Nobody Wants Your Television

In Amsterdam last week I stopped in front of a shop window with a small sticker on the glass saying bitcoin was accepted inside. The conversation that started has been rattling around my head since, and it comes down to this: burglary is a declining profession, theft is not, and almost nothing about how we protect ourselves has caught up.

A Sticker In A Window

The sticker was unremarkable. A payment-processor logo, the kind of thing that has been in shop windows for a decade, next to the card network decals nobody looks at any more. What made me stop was the company I was with pointing at it and saying, more or less, that a shop advertising it accepts bitcoin is also advertising that somebody in there has a wallet.

That is a slightly paranoid reading of a payment sticker and it is also, I have since concluded, correct in a way I did not appreciate at the time. It sent me down a week of reading, and what I found reorganised how I think about a category of risk I had been treating as two separate problems.

Here is the claim, and the rest of this is the evidence for it. Theft did not decline. Theft relocated. The thing worth stealing stopped being in your living room and started being in your accounts, and the entire apparatus we built for protecting the first kind of property, locks, alarms, insurance, police response, the mental model of what being robbed feels like, does not apply to the second.

A Declining Profession

Start with the part that sounds like good news, because it genuinely is.

Burglary in the United States has been falling for thirty years and the decline is not marginal. The last full year of published FBI figures puts the burglary rate at roughly 229 incidents per hundred thousand people, down about sixty-nine percent from 2005. The overall property crime rate is at its lowest point in the entire published series, which goes back to 1976. That is not a blip, a redefinition, or a reporting artefact. Fewer people are breaking into houses, and they have been doing so less every year for most of my adult life.

The usual explanation is deterrence: cameras on doorbells, phones in pockets, alarm systems that cost nothing. That is part of it. But there is a simpler explanation sitting underneath, and I think it does most of the work.

The stuff is not worth stealing any more. A stolen television has almost no resale value and is heavy and identifiable. A laptop is locked to a person and remotely wipeable. Jewellery still moves, and beyond that the modern house is full of expensive objects that convert to cash badly. Meanwhile the average household has migrated the majority of its actual net worth into accounts that can be reached from anywhere on earth, by someone who never needs to know your address.

A burglar is a person who has chosen a high-risk, low-reward, geographically constrained job in an era when a better-paid version of the same crime can be committed at scale from a different jurisdiction with a much lower chance of ever meeting a police officer. Framed that way, the collapse in burglary is not a mystery about deterrence. It is a labour market responding to incentives.

The Other Side Of The Ledger

And here is the other side of that ledger, which almost never gets printed next to it.

The FBI's Internet Crime Complaint Center took just over a million complaints in 2025 and put the reported losses at 20.9 billion dollars, a twenty-six percent increase on the year before. Cryptocurrency-related complaints accounted for 11.4 billion of that. Americans over sixty filed some two hundred thousand complaints and reported 7.75 billion dollars in losses, up fifty-nine percent in a single year, with an average loss per victim of around thirty-eight thousand dollars.

Sit with that last figure. The average older victim of internet crime lost about thirty-eight thousand dollars. The average burglary loss is a fraction of that, and the burglary is the one that gets a police visit, an insurance claim, and a story people tell.

On the crypto side specifically, Chainalysis put at least 154 billion dollars received by illicit addresses in 2025. Most of that headline number is sanctions-related flows rather than theft from individuals, and it should not be quoted as if it were all stolen from consumers. The subcategories are the ones worth looking at: roughly seventeen billion in scams and fraud, about 3.4 billion in outright theft from hacks, and something in the region of eight hundred million in ransomware payments. A single exchange breach in February 2025 accounted for about 1.5 billion of the theft figure on its own, the largest such heist on record.

And every one of those numbers is an undercount, for a reason that is structural rather than statistical. These are reported losses. Fraud is chronically under-reported because the victim feels foolish, and it is under-reported worst in exactly the demographic losing the most money. Nobody files a police report for having been made to feel stupid.

The Front Door Is A Session Cookie

The mechanics matter here, because the popular picture of how this happens is about twenty years out of date.

Almost nobody is guessing your password. That was the threat model of 2005 and it drove a generation of advice about mixed case and special characters that turned out to be largely beside the point.

The modern route in is credential-stealing malware, and the thing it takes is not always the password. It is the session cookie. When you log in to your bank and complete the second factor, the site hands your browser a token that says this browser has already proved who it is, do not ask again. That token is a bearer credential. Anyone holding it is you, for as long as it is valid, and presenting it does not trigger a second factor because from the site's point of view the second factor already happened.

Industry reporting on the scale of this varies enough that I would not quote a single figure with confidence, but the consistent finding across the last two years is that a substantial minority of stolen credential records, somewhere around a third in the sets that have been analysed, arrive with live session tokens attached. That is the part worth internalising. A meaningful fraction of account takeover in 2026 completely bypasses multi-factor authentication, not by defeating it, but by arriving after it.

Which reframes the advice. Multi-factor authentication is still essential and I am not suggesting otherwise. But the marketing implied it was a wall, and it is a door with a very good lock, standing in a room the attacker may already be standing in. The thing that actually helps against session theft is not a stronger factor, it is a smaller attack surface: fewer machines that touch financial accounts, aggressive session expiry, and hardware-bound credentials that cannot be lifted and replayed from somewhere else.

They Attack The Person

Though focusing on the malware is itself slightly out of date, because the most productive attacks this decade do not bother with any of it.

They ask you. Politely, urgently, and with a plausible reason. Investment fraud is the largest single loss category in the IC3 figures and it is not a technical attack at all. It is a long, patient, entirely human confidence trick, conducted over weeks, that ends with the victim voluntarily transferring their own money using their own credentials on their own device. Every technical control in the chain works perfectly. The authentication succeeds because it is genuinely you.

What has changed recently is the cost of running that play. I wrote a review of what AI actually changed at the end of last year, and the conclusion I keep returning to applies here more than anywhere: the ceiling did not move much, the floor collapsed. Fluent, native-quality text in any language, at volume, ended the era when bad grammar was a usable filter for detecting a scam. Voice cloning from a few seconds of audio ended the era when hearing a familiar voice was evidence of anything. Neither of those required a research breakthrough. They required a commodity tool and an afternoon.

The other underrated vector is the help desk. Account recovery exists because people genuinely lock themselves out, and every recovery path is by construction a legitimate way to take over an account without the credentials. Mobile carriers are the weak link that matters most, because a transferred phone number recovers most of the rest, and a carrier support representative is a human being who can be persuaded, bribed, or simply mistaken.

Bearer Assets Came Back

All of which is bad, and none of it is new. What is new, and what the sticker in the window was actually about, is a change in the kind of property involved.

Most of financial history since the invention of the cheque has been a slow migration away from bearer assets. Cash is a bearer asset: whoever holds it owns it, and if it is taken from you there is no ledger anywhere that still says it is yours. Almost everything else we invented since is the opposite. Your bank balance is a claim, recorded by an institution, reversible by that institution, insured by a government, and disputable in a court. If someone steals your card number, the money moves and then it comes back, because at no point did the thief actually acquire ownership of anything. They acquired an entry, and entries can be corrected.

Self-custodied crypto is a bearer asset. Not metaphorically. The private key is the property. There is no institution holding a claim on your behalf, no reversal, no chargeback, no fraud department, and no court that can order the coins back because there is nobody to order. A transfer signed with your key is, by design and by the entire point of the system, indistinguishable from a transfer you meant to make.

I want to be careful here, because this is a design choice with genuine merits and I am not making a case against it. Censorship resistance and irreversibility are the same property described in two tones of voice, and the people who value the first accept the second knowingly. The problem is that this property is now held by a very large number of people who have not thought about it in those terms at all, and who are relying on habits formed in a world where a mistake could be undone by a phone call.

In the Netherlands alone, something like fourteen percent of adults hold crypto in some form. That is not a fringe. That is a substantial share of a population carrying bearer instruments in their pockets while retaining an instinctive, entirely reasonable, and completely wrong expectation that somebody would fix it if it went missing.

And Then They Come To The House

And that is the part that turns this from a story about fraud into something with a much older shape.

If a fortune is protected by cryptography that cannot practically be broken, and the entire fortune can be moved irreversibly by whoever holds a twelve-word phrase, then the cheapest attack on that cryptography does not involve computers. It involves finding the person and hurting them until they say the words. The security community has called this the wrench attack for years, as a joke about how all the elegant maths in the world loses to five dollars of hardware and a willingness to use it. It stopped being a joke somewhere around 2025.

The verified count of physical coercion incidents against crypto holders roughly doubled between 2024 and 2025, into the dozens globally, and France in particular became the focus in a way nobody has fully explained. The counts vary depending on who is doing the counting and what they classify as crypto-related, which is itself a sign of how new the category is. The cases are not ambiguous, though. In January 2025 a co-founder of a well-known hardware wallet company was kidnapped in France and one of his fingers was severed and sent as part of a ransom demand. Others have involved families, children, and organised groups recruiting teenagers to do the physical work. French prosecutors have since charged dozens of people, including minors, in connection with a wave of these.

This is the inversion that makes the whole subject worth writing about. The thesis of this post is that thieves stopped coming to your house because the valuable thing left the house. Bearer-form digital assets reverse that, precisely and cruelly. They put the valuable thing back in the house, or rather back in the person, and they do it while removing every protection the older arrangement provided. There is no vault, no ledger, no reversal, and no institution absorbing the loss. There is a human being who knows the phrase.

Which is why a sticker on a shop window is not a neutral piece of information. Publicly holding, publicly transacting, publicly enthusing about self-custodied assets is a form of disclosure about what you are carrying and how irreversibly it can be taken. Most people advertising it have not modelled it that way. I had not, until somebody said it out loud on a street in Amsterdam.

Insured Against The Wrong Thing

The gap that bothers me most, though, is not technical. It is that none of our protective institutions have moved.

Home insurance will replace a stolen television, an object almost nobody now bothers to steal. There is no equivalent standing behind the assets that actually get taken, and where cover exists for digital theft it is generally an endorsement with a low limit and exclusions wide enough to drive a lorry through.

Card fraud is genuinely well handled, and that success is why everyone's instincts are miscalibrated. Card networks decided decades ago that the customer should not carry the loss, because a payment system nobody trusts is worth nothing. So an entire generation learned that theft of money is annoying and temporary.

Push payments, where you authorise the transfer yourself, historically carried no such protection, which is exactly why fraud migrated to them. The UK made reimbursement mandatory for authorised push payment fraud in late 2024, which is the single most interesting consumer-protection development in this area and one most countries have not copied. Nothing comparable applies to a self-custodied transfer, and by construction nothing can.

So the loss lands entirely on the individual, in the category where the sums are largest, the victims are oldest, and the reporting is worst. I do not have a policy proposal. I have an observation, which is that we have built a great deal of consumer protection around a form of theft that is disappearing, and almost none around the form that replaced it.

What I Actually Do

What I actually do, offered as one person's practice rather than as advice, and deliberately boring.

Hardware keys, not codes

Anything with money behind it uses a physical security key, not SMS and not an authenticator app. The reason is specific: a key is bound to the origin and to the device, so it cannot be phished onto a lookalike site and it cannot be lifted and replayed from somebody else's machine. Codes can be read out over the phone by a person being manipulated in real time. Keys cannot.

Lock the phone number

A port-out PIN and an account lock with the mobile carrier, because the phone number is the master key to more recovery flows than anyone realises, and the carrier's support desk is the softest target in the chain.

A separate surface for money

Financial accounts get their own browser profile at minimum, and ideally their own machine that does nothing else. Not because that machine is magic, but because session tokens are stolen from the browser you use for everything, and the browser you use for everything is the one that visits things you have not vetted.

Freeze the credit files

Frozen by default at all the bureaus, thawed deliberately when needed. It costs nothing and it removes an entire category of attack that does not touch any of your accounts at all.

A family phrase, agreed out loud

A word that has to be said on any call asking for money or urgent action, agreed in person, never written anywhere. This is a direct answer to voice cloning, it takes five minutes to set up, and it is the single highest-return thing on this list for anyone with older relatives.

Do not advertise

No public discussion of holdings, no stickers, no answering the question at a party honestly. This felt faintly ridiculous to write down and then I read the French cases.

Assume no reversal

Anything held in bearer form is treated the way I would treat the same value in cash under the floorboards: split, mostly not at home, and never the whole position in one place with one person knowing where it is.

The shop was still open when we walked back past it. The sticker is a perfectly ordinary piece of commercial signage and I want to be clear I am not suggesting anyone take theirs down, or that accepting a payment method is reckless.

What I took from the conversation is smaller and, I think, more useful. We have all inherited a model of theft where the danger is a stranger in your house at night and the remedy is a lock, an alarm and a claim form. That model described the world accurately for a very long time and it describes almost nothing that is actually happening now. The house is safer than it has ever been. The person living in it is not.