The Pomp Podcast - #1540 Jameson Lopp | How To Keep Your Bitcoin Safe
Episode Date: April 29, 2025Jameson Lopp is the Co-Founder & Chief Security Officer of bitcoin security provider Casa. This conversation was recorded at Bitcoin Investor Week in New York. In this conversation we talk about J...ameson being swatted, why he removed himself from the internet, steps to keep yourself and your bitcoin safe, projects Casa are building for bitcoin security, and tips to keep you safe while traveling. =======================The future is being built today and the future of currency isn’t dollars, euros, pounds, or yen, it’s crypto. And Gemini thinks that’s a great thing. Because a future where money is decentralized, inclusive, and globally accessible, that’s a future that we are anxious to be a part of. Go where dollars won’t. With Gemini. =======================Polkadot is a scalable, secure, and decentralized blockchain technology aimed at creating Web3. Created by Gavin Wood, co-founder of Ethereum, Polkadot empowers users to build decentralized applications with ease. Backed by industry leaders, making it a preferred choice for big names, Polkadot stands out as a leading choice for investors seeking a reliable, future-proof solution in the growing world of Web3 technology. Learn more at https://polkadot.com/.=======================Pomp writes a daily letter to over 265,000+ investors about business, technology, and finance. He breaks down complex topics into easy-to-understand language while sharing opinions on various aspects of each industry. You can subscribe at https://pomp.substack.com/=======================View 10k+ open startup jobs:https://dreamstartupjob.com/Enroll in my Crypto Academy: https://www.thecryptoacademy.io/
Transcript
Discussion (0)
What's up everyone? This is Anthony Pompliano. Many of you know me as Pomp. You're listening
to the Pomp Podcast, which is my effort to find the most interesting people in the world
and sit with them for hours while I ask questions in an effort to learn. So it would mean the
world to me if you would subscribe to the show on your favorite audio platform, watch
episodes on YouTube, and tell your friends and family about the podcast. My goal is to
help millions learn from the world's most interesting people. So let's get into today's
episode. Today's episode is brought to you by Gemini. The future is being built today,
and the future of currency isn't dollars, euros, pounds, or yen, it's crypto. And Gemini thinks
that's a great thing because a future where money is decentralized, inclusive, and globally
accessible, that's a future that we are anxious to be a part of. Gemini teamed up with futurists,
technologists, and designers like award-winning artist Matt Griffin, known for his illustrations
for Dune, to craft a vision of the future with crypto at its core. The creative theme,
Go Where Dollars Won't, emphasizes exploration, growth, and the crypto market's limitless
potential. Whether it's going on that Martian safari to capture an unforgettable photo of a
herd of woolly mammoths grazing the red planet, or using Bitcoin to pay for your lift pass to go
strata skiing down the mountain peak of a breathtaking comet. Whatever adventures we'll
be living, one thing is for sure. In a future this fantastic, the limits of traditional currency
simply cannot keep up. Financial innovation will usher in this new frontier. And so go where
dollars won't with Gemini. Go check them out at Gemini.com slash go where dollars won't. Again,
go check it out at Gemini.com slash go where dollars won't. Today's episode is brought to
you by Polkadot. Polkadot offers secure, scalable, and decentralized blockchain technology that
perfectly aligns with the needs of innovative projects. It was developed by Gavin Wood,
one of the co-founders of Ethereum and the creator of Solidity. Polkadot aims to build
an internet where users have full control over their data and their applications. Polkadot offers
tons of unique features, a shared security model, along with a new auction model and significant
implementations like ASIC banking. Given these characteristics, it's easy to understand why
Polkadot is gaining more and more traction in the cryptocurrency world. Some people even are
talking about it as the AWS of Web3. Now, companies such as Mythical Games, Astro Network, and over 50
other independent blockchains with hundreds of applications already leverage Polkadot's
technology to power their platforms. If you're looking for a reliable, scalable and cutting
edge solution, Polkadot seems to be the top choice for industry players. Go check them out today at
polkadot.com. Jameson, people don't know this. Well, some people on the internet know, but most
of the people here probably won't know. You've deleted yourself off the internet. And I think
the reason why you did it is because there's a physical security component. You were swatted
at least once that I know of, maybe twice. And for those that don't know swatting, maybe you can
describe the experience of being swatted and kind of what led you to deleting yourself and kind of
thinking so much about security. Yeah, only the one time. Swat me once, shame on me. Don't let
that happen again. Basically, this is a form of physical attack that is very low risk for the
attacker because they're not putting themselves in any physical danger by doing it. And it's
really annoying because for a very, very low cost, and we're talking like tens of dollars if
you have the right skill set and you know which tools to use, you can direct an insane amount of
state-backed lethal force at pretty much whatever target you want. And so that's what happened to
me. One day, I find myself, my entire 400-home suburban neighborhood barricaded at every entrance
and exit. Dozens of cops, SWAT team with their mobile headquarter command unit down the street.
And it was an overwhelming display of force. And because that's what SWAT does. You basically use
the correct trigger words. And in my case, it was, you know, shot people, had hostages, had
explosives, and I was going to hurt more people if I didn't get money.
Just so people understand, somebody called the police in your area and said,
at this address, all these things have happened.
Yeah, yeah. So swatting started out in the video game community, but essentially what it is,
is someone finds your home address, and then they pose as you or as someone who knows you
and says, you know, there's an incident, an active shooter incident happening at this address,
and this is the person who's doing it. And of course, in my case, I fit the profile because
I'm well known to have more guns than I can count. So it was plausible, I suppose, that I could have
done that. And, you know, thankfully, the incident ended well. It was actually a bit of luck because
I had posted something to Twitter when I was not at home and I was at the gym at the time.
And so the attacker thought that I had just rolled out of bed. And so I actually ended up
running into the police barricade coming back to my house. If that one little thing had been
different and I had actually been home at the time, my encounter with law enforcement might
have ended very differently. So obviously it's scary. And you go on this whole journey of,
I got to figure out what information is about me out there on the internet. I need to kind of
delete myself and really start thinking about physical security. Walk us through maybe some
of the steps that you took. And what I would love to do is kind of take us on a journey from
as far external to you, you know, security wise, all the way to what Kasa is doing with the actual
security of Bitcoin. But you first have to start with, can people find you on the internet? Can
they locate things? Like walk us through that journey. Right. And I mean, I still have an
internet presence, right? And I'm still here. I took the difficult path. The easiest and smartest
thing for me to do would have been to delete all of my accounts, stop showing up to stuff like this,
stop putting my face and my name out there, because that's how you get targeted. It's a very
long story that we won't go into because you can read it all on my blog, but I did end up finding
the guy after about five years and spending a lot of money. I did find the guy. He was some 15-year
old kid living in his mother's basement. And it was, you know, it was, it was a happy ending in
the sense that nobody got hurt. But in order to prevent someone from doing that again, because
like I said, 15 year old kid basically, you know, fell in with the wrong crowd, had the right skill
set. They egged him on to do this because of things that I was saying on Twitter. So that was
what made me the target, just being a public figure. And you have a large enough audience,
there's inevitably going to be a few crackpots or a few people who are willing to do things that
might harm you. And so if you're not willing to completely go off the grid and you still want to
be out there, then you have to figure out how do I harden myself? How do I make it so that no one
can actually target me and put this lethal force directed at me? And so that's the really hard
thing. On the bright side in America, we have a number of legal opportunities, entities that we
can set up to essentially obfuscate our publicly registered property. But this takes a lot of time,
effort, like you have to find the right attorneys who have expertise with structuring these things.
And that is only the beginning.
That is like the beginning of probably at least a five-figure investment just to set it up.
Going beyond that, though, is the lifestyle change.
You have to never leak your address, never associate it with your real name.
And that is the hard thing.
you're setting up other phone numbers, other post office box addresses for receiving mail
and stuff like that. And basically, in some cases, lying. You have to get very comfortable
with just not telling the truth about associating your real name and address. So I have an alias,
a pseudonym. The people, my neighbors, where I actually live, don't know my real name and what
I do. They know the cover story. And that was probably the hardest thing. It took me like a
couple of years to really get comfortable with that and not make mistakes. And it becomes second
nature. And I think that it's still okay and a moral thing to do. And it's legal to do as long
as you're not entering into like a legal contract or using this misrepresentation to perpetrate
some sort of fraud. What is your alias? Nice try. We recently have seen a number of incidents
around the world. You document these on your Twitter account. Everything from what I think
people think of as like the $5 wrench attack where somebody's hit over the head while traveling
abroad somewhere, all the way to the Ledger co-founder was recently kidnapped and there
was kind of a ransom demanded. What are the things that you spend the most time thinking about from
a safety standpoint that if you were to sit down with folks here one-on-one and say, hey,
here's the three things that will have the biggest impact to keep you safe?
Well, I deal with the security of keys and assets. I've been working on self-custody
products for over a decade now. And I think that that's also what most people tend to veer towards
is like, how do I set up my keys? How do I set up a distributed vault so that I don't have a
single point of failure? And essentially, that's the only way to protect yourself from what we
call a wrench attack. Basically, if someone takes you hostage, if someone is threatening you,
you are under duress, then all of your security and authentication mechanisms become worthless
because you are capable of authenticating and bypassing, you know, whatever schemes you have
set up. So the short version is, like, if you from your house or especially from your phone,
if you are able to move substantial amounts of assets quickly just in one location,
then that means if someone points a gun at you, then they can force you to move those assets
over to them or to one of their compatriots.
So that is like the single point of failure
that you want to avoid from a security perspective.
And the only way to do that is to get those controls
directly away from you.
And we recommend doing that by using multi-signature setups,
basically having multiple keys distributed around physically,
and each of those keys has its own set
of diverse security protocols.
And a big part of this is just time.
These type of attackers, if it's a wrench attack where they're actually coming and doing a home
invasion or kidnapping you or whatever, they want to get in and out. They don't want to be holding
you hostage for a really long period of time because the longer they're doing that, the more
at risk they are of law enforcement coming in and finding them. So the longer it takes and the
harder it is to actually move substantial portions of your digital assets, the safer they're going
to be. But people should not conflate the safety of your digital assets with the safety of your
physical person. These are two completely separate problems. And the physical security of your
person is a very well understood problem. We have been dealing with this for all of human
civilization. And so there's a lot of good resources out there for how to work on that.
But the thing that I try to impress upon people, because as you said, there's some billionaires in
the room, I'm sure, you know, they have bodyguards and security and stuff. Most of us are not at
that level and we don't really want to be. The best investment that you can make is in your
privacy. And you should think of your privacy as the outermost layer of your security. You know,
security, any security system should be a multilayered system because you should expect
any given layer, authentication, protocol, whatever, may be bypassed. But the more layers
you have, the harder it is, it slows down the attacker. And once again, attackers want to get
in and out as quickly as possible. And if you have that privacy layer, if that privacy is strong,
you don't even get targeted in the first place. And so none of those layers of security are even
going to get probed. When I think of the market today, there's like individuals, and I know that
There's a lot of folks that are trying to figure out custody solutions.
We've seen people say, hey, I'm just going to buy the ETF because I don't have to worry about keys.
There's people who use these third-party custodian services, and then there's people who use products like CASA.
Institutions are not going to allow fund managers to walk around with the private keys in their pocket.
They're going to demand whether it is qualified custodians or multi-sigs, things like that.
So talk a little bit more about the products that you guys are building because I do think that there's a friction point that you're adding,
which will slow down these attackers, but also there's just a pure security standpoint, right?
Actually being able to, even if you're not worried about somebody coming and kidnapping you or a home
invasion or something like that, it's just a good protocol so that if you get hacked or your email
is compromised or something that could be not physical security, but just kind of digital
security, these products are actually pretty valuable for it. Yeah. I mean, there's so much
to unpack in so little time. But one thing that I will say about the ETFs, they do resolve that
issue of the single point of failure where if there's no way to withdraw, then of course if
someone points a gun at you, you can't move your assets over. So an ETF does solve that problem.
But you're making a big tradeoff. You are trading that off for all of the risks that come with
third party custody. And if you understand like Bitcoin, read the white paper, then that's kind
of the whole point of this whole industry, this whole ecosystem is to get rid of trusted third
parties. But people have the freedom if they want to use trusted third parties. I try to implore
people to understand that third party custody is just somebody else's self custody. So it has all
of the same risks. It's like the Venn diagram is you have all of the risks of self-custody
and then third-party custody is outside of that. The entire, you know, self-custody is inside and
then you have all the third-party risks. The third-party risks basically being all of the
employees, you know, insider attack risks, infrastructure risks, and even, you know,
nation-state risks. If everybody puts their money in the same custodian, it becomes a honeypot for
any number of different attacks. When you're thinking about best practices, so somebody uses
the Kasa product, they use multi-sig, all this stuff, who do I give the other keys to? How do I
think about the protocol for the treatment of those keys that somebody else has? Because I think that
people are like, oh, multi-sig is just this great thing, but it's kind of like if you go and you
gave the keys to criminals that just collude against you. So how do you think about selecting
who holds the keys and what those protocols look like? Yeah. And this is why I would say our
advisory support is one of the more important aspects of what we do at Casa. Because multi-sig
is not panacea. It's not, oh, you just have multiple keys and now you're automatically
safe from everything. I mean, we've seen people who set up a multi-sig and then kept all of their
keys at their house. That doesn't really protect you from anything. I mean, if your house burns
down, that's a problem. If you get a home invasion, that's a problem. So this is why it's a very
personal issue. Because everybody has different connections, different friends, family, maybe
attorneys, semi-trusted people that they might be willing to act as key holders. And that's why
thinking through all of these decisions is something that we can help out with. It's
certainly possible to set up, you know, multi-sig where it's only you. Then you just have to decide,
you know, where are the other geographically dispersed locations where I put it. And if you
don't have, you know, multiple houses or residences or offices that you can disperse them
amongst, then you're probably going to be looking into various high security like safety deposit
box type setups. And do you think that those safety deposit boxes and things like that are
okay if you've got the keys split or do you worry about, you know, we've seen plenty of like civil
forfeiture and things like that. So kind of, you know, maybe peel back a little bit more and talk
about some of the nuances of where you're putting those keys. Yeah. I mean, any given safety deposit
box, really any given person or organization that might be storing a key for you, you should
assume could be compromised. And so that's why the true strength in a well-architected
multi-key setup is diversity. And it's diversity in every possible vector, whether it's diversity
in the hardware that it's stored on, the software and the firmware the keys are stored on, the
geographic locations and the possible weather events or natural disasters. The more diversity,
the better. And the reason for that is that we have to assume that things will go wrong.
We have to assume that humans will make mistakes. And the more differences there are between the
different security protocols that are protecting each of your keys, the more likely it is that
any given type of failure will only affect one of them and not multiple.
How do you look at corporations? We're talking a lot about companies putting Bitcoin on their
balance sheet. So far, every company that I'm aware of, they're using qualified custodians and
shareholders are not even thinking about self-custody or anything like that. Do you see
the world kind of going that way and the self-custody at the corporate level ends up being
kind of the state we end up in? Or do you think that there's kind of this element of when lots
of people around the table like price, but they don't maybe understand Bitcoin, the natural thing
is like just replicate what's in the traditional financial system and like give it to somebody
else? Yeah, no, I mean, third party custody is the default because of how people get onboarded
into the space generally through some third party custodian. And it's also the more convenient
option. So I kind of see what I've been doing for the past 10 years is actually fighting against
human nature. And it's a fun battle to fight because really what we're trying to do is make
self-custody as user-friendly, as easy as possible because third-party custody is always going to be
easier. It's always going to be easier to pawn off all the risks onto somebody else and say, oh,
well, if it all goes haywire, you know, I can just blame it on them, right? I don't have to worry
about my job. So to answer your question, I think probably most corporations will go with third
parties, even if they're not actually legally required to do so. But we have built solutions
at Casa where we can help you set up, architect, and maintain a self-custody system. And that
works really well for either larger companies or remote companies where you already have
employees that are geographically distributed. Talk a little bit about security while traveling,
because one of the things that you opened my eyes to very early on was, you know, you go and you use
the Wi-Fi somewhere, you go into a hotel, you're at the airport, you know, all these things, they're
things that convenience has really, you know, empowered people in society, but it has opened
massive security vulnerabilities. And so maybe when you travel, what are the things that you're
paying attention to? What are the things you're doing to mitigate those risks? But still, you
do have an X account. You do go places. You do kind of live your life. So walk us through maybe
what that protocol looks like. Again, kind of that layer right above maybe where Kasa sits.
Yeah, this is tough because actually most hotels KYC. And I actually, I booked a hotel
this morning that actually did a KYC and liveness check on the portal while I was checking out.
not like when I got to the hotel concierge, but as a part of the actual purchase process. So like
that's the direction we're going in. Now, if you want to get crazy with this, like there are ways
where you can basically get IDs, legal IDs, usually from other countries that basically have
an alias or a pseudonym. You don't have your real name on them. I still use my real name,
but what I do is whenever I am asked for my documents, I give my passport. And the reason
I give my passport is there's no address on it. And so this fulfills the obligations that they
want. But once again, I don't trust really anything or anywhere that I go. So like a hotel
room is not secure by any means. The safe in the hotel room is not secure. Like unless you bring
your own safe and bolt it to the floor, it's really not secure. But there are things that you
can do to improve your security. There's various travel devices that you can get that will
actually act as a better lock on your hotel door. Pretty much every hotel door can be easily
bypassed, either physically or digitally. The digital ones are really scary. Usually like a
$50 flipper chip can get through most of those. But as long as we're not talking about like going
through border control, you can generally move around fairly. What about like Wi-Fi and stuff,
right? I think that's one of the areas where people get on a plane, they're in an airport,
they're at a hotel, they connect. All of a sudden, you know, I've literally sat on planes
next to people who pull up their bank accounts and I mean, do all kinds of crazy stuff. And
you're just like do you know that everyone can see this right now yeah i mean that's people don't
really think about like the man in the middle um so we say you know not your keys not your coins
i mean not your wi-fi router not your internet connection um they could be depending on whether
it's encrypted or not you know they could be basically seeing all of your traffic or they
may only be seeing sort of metadata parts of it. So I use a VPN 24-7 on all of my devices. That
just adds another layer of obfuscation to it. But none of these things are perfect. Whether
we're talking about privacy or security, there is no one silver bullet. It's just sort of the
aggregate of doing many, many different good practices that make you a harder and harder
target. Before I let you go, who is the ideal client for Casa? When you say, hey, is it people
with a certain amount of Bitcoin? Is it people who have a certain public profile? Just walk me
through, who do you guys see the most success with? Well, I mean, I think for any sort of
entry-level multi-sig, when you have enough Bitcoin that losing it would be a life-changing
event, whether you're a whole coiner, or it just it makes up a large portion of your portfolio,
then I think it's worth starting to think about eliminating single points of failure.
And that's just on the technical side. If you're a public figure, if you're like talking about
Bitcoin crypto stuff all of the time, that's making you more of a target. That's when you
may be a good fit for our highest level concierge service where we provide advice, not only about
your keys and your digital assets, but about all the other stuff, the privacy and the security
that surrounds that. Because ultimately, all of the privacy and security that's part of your life
can then affect the security of your assets. Ladies and gentlemen, Jameson Lopp.
