Some time ago, I wrote a post about how to secure EOS private keys and avoid getting hacked. I didn't quite explain the reasons why I made those suggestions properly in that article. So, I have re wrote it with proper explanations and posting it here for my readers.
Scatter chrome extension or the desktop wallet are installed in the computer and are generally connected to the internet. If your computer is hacked and a hacker gains access to its administrative permissions, he can take control of it by remote desktop without you even noticing that.
This kind of situation is rare but they do happen. If you keep your owner key secure and offline and only keep your active key in the scatter wallet, your staked funds will be secure in a situation like that. And you will have three days to change the permission of your active key.
EOS based services don’t need your private key to provide you with services. They can use blockchain interface such as scatter to sign transfers or contract actions. Any service that requires you to input your private key on their website will have full control over your EOS account and your funds.
Spyware programs are generally known for snooping on clipboard copied contents. If you have a stealth spyware installed in your system without your knowledge, it can steal your keys if you copy the whole key to the clipboard.
If you don’t copy the first 4-5 characters of the private key, the spyware program will most likely fail to determine what key it is. This doesn’t apply to you if you have confidence that your system is secure and free of any malicious software.
Downloading wallet software from unofficial sources is not secure. Unofficial sources sometimes contain malicious versions of wallet software that are programmed to steal private keys. Recently, a EOS holder lost 200 EOS tokens after he downloaded and installed a malicious version of Greymass EOS Voter wallet.