The perfect password book is combined with a word you remember but don't write down as a pepper, but I doubt it's much of a problem in practice; it takes one leak of an u hashed password to break the code.
I think for many the risk of someone breaking in and stealing your password book is much smaller than the risk of a centralised password manager getting hacked (LastPass and friends).
And your wife bought something from my eBay store. Now I have your home address.
And if I am a ruthless character then I quietly break into your house one day with th3e objective of leaving no sign I was ever there. Search for written down passwords, take a photo, leave.
You'd find a legit way into the house.
The point is that companies put vast effort into digital security but in many cases it's easily compromised by going to the home of the person that is the hacking target.
Especially if your parents accidentally left you home alone..
On a desk at home? It is marginal, certainly a burglary is a low frequency event, but we also have events like fire that make it insecure in other ways.
https://twitter.com/LukeDashjr/status/1609618498027753472
EDIT: Right, maybe it's all
Which implies that it is indeed most of his bitcoins.
A "hot" wallet is a type of wallet that's typically stored in internal storage of a network-connected device, such as your personal computer or your smartphone. This is riskier way of storing funds because they can be exfiltrated by malware. You would typically use a hot wallet for day to day transactions.
A "cold" wallet is a type of wallet where private keys to control the funds are never in contact with a network-connected device. They're typically stored in the form of recovery phrases written on paper or metal (in a secure location), or some kind of a smart card that securely stores private keys and exposes an interface to sign individual transactions (e.g. Ledger devices). Funds stored in a cold wallet are much harder to access, but are extremely (or completely) resistant to theft, short of physical access.
In crypto a "hot" wallet should be treated as cash, while a "cold" wallet is more like a savings account.
It's possible to create a bitcoin wallet completely offline in a secure environment. The details to the wallet are then stored physically in a secure location/medium. This is called a cold wallet. People typically use a cold wallet for long-term storage of coins.
and the bulk of it should be on a paper wallet, in the vault of a bank or another real world institution. the hardware used to generate this key should be wiped out. so if he followed best practices, he didn't lose this money
edit: just found out that the btc was stolen from a dedicated server on ColoCrossing. this makes no freaking sense. no server connected to internet should have access to the keys to your btc (or access to any keys that could be used to later on grab cryptocurrency keys). hot wallets should be hardware wallets, cold wallets should be acid free paper
Plenty of "normal people" use combinations of physical security to protect their assets. Safes, deposit boxes, tamper proof materials etc.