How to Keep Your Crypto Wallet Safe: The Step Most People Miss

How to Keep Your Crypto Wallet Safe: The Step Most People Miss
by Marija Matic
By Marija Matic

Roughly 92 crypto wallets were recently robbed to the tune of $776,575.

The people who lost the money didn’t click a bad link that day. 

They didn’t fall for a phishing scam. And nobody hacked their passwords or found a flaw in the wallet’s code. 

Most of them, in all likelihood, hadn't opened their wallet in years.

Source: Binance.1

 

What got them was poor crypto wallet management. 

But you don’t have to make their same mistake.

If you have ever connected your wallet to a decentralized website — like a decentralized exchange to swap cryptos, or a lending platform to lend, borrow or earn yield — then your wallet could be at risk. 

Because there’s likely a key step to securing your wallet you haven’t taken: clearing out permissions.  

Granting & Removing Permissions

Here is the thing that trips up everyone coming from centralized exchanges: When you connect your crypto wallet to a DeFi website, you aren’t telling the wallet to move coins onto the platform. 

You’re handing over permission for the siteto access a specific asset in your wallet.

Think of a direct debit mandate. 

When you set up your utilities, chances are you don’t move the money over right away. Instead, by signing the contract, you let the bank know that the electric company can take money out of your account. 

The cash stays where it is. What you've given away is the authority to reach in and take it. 

A crypto wallet approval is that mandate, with two differences that matter enormously.

  • The first is that, unless specified otherwise, the amount is usually unlimited.
  • The second is that this permission never expires. A wallet approval sits on the blockchain until you personally remove it. 

So, while you may barely remember the time you swapped coins on Uniswap (UNI, “C”) in 2022, the platform hasn’t. It still has permission to interact with your wallet. Still unlimited. 

That’s the exact vulnerability that was targeted this month. 

The Dead Protocol

BarnBridge was a real name during the 2020–2021 DeFi boom. More than half a billion dollars in crypto ran through its pools. 

Then, the SEC came knocking. 

Operations were shut down in 2022. By the end of 2023, it had paid a $1.7 million settlement and agreed to wind the whole thing down. Everyone considered it a "closed chapter" in crypto history and moved on. 

But there's something a lawsuit cannot do: It cannot switch a smart contract off

Which is why 92 wallets still had a live, unlimited approval, years after the obituary. Pointed at a contract that belonged to a company that no longer existed, watched by nobody.

Martin Marchev, the Certora security researcher whose breakdown2 of the attack is the clearest account out there, puts the key insight in one line: “The leftover money isn't the dangerous part — the leftover permissions are.”

 

So, the hacker was able to gain access by putting themselves at the heart of what remained of BarnBridge. 

Like most DeFi projects, this one was run by a Decentralized Autonomous Organization (DAO). Instead of a board of directors, decisions get made by a vote of whoever holds the governance token. 

Simply put, if you have a tokens, you get a vote

Perfectly ordinary in the world of DeFi.

But for BarnBridge, two other key facts aligned to set up an opening for the hacker … 

First was the smart contract itself. This is the algorithm that runs the platform. And this smart contract allowed funds to be pulled from wallets by a single role. 

Think of it like a bank manager. Whoever holds the role controls the mechanisms that pull funds in from wallets that have given approval.  

Second, who gets the manager role is decided by a vote. And in this case, that vote was for sale. 

Only about 146,000 (now almost worthless) BOND tokens — roughly 1.5% of the supply — were still staked and eligible to vote at all. And likely forgotten by those who staked them. 

All the attacker had to do was buy and stake enough BOND tokens to clear the threshold to pass new rules for the platform. 

On July 5, they did just that … for a whopping $625.

As a DAO, however, BarnBridge required all proposed changes to be publicly posted for a few days before a vote. So, for a few days, the hacker carefully hid their plans in plain sight. 

They introduced a proposal to replace the old smart-contract manager with an update that looked minor. But hidden inside was a measure that would allow the manager to be rewritten by the owner. 

That was something entirely new. Think of it like a back door, built-in secret and hidden in the shadows.  

When the vote was cast on July 11, no one voted against. Because with a dead project, there’s no community keeping watch. 

Four days later, the proposal goes through. Five minutes later, the manager’s rewritten code begins to go through the list of wallets that still have open approval and pulls funds from them.

The entire attack took only twelve minutes and thirty-six seconds, with a total of 776,575 USDC stolen from 92 wallets.

This is the part of “being your own bank” that crypto enthusiasts don’t exactly put on the brochure. 

When you're a customer of a bank or keep your crypto on a centralized exchange, an enormous amount of unglamorous work happens behind the scenes to keep your assets secure. 

Somebody expires the dormant mandates. Somebody flags the strange payment. In the end, you get it all summarized in a neat statement. And if you have complaints, you get a phone number to ring.

Hold your own crypto, and you inherit all of it. 

Not just the vault and the control. You also get the back office, too. And if you don't do your own routine housekeeping, it does not get done.

Wallet Maintenance, In Practice

The good news: This chore takes about ten minutes, twice a year.

1. Find an approval checker. revoke.cash is the tool most people use, Marchev included. Though he notes he has no affiliation with them, and neither do we. 
 
Note: Make sure to type revoke.cash directly into your address bar. Do not click a search result, and do not click a link from a reply on X. Fake approval-checkers exist and they are malicious.

2. Connect your wallet and look. Once you connect your wallet, the website will list every permission your wallet has ever handed out, and to which website. Heavy DeFi users may be startled by the length of the list. 

3. Revoke anything you don't recognize, and anything belonging to a protocol you haven't touched in a year. Just click on the “revoke” button on the right side of each coin. If you ever go back, you can grant it again in one click.

 

Revoking moves no coins and touches no balances. It only cancels a permission. 

4. Check each network separately. Approvals are per-network, and some wallets, like MetaMask, can support several networks — Ethereum (ETH, “B+”), Arbitrum (ARB, “D+”), etc. 

You’ll need to check every chain you've been active on, by changing it via this button:

 

You should know that it does cost a small network fee to remove permissions. Typically, it’s less than a cent. 

That is the price of the chore. And it’s much cheaper than staying vulnerable.

For wallets you've kind of abandoned but still hold fundsyou can still revoke permissions. Or you can move those coins to a new wallet that hasn’t connected to any platforms yet. 

That’s the cleanest slate you can get. 

One more thing, and it is not hypothetical: If you ask for help online, you will see fake “support” accounts swarm to answer you. 

Here’s how to spot them: No legitimate party will ever ask you to move funds, click a link or sign a transfer to "secure" them. In this case, revoking — through a simple tool you navigated to yourself — is the only action required to keep your wallet safe. 

Bottom Line

The uncomfortable takeaway after this attack is that every dead protocol is now in precisely the same position as BarnBridge. Their codes are still running and permissions are still live. 

But nobody is home to watch out for them. 

The next attacker won’t need to be a genius or wealthy to pull this stunt off again. The playbook is out. And it’s cheap and easy to follow.

We cannot make an abandoned team clean up after themselves. Instead, we channel our energy into ensuring our own security.

Routine maintenance is a chore. But a few minutes and cents every few months is more than worth the effort to keep your wallet clean and secure.

Best,

Marija Matić


1https://www.binance.com/en/square/post/07-15-2026-barnbridge-smart-yield-protocol-hit-by-776k-governance-attack-on-ethereum-344893422742034

2https://x.com/MartinMarchev/status/2077377000109486564

About the Contributor

Marija Matic is a master superyield hunter. That is, she is an expert at finding crypto income opportunities that offer outsized yields. She's equally adept at explaining these multi-step processes simply and clearly for investors who want to explore this relatively uncharted, and therefore fertile, area of the major crypto exchanges and blockchains.

Crypto Ratings
Loading...