XFollowListPeople, ideas and original work on X

Crypto reading list

Crypto security & investigations

Crypto security starts with several different questions. How did stolen funds move? Which rule in a contract failed? How did someone gain access to an account or device? Choose a question below and read a worked example from the person investigating it.

Selected sources
10

People to read

Open the first material, then continue with the author on X. People appear once, grouped by their main reading use and ordered by handle within each group.

4 of 10 people

Personal security

Learn to recognize the risks in messages, calls, permissions, devices and backups before going deeper into technical research.

  • @dguido Dan Guido Security educator

    Dan Guido connects crypto theft to the security of devices, workflows and professional relationships. As cofounder and CEO of the security firm Trail of Bits, he offers a practitioner’s view of organizational defenses and their tradeoffs.

    Start with this Web material · blog.trailofbits.com

    Mitigating ELUSIVE COMET Zoom remote control attacks

    A concrete example of a fake media invitation leading to a remote-control request. Read the account of the approach first, then the discussion of permissions and organizational controls.

    Published . Material checked .

  • @lopp Jameson Lopp Security educator

    About Jameson Lopp & selected work

    Lopp explains Bitcoin self-custody through threat models and experiments with backups and physical storage. He is a cofounder and Chief Security Officer at Casa; read him to understand the choices a storage design makes and the risks it leaves open.

    Start with this Web material · blog.lopp.net

    How to Back Up a Seed Phrase

    The article maps the decisions behind a seed backup: loss, damage, theft and the people who may need access. Use the decision process to understand tradeoffs before comparing particular storage products.

    Published . Material checked .

  • @PabloSabbatella Pablo Sabbatella Security educator

    Pablo teaches the everyday security of accounts, messages and work devices used in crypto. His perspective includes his security and training venture Opsek; start with the kinds of access a message or call asks you to grant.

    Start with this Video · archive.devcon.org

    OpSec for the Dark Forest (or how to avoid getting rekt)

    The official Devcon archive hosts this nine-minute talk. Its scope includes devices, email, social accounts, passwords, 2FA and social engineering—a compact route into the questions to ask about everyday access.

    Material checked .

  • @tayvano_ Taylor Monahan Security educator

    Taylor explains phishing, malicious software and the ways people are persuaded to grant access themselves. Her MetaMask writing helps you look beyond a wallet interface to the device, message and permissions around it.

    Start with this Web material · metamask.io

    Blockchain malware’s neverending novelty

    The article asks what a blockchain actually does for a malware campaign. Start with the delivery chain and compare the headline about a novel technique with the practical route onto a victim’s device.

    Published . Material checked .

A few bearings for your reading

These field notes explain the people, language and questions you may meet along the way.

XFollowList field note

Meet ZachXBT through an investigation

See what a transaction link establishes and where an investigator needs additional evidence.

XFollowList field note

Follow a claim back to its source

A practical way to read the conversation around an incident on X.

How this list is selected

We selected people through their own investigations, articles, code and talks. Linked public sources connect names or pseudonyms to X accounts. Material dates describe the linked work; check dates describe checking the material and its authorship through the cited sources. Recent X activity is recorded separately and remains unknown where it was not checked. Read case-specific conclusions alongside the evidence and any later updates.