Tired of ads? Enjoy an ad-free experience by signing up.
  • Insights
    This article was written by a TIA community member. Insights pieces undergo the same rigorous editorial process that newsroom-produced articles have.
Liraz Siri · · 5 min read

This security expert shares 10 ways to protect your ICO campaign

bitcoin-trends

Photo credit: David McBee

In 2017, the total amount of funds raised through ICOs was near US$4 billion, says EY. Such volume has caught the attention of hackers—over 10 percent of ICO proceeds are gone and crypto exchanges lost an average of US$2 billion due to attacks.

I am Liraz Siri, a professionally paranoid white hat hacker, early bitcoin supporter, and co-founder of TurnKey Linux. At 18, I scanned the internet for vulnerabilities. Later, in the military, I co-founded an Israeli cyber-unit. Today, I am security advisor at WePower, and I want to share a few important tips on securing your ICO campaign.

Key guiding principles

My main strategy is raising the team’s awareness of the risks and suggesting countermeasures that apply the 80/20 rule (80 percent benefit and 20 percent effort). Here are the key principles:

  • Do the simplest thing that could possibly work. Security issues thrive in the gap between what is and what is understood. The less complex your system is, the less likely it is to have critical security issues.
  • Tolerate failures. Assume some failures are inevitable and set things up so that if one security measure fails, others still stand to compensate.
  • Don’t underestimate safety. Don’t strive for just-enough security but go for a little bit more than you think you need. In other words, better safe than sorry!
  • Use minimum privilege policies. Restrict the permissions of people and systems to just the minimum set of privileges they need to do their jobs.

How to be more secure

1. Hire a chief security officer (CSO)

If you’re raising funds on the blockchain, you need someone with a deep understanding of the risks in order to set sane security policies. A good CSO will ensure that your security policies are audited, implemented correctly, and followed by the whole team.

2. Set up dedicated devices

Network endpoints such as end-user mobile devices, laptops, and desktops are common security Achilles heels. That’s because their operating systems and accompanying pieces of software almost always prioritize functionality over security. Attackers are very good at taking advantage of security holes in endpoints to take over your system. To minimize the risk, consider setting up devices that are used exclusively for your fundraising project and nothing else.

3. Don’t use phone-based authentication

Enable two-factor authentication on everything but avoid using phone-based authentication such as SMS or phone calls. Phone numbers are not a good security mechanism as they can all too easily be intercepted and hijacked via SS7 attacks.

It is best to use hardware tokens such as Gemalto or YubiKey alongside Google Authenticator. YubiKey has a mobile app that stores one-time password (OTP) seeds and provides these passwords to Google Authenticator via NFC sensors.

4. Secure your smart contract

First of all, read up on all the security pitfalls and make the minimum amount of changes necessary to tweak the smart contract to your purposes.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

Community Writer

Liraz Siri

Liraz Siri is a professionally paranoid whitehat hacker, early Bitcoin supporter, and co-founder of TurnKey Linux which powers & protects 100,000+ servers worldwide.