COMMANDMENT 3: Thou shalt revoke unused approvals regularly ๐
Not "whenever I happen to think about it," which in practice means never, but on an actual recurring reminder set on your phone or calendar - monthly is a reasonable cadence for most people, more often if you're actively degen-ing across a lot of new dApps.
Treat it the same way you'd treat any other routine maintenance task that's boring but non-negotiable, like checking smoke detector batteries.
Approvals you forget about are approvals a scammer is quietly counting on - the entire attack only works because most people never come back to clean up after themselves.
Approval hygiene recap, because it genuinely bears repeating until it becomes automatic ๐งน
Unlimited token approvals don't quietly expire just because time has passed - there's no built-in timer, no default cleanup, they sit there active indefinitely until you manually go in and revoke them yourself.
Revoking them regularly costs you maybe 5 minutes a month if you're consistent about it, less than the time it takes to scroll through your timeline once. Not revoking them can cost you literally everything in that wallet, in a single bad transaction, from a contract you approved and forgot about years ago.
The math genuinely isn't close, and yet this is one of the most skipped habits in all of crypto.
For user convenience, whenever they use a DeFi protocol and their assets are on a blockchain that isnโt enabled in @zkxwallet yet, a prompt will automatically pop up with network information from Chainlist.
Users can add the network with one click no need to manually enter RPC or network details like in MetaMask or other wallets.
Drop a screenshot of a scammer who tried asking for your seed phrase (blur out any personal info first) ๐ธ
The fake support account with a suspiciously official-looking blue checkmark, the "urgent wallet verification" DM that showed up at 2am, the cloned Discord bot pretending to be a moderator - all of it counts, no story is too small or too obvious in hindsight.
Let's build a little public archive of the tactics so the next person who sees the same message recognizes it instantly instead of hesitating for even a second.
Community protection, one screenshot at a time ๐ก๏ธ
COMMANDMENT 2: Thou shalt never share thy seed phrase - not even with "support," not even with someone who seems to know everything about your account already, not even when the request comes wrapped in urgency about a security issue that needs "immediate verification" ๐
Scammers who ask for seed phrases have often done real homework - they know your wallet address, your recent transactions, sometimes even details from a data breach elsewhere - and that familiarity is designed specifically to lower your guard. No legitimate team, wallet provider, or protocol will ever, under any circumstance, ask for it.
Full stop, no exceptions, no "just this once," no matter how convincing the story attached to the request sounds.
Private keys, encrypted locally, on your own device, always - that's not a tagline, it's the literal architecture underneath the entire wallet ๐
When you create or import a wallet, the encryption and storage happen entirely client-side; nothing is ever transmitted to any server, not even ours, not even encrypted, not even as a backup.
That's what "self-custodial" actually means in practice - not a claim on a landing page, but a technical reality you can verify - from the very first moment you install ZKX Wallet, not just something buried in a privacy policy nobody reads.
ZKX Wallet will NEVER ask for your seed phrase - not in a DM, not through a "support" ticket, not through email, not in a voice call, not ever, under any circumstance whatsoever ๐ซ
No legitimate team anywhere in crypto needs it, because a real support flow works entirely without ever seeing your keys. If anyone claiming to be us - or claiming to be any wallet, exchange, or protocol - asks for it, screenshot the conversation, block them immediately, and know for certain it is not us and never will be.
This one rule alone, if literally everyone in crypto actually internalized it, would probably prevent more losses than every other piece of security advice combined.
COMMANDMENT 1: Thou shalt use a hardware wallet for the majority of thy assets ๐
Cold storage for anything you're not actively trading or using in DeFi right now is, without exaggeration, the single highest-leverage security habit in all of crypto - nothing else you do this month will do more for your safety per minute invested.
A hardware wallet means your private keys physically never touch an internet-connected device, which means a compromised browser, a malicious script, or a cloned website simply cannot reach them, no matter how convincing the attack is. It turns "my wallet got drained while I slept" from a real, depressingly common possibility into basically a non-issue.
If you only take one commandment seriously out of the ten coming this month, start here - everything else is optimization on top of this foundation.
Introducing the ZKX Decalogue ๐
Ten commandments of good crypto behavior, one revealed per day over the next two weeks, starting right now.
Think of it as the positive flip side of everything we called out last week - the sins told you what quietly goes wrong, the commandments tell you exactly what to actually do instead, no ambiguity, no vague "be careful out there" advice that doesn't translate into an action.
Some of these will feel obvious once you read them, some will genuinely change how you operate day to day, and all ten together are basically the operating manual we wish every new wallet holder got on day one.
Let's build some good habits ๐ก๏ธ
All 7 deadly sins, officially ranked by your replies this week ๐
Sloth and Greed are neck and neck for the community's most-confessed sin, which honestly checks out - one is about not doing the boring maintenance work and the other is about not being able to say no to more, and crypto rewards both instincts right up until it doesn't.
Pride and Wrath trail close behind, Lust and Envy are apparently things people would rather not admit to even anonymously, and Gluttony rounds it out.
Redemption arc starts Monday ๐
Which one are you personally guilty of - no wrong answers here, we're all walking around with at least one of these, and admitting it is the first actual step toward fixing it.
Tell us about a transaction you rushed through and immediately regretted ๐ฌ
The one where you clicked approve before your brain caught up, then spent the next hour refreshing a block explorer every ten seconds hoping you'd somehow misread what happened.
Maybe it was a wrong contract, an approval you didn't mean to grant, or a swap at a price you'd never have accepted if you'd waited five more seconds.
We've all got at least one story like that sitting somewhere in the back of our minds - let's actually hear it instead of pretending it never happened.
Why we panic-sign transactions during a dump, explained ๐ง
The fear of missing your exit window triggers roughly the same part of the brain as fear of actual physical danger - the amygdala doesn't distinguish between a falling chart and a real threat, so it fires the same fight-or-flight response either way.
It's a survival reflex, not a rational decision process, and reflexes don't read fine print. Your thumb hits "approve" before your brain has even finished reading what it's approving, because in that split second your nervous system has already decided speed matters more than accuracy.
Knowing this is half the fix - the other half is building a habit that forces a pause before your hands can catch up with your fear.
Same wallet, every surface, zero compromise.
Whatever you can do on the browser extension - shield assets, connect hardware wallets, batch transactions - you can do exactly the same way on the web app ๐
Your choice of surface is about convenience, never about missing features.
Batch Transactions bundle multiple approvals and revokes into one single signature, one gas payment, one confirmation screen โก
Once you're set up on ZKX Wallet, the "I'll clean up my approvals eventually" excuse mostly disappears - it's genuinely quick enough to do on a whim.
Weโre excited to announce that @zkxwallet v0.0.41 is now live on the Chrome Web Store! ๐
We believe the wallet not dApps will slowly become the MAIN trading UI, a place where users can trade and navigate onchain while being better protected from the countless risks and attack vectors that can lead to lost funds.
We redesigned the extension to evolve into a FULL trading station, with hundreds of tools integrated directly into the wallet to help users trade and navigate EVM blockchains while reducing the risks they face every day.
This thread is dedicated to showcasing the new features in v0.0.41 and the changes weโve made. ๐งต
How many dApps is your wallet actually connected to right now? Be brutally honest ๐
Go check your connections/approvals page real quick, come back, and drop the number below. We're guessing it's higher than you think ๐
DYOR, actually defined instead of just repeated as a meme ๐
Is the contract verified?
Is liquidity locked, and for how long?
Is the team doxxed, or at least consistently active and identifiable?
Is token distribution reasonable, or does one wallet hold 40% of supply?
If you can't confidently answer at least two of these questions, that silence is already your answer ๐ง
Real talk - do you actually DYOR before or after you ape into something? ๐ง๐
โ Before, every single time
โฐ After, usually when it's already too late
๐ Honestly what even is DYOR
A young Afghan woman exposes the brutal reality of life for women under Taliban rule:
โIf youโre a woman and you have a toothache, you CANNOT get treated.
Women are denied the right to education, so there are no female dentistsโฆ and men are not allowed to treat women.โ
This is happening right now in 2026. Women in Afghanistan are trapped in a nightmare, denied basic healthcare, education, and freedom, all in the name of strict Islamic law.
The world must stop looking away.
This is what full Sharia rule looks like.
Share this. Donโt stay silent.