Thinking about your threat model
A threat model is just a clear answer to "what am I actually protecting against?" Without one, people waste effort on theatrics and miss the real risks. Here is a realistic one for a market visitor.
The real risks, ranked
- Phishing. By far the most common way people lose accounts and coins. Defended by verifying addresses.
- Self-deanonymisation. Reusing a username, leaking details in messages, paying from an exchange. Defended by compartmentalisation.
- Account takeover. A stolen password. Defended by a unique password and PGP 2FA.
- Network observation. Handled largely by Tor itself, strengthened by Tails.
Where to spend effort
Notice that the top two risks are behavioural, not technical. No tool fixes a reused username or an unverified address. Spend your effort on habits first and tools second. The following pages give you those habits.
Next
Start with the biggest risk: defeating phishing.Last reviewed 2026-07-13.