BTC Sessions - ‘One Bitcoiner Is Kidnapped Every Week’ — How Pros Protect Ultra High Net Worth
Episode Date: April 23, 2026Mentor Sessions Ep. 065: One Bitcoiner Kidnapped Every Week, You're Literally One Search Away From a Physical Attack, and Why Privacy Is Now Life-or-Death Security | Wayne DeCoste & Chris Wing...fieldOne Bitcoiner is kidnapped and tortured somewhere in the world every single week. And you could be next — without ever knowing you were a target.Security experts Wayne DeCoste and Chris join BTC Sessions to break down the escalating wave of physical and digital attacks targeting Bitcoiners and high-net-worth individuals in 2026. You'll learn exactly how data brokers and AI are eroding your privacy in real time, what real-world attack case studies reveal about how criminals select their victims, and the specific digital, physical, and operational security steps you can take today to dramatically reduce your exposure. Whether you hold one bitcoin or one hundred, this conversation could save your life.⏱️ Timestamps:0:00 - Intro: "One Bitcoiner Kidnapped Every Week"1:17 - Meet Wayne DeCoste and Chris — Who They Are and Why They're Here2:11 - The Escalating Attack Statistics on Bitcoiners and Crypto Holders3:49 - Real-World Case Studies: What Actually Happened to Victims6:08 - The Data Broker Ecosystem: How Your Information Is Already Out There9:18 - AI and Data Breaches: The New Weapons Used Against You11:58 - How Criminals Select Their Targets: The Threat Assessment Process19:32 - Digital Security Fundamentals Every Bitcoiner Needs48:20 - Physical Security: Hardening Your Home and Daily Routine55:05 - Operational Security (OpSec): What You Say, Post, and Share Online1:02:30 - Privacy Tools That Actually Work in 20261:09:00 - What High-Net-Worth Individuals Do Differently1:15:45 - The Biggest Mistakes Bitcoiners Keep Making1:22:10 - Step-by-Step: Building Your Personal Security Plan1:28:50 - Final Warnings and Where to Learn More 🔗 Links & Resources:→ Wayne DeCoste: https://www.rescorgroup.com/→ Chris Wingfield: https://360privacy.io/Bitcoin + Privacy + Security: https://btcmentor.io/untouchable-bitcoiner/Bitcoin Survival Workshop: https://btcmentor.io/bitcoin-survival-workshop-2026/📌 Previous Episode: Simon Dixon → https://youtu.be/ZWUGS92Dv8U⚡ POWERED by Abundant Mines: Fully managed Bitcoin mining. Learn more at https://qrco.de/bgYKPB🔒 Lockdown your Bitcoin with the BEST gear on the market from Coinkite. Get the 5% Off the COLDCARD visit: https://qrco.de/bfiDBV💡BOOK Private Sessions with Nathan, Gary, or Ben at Bitcoin Mentor: Master self-custody, hardware, multisig, Lightning, privacy, and more. 👉 Visit btcmentor.io Follow Us on X:• BTC Sessions: @BTCsessions• Nathan: @theBTCmentor• Gary: @GaryLeeNYC#Bitcoin #BitcoinSecurity #BTCSessions #CryptoSecurity #PrivacyTools #PhysicalSecurity #BitcoinPrivacy #OpSec #DataBreach #HighNetWorthSecurity #BTC #BitcoinSelfCustody #OnlinePrivacy #Privacy #Security
Transcript
Discussion (0)
You're literally one Google search away from a digital exposure becoming a possible physical exploitation.
One Bitcoiner is kidnapped and tortured globally every week in the world.
North America is the global leader for that.
There's been over $40.9 million stolen just through physical attacks.
And that was a 75% surge.
There was a 66% increase in kidnappings.
54% of those targeted family members.
I was in the Uber and I just did some open source digging on you.
In like five minutes, I was able to find members of your family.
GROC was live doxing people.
On Twitter, the address, right?
Viewed by a million people.
They can case your residence on zillow.com or redfin.com.
Findability precedes targetability.
Today, I'm fortunate enough to be joined by two experts on the front lines of protecting
high net worth bitcoins from modern threats.
Wayne DeCost, former military, now CEO and founder of Rescor Group,
an executive protection and security firm.
And Chris Wingfield, former digital targeter for the intelligence community,
now chief innovation officer at 360 privacy.
In this episode, we discuss why online privacy is critical to physical security,
how most people are far more exposed than they realize,
and these simple steps that you can take today to avoid being the next victim.
I'm Nathan with the BBC mentor. Let's get into it.
All right, gentlemen, thank you so much for joining me today.
Wayne, great to have you back on the show.
And Chris, thank you so much for joining us today.
The reason, Chris, I want to have you come on this as well, too,
is last time, Wayne, we talked,
you really highlighted this idea that privacy and security are inextricably linked, right?
Kind of like if you got a $10 million vault, but the blueprints and schematics are online,
it's kind of not necessarily doing you any favor.
So, Wayne, to just kind of kick off the conversation,
I was wondering if you give me an idea of the scale of the attacks kind of right now going on
on Bitcoiners, high net worth individuals.
And if you have any case studies, any examples that maybe we can draw some lessons from.
Yeah, no, absolutely.
I appreciate you having me back on.
You know, I know we talked about a lot of this stuff.
on the first episode, but it's been, it's been a crazy year.
We talked, I think, last March and then the episode, I think, aired early April last year.
So almost to the T a year was, you know, the last time we spoke about this stuff.
So when I started pulling the dad on, it's crazy.
And the spikes and everything that we talked about a year ago is continue to increase,
and it's going to continue to increase this year.
So, yeah, just since the last time we spoke a year ago,
there's been over $40.9 million reported in crypto stolen
just through physical attacks, those wrench attacks that we talked about.
That was a 75% surge to the year prior.
There was a 66% increase in kidnappings.
54% of those kidnappings targeted family members.
We've got the statistic now where one Bitcoiner is kidnapped and tortured globally every week in the world.
North America is the global leader for that, right?
So this is at home.
You know, it's not in third world or developing countries, right?
And then on top of that, there's been $17 billion stolen in hacks and scams, right?
So that's a little bit kind of less of a concern in a sense of like people getting kidnapped and murdered.
But no, there's been all sorts of all sorts of new ways and new ways of doing this stuff.
Right.
So, you know, they're happening.
They're happening in prominent cities, right?
So like there was the incident in Manhattan last May where, you know, an Italian crypto millionaire was basically held hostage in a,
in a townhouse in Manhattan.
You know, they got away with millions of millions of dollars there.
There was an incident in November here in San Francisco that repeated in L.A.,
San Jose Sunnyvale, where, you know, people were basically hacking crypto holders, like Uber
Eats accounts and finding ways to kind of come to their address and extort money.
There was, you know, a murder in Vienna.
you know, there's these things just keep happening and we could case study each one.
But like the the real interest in fact is like everything's been done differently, right?
So, you know, we can we can sit here and we can talk about and Monday morning quarterback these events and what these people should have done differently and how they could have helped themselves.
But it's really just everything we talked about on the last episode, it's being proactive with your security, right?
And that's that's something that I feel like everybody struggles with.
And, and, you know, it's similar to, you know, and I know Chris will get into this later,
but like the Sam Haltman incident, you know, this weekend, you know, where there was a, you know,
attack on an AI leader and now everyone's reactive, right?
It's like it's something that we talk about, you know, all the time in our space.
And it's just being proactive with these things and staying up on, on, you know, what's
modern and what's happening and everything from, you know, the AI space, which is really kind of,
you know, the main source. Like, you don't have to be a seasoned criminal to do this. But,
you know, it's, it's big with organized crime. It's big with, it's big with gangs and,
and it's continuing to happen. And, you know, I'm worried to see what the numbers are a year from
now when we talk, but hopefully the listeners can gain some value and feedback from this episode.
No, 100%. Chris, on that, I'm kind of curious what you're seeing specifically in the privacy realm. And maybe you want to touch on the AI aspect. Has things been getting worse for you as kind of a result of that? What kind of things are you seeing? Yeah. No, that's a great question, Nate. And you know, the way I look at it is there was this old idea of something called practical obscurity, which was in the late 1980s, the Supreme Court was talking really about, you know, it's not that your data has so much secret or that it's private. It's just that there's this friction and actually compiling the disparate data points, right? You used to have to have to.
go to a courthouse to get these records used to have to hire a private investigator.
Now it's like, you don't have to do any of those things.
I mean, think about Vance Bolter, the murders in Minnesota.
You know, last June, they find his notebook.
You know, it was really an operational manual.
You have Senator Ron Wyden and say, this is the first time.
There's no way we could debate that people aren't getting killed from data that's
pursuable through a credit card, right?
So you start to see like the way I look at is there's really two barriers that have eroded.
The data broker ecosystem worth about $300 billion.
You know, now those are just.
coming up on Google searches or groc prompts, right?
And we can get into that.
The second one is really just the utilization of AI.
If you can actually lower the technical barrier and just leave intent, there's a lot of
people with intent that didn't have capability before.
So then the erosion of that, that really combining those disparate data points goes away.
And you're left with what we call democratized targeting, really meaning like anybody could
do this.
If you look at Luigi was right, the CEO database from last summer, if you remember that,
you know, there were thousands of executives and companies that were docs.
They're professional and some personal information on this website, you know, really did a deep dive into who the individual was.
Identified the individual, no technical background, mid-60s, living in the middle of nowhere in a state within United States.
Very interesting, right?
And we were able to actually identify through a code dump of the entire website, exactly which AI model that the individual utilized to create the website, right?
So you start to see non-technical people doing very much more technical things, right?
And I mean, there's so many examples of that, Nate.
I mean, you think about, you know, GROC, which is XAI's model for AI, obviously was live doxing people on Twitter.
Somebody posted a picture of Dave Portnoy's house, said, do you know what this is?
Listed the address, right?
Viewed by a million people.
So then it's like, okay, cool.
Yes, GROC did that.
But really, it's like out of the million people or however many people viewed that post,
is there a catalyst in there that actually has something against Dave Portnoy?
So I think it dives really deep into Nate of like criminals do care.
about time and resources at the end of the day.
Like they are losing, you know, money.
And like I think deeply about really the St.
Felix group,
which really started with the Moss family out in Durham with a lot of this initial kind
of crypto targeting.
They were originally targeting through SIM swap attacks,
which take a lot of,
it takes a lot of time.
You have to collect a lot of data.
There's a lot of social engineering.
And then they moved much more to,
hey, like,
let's see if we can actually get this data on leaked databases
or where can we like reduce friction for ourselves.
So when I think about,
privacy and I think about security and what we call the convergence and we say that word way too
many times in the space is that understanding that you do have to reintroduce friction because
unfortunately the system by design has removed all this friction and it's like it's not so much an
Orwellian situation of like Big Brother. It's more the Kafka, the trial side of like you're part
of a system doesn't really care about you, cares about your data and then unfortunately people
are poor stewards of your data. That's incredible. I'm actually curious, Chris,
if you have any information regarding the Sam Altman situation.
One, if we have any idea of what the vulnerability might be there,
and people who might not be familiar,
could give us a little bit of a rundown of what actually happened, what transpired.
Yeah, of course.
And this is widely on the news as well.
But, you know, somebody showed up to Sam Alman's residence over the weekend,
threw a Molotov cocktail at the residence and then went to Open AI's headquarters
and, you know, was causing a disturbance there as well.
You know, the big piece here is really just understanding maybe this person,
young person, by the way, like this person is young. You know, you're starting to see this a lot more.
You start to see the teenagers. You know, if you think about a lot of the larger ransomware groups,
a lot of them are young people that are digital natives and now becoming AI natives as well.
You know, they can become, you know, they can lean into ideologies that may not have been
easily accessible and they are much more easily accessible today. And so the concern there is
similar to what Luigi Mangione did when he murdered Brian Thompson for the United Health Group back in December
for 2024 is really this, what we call lionization of the ideology there of, you know, after that event,
obviously I work at 360 privacy. We focus on ultra high net worth. We work in 40% of the Fortune 100.
Like that is, that is my world. When I look at how many people I had to then do investigations on
that posted on Twitter X all over social media, I have $50,000 ransom on the head of insert Fortune
100 CEO or board member or executive, you know, you start to look into the people and it's like,
This person doesn't seem like a threat.
But this person could be the catalyst or the event that leads to somebody actually taking down that ideology and moving forward with it.
And that's always the concern.
Because when you look at what AI is doing, democratized targeting is doing, there used to be this window, Nate, where I could say, okay, this person is going through this attack cycle.
We caught them when they were casing the residence.
We caught them doing XYZ.
Now it's like they can case your residence on zillow.com or redfin.com, any of those that have interior photos of
your home, right? Not calling out those websites specifically, but just saying like, you know,
it's easy to see the interior, you know, layout of a home, right? And so it's like as that
information is just so much more readily available, more people can now utilize that. They don't
have to have the deep intel backgrounds, targeting backgrounds. And then it's just this quick now,
that window of where you used to kind of have opportunity to identify patterns, those patterns are going
away, which as we kind of talked about earlier, Nate, when we think about the annual threat
assessment, that's something that we can talk about later in this session as well.
No, that's wonderful. Thank you, Chris.
Wayne, I want to pose kind of a question to you because the last time we hung out,
we talked a lot about the things that we could do to prevent and to like up our privacy and security.
And we will cover that information here as well too.
But just to get an idea of what's kind of what processes are going on, what the attackers are actually looking at,
if you were going to target me, Wayne, if you decided I'm going after my buddy, Nathan,
what would you do?
Where would you start?
Yeah, open source information, right?
And it's funny, you ping me this morning, right?
that you might law off that question my way.
And so I was I was in the Uber on the way to the office here.
And I just did some open source digging on you, right?
And I used chat GPT.
I use Claude.
I use perplexity.
I kind of referenced some of it with the open source.
But in like five minutes, you know, I was able to find, you know, members of your family, right?
Like your background's pretty, pretty like locked in because, you know, obviously, you know,
you've got a big face and stuff like that.
You have the podcast, but it was,
it was pretty easy to find information on,
on related family members and tied addresses and places their work in and stuff like that.
So that's where I would start, right?
So I would, I look, I look, I look,
being up in Canada, it's a lot more locked down.
Us in the United States, I feel like, are a lot more vulnerable and, and, and,
really, I want to just pause on that for a second.
And why is the U.S. more vulnerable than Canada?
I would have assumed the other way.
Yeah.
You know, it's, it's kind of surprising to me, too.
And a lot of this kind of comes from like, you know,
and it stems to like the crypto, right?
And the regulations and all that, like the know-your customer,
the K-Y-C laws and stuff, right?
So where like, and the U.S. is really kind of trailblaze this, right?
So they're a little bit ahead of Canada.
But it's, this stuff in Canada is going to,
you know, be easier as well. But like, you know, in 2009 through 2012, you could just trade anonymously
on, you know, these platforms and, and, you know, buy these things. And then, you know, 2013, the IRS got
involved in the treasury. And, you know, they started, they started making, you know, these crypto platforms
following the banking rules, you know. But that was really just the initiation phase, right? And then kind of the
2015 to 2017 role is where they really started adopting it and started enforcing like this information.
But, you know, there was a big case in 2017 where the IRS forced Coinbase to hand over all the user records, right?
So now the government has access to who's trade in and where they live and, you know, what they're doing.
And, you know, from 2018 to 2021, that expanded globally over to Europe and the other countries.
And then really kind of from 2022 to now, it's been like fully integrated, right?
So your data is available.
Like a lot of people are naive in the crypto space and they're like, you know, this is the reason I'm into this is because it's so private.
And it's just not the case anymore.
Right.
So there was in 2025 last year, there was a Coinbase brief.
reach and over 70,000 customers had their information leaked.
And that's in the dark web, right?
There was the ledger leak historically where a lot of people went there.
Right.
So now, right?
Like you look at like information.
I look at, you know, Target and family members.
If I was, if I was a bad guy, you know, what, what, what is special to you?
Right.
And then there's also other things, right?
There's, there's more than just the data leaks from Coinbase and stuff like that.
Like, you know, a lot of, a lot of crypto holders will have, you know, K&R policies,
like kidnapping ransom policies through insurance companies, right?
So Lloyds of London is a big one in the crypto space that covers, you know, crypto holders,
right?
But like, again, if you're on a K&R policy and that information is leaked, you know, and I'm
a bad guy, I'm going, okay, well, they have an insurance policy.
So if I grab Nathan's mother, right?
and I know he's got a K&R insurance policy,
this is going to be like stealing, stealing money from a baby.
Like this is, this is easily accessible.
And there's common themes in a lot of things, like I said,
people are hacking Uber Eats accounts, you know,
and going down that road.
A big thing we're seeing right now with a lot of homes in the L.A. area
and Beverly Hills is Wi-Fi jammers, right?
So people have, people have good access control and good camera systems.
and, you know, alarm systems,
but there's jammers now that you can buy very easily
and you can go and you can shut down the cameras
and alarm systems on a home, right?
Oh, wow, I never even thought about something like that.
Yeah, and this is, it's just a new modern technique, right?
Next year there'll be 10 other different ways to do it, right?
So it's staying informed.
It's staying informed.
And this isn't something that people should freak out about
and be scared about, but, you know,
when we talk about crypto security specifically, there's three layers to that, right?
It's there's the digital operational security.
There's the physical operational security in your wallet architecture, right?
So, you know, companies like ResCorp group with me, like, you know, we really kind of heavily
focus on the physical, right?
And the consultation piece, like, hey, look, these, you know, we should probably hardwire
the camera systems on your own if you hold this much in crypto and we should do this, right?
And then, you know, we use companies like 360 privacy and Chris and we set them up with our clients.
And it's like, all right, you guys handle the digital operational security.
Clear this information about Nathan's family online, right?
Like, let's go and make sure that this information on the dark web and the stuff that's been leaked isn't there.
And like, let's talk about your wallet architecture.
You know, let's make, you know, coercion useless if there was an attack.
Right.
So there's different layers to this.
And it's, you know, whatever plan and whatever steps you take this month, you're going to need to adjust next month.
Right. So it's, it's just a constant evolving thing. And it's important to have kind of the right people informing you on things, right? And, you know, a lot of our clients, we get a lot of phone calls about people going on like France and Paris and stuff like that because that seems to be a hotspot for crypto attacks, right?
So there was a tax authority leak, right? They had somebody inside the tax authority that was leaking the information.
regarding who had paid taxes regarding Bitcoin and crypto.
Yeah, right?
So it's this information's, you know, out there.
It's not, it's not hard to get, right?
And then you get the basic information that you want and you can go on the dark web
and you can buy the rest of the information at a very cheap rate, right?
So it's a scary world we're living in right now, but there's cost effective ways to protect
yourself and your family.
And it's important that everybody does their own due diligence and, you know, is paying attention to these things.
No, I completely agree.
And yeah, for anyone, security for me, when I'm, you know, consulting people is always kind of a moving target, right?
Kind of where are you?
Where do we want to be?
And also, I'm very conscientious that more Bitcoin has been lost than been stolen.
So trying to balance those scales.
But yeah, if you're talking about a substantial amount of Bitcoin that you're holding,
that we definitely should be looking at least in something like a multi-sig or a multi-sig or a multi-sig or if I want to be super hyper paranoid or sorry,
a collaborative multi-sig as well, too.
and there are a lot of great providers out there that I'm comfortable recommending.
Chris, I want to kind of dive a little bit more in on the privacy side.
And the question I had for you is, one, when you're doing research for a client,
if you're trying to figure out what information is out there and available,
how are you doing that and what sort of stuff are you finding?
And then additionally, is something like,
because then if there's just paid services or you can go and request like brokers,
erase your information, I forget the proper term is,
but you can request like data be removed.
Is that sufficient for people to do?
Yeah, no, that's a great question.
and just to quickly touch on some of the things that Wayne was talking about.
I think when we talk about targeting you and it's like, well, we found your family.
I think some of the listeners may be like, oh, okay.
But it's like the problem is really like who has keys to your kingdom, right?
And it's your family.
It's your executive assistant.
It's these types of people.
I mean, you look at it.
This is historical.
I mean, Zardikawi was found through his religious advisor.
Bin Laden was gotten through the courier.
El Mincho was caught through his girlfriend.
Nancy Guthrie, obviously, like, why was she the target?
And that's an ongoing investigation.
But again, it's like, you know, you think about even back to medieval times, a big history nerd, it's like when a king left the castle, he gave the keys to someone name a Castellan.
Was it castellan valuable because that was who he was?
No, it was valuable because he would, what he held, right?
And so it's the same way that I look at crypto here, I think there's this, this almost thought or like ideology that like, I'm a nobody, like nobody would care about me.
And like, or they do it the other way where it's just like, I'm just me.
Like, I'm out here.
And it's like, well, at the end of the day, like, if you think about, you know, we brought up the, the Moss situation earlier, that was just a regular person.
But it's like, no one cares about you personally.
They care about that number on the ledger that shows like, oh, this person has wealth.
And then they look at, okay, this person has wealth.
And maybe they're at the level of they have a Wayne.
They have a security company.
This person has wealth, but they seem like a normal retired, 70 year old high school physics teacher.
So like, why don't I go target that person?
Because the friction, again, it's the whatever friction, again, it supports them as well.
well. Now, to your question about targeting, you know, I think it's interesting, Nathan,
because every day it changes. But it's really unfortunate in United States, you could literally go
type first name, last name, city state, home address into a search engine. And you are going to
find people's home addresses, their phone numbers, their emails, their relatives, where they work.
Most of this information is free, right? You see Vance Bolter, who murdered the, you know,
individuals up in Minnesota last summer. In his notebook, he had 11 data aggregators, which are, you know,
lower from the data broker space, but a lot of those were free.
He even marked like, this one's free.
I need to search this one of the address, things of that nature.
Like the data is so easily accessible, you know, and so really what it becomes
name is like, how can you reduce your discoverability?
Because findability precedes targetability because it's really hard to target someone
if you can't find them, right?
Yeah, no, fair enough.
And it's like, and how much, how much time and effort is that, that group or those people
going to put into you because, you know, you think about, you know, the group that went from
SIM swapping to actually physical attacks.
It's like, that was a lot of work.
Whereas now it's like, hey, like, let's just go case these people.
Let's gain access to some of these email accounts, et cetera.
And then you brought up Nate, the Waltio, which is the tax platform in France that was,
that was breached.
You know, there's 50,000 users tax data was posted.
And even the French government came out and said users could be at risk of being kidnapped.
Now, one thing I do appreciate that the French government's doing is that they are almost
mandating what we would say is like education.
Like we will send people to your home to talk about this.
We'll send security professionals to check in on you.
We are working on how can we actually get that information where it's not required.
If you're a crypto holder, you won't have to post your personal address and things like that.
And so part of the problem, Nonae is like in this space, when you think about AI, you think about quantum computing,
you think about how all of that ties into crypto.
At the end of the day, like, we're thinking about it linearly while the space is growing exponentially, right?
And so it's like legislation will never catch up.
So, you know, proactive looks different for a lot of people.
But, you know, first thing, to your question, like, how do I target people?
There's a lot of weird things that you can do.
Obviously, just Google and find them.
You can use GROC.
You can use some of the other AI models.
Some are different than others, obviously.
And that's what I spend a lot of my time researching.
But a lot of times, day, is the things people don't think about, right?
Like, what do you have on your LinkedIn?
Do you have your actual city and state where you are?
Because then all of a sudden, that search engine pivot, a first name, last name, city,
stay home address.
now I can do that just from your LinkedIn profile, right?
Do you leave Google contributions because public contributions are public?
I can use that to build pattern of life analysis on you, right?
So it's like, I think people get caught up in like there's open web and dark web and like all this spooky.
Like it's not spooky.
Like this is literally just really easy to do.
It's very unfortunate that it's so easy to do.
But I mean, you have some of these data aggregators actually have your Amazon wish list
because by default, a lot of these types of things are public.
So a lot of times that will get aggregated.
That'll get aggregated connected to your old social media accounts.
So all of a sudden in like a free profile or maybe I take 20 bucks a month for unlimited profiles,
you know, do I have your Amazon wish list?
Do I have your entire family ecosystem, right?
Like do I have where you work?
I have your old email account.
Like think about the Cash Patel event recently where.
Oh my God.
Yes.
Yeah.
There's like a lot of really cool.
Like the signal scam is going on right now is really good to talk about Cash Patel's
Gmail account and then DarkSort.
right, which is an OS exploit for iOS exploit for the iPhone.
There's like a lot of really interesting things going on in the space.
But when I think about Cash Patel, it's like, you know, there's argument that his Gmail had been in 11 different, you know, breaches, leaks, some type of records that, you know, the Hyundai group may have actually just logged in, right?
So you talk about account security.
A lot of our listeners are going to be like, 2FAs like, you know, that's the standard.
But then you started talking, moving like, okay, well, let's talk about hardware keys and like why that matters, like you've a key.
or Titan keys, you know, depending on what you want to use, your flavor, your, your, your,
place, you know, but it's like, Cash Patel is like, yeah, it was an old email account, but it's like,
it's a junk drawer. So it's like, if you think about it for listeners, like, how many of you
have a junk drawer that's digital? And if somebody got access to it today, like, what are you
losing? Like, do you have receipts? Do you have family photos? Like, obviously we saw from Cash
Mattel's that he did. And so it's kind of like thinking deeply now about what data do I need to actually
store. And if I do have an old email account, do I need that? And, like,
Like, yeah, it may take you time to go close some of those old accounts, but it's like, is it worth it to you, right?
It's like really like what is that, you know, what I see with a lot of my clients, convergence of convenience and security.
Something gets inconvenient.
Security usually goes first.
And so it's more of like, what can you do?
And so to your second question, Nate, when you look at reducing discoverability, you need a program that's focusing on search engines.
And that's what a lot of these companies aren't doing.
They're like, I remove from 1,000 data aggregators.
And it's like, A, what information are you sending that data aggregator?
Like, did you confirm that they have my information?
You know, where is that data?
Like, who are you communicating with?
What of my personal information are you sending?
That's like the first question.
Second question is like, cool, you removed a lot of things from the route.
But what if Google's indexing sites that you don't remove from?
Or if Google, that's a dead link, right?
It needs to be de-indexed and Google needs to reset the cache.
At the end of the day, like, how long does that link stay up where a preview still shows
me, your home address, your relatives, your phone number, right? So you need that.
The other thing that's interesting with AI research right now, Nate, and please cut me off
whenever. No, please continue. There was some really cool research out of a company called Grow and
convert where they're looking at like kind of this idea of like, is search engine optimization,
like dying, is it dead? Now we're looking at LLM optimization, like Jim and I's giving you
summaries on Google and things like that. So they had 400 keywords that they search. And
those 400 keywords always come up on the first page of Google.
And so what they found, they were testing perplexity and they were testing chat GPT.
77% of the time, those keywords were also coming up when prompted in those AI models.
And then they went and looked at if it was the first three results, which are your highest fidelity
results on a search engine, it went up to 82%.
Therefore, we're seeing LLMs obviously are pulling from the highest fidelity data through a
process called retrieval augmentation generation, which is just, hey, this is good.
data, I'm going to pull it and show it to the user when they prompt. So at the end of the day,
that's so important because if you're not focusing on reducing your discoverability, it's like,
cool, you removed a bunch of stuff in the background, but somebody can still come through the front
door. When I first got into Bitcoin, I was overwhelmed. The jargon, the security risks,
the fear that one mistake could cost everything. I remember staring at my screen and wondering,
are my keys safe? Did I do this right? That experience is why I started BTC sessions. For over
a decade, this channel has helped millions of people like you learn how to use and secure
Bitcoin. But I realized something. For many people, videos aren't enough. Everyone learns differently.
Some need to ask questions in real time as an expert walks through their setup, their goals,
and their threat model. And certain things like advanced cold storage, inheritance planning,
privacy, and node or mining setups often can't be fully solved by watching another tutorial.
So I built BTC mentor.
I recruited the best Bitcoin educators on the planet to work with you one-on-one.
Real experts, real answers, personalized hands-on guidance, tailored to your exact situation.
Whether you're brand new or building a complex setup, we meet you where you're at and walk with you step by step.
By the end, you don't just hope your Bitcoin is safe.
You know it is.
If you're ready for that level confidence, then head to B2BTCHA.
BTC Mentor.io and book a call with us today.
Jeez.
Okay, there's a few things that I definitely want to touch on.
First and foremost, Chris, which chat app are you using?
That's a great question.
So it depends on the use case, right?
And also to our listeners, like what you put in a chat app,
whether it's your personal or your professional,
it's enterprise account, there are differences.
If you want to get really nerdy, is it in bedrock?
Do you, did you really download your own weights and you're using like an open source model or just running your own model in that way?
So, Claude 46 as far, Opus 46 is the best at research right now.
A lot of people probably saw from our listeners, Claude Mythos, which has not been released.
There's Project Glasswing.
I do have, you know, obviously a lot of friends in this space.
So have some other knowledge about that project.
Very interesting, right?
When Claude Opus 46 comes out February 5th, it was able to identify 500.
plus vulnerabilities in open source code.
Mythos, what they're reporting is thousands,
is just the world thousands, right?
And so now you see a group called Project Glasswing.
You have the people you'd expect,
the AWS is the Googles, the Crowd Strikes, the Cisco's,
the J.P. Morgans.
They're getting early access trying to look at
how can we utilize mythos to actually,
A, like keep it safe from, you know,
the malicious actors that could use it,
but B, like, how can we use it to better protect
our critical infrastructure?
because if we're creating a model like that, we have to also assume there may be other nation states that have similar models.
So, you know, this is an exponentially growing field.
And so when I look at that, you know, you start to see Anthropic is really, really pushing ahead.
Obviously, they had some issues with the current administration saying they were a supply chain risk.
And this is not meant to take a, you know, a political stance.
That's just exactly what happened.
So then Open AI stepped in and kind of, you know, took over that contract.
again, not a political statement.
But it is very interesting to see in the space.
You know, you have perplexity who really started as you just give a prompt,
we'll pick the best model, and then they trained their own model.
So perplexity for like an everyday browser is very interesting.
You have OpenAI comes out with the Atlas browser, right?
It's very interesting as well.
Now, if I was digitally targeting somebody and I was being paid to do that
because in a legal way, GROC is 100% the go-to because GROC in my opinion,
Grock lives what I would call the practical obscurity that we talked about before.
He lives that to the fullest of if the data is findable, it's findable.
And so there's actually some interesting research in December.
There was a group who just prompted Gronk 33 names.
It literally just said name, address.
They did it 33 times.
And I believe it was like 17 out of those times.
It actually brought up like legitimate either business address, personal address.
or old personal address.
Only one out of 33 did it say, like, I can't do this, right?
And a lot of the listeners will be like, well, you can get around that.
Yeah, of course you can.
Like, you can literally say, like, well, I am the person or I'm a red team targeter, right?
Like, there's a lot.
And I don't want to go into like how to exploit.
How to get around here.
But, you know, at the end of day, I would use GROC because, you know,
and I use this with security teams to say, hey, you have to assume if there's a free model of any AI,
people are using them.
Threat actors are utilizing them.
So you need to look at what the model is pulling back on your principle and actually use that as like a checklist to understand like, oh, I can actually go affect to this. I can go change my LLC. I can go do these things and then start to see how that data changes. I was actually on a podcast exactly like this about a year ago, Nate. And the host was like, Chris, like, if you target me with Grock or one of these AI models, like, what would you do? I was like, well, a high fidelity source is typically linked in a lot of times, especially you have it verified. It's been there for a long time. You know, with one prompt, it was pulling.
up he lives in this very specific suburb of Boston because he had Boston, the very specific
suburb on his LinkedIn. And then that connected the disparate data points to data aggregated
records. On the podcast, he changed it live. Next day, same prompt. It just said like, because he has
a very John Smith name, right? It just said like in Boston based upon LinkedIn, but I can't find,
like, yes, you could go down the rabbit hole. You could continue to target. But again,
reintroduce friction by design is really how you can better protect yourself,
privacy and security-wise, physical and cyber.
Very cool.
Wayne, I want to ask you quickly,
when you're talking to your client specifically
about sort of digital privacy and digital security aspect
of their physical security,
are you using things like Ub-Kee and Titan Key?
Is something like Google Authenticator sufficient?
Are there any physical tools that you're putting in their hand as well, too?
Yeah, and honestly, we don't really make a ton of recommendations in that space
just because there's subject matter experts that do it a lot better than we do.
You know, we really focus on kind of the physical protection piece, right, and and being proactive about putting those resources around you.
But like, like, you know, Chris was saying like these databases, they're basically just centralized honeypots of information, right?
So it's for us, but like, you know, we'll have people and our clients will come to us all the time.
And they're like, hey, we want residential security at our house 24-7 and we're worried about a threat.
Or we want someone to drive us, you know, Monday through Friday to the office.
And for us, like, we don't even want to take a project on or take a client on until their digital security and their digital footprint is secure.
Right.
Because like, and yeah, it's probably not the best business model for me, right?
because I could just put residential security on and start charging, you know,
tens of thousands of dollars a month and be fine and just look the other way.
But I want to make sure that you're not, you know, easily accessible and you're not, you know,
vulnerable.
And so we use companies like before we even get started, we'll do an initial risk assessment, right?
And we'll come in and we'll take a look at this stuff and we'll see what type of protections you have on your, on your, you know, IP and your software.
and all the stuff we've got it going on at your house.
And we bring in other organizations, you know,
we bring in companies like 360 privacy.
And we bring in companies like bashing projects is a really good one that we use a lot.
Right.
And these guys are subject matter experts in this, right?
So they'll, you know, kind of come in and do that full scale protection model
around digital and your pass codes and all that stuff around you.
And then once all that stuff's secure, now it's like, okay, cool.
now let's focus on the physical piece, right?
Let's focus on kind of the game plan and everything to, you know,
make you not be a soft target, right?
So that's basically what we're doing.
And we're looking at your schedule, right?
So like, you know, circling in on crypto specific, right?
If you're going to the Bitcoin conference at the end of the month in Las Vegas,
there is going to be threat characters there.
Like there's going to be people there that are paying attention to who's going,
you know, and where they're drinking at at the bars after and hanging out with their friends.
Like, you know, the Bitcoin conference being in Sin City is like, you know, it's kind of like,
it's just a breeding ground for someone to become a victim, you know, for something.
So it's just, it's interesting.
And all these things kind of go together, right?
And we try to explain it all the time, especially to like estate managers and executive assistants that are like,
hey, no, we need a security driver.
The Sam Altman thing this weekend really made us nervous.
So we want somebody to start driving our boss to work and we want someone at the house.
And it's like, yeah, you know, what we need to do first.
Absolutely, we can do that temporarily.
But we need to really like look at, look at kind of, you know, everything from a, from a holistic view, right?
And it's it's like going to the doctor.
You could go to the doctor with, you know, hip pain, right?
And, and you're like, hey, I want some painkillers to deal with this hip pain.
and, you know, maybe some physical therapy and see, but, right, the real problem stemming from,
like, a slip disk in your back, right, that you didn't know, right? So you need to kind of do these
full-on assessments and really kind of see, you know, where the actual issues align. And, like,
you know, we, a lot of times these, you know, people, they think that, you know, they know,
they know the answer to something and like, hey, we'll just, you know, and this happens a lot
with, like, corporate security directors and people that are high up that, you know, it's, it's,
it's a world now, everyone like works remote and they make their kind of, they put their opinions
and they're not really kind of on the ground on the day to day. And they'll increase security
for something after, you know, the United Healthcare incident or they'll increase security after
the Sam Altman incident. And it's like, you know, security's like wearing a seatbelt in a car,
you know, just because you haven't gotten a car accident in a year or two doesn't mean you take
your seatbelt off. Like this, this is something that we should constantly be proactive about. And we
tell it to, you know, assistants and nannies and stuff all the time. And it's like, yeah,
you know, you might be able to make a grilled cheese. But like, you know, like you, but you're not
a chef and our executives like the dinners from the chef, right? So like, let the security kind of
team come in. And it and it shouldn't really be a one shop, you know, one size fits all type of
ordeal. Like there's different, you know, there's different entities. Just like with family
offices that we deal with, they've got their nannies and they got their assistants and they
got their estate managers and they got their pilots or they got their, you know, their legal
council team. And they've, you know, they've got different avenues. Your security should be built
the same way, right? So you've got your physical security kind of consultations and stuff like
that. And you've got your digital security experts and you've got, you know, there's different avenues.
And this stuff seems difficult and it's intimidating to a lot of, you know, high net worth families.
Is it like this just seems like a lot.
And really all it is is just having the right kind of consultation and really just having
the right people there to inform you.
You know what?
You know, I'm not really sure if your passwords are protected in the right spot.
That's not really my avenue.
But here's the top three people that deal with this.
Why don't we, why don't I get some quotes for you, right?
In the meantime, let's, let's think with Chris and have him see what's kind of, you know,
online about you guys and your family and everyone else.
So it's a collaborative effort, right?
And we use the word security a lot and executive protection or physical security.
And a lot of people just kind of stem it to like bodyguard work, right, where you've got kind of somebody just sitting next to you and doing these things.
And it's changed, right?
Executive protection now is a science, right?
It's not just having some, you know, seven foot tall big guy with an earpiece following you around all day.
That's reactive.
That's not what we want to be doing in crypto.
That's not what we want to be doing.
And, you know, physical security.
Someone wouldn't do it at all, right?
Like if I'm a famous rock star, maybe that's the right way to go about it.
But like if I'm an executive or I'm a businessman, a family man, it's like we need to be ahead of these things.
Right.
There's, you know, and it's not just like, you know, the crypto attacks.
There's, you know, so much stuff going on in the world right now.
There's, you know, drone, like, you know, the big thing that you talk about.
about with Anthropics, it's, it's, you know, over drones and stuff like that.
And who has access to these man's systems and does the government have access?
And so, you know, staying up on kind of all these current events that are happening and being
able to kind of build that wall around everything that's going on is just, it's so important
now more than ever, right?
And it's, it's not something that costs millions and millions of dollars or even hundreds
of thousands of dollars.
Like there's ways, right?
Like, you know, that you can, you can do this.
at a very small budget, you know, and granted, you know, depending on how much and what you
want to do, that expands. But no, it's a, it's a crazy time to be alive. And people need to just
start thinking about this stuff more moralistically and proactively. Well, I'm kind of thinking
about it. So, Chris, I want to come back to you in a second. I do want to talk about the signal
scams and Darksort as well, too, because I really want to dive into what those are. But before I do,
I'm going to be at Vegas doing some educational workshops with Venn. Very excited to be there and to be
coaching people on how to use the Bitcoin tools properly and what they can do with them.
So if we're looking at me, Wayne, is there anything that, like if you were consulting me on
security going to this event, and you mentioned that there will likely be threat actors there,
one, how would I be on the lookout for threat actors? And is there something that I should be
considering? Or what would you do? If we were like, okay, here's what the plan is. Here's what I
think you should assess. Here's what, just a rough outline. What should I be considering for my own
security going to one of these events? Yeah, honestly, it's the things that you associate yourself with.
right like I'm going as well right and like for example like you know we're a sponsor
Rescores a sponsor of the of the conference this year and we're doing a lot of hosting in the
whale lounge and some of those events right so with that came like the whale lounge access and
and the tickets and and the stuff that goes associated with that but I'm getting emails of every
single person that also has a whale ticket right and I'm really I'm getting their names and I'm
their information, right? And there's an app you can download to try to coordinate and have
meetings with them and sync to maximize your time, right? And, you know, and then they've got also
too, the room blocks and stuff like that. So I'm looking at this, right? And it's like, all right,
if you're staying at the Venetian and Palaz, if I'm, you know, you've got everybody, right? You've
got like the organized crime groups that I'm sure will be paying attention. And then you've just got
the regular, like, regular, you know, low life kind of criminals, right? But like, if you're,
if you're kind of on that lower side of things, right?
Like, I would not be going to the after-party events at the bars at the Venetian and Palazzo.
I would not be hosting meetings in the area.
Like, I'm going to, you know, kind of try to prioritize things off the X a little bit.
Right.
So, you know, it's one of those things.
Very simple.
Be careful of even those simplest things on like what Wi-Fi's you log into, right?
At that hotel or like, you know, they could very much set up.
up a fake Wi-Fi, you know, Venetian, oh, right? Like, there's, there's so many different,
like, things to just kind of have some situational awareness on, right? And kind of be careful of,
like, who, who you're surrounding yourself with, where you're staying, what networks you're
logging into, right? Like, if you're going to, you know, something where even the workshops,
like, you know, the bad guys could target and see what they're talking about and be like,
all right, like, these people are vulnerable. They don't know this stuff, right? That's the
reason they're here or these people are bragging about it and that's the big thing like you'll find
the people that want to brag about the bags and the stuff they hold that do not talk about how much
bitcoin you have the love of god do not talk about how much bitcoin you have it's it's and it's and it's
crazy too and you think you don't have to like bring this stuff up but i guarantee like me and you like
and once this wraps out we'll go grab a beer somewhere and we'll just go sit at a bar and we can just
identify soft targets i guarantee it you know so it'll it'll be a good time and i'm looking
or to sitting in on your workshop and seeing you there and doing some of the whale events.
But, you know, that's why we're there.
We're there to try to educate some of these whales and some of these and then everyone else.
That's, that's, you know, just going for the educational piece and just being proactive with that stuff.
So it's, it'll be a good time.
But it's also, too, it's interesting to, you know, scale the room and identify these things and figure out like, you know, we do it.
team's going. We'll have probably six people from our team there. We'll go and we'll just start
identifying soft targets because it's what we do. Right. But also too, like even even outside of like
attacking your wallets in your crypto space, right? Like this is a big event with, you know, government
officials and public speakers and people that are very politically aligned one way. And people like,
Right. Like there could be there could be attackers there that are have nothing to do with trying to steal your crypto wallets. Like, right? So you want to make sure like, all right, when you get and you're setting up your workshop and you're in the conference space, like no kind of your exits, know where you're going if something goes wrong. Because it might not even be targeted at you. But this is a big event that could be targeted with just or just a crime. Right. Like this stuff happens every day. So just kind of being aware of your surroundings, where to go, kind of having a plan in place. And, you know,
And none of this stuff is like crazy,
crazy things that you should, you know,
make yourself, you know, paranoid over.
But like, you know, when you get there,
you should, you should ask the questions
when you're setting up your base.
Like, all right, cool.
What access does people have access to?
Where do I, like, where do,
how do I get out of this conference area
of something bad happens, right?
And it's, it's a lot of little things.
But, you know, we'll talk about it too
when we get down there and it'll be interesting.
Coin Kite has been in the game for years, creating hands down the best and most secure hardware
when it comes to securing your Bitcoin.
The cold card Q is an absolute powerhouse and my daily driver,
and it's ideal for newcomers and advanced users alike.
The tab signer gives you a low-cost, user-friendly option for those just getting started
or for convenience when traveling.
You can head to coinkite.com and use code BTC sessions for discounts,
or simply scan the QR code on the screen to get started right away.
One company I like pointing people to when they ask about Bitcoin mining is abundant mines.
They were founded by Bo and Christine Turner after losing over half a million dollars to broken promises in the mining industry.
And they built their hosting model to remove the usual headaches.
With abundant mines, you own your machines and keep 100% of the Bitcoin you mine.
There's no revenue share, no hidden skim.
pricing is simple. One flat monthly fee covers power, parts, labor, and repairs. They also guarantee uptime. The machine goes down, their hash rate redirect system, routes hash power from their fleet, so earnings don't just stop. And every machine is insured at full replacement value. Everything is hosted in the U.S., powered by hydro, and mining equipment may qualify for 100% Year 1 bonus depreciation. Learn more at abundant mines.com
sessions. Beautiful. That sounds good. Yeah, I think you're right too. One of the things you
highlighted last time was just the risk of travel too. So whether it's like Vegas or it's Prague or it's
Thugano or it's Helsinki, I think particularly for Bitcoiners, anytime you're traveling to a well
publicized event, that's a public organization, at the very minimum you have to have that
situation on awareness. Just at least be aware of your surroundings, I think goes a long way.
Chris, I'm curious if there's anything that you have to add to that. And then I wanted to make
sure that we dove into the signal scam and Dark Sword as well. Yeah, absolutely. I mean, I think
you know, what Wayne's saying is, you know, it's easy to identify soft targets. I mean, when you look at really crypto attacks historically, you know, I think the difference between like crypto versus like your typical wealth investments is the fact that like there is this ledger that just, you know, it is a public thing, right? Whereas that, you know, my investments and like my bank statements and things like that is not by default public. So when you really look at like data brokers make you easy to find, AI makes it easy to correlate and then here really is this easy way.
that's public, you start to really see how easy it is to really kind of combine those disparate
data points. And so I think, you know, when I look at the coin base breach, you know, that was social
engineering, that was bribery that was, hey, like take pictures of accounts. And, you know,
if you send those to me, you get in dollars. So like, again, you see the human element. The human
element's always going to be the weakest link because you can get all your hardware set up and all your
software. But again, it's like, is the human going to click the link? Is the human going to respond
to the signal message to Russian intelligence service, right?
Like, there's all of these types of things there.
And so I think it's really just important to remember that education is important.
I think we hear the term education and people gloss over,
but it's like there is this inverse relationship and like technology is exploding.
And like our education of how to just use it in a way that doesn't make me a soft target just by
using that technology has completely started to diminish.
And so understanding education, understanding you start seeing a lot of these authoritative risk
frameworks for physical security are now mandating digital exposure assessments, which is showing that,
you know, cyber and digital is 100% fuel for fire for physical attacks because like I always tell
my clients, Nate, and it sounds morbid, but it's like you're literally one Google search away
from a digital exposure becoming a possible physical exploitation. Like, it's not that hard.
And so when you really start thinking about if you have data from, you know, a tax platform in France
or you have good data.
Like I think about the national public data breach, right?
Like that was 270 million unique social security numbers.
Into the day, it's like that was all the data you could want.
But again, like we're all part of a system where data is stored and we don't really have
control over a lot of that data.
So I think part of being proactive is, yes, reducing your discoverability, which we can talk about.
There's easy things that every listener here can do for free today that make you a harder
target, which we can get into.
And then there's things that you can pay for.
but it's like being proactive could be all of these digital things that you can do,
while also understanding that you are part of a system that could be exposed
because people aren't great stewards of your data, unfortunately.
And that's where Wayne and like his team and like what they specialize in.
Because I think a lot of times if you look at one without the other,
it just becomes reactive.
And so if you really do want to proactive, it does have to be holistic.
Oh, beautiful. Okay, we mentioned the signal scam specifically,
if there's anything we have to add to that.
And additionally, DarkSword, I hadn't heard.
of Darksword before. I think you said it was an iOS vulnerability. Yeah, it was. Yeah. So Darksword
was leaked on GitHub recently. It was actually an iOS vulnerability, which is a big deal. I mean,
you're talking about a nation state level exploit. You know, I'm not going to say it's the exact
same as Pegasus or even in that same ballgame, but it is nation state level. It is an iOS vulnerability.
And then, you know, obviously it's targeting older versions of your whatever model that you're
running for your operating system on your iPhone.
But the importance is, and one thing I like to tell clients and then people listening to it,
because a lot of your listeners are going to be very privacy-focused people, right?
And so what's interesting is when you look at Citizen Labs, Amnesty International,
these are like the gold standard of objective people looking at digital vulnerabilities
and saying these are things that we stand behind, there is a function on an iPhone called lockdown mode.
Some people know about it.
Some people don't like using it because, you know, it does kind of turn your phone into
what I actually appreciate, which is just a phone and not so much a computer.
But, you know, they actually recently came out after Dark Sword was leaked on GitHub.
Obviously, so we had seen this.
It's being used.
You've seen it used in obviously the Middle East and the Gulf, you know, a lot of different nation state levels.
What specifically is Dark Horse doing, by the way, sorry.
Yeah, so it's zero-day exploit.
It's really, it's very similar to Pegasus in that way.
It has six different exploits that it's looking at.
Most of them are zero-click.
You know, you get to a honeypot site.
zero-click, you know, and then all of a sudden your device is owned effectively,
similar to how Pegasus operates and things like that.
And you may, you wouldn't know.
It's just there.
But one thing that's interesting is like Amnesty International Citizen Lab came out with
independent research recently and said they have never seen an iPhone that had
lockdown mode enabled, have any sort of nation level, nation-state level malware on it,
meaning they've never actually seen a phone with lockdown mode, with Pegasus, with these
types of vulnerabilities because it reduces the attack surface of those vulnerabilities so much,
right? And so I think that's like really important because it's like, yes, does it change
some of the functionality of your device? Yes. And for a lot of my principles, I would never tell
them to do it. But for like a lot of your listeners, especially people in the crypto space that are
really like, what's the next level that I could go to? That is natural. I mean, you're starting to
see NATO actually is utilizing iPhones just out of the case with the security that they have.
Like they're actually cleared to operate at that level now. So it's like, you know, the security is,
good. Obviously, we can get into like how we feel about how it's so hidden and like, where's that
data going and like, you know, you had the mobile advertising IDs. They were on by default. Now
they're off. So where's that money? Like, they lost some money there. So, you know, there's always
those kind of theories and things of like, where's that money funneling. But at the end of the day,
like that is a really good research. And then the signal thing is important, especially for your
listeners, Nate, with privacy folks people. They're like, we use signal. It's end to end. It's really like
that kind of default app that people go to now, you know, and it wasn't so much like that,
you know, five years ago. It's like, you're using signal like you're a weirdo, right?
And now it's like everyone. It's like, I don't even have to ask people if they're on signal now.
But what was interesting about that name, like, I think, you know, size a, you know,
CISA, however you want to pronounce that, FBI, like they came out with a joint statement saying,
like, you know, this is not breaking the end to end encryption of signal. What it is is,
it's 100% social engineering. So again, education, human element really matters.
matters. I think what's important with this one, Nate, is if you just go into your settings on
signal and you go to privacy and there's a setting that you cannot be discovered by phone number,
right? What that does is even if, like, I have two phones, right? If I know that this one's on
signal and I change that setting and I put in that phone number on this other device, it says,
this person's not a signal user, do you want to invite them? So instead of that actually coming
through signal from this scam, it would have come through as an actual SMS text message, inviting
you to signal, which again, it would raise red flags of like, why am I being invited to signal?
The other thing is using username on signal versus phone number, right? You don't have to give out
your phone number now. They have QR code. They have links. Obviously, we can go deep into how I feel about
QR codes and links. But at the end of the day, it's like, if I am trying to exploit a data
broker ecosystem that's worth $300 billion, it's really easy to find both of your phone numbers, right?
but if you're a username that you created and I'm trying to be mindful of how much money I'm spending exploiting you to,
then I'm probably not going to like if you only use username, then all of a sudden that cuts that off.
It introduces friction.
So it's like lockdown mode is amazing for the iPhone for the exploit.
Understanding your settings at an app level are super important.
And then honestly made like a thing that people overlook when I talked about earlier like search engine discoverability reduction,
Google has a program for this, right?
And like, again, I'm a huge privacy person.
So if somebody says like, oh, there's a Google program to remove my information,
like I may feel a certain way about that.
But one thing that's interesting is like if you have a Gmail account, set it up however
you want.
You have a key, Titan key if you're a Google person for life, right?
Like, however you want to set up the security on that, what you do is you actually upload,
you can upload three names, three addresses, three phone numbers, three emails.
It goes 24 every 24 hours.
It looks for any index information matching your PII.
It tells you what you can remove.
You click remove.
It doesn't remove from the source.
but it removes that discoverability layer, right?
What I tell my clients is like, hey, you know,
if you're thinking about doing this for your family,
you don't want to pay for 360 privacy for your entire family,
go reduce the discoverability.
It'll identify, hey, maybe you had 15, arbitrary number, 15 results.
Now you can actually go to those 15 sites.
And instead of it feeling like this is a system you can never beat,
it's like, oh, these are little pieces that I can do that are free
that better protect myself, my ecosystem.
So then again, protect myself.
So there's a lot of like easy little things like that.
I think a lot of times with AI and quantum and all this and crypto, it's like people are like,
there's just too much.
We're part of this system.
Why is Canada protecting me more than the U.S.?
Like, you know, there's all these things.
But at the end of the day, it's like there's easy things.
Like change your LinkedIn URL.
Like people don't talk about that.
You can change your LinkedIn URL as many times as you want.
It says you can't, but I promise you you can.
And at the end of the day, like they use that to as part of an anchoring point for your ID
graph to say, hey, this is Chris Wingfield.
This is a phone number, his address.
because you can go search like a binverified.com, which is a well-known data aggregator,
you can search by username.
And they have compartmentalized like associated to Chris's username.
I have this phone number.
And it may not be as robust or profile.
But people don't realize that when you change that, you start messing up the Zoom
infos, the rocket reaches, the contact outs, all of those.
And a lot of that data is exactly what was in.
Luigi was right, the CEO database types of data.
So it's important to think like business databases used to be your business email
and maybe your, you know, desk phone.
Now it's your personal Gmail and your personal cell phone number.
So there's really easy things people can do.
Just to piggyback that, like those little things get people to move on from you, right?
Like it's simple.
Like, granted, like, if you're a bigger target and there's an organized crime, like that, that's
different.
But for like most of the listeners, like, that are on this podcast right now, just putting up
a couple of like, you know, proactive measures like Chris just talk about.
People are going to move on.
Like they're going to be like, all right, this is a little like,
I spent my three to five minutes trying to find this information.
I'm not getting what I want.
Like,
I could probably get it,
but I don't want to waste the time on it.
Let me move on to somebody else,
right?
Because you find,
you find the,
the undisciplined ones online, right?
The people that are undisciplined and have poor digital hygiene,
you know,
there.
And those,
those become your easy targets,
right?
So just a couple of those simple things that cost no money will just,
like,
it'll reduce your,
your percentage of being attacked drastically, right?
Just doing those simple things because it's simple because the guy,
the people want that information that's easiest and most,
most accessible because they know you probably don't have follow on measures.
If they can find that info.
Yeah.
Oh, I ever even thought of that.
So I was thinking from the perspective of like,
if it's remotely difficult,
there's enough targets out there,
you just move on to the next one.
But I didn't realize that it's also a signal that if you've done that,
you may have done other things.
Yeah, it's a flat, right?
it's hard as well to do it.
It's a flag.
Just move on here.
100%.
Chris,
I want to ask you quickly,
and then I want to talk
about the annual threat assessment.
Do you ever,
is there any value,
do you ever do, like,
insult the earth with bad information?
Meaning that, like,
the internet is forever.
I can imagine it's quite difficult
to continuously be scraping this information,
hence, like,
you have your paid service and stuff as well.
Do you ever purposely put out
incorrect information
to try and leak bad data?
Does that make sense?
Yeah.
No, it makes sense.
And it's genius.
And yes.
And the whole purpose is like the data broker ecosystem
is meant to aggregate on high fidelity data.
So once you can identify, what are those high fidelity sources?
If I can get something high up on a Google search, then I know that data will start to go through, right?
You think about you purchase a domain.
It's like, who is record, right?
A lot of people get those redacted.
But if you want to buy a domain, leave that not redacted, you don't realize how many scrapers
are actually going through taking that data, putting that in data lakes, and then that
starts the churn, right?
Big thing like I just brought up changing your LinkedIn URL, what I brought up at the
very beginning, right? If you use someone's LinkedIn to just do first name, last same city,
stay home address, do you have to have your city state on there? Could you have, could you,
Nate, have United States? Could you pick a random state? Right, exactly, right? Because at the end of the
day, I know that they're using that LinkedIn URL and the information there. I mean, how many times
are these public sites scraped? Right? I mean, nothing against LinkedIn. It's just like,
if you have public sites, they're going to get scraped, they're going to get posted on the dark web.
So one thing I actually talk about a lot, Nate, is I think people hear dark web. And it's similar to, it's just
like, they're like, oh, no. And it's just like, oh, no. And it's just like,
It's like, hold on.
Like, think about what you can control, right?
If I'm always utilizing, like, and I love that Apple does this.
They have Apple hide my email.
Obviously, if you want to talk proton, proton aliases and like the whole nine of like going deeper into that privacy rabbit hole.
But I cloud.
I can send emails from something that isn't my email.
It's hide my email, right?
So no one actually has my email.
So the next time there's a dark web breach, it's like that email doesn't give you access to my iCloud.
So I don't really care, right?
then you think about like a privacy.com.
So you have virtual credit cards.
It's hard to like can.
I mean, it's not hard, but you have to call the bank.
You'd have to cancel credit card.
You have to get a new one.
Whereas with that,
it's like I can have that locked to this only gets $30 a month and it goes to Amazon.
So if it gets out there, I can cancel it easily on the app.
I'll just get a new privacy credit card.
Right.
Then you start thinking like, okay, virtual numbers, right?
You have a Google VoIP.
Obviously, there's a lot of different companies that do this.
End of the day, it's like, okay, then the next dark web breach that comes out.
It's like a phone number that's not.
mine, an email that doesn't trace back to me, a credit card that doesn't trace back to me,
I send everything to my house or I send it to a privacy box that has a different alias,
right? So all of a sudden, you start thinking about it. And it's like, yes, if you want to start
thinking about, like, things that Wayne and I would deal with, of like, you want to set up your
entire property where all utilities go through a different LLC and it's not, like, there is a lot
to that. But I think what I tell listeners and to my clients, like there's so many little things that
reintroduce friction that just make you a harder target. Like, yes, if you are the target, like that is
what it is at the end of the day. But it's like you continue to reintroduce friction. And then you have
Wayne's team on the physical side that's ready for any type of, you know, attack because they're
proactive about that from the physical perspective. So those are a few of like the tips I typically
talk about. It's just understanding there's small things you can do that make a huge, you know,
it feels incremental, but they actually make an exponential difference. Because you mentioned dark web,
I just want to quickly touch on this as well too. VPNs and Tor. Any thoughts on using those?
Yeah. I mean, that's a great question. Nate, I think, you know, a lot of
people, there's a lot of companies out there that are VPN companies. Then you start looking through
the privacy policies and it's like they say there are no logs on the website and the privacy policy
says that they got all these logs. They haven't been, you know, they haven't been audited by anybody,
right? Like citizen labs or Amnesty International hasn't come in and said like, you know, I actually audit
these people and they really are no logs and things of that nature. So I mean, I think it's interesting.
A lot of people are then get down to, well, could I just set up my own wire guard configuration on my own
server and kind of run my own configuration there.
Then you start getting into the DNS side of the house, right?
Like, end of the day, like, cool, but like, are you still using your ISP as the DNS
resolver?
Because that's like they're still, they're not seeing your content.
They're seeing your metadata, which is a historical argument, right?
We're talking Smith and Maryland in the late 70s.
Literally, there was, this was a ruling that the pin register of like your phone calling
my phone, that's not anything against the Fourth Amendment, right?
Because it's just like, it's just metadata.
It's not content.
Same reason the United States Postal Service can scan the outside of everybody's mail packages, right?
But like those inferences, people act like that's an anonymous thing.
That's pseudonymous at best, right?
I mean, it's very easy to say, like, me and Nate have been calling each other.
Maybe we're about to do a podcast.
Like, you know, you can really start piecing those disparate data points together.
So what I always tell people when it comes to VPNs, things of that nature, anything you can control personally,
especially as if you are a privacy, security-minded person that is very technologically advanced
to set things up personally, do so.
Then there's the next layer, right?
I think of a good, better, best.
Like, some people, they will use 2FA through a text message and an email,
but that's better than nothing, right?
And then it's like some people move on to the authenticator application.
And then you kind of have the other end of people using the hardware keys,
multiple hardware keys, multiple passwords, you know, all of those types of things.
And so it's like, I always say like control it you can control.
If you don't have that depth in technology, you know, go up one,
independently audited.
You can read the audit reports.
no logs, things of that nature and deeply think through that.
Because I think what's unfortunate in a is like there are the national public data breaches out
there. There are the KYC breaches out there where it's like, unfortunately, like that data
is legit because it was KYC or it was a data broker company and things like that.
But the other majority, which are just these lower level apps and things, like you don't have
to have things sent to your house and your name.
You can start utilizing some of these things that are, you know, native to your iPhone or
like Android, we can talk through that as well.
Obviously, there's, you know,
Graphene OS and a lot of operating systems
you could utilize on Android devices.
And then we work closely with a company
called Glacier Security.
They were, you know, national security type engineers
and they make hardened iPhones and Android,
and they do home networks and things like that.
So, you know, I control servers.
If I utilize them, I control the servers.
It's compartmentalized to me.
So there's a whole slew of things you can do
to better protect yourself.
Beautiful. I love it.
All right, gentlemen, I want to jump into the,
annual threat assessment. Chris, I'll get you to start that one off and then we'll get your
thoughts on it. What did you see in there? Was there anything that stood out? What was your take on
this year's annual threat assessment? Yeah. No, it's great. And like for the listeners that don't
read the annual threat assessment, that's obviously, you know, something the intelligence community
pushes out every year. And it's just to say like, what is the lay of the land from last year to this
year? And I think Nate, like a lot of people would get kind of lost in like, oh, okay, AI, quantum.
Like, you know, I think unfortunately we're starting to be like desensitized to those terms,
but it's like we don't realize like what that exploitation means.
Like you think about anthropic mythos and like what that model can do.
It's like now AI is very interesting.
And one thing I actually argue, Nate, is that we're not dealing necessarily with new problems.
We're just dealing with an ecosystem that is expedited by the exploits available through AI and the data broker ecosystem.
You know, these aren't new things.
Targeting people isn't new.
Even in the late 1980s when they brought up practical obscurity, John Paul Stevens actually,
He said, like, imagine a world where all this data is just available in one clearinghouse.
And it's like, now it's available in a lot of clearing houses to everybody.
And there's no KYC on most of these data aggregators, right?
And so when I look at the annual threat assessment, there was a lot of really good things in there.
But I think the most interesting piece to me is like if you distill down what AI means to targeting,
if you still down quantum and what that means to targeting is really what they stated is that
we are in just a connected threat ecosystem, meaning that things aren't really episodic.
anymore. It's just an ambient threat environment, meaning, you know, this event could be a catalyst for all these people with the same ideology. It's not as episodic. It's not as like clearly defined as it used to be. And of course, that shows like, yeah, ecosystem. It's easy to find people. It's easy to correlate. I don't have to be a technical person. I can utilize technical models to help me be a little bit more technical. So what you did is you remove this barrier and now you're left with capability is removed. You're left with intent at that point. So I think my biggest
piece is just the ambient threat environment is so important. And distill down, like, get through
the AI, get through the quantum, like those things matter. What does it actually mean? It just means that
there's a lot more people that can do a lot more things digitally, which could lead to more
increase. And we've seen it increase in physical violence. Wayne, do you have anything you want to add
there? Yeah, no, he touched a lot there. You know, for me, I'm just constantly looking at what's going
on in the world, right? And what's going on globally and then what's going on domestically. And,
you know, there's, there's, you know, obviously the AI and, you know, crypto and everything that
we've talked about already on this show. But just everything from like politics, stateside, to civil
unrest, to environmental disasters, to, you know, the wildfires in California that, like,
you know, the war in Iran, the war in Ukraine, like, there's just so.
much going on right now, right? That people, I just, I think people just really need a focus,
you know, on looking at security in a different space. And a lot of it is communication, right? And a
lot of people think securities, it's just a thing on an island that they should do. And it's,
it's communicating it with everybody, right? And it's, it's very important. Like, and we do it with,
with our clients and we do it with people that we consult for that don't have full-time security
programs, but it's all these things go together, right? Your security element should tie in
with your insurance policies and your insurance premiums and your security should tie in with,
you know, your, you know, financial teams. So you can correlate things with the IRS and get
certain write-offs and get kind of discounts and advantages on things. And they should, they should
correlate it with everything.
Right. And then and these things all stem out in the different areas and and security shouldn't just be something that like, you know, you, you, you, you spin up and do. But like it's, it's constantly coming up with different ways to help you with with everything, right? So protecting your home, protecting your home from environmental, protecting yourself from crypto, protecting yourself, you know, from things political, civil unrest, your travel, everything, right? So, no, there's there's a lot going on and and these things are going to.
change, you know, that the report, you know, that came out, you know, two months ago is going to be
different, you know, two months from now. So it's, it's important to constantly be staying up on what's
going on and not get sucked too much into the news and the headlines and stuff like that, right?
Like simple, simple consultation goes a long way and simple methods is important to stay up on.
Wayne, is there anything like low-hanging fruit, just like one or two, maybe three things that everybody could really start to consider or think about, we'll just say for residential and personal security, something that they should maybe, if they haven't looked at, maybe start to consider?
Yeah, definitely, right?
Definitely your camera systems, right?
Like, that's a big thing.
Like, it's a simple, simple design, right?
And I know I kind of talked about jammers and hackers, right?
But, like, you can, you can, there's so many different programs out there where you can,
just get, you know, simple, simple cameras and simple access and, and little things, right? And,
and again, just trying to clear that information online, it doesn't cost a lot of money,
but just being conscientious of things, right? Like, the little things, like the Uber eats,
like getting food delivered to your home or even taking an Uber, right? When I take an Uber,
I'd rarely go to my home address, right? It's usually associated with a different address and I'll walk,
you know, a block or two, you know, the other way. But like, now it's, it there's, I think we covered a lot of it right now. I wouldn't say there's anything like really, really specific. But it's, it's one of those things. Be careful on who you invite in your home, you know, everything from landscapers to pool cleaners. Like, I know I talked about it on your last episode. Like we've, we have clients that are billionaires that have MS-13 gang members that are coming on their property and doing the garden and stuff because they don't have proper checks and balance. And we've, we have, we have clients.
in place on these things. And, you know, I know a lot of these, these people listen and are
billionaires, but it's, it's this, it's the little things, right? It's, it's, it's everything that from
the stuff you put in your garbage can, right? Like, I live, you know, in the Bay Area and there's
people that go through my, my garbage, right? So like, making sure that even just the littlest things,
like, you know, putting some of your, putting some of that mail through a shredder before you
toss it in your can. Like, there's just little, there's so many little things you can do.
to just like, you know, that don't take much time at all to just be conscientious of
protecting everything around you.
Beautiful.
I love it.
Wayne, tell everybody where they can find you, check out your stuff.
Yeah, Rescor Group.com.
You can find me on LinkedIn.
We're located here in the Bay Area, but we've got offices in New York, Florida, Texas.
We're scaling pretty quickly.
Reach out to me on LinkedIn.
Go to our website.
Check us out.
We're constantly posting news articles and different videos and just trying to stay as informative as possible on things that are going on.
So, you know, definitely, definitely cue in on what we're doing and read some of the articles.
And it'll definitely help you deep dive and be proactive about things, overall security in your life.
Beautiful.
And Chris, where can everybody find you if they wanted some help with their privacy?
Yeah.
Which is kind of ironic that they have to find you.
Yeah.
Yeah, you may have to find me.
360 privacy.io headquartered in Nashville, Tennessee. I live up in the northeast in Manhattan,
so come by anytime. You know, the city life's a little different. The danger's up there a little
different. But yeah, 360privacy.com. Reach out anytime. I'm more than happy to take any questions,
and they won't be, you don't have to pay for that.
Hey, guys, thanks for watching the video. Just wanted to quickly let you know we're going to be doing
our annual Bitcoin Survival Workshop covering how to privately use and acquire Bitcoin, June 28th
in Banff. You can scan the QR code or check the link in the description.
to learn more, would love to have you there.
If you enjoy this episode with Wayne and Chris,
please do like and subscribe
and check out the previous episode
with Simon Dixon or the recent live stream.
