DeFi Safety Fundamentals

How to interact with decentralised finance without losing the wallet you connect: the risks that are structural, the ones that are avoidable, and the habits that separate them.

What makes DeFi different

There is no customer support, no chargeback and no reversal. A signature is final, and a single approval can be enough to drain a wallet. That is the trade for permissionless access, and it changes what care means.

The main risk categories

Smart contract bugs and exploits, rug pulls by the people who built a protocol, phishing sites that mimic real interfaces, and token approvals that stay open long after the transaction they were needed for.

Approvals are the recurring one

Granting a contract permission to spend a token is not a one-off act: the allowance persists until it is revoked. Reviewing and revoking old approvals is the single most useful habit for anyone who interacts with more than a couple of protocols.

Compartmentalisation

The practical defence is to keep the wallet you connect to protocols separate from the wallet holding your position, so an exploit reaches only what you were willing to expose.