Security & Compliance Glossary
Plain definitions of the vocabulary that actually matters on a security and compliance desk — approvals, drainers, the Travel Rule, VASPs, proof of reserves. Each entry says what the term means and why it matters, and links the incidents where it showed up.
30 terms defined
A
Sending a tiny or zero-value transfer from an address whose first and last characters match one you have used, so that copying from your transaction history…
B
Approving a transaction your signing device cannot decode into human-readable terms, so it displays raw data rather than what the transaction will do.
A system that locks an asset on one chain and issues a representation of it on another, releasing the original when the representation is destroyed.
C
The authorisation category under the EU's Markets in Crypto-Assets Regulation for firms providing crypto-asset services.
Holding private keys on a device or medium that has never been, and is not, connected to a network.
Custodial means a third party holds the keys and you hold a claim against them; non-custodial means you hold the keys and there is no counterparty.
F
An uncollateralised loan that must be borrowed and repaid within a single transaction, reverting entirely if repayment fails.
G
Acquiring enough voting power to pass a proposal that benefits the attacker, rather than exploiting a code defect.
H
A dedicated device that stores private keys in isolation and signs transactions internally, so the key never reaches an internet-connected computer.
A wallet whose keys are held on an internet-connected system so that transactions can be signed automatically.
K
Ongoing screening of blockchain transactions against risk indicators — sanctioned addresses, mixers, known theft proceeds — as distinct from identity checks on the customer.
M
The European Union's Markets in Crypto-Assets Regulation — a directly applicable framework covering crypto-asset service providers, asset-referenced tokens and e-money tokens, and market abuse.
A wallet requiring signatures from several keys before a transaction executes, expressed as a threshold such as three of five.
O
Distorting the price feed a protocol relies on, so that the protocol values collateral or debt incorrectly and can be exploited at that valuation.
P
An off-chain signed message that grants a token allowance without an on-chain approval transaction, defined by EIP-2612 and similar schemes.
A published attestation that a custodian holds assets corresponding to customer balances, usually via a cryptographic commitment to the liability set plus evidence of controlled addresses.
R
The ordered list of words from which a wallet's private keys are derived. Also called a seed phrase or mnemonic.
A vulnerability class in which a contract calls out to another contract before updating its own state, allowing the external contract to call back in and…
A fraud in which a project's operators withdraw pooled liquidity or exercise a retained privilege to expropriate holders, having marketed the project as legitimate.
S
Checking counterparties and addresses against government sanctions lists, such as the US Treasury's Specially Designated Nationals list.
A requirement that customer assets be held separately from a firm's own operating funds and identifiable as customers'.
Persuading or bribing a mobile operator to transfer a victim's phone number to an attacker-controlled SIM, capturing SMS codes and account recovery.
A review of contract source code by a third party against known vulnerability classes and the protocol's intended behaviour.
Compromising a dependency, build system, package registry or distribution channel so that malicious code reaches users through a trusted route.
T
A mandatory delay between a privileged action being approved and being executed.
A standing permission allowing a named contract address to move a specified amount of one of your tokens, at any time, until the permission is changed…
An anti-money-laundering requirement that originating and beneficiary information accompany transfers of value above a threshold between regulated institutions.
V
An address generated by repeated trial until it begins with a chosen string of characters.
The FATF term for a business conducting virtual asset activities on behalf of others — exchange, transfer, custody, or participation in financial services relating to an…
W
Malicious code — usually injected into or hosted as a web front end — that induces a user to sign a transaction or approval transferring their…