Security has always been a cat and mouse game. The usual precautions about software updates, least privileged access, separation/sandboxing, and precautions like not pasting/installing random software (especially something on Show HN) continue to apply; but at this point, I'd suggest thinking more towards a model of "How do I best detect, and contain a compromise" model.
One thing I do is a wallet.dat honeypot with (now) ~$1700 of bitcoin. Any movement essentially shuts down my home network from external access. At worst, it's a justifiable tax deduction, not capital gains :)