From 9c949a942dcf706f90d5bf39ccecdf0be8a86634 Mon Sep 17 00:00:00 2001 From: 0xusmanf <110072406+0xusmanf@users.noreply.github.com> Date: Wed, 23 Sep 2026 00:30:08 +0500 Subject: [PATCH 1/5] docs(wallet-security): add security best practices for hot wallets --- .../for-beginners-and-small-balances.mdx | 18 +++++++++++++++++- 1 file changed, 17 insertions(+), 1 deletion(-) diff --git a/docs/pages/wallet-security/for-beginners-and-small-balances.mdx b/docs/pages/wallet-security/for-beginners-and-small-balances.mdx index a0de30498..37b8cda98 100644 --- a/docs/pages/wallet-security/for-beginners-and-small-balances.mdx +++ b/docs/pages/wallet-security/for-beginners-and-small-balances.mdx @@ -6,7 +6,7 @@ tags: - Security Specialist contributors: - role: wrote - users: [pinalikefruit] + users: [pinalikefruit, 0xusmanf] - role: reviewed users: [Coinspect] - role: fact-checked @@ -65,6 +65,22 @@ on specific criteria such as transaction clarity, protection against known threa Using these tools can provide valuable data points to help you assess a wallet's security posture and make an informed decision. +## Security Best Practices + +- **Strong Password:** Use a strong, unique password. Do not reuse passwords from other accounts. +- **Antivirus Software:** Install antivirus on the device used for wallet access, since hot wallets are exposed to +browser and OS malware. +- **Minimal Auto-Lock Time:** Set auto-lock to 5-15 minutes. Shorter timers limit exposure if unattended and reduce how +long decrypted keys stay in memory. +- **Dedicated Browser Profile:** Use a separate browser profile for wallet and dApp use, isolated from the extensions +and sites you use for general browsing. +- **No Browser Sync:** Keep extensions out of browser sync. Sync can auto-install extensions across devices, so one +malicious extension can spread to every synced device. +- **Minimal Browser Extensions:** Keep extensions to a minimum. Each one is added attack surface, a compromised +extension can script wallet popups and alter or intercept transactions. +- **No Wallet Exposure on Calls:** Never unlock or reveal a hot wallet during screen shares or remote calls. Attackers +use fake support calls to capture passwords or seed phrases the moment they're visible. + ## Further reading - [Wallet Security overview](/wallet-security/overview): how the pages of this framework fit together From 94d1a4543621b2745b1df49ab3ef79c92b002cc4 Mon Sep 17 00:00:00 2001 From: 0xusmanf <110072406+0xusmanf@users.noreply.github.com> Date: Wed, 23 Sep 2026 00:50:27 +0500 Subject: [PATCH 2/5] docs(wallet-security): minor acronym fix --- docs/pages/wallet-security/for-beginners-and-small-balances.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/pages/wallet-security/for-beginners-and-small-balances.mdx b/docs/pages/wallet-security/for-beginners-and-small-balances.mdx index 37b8cda98..942c79d47 100644 --- a/docs/pages/wallet-security/for-beginners-and-small-balances.mdx +++ b/docs/pages/wallet-security/for-beginners-and-small-balances.mdx @@ -69,7 +69,7 @@ decision. - **Strong Password:** Use a strong, unique password. Do not reuse passwords from other accounts. - **Antivirus Software:** Install antivirus on the device used for wallet access, since hot wallets are exposed to -browser and OS malware. +browser and operating system malware. - **Minimal Auto-Lock Time:** Set auto-lock to 5-15 minutes. Shorter timers limit exposure if unattended and reduce how long decrypted keys stay in memory. - **Dedicated Browser Profile:** Use a separate browser profile for wallet and dApp use, isolated from the extensions From 6141d60587a98d34436ebd5a7b4449ee17612eba Mon Sep 17 00:00:00 2001 From: 0xusmanf <110072406+0xusmanf@users.noreply.github.com> Date: Thu, 24 Sep 2026 00:25:31 +0500 Subject: [PATCH 3/5] docs(wallet-security): implement requested changes. --- .../wallet-security/for-beginners-and-small-balances.mdx | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/docs/pages/wallet-security/for-beginners-and-small-balances.mdx b/docs/pages/wallet-security/for-beginners-and-small-balances.mdx index 942c79d47..e5b8295cb 100644 --- a/docs/pages/wallet-security/for-beginners-and-small-balances.mdx +++ b/docs/pages/wallet-security/for-beginners-and-small-balances.mdx @@ -67,9 +67,8 @@ decision. ## Security Best Practices -- **Strong Password:** Use a strong, unique password. Do not reuse passwords from other accounts. -- **Antivirus Software:** Install antivirus on the device used for wallet access, since hot wallets are exposed to -browser and operating system malware. +- **Strong Password:** Follow [Strong Password](/opsec/passwords/overview#what-is-a-strong-password) rules. +- **Antivirus Software:** Install antivirus to protect your device from malware attacks. - **Minimal Auto-Lock Time:** Set auto-lock to 5-15 minutes. Shorter timers limit exposure if unattended and reduce how long decrypted keys stay in memory. - **Dedicated Browser Profile:** Use a separate browser profile for wallet and dApp use, isolated from the extensions @@ -78,8 +77,6 @@ and sites you use for general browsing. malicious extension can spread to every synced device. - **Minimal Browser Extensions:** Keep extensions to a minimum. Each one is added attack surface, a compromised extension can script wallet popups and alter or intercept transactions. -- **No Wallet Exposure on Calls:** Never unlock or reveal a hot wallet during screen shares or remote calls. Attackers -use fake support calls to capture passwords or seed phrases the moment they're visible. ## Further reading From 488b758c1f5bdeacdaa8ec8912f932ba8b7b7025 Mon Sep 17 00:00:00 2001 From: 0xusmanf <110072406+0xusmanf@users.noreply.github.com> Date: Mon, 28 Sep 2026 22:42:02 +0500 Subject: [PATCH 4/5] docs(wallet-security): removed password and minimal autolock bullet points --- .../pages/wallet-security/for-beginners-and-small-balances.mdx | 3 --- 1 file changed, 3 deletions(-) diff --git a/docs/pages/wallet-security/for-beginners-and-small-balances.mdx b/docs/pages/wallet-security/for-beginners-and-small-balances.mdx index e5b8295cb..ed5575cc1 100644 --- a/docs/pages/wallet-security/for-beginners-and-small-balances.mdx +++ b/docs/pages/wallet-security/for-beginners-and-small-balances.mdx @@ -67,10 +67,7 @@ decision. ## Security Best Practices -- **Strong Password:** Follow [Strong Password](/opsec/passwords/overview#what-is-a-strong-password) rules. - **Antivirus Software:** Install antivirus to protect your device from malware attacks. -- **Minimal Auto-Lock Time:** Set auto-lock to 5-15 minutes. Shorter timers limit exposure if unattended and reduce how -long decrypted keys stay in memory. - **Dedicated Browser Profile:** Use a separate browser profile for wallet and dApp use, isolated from the extensions and sites you use for general browsing. - **No Browser Sync:** Keep extensions out of browser sync. Sync can auto-install extensions across devices, so one From a47094152050aa93354547f9a3e7c28ae0bc94b3 Mon Sep 17 00:00:00 2001 From: 0xusmanf <110072406+0xusmanf@users.noreply.github.com> Date: Mon, 28 Sep 2026 22:46:19 +0500 Subject: [PATCH 5/5] docs(wallet-security): add password and minimal autolock bullet points --- docs/pages/wallet-security/cold-vs-hot-wallet.mdx | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/docs/pages/wallet-security/cold-vs-hot-wallet.mdx b/docs/pages/wallet-security/cold-vs-hot-wallet.mdx index f67707ffa..e25d93624 100644 --- a/docs/pages/wallet-security/cold-vs-hot-wallet.mdx +++ b/docs/pages/wallet-security/cold-vs-hot-wallet.mdx @@ -11,7 +11,7 @@ contributors: - role: reviewed users: [Coinspect, patrickalphac] - role: fact-checked - users: [] + users: [0xusmanf] --- import { TagList, AttributionList, ContributeFooter } from '../../../components' @@ -95,6 +95,9 @@ Regardless of the type, non-custodial wallets place the full burden of security - **Online Vulnerabilities**: If the device they are on (computer or phone) is compromised, your assets can be stolen. - **Supply Chain Attacks**: Be cautious of both software and hardware integrity. Always download wallet software from official sources and purchase hardware wallets directly from the manufacturer to avoid receiving a tampered device. +- **Strong Password:** Follow [Strong Password](/opsec/passwords/overview#what-is-a-strong-password) rules. +- **Minimal Auto-Lock Time:** Set auto-lock to 5-15 minutes. Shorter time limit exposure if unattended and reduce how +long decrypted keys stay in memory. ## Further reading