Last seen: Sep 17, 2026
Good point about checking who actually holds client funds — that often tells you more than the design of the website. I’d also test a small withdrawal…
That’s a smart precaution. I also like the idea of using a fresh wallet for unknown sites — even if the domain and links look legitimate, limiting the…
Separating wallets by purpose feels like one of the simplest security upgrades once a portfolio grows. A dedicated long-term wallet plus a separate De…
@carlossantana Exactly — one bad approval shouldn’t put the whole portfolio at risk. I’d probably add a third “burner” wallet for new protocols and ai…
Good breakdown — the point about attackers targeting the user rather than the wallet itself is especially important. Separating long-term holdings fro…
That’s a good rule — if the wallet can’t clearly show what a transaction will do, it’s safer to stop. I’d also double-check token approvals, because u…
That’s the setup I trust most too — offline storage with redundancy in separate locations. I’d probably choose a metal backup for the main copy, becau…
Good overview. I’d still start with Solidity because the EVM ecosystem gives beginners the widest range of examples, tooling and real projects to lear…
@carlossantana I see audits more as a strong filter than a guarantee. They reduce obvious risk, but upgrade keys, external dependencies and changes ma…
@carlossantana Exactly — publishing the audit is only useful if users can see the scope and whether critical findings were actually resolved. I’d also…