10 open roles across the @solana ecosystem, all handpicked for @solana_devs who write Rust or work in security.
Transaction landing, MEV, RWAs, trading infra, and four security-heavy seats. Pay goes up to $465K where it's listed.
Cohort 6 is on the way. Until then, save this and send it to a fren who's looking ↓
The rails of DeFi are becoming the rails of global finance. Huge news for onchain finance and blockchain security as a whole🔥
Today we are announcing that S&P Global has entered an agreement to acquire OpenZeppelin.
Onchain finance is growing from an emerging market into core financial infrastructure, and the standards and rails our team and community built are becoming the rails of global finance. OpenZeppelin smart contracts facilitated over $37 trillion in value transferred, with the vast majority of the largest DeFi protocols, blockchain networks, stablecoins and tokenized funds relying on them.
With S&P Global, we expect to accelerate the impact of onchain finance, backed by more than a century of trust in global markets, benchmarks, and risk frameworks.
To our clients and to all the users of OpenZeppelin open source tools:
• OpenZeppelin Contracts and all our open source applications and tools remain open source, free, and publicly maintained on GitHub. Building open source standards stays a core priority.
• Audits, engineering work, and ecosystem programs continue with the same team, brand, quality, and customer experience, with what will be the added benefit of S&P Global's research capacity, market data, and institutional reach.
For the last decade, OpenZeppelin has set the security standard for onchain finance. Today begins a new chapter for that mission, together with one of the most trusted names in global markets.
Read the full announcement: https://t.co/lxBUWkWVUK
Today we are announcing that S&P Global has entered an agreement to acquire OpenZeppelin.
Onchain finance is growing from an emerging market into core financial infrastructure, and the standards and rails our team and community built are becoming the rails of global finance. OpenZeppelin smart contracts facilitated over $37 trillion in value transferred, with the vast majority of the largest DeFi protocols, blockchain networks, stablecoins and tokenized funds relying on them.
With S&P Global, we expect to accelerate the impact of onchain finance, backed by more than a century of trust in global markets, benchmarks, and risk frameworks.
To our clients and to all the users of OpenZeppelin open source tools:
• OpenZeppelin Contracts and all our open source applications and tools remain open source, free, and publicly maintained on GitHub. Building open source standards stays a core priority.
• Audits, engineering work, and ecosystem programs continue with the same team, brand, quality, and customer experience, with what will be the added benefit of S&P Global's research capacity, market data, and institutional reach.
For the last decade, OpenZeppelin has set the security standard for onchain finance. Today begins a new chapter for that mission, together with one of the most trusted names in global markets.
Read the full announcement: https://t.co/lxBUWkWVUK
Ohh wow.
"They used ChatGPT for writing and coding, including to answer basic questions and complete assignments they struggled with themselves. They preferred Google Gemini for image alteration and document forgery."
That's from an investigation into North Korean IT workers - people whose salaries help fund Pyongyang's nuclear weapons program (~$800M in 2024 alone, per US Treasury).
So let's apply the DOJ's logic from the Tornado Cash case:
@Google and @OpenAI know their tools are being used by DPRK operatives. They've known for years. They keep providing the tools and profit from every subscription.
Facilitating crime?
Enabling it?
Founders in prison?
Sounds absurd, right?
Yet that's exactly the theory behind USA v. Roman Storm: build a neutral tool, bad actors abuse it, and the developer gets prosecuted instead of the criminals.
If that logic is absurd for Google and OpenAI - it's absurd for Roman Storm.
You prosecute the criminal, not the toolmaker. Writing code is not a crime.
So let's be consistent: subpoena every Google and OpenAI employee. Dig through their text messages for any hint they knew their tools were used by DPRK. Indict them for 20 years in prison on IEEPA charges.
Source: https://t.co/nNs9AwgyZc
Top 3 researchers this week:
🥇 @0xTonraq
🥈 @tchkvsky_eth
🥉 @shealtielanzz
Keep it up! 🏆
Want your handle here? Join active programs: https://t.co/whfHUbqK9P
Aftermath Postmortem
On April 29th, Aftermath experienced an isolated security incident in the integrator feature of AF Perps.
All other products (afSui, Pools, Farms, Agg, SOR) are completely unaffected & all users will be made whole.
This has been a scary week for crypto. AI tooling is developing rapidly, and we were among the almost a dozen protocols affected by hacks. We’re hopeful that by sharing our experience, we can help the broader crypto community learn and build back stronger.
Root Cause
The root cause was a signed integer issue in the integrator accounting logic. A malicious user was able to create their own integrator with a negative taker fee. This negative fee is then credited to a newly created account, which can be freely withdrawn from the vault.
This issue was introduced as part of a diff on August 29, 2025. The changes were audited by @osec_io in Nov 2025, but the issue was unfortunately missed.
Timeline
The attacker (https://t.co/I6h41yV7P3) was first funded on 04-28 22:02:07 UTC with 405.24 SUI.
At 04-29 08:21:48 UTC, the attacker swapped 300 SUI for ~278 USDC via the SOR to obtain seed collateral for opening perp positions.
From 04-29 08:55:50 UTC to 09:31:49 UTC, the attacker drained ~1,139,927 USDC from AFperps across 17 attempts (11 successful, 6 failed).
Each of the 11 successful transactions was a single PTB that opened two accounts, registered the attacker as their own integrator with a negative 100,000 taker fee, executed a market order that crossed against a real counterparty’s maker order, then withdrew the resulting synthetic collateral as real USDC.
From 04-29 09:22:23 UTC to 10:45:22 UTC, the attacker laundered the proceeds through fresh single-use wallets and DEX swaps before depositing to Binance (https://t.co/GhFCjQhouT) (~$250K USDC), KuCoin (https://t.co/F4O7trwVwZ) (~$400K USDC), Huobi (https://t.co/9TBZOPyPDh) (HTX) (~150K SUI), and HitBTC (https://t.co/ZYToOISmm7) (~$150K USDC).
Next Steps
Out of an abundance of caution, we’re conducting an additional audit before relaunching AFperps with a separate company. That being said, we also recognize that manual review alone is insufficient in 2026.
We are investing heavily to improve our AI-security workflows. AI tooling is developing rapidly, and we were among the almost a dozen protocols affected by hacks this week.
We’re thankful to all of our partners for their rapid response and help. In particular, Blockaid, ZeroShadow, OtterSec, Sui Foundation, and Mysten Labs.
Update: We've been working with professional security teams including @SEAL_911 and @blockaid_.
Further updates will be shared as soon as they are available.
Do not interact with Wasabi contracts until further notice.
🚨 Blockaid's exploit detection system identified an on-going admin-key compromise exploit on @wasabi_protocol across Ethereum and Base. The Wasabi: Deployer EOA was used to grant ADMIN_ROLE to an attacker helper contract, which then UUPS-upgraded the perp vaults and LongPool to a malicious implementation that drained balances.
Syndicate Labs experienced a security incident. A private key compromise enabled malicious upgrades to bridge contracts on two chains, moving ~18.5M SYND and ~$50,000 of tokens from customer chains.
All impacted parties are being made whole. Details below ↓
As more and more admin keys are compromised to drain protocols, here's your check list if you are running one:
1) Learn as much as you can about your external dependencies. Once you learn about them, monitor their setup for upgrades 24/7. It's ridiculous to rely on an audit to tell you "hey, the doors to your house are locked, we checked it on 23rd of March". Today the external token that you may depend on could be L0 4/4 DVN; tomorrow, it may be 1/1 DVN. You should get an alert of a change and react to the news
2) As you should monitor your external dependencies, anyone relying on you should monitor you - for them, you are their external dependency. They should monitor every single MultiSig that you run, every single EOA that you set up - it's potentially their liability. Once an unsafe setup is detected, they may (and frankly should) refuse to use your protocol. So make sure you don't have these freaking EOAs that you set up just for operational efficiency
3) The first people spotting your weak points will be hackers. Then, external teams. Finally, your internal ops team. You need to reverse that order
4) Don't rely on AI slop for risk analysis. This current trend, where we see dozens of "risk-mgmt dashboards that I vibe-coded over the weekend" is frankly beyond scaring and outright irresponsible. You will get beautiful-sounding report, but you will never be sure if it is correct or bullshit or something in between
The above you should do on top of code audits of your protocol and impeccable internal opsec, circuit-breaker infra, and whatnot. If you think that's frankly too much or too expensive - gtfo of DeFi
And if you are overwhelmed with the complexity of the task - talk to @l2beat 💕
$86M lost in Q1 2026. +213% YoY.
Most of it didn't come from novel exploits. It came from the same gaps repeating across teams.
We mapped them.
Get a free blueprint: https://t.co/tLaKFZjWBC
Big news for Rektoff students: [Training meets placement.]
We're officially partnered with @SuperteamTalent, a community-powered recruiting agency building careers in the Solana ecosystem, backed by @SolanaFndn and @superteam.
From now on, beyond the top-notch training in Rust and Solana security, every Rektoff student now gets a direct pipeline into the best jobs the Solana ecosystem has to offer.
When an incident happens, a lot of people rush to make a "spicy" tweet. Worth remembering:
- You do not have all the information
- Security is hard, and pointing fingers is always easier after the fact
- If you run a high TVL protocol, assume you are next
The best thing to do right now: review your signing configuration, and the ones of the protocols you integrate with