Sug It, Fug It or Rug It โ Security Edition
Host: May June (@MayJune20121)* with co-host Yot (@yotdog69) ยท Mon 20 Jul 2026 ยท 1:17:15 ยท ~7 speakers
TL;DR
- A recurring FUGs Monday Space, this week reworking web3 security into a game show: for each project, habit, or scenario, panelists call it Sug it (give it a chance), Fug it (marry it, green flag), or Rug it (hard pass) โ the crypto cousin of Kiss Marry Kill.
- Security expert Drew (@nft_dreww) anchored the panel with concrete, repeatable advice: antivirus, a password manager, proper 2FA (a YubiKey or authenticator, never SMS), and a hardware wallet with the seed phrase stored offline.
- A running theme: most web3 hacks are really web2 failures. Drew sent everyone to pentester.com to check for leaked credentials โ and Souls immediately found his own email compromised on air.
- Panelists shared near-misses and one real one: Souls' co-founder clicked a fake Calendly link a year before Kabu launched, and the attacker sat quietly until mint day.
- Tool tips to take home: revoke.cash now has a browser extension with transaction simulation and scammer-labeling for X profiles.
- Yot closed with good news โ a community member, Kenny, was drained of five Fugs in the last 24 hours, but the community tracked and returned all of them.
Highlights
[4:52] The game gets explained. May lays out Sug it / Fug it / Rug it and Yot confesses that his "avoid" wording in the promo post was an accident โ his brain blended the British "snob marry avoid" with the American "kiss marry kill" and short-circuited. The bit sets the tone for the whole hour.
[7:56] Yot's one near-miss. Five years in and never drained, but he came a hair from it once โ peak NFT season, middle of the night, a link he almost connected his one loaded wallet to. He checked it at the last second; the Discord had been hacked and the link was dodgy. "That could have been it for me."
[10:31] Souls on the Kabu hack. His co-founder Josh clicked a fake Calendly meeting link a year before Kabu launched. The attacker quietly compromised the machine and waited for launch day to drain the collection โ a sobering reminder that a click six months ago can still be live.
[20:45] Drew's core thesis: web3 security is mostly web2. He argues 70โ80% of web3 hacks trace back to web2 gaps, then gives the starter kit [21:10]: antivirus, a password manager, and proper 2FA (YubiKey ideally, never phone/SMS). He points everyone to pentester.com to see their own leaked data.
[25:10] The pentester gut-check lands. Souls runs his email while the Space is live and reports back that it's compromised. Drew's fix: spin up a fresh email, set the old one as an alias so nothing's missed, and never reuse a password.
[32:42] Hardware wallets, demystified. Drew's clearest teaching moment: a hardware wallet's one job is generating keys offline. He walks through a vault/marketplace/mint/delegate wallet setup and explains scammers often lurk 40+ days, socially engineering you before striking โ the spray-and-pray era is over.
[37:38] Seed-phrase horror stories. Yot's old friend who hid a photo of his seed phrase in a hidden folder ("genius or one of the most... retarded responses I've had back"). Drew tops it: a man whose seed phrase was written down and visible on police bodycam footage โ published to Facebook โ costing him ~$43k. Plus the dog who ate a seed phrase out of the safe.
[51:39] The best listener question. Super High asks whether iPhone's auto-generated passwords are safe. Drew says yes and uses it to explain what a password manager actually is (unique 32-character passwords per site, one master vault key you treat like your SSN), noting we're drifting toward passwordless biometric auth.
[1:00:37] Drew's parting tool drop. Before dropping for another call, he plugs the new revoke.cash browser extension โ transaction simulation plus scammer labels that surface right on your X feed when a flagged account slides into your DMs.
[1:14:54] The community win. Yot reveals that a FUGs member, Kenny, was drained of five Fugs in the past day โ but the community caught the dispersed funds and sent them all back. He's dialing in from Bangkok at 1am, "seeing me less, but not doing less."
Topic timeline
| Time | Topic |
|---|---|
| [0:51]โ[4:50] | Intros, mic checks, hellos |
| [4:52]โ[7:22] | Game rules: Sug it / Fug it / Rug it |
| [7:22]โ[24:50] | Icebreaker: first security lesson learned the hard way |
| [21:10]โ[26:13] | Drew's web2 starter kit + pentester.com |
| [27:40]โ[43:02] | Round 1โ2: wallets, blind signing, 2FA/password managers/seed phrases |
| [43:49]โ[51:06] | Round 3: project trust โ anon founders, KYC teams, community-owned |
| [51:39]โ[54:48] | Password managers & iPhone passwords explained |
| [55:01]โ[1:00:33] | Round 4: scam tactics (DMs, urgent claims, airdrop links) |
| [1:00:37]โ[1:02:32] | Drew's tools rundown, then departs |
| [1:02:32]โ[1:13:55] | Wrap round: biggest web3 red flag |
| [1:14:42]โ[1:17:07] | Kenny recovery story, closing beatbox |
Notable quotes
- "Completely blind hard transactions. I don't even look at the thing. Fug it." โ Yot [29:02]0:38
- "TLDR, get a hardware wallet and store your seed phrase offline." โ Drew [35:45]0:38
- "I don't know to this day still if that was genius or one of the most fucking retarded responses I've had back." โ Yot, on the friend who hid a photo of his seed phrase [37:38]0:38
- "Nothing's urgent. Literally exactly nothing is urgent. The only urgency is that they need me to pay for their next meal." โ Yot [59:49]0:38
- "Yot sent me a link and I clicked it and it rugged me out of the space." โ Souls, on getting dropped from the room [17:17]0:38
- "If anybody promises you anything or sends you any link blindly, you know what their intentions are." โ Souls [1:06:07]0:38
Who said what
- May June (host, @MayJune20121)* โ ran the game show, kept the rounds moving, wrangled the tech gremlins, and posted each round to the comments for listeners.
- Yot (@yotdog69, co-host) โ comic foil and voice of hard-won caution; dialing in from Bangkok, delivered the Kenny recovery news and thanked Drew.
- Drew / NFT_Dreww.eth (@nft_dreww) โ the resident security expert; the substance of the Space, from web2 basics to hardware-wallet setup to revoke.cash. His profile hosts a fuller tools list.
- Souls / sols (@solsweb3, Kabu founder) โ shared the Kabu hack firsthand, ran pentester.com live, and gave nuanced takes on anon founders vs KYC teams.
- Soulmate (@Soulmate889) โ artist who fought a shaky connection all hour; her lesson was learning not to trust easily after being scammed out of an early artwork.
- Super High / Superhighgasfees (@SHGFees) โ asked the standout question about iPhone passwords and flagged brand-new botted mint accounts as his top red flag.
- Bunny / 7xBun (@7xBunny) โ recounted a Telegram trading scam, credited "girl laziness" for never getting drained, and beatboxed the room out.
- Morteza (@Mortezabihzadeh) โ wandered in near the end not knowing the topic; graciously deferred to listen.
Worth a full listen
- [32:42]โ[39:39] โ Drew's uninterrupted stretch on hardware wallets, the offline-seed-phrase rule, and the parade of real-world horror stories (bodycam, dog, Hawaii fire). The single most useful block if you only replay one thing.
- [51:39]โ[54:48] โ Super High's password question and Drew's plain-English answer on password managers and the coming passwordless future; a genuinely clarifying exchange.
- [1:14:54]โ[1:17:07] โ Yot's Kenny-recovery story and Bunny's closing beatbox โ the warm, this-is-why-community-matters landing the Space earns.
* some voices are identified from context; those names are marked as likely.
