官方的 MASTR 标志 MASTR
菜单
阅读文章

钓鱼攻击、漏洞与隐私

40 #Web3 Security Tips You Wish You Knew Sooner — Save this ❗

31. Watch out for transaction fees too low to be true. Gas exploits and failed transactions can be used against you.

原文为英语,导航提供七种语言。

01

查看 X 原帖 ↗

🚨🚨🚨🚨🚨🚨🚨🚨

40 #Web3 Security Tips You Wish You Knew Sooner — Save this ❗

Your future self will thank you.

1. Use a burner wallet for unknown sites.
Don’t risk your main bag on a new mint.

2. Revoke token approvals regularly.
Old dApps could still access your funds.

3. Bookmark project websites.
Scammers buy lookalike domains.

4. Never share your seed phrase. Ever.
Not with “support,” not with “devs,” not anyone.

5. Disable DMs on Discord and Telegram.
Scammers pretend to be admins.

6. Use hardware wallets for serious funds.
Hot wallets are too easy to exploit.

7. Enable 2FA — use an authenticator app, not SMS.
SIM swaps are common.

8. Don’t sign blind transactions.
Read the prompt or use tools like Rabby/Fire.

9. Avoid shady browser extensions.
They can hijack sessions or log keystrokes.

10. Always double-check wallet addresses.
Clipboard malware can replace them.

11. Fake airdrops are a trap.
Don’t touch mystery tokens in your wallet.

12. Use different wallets for storing, trading, and minting.
One wallet, one purpose.

13. If someone pressures you to act fast — it’s a scam.
Fear of missing out = their tool.

14. Look up teams on LinkedIn, GitHub.
No online presence? Major red flag.

15. Audits help, but they’re not gospel.
Some rugs had them. Check details.

16. Use multisig for big wallets or DAO funds.
Two keys = safer decisions.

17. Avoid transacting over public Wi-Fi.
Use a VPN or mobile data.

18. Don’t store passwords in your browser.
Use Bitwarden, 1Password, etc.

19. Never download files from random Discord servers.
Could be malware in disguise.

20. DYOR means read everything — whitepaper, tokenomics, contracts.
Not just hype tweets.

21. Ask questions in public chats.
Good projects welcome transparency.

22. Don’t grant permissions you don’t understand.
If unsure, don’t approve.

23. Avoid portfolio trackers that need wallet access.
Watch-only mode is safer.

24. Check contract history on-chain.
New contract? Could be a honeypot.

25. Watch for upgradeable proxies in contracts.
Logic can change after you invest.

26. Use browsers like Brave for more secure browsing.
Fewer ads, more protection.

27. Never trust links in YouTube or Twitter comments.
Scammers target trending content.

28. Think before connecting your wallet.
No reward is worth losing everything.

29. Beware fake wallet apps.
Only download from official sources.

30. Learn basic contract reading or use a trusted reader.
Knowledge = protection.

31. Watch out for transaction fees too low to be true.
Gas exploits and failed transactions can be used against you.

32. Use read-only wallets for monitoring.
No chance of accidental approvals.

33. Check for social proof — but don’t trust it blindly.
Fake followers, fake hype exist.

34. Trust your gut.
If it feels off, walk away.

35. Don’t interact with "dust" tokens.
Some can trigger approval exploits.

36. Always test new dApps with minimal amounts first.
Verify it behaves correctly.

37. Set spending limits in your wallet settings.
Stop contracts from draining everything at once.

38. Stay up to date on recent #Scams .
They evolve fast — learn from others’ mistakes.

39. Spread your assets across wallets.
One hack shouldn’t ruin everything.

40. Follow @mastrxyz and read what we do.
We help you protect your crypto, check real projects, and offer insurance against verified #rugs

提及的账号

查找所选文章中提及的 X 账号。被提及不代表受到指控或获得推荐。

相关研究

钓鱼攻击、漏洞与隐私

Privacy, surveillance and control

A discussion of surveillance, data collection and the relationship between privacy and personal autonomy.

原创文章4 min
MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包