Backlit keyboard in a dark room

Home / Guides / Personal OPSEC

Personal OPSEC for crypto founders and executives

If you hold keys, run a platform, or are publicly wealthy in crypto, attackers target you before they target your firewall. A working checklist for the person, not the server — from a team that does OPSEC and OSINT for a living.

Personal OPSEC for a crypto founder means reducing what strangers can learn about you, hardening the accounts that anchor your identity (phone number and email above all), separating public and operational personas, and rehearsing what happens if you're targeted anyway. Most of it costs an afternoon, not a budget — and it protects against the attacks your corporate firewall never sees: SIM swaps, targeted phishing, and physical coercion.

Here's the uncomfortable asymmetry of running anything in crypto: your company's security program defends the platform, but the cheapest attack path is usually the human with the keys. Wrench attacks on holders, SIM-swap takeovers, and executive impersonation are not exotic — they're the standard playbook, because attacking a person is cheaper than attacking cryptography. We run OPSEC and OSINT engagements for exactly this reason, and this is the personal baseline we build for founders and executives.

Think like the attacker: your OSINT surface is the target list

Every targeted attack starts with research, and the research is done with open sources — the same OSINT discipline we use defensively. Before any technical hardening, understand what's already findable: your home address in data-broker listings and property records; your phone number in leaked databases from old breaches; your travel patterns from event speaker pages and real-time posting; your family, gym, and daily routine from tagged photos; your net-worth signals from on-chain activity linked to a doxxed address, funding announcements, or a "portfolio" interview. None of that requires a hacker — it requires an afternoon and patience. The defensive conclusion writes itself: what they can't find, they can't use — so the first project is shrinking the surface, and only then hardening what remains. (This is exactly the exercise in our OSINT teardown work: we show clients their own file before an adversary compiles it.)

The five-layer personal baseline

Layer 1 — The phone number: your real master key

Layer 2 — Identity anchors: email and passwords

Layer 3 — Money and keys

Layer 4 — Devices and daily behavior

Layer 5 — The company connection

Want to see your actual exposure instead of guessing? Ask about a personal OSINT + OPSEC review — we compile what's findable about you, then close it, discreetly.

What we find when we run these reviews

Patterns from real engagements, anonymized: the founder whose "private" operational email appeared in a conference attendee leak with a password still in use; the executive whose home address was one property-record query away while his on-chain address was in his social bio; the team whose entire treasury could move on one compromised laptop because multisig was "planned for next quarter." None of these people were careless by normal standards — normal standards assume nobody is specifically hunting you. The entire point of personal OPSEC is that, past a certain visibility in this industry, someone specifically is — and the defenses are mostly unglamorous: separate the personas, kill SMS recovery, split the money's control, slow down the urgent request. An afternoon of setup, a quarterly hour of upkeep — and a threat model that finally matches the fact that, past a certain point of visibility in this industry, you are not a random target but a chosen one.

The 90-minute starter, if the full stack feels like a lot

If the five layers read as overwhelming, do the highest-leverage subset tonight — it takes about ninety minutes and closes the attacks that actually target founders. Minutes 0–20: call your mobile carrier, set a port-out PIN / number lock. 20–40: remove SMS as a recovery method on your primary email, password manager, and any exchange or banking account; switch those to an authenticator app at minimum, and order two hardware keys. 40–60: check whether your main email addresses appear in known breach data, and change any password that shows up (and anything sharing its pattern). 60–80: do a five-minute search for your own home address on the top people-search sites and file the opt-outs. 80–90: tell your family and closest colleague the one rule that stops most impersonation — no money or access moves on a message alone, always a callback. That's not the whole program, but it removes SIM-swap, the leaked-password path, and the easiest impersonation script — the three things that turn a public founder into an easy target. The rest can follow over the coming weeks.

Frequently asked questions

Isn't this paranoid for a small founder nobody's heard of?

Scale the response to visibility: every founder should do layers 1–2 (they're basic account hygiene with a sharper edge); public fundraising, media presence, or known treasury control justify the full stack. The honest test — if a stranger with $500 and a week can find your home address, your phone number, and evidence you control funds, you're a rational target regardless of fame.

What's the single highest-impact change?

Removing SMS from account recovery and locking your number against port-out. SIM swap remains the workhorse of executive account takeover because it converts a $0 phone-store social-engineering attack into control of everything your number can reset.

Do data-broker removals actually work?

They raise the cost, which is the realistic goal — determined adversaries with legal process can still find records, but opportunistic targeting relies on cheap lookups, and sweeps break those. Treat it as maintenance (quarterly), not a one-time fix, because brokers repopulate.

How is this different from our company security program?

The company program defends systems the company controls; personal OPSEC defends the person attackers route through when systems hold. They meet in the middle — impersonation-proof payment processes, inner-circle hygiene, custody structure — which is why we build both under one engagement rather than leaving the founder as the unpatched perimeter.

Should my family be part of this?

Yes, for anyone with account access or whose public posting affects your exposure — spouses' travel photos and children's tagged locations are read by the same people researching you. Run the inner circle through the phone and identity-anchor basics at minimum; an attacker who can't reach you directly reaches the people around you.

What should I do first if I think I'm already being targeted?

Don't investigate alone and don't tip your hand. Preserve evidence (messages, headers, timelines), lock the identity anchors (carrier PIN, hardware keys on email), and get professional help fast — our emergency line exists for exactly this class of problem, and early hours matter.

Book a personal exposure review Our OPSEC practice

Drawn from our OPSEC/OSINT engagement practice; individual threat models vary — calibrate to your visibility and holdings. If you believe you are in physical danger, involve law enforcement immediately.