◇ Theory
Everything on-chain is public and permanent
A public blockchain is a shared ledger that anyone can read. Every transaction, balance and contract is visible, and once a transaction is confirmed it cannot be undone.
That permanence is the whole design: nobody can quietly change history. It also means mistakes are final — there is no bank to call and no chargeback.
Your keys are your identity
A wallet does not hold coins; it holds a private key that proves you control an address. Anyone with the key — or the seed phrase it is derived from — can act as you.
Every action is authorised by a signature. Some signatures send a transaction; others, like token permits, silently grant another address the right to move your funds later. Reading what you sign is the single most important habit in the ecosystem.
Approvals outlive the moment
To let a contract move your tokens you approve an allowance. An unlimited allowance to a contract that is later compromised can drain the approved token at any time.
Approve the amount you need, review old allowances periodically, and revoke the ones you no longer use.
Every lab pairs the vulnerable contract with its patched twin in the Post-Mortem stage — the exact lines that fail, and the exact lines that fix them.