0x15 Web3 Security Bulletin

Crypto and web3 security insights, including tools, hacks, and regulations.

Insightful

Aave's Winter of Discontent: Governance Crisis Following SEC Victory

Rekt News detailed Aave's internal governance conflict following December 16th SEC relief—founder Stani Leshner escalated a proposal through Snapshot without author Ernesto's knowledge during the Christmas-week coordination window, erasing $500M in market cap. Markets priced uncertainty from the governance breakdown, with token recovery contingent on leadership alignment. By January 2nd, Leshner posted conciliatory statements on revenue sharing and brand guardrails, signaling Round 2 negotiations. The crisis demonstrates governance framework risks when processes prioritize speed over community consensus. (Rekt)

Blockchain Security Brief: GlassWorm Malware, AI Deception

Rekt News' security brief documented opening-week 2026 threats including the macOS-targeting GlassWorm malware wave replacing crypto wallets with trojans, and AI-generated phishing campaigns exploiting trust infrastructure. After $4B in 2025 losses, the pattern continues: broken governance, malware supply chain attacks, and off-chain trust violations. Security teams must address simultaneous threats across protocol governance, wallet security, and AI-augmented social engineering. (Rekt)

2026 Crypto Crime Report: Nation-State Threats Reach Record Levels

Chainalysis released its 2026 Crypto Crime Report documenting record illicit activity, with North Korean nation-state hackers stealing $2.02 billion—a 51% year-over-year increase, pushing historical totals to $6.75 billion. Chinese money laundering networks emerged as dominant criminal infrastructure providers offering laundering-as-a-service. Stablecoins now comprise 84% of all illicit transaction volume. While illicit activity remains below 1% of total crypto volume, professionalized criminal ecosystems targeting sanctions evasion and terrorism financing demand enhanced law enforcement cooperation. (Chainalysis)

Blockchain Bridge Security: Part 1 of 4-Part Series

A blockchain bridge security series explores cross-chain communication vulnerabilities using sample vulnerable bridge contracts. Part 1 examines BridgeSafeTokenSend.sol and SignalProcessor.sol, establishing architecture where relayers transfer messages between source and destination chains. Two foundational vulnerabilities are analyzed: message replay attacks exploiting missing staleness checks that enable reusing executeMessage() calls to mint unlimited tokens, and signature replay attacks leveraging unsigned transaction IDs that allow attackers to reuse old signatures for new transactions—demonstrated via test_sendMsgPermit_signature_replay() where Alice intended to transfer 50 tokens but an attacker drained 100 by replaying the signature. Both vulnerabilities stem from missing validation: message hashes aren't stored to prevent reuse, and transaction nonces (IDs) aren't enforced during ECDSA verification. Part 2 expands to cross-chain signature replay, signature variations, chain ID spoofing, hash collisions, and signature expiry mechanisms. (The Caliber)

Math in Solidity — Foundation for Smart Contract Arithmetic

Mikhail Vladimirov opens a five-part series on mathematical operations in Solidity by examining numeric type systems. Despite Solidity's 5,248 numeric types (32 signed integer, 32 unsigned integer, 2592 signed fixed-point, and 2592 unsigned fixed-point types), the EVM natively supports only 256-bit signed and unsigned integers; other types truncate results after every operation, reducing efficiency. Solidity declares fixed-point arithmetic unsupported. Developers emulate wider integers via byte arrays and fractions via libraries (DSMath, ABDK, Fixidity), but incompatible formats fragment the ecosystem. Solidity's compile-time rational literal evaluation differs from runtime division (rounding toward zero), creating hidden semantic traps—expression ((7/11+3/13)*22+1)*39 evaluates to 705 at compile time but 39 at runtime. The series continues with overflow, percents, compound interest, and logarithmic operations. (Mikhail Vladimirov)

Companies in the news

Fireblocks Acquires TRES

Fireblocks announced the acquisition of TRES to consolidate its platform from security-focused infrastructure into a full-stack operating system for digital asset operations. The expansion addresses evolving market needs beyond custody and transaction processing—audit-ready financial records, tax compliance, and operational scalability. (Fireblocks)

AI First Flights: On-Demand Smart Contract Auditing Practice

Cyfrin launched AI First Flights, self-service practice audits providing instant AI feedback on security findings. Unlike scheduled First Flights with manual judging, AI variants offer 10 on-demand audits at varying difficulties, delivering results in minutes. Participants review codebases, submit vulnerability findings, and receive AI evaluation identifying missed findings and comparing analysis to experienced auditors. The submission format mirrors competitive audits, training the full vulnerability documentation workflow without reputation risk. (Cyfrin)

Cyfrin 2025 Wrap Up: Advancing Web3 Security, Audits, and Blockchain Education

Cyfrin published its 2025 retrospective highlighting expanded security audit capabilities, AI-powered educational tools, and contributions to blockchain protocol hardening. The firm conducted 100+ audits, launched AI First Flights for on-demand smart contract practice, and published exploit root-cause analyses. Cyfrin's evidence-based approach—combining formal verification with adversarial testing—reinforces industry shift toward post-audit continuous security. (Cyfrin)

Securnex Launches Wallet Risk Analysis Platform

MercyDeGreat unveiled Securnex, a read-only wallet security analysis platform addressing the critical gap between wallet compromise detection and fund loss. Most drained wallets exhibited warning signs weeks before exploitation; Securnex shifts from post-damage recovery to pre-connection risk intelligence. The platform analyzes drainer contract interactions, malicious approval patterns, exposure to compromised wallets, reused exploit signatures, and emerging risk trajectories—without requiring wallet connections, signing, or introducing phishing surface. For protocol founders, early risk visibility reduces user blame misdirection and support team friction; for everyday users, contextualized risk assessment enables informed decisions before approval revocation causes greater harm. Securnex supports Ethereum, Solana, BNB Chain, and Base with optional approval revocation for users seeking active remediation. (@MercyDeGreat)

Gimme the loot

A few notable hacks from Rekt and other sources…

January 8th...$26M Gone...

Wrench Attacks on Crypto Users Rising in Frequency and Severity

Haseeb Qureshi analyzed Jameson Lopp's database of "wrench attacks"—violent crimes targeting crypto holders to steal assets—and found both increases in incident frequency and severity. Market capitalization explains 45% of attack variance; higher crypto prices correlate with increased violence.

post image

However, normalizing by Coinbase monthly active users (2M in 2015 to 120M in 2025) reveals a more nuanced picture: violence per user has increased moderately to 2021 levels but remains significantly lower than 2015-2019 rates, suggesting population growth drives apparent attack increases rather than per-capita risk escalation. Western Europe and APAC experienced largest violence upticks; North America remains safest geographically. (@hosseeb) (charts)

GoBruteforcer Botnet Launches New Attack Wave

Check Point researchers documented a new GoBruteforcer (GoBrut) botnet wave targeting exposed cryptocurrency and blockchain project databases on servers configured using AI-generated examples. The Golang botnet targets FTP, MySQL, PostgreSQL, and phpMyAdmin services, with 50,000+ potentially vulnerable servers. Initial compromise leverages weak XAMPP FTP defaults; subsequent exploitation launches up to 95 brute-forcing threads scanning public IP ranges. Recent campaigns compromised hosts with TRON wallet-scanning tools targeting ~23,000 addresses for automated draining. LLM-generated configurations with predictable defaults amplify attack surface. (Bleepingcomputer)

Total 2026 hack events: 9

The total amount of money lost by blockchain hackers is about $29,969,400

We must have regulations

Privacy Debate Intensifies as EU's DAC8 Tax Regime Takes Effect January 1

The European Union's Directive (EU) 2023/2226, known as DAC8, commenced January 1, 2026, mandating cryptocurrency service providers to collect and report user KYC data, transaction histories, tax identification numbers, and details on transfers to self-custody wallets to national tax authorities by July 2026. The framework triggered immediate privacy backlash, with community observers characterizing the regime as "ending crypto privacy." Crypto commentator Blockchainchick's social media breakdown of DAC8 sparked broader discourse on financial surveillance versus tax enforcement. DAC8 extends the OECD's Crypto-Asset Reporting Framework (CARF)—adopted by 76 jurisdictions including the US, UK, Japan, and Brazil—establishing automated international tax authority data exchange. Platforms must report crypto-to-fiat trades, crypto-to-crypto exchanges, and self-custody wallet withdrawals; accounts lacking tax identification numbers face freezing after 60 days. The European Commission estimates €1.7 billion in additional annual revenue; first reports reach tax authorities by September 2027. While structured reporting rather than immediate enforcement characterizes 2026-2027, privacy advocates warn the infrastructure now enables unprecedented financial surveillance and cross-border asset seizure coordination. (The Block)

Elliptic's 2026 Regulatory Outlook: Five Key Crypto Trends

Elliptic identified five transformative trends shaping 2026 crypto regulation: national strategic policy prioritization, GENIUS Act progress opening new market entrants, institutional adoption expansion into DeFi, enhanced sanctions enforcement mechanisms, and blockchain analytics innovation driving data-driven compliance. US Treasury implementation of GENIUS Act and market structure legislation will attract stablecoin issuers, tech firms, and banks. Institutional participation in DeFi and cross-jurisdictional innovation partnerships signal maturation. AI-integrated blockchain analytics will strengthen AML/CFT regimes. (Elliptic)

Senate Crypto Bill At Critical Juncture: Stablecoins and Trump Conflicts Threaten Legislative Progress

The U.S. Senate faces a decisive moment advancing comprehensive crypto market structure legislation, with fundamental disagreements over stablecoin provisions and Trump administration conflicts of interest potentially derailing passage. Senator Tim Scott indicated a vote may occur as early as mid-January 2026, but TD Cowen analysts warned that political obstacles could delay final enactment until 2027, with rules potentially not taking effect until 2029. Democrats remain skeptical of provisions that could accelerate Trump's personal crypto ventures ($TRUMP meme coin, World Liberty Financial), and unresolved illicit finance concerns persist despite the GENIUS Act's anti-money laundering framework already signed into law in July 2025. The bipartisan compromise appears fragile: Republicans prioritize market clarity while Democrats demand stronger safeguards and limits on tech-firm stablecoin issuance. Industry observers differ sharply on whether consensus remains achievable. (The Block)

VCs & funding

Chainalysis Acquires Hexagate for ~$60M: Shifting From Investigation to Real-Time Prevention

Chainalysis announced acquisition of Hexagate, an Israeli Web3 security firm founded in 2022, for an estimated $60 million (undisclosed terms per Chainalysis, ~$60M per Israeli business publication Calcalist). Hexagate's machine learning platform detects and mitigates real-time threats including exploits, hacks, and governance risks across blockchain networks. The acquisition marks Chainalysis' strategic pivot from post-mortem fraud investigations toward proactive prevention and compliance. Hexagate's track record: detected 100% of known hacks over two years with 98% detected pre-exploitation; prevented $1B+ in customer losses. Customers include Coinbase, Consensys, Polygon, EigenLayer, Uniswap, Immutable, Ava Labs, and Cronos Labs. Combined entity delivers holistic risk solution spanning prevention, compliance, and remediation. (Architect Partners)

Block Security Arena (BSA) Raises $30M Seed Round

Block Security Arena, a Web3 AI security infrastructure platform, announced completion of a $30 million seed financing round at a $30 million post-money valuation. The round included participation from Hotcoin Labs, Onebit Ventures, Apus Capital, and Starbase. BSA represents the security-first incubation trend, deploying machine learning to detect and prevent blockchain exploits in real-time across multiple networks. (AI Insider)

Research corner

Autonomous Agents on Blockchains: Standards, Execution Models, and Trust Boundaries

Saad Alqithami published comprehensive guidance on autonomous agent deployment across blockchain networks, examining threat models, security considerations, and adversarial execution dynamics. The paper addresses AI agent integration with blockchain wallets, analyzing cryptographic authorization as bearer assets, MEV extraction risks, prompt injection attacks, and formal methods for agent-blockchain security. Key contributions include defense-in-depth architectures spanning input validation, reasoning constraints, transaction simulation, execution controls, circuit breakers, and monitoring frameworks. The work establishes domain-specific benchmarks and checklists for on-chain agent safety, addressing policy enforcement mechanisms and agent action recovery procedures. (arXiv)

Privacy-Preserving Data Evaluation for Blockchain-Based Systems

PrivaDE enables privacy-preserving utility computation for blockchain-based data marketplaces. The protocol allows model owners and data owners to jointly evaluate candidate datasets without revealing sensitive information. Implementation targets EVM-compatible chains to commit cryptographic inputs, enforce multiparty computation (MPC) fairness through escrow mechanisms, and enable atomic payment conditional on successful verification—preventing unilateral defection while maintaining privacy guarantees. (arXiv)