Skip to content

docs(wallet-security): add security best practices for hot wallets - #649

Open
0xusmanf wants to merge 5 commits into
security-alliance:developfrom
0xusmanf:develop
Open

0xusmanf wants to merge 5 commits into
security-alliance:developfrom
0xusmanf:develop

Conversation

@0xusmanf

Copy link
Copy Markdown
Contributor

What does this PR change?

What changed

Added a Security Best Practices section to the hot wallet documentation (docs/pages/wallet-security/for-beginners-and-small-balances.mdx), covering:

  • Strong, unique passwords and antivirus protection
  • Setting auto-lock timers
  • Using dedicated browser profiles with minimal extensions and disabled browser sync
  • Avoiding wallet exposure during screen shares or remote calls
  • Added 0xusmanf to the list of document contributors alongside pinalikefruit.

Why

To provide actionable guidelines for users storing funds in hot wallets, helping them protect their keys from malware, unauthorized browser extension access, and social engineering attacks during screen shares.

Hi @pinalikefruit, could you please review these changes when you have a chance? Thanks!

Type of change

  • New content
  • Edit to existing content
  • Outline / structure change
  • Typo or formatting fix
  • Tooling / config

If applicable

  • Editing existing content: tagged the current contributors from the attribution list
  • Framework has a steward: asked them to review
  • Outline change: updated vocs.config.ts with the dev: true parameter
  • Want community feedback: shared this PR in our Discord

Stuck on anything? Just write it here and we're happy to help.

@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
built with Refined Cloudflare Pages Action

⚡ Cloudflare Pages Deployment

Name Status Preview Last Commit
frameworks ✅ Ready (View Log) Visit Preview 94d1a45

@pinalikefruit pinalikefruit left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @0xusmanf ,

Thanks you for the contribution.

I’m not entirely sure about this section, as many points, such as "Strong Password," "Antivirus Software," or "No Wallet Exposure on Calls" are already mentioned elsewhere in the framework. Regarding extensions, the "Minimal Auto-Lock Time" recommendation specifies a concrete value. The suggestion to use a dedicated profile is sound good, and there is no need to recommend additional extensions solely for interacting with dApps.

Since many of these recommendations are repeated in other parts of the framework, I think the "Key Considerations & Trade-offs" section could be improved instead.

@0xusmanf

Copy link
Copy Markdown
Contributor Author

Hi @pinalikefruit, thank you for the review and feedback.

1- Strong Password: Agreed, but instead of removing it completely, I'd link it to the relevant section since it's in a different framework.
2- Antivirus Software: I see the reader is made aware of the malware risk in Key Considerations & Trade-offs, but this point recommends how to minimize that risk. The point sure needs to be rephrased to avoid repetition.
3- No Wallet Exposure on Calls: Agreed and removed.

and there is no need to recommend additional extensions solely for interacting with dApps.

I'm not sure what you meant here; could you please clarify?

Regarding putting them under Key Considerations & Trade-offs, happy to do that, but in my opinion, this section is more about risk awareness, and the Security Best Practices section is about minimizing risk.

@pinalikefruit

Copy link
Copy Markdown
Collaborator

Fair enough @0xusmanf , I see your point, you can leave it as "Security Best Practices."

I would focus on adding as much value as possible to the "Security Best Practices" section regarding hot wallets for example , recommending a dedicated device (like a $200 laptop) solely for using the hot wallet. I wouldn't recommend installing anything else, no extra browser extensions, antivirus software, or other apps etc.

@0xusmanf

Copy link
Copy Markdown
Contributor Author

recommending a dedicated device (like a $200 laptop) solely for using the hot wallet. I wouldn't recommend installing anything else, no extra browser extensions, antivirus software, or other apps etc.

Good point; I was thinking of adding it as a separate section, Software Wallets on Air-Gapped Devices, which sits between a hot wallet and a cold wallet. Hot wallets and Software Wallets on Air-Gapped Devices both have different risk profiles, so it is important to keep them separate to avoid any confusion.

Since people are going to use hot wallets on their primary devices anyway, what I would do is keep the Security Best Practices section as is and add Software Wallets on Air-Gapped Devices separately.

I’d love to get your thoughts on this approach. Does that structure make sense to you?

@pinalikefruit

Copy link
Copy Markdown
Collaborator

Exactly; the idea is not to repeat the same information on every page, but rather to try to provide maximum value on each one.

Speaking of wallets that sit between hot and cold wallets
There is this one: https://frameworks.securityalliance.dev/wallet-security/cold-vs-hot-wallet
And since you mentioned software wallets this one is currently undeveloped: https://frameworks.securityalliance.dev/wallet-security/software-wallets

Curious to know what you’re proposing and the best way to fit the information in.

@0xusmanf

Copy link
Copy Markdown
Contributor Author

Thanks for sharing those links, @pinalikefruit!

I agree there's baseline overlap in core hygiene (like minimal auto-lock timers and strong passwords) regardless of setup.

To address this cleanly without overloading the beginner hot wallet guide:

  1. This PR: I'll add those shared baseline security considerations to /cold-vs-hot-wallet#key-security-considerations. The rest of PR docs(wallet-security): add security best practices for hot wallets #649 stays focused on host hygiene for primary daily-driver devices (dedicated browser profiles, malware protection, etc.).
  2. Future PR: Operational controls for dedicated or air-gapped setups (offline QR signing, strict isolation) belong under a different threat model. Once my research is complete, I'll open a separate PR to build out the placeholder at /wallet-security/software-wallets.

I'll push the updates to the cold-vs-hot-wallet section shortly so we can get PR #649 merged. Let me know if this works for you!

@pinalikefruit

Copy link
Copy Markdown
Collaborator

Yes, please; first add the contributions to this PR, and then we can continue with separate PRs.

@0xusmanf

Copy link
Copy Markdown
Contributor Author

Hi @pinalikefruit, I have pushed the changes, kindly review.

This branch was successfully deployed

1 active (outdated) deployment
Preview — 94d1a454 Deployed Sep 23, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants