And the most common one is phishing attacks. That's how usually people get hacked.
They aren't just exposing their account and password to the hackers but including the private keys.
One effective action to counter this is to have a separate email password and If the wallet has an option to log-out to all of the device to delay the hacker's operation.
That's how people will realize the importance of 2FA and OTP's sent to emails before sending out to any addresses.
Right! and well, talking about a high level of security then you need to familiarize and enable these layers of security from your wallet.
I have a local custodial wallet, and I won't be worried If somebody else is accessing my account, because first; I get notified through email about an unrecognized log-in from different device or on different location. Second, they need the OTP sent to my email again to proceed any actions that involves cashing out from the wallet. Lastly, I'll be receiving a text message from this custodial wallet confirming/denying of transactions.
So, as you can see breaching an account isn't easy as long as you won't be as dumb as giving out essential infos including email password or using only one password from your web accounts, wallet accounts, down to your email address.