The unsexy truth about building a firm in Web3 security?
20% is finding bugs.
30% is sales.
50% is making clients feel taken care of.
Only audit → employee.
Audit + sell → survive.
Audit + sell + deliver → unstoppable. 🫡
In H1 2026, we blocked 10M+ risky site visits and flagged 4M high-risk signatures.
Our Web3 Security Report with @SlowMist_Team and @osec_io shows how threats are evolving, and how protection starts before you sign.
Read it here: https://t.co/Ym66NIns6c
The Humanity hack is another reminder that poor opsec is often the weakest link.
A 3/5 multisig isn't really a 3/5 multisig if 3 keys can be obtained from a single compromise. A multisig is only as secure as the independence of its signers.
After assessing the opsec of several protocols, I've found that dedicated signing devices, independent backups, and separate operators are viewed as too much effort, too expensive, and/or "overkill."
They're literally the whole point of having a multisig.
bro can we do better...
(If you're on Solana and want your opsec assessed, just apply here: https://t.co/Rn1wb07m1Q)
$1M for 24+ crits = less than 40k per crit if it were a bug bounty... not bad
$1M for 24+ crits = ~50 man week audit (mid-top tier firm)... pretty excessive and shows how much more efficient models are
Seems like having the access + capital to use these top models gives you a significant edge. However, if $1M is considered expensive, what happens when these AI companies stop subsidizing so aggressively?
This $1M run could easily cost well over $10M in the near future... Then who does it truly benefit, and what's the best-value security practice for the everyday firm?
Mythos at Palo Alto Networks "found more than two dozen critical vulnerabilities in around three weeks, roughly five times what the company would typically find using existing tools"
But the company "burned through more than $1 million worth of tokens using Mythos"
Anchor is moving to a permanent home at otter-sec/anchor as we take over its stewardship.
Solana's ecosystem has been core to our work for years. Anchor has always been security-forward, and we're committed to keeping it that way for the developers who build on it.
We found a critical soundness bug in dusk-plonk that let a malicious prover forge proofs for arbitrary false statements.
The result: an attacker could mint arbitrary amounts of DUSK out of thin air and bypass every check protecting Dusk's shielded transactions.
AI is getting ridiculously good, and it's making your security really messy... Hackers are using AI to find live bugs that were missed before AI was used in security.
If you've been audited in 2026 (at least since Q2), I'm fairly certain that every audit firm has used AI to audit your code.
However, ALL live codebases audited manually (probably pre-2026) NEED to be rechecked and triaged using AI. This applies to closed-source contracts, too.
If AI is better than any human at finding vulns, and AI audits began only a couple of months ago, what percentage of your codebase was secure against human blackhats, but not against AI?
I don't care who did your audit. Reach out to them and get a recheck of EVERYTHING. AI is only getting better, and it's going to continue to find exploitable mistakes that humans made.
I realize that I've underestimated AI (or at least the speed of how good it's getting) every time.
Now I'm convinced, it's AI or Die
False positives are still an issue with AI, and that's why I recommend getting an audit firm to do the triaging part for you guys
agree that just getting an audit is not a stamp of approval. especially with the current trend of social engineering and access control exploits.
however, we work extremely closely with major chains and protocols on a near-daily basis to not only review their smart contracts, but help develop their products, design, and inspect almost every attack vector (including opsec),
I think getting one audit is not as powerful/meaningful as it used to be. I think having this long-term, and continuous engagement with a reputable firm is.
My point is not: if they had this type of security engagement, they wouldn't have been hacked.
But more so: Projects should not feel safe just because they get an audit before they launch. There's much more to security than a smart contract audit here and there.
Sui did something similar with Cetus and received a bunch of backlash.
Circle didn't do anything with Drift and received a bunch of backlash.
However, there seems to be a lot of love for Abritrum for taking this action.
Personally, I think it's good... Despite the fundamental notion of decentralization, if we're able to freeze stolen funds, we should.
What I'm most concerned about now is the precedent being set. If a project gets hacked, what metric and threshold will the public consider appropriate for taking similar actions?
Seems like any future major hacks will have a lot of spotlight on the chains.
The Arbitrum Security Council has taken emergency action to freeze the 30,766 ETH being held in the address on Arbitrum One that is connected to the KelpDAO exploit. The Security Council acted with input from law enforcement as to the exploiter’s identity, and, at all times, weighed its commitment to the security and integrity of the Arbitrum community without impacting any Arbitrum users or applications.
After significant technical diligence and deliberation, the Security Council identified and executed a technical approach to move funds to safety without affecting any other chain state or Arbitrum users.
As of April 20 11:26pm ET the funds have been successfully transferred to an intermediary frozen wallet. They are no longer accessible to the address that originally held the funds, and can only be moved by further action by Arbitrum governance, which will be coordinated with relevant parties.
The pre-release version of Anchor v2 is out.
v2 is over 90% smaller and 3-6x faster than v1, and represents months of work focused on speed, extensibility, and security. This is a major architectural change from a dense macro-based framework to a more easily extensible trait system, with security built in from day one.
Excited for teams to give it a try. Still a few rough edges, but please DM/comment with any feedback!
Drift is actively working with @asymmetric_re, and @osec_io to consolidate a coordinated recovery plan.
Our immediate focus is to stabilize the situation and provide protocol-level assurance to all affected users and partners.
Drift will also be participating in the STRIDE program by @SolanaFndn as part of strengthening our long-term security posture.
We’re aligning closely with leading ecosystem security teams to ensure a structured and thoughtful path forward.
Further updates will be shared soon.
🚨UPDATE: @vibhu says @stabbleorg's precautionary warning was issued after the protocol learned its former CTO, who was let go a year ago, was the same person ZachXBT flagged as a DPRK worker, adding the protocol is now run by a fully new team that recently acquired it.