Web3 Security Collective - making security fairer for hackers and dev teams.
You Can't Patch a Shitty Culture: Securing Social and Organizational Risks
by Dominik MuhsWhen it comes to blockchain and smart contract development, there’s a tendency to focus heavily on writing secure code, running penetration tests, and fixing vulnerabilities. And while these technical steps are crucial, they often overlook something equally important: the organizational culture and operational procedures that underpin a secure and resilient system. At Creed, we’ve seen firsthand how many blockchain companies make the mistake of assuming that great code alone ca...
You Can't Patch a Shitty Culture: Securing Social and Organizational Risks
by Dominik MuhsWhen it comes to blockchain and smart contract development, there’s a tendency to focus heavily on writing secure code, running penetration tests, and fixing vulnerabilities. And while these technical steps are crucial, they often overlook something equally important: the organizational culture and operational procedures that underpin a secure and resilient system. At Creed, we’ve seen firsthand how many blockchain companies make the mistake of assuming that great code alone ca...

Creed Ceremony #1 August 27th, 2025
On August 27th, 2025 Creed held our first-ever Ceremony. We went over our present standing and shared our view of the future with our community. Check out an overview of what took place below: August Security Reviews:Completed security review for @Spire_LabsCurrently working on BitYield auditGrowing pipeline of reviews scheduled for coming weeks August Risk Assessments:Completed assessment for @lagoon_finance.@GetYieldFi assessment is in progressWorking on AI tooling to optimize the risk asse...

Creed Ceremony #1 August 27th, 2025
On August 27th, 2025 Creed held our first-ever Ceremony. We went over our present standing and shared our view of the future with our community. Check out an overview of what took place below: August Security Reviews:Completed security review for @Spire_LabsCurrently working on BitYield auditGrowing pipeline of reviews scheduled for coming weeks August Risk Assessments:Completed assessment for @lagoon_finance.@GetYieldFi assessment is in progressWorking on AI tooling to optimize the risk asse...
Developers Digging Deeper: why reading risk reports are important.
by Dominik MuhsAs a developer, you’re no stranger to code reviews, penetration tests, and performance audits. These processes are crucial for identifying vulnerabilities in your code and ensuring your software is secure. But there’s one key element of the security process that you might not always be involved in—risk assessments… While risk assessments are often seen as the domain of security professionals or management teams, it’s time to start viewing them as essential reading for developer...
Developers Digging Deeper: why reading risk reports are important.
by Dominik MuhsAs a developer, you’re no stranger to code reviews, penetration tests, and performance audits. These processes are crucial for identifying vulnerabilities in your code and ensuring your software is secure. But there’s one key element of the security process that you might not always be involved in—risk assessments… While risk assessments are often seen as the domain of security professionals or management teams, it’s time to start viewing them as essential reading for developer...

Letters From the Council: Creed Origins | Gonçalo
#Lettersfromthecouncil | Creed was born out of a genuine need to make the web3 security space more cohesive, fair, and safe for protocols. Founded by four visionaries who met while working at a corporate security firm, Creed represents their collective rebellion against an outdated system that no longer serves the evolving needs of the web3 ecosystem. Listen to our Co-Founder, Gonçalo https://x.com/GNSPS speak about his experiences with web3s’ culture of cybersecurity and what inspired him to...

Letters From the Council: Creed Origins | Gonçalo
#Lettersfromthecouncil | Creed was born out of a genuine need to make the web3 security space more cohesive, fair, and safe for protocols. Founded by four visionaries who met while working at a corporate security firm, Creed represents their collective rebellion against an outdated system that no longer serves the evolving needs of the web3 ecosystem. Listen to our Co-Founder, Gonçalo https://x.com/GNSPS speak about his experiences with web3s’ culture of cybersecurity and what inspired him to...

The Watch: The State of Web3 Security Councils
By Liz Dalidalian Security councils are critical yet misunderstood components of DAO governance. These councils have become the backbone of major DeFi protocols, but their implementation varies wildly across the ecosystem. At Creed, we have extensive experience with multiple security councils and believe it's time to examine what's working and what needs to change. The concept of a security council traces back to early DAOs like Gnosis (launched November 2020), which used simple "si...

The Watch: The State of Web3 Security Councils
By Liz Dalidalian Security councils are critical yet misunderstood components of DAO governance. These councils have become the backbone of major DeFi protocols, but their implementation varies wildly across the ecosystem. At Creed, we have extensive experience with multiple security councils and believe it's time to examine what's working and what needs to change. The concept of a security council traces back to early DAOs like Gnosis (launched November 2020), which used simple "si...