104 · The long haul · lesson 2 of 5
Privacy and operational security — staying off the target list
Bitcoin is not anonymous: every payment sits on a public ledger forever. Keeping that ledger from being tied to your name is the same job as keeping yourself out of a burglar’s notebook — and most of it is free.
This lesson is about what security people call operational security — OpSec for short. It is not a technology. It is the everyday habits that keep information about you from being collected and joined up: what you publish, who you tell, which details you hand over, and which ones you simply do not create. In Bitcoin it covers both halves of the same problem — keeping your coins from being linked to your name on a public ledger, and keeping your name from being linked to the fact that you hold any at all. You will see the term used everywhere once you notice it; this is what it means.
Here is the honest picture. Bitcoin’s ledger — the shared record of every transaction — is completely public, and when you see the word on-chain, that is all it means: recorded on that ledger, permanently. Your name is not written on it, but the payments are, and companies exist whose whole business is connecting those payments back to real people. Read this lesson calmly: for most people the physical risk is small, and the habits that shrink it are free and quiet.
Why on-chain privacy matters
The catch is that nicknames can be linked together. A whole industry — called chain analysis — studies the ledger to group addresses that seem to belong to the same person, then attaches a real-world identity to the group. These firms sell that intelligence to exchanges, banks, law enforcement, private investigators, and sometimes to people simply looking for a wealthy target.
So the property to understand is not ‘anonymous’ and not ‘fully exposed.’ It is ‘pseudonymous but linkable.’ Your activity is out in the open under a nickname, and the game is about whether anyone can tie that nickname to you. You have real influence over that outcome.
The two big ways privacy leaks
1. Address reuse. This is receiving multiple payments to the same address. It is the single most damaging habit. When you reuse an address, every payment to it is obviously the same recipient — no clever guessing required. Reuse one address for years and you have handed an analyst a perfect diary of your money: every coin in, every coin out, every person you dealt with, all linked.
2. KYC data leaks. KYC stands for ‘Know Your Customer’ — the ID checks an exchange or regulated service makes you pass. That exchange records your name, photo ID, home address, bank details, and every address you send coins to or from. That record is the main way a nickname on the ledger gets a real name attached. And those records get out: through court orders, through company data breaches (the 2020 Ledger leak exposed roughly 270,000 customers’ names and home addresses), and through data sold on the black market. Once your holdings and your home address sit in the same leaked file, the risk stops being abstract — it can become a physical-safety problem. This is exactly why the habits below matter.
The everyday habits that defeat most snooping
Use a fresh address every time you receive. Modern wallets generate an endless supply of addresses from your single backup, at no cost. The wallet usually offers a new one by default — let it. Never post a permanent ‘donation address’ on a website or social profile; a fixed public address links every payment to you. If you genuinely need one in public — a tip jar, a business receiving payments — there is now a way to publish a single code that is never actually reused, and it is covered under Privacy tools.
Be careful about combining coins. Think of your wallet as holding separate chunks of Bitcoin, each from a past payment. The technical name for one chunk is a UTXO (an ‘unspent transaction output’ — simply a coin you received and have not yet spent). When you spend, your wallet may pull several chunks together into one payment. That quietly tells analysts ‘all these chunks belong to the same person.’ Better wallets let you choose which chunks to spend — a feature often called ‘coin control.’ Keeping coins from different sources apart preserves your privacy. Keeping separate wallets for separate purposes (everyday spending versus long-term savings) helps too.
Reduce your KYC footprint. You probably cannot avoid ID checks entirely — most legal ways to buy Bitcoin require them. The realistic goal is not zero KYC; it is limiting how much of your stack — bitcoiner shorthand for your total holdings — is tied to any one ID check. When you withdraw from an exchange, send to a fresh address in your own wallet, and do not later mix those coins with coins from other sources. That keeps the ID-checked portion walled off from the rest.
There is more depth here if you want it. A couple of optional tools go further still — PayJoin and Silent Payments. Neither is required, and you are not behind if you never touch them, so they wait for you in Running your own node, the last lesson of this level, rather than cluttering the habits that do most of the work.
A note on Lightning. Lightning payments don’t appear on the public ledger individually, so routine spending over it leaves far less of a trail — a real step up. But opening and closing a Lightning connection is on the ledger, and if you fund it with ID-checked coins, that identity follows you in. Use it for small everyday spending; keep the habits above for savings.
From a leak to your front door — and how to stay off that road
You have seen the first half of the pipeline: a leaked ID check puts your name, your home address, and the fact that you hold Bitcoin into one file. That file circulates for years, and you cannot un-leak it.
The second half is the part you still control — the public clues you leave yourself. Posts under your real name, a talk you gave, a balance screenshot, a comment from a friend about “my buddy who’s into Bitcoin.” On their own each is harmless. Combined with a leaked home address, they turn a maybe into a yes, and that is what a target list is made of. Jameson Lopp, who keeps the most detailed public record of real-world physical attacks on Bitcoin holders, puts this above everything else: the most effective thing you can do to lower your risk is to not talk about Bitcoin using your real name or face.
That is not secrecy or shame. It is declining to paint a target on yourself. In practice:
- No balance screenshots. Not ever, not anywhere public. One screenshot travels further than you think.
- No “just bought more” posts under your real name, and no Bitcoin-branded hats, keychains, or laptop stickers in public. Small signals accumulate into a picture.
- Keep amounts vague — see below on why “even with friends” is the hard part.
- Use a separate, non-name email for Bitcoin accounts, and keep your home address off things where you can — some people ship hardware to a P.O. box or a work address.
The hard part is the people you trust. The instinct is that this rule is about strangers on the internet. It isn’t. Almost everyone who gets targeted was known to hold Bitcoin by someone who told someone else. Your brother-in-law is never going to rob you — but he might mention it at work, and the colleague he mentions it to might repeat it at a bar, and by the third telling it has reached somebody you have never met, still attached to your name and the town you live in. You control the first telling and nothing after it.
So keep it tight even at home. No figures, no screenshots, no “it’s done really well this year,” no “I bought in early.” None of that is a lie you need to tell — “I own some Bitcoin” is a perfectly good answer to a friend, and “I’d rather not get into numbers” is a complete sentence. What you cannot do is un-say a figure. Once a number is out, it travels on its own.
None of this means staying silent. Talk about Bitcoin the idea — the technology, the freedom, the economics — as loudly as you like. That’s the whole rule in one line: talk about Bitcoin; never talk about your Bitcoin.
The "$5 wrench" — and the calm way to think about it
There's a well-known joke in security circles called the "$5 wrench attack." The idea: no one needs to crack your encryption if they can simply confront you and demand you hand over the coins. It sounds scary, so let's take the fear out of it and think clearly.
First, keep the odds in view. This is rare, and it clusters almost entirely around people who were identifiable as holders. Everything in the sections above is your real defense. Prevention through privacy beats any dramatic response.
Second, the best protection is not bravery — it's a setup where cooperating fully still can't hand over everything. If your coins are arranged so that no single place, and no single action of yours, can move all of them, then "I genuinely can't do that right now" is simply true. You're not bluffing. You're not resisting. You're telling the truth, and that is far safer than trying to be a hero.
You may also hear about a duress wallet or decoy wallet — a small, believable stash you can reveal to satisfy someone, while the bulk stays hidden and separate. These can be a useful extra layer, but they're not reliable on their own. Someone may not believe a decoy is everything. So treat a decoy as one thin layer on top of the real defenses: being hard to identify, and being genuinely unable to move it all at once.
Spreading it out — and the setups that make that real
Back in the backup lesson you spread your backups across genuinely separate places. That is worth doing whatever your setup, because it defeats destruction and it makes you harder to search. But be clear about what it does not do. If you hold a single set of recovery words, every place you keep a copy is a place that holds everything. Three copies in three cities is three chances for someone to find the lot. Spreading copies around buys durability and obscurity — it cannot, on its own, make any one location "not enough."
What makes that true is how your keys are arranged, which is the whole point of the ladder. Three of its rungs give you a setup where cooperating fully still can't hand over everything:
- A passphrase (rung 2) — your words live in one place and the passphrase in another, and neither alone opens the wallet holding your savings. It is also what makes the decoy above possible: the words on their own open a small, believable stash. Back the passphrase up as carefully as the seed and store it where the seed is not — a passphrase kept only in your head is the single most documented way people lose passphrase-protected Bitcoin.
- Multisig (rung 3) — two of three keys are needed to spend, and they live in genuinely different places. One home, one break-in, one search: never enough.
- Collaborative custody (rung 4) — you hold two keys and a Bitcoin service holds the third. Someone standing in front of you cannot produce the service's cooperation, and you genuinely cannot give it to them.
Shamir backup does something similar for a single key: it splits one backup into shares, so any few rebuild it and one alone reveals nothing.
None of this is a reason to climb for its own sake. The guide's governing rule still holds — choose the simplest setup that covers you — and for most people the physical risk is small, so the honest answer at the first rung is that spreading copies out is for fire and flood, not for a confrontation. But if a physical threat is a risk you can genuinely name, this is one of the few reasons to move up a rung on purpose.
One more everyday habit, whatever rung you are on: don't carry your hardware wallet around unless you actually need it. It stays home, or wherever it lives, most of the time. There's no reason to have it in your bag on a normal day, and every reason not to have it on you if something goes wrong away from home.
Keep this in perspective
It’s easy to read a page like this and feel uneasy. Don’t. For the large majority of people, physical attacks are a small, tail-end risk — the rare worst case, not the everyday one. And the habits that guard against it are the same low-effort ones that make your whole life a little more private: a fresh address every time, no balance screenshots, no logo hats, vague amounts, backups spread out, device left at home.
You don’t need bodyguards or a bunker. You need to be unremarkable. Match your effort to what you actually hold — a modest stack needs modest habits — and then enjoy the quiet confidence that comes with holding your own keys.
Use a fresh receiving address every single time, and never be publicly known as a holder. One shuts down most on-chain tracking; the other keeps you off the list that tracking feeds. Neither costs a cent, and together they defeat far more than any tool or gadget you could buy. The past can’t be un-leaked — but good habits from today forward always improve your position.
- Use a fresh receiving address every time you receive — and never post a fixed public address.
- Keep coins from different sources apart, and use coin control if your wallet offers it.
- Limit how much of your stack is tied to any one ID-checked account.
- Never post balance screenshots or specific amounts, and skip Bitcoin-branded gear in public.
- Keep your holdings vague even with family and close friends — you control the first telling, not the third. Enthusiasm is fine; figures and screenshots are not.
- Use a separate, non-name email for Bitcoin accounts and keep your home address off things where you can.
- Spread backups and keys across a few genuinely separate places, so no single location holds enough to move everything.
- Leave your hardware wallet at home unless you truly need to carry it.
Check yourself
4 questions on what this lesson just covered. Nothing is scored, recorded or saved — it isn’t sent anywhere and it’s gone when you close the tab.
1Physical attacks on Bitcoin holders are almost never random. What typically starts one?
The pipeline runs leak, then list, then your door. An ID check at an exchange records your name, home address and the fact that you hold Bitcoin in one file, and those files get out — through breaches, court orders, and data sold on. You cannot un-leak one. What you still control is the second half: the public clues. A post under your real name, a talk you gave, a balance screenshot, a branded hat — each is harmless on its own, and combined with a leaked home address they turn a maybe into a yes. The single most effective thing you can do is not talk about Bitcoin using your real name or face.
2You tell your brother-in-law roughly what you hold. He would never rob you. Where is the risk?
The instinct is that this rule is about strangers on the internet. It is not: almost everyone who gets targeted was known to hold Bitcoin by somebody who told somebody else. He mentions it at work, the colleague repeats it at a bar, and by the third telling it has reached a stranger — still attached to your name and the town you live in. You control the first telling and nothing after it. None of this requires lying: "I own some Bitcoin" is a perfectly good answer to a friend, and "I would rather not get into numbers" is a complete sentence. What you cannot do is un-say a figure.
3Your wallet offers a new receiving address each time, but reusing the old one is easier. What does reusing it cost you?
Address reuse is the single most damaging privacy habit there is. The ledger is public and permanent, so every payment to a reused address is obviously the same recipient — no clever guessing required. Reuse one for years and you have handed an analyst every coin in, every coin out and everyone you dealt with, already grouped and waiting for a real name to be attached. The habit costs nothing to fix: your wallet usually offers a fresh address by default, so let it, and never post a fixed public address on a website or profile.
4Does taking a fresh address every time mean a new backup each time?
Your wallet generates an endless supply of addresses from your one backup, at no cost, including ones it has not handed out yet. That is exactly what makes the habit free — there is nothing extra to write down and nothing extra to lose. One related habit is worth knowing: your wallet holds separate chunks of coin from past payments, and when you spend it may pull several of them into one payment, which quietly tells an analyst they all belong to the same person. Wallets that offer coin control let you choose which chunks to spend, and keeping coins from different sources apart protects what fresh addresses buy you.
✓ Last verified: August 4, 2026