The Self-Custody & OpSec Hub

Please give a short description of the topic/cause for your Community Hub

The Self-Custody & OpSec Hub is a community-led space focused on helping Ethereum users, developers, DAO contributors, and teams use wallets and smart contracts more safely. Through practical, vendor-neutral education, the hub will cover secure key management, transaction verification, token approvals, phishing and wallet-drainer risks, multisig, smart accounts, recovery planning, privacy, and operational security across the Ethereum ecosystem

What will you offer to the Devcon attendees?

We will offer Devcon attendees a community-led, vendor-neutral space to learn and practise self-custody and operational security within the Ethereum ecosystem. Through hands-on workshops, demonstrations, discussions, and walk-in clinics, participants will learn how to safely use Ethereum wallets and dApps, verify transactions, manage token approvals, recognise phishing and wallet-drainer risks, use multisig and smart accounts, improve privacy, and plan for secure recovery. The hub will also provide a space for Ethereum users, developers, DAO contributors, and security practitioners to share experiences and learn from one another.

Rough Program Outline

The hub will run across all four days of Devcon as a practical learning space focused on self-custody and operational security within the Ethereum ecosystem.

Day 1 — Ethereum Self-Custody Foundations
Understanding externally owned accounts, smart contract wallets, seed phrases, private keys, hardware wallets, and the security trade-offs between different Ethereum account models. Attendees will build a personal threat model based on loss, theft, phishing, coercion, device compromise, and recovery needs.

Day 2 — Safe Ethereum Transactions and dApp Interaction
Hands-on sessions on reading transaction prompts, verifying addresses and contract interactions, understanding token approvals, avoiding blind signing, identifying malicious signatures, and reducing exposure to phishing sites, wallet drainers, and compromised front ends.

Day 3 — Smart Accounts, Multisig and Recovery
Practical workshops on Safe and other smart-account models, multisig operational procedures, signer separation, access control, social and institutional recovery, inheritance planning, and designing custody systems without a single point of failure.

Day 4 — Ethereum Privacy, Treasury Security and Incident Response
Sessions on wallet separation, address reuse, metadata leakage, RPC and interface privacy, operational security for DAOs and protocol teams, treasury transaction procedures, emergency response, approval revocation, and recovery after a suspected compromise.

List the people who will organise, oversee and be responsible for the Community Hub

  • Bala & Santosh - Ethereum Wallet Security

  • AD - Smart Accounts and Multisig

  • Palash - Privacy and OpSec

  • Paco - Program Coordinator

List the equipment or production needs (see what’s possible in the RFP)

  • LED TV with HDMI connection for demonstrations

  • Two whiteboards for threat-modelling exercises

  • One worktable for wallet and backup demonstrations

  • Power outlets and extension boards for test devices

1 Like

Good proposal, and I think there’s a natural pairing here: flagging a neighbouring hub application ( Devcon 8 India: Sovereign Infrastructure Hub ) rather than a competing one.

I’m posting an intention this week for a “Sovereign Infrastructure” hub, reframed from the “Node Operators” hub of previous editions. Short version: self-custody answered “not your keys, not your coins.” We’re aimed at its quieter twin: “not your node, not your data.” Light clients, node tooling on hardware people already own, and wallets that verify chain data rather than trust a provider for it.

Which puts us squarely alongside two things already in your scope.

Transaction verification: an attendee who has learned to read a transaction carefully is still reading a screen populated by an RPC endpoint they don’t control. The provider chooses what they’re shown. Same for checking token approvals through a block explorer — the check is only as honest as whoever served the page. Drainers and phishing are the attacker in your face; a filtered or lying data source is the quiet one, and it defeats a well-trained user rather than a careless one.

I’d happily co-run a session on that if it appeals: “what your wallet shows you, and who told it that” — practical, and it lands better with an audience already thinking about verification than with one that isn’t. We’ll have light client maintainers in the room who can show the difference live.

Otherwise: we’d send anyone asking “how do I know what my wallet is telling me is true” to you, and you’d have somewhere to send people who want to fix the data path. Happy to coordinate scheduling so we’re not drawing on the same audience at the same hour.

Good luck with the proposal!

Updating our proposal to follow the official Community Hub template - full version below.

Self-Custody & OpSec Collective

Summary of Proposal

The Self-Custody & OpSec Hub is a vendor-neutral, community-led space where Ethereum users, developers, DAO contributors, and teams learn to hold and operate keys safely. Through hands-on clinics on key management, transaction verification, approvals, drainers, multisig, smart accounts, recovery, backups, and privacy, it turns security anxiety into practical, repeatable habits.

Motivation and Rationale

How would this Community Hub enhance the attendee experience? Most attendees hold keys, sign transactions, and manage approvals every day but few have ever been walked through doing it safely, hands-on, by someone neutral. The hub is a calm, come-and-go space where anyone can bring a real question (“is this approval safe to sign?”, “how do I actually back up a seed so it survives?”, “how do I set up a multisig for my DAO?”) and leave with a concrete answer and a habit they’ll keep.

How would it complement Devcon 8 India, and what unique piece does it add? Devcon is full of people building the future of Ethereum; far fewer sessions cover how to not lose everything while doing it. Security is usually a one-off talk. A persistent hub makes it continuous, practical, and physical including a hands-on station where people actually create and stress-test backups running quietly alongside the whole event as a safety net.

Why is this topic significant, and why a Community Hub over a talk or workshop? Wallet drainers, blind signing, malicious approvals, compromised front ends, and lost or fragile backups cause real, irreversible losses across the ecosystem. They are learned by doing, on a test device, with someone to ask when you get stuck. The come-and-go hub format lets people return whenever they hit a blocker, across all four days.

How does it support builders of a free, open, private, and verifiable future? Self-custody is that future in practice. Builders who can verify their own transactions, separate signers, back up keys durably, and design custody without a single point of failure are less capturable and less dependent on trusted intermediaries. The hub strengthens the human layer of Ethereum’s security.

Past hubs / what we’ve learned This is our first Devcon Community Hub. Our team’s background is in running hands-on self-custody and opsec education for a technically skeptical community, and the core lesson we carry in: skepticism is healthy, so everything must be demonstrated live on real devices, shown across multiple tools and vendors, and be reproducible by the attendee.

Implementation

Standard Devcon-provided items would form the base: LED/TV screen with HDMI, whiteboards, worktable(s), chairs, power, and storage.

Additional equipment we plan to source (proposed — subject to confirmation with the Devcon production team):

  • A hands-on backup station: multiple seed-backup methods side by side (steel plate punching, stamping, and at least one alternative), so attendees physically compare durability, cost, and failure modes rather than being sold one

  • A rotating set of hardware wallets from different vendors (air-gapped, USB, and DIY/SeedSigner-style) for hands-on comparison, loaded with testnet/dummy seeds.

  • Test-only devices (spare phones/laptops) for practising transaction verification and approval-checking safely

  • Consumables for the backup demos (blank plates, punches/stamps) provided free for practice

  • Extension boards / power strips for multiple test stations

  • Printed vendor-neutral reference cards (threat-model worksheet, approval-checking checklist, recovery-planning template)

  • A physical “questions wall” for walk-in opsec questions answered throughout the day

Programming

Sample daily program (9:00–18:00, themed per day across all four days)

Time

Session

Tone

9:00–10:30

Welcome + build-your-threat-model open clinic

Light

10:30–13:00

Day’s core hands-on workshop (see day themes)

Heavier

13:00–14:00

Open networking / walk-in questions

Light

14:00–16:00

Practical lab: attendees do it themselves on test devices

Heavier

16:00–18:00

Open hours: walk-in clinics, Q&A, “check this before I sign” desk

Light

Day themes

  • Day 1 - Ethereum Self-Custody Foundations & Hands-On Backup: EOAs vs smart-contract wallets, seed phrases, private keys, and a live comparison of hardware wallets across vendors. Hands-on station where attendees physically create and stress-test seed backups using multiple methods (steel punching, stamping, alternatives) on dummy seeds. They compare durability, cost, and failure modes. Everyone builds a personal threat model (loss, theft, phishing, coercion, device compromise, recovery).

  • Day 2 - Safe Transactions & dApp Interaction: reading transaction prompts, verifying addresses and contracts, token approvals, avoiding blind signing, spotting malicious signatures, and reducing exposure to drainers and compromised front ends.

  • Day 3 - Smart Accounts, Multisig & Recovery: Safe and other smart-account models, multisig operational procedures, signer separation, access control, social and institutional recovery, inheritance planning, and designing custody without a single point of failure.

  • Day 4 - Privacy, Treasury Security & Incident Response: wallet separation, address reuse, metadata/RPC/interface privacy, opsec for DAOs and protocol teams, treasury transaction procedures, emergency response, approval revocation, and recovery after a suspected compromise.

Possible speakers / contributors Ethereum wallet-security practitioners, Safe/smart-account contributors, DAO treasury and multisig operators, hardware-wallet and backup practitioners across vendors, and privacy/opsec researchers. Final line-up to be built collaboratively and crowdsourced on this forum thread. We intentionally prefer practitioners over promotional representatives.

How does this support Devcon’s open-source ethos and community bridge-building? All software shown is open-source and self-hostable; all methods are reproducible by attendees without buying anything. Hardware and backup demos always show several competing options side by side. The hub bridges everyday users, DAO operators, and security researchers into one shared, practical conversation.

Audience

  • Everyday Ethereum users who self-custody but were never taught to do it safely

  • Developers and dApp builders who want to verify what they sign

  • DAO contributors and treasury signers responsible for shared funds

  • Security-curious newcomers building their first threat model and their first durable backup

  • Especially: Indian and Global South users entering self-custody, for whom irreversible loss is especially costly

Team

Organized under a neutral community banner, the Self-Custody & OpSec Collective:

  • Bala & Santosh - Ethereum wallet security

  • AD - Smart accounts and multisig

  • Palash - Privacy and opsec

  • Paco - Program coordinator

Why us: the team runs hands-on self-custody and opsec education for a technically skeptical community, where nothing is accepted unless it’s demonstrated live, shown across multiple tools, and reproducible by the attendee. That’s exactly the standard this hub holds itself to.

Neutrality commitment (free from marketing or promotion) The hub is strictly non-commercial, vendor-neutral, and educational. We commit that:

  • No products, brands, or tokens will be sold, promoted, or ranked in the hub.

  • Any hands-on demo involving a category of product (hardware wallets, backup plates, etc.) shows at least two or three competing options side by side with honest trade-offs; no single product is favoured, branded, or sold.

  • All software techniques are taught on open-source, self-hostable tools, and are reproducible by attendees without any purchase.

  • Consumables and test devices are provided free for practice; nothing is for sale in the space and no order-taking of any kind occurs in the hub.

  • Clear community guidelines are posted in the hub, and an organiser is present during all operating hours to keep it neutral.

Languages Content in English and Hindi, with volunteer support for additional Indian languages where possible.

1 Like

Valid suggestions… We are open to collaboration / integration.

Great — let’s make it concrete.

The session I had in mind: “What your wallet shows you, and who told it that.” Your attendees are already being taught to read a transaction carefully before signing; the missing half is that the screen they’re reading is populated by an RPC endpoint they don’t control. Same for checking approvals via a block explorer. We’d bring light client maintainers who can show the difference live — the same query answered by a provider and by software on your own laptop.

That’s one hour, co-run, and it works in either room.

You mentioned integration as well as collaboration — what did you have in mind there? Happy to talk about anything from swapping sessions to something more joined-up. Worth knowing which we’re discussing before we both plan around it.

Also: nice work reformatting to the template. Ours is at

if you want to see where the overlap sits.