[image: i.imgur.com]
[image: i.imgur.com]
[image: i.imgur.com]
[image: i.imgur.com]
[image: i.imgur.com]
[image: i.imgur.com]
sieger [1760232] Level 98
From the 12 newest archived posts.
Likes as archived at fetch time, adjusted for how long each post had been up. Scored posts only; the full score pass runs after the import.
All types of wallet/token/NFT hacks fall into two categories:
[image: cdn.mos.cms.futurecdn.net]
Token approvals are essentially a permission for smart contract to access and move specific type or amount of a token from your wallet. Like giving permission to OpenSea or Uniswap to move your NFTs so you can see them.
In detail, on Ethereum network, everything except ETH is ERC-20 token. NFTs are are mostly ERC-721 and 1155 tokens respectively. Their approval mechanics work similar to ERC-20s but for NFT marketplaces.
If you are not careful about that, you might just give grant tokens permission to a malicious smart contract to get your assets stolen.
Many DeFi apps will prompt for unlimited approval of ETC20 token by default. This is to improve user experience, and it is more convenient as it does not require potential future approvals thus saving on time and gas fees.
So limiting this for max amount of tokens will fix the problem.
NFT marketplaces will ask for that kind of approval, thus when you sell and NFT to a buyer, that marketplace’s smart contract can move the NFT automatically to the buyer. This sounds cool, but can also be used by malicious websites/contracts to steal your NFTs.
Example: When you are about to mint an NFT, from a website which looks totally legitimate, in the background their contract searches for your wallet and chooses the highest value NFT and asks for permission to take it, and when you think you are minting, you are giving away your NFT.
Limit your risk to approvals:
Hot wallets are connected to the internet thtough your computer or phone so the keys stored online.
Cold wallets are hardware devices where the key is generated and stored offline.
So it is a lot safer to use hardware wallet, I would suggest Coldcard mk4 for #btc, and trezor for #eth
There are some stuff to look for:
The point is assume that everything you have in a how wallet is already compromised or can be at any point, so act accordingly.
I’ve been having a lot of deep thoughts recently, I go through stages of reflection more and more often now as I get older.
In fighting we always used to do this exercise.
When a new guy had a fight coming up we’d ask them
“Imagine you’re fighting for the UFC title, how would you train?”
What would your diet be?
What would you do outside training?
Who would you spend time with?
What time would you wake up?
How hard would you train?
What would you spend your money on?
How often would you go out and get drunk at the weekend?
What would you do with every minute of every day?
They would always say the same thing… “I’d train harder than I have ever before, I’d eat perfectly, I’d be 100% focused on becoming UFC champion”
Then you would simply say…
“Great… so let’s pretend your next amateur fight is for the UFC title and you have to do everything you just described”
Those that followed through with it never lost.
Everyone thinks external things are going to help us become better versions of ourselves…
The reality is we become the best version of ourselves by BEING the best version of ourselves everyday.
Treat today like you are already better than your villain that guy who has everything he could ever dream of…
How does that guy walk, talk, enter a room, treat people, work, how does he live daily?
Then just start doing that soon you’ll realize you were that man all along.
I think it is just commonsense, if you do not install random exe files, there wont be any problem.
Sometimes they hijack major software (like ccleaner) but soon after it will be fixed. So as a user who has half of a brain, no need to worry about that.
All types of wallet/token/NFT hacks fall into two categories:
[image: cdn.mos.cms.futurecdn.net]
Token approvals are essentially a permission for smart contract to access and move specific type or amount of a token from your wallet. Like giving permission to OpenSea or Uniswap to move your NFTs so you can see them.
In detail, on Ethereum network, everything except ETH is ERC-20 token. NFTs are are mostly ERC-721 and 1155 tokens respectively. Their approval mechanics work similar to ERC-20s but for NFT marketplaces.
If you are not careful about that, you might just give grant tokens permission to a malicious smart contract to get your assets stolen.
Many DeFi apps will prompt for unlimited approval of ETC20 token by default. This is to improve user experience, and it is more convenient as it does not require potential future approvals thus saving on time and gas fees.
So limiting this for max amount of tokens will fix the problem.
NFT marketplaces will ask for that kind of approval, thus when you sell and NFT to a buyer, that marketplace’s smart contract can move the NFT automatically to the buyer. This sounds cool, but can also be used by malicious websites/contracts to steal your NFTs.
Example: When you are about to mint an NFT, from a website which looks totally legitimate, in the background their contract searches for your wallet and chooses the highest value NFT and asks for permission to take it, and when you think you are minting, you are giving away your NFT.
Limit your risk to approvals:
Hot wallets are connected to the internet thtough your computer or phone so the keys stored online.
Cold wallets are hardware devices where the key is generated and stored offline.
So it is a lot safer to use hardware wallet, I would suggest Coldcard mk4 for #btc, and trezor for #eth
There are some stuff to look for:
The point is assume that everything you have in a how wallet is already compromised or can be at any point, so act accordingly.
I’ve been having a lot of deep thoughts recently, I go through stages of reflection more and more often now as I get older.
In fighting we always used to do this exercise.
When a new guy had a fight coming up we’d ask them
“Imagine you’re fighting for the UFC title, how would you train?”
What would your diet be?
What would you do outside training?
Who would you spend time with?
What time would you wake up?
How hard would you train?
What would you spend your money on?
How often would you go out and get drunk at the weekend?
What would you do with every minute of every day?
They would always say the same thing… “I’d train harder than I have ever before, I’d eat perfectly, I’d be 100% focused on becoming UFC champion”
Then you would simply say…
“Great… so let’s pretend your next amateur fight is for the UFC title and you have to do everything you just described”
Those that followed through with it never lost.
Everyone thinks external things are going to help us become better versions of ourselves…
The reality is we become the best version of ourselves by BEING the best version of ourselves everyday.
Treat today like you are already better than your villain that guy who has everything he could ever dream of…
How does that guy walk, talk, enter a room, treat people, work, how does he live daily?
Then just start doing that soon you’ll realize you were that man all along.