In Amsterdam last week I stopped in front of a shop window with a small sticker on the glass saying bitcoin was accepted inside. The conversation that started has been rattling around my head since, and it comes down to this: burglary is a declining profession, theft is not, and almost nothing about how we protect ourselves has caught up.
14 July 2026·10 min read·security
The sticker was unremarkable. A payment-processor logo, the kind of thing that has been in shop windows for a decade, next to the card network decals nobody looks at any more. What made me stop was the company I was with pointing at it and saying, more or less, that a shop advertising it accepts bitcoin is also advertising that somebody in there has a wallet.
That is a slightly paranoid reading of a payment sticker and it is also, I have since concluded, correct in a way I did not appreciate at the time. It sent me down a week of reading, and what I found reorganized how I think about a category of risk I had been treating as two separate problems.
The rest of this is the evidence for one claim. Theft did not decline. Theft relocated. The thing worth stealing stopped being in your living room and started being in your accounts, and the entire apparatus we built for protecting the first kind of property, locks, alarms, insurance, police response, the mental model of what being robbed feels like, does not apply to the second.
Burglary in the United States has been falling for thirty years. The decline is not marginal. The last full year of published FBI figures puts the burglary rate at roughly 229 incidents per hundred thousand people, down about sixty-nine percent from 2005. The overall property crime rate is at its lowest point in the entire published series, which goes back to 1976. The decline is not a blip, a redefinition, or a reporting artifact. Fewer people are breaking into houses, and they have been doing so less every year for most of my adult life.
The usual explanation is deterrence: cameras on doorbells, phones in pockets, alarm systems that cost nothing. That is part of it, but there is a simpler explanation sitting underneath, and I think it does most of the work.
The stuff is not worth stealing any more. A stolen television has almost no resale value and is heavy and identifiable. A laptop is locked to a person and remotely wipeable. Jewelry still moves, and beyond that the modern house is full of expensive objects that convert to cash badly. Meanwhile the average household has migrated the majority of its actual net worth into accounts that can be reached from anywhere on earth, by someone who never needs to know your address.
A burglar is a person who has chosen a high-risk, low-reward, geographically constrained job in an era when a better-paid version of the same crime can be committed at scale from a different jurisdiction with a much lower chance of ever meeting a police officer. Framed that way, the collapse in burglary is a labor market responding to incentives.
The FBI's Internet Crime Complaint Center took just over a million complaints in 2025 and put the reported losses at 20.9 billion dollars, a twenty-six percent increase on the year before. Cryptocurrency-related complaints accounted for 11.4 billion of that. Americans over sixty filed some two hundred thousand complaints and reported 7.75 billion dollars in losses, up fifty-nine percent in a single year, with an average loss per victim of around thirty-eight thousand dollars.
Sit with that last figure. The average older victim of internet crime lost about thirty-eight thousand dollars. The average burglary loss is a fraction of that, and the burglary is the one that gets a police visit, an insurance claim, and a story people tell.
On the crypto side specifically, Chainalysis put at least 154 billion dollars received by illicit addresses in 2025. Most of that headline number is sanctions-related flows rather than theft from individuals, and it should not be quoted as if it were all stolen from consumers. The subcategories are the ones worth looking at. Roughly seventeen billion in scams and fraud, about 3.4 billion in outright theft from hacks, and something in the region of eight hundred million in ransomware payments. A single exchange breach in February 2025 accounted for about 1.5 billion of the theft figure on its own, the largest such heist on record.
And every one of those numbers is an undercount, for a reason that is structural rather than statistical. These are reported losses. Fraud is chronically under-reported because the victim feels foolish, and it is under-reported worst in exactly the demographic losing the most money.
Almost nobody is guessing your password. That was the threat model of 2005 and it drove a generation of advice about mixed case and special characters that turned out to be largely beside the point.
The modern route in is credential-stealing malware, and the thing it takes is often the session cookie. When you log in to your bank and complete the second factor, the site hands your browser a token that says this browser has already proved who it is, do not ask again. That token is a bearer credential. Anyone holding it is you, for as long as it is valid, and presenting it does not trigger a second factor because from the site's point of view the second factor already happened.
Industry reporting on the scale of this varies enough that I would not quote a single figure with confidence, but the consistent finding across the last two years is that a substantial minority of stolen credential records, somewhere around a third in the sets that have been analyzed, arrive with live session tokens attached. A meaningful fraction of account takeover in 2026 completely bypasses multi-factor authentication, not by defeating it, but by arriving after it.
Which reframes the advice. Multi-factor authentication is still essential and I am not suggesting otherwise. But the marketing implied it was a wall, and it is a door with a very good lock, standing in a room the attacker may already be standing in. What actually helps against session theft is a smaller attack surface: fewer machines that touch financial accounts, aggressive session expiry, and hardware-bound credentials that cannot be lifted and replayed from somewhere else.
They ask you. Politely, urgently, and with a plausible reason. Investment fraud is the largest single loss category in the IC3 figures, and it is a long, patient, entirely human confidence trick, conducted over weeks, that ends with the victim voluntarily transferring their own money using their own credentials on their own device. Every technical control in the chain works perfectly. The authentication succeeds because it is genuinely you.
What has changed recently is the cost of running that play. I wrote a review of what AI actually changed at the end of last year, and the conclusion I keep returning to applies here more than anywhere: the ceiling did not move much, the floor collapsed. Fluent, native-quality text in any language, at volume, ended the era when bad grammar was a usable filter for detecting a scam. Voice cloning from a few seconds of audio ended the era when hearing a familiar voice was evidence of anything. Both were built without a research breakthrough. They required a commodity tool and an afternoon.
The other underrated vector is the help desk. Account recovery exists because people genuinely lock themselves out, and every recovery path is by construction a legitimate way to take over an account without the credentials. Mobile carriers are the weak link that matters most, because a transferred phone number recovers most of the rest, and a carrier support representative is a human being who can be persuaded, bribed, or simply mistaken.
Most of financial history since the invention of the check has been a slow migration away from bearer assets. Cash is a bearer asset: whoever holds it owns it, and if it is taken from you there is no ledger anywhere that still says it is yours. Almost everything else we invented since is the opposite. Your bank balance is a claim, recorded by an institution, reversible by that institution, insured by a government, and disputable in a court. If someone steals your card number, the money moves and then it comes back, because at no point did the thief actually acquire ownership of anything. They acquired an entry, and entries can be corrected.
Self-custodied crypto is a bearer asset. Not metaphorically. The private key is the property. No institution holds a claim on your behalf, no reversal, no chargeback, no fraud department, and no court that can order the coins back, because nobody is there to order. A transfer signed with your key is, by design and by the entire point of the system, indistinguishable from a transfer you meant to make.
This is a design choice with genuine merits, and none of this is a case against it. Censorship resistance and irreversibility are the same property described in two tones of voice, and the people who value the first accept the second knowingly. The problem is that this property is now held by a very large number of people who have not thought about it in those terms at all, and who are relying on habits formed in a world where a mistake could be undone by a phone call.
In the Netherlands alone, something like fourteen percent of adults hold crypto in some form. A number that size is too many people to wave off as enthusiasts, and a substantial share of a population carrying bearer instruments in their pockets while retaining an instinctive, entirely reasonable, and completely wrong expectation that somebody would fix it if it went missing.
If a fortune is protected by cryptography that cannot practically be broken, and the entire fortune can be moved irreversibly by whoever holds a twelve-word phrase, then the cheapest attack on that cryptography does not involve computers. It involves finding the person and hurting them until they say the words. The security community has called this the wrench attack for years, as a joke about how all the elegant maths in the world loses to five dollars of hardware and a willingness to use it. It stopped being a joke somewhere around 2025.
The verified count of physical coercion incidents against crypto holders roughly doubled between 2024 and 2025, into the dozens globally, and France in particular became the focus in a way nobody has fully explained. The counts vary depending on who is doing the counting and what they classify as crypto-related, which is itself a sign of how new the category is. The cases are not ambiguous, though. In January 2025 a co-founder of a well-known hardware wallet company was kidnapped in France and one of his fingers was severed and sent as part of a ransom demand. Others have involved families, children, and organized groups recruiting teenagers to do the physical work. French prosecutors have since charged dozens of people, including minors, in connection with a wave of these.
The thesis of this post is that thieves stopped coming to your house because the valuable thing left the house. Bearer-form digital assets reverse that, precisely and cruelly. They put the valuable thing back in the house, or rather back in the person, and they do it while removing every protection the older arrangement provided. No vault, no ledger, no reversal, and no institution absorbing the loss. One human being knows the phrase.
A sticker on a shop window is not a neutral piece of information. Publicly holding, publicly transacting, publicly enthusing about self-custodied assets is a form of disclosure about what you are carrying and how irreversibly it can be taken. Most people advertising it have not modeled it that way. I had not, until somebody said it out loud on a street in Amsterdam.
The gap that bothers me most is that none of our protective institutions have moved.
Home insurance will replace a stolen television, an object almost nobody now bothers to steal. The assets that actually get taken have no equivalent behind them, and where cover exists for digital theft it is generally an endorsement with a low limit and exclusions wide enough to drive a truck through.
Card fraud is genuinely well handled. That success is why everyone's instincts are miscalibrated. Card networks decided decades ago that the customer should not carry the loss, because a payment system nobody trusts is worth nothing. So an entire generation learned that theft of money is annoying and temporary.
Push payments, where you authorize the transfer yourself, historically carried no such protection, which is exactly why fraud migrated to them. The UK made reimbursement mandatory for authorized push payment fraud in late 2024. Most countries have not copied it. No comparable rule applies to a self-custodied transfer, and by construction none can.
So the loss lands entirely on the individual, in the category where the sums are largest, the victims are oldest, and the reporting is worst. I do not have a policy proposal. I have an observation, which is that we have built a great deal of consumer protection around a form of theft that is disappearing, and almost none around the form that replaced it.
Use hardware keys on the accounts that matter. Anything with money behind it uses a physical security key, not SMS and not an authenticator app. The reason is specific: a key is bound to the origin and to the device, so it cannot be phished onto a lookalike site and it cannot be lifted and replayed from somebody else's machine. Codes can be read out over the phone by a person being manipulated in real time. Keys cannot.
Lock the phone number. A port-out PIN and an account lock with the mobile carrier, because the phone number is the master key to more recovery flows than anyone realizes, and the carrier's support desk is the softest target in the chain.
Keep a separate surface for money. Financial accounts get their own browser profile at minimum, and ideally their own machine that does nothing else. The separation is doing all of the work on its own. Session tokens are stolen from the browser you use for everything, and the browser you use for everything is the one that visits things you have not vetted.
Freeze the credit files. Frozen by default at all the bureaus, thawed deliberately when needed. It costs nothing and it removes an entire category of attack that does not touch any of your accounts at all.
Have a family phrase, agreed out loud. A word that has to be said on any call asking for money or urgent action, agreed in person, never written anywhere. The phrase is a direct answer to voice cloning, it takes five minutes to set up, and it is the highest-return thing on this list for anyone with older relatives.
Do not advertise. No public discussion of holdings, no stickers, no answering the question at a party honestly. This felt faintly ridiculous to write down and then I read the French cases.
Assume no reversal. Anything held in bearer form is treated the way I would treat the same value in cash under the floorboards: split, mostly not at home, and never the whole position in one place with one person knowing where it is.
The shop was still open when we walked back past it. The sticker is a perfectly ordinary piece of commercial signage and I want to be clear I am not suggesting anyone take theirs down, or that accepting a payment method is reckless.
What I took from the conversation is smaller and, I think, more useful. We have all inherited a model of theft where the danger is a stranger in your house at night and the remedy is a lock, an alarm, and a claim form. That model described the world accurately for a very long time and it describes almost nothing that is actually happening now. The house is safer than it has ever been. The person living in it is not.