The market has spoken. With the passage of Meta-038, MetaDAO is now employing Groom Lake for institutional-grade security, intelligence - including due diligence on prospective founders and teams - and 24/7 incident response.
Friendly reminder that audits don't catch everything.
Cetus had three. Ronin had been audited. Bybit's Safe contracts were fine. Combined losses still cleared $1.6 B.
An audit tells you what your code looked like on the day someone read it. Everything that happened after is on you.
You don't know what you don't know.
April 2026 set the monthly record for crypto exploits. 28 incidents, $635M stolen. We pulled data on 512 incidents across 2024-2026 to understand how billion-dollar crypto hacks actually happen now.
Five trends from the past two years 🧵
Given the recent TanStack-related supply chain compromise activity, I put together a read-only detection script to help identify currently known indicators of compromise and suspicious artifacts tied to the “Mini Shai-Hulud” npm worm activity.
The script performs local IOC checks against lockfiles, node_modules, GitHub Actions workflows, known dropper filenames, malicious package versions, credential staging artifacts, and related persistence indicators. No network calls are made.
If your environment uses affected TanStack packages, would strongly recommend running it to verify you are clean and review findings manually.
https://t.co/R2QLlCBt0q
Had an interview with a “crypto” recruiter. We talked for about 40 minutes, and then they asked me to look at some code.
Their first instruction was to clone the repo. I didn’t. They seemed surprised, so I told them I wanted a moment to check whether it was safe first.
I ran a quick analysis with Claude.
Turns out the code had a backdoor. It would copy my environment variables and send them to a remote server.
The recruiter went speechless and ended the call pretty quickly.
Be careful who you talk to. Scammers are real.
100,000 North Korean operatives. Deepfake video interviews. AI-generated identities. Stealing millions in IP and crypto while funding nuclear weapons.
The hiring process is broken. Companies are unknowingly employing state-sponsored hackers. FBI confirms: $600 million+ siphoned to the regime annually.
Your next hire might be working from Pyongyang
Wrench attacks are still climbing in 2026 and they have nothing to do with your keys.
Criminals skip the technical side entirely and go straight for the person, with threats, coercion, physical force until you hand over access yourself. Analysts found roughly 45% of reported attack frequency tracks directly with market cap, so as prices rise, so does the violence.
Reduce your exposure: keep your public identity separate from your holdings, split day-to-day funds from long-term storage, and audit what's out there with your name attached to it.
Following the recent DNS hijacking incident, the Neutrl domain has been successfully migrated to https://t.co/XlWqYSjSc0 and is now secured on a new DNS provider.
Neutrl smart contracts have been unpaused and are fully operational.
ALL USER FUNDS ARE SAFE.
Protocol NAV, including reserves and user funds, remains secure within Neutrl’s custodial wallets, supported by a custody framework and off-exchange settlement (OES) that isolates funds from front-end and infrastructure risks.
Users should no longer interact with neutrl[.]fi under any circumstances and should only use the new domain moving forward. The .fi domain will be sunset.
As an added precaution, users who interacted with the compromised domain are advised to review and revoke permissions via revoke[.]cash, including any Permit2 approvals associated with the following malicious addresses:
0x23f2741EaA0045038e9b52100CdcC890163dE53F
0xa0Adf074056E41dfB892aFC69881E15073b384b9
Please also revoke any approvals associated with addresses you do not recognize.
We extend our sincere gratitude to the teams at @0xGroomLake and @SEAL_911, whose support and expertise were instrumental in our response. Their work in strengthening security across the ecosystem is invaluable.
Additional updates will be shared as they become available, along with a full post-mortem.
Compute scales. Human attention doesn’t.
Agentic, end-to-end attack loops are now showing up in the wild.
Continuous, automated security has to be the new baseline.
You can’t defend what you can’t see.
Reaper AI continuously maps exposed identities, leaked data, and reconnaissance signals across your organization.
Early access → https://t.co/55LwbRKEai