Important point of attention to prevent risk of theft of your coins.
Make sure you log in with minimal SMS 2fa on your google account.
If you do not have additional log-in security for your google account, then this is a maybe gold mine for crypto scammers.
All saved passwords can be found in your account where you chose to save once when you got a popup. This login names with passwords and websites can all be made visible with a simple password viewer extension in every browser.
As an example, what I mean in your google account

Especially when you participate in airdrops or bounty it can be important, because you often make an account on those websites. Great chance that airdrops are scam. And that they use that login data. For example, to break into your google account or email address.
Use minimal SMS 2fa to access your google account.
Never use the same login information as that of your email and google account
Always use google 2fa authenticator to log in on exchanges.
Never install any APIs that can steal all information.
If you make these 4 things better. I can say, you are a bit safer!
Of course there are many more protections for your exchange accounts, but this is sometimes forgotten by people, while this is full of passwords.