0x11 Web3 Security Bulletin

Crypto and web3 security insights, including tools, hacks, and regulations.

Insightful

Surfs up!

Surf, who also made a splash with it's first funding round this week (see below) has joined the ranks of Anthropic and LISA using AI powered agent models to locate vulnerabilities in smart contracts.

SlowMist Publishes Comprehensive Crypto Asset Tracing Handbook for Investigators

SlowMist’s team presents a practical handbook on tracing crypto assets across major blockchains, combining on-chain analysis, exchange KYC records, and OSINT techniques. The guide walks investigators through evidence preservation, address clustering, transaction path reconstruction, cross-chain bridge tracking, and collaboration with law enforcement. It aims to standardize workflows for incident response, fraud investigation, and asset recovery in increasingly complex multi-chain environments. (Slowmist on Github)

a16z Crypto - Quantum Threats to Blockchains

Cryptographically relevant quantum computers (CRQCs) remain unlikely before 2035 despite corporate hype inflating timelines, as current systems lack the millions of fault-tolerant logical qubits needed to break RSA-2048 or secp256k1. Encryption faces urgent "harvest now, decrypt later" risks demanding immediate hybrid post-quantum migration, while signatures and zkSNARKs lack retroactive attack surfaces—making premature migration riskier than bugs and side-channel attacks. Bitcoin must begin planning active user migration now due to governance constraints and exposed P2PK addresses, not imminent quantum threats. (a16z Crypto)

Stablecoins - Programmable Payment Rails for Banking Infrastructure

Chainalysis analysis reveals stablecoins have evolved from trading utilities to live programmable payment systems settling value in minutes across borders. Banks face mounting client demand for faster settlement, lower costs, and embedded money movement as fiat-backed stablecoins dominate real-world payment use cases. (Chainalysis)

Companies in the news

Elliptic Unveils Platform for Digital Asset Compliance

Elliptic launched its next-generation Data and Intelligence Platform purpose-built for the rapidly growing digital asset industry. The platform addresses linear scaling problems in crypto compliance where increased transaction volumes traditionally required proportional analyst headcount increases. Elliptic's intelligence data indicates crypto transaction volumes and regulatory scrutiny continue intensifying, demanding automated, scalable compliance solutions beyond traditional alert-driven workflows for financial institutions, law enforcement, and regulators. (Elliptic)

Gimme the loot

A few notable hacks from Rekt and other sources…

Infini Neobank Loses $50M to Admin Wallet Compromise

Crypto-focused stablecoin neobank Infini suffered attack with attacker gaining access to wallet with admin rights, stealing nearly $50 million from the company. The incident exemplifies ongoing pattern where centralized control points and privileged access credentials represent primary attack vectors rather than smart contract vulnerabilities. Strict access control, privilege separation, and multisig governance remain critical mitigations for institutional custody and treasury management systems. (Rekt)

USPD Stablecoin Suffers $1M Front-Running Attack

USPD stablecoin lost over $1 million when attackers exploited a front-running vulnerability during smart contract deployment. The attacker performed a Multicall3 transaction claiming administrator role before the protocol's deployment script, then deployed a malicious proxy contract forwarding interactions to legitimate audited code while maintaining hidden control. After waiting 78 days, the attacker minted 98 million unbacked USPD tokens and drained 232 stETH, demonstrating infrastructure security failures despite audited smart contract code. (Halborn)

Binance Co-CEO Yi He's WeChat Account Compromised in $55K Phishing Scam

Binance Co-CEO Yi He's WeChat account was hacked December 2025, with attackers impersonating her to solicit $55,000 from contacts through fabricated emergency scenarios. The incident highlights escalating social engineering attacks targeting crypto executives, with phishing responsible for 48% of exchange breaches. (CoinDesk)

React2Shell Exploitation Delivers Crypto Miners via CVE-2025-55182 RSC Vulnerability

Huntress observed attackers targeting organizations via CVE-2025-55182, a critical remote code execution vulnerability in React Server Components (RSC) enabling unauthenticated exploitation. First recorded Windows endpoint exploitation occurred December 4, 2025, with campaigns prominently targeting construction and entertainment industries deploying cryptocurrency miners and new malware variants. The supply chain attack vector highlights ongoing risks in modern JavaScript frameworks and Node.js ecosystem dependencies powering Web3 frontend applications. (The Hacker News)

Total 2025 hack events: 191

The total amount of money lost by blockchain hackers is about

$2,940,399,055

VC's & funding

Crypto-Specific AI Platform 'Surf' Raises $15 Million to Combat Hallucinations

Surf, an AI platform purpose-built for cryptocurrency markets, secured $15 million from Pantera Capital, Coinbase Ventures, and Digital Currency Group to address the high hallucination rates of generalist models like ChatGPT in crypto contexts. Founded by Ryan Li, the platform claims 4x better accuracy on crypto tasks based on Princeton co-authored benchmarks and currently serves 300,000 users. Surf generates revenue through tiered subscriptions and plans to launch its advanced 2.0 model in February 2026, targeting $10 million in revenue by year-end. (Fortune)

We must have regulations

SEC's January 2026 Rule-making Shift: What Crypto Firms Must Prepare Now

The SEC transitions from enforcement-driven crypto oversight to formal rule-making in 2025, demanding crypto firms implement custody segregation, disclosure frameworks, comprehensive audits, and incident response protocols. Chair Paul Atkins announced an "innovation exemption" launching January 2026 alongside proposed "Regulation Crypto" establishing tailored token taxonomy, refined Howey test application, and proportionate safe harbors, ending the multi-year "regulation by enforcement" era in favor of clear, knowable rules supporting U.S. blockchain competitiveness. (Cantina)

Research corner

Hash-Based Signatures as a Bitcoin Post-Quantum Solution

Blockstream Research published a comprehensive analysis of hash-based signature schemes (like SPHINCS+) as a promising post-quantum alternative for Bitcoin. By relying solely on hash functions—primitive Bitcoin already trusts—and optimizing parameters (e.g., SPHINCS+C), researchers achieved 3-4KB signature sizes, comparable to lattice-based alternatives but with more conservative security assumptions. The paper explores tradeoffs for HD wallets and multisig, offering a concrete path for Bitcoin's quantum resistance without new cryptographic hardness assumptions. (Blockstream Research)

"Awesome Solana Security" Resource Collection for Developers and Auditors

0xhuy0512 maintains a comprehensive and recently updated repository of Solana security resources, categorizing essential tools, documentation, and educational materials for building secure programs. The collection spans official documentation, Rust and Anchor framework guides, vulnerability databases from Helius and SlowMist, and study-ready codebases like Raydium and Metaplex. It also aggregates audit reports from platforms like Cantina and Sherlock, CTF challenges, and community support channels to accelerate auditor training and secure development practices. (0xMacro on Github)

Zero-Knowledge Learning Path for Developers

Hickup's ZK Journey offers a structured, curated roadmap for mastering zero-knowledge proofs, guiding learners from foundational cryptography concepts to advanced zk-SNARKs and zk-STARKs implementation. The resource aggregates tutorials, academic papers, workshops, and hands-on projects—including tools like Circom, Noir, and Halo2—serving as a central knowledge hub for developers transitioning into privacy-preserving blockchain engineering and scalable auditing practices. (Hickup's on Notion)