BA-10 · Expert

Privacy, security, and threat modelling

Protect users against both cryptographic and operational failure.

Follow these 8 lessons in order, or choose the topic you need. Each lesson combines an explanation, a worked example and practice inside the Guild.

  1. Common-input and change heuristics

    Chain surveillance infers ownership from transaction structure; heuristics are probabilistic, not consensus facts.

    35 minutes · Open lesson
  2. CoinJoin

    Collaborative transactions break simple ownership heuristics but introduce coordination, amount, and operational considerations.

    45 minutes · Open lesson
  3. PayJoin and silent payments

    Receiver-assisted construction and reusable scanning addresses reduce common transaction graph signals.

    55 minutes · Open lesson
  4. Network privacy

    IP observation, timing, wallet queries, and address reuse can reveal links even when on-chain structure is careful.

    65 minutes · Open lesson
  5. Hardware-wallet threat models

    Secure elements, firmware, host compromise, supply chains, and verification UX define actual signing security.

    35 minutes · Open lesson
  6. Multisig operations

    Geographic separation and policy redundancy help only when backups, quorum availability, and change verification are practiced.

    45 minutes · Open lesson
  7. Protocol attack surfaces

    Parsing, consensus divergence, nonce reuse, oracle manipulation, key compromise, and economic exploits require layered controls.

    55 minutes · Open lesson
  8. Incident response

    Preparation includes detection, communication, key rotation or migration, evidence preservation, and safe recovery procedures.

    65 minutes · Open lesson