Skip to content
Blog

Thinking clearly about Web3 security.

Insights, guides, and deep dives into token allowances, wallet defence, and DeFi best practices.

Every Approval You Sign, Decoded
FeaturedEducation

Every Approval You Sign, Decoded

Four approval shapes, each looking almost identical in the wallet modal, each with its own trust implications. A reference for reading what you are actually signing before you sign it.

April 18, 2026 · 11 min read
Read article
Eight Approval Exploits, One Pattern
Security

Eight Approval Exploits, One Pattern

Six of the eight largest DeFi hacks between 2022 and 2024 had nothing to do with user token approvals. The seventh and eighth tell us where approval hygiene actually matters — and where it cannot help.

Apr 18, 2026 · 10 min readRead
Hardware Wallets and Multisigs: Elevating Your Security
Security

Hardware Wallets and Multisigs: Elevating Your Security

True digital sovereignty requires a shift from digital convenience to physical security. Hardware wallets and multisigs create layers of defence that are nearly impossible for remote attackers to penetrate.

Dec 19, 2024 · 12 min readRead
Archive

All articles.

The Six Wallets of 2026: What Each One Shows You Before You Sign
Education

The Six Wallets of 2026: What Each One Shows You Before You Sign

Every wallet decodes the transaction you are about to sign a little differently. Some show you the token, the spender, the amount, the deadline; some show you a hash and wish you luck. A practical comparison of the six most-used wallets on the specific question of whether you can read what you are signing.

Apr 19, 2026 · 15 min readRead
Four Lenses on an Unknown Contract: A Reading Strategy Before You Approve
Security

Four Lenses on an Unknown Contract: A Reading Strategy Before You Approve

A smart contract you have never interacted with is asking for an approval. You have roughly ninety seconds before the moment passes. Four lenses — bytecode, source, deployment history, and on-chain behaviour — give you enough signal to decide without needing to be a Solidity engineer.

Apr 19, 2026 · 13 min readRead
How to Revoke a Permit2 Approval (The Signature-Based Kind)
Tutorial

How to Revoke a Permit2 Approval (The Signature-Based Kind)

A classic ERC-20 approval is revoked by writing zero on-chain. A Permit2 approval lives in a different place, expires on a different clock, and sometimes never touched the chain at all. A short walk-through of what Permit2 revocation actually looks like and when you still have to do it.

Apr 19, 2026 · 8 min readRead
The Quiet Death of approve(): Four Changes Coming to Wallet Permissions
Innovation

The Quiet Death of approve(): Four Changes Coming to Wallet Permissions

For a decade, approve() was the only way a wallet granted a contract the right to move a token. That model is quietly ending. Four distinct replacements are already live or near-live, each with its own security shape. A field guide to what is coming and what it changes.

Apr 19, 2026 · 12 min readRead
Ten-Minute Wallet Audit, No Install
Tutorial

Ten-Minute Wallet Audit, No Install

A no-install, no-account audit of every active token approval on your wallet across 27 chains. Five steps, ten minutes, one-click revoke for anything you do not want any more.

Apr 18, 2026 · 10 min readRead
NFT Approvals: The setApprovalForAll Trap
Security

NFT Approvals: The setApprovalForAll Trap

When you list an NFT on a marketplace, you sign something called setApprovalForAll. It gives a contract permission to transfer every NFT you own in that collection. Most holders click through it without thinking.

Apr 14, 2026 · 6 min readRead
Allowance Guard