Security guide
Published 25 July 2026
About 25 minutes
Losses involving browser wallets almost never begin with broken cryptography. They begin with an
approval the person did not understand. This guide takes apart the approval step, the seven scam
patterns that exploit it, and the checks that separate a real interface from a convincing copy.
In preparation
We publish when an article is finished and checked, not on a schedule. These subjects are in
research now. They are listed without links because nothing has been published yet.
- Browser extension permissions: reading a manifest before you trust it.
- Account recovery flows: why the reset path is usually the weakest one.
- Phishing that survives two-factor authentication: proxy kits, and what actually stops them.
- Reading a security advisory: what a CVE score does and does not tell you.
How to read us
Each guide opens with a direct answer, then a table of contents, then the detail. Technical
claims carry a numbered reference to a primary source, and every article closes with a full
bibliography you can check line by line.