Today we found out how many people don’t practice basic wallet security by keeping wallet approvals revoked.
When I first started Boring Security I had one of our contributors make a spreadsheet of "accounts with approvals to services with their apes in it". Dangerously high, so we tried to take action...
For a while we tried going around DMing everyone about their dangerous approvals, but that went as well as you might imagine. So we gave up and tried to create an Alumni program and reward folks with a few ApeCoin and steeply discounted/free branded Ledgers for taking our classes in partnership with the ApeCoin DAO, and ThankApe (at the time). Better than nothing...
The whole NFT space is extremely vulnerable to the broader negligence to end-user education and ETH UX for safety. I know it's much easier to blame each protocol whenever this happens, but the reality of it is, good security hygiene prevents this. Not selling your assets? Put them in a wallet address that has no approvals on it.
I know this sounds simple, but the reality is the average person needs several hours of safety education to have a chance in hell in not losing their assets here, even in 2026 it's only gotten more difficult with Smart Accounts, Delegation and the like. That makes the busy, non-technical artists and creatives the most vulnerable. The people who made the space worth waking up for have mostly all been hacked, few stayed.
The NFT community is one that is experiencing a weird kind of gentrification and shrinking, where all the cool people get displaced, not because they can't afford to hang, but because the people who made this place cool all got scammed, rugged, or exploited because of otherwise well-intentioned, albeit negligent, actors.
To date, few projects have done anything proactive for its community wrt security, aside from the ApeCoin DAO funding the existence of Boring Security, and Pudgy Penguins offering a Safety Pin SBT (which even got a$PENGU alloc!), and of course the projects partnering with Boring Security for education classes.
But ultimately Quit, BSec, other security researchers, and Yuga continuously bailing out the poor security practices of users and negligent protocols is unsustainable. Yuga is shelling out fistfuls of ETH and man hours to cover for NFTTrader, Flooring, and now ME's mistakes.
We need a lot, but at the very least, how about NFT drops that award based on no approvals and good security hygiene? This is a problem in the broader crypto ecosystem as well, but there is no real "community" in DeFi, perps, or memes, so likely, no change will happen there.
There are a million other things I think we "need" and are working on some, but this whole space needs to come together to see that we need to incentivize secure behavior of end-users, because the UX/Security improvements that were "supposed to save us" 5 years ago still haven't arrived.