Short, technical reads on holding your own keys — how drainers actually steal, what a signature authorizes, and the habits that keep funds yours. Real attack mechanics and real standards, in plain terms.
6 guides·4 topics·~6 min average read
Drainer kits like Inferno and Angel turned wallet theft into a service anyone could rent. We trace the mechanics step by step — approve, setApprovalForAll, permit and Permit2 signatures that persist until revoked, and the opaque eth_sign hash nobody can read — the exact pattern behind the $494M Scam Sniffer counted stolen in 2024.
Read the guideApprovals, permits and the opaque eth_sign hash — the signature tricks behind the $494M lost to drainers in 2024, and how to spot the ask before you click.
AttacksAttackers seed your history with look-alike addresses — 270M attempts and counting. Why "copy from history" is a habit worth breaking.
CustodyTwelve to twenty-four words from a fixed 2,048-word list — the last one a checksum — encode your whole wallet. What BIP-39 stores, and how to keep it alive.
AttacksClipboard hijackers, dust and fake support DMs never touch the chain — they touch you. The off-chain playbook, and the hygiene that beats it.
SecurityBlind signing asks you to approve a hash you cannot read. Simulation shows the outcome first. What to check on every confirm screen.
FeesMetaMask charges 0.875%, Phantom 0.85%, exchanges hide it in the spread — Nova is a flat 0.3%. Lining up what a swap actually costs.
Read how Nova keeps keys sealed on-device — air-gapped input, zero telemetry, Shield screening before every signature — then come back for the post-mortems.