Recently, I saw someone’s wallet being drained again. After flipping through transaction records for a while, I finally found out that six months ago, they granted unlimited authorization to a contract that looked very legitimate... Basically, this thing is like giving your house key to a stranger and saying, "Come and go as you please."



During the time when new L1/L2s were offering incentives to attract TVL, it was even easier to fall for this. People would complain about mining and selling, but at the same time, they’d approve max permissions just to save trouble, then forget about it. Revoking permissions is like sleeping: not doing it won’t cause immediate death, but someday something will go wrong, and you’ll realize, “Why didn’t I lock the door?” My current habit is to revoke permissions right after I finish or use something. It’s a bit of trouble, but at least I can sleep peacefully.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin