2FA App Preferable
2FA App Preferable is preferring app-based or hardware 2FA over SMS for exchange accounts.
Read full definitionShouldEye Trust Intelligence Glossary
Approvals, phishing, malware, exploits, and wallet safety concepts for consumers.
Educational information only. ShouldEye does not provide legal, banking, or individualized financial advice. Dispute rights, deadlines, and outcomes depend on your payment method, card network, issuer, processor, jurisdiction, and the facts of your case. Legal Disclaimers
36 published definitions in this topic.
2FA App Preferable is preferring app-based or hardware 2FA over SMS for exchange accounts.
Read full definitionAllowlist Spend Policy is wallet rules permitting sends only to known addresses.
Read full definitionCompromised Deployer Key is leak of a project deployer key enabling malicious upgrades or mints.
Read full definitionCompromised Hot Wallet is a hot wallet whose keys were stolen by malware or phishing.
Read full definitionCounterparty Risk Crypto is risk that the other party or platform fails to meet obligations.
Read full definitionCross-Chain Approval Confusion is approvals on one chain do not revoke the same spender on another chain.
Read full definitionCrypto Scam Report Evidence is preserving TX hashes, addresses, chat logs, and domains before reporting — not a recovery promise.
Read full definitionCustodial Insolvency Risk is risk that a custodian cannot honor withdrawals due to insolvency.
Read full definitionDuress Wallet Concept is optional secondary wallets some users prepare for coercion scenarios — advanced and easy to misuse.
Read full definitionHardware Confirm Every Detail is verifying full addresses and amounts on a hardware display before approving.
Read full definitionMemo Tag Omission Loss is losing exchange credits by omitting required destination tags — not always recoverable.
Read full definitionNo Recovery Guarantee Principle is the principle that no honest party can guarantee crypto recovery after irreversible sends.
Read full definitionOfficial Domain Verification is checking domains via official documentation rather than DMs or ads.
Read full definitionPassword Manager Seed Storage Risk is storing seeds in password managers that sync online can create cloud exposure.
Read full definitionPrinted Seed In Wallet is carrying paper seeds in a physical wallet that can be lost or photographed.
Read full definitionProof of Reserves Misread is misinterpreting reserve snapshots as full liability coverage or insurance.
Read full definitionPublic Photo Seed Leak is accidentally posting a photo that includes a seed backup sheet.
Read full definitionReplay Attack Confusion is user confusion after forks when transactions could be replayed without protection.
Read full definitionRevocation Hygiene is periodically reviewing and revoking unused token and NFT approvals.
Read full definitionRoyalty Bypass Confusion is marketplace disputes around royalties — not itself a scam, but used in social engineering stories.
Read full definitionSeed On Camera Risk is displaying seed words on camera during streams or support calls.
Read full definitionSeed Phrase Cloud Leak is exposure of recovery words via photos, notes apps, or email drafts.
Read full definitionSeed Phrase Email Attachment is sending yourself seeds by email — a high-risk exposure pattern.
Read full definitionSeed Reuse Across Wallets is importing the same seed into many apps expands the malware attack surface.
Read full definitionShared Seed Household Risk is multiple people knowing a seed increases theft and coercion risk.
Read full definitionShouldEye Never Asks Seeds is a safety principle: ShouldEye never asks for seed phrases, private keys, keystores, or wallet passwords.
Read full definitionSlippage Settings Confusion is very high slippage tolerances that allow unfavorable or malicious fills.
Read full definitionSpending Limit Wallet is policies capping daily transfers to limit blast radius of compromise.
Read full definitionStale Approval Risk is old unlimited approvals remaining dangerous years later.
Read full definitionTime-Locked Vault is contracts delaying spends to reduce theft speed after key compromise.
Read full definitionAn unlimited token approval lets a smart contract spend an unbounded amount of a specific token from your wallet until revoked.
Read full definitionA valid wallet address is a string that passes format and checksum rules for a network — not proof the recipient is the intended or honest party.
Read full definitionValidator Compromise is compromise of validator keys leading to slashing or network risk.
Read full definitionWithdrawal Address Allowlisting is restricting custodial withdrawals to pre-approved addresses.
Read full definitionWrong Asset Deposit is sending a token standard a platform does not support for that address.
Read full definitionWrong Network Deposit is depositing on an unsupported chain/network for a custodial address.
Read full definition