任何公有区块链的启动期都是一个令人无比兴奋的时刻,但这也恰恰是恶意行为者可能试图借机牟取私利的时期。持有并能够访问加密货币,可能会让你成为攻击者眼中的高价值目标;不过,你仍然可以通过许多方式提升个人安全性,降低甚至消除安全风险。

社会工程学

社会工程学几乎和人类历史一样久远,而在技术时代,它通常表现为网络钓鱼或鱼叉式网络钓鱼。这两类攻击都是极其成功的欺骗手段,导致了超过 95% 的账户安全泄露,而且它们并不只发生在电子邮件里:如今,只要你有收件箱的地方,就可能出现机会主义或定向钓鱼攻击。无论你使用的是 Signal、Telegram、短信、Twitter,还是在论坛或社交网络中查看私信,攻击者都有大量机会切入你的数字生活,试图夺走那些你绝对不希望失去的宝贵信息和资产。如果出现一个好得令人难以置信的交易机会,或者你收到一条索要本不该向任何人透露的信息的消息,在与其互动之前,你始终可以通过自行访问我们的官方网站或 Cosmos 官方沟通渠道来核实真伪。
  • 对意外收到的附件保持怀疑,尤其是那些要求你在区块链或加密货币语境下访问可疑或陌生网站的邮件。 攻击者可能试图诱导你访问一个已被攻陷的网站,从你的电脑中窃取敏感信息。如果你使用 Gmail,可以在这里测试自己对最新电子邮件钓鱼手法的抵抗能力。
  • 在购买 ATOM 之前,请务必做好尽职调查。Tendermint 团队和 Interchain Foundation 都不会在启动时出售 ATOM,因此如果你看到社交媒体帖子或邮件声称我们正在进行代币销售,那一定不是真的,应立即忽略。如果你正在寻找 ATOM,请确保已对卖方或交易所进行调查,确认这些代币来自可信来源。
  • Cosmos、Tendermint 团队或 Interchain Foundation 的任何人,都绝不会发送电子邮件要求你向我们提供任何形式的账户凭证或你的 12 个助记词;我们始终会通过官方 Twitter、Medium 和 Github 账户,直接向 Cosmos 社区发布重要消息。
如果你收到一封好得令人难以置信的邮件或一条推文,它很可能就是骗局。

密钥管理

要尽可能降低 ATOM 被盗或丢失的风险,最好的方式是为你的私钥制定稳健的存储与备份策略。保存密钥最安全的方法是离线存储,无论是在加密货币钱包中,还是放在一台从不连接互联网的设备上。最佳的密钥备份策略,是确保你在安全地点保存多份副本,并采取专门措施,至少让其中一份副本能够抵御你所在地区可能发生的自然灾害。 为了保护你的 ATOM,不要与任何人分享你的 12 个助记词。 唯一应该知道它们的人就是你自己。无论你是将 ATOM 委托给网络中的验证者,还是使用托管服务,都不需要分享你的私钥。如果有人向你索要这些密钥材料,

软件漏洞

为了保护自己并确保使用的是最安全的代码,你应当使用可获得的软件最新版本,并在安全公告发布后立即更新(或尽快更新)。这对于你的笔记本电脑、移动设备、加密货币钱包,以及任何可能与你的身份或加密货币相关联的设备都非常重要。 为了保护你的 ATOM,你应当只从官方来源直接下载软件,并在进行任何涉及你的 12 个助记词的操作时,确保始终使用最新、最安全版本的 gaiad。 Tendermint、Cosmos-SDK 和 gaiad 的最新版本始终都会在我们的官方 Github 仓库中提供。 Cosmos、Tendermint 团队或 Interchain Foundation 的任何人,都绝不会在发布安全公告或提供补丁之后,再通过电子邮件要求你下载某个软件附件。

验证交易

请对技术建议保持警惕,尤其是来自论坛和群聊频道中陌生人的建议。熟悉重要命令,特别是那些会帮助你执行高风险操作的命令,并查阅我们的官方文档,以确保你没有被诱导去做会伤害你自己或你的验证者的事情。 在发送交易,或进行任何可能花费代币的操作时,你都应当在点击发送前先验证交易内容。 虽然地址字符串很长,但按每 4 个字符为一组进行目视比对非常重要,这样可以确保你把资金发送到了正确的位置,而不是让它凭空消失。

账户安全

要保护你的加密货币并消除风险,你能做的最重要事情之一,就是加固所有关键在线账户的安全。攻击者会尽可能寻找立足点,并利用这个立足点从一个地方横向移动到另一个地方。未受保护的账户,例如电子邮件、社交媒体、你的 Github 账户、Cosmos Forum,以及介于其间的其他任何账户,都可能成为攻击者切入你在线生活的机会。 对于持有加密货币的人来说,可以采取两项特定的账户安全措施,以消除区块链世界中的一些特有风险。
  • 第一,尽可能在所有地方启用双因素认证,并确保你的第二因素使用的是验证码生成器或U2F 硬件密钥。
  • 第二,留意用于重新获得最重要账户访问权限的账户恢复方式,并确保不要使用短信作为恢复手段。如果你还没有这样做,请立即在你的个人邮箱账户以及其他管理代币的地方开始使用身份验证器应用或硬件密钥,尤其是在你使用在线交易所的情况下。

供应链攻击

无论你购买的是硬件设备还是硬件钱包,都应当直接从供应商或可信来源购买。这是彻底消除设备或芯片被篡改、进而窃取你私钥风险的唯一方法,尤其是在已有报道称,遭到篡改的钱包曾通过 Amazon 及其他热门在线市场出售的情况下。

免责声明

请注意,这是一款高度实验性的软件。在当前早期阶段,我们预计会出现问题、更新和缺陷。现有工具需要高级技术技能,并且涉及超出 Interchain Foundation 和/或 Tendermint 团队控制范围的风险(另请参见 Interchain Cosmos Contribution Terms 中的风险部分)。任何对这款采用 Apache 2.0 开源许可的软件的使用,均由你自行承担风险,并且软件按“AS IS”基础提供,不附带任何形式的担保或条件;对于因该软件引发的任何损害,Interchain Foundation 和/或 Tendermint 团队概不承担任何责任。请务必极度谨慎!`
The launch of any public blockchain is an incredibly exciting time, and it’s definitely one that malicious actors may try to take advantage of for their own personal gain. Owning and having access to cryptocurrency can make you a valuable target for an attacker, but there are many things you can do to improve your personal security and reduce or eliminate security risks.

Social Engineering

Social engineering has existed for about as long as human beings have been on the planet, and in the technical era, it usually takes in the form of phishing or spearphishing . Both of these attacks are wildly successful forms of trickery that are responsible for over 95% of account security breaches, and they don’t just happen via email: these days, opportunistic and targeted phishing attempts take place anywhere that you have an inbox . It doesn’t matter if you’re using Signal, Telegram, SMS, Twitter, or just checking your DMs on forums or social networks, attackers have a plethora of opportunities to gain foothold in your digital life in an effort to separate you from valuable information and assets that you most definitely don’t want to lose. If a deal pops up that sounds too good to be true , or a message shows up asking for information that should never, ever be shared with someone else, you can always verify it before engaging with it by navigating to our official website or an official Cosmos communication channel on your own.
  • Be skeptical of unexpected attachments, or emails that ask you to visit a suspicious or unfamiliar website in the context of blockchains or cryptocurrency. An attacker may attempt to lure you to a compromised site designed to steal sensitive information from your computer. If you’re a Gmail user, test your resilience against the latest email-based phishing tactics here .
  • Do your due diligence before purchasing ATOM. Neither the Tendermint team nor the Interchain Foundation will be selling ATOM at launch, so if you see social media posts or emails advertising a token sale from us, they’re not real and should be dismissed immediately. If you’re on the hunt for ATOM, make sure that you’ve researched the seller or exchange to confirm that the tokens are coming from a trustworthy source.
  • No one from Cosmos, the Tendermint team or the Interchain Foundation will ever send an email that asks for you to share any kind of account credentials or your 12 words with us, and we will always use our official Twitter, Medium, and Github accounts to communicate important news directly to the Cosmos community.
If you receive an email or tweet that sounds too good to be true, is likely to be a scam.

Key Management

The best way to minimize the risk of theft or loss of ATOM is to have a strong storage and backup strategy for your private keys. The safest way to store your keys is offline, either in a cryptocurrency wallet or on a device that you never connect to the internet. The best backup strategy for your keys is to ensure that you have multiple copies of them stored in safe places, and to take specific measures to protect at least one copy of your keys from any kind of natural disaster that is a likely possibility in your part of the world. To protect your ATOM, do not share your 12 words with anyone. The only person who should ever need to know them is you. You do not need to share your private keys if you’re delegating ATOM to a validator on the network or to use custodial services. If anyone asks for your key material,

Software Vulnerabilities

To protect yourself and ensure you’re using the safest code is to use the latest version of software available, and to update immediately (or as soon as you can) after a security advisory is released. This is important for your laptops, mobile devices, cryptocurrency wallets, and anything else that may be linked to your identity or your cryptocurrency. To protect your ATOM, you should only download software directly from official sources, and make sure that you’re always using the latest, most secure version of gaiad when you’re doing anything that involves your 12 words. The latest versions of Tendermint, the Cosmos-SDK, and gaiad will always be available from our official Github repositories. No one from Cosmos, the Tendermint team or the Interchain Foundation will ever send an email that asks for you to download a software attachment after sending out a security advisory or making a patch available.

Verifying Transactions

Be skeptical of technical advice, especially advice that comes from people you do not know in forums and on group chat channels. Familiarize yourself with important commands, especially those that will help you carry out high-risk actions, and consult our official documentation to make sure that you’re not being tricked into doing something that will harm you or your validator. When sending transactions or doing anything that may spend coins, you should always verify those transactions before hitting send. While address strings are long, it is important to visually comparing them in blocks of 4 characters at a time to ensure that you are sending them to the right place rather than into oblivion.

Account Security

One of the most important things you can do to protect your cryptocurrency and eliminate risk is to harden all of your critical online accounts. Attackers will try to gain foothold wherever they can, and will use that foothold to pivot from one place to another. Unprotected accounts like email, social media, your Github account, the Cosmos Forum and anything in between could give an attacker an opportunities to gain foothold in your online life. For people who hold cryptocurrency, there are two specific account security actions that can be taken to eliminate specific risks that come with being part of the blockchain world.
  • First, it is important to enable 2-factor authentication everywhere you can, and to make sure that you are using a code generator or U2F hardware key as a second factor.
  • Second, be mindful of account recovery methods used to regain access to your most important accounts and make sure that you do not use SMS as a recovery method. If you haven’t done so yet, start using an authenticator app or a hardware key immediately for your personal email account and wherever else you manage your tokens, especially if you use online exchanges.

Supply Chain Attacks

Whether you’re buying a hardware or a hardware wallet, it is important to purchase whatever you need directly from the supplier or from a trusted source. This is the only way to completely eliminate the risk of a compromised device or chip from stealing your private keys, especially since there are reports of compromised wallets being sold on Amazon and through other popular online marketplaces.

Disclaimer

Please note that this is highly experimental software. In these early days, we can expect to have issues, updates, and bugs. The existing tools require advanced technical skills and involve risks which are outside of the control of the Interchain Foundation and/or the Tendermint team (see also the risk section in the Interchain Cosmos Contribution Terms). Any use of this open source Apache 2.0 licensed software is done at your own risk and on a “AS IS” basis, without warranties or conditions of any kind, and any and all liability of the Interchain Foundation and/or the Tendermint team for damages arising in connection to the software is excluded. Please exercise extreme caution!`