Using Bitcoin on a public Wi-Fi hotspot abroad is one of the most common security mistakes Australian travellers make, and it's easy to understand why. You're in an unfamiliar country, your mobile data is expensive or patchy, and the hotel lobby has a perfectly usable free network. The problem is that network is almost certainly shared with strangers, and in some locations it may be deliberately set up to intercept traffic.
Why public Wi-Fi abroad is riskier than at home
Public Wi-Fi in Australia already carries risks, but those risks multiply when you're travelling internationally. Regulations around network security vary enormously between countries. In some regions, there's no legal obligation for a café or hostel to secure its network at all. Beyond that, you're less likely to recognise a suspicious network name or notice that "Airport_Free_WiFi" isn't the official airport service.
The two most common threats on open networks are man-in-the-middle attacks and rogue access points. In a man-in-the-middle attack, a third party positions themselves between your device and the router, capturing everything you transmit. A rogue access point takes that one step further: an attacker creates a fake network with a convincing name, waits for devices to connect automatically, and then reads all outgoing traffic. Neither attack requires any sophisticated equipment.
Bitcoin transactions can't be reversed once they're broadcast. That asymmetry is what makes network-level interception so serious for crypto holders.
What attackers can and can't do
It helps to be clear about what the actual risk is. An attacker on the same public network can't directly steal Bitcoin from your wallet by watching your traffic. What they can do is more subtle.
- Intercept login credentials for exchange accounts that don't enforce HTTPS properly.
- Inject malicious code into unencrypted web pages you visit, including fake wallet interfaces.
- Capture session tokens that let them impersonate you on exchanges or wallets accessed through a browser.
- Redirect you to a phishing site that looks like your wallet or exchange login page.
The risk to your private keys is lower if your funds are in a hardware wallet that never connects to the internet. But if you're logging into an exchange, checking a software wallet, or copying a receive address on a compromised network, you're exposed.
Bitcoin clipboard hijacking is a related threat worth knowing about. Malware delivered through an unsafe network can silently swap the wallet address you paste into a transaction. How to recognise a Bitcoin clipboard hijacking attack covers that specific attack in full detail.
Steps to take before you connect abroad
The best protection starts before you leave Australia, not after you've already opened your laptop in a Bangkok café.
First, install a reputable VPN and test it on your home network. A VPN encrypts all traffic between your device and an exit server, making the local network largely irrelevant to an attacker. Not all VPNs are equal: look for one with a no-logs policy audited by an independent firm, a kill switch that cuts your internet if the VPN drops, and servers in countries you're visiting. How to safely use a VPN with Bitcoin walks through what to look for in the specific context of crypto security.
Second, move significant Bitcoin holdings to cold storage before you travel. If your funds are on a hardware wallet that never touches an internet-connected device, they can't be reached through a network attack. Only keep a small operational balance in a hot wallet or exchange account.
Third, enable two-factor authentication on every exchange and wallet account you might access while abroad. Use an authenticator app, not SMS. SIM-based 2FA can be bypassed even without network access through a separate attack vector.
Safer habits when you're already connected
Sometimes you're already on a public network before you've had a chance to plan. In that situation, a few habits reduce your exposure significantly.
Turn on your VPN before you open any crypto-related app or browser tab. Order matters: if you check your wallet before the VPN is active, that traffic has already left your device in the clear. Confirm the VPN is connected by checking your IP address at a plain lookup site, not through an app that might misreport.
Avoid logging into exchanges in a browser on a public network if you can. The exchange's mobile app with certificate pinning enabled is harder to intercept than a browser session. Certificate pinning means the app will reject any certificate that doesn't match its expected value, making SSL-stripping attacks much harder.
Double-check every wallet address before you confirm a transaction. Read the first four and last six characters of the destination address, not just a glance at the first few. Rogue network tools can inject modified addresses into copy-paste buffers or modify the displayed address on a web page. Verifying character by character is the only reliable check.
If you're not actively using Bitcoin, lock your phone and disable Wi-Fi. Devices left on an open network continue to broadcast and receive traffic even when your screen is off.
Networks to treat as high risk
Not all public Wi-Fi is equally dangerous. Hotel business centre computers are the highest risk category: shared hardware, no control over installed software, no way to know what's been logged. Airport lounge networks are lower risk than terminal floor networks but still untrusted. Café networks in countries with poor cybersecurity infrastructure carry more risk than the same network in Singapore or Japan.
Any network that doesn't require a password is open to anyone and should be treated as actively hostile. Password-protected networks are safer but not safe: the password is often printed on a sign visible to anyone who walks in.
Your own mobile data connection is safer than any public Wi-Fi when the stakes are high. International roaming data is expensive, but the cost of a compromised exchange account is higher. A portable travel router that accepts a local SIM card gives you your own encrypted network in most countries for under AU$80.
What to do if something goes wrong
If you suspect your device was compromised on a public network, the first step is to disconnect immediately. Don't close apps or take other actions that might overwrite evidence or trigger further damage.
From a separate, trusted device, change passwords and revoke active sessions for every exchange and wallet account you accessed on the compromised network. Most exchanges allow you to view and terminate active sessions from the security settings page. Do this before anything else.
If you use a software wallet, generate a new wallet on a clean device, verify your seed phrase is intact, and transfer funds to the new wallet before accessing it on any network. The Bitcoin seed phrase storage guide covers how to verify your backup is complete and accessible before you need it urgently.
Contact McLeod Pacific Investments if you have concerns about the security of a buy or sell transaction initiated during a period of possible compromise. Acting quickly gives you the best chance of limiting exposure before a fraudulent transaction can be broadcast or settled.

