🗳️ With @tallyxyz winding down, delegates and token holders need reliable places to participate.
Multiple independent frontends aren't just nice to have, they reduce single points of failure.
🔗 Anticapture is now available as a governance interface:
https://t.co/J9nzGBmHQK
Access Control is becoming one of DeFi’s most critical risk layers.
Between May and June, 70+ exploits took place, with around $650M stolen in May and $81M in June.
Many of them shared a common pattern: weak permissions, unsafe execution paths, or failures in Access Control.
Why does that matter?
🧵
Our first funding round was a massive success!
Congratulations to all the Ethereum security projects collecting about $1.6M in total and to Giveth for organizing a fantastic QF Round.
What started as a 500 ETH matching pool ultimately grew to 637 ETH+ thanks to ecosystem contributions.
Shout out to @wintermute_t for adding $200K to the matching pool and to @Quantstamp whose early $50K donation helped kick off momentum for direct matching pool contributions across the round.
We also saw over $300k+ in direct donations to 134 projects!
Our hope is that one day using Ethereum will be safer than using banks. To get to that day we believe it will require a community effort. This round validates that approach.
Grateful to be part of this round with so many teams working to make Ethereum safer!
Every contribution helps make Ethereum more resilient before things break.
Thank you to the organizers for coordinating this and making these donations possible, including 6+ hours of live coverage.
The Ethereum Security QF results are live.
To the 100+ people who supported Anticapture: thank you 🫡
And thank you to everyone who donated across the round. So many strong projects showed up.
Funding security is an ecosystem effort.
Thank you @Giveth and @thedaofund.
🛡️ The results for the @thedaofund’s Ethereum Security QF Round are LIVE!
This historic round is closing with a HUGE last minute contribution:
@wintermute_t has added $200K to the matching pool 🔥
Wintermute is a well known liquidity provider, and one of the leading supporters of Ethereum security, in fact exactly a year ago today they donated $1M to @_SEAL_Org.
This year they teamed up with TheDAO, @Quantstamp & several other community partners to allocate over $1.6M worth of funding to Ethereum Security Public Goods 👇
This Wednesday, blockful Research goes live to break down the @giddydefi exploit.
$1.25M was stolen, but the compromised key was only part of the story.
Set a reminder and join us live. https://t.co/KvqL7aUlwB
The Giddy incident was not only about a compromised keeper key. It also showed what can happen when an execution path carries more authority than it should.
Tomorrow, we’ll go through the case with blockful Research.
The SquidRouterModule incident shows how security risk can sit outside the core protocol while still affecting users through trusted execution paths.
According to public reports, around $3.2M was drained from Safe wallets across Ethereum and Base through a third-party module carrying the Squid name. Squid stated that its core protocol and router contract were not affected, and that the exploited module was not built, deployed, or operated by its team.
That distinction matters because modular systems often depend on components that sit close to trusted infrastructure without being part of the core protocol itself. Wallet modules, permissions, integrations, and deployment history can all become part of the actual risk path.
For DAOs and DeFi teams, this points to a security review problem that goes beyond the core protocol: the full permission and execution path needs to be understood before a module is treated as safe to use.
Read more via @TheBlockCo
This Wednesday, the research team behind Anticapture’s analysis framework will be live with blockful Research.
A closer look at execution paths, authority assumptions, and the design choices that shape security outcomes.
This Wednesday, blockful Research goes live to break down the @giddydefi exploit.
$1.25M was stolen, but the compromised key was only part of the story.
Set a reminder and join us live. https://t.co/KvqL7aUlwB
New date for our X Space on the Giddy Finance exploit:
🗓 Wednesday, May 27
🕑 7pm UTC / 4pm BRT
We’ll take a closer look at the incident with blockful Research and unpack what this case reveals about execution, authority, and design under stress.
@anticapture — Anticapture’s mission is to make governance security easy to adopt and analyze. Built by Blockful, it turns unknown governance risks into monitored indicators, helping DAOs understand where they are exposed and what needs attention.
The goal is to give protocols, delegates, and ecosystem stewards clear step-by-step roadmaps to evolve from fragile governance structures into safer, more resilient systems. https://t.co/ZBCfMpA5P2
The space will be led by blockful Research, the team behind @anticapture’s analysis framework: @theZeugh and @guiriba.
We’ll use it to unpack what this exploit reveals about execution, authority, and design under stress, and why those lessons matter beyond Giddy itself.
Join us live on Thursday.
This week, we’re hosting an X Space with our research team to break down recent DAO and DeFi security incidents across the ecosystem.
🗓 Thursday, May 21
🕔 5pm BRT / 8pm UTC
The idea is to make this a weekly session, looking at one attack at a time.
Set a reminder and join us live.
2/
@anticapture is an open-source framework and dashboard for governance security.
It makes information legible to catch attacks ahead of time, helping DAOs read governance risk through concrete signals:
- voting concentration
- treasury exposure
- capture risk
- attack profitability
- governance activity
- classified into risk stages
4/
QF rewards broad support, not only large checks.
We’re grateful to the 100+ people who have donated to @anticapture so far!
Small donations count: more unique supporters can increase the matching.
Support open-source governance security:
https://t.co/l6ImR9ZydY
14 hours left to support Anticapture and other security projects in @thedaofund Ethereum Security QF.
April 2026 showed why this matters:
- projects faced attacks almost every day
- 30+ incidents
- ~$630M drained
Attacks exploit economic and behavioral vulnerabilities.
@YashKamalChatu1@Giveth@thedaofund@griffgreen Love to see people using this visualizer to share :)
Thank you for tagging!
Focusing on making data visible is also exactly what we do on @anticapture but for governance security!
Any donations in the QF from $1 or up go a long way for us!