud, I don't know. It's like, well, there are some risks. Therefore, it's better to onboard immediately. There's card storage, super cheap. Please explain, let's take card storage now. What is this beast with an NFC chip? Why is it recommended? Because it's the first step, >> yes? Well, actually, here, without a seed, right, so there are different options, of course. There's a way to store assets without a seed, with a seed phrase, but the point is that it's all very convenient, right, so you, NFC, the firmware in the card, it doesn't update. So, the device itself is much simpler, if we're talking about these cards, than if we take some hardware wallet, Trezor, Keystone, Ledger, which still needs to be updated, and there are different interfaces. So here everything is minimized. Very simple onboarding and NFC. NFC, I think, is a foolproof thing. So you bring it close, Bluetooth can disconnect, you need to connect somehow, right? So NFC is much simpler. Therefore, NFC started to be used to, well, transmit transactions, right, and in general, >> Guys, friends from School Wallet have allocated several wallets for us to share with you. But the most important thing is that you must use cold storage. I'll say this, no self-respecting cryptographer with a normal deposit, with an already abnormal deposit, uses centralized exchanges for permanent storage, or even hot wallets, because when you install the same famous Trust Wallet, which is available in web stores and so on, it doesn't automatically give you a seed phrase. You need to go into settings to retrieve it. You don't own your crypto. Tell someone this in 2017, and even in 2020 they would have spun their finger at their temple and wouldn't have used such a product at all. Mass audience demands something convenient, but that's why companies like CoolWallet create products with cards, with NFC chips, where you just tap and make a transaction, which is convenient. But cold storage is mandatory. Main deposits, main funds should be stored on them. Use them. >> Please tell us about the Coolwallet company's product. What does it represent? So, yes, the company CoolBitX, which founded, created Cool Wallet itself, was founded in 2014. And the company's goal was to create a product so that people could 100% own and store their assets in isolation, i.e., in a cold wallet. This happened when the MT Gox hack occurred back in those years. [heavy sigh] And there were, I think, only two manufacturers on the market at that time, if I'm not mistaken. And then Michael, who founded CoolBitX, had the idea to create another cryptocurrency brand, but more physical, so that it couldn't be physically opened, so that no components could be replaced, meaning it would be completely protected from physical interference. And in 2016, the first model, Cool Wallet First Generation, was released. Then in 2018 the S model, in 2021 the Pro model, and in 2025 the Ho model. So the company focuses on security first and foremost. So there are several products, SignBridge, for example, which is for enterprise services, then several saving products, and then the hardware wallet itself. So the company became popular more because people buy and use the wallet. >> Why did you bet on the card format, rather than, say, a USB flash drive? That's a good question, actually. Well, I think when we started creating the product, first of all, we wanted to combine security and convenience, so that it could be put in a wallet to carry around, a daily wallet that doesn't even catch the eye, right, a card is just a card. This point, and I think the main point that prompted us to create a card form factor is that if you recall from 2015 to 2018, when fake brands of other wallets, other companies, were sold on marketplaces, and they would hide the lid and solder their chip there and sell it as new on marketplaces. Such situations occurred. And brands constantly said: "Oh, never buy a wallet from marketplaces, always get it from trusted resources, authorized resellers, distributors, from trusted sources, or directly from the brand." And then the idea came to create a wallet where components cannot be replaced. So if the wallet is opened, it stops working. You can't resell it. So that's the protection against physical interference. You can't replace any components inside the wallet. And the card is tamper-proof because all components are fused together and it's impossible to replace them, solder another chip, and so on. And then, in the situation where these wallets were sold on marketplaces, people who bought them for a cheap price, the person who had already soldered their unauthorized chip already knew what seed phrase this person would have who would unpack this wallet, activate it, and load their bitcoins. And in subsequent cases, there were many such cases where people simply lost their money because the wallet was not physically tamper-proof. And then the idea came to our minds to make it in the form of a card with a screen. >> What was the most difficult thing in developing such a product from a security perspective? The most difficult thing, I think, was how to connect all this architecture into one. We include the screen here, we include the button here. Well, okay, screen, button, and chip. They communicate, the chip communicates with the screen in offline mode. What is shown on the screen, on the card itself, the chip provides this information. Not your phone, not your wallet software provides it, it's directly from your chip, it provides this information, and it's the signature, and it's how much assets you're withdrawing. And the most difficult thing was to connect all this so that everything works as a whole, so that the user can very well understand what they are doing, how they receive crypto, send it via Bluetooth encryption. Then, well, all this architecture to combine into one. It was all a quite complex process. And in 2023, we also had the task of opening the source code for the chip itself, so that people could, the user could verify that there are no additional, callable codes, lines of code that, for example, could affect some hack, and so on. So, and in 2023, we finally opened it. This was also not an easy process. And I think, yes, this whole architecture construction was quite complex. Especially the tamper-proof, protection against physical interference was also, this is physical security. Physical security must be present not only in the chip, not only, I don't know, encrypted Bluetooth, but also the device itself must be secure. So this was the task that we, accordingly, solved. >> What updates and releases do you plan in the coming years? Regarding updates, well, the most important thing, I think, is always to improve the product, always to create some new UX/UI design, because the evolution of wallets is happening. If before, we remember, we put crypto in a cold wallet and hid it in a safe, now it has become our everyday product. We use it every day. This is the product that needs updates. And, of course, I can include adding new networks, because a wallet without networks is not a wallet. I'll even say this, there should always be network additions, whatever users ask for, whatever network, we always support it. Adding new coins for staking through a secure wallet. So now people can stake. And also, I think, adding many major features so that the user feels in a moment where they are protected, where they can do basically everything. From trading to buying crypto for storage, and so on. Knowing that their seed phrase, it is stored offline. Not the seed phrase, the private key is stored offline. >> What advice would you give to a beginner who is just looking at this world and thinking about cold storage? Well, I think the most, you could say, some might call them banal tips, always, well, choose the device that suits your style. For example, if you travel, if you are always on the go, right, so now there are many wallet brands, and they are all of different styles. They all differ in form factor, they all
They differ in style, according to your requests, by networks, and so on. That is, choose, proceed from what your style is, what you really need, and choose a wallet for such a style. Well, and, accordingly, always look at the fact that the wallet you are buying is purchased from official resellers. Uh, they are present in Russia. Also, make sure that the seed phrase you write down is always in a reliable, secure place, offline. Never photograph it. These are such banal tips that everyone should, I think, know. Well, and I think the most important thing is, uh, well, don't enter your seed phrase anywhere, not into any online chats, even support will never ask for it. This is already, as a rule, all cryptocurrency brands, including us, we never ask for a seed phrase to be sent to someone, and so on. That is, this is your personal seed phrase, which helps you 100% to 100% own your cryptocurrency. Well, and I think from the last thing is that you always need to check your transaction. When you make any transaction, you always need to look at what the chip gives you, what information it gives, and what information your phone gives. These can be two different things. Therefore, you always need to look at the transaction, always look at what you are signing, and not just blindly sign. That's why these, I think, are banal tips, but they are sometimes very, as it were, necessary, because a lot of people lose their assets because of such stupidities. >> The most unpleasant thing is to lose. As I like to say, it's hardest to get up after that, just by mistake, poof, you have zero. Let's move on to the segment above. Uh, Ledger with screens, right? So no, let's, no, most likely it's SafePal, Ledger, these are more mid-segment wallets, like how much? For 50 dollars, for 70 dollars. >> Ah, well, now they are, yes, 80 and above. >> 80 and above. Uh, their fundamental difference, besides cards, which are cheaper, is the presence of a small screen. >> Yes. Yes, essentially a small screen. In general, Trezor, they have completely updated their lineup. And this is Trezor Safe S, and there is also the Trezor Safe 7 model. So, well, Trezor, they have remained for geeks, right, and they don't constantly add many coins, like many manufacturers, for example, like Ledger has very high multi-currency support, SafePal, by the way, has high multi-currency support, Tangem has high multi-currency support, right, and there are vendors who, well, don't go in this direction. So, Trezor belongs to them, for example, uh, Keystone, CoolWallet. Although CoolWallet, in terms of multi-currency, will certainly be better than, say, Keystone and Trezor. >> Multi-currency, >> right? Yes. >> Uh-huh. And now let's talk about the segment, probably, for 500+ dollars. Why the hell are such wallets needed? Are they needed there, no? I understand, I understand that metal, a case, right, there, well, as it were, at some crypto event, so it will, well, as it were, look status, right, to pay. But from the point of view of technical security, >> from the point of view of security, actually, I believe that there is no difference. That is, you can buy, let's take, for example, from budget wallets, even the oldest SafePal S1 model, right, and let's take, for example, your favorite, right, and let's take this Ledger Nano S, which costs 400-500 dollars, and so, well, actually, in terms of security, they are all the same. That is, both support passphrase, and here support passphrase. Seeds are supported, addresses are supported, right, secure chips are installed. Naturally, the secure chip here is faster, that is, uh, transactions will probably be signed faster, right, uh, the screen will probably be more responsive than SafePal's. These kinds of things. This is what people overpay for, so that it's something more new, convenient, similar to smartphones and a familiar experience for us. Let's talk about the panacea. There is an opinion that a cold wallet is a panacea, it is actively pushed by all opinion leaders, and as if most of them own them. There are risks of hot wallets, Windows, right, of everything. I even, I, no matter how much I talk about myself, like, that well, one of the safest is iPhone, because you download little here, except for the store. Well, some kind of application torrents. Well, I don't know, I, in short, don't need them. But on Mac, and even on Windows, I have movies. Yes, yes. >> Yes. So you, as it were, let's talk about the risks with cold wallets, because there is NFC, there is Bluetooth connection, and there is wired connection, where you can, in general, get burned. Uh, I'll say right away that this is a sufficiently complex attack, well, to be scammed at the level of transaction transmission, because what you're talking about, NFC, cable, uh, yes, Bluetooth, these are all ways of transmitting transactions. The probability of being scammed is there, yes, but it's small. And such attacks. Well, I rarely encounter them, right, but, uh, the most, the most safe for me personally is still QR codes. Air-gap mode, when we see a QR code, right, and scan it. The most, as it were, air-gap, right, without, well, if translated literally, air gap. That is >> not air, you when you send a QR code, you just scan the address, >> scan the QR code, like on SafePal. >> This is the safest, I still >> this is what I like the most. I wouldn't say it's the safest, because again, there's a very small probability, right, uh, to scam, say, Bluetooth is just fantastic, for example, if we take Ledger, right, and, uh, for Ledger to transmit a transaction via Bluetooth, for it to somehow change, load into the application, and the application to push it to a scammer. Well, this is fantasy, right? Therefore, but I personally like openness. Therefore, when I see a QR code that I scan, and I know that I can decrypt this QR code and see what's there, I feel a little calmer, unlike, for example, a cable or Bluetooth, right? Because something was transmitted via Bluetooth, you don't quite understand what was transmitted, and via cable, too. Well, therefore, for me personally, the picture, the QR code, is safer, but I have such a strong level of paranoia, right, so you probably shouldn't orient yourself by me. >> Like your car should, if you were some kind of forester, hunter, like a dacha with a house, right away, well, you know, for everything there is such a thing for all occasions tomorrow. But for now, this is not for everyone, that is, in general, the transmission methods are also all safe. Well, the most important thing here, you know, is personal hygiene. That's what's important. That is, uh, you can scam any person, actually. And here you just need to understand what you are using. Behavior, if you install a lot of unknown applications on your Mac or Windows or Linux, then you always have a chance to get scammed. >> Let's talk about hygiene now. Let me formulate the question like this. Imagine in a vacuum. I come to you, I'm a student, I know nothing about crypto. Before that, life has already beaten me. I lost, you know, I made stupid mistakes. I say: "That's it, I'm ready to learn. Give me the protocol for this security hygiene, password storage, step by step." I have my own vision for it. Let's start with you first. >> Well, the very first stage, probably, is community. I believe that crypto is like, I always compare it to the jungle. That is, if you are a beginner, if you come there, there are a lot of animals, these scammers, right, who are looking at you and are ready to scam you. That's why the first stage is to join a good community that will help you figure things out, answer many questions. And there will be thousands of questions here, because crypto is so multifaceted, right, there is a lot of everything there. You definitely won't figure it all out on your own. Therefore, the first thing is a good, proven community, which you need to join and which will, in essence, be a settlement that will protect you from these scammers and fraudulent schemes. And the second is, undoubtedly, uh, a personal acceptance, probably, that you are ultimately responsible for your crypto. you don't place, you don't shift responsibility onto someone else, and therefore you are personally responsible for what you buy, what you use, right, and for everything you are responsible. >> Interesting. >> And this, yes, and this already allows you, this is a resource, as it were, this paradigm, this is a very powerful resource that will allow you to further make decisions about your hygiene, that is, PC, uh, smartphone. If you are a beginner, right, then it's probably better to buy a completely clean PC. You can use it on it >> a clean Mac. A completely ideal picture. >> A clean Mac, a clean Windows, a clean Linux, it doesn't matter actually. That is, uh, the main thing is that it's a clean machine and you only use it for crypto. It's also desirable to have a SIM card, if there are exchanges, verifications, uh, email. Why I'm talking about a new email too. Yes, because if you use, uh, verification methods such as a SIM card or email, this is all for authorization, >> if they have a very large digital footprint. If you fall into at least one scam database, for example, from DEX, we remember, there were 21 million email addresses with names, with emails, with phone numbers, right, so imagine how huge a database leaked. And if your email has this digital footprint, it's already a vector for attack. Therefore, uh, a new virtual SIM card, you can have a new email, a new PC, a smartphone can be left. We believe that a smartphone, well, there is an iPhone, for example, it's impossible to install something like that. Well, maybe it's possible, but ordinary users don't do it, right? And this is already a kind of, you know, a very strong foundation that will allow you to withstand many years and preserve your assets for many years. >> I'll expand the topic a bit. I studied this issue, by the way, I'll raise my hand. I have a separate device, I won't say where it is. It's, well, if I ever decided, I bought a separate device for using crypto. It doesn't necessarily have to be new. That is, it's, well, the main thing is that it's Apple technology. Yes. Uh, in general, as I understood it, when I read such an article, and here, actually, this hygiene, it's not, it's not separated. Real life crypto, crypto there, real life, it's all together. That is, you basically become a paranoid person, because you said correctly, one mistake, your, say, 3, 5, 10, 100 thousand dollars just dissolve. That's it. Neither the state nor anyone will help you. By the way, I have a question for you about whether it's possible to write a statement to Trezor so that they can roll something back, for example, conditionally. Uh, what I understood for myself. First, you need to admit, I'll add to your version now, that you say, create a new separate email without a digital footprint. You should have password levels. And password levels in my understanding, there is some kind of master password, for example, for email. Email, which, well, opens access to you, say, social networks, photos, personal clouds, where locked files can be stored, like these files >> encrypted, >> encrypted, you understood, right, when encrypted files, there is a physical opening, and there is also a file that, in principle, you also encrypt. Everything, understood, >> yes? Uh, there is a master password, it should only be used on these, uh, Yes, preferably this password, one person taught me once, he said, no more than 20 characters, but he gave me a secret. I'll give you a tip too. He said: "Find your track or movie or something that you will never forget, and you can always find it on YouTube. And just save it." You understood the title of this song, movie, excerpts in English, with dashes, with dots, and so on. And yes, a lot, but it's cool not to forget. Everything, then there is a second level, right, this is where you use it, well, more or less often, but the main thing is that you have a separation between the first and, say, the second or third. The third is the dirtiest password. Such, you know, like we always have one password everywhere, you need to quickly, a person is in a hurry, to enter, say, DEX, to enter some site. Everything, this is a classic of the genre, everything is leaked. I, for example, the third password, it should be super simple, but you have to throw it away like this, change it. Next is, we'll move on to this. I just haven't gotten to this yet. Here. Yes, there are encrypted files like StrongBox, there are also Passkeys. Well, this is all, as it were, software that does encryption, it's an encrypted database, you could say, right, a file where you also set a password, for example, 25 characters, which no one will ever, I think, right, it's impossible to crack, and you send it anywhere. Emails, clouds, notes, everywhere, even if the service is compromised or, for example, closes forever, so that you don't forget it, tell me about this thing. >> This is a hardware key, right? U2F Token, right, it's also called. Uh, actually, if we analyze this topic, right, then, uh, there are three factors of authorization. Knowledge, possession, characteristics, right, knowledge is a password that can be passed from one person to another. >> Characteristics - this is our biometrics, this is voice, this is, say, the iris of the eye, fingerprints, right. And knowledge >> possession, >> yes. And this is precisely possession. Possession is >> physical >> a key. It's something physical. It's a key from the door, >> yes? It's a passport too. It's a method of authorization. You show your passport at the bank to prove you are >> Yes, they won't take the passport itself, they won't give it to you without a passport, and you need this, >> yes, this is possession. And, therefore, U2F keys are also a factor of possession. That is, you can protect a lot with it, well, essentially. That is, uh, log into your Mac, your Windows. Uh, that is, without it, you won't log in. >> It just won't open, like. >> No, it, well, in the sense >> it won't turn on, like, enter the password, right, but you won't log in. This is a, well, a geek option, not for everyone, but it can be done if you bother. Uh, but what's very important is, for example, to protect your email, because you can't log into your email without U2F, right? This eliminates a huge number of attacks. And there, uh, they are all online, right, all attacks. That is, a scammer needs to get this physical key, steal it, right, to log into email. Or the same can be applied to a cryptocurrency exchange. >> Tell me, please, but this complicates things. Can it be put in a phone? No. >> NFC ones. >> NFC ones. Ah, okay, they can be attached, >> yes? Well, okay, I understand. Let's move on to this later, to the multi, well, how they are, in general, so that it breaks and you are not left with nothing. >> And here everything is very simple, actually. The possession factor and its feature is precisely that, right, when you lose the key, well, from the door, you're done, you can't restore it, >> yes? This >> is the same here. That is, it's impossible to restore the key. And this is the feature and security. That is, if it could be reproduced somehow, then it would be a knowledge factor. And here the feature is precisely that it's not, you lost it, it's over. This is such a solid, concrete protection. From this, it follows that we, of course, need to have several keys, copies, >> yes, several keys. There is a nuance here. That is, if, for example, I have a password database, say, Passkeys, I use it, well, this is a proven solution, right? >> Yes. With keys, >> yes, Passkeys, >> yes, Kas is an open-source solution. That is, if you encrypt this key, then you won't be able to decrypt the password database without U2F, >> yes? >> And if you encrypt and lose this key, then it's goodbye. Passwords, >> yes. Well, you can't, because you can't write to Passkeys support. Well, this is an offline, right, open solution. But if you have an exchange, then there is support, then you can communicate with support, go through KYC again, and you can remove the U2F lock. Therefore, it depends on what you are protecting. If you are protecting a password manager, then you need to, well, >> think 10 times. >> Two, two, yes, think 10 times, then either two or three backups, keep them in different places, because they can, I don't know, fire, they can be stolen, right, and so on. By the way, they are also password-protected. That is, to use it, you can additionally set a password. That is, here is such a password factor, right, it's like a key to the door, but to use it, you need a password. That is, this is protection for those who want maximum security, but here there is a barrier that needs to be overcome and understood how it all works. >> And there is another barrier. By the way, a not unimportant thing. Now, yes, I'll ask a question. I remember you once said [snorts] when we met, about the story that you encrypted yourself like this, everything is packed completely and you died. You have relatives left, well, a wife, children, and everything. >> And what to do? Yes, well, this is 100%, actually. No one is protected from this. And here you need to have a trusted >> think, right. And this is important. You already need to think, uh, well, how and where this protocol, like an action, you know, like in a movie, Mission Impossible, roughly speaking, the guy thought ahead, hid it in a bunker, it all opened at the right moment, >> yes? That is, there must be a trusted person, or I'll tell you a case, it's just crazy, actually. Well, in terms of trust, it's just hell. Uh, a woman I don't know at all writes to me in private messages, she writes me a message, like: "Hello, Vladimir, my husband is gone, yes, I know, but I know that he watched you very often. I don't understand crypto at all. Here, he left me this, this, this, and I'm afraid to do anything, right, so can you help?" Uh, well, I later found out that this is our client, so I started asking questions, right, but this moment, of course, is very important, because if you think about it, if you don't have a trusted person, if you haven't done it in advance, then if you're gone, then a person who has no idea can simply be scammed and have their money stolen. The question is important. >> The question is important. And also, actually, yes, let's have three levels of passwords, for example, even two. Okay, two levels of passwords. A password database protected by a physical key, which is also password-protected, a clean system for activation. And most importantly, in this database is the seed phrase >> two-four words, >> and we haven't discussed one important point yet. >> And a passphrase, right, a passphrase too. Yes, >> yes, >> there is also. Explain, please. Well, let's wrap this up, right, to make it really cool. >> No, this is my dream, I'll tell you. This is, you know, like when you sleep and you feel that you, you know, like that guy who walks around the city, well, like that Wasserman, you know, packed for all occasions [laughter] of life. Well, passphrase >> this is, actually, a very cool thing. Many people still don't know about it. Although they seem to have this functionality, it's always somewhere in the menu. You have to go deep into Ledger. Before, well, you go far away. Now it's somewhere here, well, as it were, quite close, but still many don't know about it. Explain, please, what it is, how it works. [snorts] Ah, passphrase. Oh, by the way, Passkeys, we didn't discuss it, right? Pass. Passphrase, yes, this is a passphrase. This is an additional password, right, which allows, it affects, so it's a very important point that this is not just a password, right, but when I described the wallet structure and how it's created, I told you that there are 28 words. Oh, >> yes, bits. >> 28, 128 bits, that is, 128 units of zeros. And at the very initial level, uh, any wallet, right, already contains a passphrase. It's called, well, a mnemonic, >> yes? >> You know this topic? >> What is your seed and the word mnemonic. And this word is your passphrase. And actually, all cryptocurrency owners, everyone who has wallets, right, they have a passphrase, this mnemonic word. This is a standard, >> in the sense of the word mnemonic, right? Exactly the word >> everyone has the same. >> Everyone has the same. And if you can add an additional one, if you add a word, it's added to the mnemonic word. That is, you write, I don't know, the word cryptus, right, you'll have mnemonic cryptus, this is your, >> yes, anything, any symbols, >> yes, yes, any symbols, anything. And this is precisely at the very beginning, this is the entropy level, it affects the entire wallet structure, all addresses, all your senior, junior keys, right, everything is affected. And, accordingly, any change in this passphrase affects the final address you get. What does this give? It allows you to create hidden wallets, right? Uh, well, essentially, the main thing. And, naturally, the second thing, which is very important, is that it will allow you to protect your seed if someone finds it. >> Yes, and, well, this is an awesome thing, it's so boundless. In general, uh, there is such a problem, right, people used to write seed phrases on pieces of paper. I never liked this option. Firstly, I don't like writing. Secondly, the pen wears off. It's always a piece of paper somewhere, well, in the modern world, where do you keep pieces of paper? Even now, if you ask me: "Show me a piece of paper." I don't know. Well, today Nikita brought me paper for filming. Well, it's not there, right? There isn't even a place to store it, and so on. Everything is online. Uh, and the question was, where to store it? I remember before I had my very first experience with Ledger, two sheets of paper, folded in half, written on each sheet and kept in different places. But again, the risks of flooding, throwing away. Well, this is a very fragile, as it were, a fragile cell, right? >> And you told me about passphrase then. I was like: "Wow, no way." That is, it's a compilation of your seed phrase and any passphrase, even if it's 100 characters long, just remember them, right, it opens a new cell, so to speak. And what does it give? >> Yes, >> I discovered for myself. Now your seed phrase. You can store it anywhere, even engrave it on your car, so that everyone sees it. They will have access to your original wallet, but you always have a second bottom that opens something new from your head. And this simplifies, as a result, the storage issue. Now it's stored, right, in open access, but the passphrase opens the wallet. This is the final level. I have nothing more to add, actually, to storage. >> Or, you know, you can have a top level - there are test seed phrases. Test seed phrases, you know, that developers use. That is, test seed phrases are usually 11 identical words and then all, all, and at the end. That is, 11 words all >> the same, right, >> and the last one is Z. That is, the checksum matches. And this is what developers use, because, well, it's easier to test such phrases. They are, well, indexed in the dictionary at the beginning, right, and so on. And you can, in principle, use such a seed phrase, which is, I don't know, in thousands of documents on GitHub and codes that contain this seed. That is, you will never lose it in your life, right, because it has already spread everywhere. >> And you, and you can, I understood, >> yes, and you can set a complex passphrase on it and use it. Well, that is, but such a moment, >> uh, regarding the reverse traversal, how to roll back a transaction in Tezos, with Tezos. We'll talk about it, because everyone is tied to it. In Bitcoin, it's impossible, right. Such a 51% in Ethereum too, as I understood. Well, in Bitcoin it's possible, actually, if the transaction is still >> pending, >> yes, if it's in the mempool, that is, before [coughs] receiving the first block, it's always possible to roll back. >> This is a miner attack, получается. They just don't take it into work. >> Uh, this is not, this is not an attack at all, this is just a normal story. You change the fee and you can completely replace the addresses. Ah, I understand. That is, you change the fee, and you become higher in the mempool. Miners, well, they look at you with priority, because they will take transactions that pay the most. >> Uh-huh. Uh, regarding rollback in Tezos. How often has this happened recently, damn, well, this case is very common for me. When we were robbed, we tried to solve it, well, they tracked the money, it went to OKX and after that it was immediately dropped to a wallet. >> Uh-huh. Two or three more cases I remember when crypto, the classic scam genre, goes to a dropper to some exchange and then goes somewhere else, uh, to a hot wallet. Technically, the police, all this can be recorded. There are countries that are more developed in terms of digital, well, you understand, digital trackers, I'll call them that. There are guys in Russia who are really cool and are in the global community. But still, I've never found a story where someone said: "Damn, guys, 2 years have passed, you know, I rolled it back." No, no, no, they don't do it, right? >> There is such a story with me. Actually, if you've been scammed, then write to Tezos. That is, here you can only write to the exchange, and there, naturally, a police report is needed, and only the police should write. There is a special verification level, right, when the exchange determines who is contacting. That is, an individual is pointless. How can you roll back a transaction? And where I was actually a witness and a consultant, right, and there was actually success? This is if you send funds to some non-existent address. In this case, Tezos, for a small fee, I don't remember, their fees change, for a small fee, right, they will burn the funds sent to a non-existent address and send them to a new one. Why is this possible? Because it's very easy to prove that the address is, well, invalid. There is a checksum, right, for any address, even for Ethereum, right, if you know, if you are aware, if the address for Ethereum and the EVM network can be in lowercase, and in uppercase, or mixed case, >> mixed, >> there is a way to check if it's a valid address or not. >> Well, mostly it's mixed. Uh, well, it varies, by the way, many exchanges now, I see, use only lowercase letters, right? Well, in general, the point is that Ethereum has a way to prove whether an address is valid or not. That is, if it's an invalid address, then you boldly, uh, write to Tezos, say: "Guys, check the address, it's invalid." Then you say: "This is my address, I'm ready to confirm, right, whatever you want. I can sign a message for you and I can make a test transfer somewhere you tell me. Yes, you go through this verification. They return your money. Such a case happened. This is only one case, if you, well, as it were, sent, well, somewhere where such an address doesn't exist. It's easy to prove. >> And specifically, you didn't send to someone at a non-existent address. Everything, they just print, well, >> I understand, they simulate and as it were, their balances are plus or minus. >> They just burn it, right, and return it. And I was surprised, actually. It was a long time ago. The client wrote, said, after some time, listen, it worked, they returned it, like, here. And if you write to the issuer, for example, USDT, that you've been scammed, the answer is always the same: we can't do anything, right, contact the police and to the environment where these tokens went. >> But those, well, let's say, uh, well, they are involved in rollbacks. Well, maybe not for us, but for someone else, for example, for a large one. >> Unlocking. >> Unlocking, no, for example, rollback, for example. Yes. >> What do you call rollback? >> Well, when, for example, there are cameras, they stole, for example, conditionally, 15 million USDT, and then they returned it after some time. >> Well, there are no such cases. It's all through court, it's all through the police. I, I haven't seen such cases. That is, I have seen cases of gratitude on Twitter, right, and they even tag the founder, right, the founder. Uh, Tezos very often, like, thank you very much, we, well, we, uh, restored the money, only there is some kind of mistake, an error in the address, they burned the money somewhere, right, these kinds of things, they are very easy and public, right, well, imagine if something like this happened in the public sphere, that we rolled back, and there are tens of thousands of such cases, right? There will be some injustice, and why did you do it here, and not here? That is, Tezos, they, well, somehow, apparently, they have such a policy >> mafia-like in general. >> Well, like [snorts] that >> yes. >> Well, if it's done on instruction, some kind of order, say, from OFAC, then naturally, they block it. >> Are you deeply aware of what's happening? Well, there, without, security, losses, rollbacks, returns. Let's put it this way. What is the most, for you, for you, the most terrible mistake that can be made with crypto? >> An ordinary user. >> Let's say an ordinary user and you, for example, I don't know, a phobia of an ordinary user or your phobia. >> Well, what, probably, well, you know, what happens most often? For example, I have such a phobia. And by the way, like you, actually, uh, when I send a significant amount, well, there's always some kind of [snorts] inside, right, this nervousness, >> yes, yes. Although, well, I understand that, well, you've been doing this for so many years, why are you worried, right? So, I always have some kind of nervousness inside, but I think it's healthy and you should treat it well. Sometimes, even for you to understand, I have a level, well, when it's a really large sum that I'm sending, I sometimes have a QR code printed on paper. Well, that is, well, because paper, you can't really transfer it. >> Addresses, >> yes? Yes. >> Listen, by the way, about QR codes, they can be compromised. Well, of course, they can be compromised. Of course. >> I just always use them. I even ask for requests. Yes, they can be compromised, but there are just a lot of poisoning, right, this whole transaction story. And even if they send you something in Telegram, right, some address, you copy it, send a test transaction, and then you need to check, maybe this person was scammed, and the message has been changed, right? So, well, there are many vectors, actually. Therefore, for me, probably, the most, what I encounter most often, right, is when a transaction is being sent and, well, I worry internally. So, for me, probably the most terrible thing would be when I read these news, how someone, a million dollars, I just, 1,000 Bitcoins, there was news on Twitter, SlowMist published it, there were 1,100-something Bitcoins that someone sent, well, wrapped Bitcoins in the Ethereum network through poisoning. Well, this is just hell. I think, damn, how can a person feel after making such a mistake? Well, this is hell. Therefore, I read these news, and probably because of this, all this happens to me. I read all this and think: "Damn, and somehow this, you know, is inside me." And probably, this is some kind of professional story, that's why I'm paranoid because of it. >> There's even such a feeling when you send, you know, as if, imagine that the blockchain is some kind of, I don't know, it's space, right? That is, you understand that there is some shuttle there, a shuttle here, but you, well, you don't see, there is some trajectory, right, but you can, like, guess wrong and all this, >> yes, by the way, a good example. >> This is like, everything is minor, you know, yes, the goal is very far away. The slightest deviation by a ten-thousandth of a degree will take you to another galaxy and that's it. >> Yes. And that's it. And forget about it. >> Yes. This is a very good analogy, actually. Therefore, blockchain is indeed some kind of space, a super unfriendly environment. Uh, therefore, it's scary >> sometimes the rules, right, that people have, bankless, all that, but it greatly simplifies usage. Still, all these, say, banking, states, institutions, they, of course, they earn, and so on, but they still make sure that people, you know, don't burn themselves, because there are geeks, and most will be them, >> of course, yes, listen, I recently transferred, I paid, I paid taxes, by the way, yes, I paid taxes, through Gosuslugi, through QR code there, I scan and block, right? A bot calls me immediately: "Hello, are you sure you didn't send it to a scammer?" Well, in short, and I understand that on the one hand, well, damn, imagine, so in blockchain, there won't be anything like that, no one will call you. That is, indeed, the entire fiat environment protects us, perhaps even excessively protects us. Therefore, people who are from fiat, who are moving to crypto, they need to see this shock, right? That is, this is planet Earth, warm, cozy, beautiful, and blockchain is space, where it's cold and >> you are alone. >> Yes, you are alone. >> I was actually filming today, towards the end, uh, a series of short videos, I'm filming about problems that affect people. Like, signed the wrong document, right, I was deceived, for example, gave a friend, asked to borrow money, or gave a card to transfer a sum and turned out to be a dropper in the chain. And, actually, there are ways for you to react quickly, write to support, provide screenshots, intentions, that you are clean for future court, that you are not in collusion, and you, as it were, well, there are these chains, right, for example, when they sent you some funds, well, as a dropper, you don't need to send them back yourself. You need to write to support, received from an unknown person, an unknown amount, I don't know what it is. I request to roll back this transaction. That's it, the bank does it itself. And in court, when they accuse you, you say: "Guys, yes, listen, I wrote, I didn't even want to touch it." There is such a thing in the system. In the system. Yes. You can perceive this word differently. Yes. >> Yes. In the system. Uh, guys, I always recommend Vladimir, as a person who, damn, you're the only one in Russia, I think, who deals with wallets. >> Not the only one, but we've been doing it for a long time. Yes. A titan, a colossus. A colossus, yes. Use cold storage. Use smart storage in general, because all the mistakes my acquaintances made, people lost, no one smiled happily at the moment. It's always a tear somewhere, it's always disappointment somewhere. Yes. And I remember when, by the way, we lost 50,000 dollars, we were scammed because of a table, because we stored private keys in an Excel table, and accidentally someone sent it, and other admins saw it in the chat history. For a week, just silence. You walk around like zombies. You're looking for the culprit. It's a terrible feeling. Therefore, it would be better if this didn't happen. It's better to earn and share than to lose and look for the culprit. >> Super. >> Thank you. >> Bomb. [music] Ah.