- Insights This article was written by a TIA community member. Insights pieces undergo the same rigorous editorial process that newsroom-produced articles have.
This security expert shares 10 ways to protect your ICO campaign

Photo credit: David McBee
In 2017, the total amount of funds raised through ICOs was near US$4 billion, says EY. Such volume has caught the attention of hackers—over 10 percent of ICO proceeds are gone and crypto exchanges lost an average of US$2 billion due to attacks.
I am Liraz Siri, a professionally paranoid white hat hacker, early bitcoin supporter, and co-founder of TurnKey Linux. At 18, I scanned the internet for vulnerabilities. Later, in the military, I co-founded an Israeli cyber-unit. Today, I am security advisor at WePower, and I want to share a few important tips on securing your ICO campaign.
Key guiding principles
My main strategy is raising the team’s awareness of the risks and suggesting countermeasures that apply the 80/20 rule (80 percent benefit and 20 percent effort). Here are the key principles:
- Do the simplest thing that could possibly work. Security issues thrive in the gap between what is and what is understood. The less complex your system is, the less likely it is to have critical security issues.
- Tolerate failures. Assume some failures are inevitable and set things up so that if one security measure fails, others still stand to compensate.
- Don’t underestimate safety. Don’t strive for just-enough security but go for a little bit more than you think you need. In other words, better safe than sorry!
- Use minimum privilege policies. Restrict the permissions of people and systems to just the minimum set of privileges they need to do their jobs.
How to be more secure
1. Hire a chief security officer (CSO)
If you’re raising funds on the blockchain, you need someone with a deep understanding of the risks in order to set sane security policies. A good CSO will ensure that your security policies are audited, implemented correctly, and followed by the whole team.
2. Set up dedicated devices
Network endpoints such as end-user mobile devices, laptops, and desktops are common security Achilles heels. That’s because their operating systems and accompanying pieces of software almost always prioritize functionality over security. Attackers are very good at taking advantage of security holes in endpoints to take over your system. To minimize the risk, consider setting up devices that are used exclusively for your fundraising project and nothing else.
3. Don’t use phone-based authentication
Enable two-factor authentication on everything but avoid using phone-based authentication such as SMS or phone calls. Phone numbers are not a good security mechanism as they can all too easily be intercepted and hijacked via SS7 attacks.
It is best to use hardware tokens such as Gemalto or YubiKey alongside Google Authenticator. YubiKey has a mobile app that stores one-time password (OTP) seeds and provides these passwords to Google Authenticator via NFC sensors.
4. Secure your smart contract
First of all, read up on all the security pitfalls and make the minimum amount of changes necessary to tweak the smart contract to your purposes.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.





