Outta Luck: Security Lessons from Crypto Forums
RSA Conference 2024 · Track Session
Overview
In "Outta Luck: Security Lessons from Crypto Forums," Rachel S. Miller, Principal Security Architect at Protect AI, delivers a compelling and often humorous exploration of the unique and paradoxical security culture within the cryptocurrency and NFT communities. Far from an endorsement of digital assets, Miller's talk delves into the extreme risks inherent in this unregulated space, contrasting them with the surprisingly robust, community-driven security practices that have emerged out of necessity. She challenges traditional security professionals to learn from the "degenerate gamblers" of crypto, who, facing immense and irreversible financial losses, have cultivated a zero-trust mindset and a highly effective, grassroots approach to threat intelligence and risk management.

Key moments
- 0:00 Talk intro, censored title, and speaker's disclaimers
- 1:00 Speaker's personal motivation: 'Middle child syndrome' and blockchain research
- 2:00 The Pixelmon NFT rug pull: a $70M scam
- 2:45 Kevin the Voxombie: how an ugly NFT became valuable
- 4:00 Crypto Punk vs CryptoPhunk: demonstrating speculative NFT value
- 6:00 'Wezmee sadly': the $70k loss and instant acceptance
Outta Luck: Security Lessons from Crypto Forums
Speakers: Rachel S. Miller, Principal Security Architect, Protect AI
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=NXM2QujnNv8
Overview
In "Outta Luck: Security Lessons from Crypto Forums," Rachel S. Miller, Principal Security Architect at Protect AI, delivers a compelling and often humorous exploration of the unique and paradoxical security culture within the cryptocurrency and NFT communities. Far from an endorsement of digital assets, Miller's talk delves into the extreme risks inherent in this unregulated space, contrasting them with the surprisingly robust, community-driven security practices that have emerged out of necessity. She challenges traditional security professionals to learn from the "degenerate gamblers" of crypto, who, facing immense and irreversible financial losses, have cultivated a zero-trust mindset and a highly effective, grassroots approach to threat intelligence and risk management.
Miller's presentation is a critical examination of how a "no safety net" environment fosters an acute awareness of personal security and collective defense. Through personal anecdotes, real-world scam examples, and a deep dive into the technical underpinnings of crypto vulnerabilities, she highlights the rapid information sharing, proactive scam identification, and mutual support that characterize these communities. The talk ultimately serves as a powerful call to action for the broader cybersecurity industry, urging professionals to adopt similar principles of accessibility, community education, and transparent risk communication within their own organizations.
The talk is particularly relevant in today's digital landscape, where phishing, social engineering, and rapid exploitation of vulnerabilities are rampant. By dissecting the security lessons from a domain often viewed with skepticism, Miller provides fresh perspectives on fostering a more resilient security posture, not just through technology, but through human vigilance and collective responsibility. It's a testament to the idea that even in the most chaotic and speculative environments, valuable lessons about risk, trust, and defense can be found.
Background
▶ Watch: Talk intro, censored title, and speaker's disclaimers (0:00)
Rachel Miller’s journey into the intricate world of cryptocurrency and NFTs began, somewhat unconventionally, from a place of "middle child syndrome." Driven by a desire to outdo her older sister who worked at a crypto exchange, Miller embarked on a personal quest to understand blockchain technology. This initial curiosity quickly transformed into a deeper, more critical investigation after she stumbled upon a March 2022 article detailing the Pixelmon NFT project. Pixelmon, which raised an astonishing $70 million from investors expecting a high-quality, open-world game, instead delivered notoriously poor art, leading to what is commonly known as an NFT rug pull – a crypto term for a scam where developers abandon a project after raising significant funds. The enigmatic "Cyber," the project's founder, turned out to be a 21-year-old New Zealander with no prior game development experience. The most infamous outcome was the character "Kevin," a "Voxombie" NFT so ugly it became a meme, paradoxically skyrocketing in value to $13,000 while other Pixelmon NFTs plummeted to $1,500.
Intrigued by the aftermath, Miller joined the Pixelmon Discord server, initially seeking amusement at the expense of speculative investors. However, her prolonged presence in the community revealed a stark reality: people were willing to gamble "unbelievable sums of money on digital assets" that were often indistinguishable in value or utility. She vividly illustrates this with an example of two NFTs, one a CryptoPunk (an original NFT project from 2017) valued at $23.7 million, and the other a phonetic "Crypto Phunk" derivative worth a mere $150. This extreme speculation, coupled with the inherent difficulty in assessing genuine value, sets the stage for a unique approach to risk management.
The pivotal moment that solidified Miller’s research direction was witnessing a real-time wallet draining incident. An active community member lost half a dozen NFTs, sold for "less than a penny of Ethereum," a clear indicator of a hack. The victim's immediate, almost nonchalant response: "Was me sadly." This phrase, an instant acceptance of theft, deeply troubled Miller. A subsequent investigation of the blockchain revealed the true cost: $70,407.22 worth of assets were stolen. This casual acceptance of such a significant loss highlighted the fundamental difference between traditional finance and crypto: there is no safety net. Unlike credit card fraud, where liability is capped at $50, or debit card fraud with 60-day reporting protections, crypto transactions are, by design, irreversible and largely unregulated. Once a promissory transaction is approved, there is no recourse; the money is "shit out of luck," hence the talk's original, uncensored title. This inherent lack of consumer protection forces crypto enthusiasts to operate with an elevated, self-reliant sense of security, a phenomenon Miller found profoundly insightful.
Key Findings
▶ Watch: The Pixelmon NFT rug pull: a $70M scam (2:00)
Miller’s deep dive into crypto forums uncovered a paradoxical yet highly effective security culture born out of extreme necessity. Despite the speculative nature and the constant threat of irreversible loss, these communities exhibit a zero-trust mindset more consistently than many traditional enterprises. Key findings include:
- Community-Driven Threat Intelligence: In the absence of a central authority like CISA or official CVEs, crypto communities have developed highly effective, decentralized threat intelligence networks. Users actively monitor for scams, hacks, and emerging vulnerabilities, sharing alerts in dedicated "scams and security alerts" channels on platforms like Discord and Twitter. Miller cites an example where a user identified a wallet drainer hidden in Discord links, and another where the NFT trader platform was compromised, with a user tweeting a warning that garnered 1.5 million views, instructing others to revoke live connections immediately.
- Rapid Incident Response: The communities demonstrate an astonishing speed in detecting and responding to security incidents. When the Pixelmon project's Twitter account and CEO's account were compromised, a normal user noticed the hack within 50 seconds. This swift detection and communication throughout the Discord community prevented members from interacting with the malicious wallet drainer, resulting in no losses for those within the community. Miller contrasts this with the often slower, more bureaucratic incident response times in traditional companies, expressing "jealousy of the speed of this response."
- "No Stupid Questions" Culture: The inherent "silliness" of crypto, with projects like Dogecoin, Garlic Coin, or Kale Panda, fosters an environment where users feel comfortable asking even the most basic security questions without fear of judgment. Miller provides an example of a user asking if a random airdrop offering $583 was legitimate, receiving an immediate "scam" confirmation from the community. This open communication channel is crucial for educating new users and preventing costly mistakes.
- Proactive Security Enforcement by Projects: Crypto projects themselves, recognizing the reputational damage caused by scams, often implement and enforce stringent security rules. The Azuki project, for instance, has seven rules, four of which are explicitly focused on preventing scams: "keep your direct messages closed," "no team member or bot will ever DM you," "any announcement or links sent through a DM is a scam," and crucially, "help educate others about how to avoid getting scammed." This last rule explicitly makes security a communal responsibility.
- Personalized Security Nudging: Some projects go a step further, actively checking user settings and providing personalized security advice. Miller recounts receiving a message from a project (with the tag line "you're a lizard Larry") informing her that her dummy account was not secure and that she should disable DMs. This proactive, accessible guidance stands in stark contrast to many enterprise security programs that offer features but require users to seek them out.
- The FOMO Paradox and Risk Acceptance: The high-stakes, high-reward nature of crypto cultivates a unique relationship with risk. Miller's personal experience of her NFT gaining significant value triggered FOMO (Fear Of Missing Out) on larger gains, but also intense anxiety about losing everything if she made a mistake. This constant tension between potential profit and irreversible loss drives a heightened awareness of every transaction's security implications, leading to an almost fatalistic acceptance of risk ("was me sadly") combined with extreme vigilance.
These findings suggest that while the crypto space is rife with dangers, it has inadvertently forged a highly adaptive and resilient security culture that prioritizes collective defense, rapid information sharing, and personal responsibility—lessons highly valuable for any organization.
Technical Deep Dive
▶ Watch: Kevin the Voxombie: how an ugly NFT became valuable (2:45)
The crypto ecosystem, while innovative, introduces a host of unique technical vulnerabilities and attack vectors that demand a specific understanding of its underlying mechanisms. Miller meticulously breaks down several key areas:
Wallet Draining and Promissory Transactions
At the heart of many crypto scams is the concept of wallet draining. Attackers gain unauthorized access to a user's digital wallet, often through phishing or malicious contract approvals, and then rapidly transfer assets. Miller illustrates this with the $70,407.22 incident where NFTs were "sold for less than a penny of Ethereum." This isn't a true sale but a quick transfer mechanism where the attacker "sells" the assets to their own wallet at a negligible price to move them off the victim's account before the victim can regain control.
The irreversibility stems from promissory transactions. Every interaction with a crypto wallet, whether buying, selling, or approving a contract, requires a digital signature. Once signed, these transactions are recorded on the blockchain and are immutable. Unlike traditional banking, there's no central authority to reverse a fraudulent transaction. This fundamental design choice, while offering decentralization, eliminates the safety nets consumers are accustomed to.
Blockchain Transparency
The blockchain itself is a public, distributed ledger. While this transparency is touted as a feature, it's a double-edged sword for victims of theft. Miller painfully describes how users can "view the exact moment your assets were stolen," see "the wallet address your assets were moved to," and even "what it was sold for and who is now the owner." This public visibility without recourse is "the most hilarious kind of cruel," akin to seeing a thief waving your wallet but being powerless to retrieve it.
Gas Fees and Urgency
A critical technical element driving security oversights is gas fees. These are transaction fees paid to the distributed network (miners or validators) to process and record transactions on the blockchain. Gas prices fluctuate significantly based on network congestion, ranging from "a few bucks to hundreds of dollars." When initiating a transaction, users are presented with a gas price and a limited time (e.g., 36 seconds) to accept it. The pressure to secure a "good price on gas," especially for those "flipping a digital asset for a couple of bucks profit," can bypass critical thinking. This urgency often leads users to accept transactions without thoroughly checking the URL or wallet address, making them susceptible to phishing.
Crypto Exchanges and Centralization Risk
While crypto champions decentralization, most users interact with centralized crypto exchanges (e.g., Bitcoin, FTX, Celsius, Mt. Gox). Miller highlights their inherent volatility and risk:
- Collapse Frequency: Exchanges "collapse all the time" due to poor management, fraud (FTX, Celsius), or hacks (Mt. Gox).
- "Not Your Keys, Not Your Crypto": This mantra emphasizes that if you don't hold the private keys (seed phrase) to your wallet, you don't truly own your crypto. Assets held on an exchange are effectively under the exchange's control, making them vulnerable to its failures.
- Lack of Insurance: Unlike banks (FDIC) or stock exchanges (SIPC), crypto exchanges lack insurance. If an exchange goes bankrupt, customer funds are locked in bankruptcy proceedings with no guarantee of return.
- Onboarding Requirements: Despite the risks, onboarding with US-based exchanges requires an "uncomfortable amount of information"—Social Security numbers, bank info, passport copies, 3D face scans—posing significant data privacy risks.
- Scams: The collapse of exchanges often spawns sophisticated phishing campaigns. Miller received a convincing email, post-Bitrix bankruptcy, with her full legal name and accurate details, only foiled by the ludicrous claim of her having $8,000 left on the exchange.
Airdrops: A Unique Attack Surface
Airdrops present a particularly "bizarre and terrifying attack surface." An airdrop is when any person can send a digital asset (like an NFT or token) to your wallet. Crucially, "because an interaction with a digital asset requires a sign of a contract, you can't delete it either." You can only hide it, but it "will continue to exist in perpetuity."
Attackers leverage airdrops in two primary ways:
- Malicious Contract Signing: The most common airdrop scam involves sending a seemingly valuable token or NFT to a user's wallet. The attacker then offers to buy it for a significant sum on a less reputable exchange. To "claim" this offer, the user must sign a transaction. However, the malicious contract embedded in this transaction grants the attacker permission to drain all other assets from the user's wallet. Miller explains this clearly in the Q&A: "most people don't actually read the contracts that they're signing. And it will give that person, the hacker, permission to transfer all the assets out of their wallet."
- CSAM (Child Sexual Abuse Material) Threat: Miller raises a chilling, yet unaddressed, hypothetical: what prevents someone from airdropping CSAM NFTs into a public wallet as revenge or to frame a crypto influencer? Given the permanence and inability to delete airdropped assets, this presents a severe and currently unmitigated risk for public figures in the crypto space.
Coinbase has implemented a helpful security feature for token airdrops, displaying a banner indicating if a token is on a different network (e.g., "Nose network" instead of Ethereum), signaling a potential scam. However, the underlying asset still cannot be removed, creating a "constant temptation and threat that looms over you."
These technical intricacies, combined with the human element of speculation and urgency, create a highly volatile and risky environment that forces its participants into a state of constant vigilance.
Demo / Proof of Concept
▶ Watch: Crypto Punk vs CryptoPhunk: demonstrating speculative NFT value (4:00)
While Rachel Miller did not conduct a live software demonstration in the traditional sense, her presentation served as a powerful personal proof of concept for understanding the psychological and security dynamics of the crypto world. Driven by her need to truly comprehend the "was me sadly" mentality, she made a deliberate decision to immerse herself in the ecosystem.
Miller recounts: "So I bought one of these things. I do and head first, eyes open, but head first." With a strong sense of fiscal responsibility instilled by her father, she invested only "money I was able to lose," reiterating that this was not an endorsement for others. Her goal was to experience the ecosystem firsthand, to understand the nonchalant reaction to a $70,407.22 loss.
The true "demo" came when her purchased NFT, initially bought without expectation of return, "suddenly became worth largely more than I bought it for." This personal experience triggered a profound shift: "I briefly, briefly, lost my sense of reason." She felt the "anxious excitement" akin to winning a slot machine, questioning whether to hold for even greater gains (succumbing to FOMO), but simultaneously became "terrified to lose it." The realization that any mistake in signing a digital contract could mean losing everything in her wallet, with no recourse, was "agonizing." Every wallet transaction became a moment of holding her breath, unsure if she was making a critical error.
This experiential learning solidified her understanding of the crypto community's assumed risk mindset. It wasn't just about the technical vulnerabilities or the lack of safety nets; it was about the intense psychological pressure, the constant vigilance required, and the ultimate acceptance of irreversible consequences. Her personal journey through buying and selling an NFT became the most compelling "demo" of the talk, illustrating the human element that underpins both the risks and the unique security culture of crypto. She eventually sold the NFT, not for "Oklahoma house money" or "vintage Jordan money," but for "Vespa money," a tangible, if whimsical, reward that made the abstract risks and rewards concrete.
Defensive Implications
▶ Watch: 'Wezmee sadly': the $70k loss and instant acceptance (6:00)
The lessons gleaned from the crypto community, despite its chaotic nature, offer profound defensive implications for traditional enterprises. Miller argues that if a "ragtag group of degenerate gamblers can form a tight-knit security community based on mutual risk," then traditional companies can and should do the same.
- Foster a "No Stupid Questions" Culture and Accessible Security: Miller emphasizes the importance of making security approachable. At Protect AI, she has implemented a strategy of being a "visible and inviting person" who is "easy to reach out to and generally quick to respond." Encouraging employees to ask any question, even those they might deem "silly," helps uncover more pressing security details and builds positive relationships. When people feel comfortable asking without judgment, they will ultimately ask more questions and take fewer unnecessary risks, mirroring the open communication seen in crypto forums.
- Communicate the "No Safety Net" – Define Business-Killing Risks: Just as crypto users face irreversible losses, companies face "business-killing risk" from breaches. Miller suggests that during employee onboarding, organizations should articulate their own "no safety net." For Protect AI, a security company, a massive breach and poor response could destroy its reputation and business. This isn't meant to scare employees but to "arm them with knowledge," fostering a soldier-like commitment to security, much like the crypto community's understanding of reputation being critical.
- Make Security Front-Facing and Proactive: Security needs to be an integral, visible part of company culture. Simple initiatives, like "five-minute security snack bite presentations" during all-hands meetings, allow security professionals to regularly communicate easy, helpful tips (e.g., being mindful in public, updating devices). This proactive engagement mirrors how crypto projects actively enforce security rules and even check user settings (like the "Lizard Larry" message) to ensure DMs are off for security. Companies should strive to reach out to employees at increased risk and provide simple, actionable steps to improve their security posture.
- Embrace and Prepare for Recovery and Incident Response: While crypto lacks recovery options, traditional enterprises have incident response tools. Miller urges organizations to "learn from their pain" and leverage these resources. The crypto community's astonishingly rapid detection (e.g., Pixelmon hack noticed in 50 seconds) and communication should serve as a benchmark. Companies should strive to cultivate an employee base "primed to recognize the signs of malicious actors" and able to alert security teams within minutes, transforming every employee into a potential early warning system.
- Cultivate a Community-Driven Threat Intelligence Model: Enterprises can learn from the decentralized, grassroots threat intelligence of crypto. While CISA provides official alerts, internal communities (e.g., company Slack channels) can be leveraged for rapid, peer-to-peer sharing of emerging threats, phishing campaigns, or observed anomalies—similar to how crypto users share "community-generated" alerts about wallet drainers or compromised platforms. This fosters a collective sense of responsibility for security.
- Adopt a Zero-Trust Mentality Internally: The "if there's one thing you can't trust in web3, it's everyone" sentiment is a harsh but effective form of zero trust. While not advocating for internal distrust, enterprises can apply this by assuming compromise, rigorously verifying access, and ensuring that no single interaction is implicitly trusted. This constant vigilance, born from the irreversible nature of crypto transactions, can significantly harden an organization's security posture.
By integrating these lessons, organizations can move beyond purely technical controls to build a more resilient, human-centric security culture that is both proactive and deeply ingrained in the daily operations of every employee.
Key Takeaways
- No Safety Net Fosters Vigilance: The irreversible nature of crypto transactions and the absence of traditional consumer protections cultivate an extreme sense of personal responsibility and vigilance among users.
- Community-Driven Security is Powerful: Despite lacking centralized authority, crypto forums demonstrate highly effective, rapid, and peer-to-peer threat intelligence sharing and incident response.
- Accessibility and Transparency are Key: Crypto projects that make security rules clear, simple, and even proactively nudge users towards better security practices see greater adoption and effectiveness.
- Embrace a "No Stupid Questions" Culture: Fostering an environment where employees feel comfortable asking any security question without judgment leads to better awareness and fewer unnecessary risks.
- Define and Communicate Business-Critical Risks: Like the "was me sadly" acceptance of loss, companies must clearly articulate their "no safety net" – the business-killing risks of a breach – to arm employees with knowledge.
- Prepare for Recovery, Learn from Irreversibility: While crypto offers no recovery, enterprises should learn from its pain by rigorously preparing for and embracing incident response and recovery tools, aiming for rapid detection and mitigation.
About the Speaker(s)
Rachel S. Miller is a Principal Security Architect at Protect AI. Her journey into cybersecurity and the unique culture of crypto forums is marked by a blend of intellectual curiosity and personal anecdotes. She humorously attributes her initial interest in blockchain to "pure middle child syndrome," driven by a desire to understand and even surpass her older sister's knowledge of the crypto space.
Miller is characterized by her candid and self-aware approach to risk. She describes herself as someone with a "strong sense of fiscal responsibility" instilled by her father, investing only money she was "able to lose" in her personal exploration of NFTs. She openly shares details about her life, noting that she doesn't own a car and still lives with her mom, emphasizing that her personal financial choices may not be universally applicable. Her presentation style is engaging, confident, and analytical, yet grounded in relatable experiences, making complex security concepts accessible. Her work at Protect AI involves implementing some of the community-centric security ideas she advocates for, focusing on making security accessible, inviting, and fostering open communication within the workplace.