These two weeks, security incidents have piled up—your account may be riskier than you think
Recently, several security incidents have happened one after another in the circle. Someone’s account was stolen; even after it was frozen, the API was not removed, and 340,000 USDT was transferred out anyway. There were also cases on public chains where, due to a gateway vulnerability, extra tokens were minted—leading to a direct restart.
My biggest takeaway after reading everything is: most people lose money not because of the market, but because of poor security habits.
Here are a few solid, actionable recommendations—you can finish them in ten minutes.
First: minimize API permissions. For quant and copy-trading tools, enable only read and trade permissions. Never enable withdrawal permissions. You must bind an IP whitelist. If you don’t need it, delete it immediately. That 340,000 USDT case happened because of the API.
Second: enable the withdrawal whitelist. Allow withdrawals only to the few addresses you commonly use. Even if the account gets logged into, the money can’t be transferred out.
Third: set an anti-phishing code. Official emails you receive in the future will include this code. If there’s no code, treat it as a scam.
Fourth: if you can use a passkey, don’t rely only on SMS verification. Every year there are cases of phone numbers being hijacked.
Fifth: for large assets that you won’t move for a long time, store them in a cold wallet. Periodically revoke on-chain authorizations. Messy contract approvals are basically backdoors left for hackers.
One more thing that many people ignore: don’t click any “airdrop” links in groups; don’t save screenshots of your seed phrase to your photo album; and don’t trust customer service from private chats.
In a bull market, there are many opportunities to make money—but your principal only has one life. Once it’s gone, it’s really gone.