• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Some Fortune Crypto pricing data is provided by Binance.
CryptoCryptocurrency

Crypto users keep getting robbed because of a simple design flaw—but a solution is at hand

By
William Mougayar
William Mougayar
Down Arrow Button Icon
By
William Mougayar
William Mougayar
Down Arrow Button Icon
May 7, 2026, 9:00 AM ET
A stack of coins tumbles over on top of a solid background.
Uniswap is one of crypto's longest-standing trading protocols.Illustration by Fortune

If you have ever paid online with Stripe’s new Link wallet, autofilled a checkout with Apple Pay, or topped up a Revolut account, you have used a piece of financial architecture that took decades to perfect. Sadly, for crypto and all its talk of reinventing money, the crypto industry has stubbornly failed to catch on.

Recommended Video

The principle is so simple it feels obvious. The thing you tap to pay should not be the thing that holds your money.

When you use Apple Wallet, your real money sits in your bank or on a credit line at a card issuer. Apple Wallet is a key. The bank is the vault. When you check out with Stripe’s Link, the funds are charged to your linked debit card or bank account. Link itself holds nothing. Revolut takes a hybrid approach: a small balance for daily spending, with the rest of your financial life parked in linked accounts and cards. In every case, the architecture is the same: the spending interface and the store of value live apart. The interface is exposed to the world. The vault stays sealed.

Crypto’s approach to wallets is decidedly the opposite. 

A crypto wallet, as the industry has built it, is not a wallet at all. It is a vault with a public-facing slot. Open MetaMask, Phantom, or any of the dozen consumer wallets that dominate the space, and what you are looking at is your entire net worth balance: Every token, every position, every digital deed, sitting at a single address controlled by a single private key. Each time you connect that wallet to an application, sign an approval, or send a transaction, you re-expose the whole thing to the open internet.

The consequences are not theoretical. Last year, on-chain analytics firm Chainalysis tallied billions of dollars stolen through phishing signatures, malicious approvals, and so-called drainer kits. Pre-packaged scams that wait for a user to connect to a compromised site and empty the wallet in seconds. These are not edge cases. They are the predictable consequence of a category mistake. The wallet is the vault. Drain one, and you have drained both.

Compare the failure modes. If your Link credentials are compromised, the bank’s fraud system reverses the charges. If your Apple Wallet is stolen, the tokenized card numbers are revoked, and your underlying cards remain untouched. If your MetaMask is drained, the funds are simply gone. There is no hotline, no chargeback, no insurer.

How did the industry that markets itself as the future of finance design something this fragile? Three reasons, none of them flattering.

The first is ideology. “Not your keys, not your coins”, the founding slogan of self-custody, was read as a license to collapse every function into a single key. The second is history. The one-key-one-address model was an early simplification when crypto was worth pennies, never engineered to carry a trillion-dollar weight. The third is inertia. Once millions of users learned the habit, the industry papered over the cracks with warning pop-ups instead of redesigning the foundation.

The fix is not better warnings. It is architectural and, crucially, does not require giving up on self-custody. It requires extending it.

The wallet of the future should look more like Link than like MetaMask. The money lives in a vault. The wallet is what you carry to the door. Both belong to you. Both are under your control. What changes is that the two are no longer the same thing.

That separation is the whole point. The wallet handles the transaction. The vault handles the money. If your wallet is compromised through a bad signature, a fake site, or a careless click, the damage stops at the wallet. The vault does not move. At worst, you lose what you were about to spend. You do not lose what you saved.

Today, in crypto, those two functions are fused. Compromise the wallet, and you compromise everything. Tomorrow, they need to be separate. The wallet will carry only what a session needs: a spending limit, allowed destinations, and a time window. When the session ends, its authority expires. The vault stays where it was, like a secure bank account.

It’s worth asking, of course, whether such a fundamental change is feasible or if, after 15 years, crypto is too locked in by path dependency to alter its design course. Fortunately, the evidence suggests not only that a change is possible, but that it might be underway.

Consider how Ethereum’s 2025 Pectra upgrade allows the front end to control a vault via a cryptographic authorization of the action. This lets existing wallets like MetaMask and Coinbase Wallet borrow these superpowers without moving funds or changing addresses. 

The rails exist. What’s missing is the framing: the industry has been selling convenience when the deeper offer is structural. Three years ago, a wallet start-up called Chamber attempted this separation, but didn’t get traction. More recently, the Porto wallet development framework supports this functionality, and it is no surprise that it was recently acquired by Tempo, the Stripe-backed blockchain.

Stripe, notably, is from the world of fintech, which baked in the critical wallet-vault separation at the outset by relying on third parties to handle the vault portion. Crypto can do the same, but while leaving the vault in the user’s own hands. That is self-custody that scales: sovereignty without the booby trap.

The opinions expressed in Fortune.com commentary pieces are solely the views of their authors and do not necessarily reflect the opinions and beliefs of Fortune.

FORTUNE CRYPTO 100: Fortune's new annual list will recognize companies driving meaningful progress in digital assets—from infrastructure and investment to applications and adoption. Is your organization is shaping the future of blockchain? Submit your nomination today.
About the Author
By William Mougayar
See full bioRight Arrow Button Icon

Latest in Crypto

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Crypto

Elizabeth Warren speaks into a microphone during a Senate Banking Committee meeting
Cryptostablecoins
Elizabeth Warren seeks information on Meta’s latest stablecoin plans in letter to Mark Zuckerberg
By Jack KubinecMay 7, 2026
3 hours ago
A stack of coins tumbles over on top of a solid background.
CryptoCryptocurrency
Crypto users keep getting robbed because of a simple design flaw—but a solution is at hand
By William MougayarMay 7, 2026
4 hours ago
Trump’s AI policy team came into office opposing everything Biden did. Now it’s on the cusp of implementing many of the same policies
CryptoWashington
Trump’s AI policy team came into office opposing everything Biden did. Now it’s on the cusp of implementing many of the same policies
By Sharon GoldmanMay 6, 2026
23 hours ago
Pantera Capital founder and managing partner Dan Morehead onstage at a conference in 2023
CryptoCryptocurrency
Wall Street is abuzz about ‘tokenized assets’—but most activity is limited to a nascent ‘wrapper’ phase, report finds
By Jack KubinecMay 6, 2026
24 hours ago
A phone with a Zcash logo is held up in front of a computer monitor displaying price information
CryptoCryptocurrency
Zcash spikes 30% after Multicoin managing partner says firm bought the token, calls it protection against wealth taxes
By Jack KubinecMay 6, 2026
1 day ago
Over 98% of stablecoins are dollar backed. That’s good for the U.S.—until it’s not
Cryptostablecoins
Over 98% of stablecoins are dollar backed. That’s good for the U.S.—until it’s not
By Jeff John RobertsMay 5, 2026
2 days ago

Most Popular

A Michigan farm town voted down plans for a giant OpenAI-Oracle data center. Weeks later, construction began
Magazine
A Michigan farm town voted down plans for a giant OpenAI-Oracle data center. Weeks later, construction began
By Sharon GoldmanMay 6, 2026
1 day ago
Tokyo is throwing out its strict office dress code and asking workers to wear shorts amid the war in Iran energy crisis
Success
Tokyo is throwing out its strict office dress code and asking workers to wear shorts amid the war in Iran energy crisis
By Emma BurleighMay 5, 2026
2 days ago
Mark Zuckerberg once gave a Facebook engineer startup advice at 2 a.m. while 'hanging out with all the interns'—she quit and raised millions after
Success
Mark Zuckerberg once gave a Facebook engineer startup advice at 2 a.m. while 'hanging out with all the interns'—she quit and raised millions after
By Orianna Rosa RoyleMay 6, 2026
23 hours ago
Economists have found an answer to slowing cognitive decline: avoid retiring early, study finds
Economy
Economists have found an answer to slowing cognitive decline: avoid retiring early, study finds
By Sasha RogelbergMay 5, 2026
2 days ago
U.S. Treasury will have to borrow $2 trillion this year just to continue functioning—more than $166 billion every month
Economy
U.S. Treasury will have to borrow $2 trillion this year just to continue functioning—more than $166 billion every month
By Eleanor PringleMay 7, 2026
6 hours ago
AI could solve America's $39 trillion debt crisis—but only if Washington abandons displaced workers, Yale Budget Lab warns
Economy
AI could solve America's $39 trillion debt crisis—but only if Washington abandons displaced workers, Yale Budget Lab warns
By Jake AngeloMay 6, 2026
24 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.