Just now I almost dumbed myself again: searched for a project’s official website, and ended up clicking on a phishing site that looked exactly the same, a pop-up asked me to “verify wallet,” luckily I noticed the domain had an extra hyphen and stopped. Now I’m becoming more sensitive about “signing,” especially those authorization prompts where you just click confirm, and suddenly you give unlimited access, not to mention seed phrases—if someone asks me, I just assume the other side isn’t human.



To put it plainly, there are three red lines for wallet security: never put your seed phrase on a webpage or send screenshots; don’t treat signing as “logging in,” make sure you understand what you’re authorizing and whether it’s unlimited; for unfamiliar sites, it’s better to hold back a little than to rush in recklessly. Recently, everyone’s been criticizing miners/validators for their income and MEV causing unfair ordering, I understand that, but no matter how much you yell “fairness,” if you treat signing as a game of clicking buttons, your assets will only be harvested faster… Anyway, I now prefer to play it safe and double-check everything.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin