# 0x13 Web3 Security Bulletin

*Crypto and web3 security insights, including tools, hacks, and regulations. *

By [W3SB](https://paragraph.com/@w3sb) · 2025-12-26

web3, crypto, security, cybersecurity, regulations, hacks, exploits

---

Insightful
==========

**Bitcoin Optech Year-in-Review 2025: Key Security & Privacy Developments**

*   **Vulnerability Disclosures:** 2025 saw significant disclosures, including privacy weaknesses in centralized coinjoin protocols (Wasabi, Ginger, Trezor Suite) that allowed coordinators to deanonymize users. Critical bugs were patched in Lightning implementations: LDK fixed a theft-of-funds vector in claim processing and a settlement failure bug; LND resolved a "pay-and-refund" theft exploit and a gossip-based DoS; and Eclair patched a vulnerability allowing theft via old commitment transactions.
    
*   **Quantum Security:** The threat of quantum computing drove new proposals, including a "quantum-resistant" tapscript opcode, BIP360 (P2TSH) for quantum-safe outputs, and mechanisms to burn or recover vulnerable coins in a post-quantum future.
    
*   **Network Attacks & Mitigations:** Research highlighted BGP interception risks that could partition nodes or enable eclipse attacks. New defenses against Lightning "channel jamming" were simulated, with proposals for upfront and hold fees gaining traction.
    
*   **Consensus & Mining:** A theoretical consensus failure in NBitcoin was patched, and concerns over "MEVil" (mining centralization via MEV) spurred a proposal for a private block template marketplace to decentralize transaction selection. ([Bitcoin Optech](https://bitcoinops.org/en/newsletters/2025/12/19/))
    

**Adam Back vs. Nic Carter: The Quantum Threat Debate Heats Up**

A public spat erupted between Blockstream CEO Adam Back and VC [Nic Carter](https://x.com/nic_carter/status/2002044276062982618?s=20) over the urgency of quantum computing threats to Bitcoin. Carter, citing his investment in quantum-defense startup [Project Eleven](https://www.projecteleven.com/), argues that many developers are in "denial" about imminent risks (potentially 2–9 years out), while Back dismissed Carter's warnings as "uninformed noise," maintaining that the community is already quietly preparing and that practical quantum attacks remain decades away. ([Cointelegraph](https://cointelegraph.com/news/quantum-computing-bitcoin-adam-back-nic-carter-debate))

**BitMEX Research Digs Up Bitcoin’s 2011 Quantum Panic**

BitMEX Research revisits early BitcoinTalk discussions on quantum computing, showing that today’s “quantum breaks Bitcoin soon” debate closely mirrors posts from 2011—including predictions that ECDSA could fall within a few years. The thread argues the rhetoric hasn’t evolved much, but post-quantum cryptography options have improved materially, reframing the issue as planning and migration rather than surprise catastrophe. ([BitMEX on X](https://x.com/bitmexresearch/status/2003587862034297079))

Companies in the news
=====================

**Project Eleven x Solana: Prototyping Post-Quantum Signatures on Testnet**

Project Eleven announces a collaboration with the Solana Foundation to harden the network against future quantum computing threats. The engagement included a comprehensive risk assessment of Solana's core infrastructure and the successful deployment of a post-quantum signature scheme on a testnet, demonstrating that quantum-resistant transactions are scalable and practical without sacrificing performance. ([Project Eleven](https://blog.projecteleven.com/posts/project-eleven-to-advance-post-quantum-security-for-the-solana-network))

**Cantina x Uniswap Labs 2025: A Historic Year For Liquidity, Institutions, And Security**

Paul from Cantina recaps a pivotal year for Uniswap, marked by the rollout of v4 Hooks, the Cross-Chain Assessment (CCA), and the integration of Monad and Unichain. The post underscores the protocol's focus on security and institutional adoption, highlighted by a record-breaking 15.5M USDC DeFi bounty program designed to harden the ecosystem against emerging threats. ([Cantina](https://cantina.xyz/blog/cantina-x-uniswap-labs-2025-a-historic-year-for-liquidity-institutions-and-security))

Gimme the loot
==============

_A few notable hacks from_ [_Rekt_](https://rekt.news/) _and other sources…_

**Compromised Trust Wallet Extension Update Drains User Funds**

A malicious update to the Trust Wallet Chrome extension, released on December 24, has reportedly led to widespread wallet drains for users who installed it. Security observers noted the launch of a phishing domain coinciding with the compromised update, prompting urgent warnings for users to check their extension versions and revoke permissions if necessary. ([Bleepingcomputer](https://www.bleepingcomputer.com/news/security/trust-wallet-chrome-extension-hack-tied-to-millions-in-losses/))

[![User Avatar](https://storage.googleapis.com/papyrus_images/c6a1eda281eed6790c9ea5fbc656c1d4bf6f4fb10c6ad7646f2c6428194f4936.png)](https://twitter.com/SlowMist_Team)

[SlowMist](https://twitter.com/SlowMist_Team)

[@SlowMist\_Team](https://twitter.com/SlowMist_Team)

[](https://twitter.com/SlowMist_Team/status/2004505094646345905)

![🚨](https://abs-0.twimg.com/emoji/v2/72x72/1f6a8.png)SlowMist: Analysis of Trust Wallet Browser Extension Hack![🚨](https://abs-0.twimg.com/emoji/v2/72x72/1f6a8.png)  
  
Today, [@TrustWallet](https://twitter.com/TrustWallet) issued a statement confirming that version 2.68 of the Trust Wallet browser extension contains a security risk. Below is our detailed breakdown:![👇](https://abs-0.twimg.com/emoji/v2/72x72/1f447.png)

[![User Avatar](https://storage.googleapis.com/papyrus_images/35516f5a7fecb3f1d55c879240bb19cf444326209c2f2f0a6c152a4de8a1a8ff.jpg)](https://twitter.com/TrustWallet)

[Trust Wallet](https://twitter.com/TrustWallet)

[@TrustWallet](https://twitter.com/TrustWallet)

[](https://twitter.com/TrustWallet/status/2004316503701958786)

We’ve identified a security incident affecting Trust Wallet Browser Extension version 2.68 only. Users with Browser Extension 2.68 should disable and upgrade to 2.69.  
  
Please refer to the official Chrome Webstore link here: [chrome.google.com/webstore/detai…](https://t.co/V3vMq31TKb)  
  
Please note: Mobile-only users

[11](https://twitter.com/SlowMist_Team/status/2004505094646345905)[

11:50 AM • Dec 26, 2025

](https://twitter.com/SlowMist_Team/status/2004505094646345905)

**Investor Loses $50M in Address Poisoning Scam**

An investor mistakenly transferred nearly $50 million USDT to a scammer after falling victim to an "address poisoning" attack. The attacker contaminated the victim's transaction history by sending a tiny amount (0.005 USDT) from an address mimicking the intended recipient's characters. Despite sending a successful test transaction first, the user copied the fraudulent address from their history for the main transfer, allowing the attacker to swiftly swap the funds for Ethereum and launder them via Tornado Cash. ([Forklog](https://forklog.com/en/investor-loses-nearly-50-million-in-address-spoofing-attack/))

**And a $38M loss too...**

[![User Avatar](https://storage.googleapis.com/papyrus_images/2a56f214f1aa1fbce4f6c4e0a9488e35eb5aef380b4bafd3714ca4850d296679.jpg)](https://twitter.com/SpecterAnalyst)

[Specter](https://twitter.com/SpecterAnalyst)

[@SpecterAnalyst](https://twitter.com/SpecterAnalyst)

[](https://twitter.com/SpecterAnalyst/status/2001302088094191679)

A victim’s private key may have been compromised, resulting in a loss of $38 million.  
  
What makes this interesting:  
  
The victim created a multisig wallet (1/1) and moved funds into it on 04-11-2025 at 07:48:11.  
  
At 08:23:23, the main wallet, which was also the signer wallet,

![](https://storage.googleapis.com/papyrus_images/7a432cec8bb7d9f8adfc080ca8755e7e325a59e0aee66da526799e3168ba8d55.png)

[281](https://twitter.com/SpecterAnalyst/status/2001302088094191679)[

3:42 PM • Dec 17, 2025

](https://twitter.com/SpecterAnalyst/status/2001302088094191679)

[SlowMist stats this week](https://hacked.slowmist.io/statistics/?c=all&d=2025)
-------------------------------------------------------------------------------

Total 2025 hack events: 200

The total amount of money lost by blockchain hackers is about

$2,924,042,055

We must have regulations
========================

**Authorities Seize E-Note Exchange for Laundering $70M in Cybercrime Proceeds**

Bill Toulas reports that U.S. law enforcement has seized the domains and servers of E-Note, a cryptocurrency exchange allegedly used to launder over $70 million from ransomware and account takeover attacks. The operation, which also targeted the platform's mobile apps and customer databases, led to money laundering charges against a Russian national believed to be the operator. ([Bleepingcomputer](https://www.bleepingcomputer.com/news/security/us-seizes-e-note-crypto-exchange-for-laundering-ransomware-payments/))

**UK Crypto Roadmap Locks In 2027 FCA Regime**

An outline of how the UK’s final Cryptoassets Regulations 2025 will pull trading platforms, stablecoin issuers, custodians, staking and DeFi intermediaries into full FCA authorization by October 2027, backed by a new designated activities regime for listings, disclosures, and market abuse. The FCA’s CP25/40–42 consultations now sketch prudential, conduct, and market rules that will turn “same risk, same regulatory outcome” into day‑to‑day supervision. ([TaylorWessing](https://www.taylorwessing.com/en/insights-and-events/insights/2025/12/more-milestones-on-the-uks-crypto-roadmap))

Research corner
===============

**SoK: Speedy Secure Finality**

_Yash Saraswat and Abhimanyu Nag_ present a Systematization of Knowledge (SoK) on blockchain finality, analyzing the trade-offs between latency and security in various consensus protocols. The paper categorizes existing approaches to achieving "speedy" finality and evaluates their resistance to attacks, providing a framework for understanding how different chains prioritize confirmation speed versus immutable security. ([arXiv](https://arxiv.org/abs/2512.20715))

**Fast Deterministically Safe Proof-of-Work Consensus**

_Ali Farahbakhsh et al._ introduce a new Proof-of-Work consensus mechanism that achieves "deterministic safety" significantly faster than traditional Nakamoto consensus. The protocol is designed to offer strong safety guarantees without the long confirmation wait times typically associated with PoW chains, potentially revitalizing interest in PoW for high-throughput applications. ([arXiv](https://arxiv.org/abs/2512.19968))

---

*Originally published on [W3SB](https://paragraph.com/@w3sb/0x13-web3-security-bulletin)*
