We published the private key to a Safe on purpose. The Safe holds test USDC.
Take the key and try to withdraw the money: https://t.co/kL0x83cIOe
Sign all you want. Without a 2FA code matched to the exact recipient and amount, @newton_xyz denies the transfer.
An early warning only helps if tools can act on it before the exit liquidity is gone. A dashboard that flagged risk and a vault that was still allowed to sit there are two different failure points.
Watch the SVB dip on this chart π
Circle disclosed $3.3B stuck at SVB on a Friday night. By Saturday USDC was at $0.87, and everyone heading for the exit was going through the same few Curve pools.
The data backs this up: by dollar value, most losses trace to compromised keys, not contract bugs. A step-up check in front of the signing action, not just around it, is key for operational security.
Most crypto hacks aren't smart contract bugs.
Look at the data by dollar value and the majority come from compromised keys. Once an admin key breaks, nothing stops it. "Other than stopping blockchain."
@0xdenniswon, co-founder of Newton Labs, on why opsec, not code, is the bottleneck for DeFi, and how Newton puts 2FA in front of a Safe wallet.
Full episode π https://t.co/yaXqs8DRSW
@newton_xyz@0xdenniswon securing onchain finance is more than just airtight code, it requires protections and authorizations across the entire operational stack
Everyone already has address intelligence. It's that the decision to allow, cap, or deny gets written down at the moment it happens, signed, checkable by anyone with the transaction hash. That's the difference between "we have a counterparty policy" and "here's the policy that ran, and here's proof it ran."
$104B reached sanctioned entities last year. None of it announced itself.
@arkham labels the entity behind the address. Newton checks the label before your agent's transaction settles.
Read more in the blog π
Escrow, clearing, and letters of credit all worked by putting a trusted third party in control of the asset. What's being built here is closer to the opposite: authorization without custody. The rule gets enforced before the transaction settles, but nobody has to hand over the keys to get that enforcement.
Escrow exists because "trust me" doesn't scale.
Every system that moves money built a place where the rules hold.
Onchain finance is building its own right now.
Honestly, any of them, as long as breaching the rule makes the transaction fail instead of generating a notification after it settles. A rule that can only alert you but fails to stop the harm isn't helpful.
4/ The industry's answer so far is monitoring. Dashboards, alerts, risk scores.
Monitoring tells you the mandate was breached.
It has never once stopped a transaction. That's not what it's for.
$100,000,000,000+ now sits in onchain vaults.
~$9B of it is run by curators.
Amount protected by risk limits the curator physically cannot break: almost none.
This is the biggest unpriced risk in DeFi right now.
Curating an onchain vault means real power over depositor capital β and today the only thing behind it is trust.
@newton_xyz VaultKit checks every curator action against policy before it reaches the vault. Inside the rules, it executes. Outside them, it fails closed.
1/ Institutional capital moved onchain faster than the controls meant to govern it. Today that changes.
Magic Labs is launching VaultKit, the SDK curators use to make a vault's rules enforceable onchain, alongside @newton_xyz mainnet beta launch! π₯³ π§΅
https://t.co/ESnYTP5gZD