Security

Security for holders: a routine for custody, access and permissions

Simple, repeatable measures reduce exposure to phishing, loss of access and excessive contract permissions.

Dispositivo seguro e backup para proteção de ativos digitais
Dispositivo seguro e backup para proteção de ativos digitais

Protect the recovery point

Email, exchange accounts and authentication devices are part of custody. CISA recommends MFA and identifies FIDO/WebAuthn as the most phishing-resistant option when available.

Keep recovery phrases offline, never in photos, messages or unplanned cloud storage. For meaningful transfers, confirm the address on the signing device and make a small test first.

Contract permissions are also risk

Connecting a wallet to a site is not the same as granting permission to spend tokens. Ethereum.org warns that unlimited approvals can remain valid even after you withdraw funds from a platform.

A monthly routine

Review MFA, connected devices, token permissions, browser extensions and updates. Do this calmly, not in response to an alert on social media.

Sources: CISA MFA and Ethereum.org token-access guidance. Reviewed on July 18, 2026.

A sound market reading combines data, context and clear risk limits.