In Escaping the Bank, Did Crypto Investors Move Closer to the Hacker?

Digital assets promise freedom from governments and financial institutions. But they do not eliminate trust. They simply move it into places many investors do not understand.

For many people, the appeal of digital assets begins with distrust.

Distrust of governments that can change rules, impose restrictions, or misuse public money. Distrust of banks that charge fees, freeze accounts, or seem to profit from a system designed for everyone except the ordinary customer. Distrust of financial institutions that promise prudence, then fail spectacularly.

This instinct is not irrational.

In Malaysia, as elsewhere, people have seen that institutions can fail. Governments can make poor decisions. Powerful individuals can abuse public resources. Regulators can be slow, rules can be unevenly enforced, and ordinary people may bear the cost when those at the top make mistakes.

It is understandable, then, that some investors find digital assets attractive.

Bitcoin, Ethereum, stablecoins, decentralised finance, and self-custody appear to offer an alternative. No bank needs to approve a transaction. No government should be able to easily control the asset. No intermediary needs to be trusted. The investor can hold the private key and control their own money.

“Be your own bank,” the industry says.

But there is a problem with this promise.

In trying to move away from governments and banks, investors may be moving closer to hackers, scammers, anonymous token holders, flawed software, and systems they are not equipped to evaluate.

The misconception is not that blockchain is necessarily insecure.

The misconception is believing that blockchain security automatically makes the investor secure.

The illusion of trustless finance

Digital assets are often described as “trustless.”

The phrase sounds powerful. It suggests that the investor no longer needs to rely on a bank, broker, custodian, government, or other intermediary. The rules are written into code. Transactions are recorded on a blockchain. Ownership can be transferred without permission from a central authority.

But no financial system is truly trustless.

Digital assets do not eliminate trust. They merely change what—and whom—the investor must trust.

Instead of trusting a bank, an investor may need to trust:

  • The exchange holding their assets.
  • The wallet application they use.
  • The security of their phone, laptop, email account, and SIM card.
  • The private key or recovery phrase that controls their wallet.
  • The developers who wrote a smart contract.
  • The auditors who reviewed that smart contract.
  • The price oracle feeding data into the protocol.
  • The bridge moving assets between blockchains.
  • The token holders who govern the protocol.
  • The people or entities holding administrator keys.
  • Their own ability not to make one irreversible mistake.

This is not a smaller trust burden. It is often a more complicated one.

A conventional investor who buys a unit trust, bond, equity, or ETF through a regulated intermediary still faces risk. The investment can fall in value. The intermediary can fail. The institution can act badly. But there are usually identifiable entities, legal duties, disclosure requirements, regulators, complaint channels, and potential remedies.

The investor may be frustrated by those institutions. But they know where they are.

In decentralised finance, risk may be hidden in a smart contract, a voting mechanism, a wallet approval, a piece of code, a token’s ownership structure, or a message from a fake customer-support account.

The blockchain can work exactly as designed—and the investor can still lose everything.

The blockchain was secure. The investor was not.

This is the distinction many digital-asset investors fail to make.

They hear that a blockchain is secure because it uses cryptography, decentralised validation, and an immutable ledger. They then conclude that an investment built on that blockchain is secure.

But these are entirely different propositions.

A blockchain may be resilient against someone rewriting its transaction history. That does not protect an investor who gives away a recovery phrase, clicks a phishing link, approves a malicious wallet transaction, uses a compromised exchange, or deposits funds into a poorly designed decentralised protocol.

The security of the network is not the same as the security of the investor’s position within the network.

Claim

What it actually means

What it does not mean

“The blockchain is secure”

The network may be difficult to alter or attack at the protocol level

Your wallet, exchange account, private key, or investment is safe

“I hold my own keys”

You directly control the asset

You are protected from theft, loss, error, or fraud

“The protocol is decentralised”

Control may be distributed among token holders

No one can acquire, manipulate, or concentrate that control

“The smart contract is audited”

A reviewer has assessed aspects of the code

No vulnerability, governance flaw, economic attack, or operational risk exists

“There is no bank involved”

A conventional intermediary may be absent

There is no need for trust, governance, or consumer protection

The OECD has warned that crypto-asset users face cyber-security risks, including compromised private keys and irreversible transactions, while many retail users may not fully understand the operational responsibilities involved in managing wallets.

This is the hidden trade-off of self-custody.

Self-custody gives the investor control. But it also makes the investor responsible for security, recovery, fraud prevention, and operational resilience.

A person who buys digital assets may think they are making an investment decision. In reality, they may also be becoming their own custodian, cyber-security officer, fraud-control team, and disaster-recovery function.

When governance becomes an attack surface

The recent Term Finance incident illustrates an even less obvious risk.

Term Finance, an Ethereum-based decentralised lending protocol, reportedly lost approximately USD8.5 million after an attacker acquired sufficient governance voting power to take control of its Meta Vaults.

This was not the kind of risk most retail investors imagine when they hear the word “hack.”

They may imagine someone breaking cryptography, defeating the Ethereum blockchain, or discovering a coding error that allows funds to be stolen. But the reported attack appears to have involved something more unsettling: the attacker allegedly bought enough voting influence to control the protocol’s governance and direct assets out of the vaults.

The blockchain continued to function.

The transactions were recorded.

The system may have followed the rules embedded in its design.

Yet depositors still lost money.

That is because the risk was not only in the code. It was in the governance.

This is a problem that capital-markets professionals should immediately recognise.

In conventional markets, ownership and voting rights can create control. A shareholder with enough votes may influence the board, management, strategy, capital raising, asset sales, related-party transactions, and corporate direction.

That is why traditional capital markets have developed safeguards over decades:

  • Disclosure of substantial shareholdings.
  • Takeover rules.
  • Independent directors.
  • Minority-shareholder protections.
  • Related-party transaction controls.
  • Fiduciary duties.
  • Regulatory oversight.
  • Legal remedies and enforcement.

These safeguards are imperfect. They can fail. But they exist because ownership and control create risk.

DeFi has not removed this old problem. It has created a new version of it.

A governance token is not merely an investment asset. It can be a control instrument.

And if control can be accumulated quickly, anonymously, or cheaply, then the protocol’s governance becomes a potential attack surface.

The investor escaped the bank manager—but not the problem of who controls the money.

From institutional risk to technical risk

This does not mean governments and banks are always safer, wiser, or more trustworthy than decentralised systems.

They are not.

Malaysia’s public trust in institutions is relatively high by international survey measures: the 2026 Edelman Trust Barometer gave Malaysia an overall trust index of 71, including a government trust score of 72. Yet Malaysia’s Corruption Perceptions Index score for 2025 was 52 out of 100, an improvement from the prior year but still a reminder that institutional integrity is never guaranteed.

That tension should make investors more thoughtful, not more ideological.

The answer to institutional weakness is not automatically to abandon institutions for code.

The answer is to understand the risks of each system.

Conventional finance

Digital assets and DeFi

Institutional, political, and intermediary risk

Cyber-security, protocol, custody, governance, and operational risk

Banks or custodians may fail, misuse power, or restrict access

Wallets can be compromised; keys can be lost; transactions may be irreversible

Regulators may be slow, weak, or inconsistent

There may be unclear jurisdiction, anonymous actors, and limited legal recourse

Intermediaries charge fees and can impose conditions

Investors may face direct responsibility for complex technical risks

Legal remedies may exist, even if imperfect

“Code is law” can mean the loss is final even when the outcome is obviously unfair

The phrase “out of the frying pan and into the fire” may be too simple.

A better description is this:

Investors may leave one system of trust without realising they have entered another—one with different gatekeepers, different failure modes, and fewer ways to recover when something goes wrong.

The danger is not decentralisation itself. The danger is treating decentralisation as a substitute for due diligence, governance, security controls, and accountability.

What investors should ask

Before investing in or depositing assets into a digital-asset platform, investors should ask questions that go beyond price charts, token narratives, and social-media enthusiasm.

Who controls the assets?

Who holds the private keys? Is the investor using self-custody, a centralised exchange, a third-party custodian, or a smart-contract vault? What happens if a key is lost, stolen, or compromised?

Who can change the rules?

Can developers, administrators, multisignature signatories, or governance-token holders upgrade contracts, alter withdrawal rules, redirect funds, or change investment strategies?

How concentrated is governance power?

Are a few wallets able to control proposals? Can voting power be borrowed, delegated, purchased, or accumulated cheaply in a thin market? Is there a meaningful delay between a governance vote and implementation?

What protections exist?

Is there a timelock? Can depositors withdraw during that period? Are there independent vetoes, guardians, multisignature requirements, or risk controls? Have they been tested against a hostile-governance scenario?

What happens if something goes wrong?

Is there a legal entity? A regulator? A complaint mechanism? Insurance? A recovery process? Or is the investor relying on an anonymous online community to voluntarily make them whole?

Malaysia’s regulatory framework for recognised digital-asset exchanges is evolving, including stronger requirements around governance, client-asset safeguards, and access to the Financial Markets Ombudsman Service for DAX customers. These protections do not make a digital asset a good investment, and they cannot remove price risk. But they demonstrate an important principle: investor protection is not merely about preventing losses. It is also about having accountability and recourse when systems fail.

The real lesson

The appeal of digital assets is understandable.

People want more control over their money. They want alternatives to institutions that have sometimes failed them. They want a system that does not depend entirely on political power, banking gatekeepers, or corporate intermediaries.

But “be your own bank” is not just a slogan about freedom.

It is a warning about responsibility.

A bank does more than hold money. It operates cyber-security systems, fraud monitoring, recovery procedures, customer support, compliance controls, audit processes, and legal infrastructure. These systems can fail, and institutions can abuse their power. But removing them does not remove the need for their functions.

It may simply place those functions on the individual investor.

Digital assets do not eliminate trust. They relocate it.

They move trust from institutions we can see—governments, banks, brokers, regulators, and courts—to systems many investors cannot see or evaluate: cryptographic keys, wallet permissions, smart contracts, governance tokens, anonymous developers, and code that may execute exactly as written even when the result is catastrophic.

The lesson is not to trust governments blindly.

It is not to trust banks blindly.

And it is certainly not to trust code blindly.

There is no trustless financial system. There are only different trust arrangements, different failure modes, and different answers to the most important question in finance:

When something goes wrong, who bears the loss?

Similar Posts

Leave a Reply