ICO investor Ian Balina got hacked for over $2M
https://www.ccn.com/ian-balina-hacked-for-millions-through-old-email-account/
Here are some of his mistakes that I can think of
-Position sizing, he had over 95%+ of his networth in alt coins, which is just downright absurd. It was fun for him on the way up as he rode $90K all the way to $5M but then the market tanked it back down to under $2M and now he got hacked out of most of it
-He didnt properly secure his Gmail account. Removing phone recovery and email recovery (which are used in case you lose your password to regain access to the account) seem to be a better option. Save the password in a piece of paper somewhere instead of allowing email recovery. If you allow email recovery, now you got to protect 2 accounts (the main one and the recovery one), the recovery one might itself have a recovery email. This all increase the vulnarability surface of the setup
-No hardware wallet. The guy was worth millions but didnt bother to buy a simply hardware wallet, which would be a lot harder to hack (though still possible)
-He kept his private keys in encrypted evernote texts. The problem was that ALL his private keys were exposed once someone cracked his encryption passphrase, which I believe the hacker did doing a brute force off the data found in his email account (using common words, interests, numbers, etc)
-I'm not sure but I believe he didnt had 2 factor authentication on evernote
I learned from his mistakes, this morning I removed the recovery email and phone (someone can take over someones phone number through social engineering by calling the phone company) from my gmail account. I rather lose access to my gmail account then to let someone else in.
Crypto is too unforgiven for people to mess around with weak security