Skip to content

docs(wallet-security): add security best practices for hot wallets - #649

Open
0xusmanf wants to merge 2 commits into
security-alliance:developfrom
0xusmanf:develop
Open

0xusmanf wants to merge 2 commits into
security-alliance:developfrom
0xusmanf:develop

Conversation

@0xusmanf

Copy link
Copy Markdown
Contributor

What does this PR change?

What changed

Added a Security Best Practices section to the hot wallet documentation (docs/pages/wallet-security/for-beginners-and-small-balances.mdx), covering:

  • Strong, unique passwords and antivirus protection
  • Setting auto-lock timers
  • Using dedicated browser profiles with minimal extensions and disabled browser sync
  • Avoiding wallet exposure during screen shares or remote calls
  • Added 0xusmanf to the list of document contributors alongside pinalikefruit.

Why

To provide actionable guidelines for users storing funds in hot wallets, helping them protect their keys from malware, unauthorized browser extension access, and social engineering attacks during screen shares.

Hi @pinalikefruit, could you please review these changes when you have a chance? Thanks!

Type of change

  • New content
  • Edit to existing content
  • Outline / structure change
  • Typo or formatting fix
  • Tooling / config

If applicable

  • Editing existing content: tagged the current contributors from the attribution list
  • Framework has a steward: asked them to review
  • Outline change: updated vocs.config.ts with the dev: true parameter
  • Want community feedback: shared this PR in our Discord

Stuck on anything? Just write it here and we're happy to help.

@github-actions

github-actions Bot commented Sep 23, 2026

Copy link
Copy Markdown
built with Refined Cloudflare Pages Action

⚡ Cloudflare Pages Deployment

Name Status Preview Last Commit
frameworks ✅ Ready (View Log) Visit Preview 94d1a45

@pinalikefruit pinalikefruit left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @0xusmanf ,

Thanks you for the contribution.

I’m not entirely sure about this section, as many points, such as "Strong Password," "Antivirus Software," or "No Wallet Exposure on Calls" are already mentioned elsewhere in the framework. Regarding extensions, the "Minimal Auto-Lock Time" recommendation specifies a concrete value. The suggestion to use a dedicated profile is sound good, and there is no need to recommend additional extensions solely for interacting with dApps.

Since many of these recommendations are repeated in other parts of the framework, I think the "Key Considerations & Trade-offs" section could be improved instead.

This branch was successfully deployed

1 active deployment
Preview 94d1a454 Deployed Sep 23, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants