I think you’re massively overestimating our influence here, where exactly do we fit into this story? Would love to clear any confusion
A little sad to see a reductive and, frankly, hateful comment from an org I’ve enjoyed interacting with in the past @kt_nowk . Have a lot of respect for the team over there
Funds stolen onchain are laundered faster than AML tooling can track. Exploits unfold in minutes, stolen funds hit mixers soon after, and existing tools weren't built to keep up.
↓ Here are 3 ways Blockaid’s Risk Exposure helps your digital asset operations enforce compliance:
We've identified an address poisoning attack targeting Squads users. We have no evidence of any users being impacted at this time.
Attack vector: Since all public keys are visible onchain, attackers are programmatically creating new multisig accounts that include existing Squads users as members. These multisigs appear in the UI because the program indexes all accounts associated with your key. Additionally, attackers are grinding public keys that match the first and last characters of your real multisig addresses, making fake accounts look legitimate at a glance.
Attacker goal: Get you to mistake a fake multisig for one of your real ones — either by copying its vault address (sending funds to an attacker-controlled account) or by signing a transaction you didn't initiate.
Impact: None, if you don't interact. This is not a protocol vulnerability. The attacker cannot access your funds, execute transactions, or modify your existing multisigs. It is purely a UI-level social engineering attempt.
Action required:
— Ignore and do not interact with any multisig you did not create or weren't added to by your team
— Do not rely on matching the first and last characters of an address to verify it — always verify the full address against your own records
— If you're unsure whether a multisig is legitimate, check with your team before taking any action
— Set your Squads accounts as default — this pins them to the top of your Squad list, making it easy to distinguish your real accounts from anything unfamiliar. We encourage everyone to do this now if you haven't already (click on ... next to your Squad in the Squad list).
UI updates shipping in the next two hours:
— A banner alerting users to this attack
— An alert on any multisig you've never interacted with before
In the next few days we are also shipping a whitelist logic where all new multisig accounts initially go to a pending state requiring you to manually add them to your Squad list.
We'll follow up here with updates as we roll these out.
2 years ago, it was a handful of us building. Today, Blockaid is the trusted security layer for the largest companies operating onchain.
→ SKO 2026 in Miami
→ GTM team 3X'd this past year
→ We're hiring: https://t.co/NNjnQGjsas
One team with a shared vision, having fun doing it.
Thx for the love @BlocksterCom - happy to see this one announced and public. Would love to share more insights on this partnership for anyone interested.
This is exactly what @blockaid_ is building.
Simulation & Validation coupled with cosigners to prevent signing malicious transactions
Onchain security monitoring to prevent smart contract exploits via early detection and automated response
We need to focus more on cyber security and less on KYC
For 22 minutes, PayPal's PYUSD Issued by Paxos would not have been GENIUS-compliant.
Yesterday, Paxos, one of the most trusted and compliant players in the space, accidentally minted $300 trillion PYUSD. The total supply onchain was greater than the world’s GDP.
It was a single administrative error that exposed how easily one anomaly can affect DeFi core systems including stablecoin issuance, collateral ratios, oracles, and liquidation logic across the ecosystem.
@RicaDixuanFU@DanaBuidl@yzilabs Congrats on the raise! Would love to connect and hear about what the team is building. I think Blockaid could be of great service as a security partner as you scale
@tomgregory100 Hey Tom, congrats on the raise today at BPN. Would love to connect and learn more about how the team is addressing security on the platform - I think Blockaid could be of massive help.