On-chain Safety Education

Understand the chain.
Protect your wallet.

Onchain Diary is an independent Web3 safety education site: 89 deep-dive articles, a 228-term glossary, and the complete BIP-39 wordlist — covering crypto scams, smart contract security, and on-chain analysis. No jargon. No sign-up. No tools to install. Just the knowledge you need to stop getting rekt.

89 Articles
228 Glossary Terms
0 Sign-ups Required
§ 01

Latest

Guides, tutorials, and deep dives.

How to Report a Crypto Scam: IC3, Exchange Freeze Requests, and What Actually Happens After You File

A field guide to reporting stolen crypto: how to assemble the evidence package, file the FBI IC3 complaint field by field, send exchange freeze requests that get read, and what to realistically expect after you hit submit.

Public Key vs Private Key vs Wallet Address: The Difference Scammers Hope You Never Learn

Every wallet scam that has ever worked relies on one thing: the victim not knowing which of the three wallet strings does what. The one-way chain from seed phrase to private key to public key to address, what leaking each one actually costs you, and the four attack patterns — fake verification, seed-phrase phishing, blind signing, and address poisoning — that exist only because people blur these boundaries.

Unbacked Mint Attacks: How Fake Receipts Drained Liquid Network and Symbiosis

In one week of September 2026, two protocols lost real Bitcoin to the same trick: minting unbacked wrapped assets with fake deposit receipts. A field dissection of the Liquid Network and Symbiosis exploits.

Why You Should Never Generate a Seed Phrase Online

Online seed phrase generators are one of two things: a phishing tool that logs or pre-loads the phrase it hands you, or a negligent service that produces unauditable randomness over an untrusted channel. How legitimate wallets generate phrases on-device, why the browser can't be trusted with creation, the chatbot variant of the same trap, and the burned-phrase protocol if you've already used one.

Where Stolen Crypto Goes Dark: Privacy Pools and What Tracing Can Still Do

Stolen funds usually end their trail in a privacy layer. How mixers, Zcash shielded pools, and viewing keys change crypto fund tracing, and what victims can still realistically do.

When 'Encrypted' Is Just a Word: A 3-Step Reality Check for Crypto Privacy Claims

A privacy-branded crypto project claimed its identities were encrypted. The page source told a different story. Here is the three-step check anyone can run before trusting a privacy claim.

Don't transact blind.

Whether you're new to crypto or deep into DeFi, understanding how scams work is the best defense. Every guide here is free.

Start Reading →