0x17 Web3 Security Bulletin

Crypto and web3 security insights, including tools, hacks, and regulations.


Beta Podcast Mode


Insightful

Web3 Security in 2026: Lessons From 2025, Projections Ahead

Sherlock reports that 2025 saw roughly $3.4 billion stolen from Web3 protocols, with losses concentrated in a few large incidents rather than many small ones. The Bybit breach alone accounted for about $1.5 billion. Many failures occurred outside code review: privileged access, signing infrastructure, third-party dependencies, and upgrade pathways. In 2026, security programs will shift from checkpoint audits to continuous lifecycle security. Teams will need to demonstrate operational controls, system behavior validation, and AI-assisted detection with disciplined triage. Security buyers will ask harder questions about access management, upgrade processes, and blast radius planning, not just code quality. (Sherlock)

Securing Real-World Assets in 2026

A joint guide between Cantina and Centrifuge on security best practices for RWAs. The piece covers contract correctness, governance, off-chain processes, and how security models must evolve as RWAs move toward broader institutional adoption. (Cantina)

AI-Powered Crypto Scams Drove $17B in Losses Last Year

The Chainalysis team reports that crypto scams and fraud stole an estimated $17 billion in 2025, with impersonation schemes and AI-assisted campaigns doing much of the damage. The piece breaks down how scam economics changed, where operations are based, and how enforcement actions are starting to claw back funds. (Chainalysis)

Secure Federated Learning with Cryptography

This Hexens post covers cryptographic methods to secure federated learning, including homomorphic encryption, multi-party computation, verifiable aggregation, and other techniques that allow machine learning models to train on distributed data without exposing raw inputs. (Hexens)

Quantum Computing Risks to Bitcoin: 2026 Outlook

The Epoch Bitcoin Ecosystem Report 2026 addresses quantum computing risks to Bitcoin. Expert timelines have shifted, with some estimates placing potential cryptographic breaks between 2026-2035, though most experts place the realistic threat in the mid-2030s or later. Neven's law (doubly-exponential quantum growth) is viewed skeptically; quantum computers have only factored numbers up to 15, and logical qubit growth hasn't matched projections. Chaincode Labs recommends a 2-year contingency plan and a 7-year comprehensive plan, noting that modern Taproot address types already provide some quantum resistance by hiding public keys until spending. The main risk is premature implementation of quantum-resistant signatures, which could reduce efficiency compared to future schemes. The Bitcoin community is actively researching solutions through BIP360, but quantum computing is not considered a primary risk for investors given current progress and existing mitigations. (Epoch VC)

Coinbase Creates Advisory Board to Study Quantum Computing Risks to Bitcoin

Coinbase announced an independent advisory board to address how to protect blockchains like Bitcoin and Ethereum from future quantum machines. While quantum computers capable of breaking modern cryptography do not yet exist, researchers warn that transitioning global financial and blockchain systems to new cryptographic standards could take years. The advisory board includes University of Texas professor Scott Aaronson, UC Santa Barbara's Dahlia Malkhi, Stanford cryptographer Dan Boneh, Ethereum Foundation researcher Justin Drake, EigenLayer founder Sreeram Kannan, and Coinbase Head of Cryptography Yehuda Lindell. The board will publish papers assessing quantum-related risks, issue guidance for users and developers, and provide independent analysis following significant developments in quantum computing. Bitcoin and Ethereum rely on elliptic-curve cryptography, which could be broken by sufficiently powerful quantum machines using Shor's algorithm. (Decrypt)

Attackers Race Security Teams with AI-Guided Exploit Hunts

Quantstamp describes “The Exploit Race,” where automated agents and faster tooling let attackers probe Web3 protocols more aggressively than traditional audit cycles anticipate. The team explains how they benchmark AI security agents, what reliable workflows look like, and why reproducibility matters when prompts and context can subtly change results. (Quantstamp)

Got skills?

Trail of Bits introduces a Claude code skills package for AI-assisted security analysis, testing, and development workflows. The repository includes over 20 plugins covering smart contract security, code auditing, verification, reverse engineering, and mobile security. Plugins include vulnerability scanners for six blockchains, static analysis tools, differential review capabilities, and property-based testing guidance.(Trail of Bits on Github)

Companies in the news

PaymentShield: Security Suite for X402 Autonomous Payments

AgentLISA announced PaymentShield, a security platform for X402 autonomous payment infrastructure. The system addresses three application-layer vulnerabilities: malicious recipient risks without sanctions validation, settlement race conditions that allow service access without payment, and resource exhaustion attacks from missing rate limits. PaymentShield includes an AI agent payment firewall with real-time sanctions screening and smart contract risk analysis, a settlement assurance engine that eliminates race conditions through atomic binding, and standardized rate limiting protections. X402 has processed over 100 million autonomous transactions in its first six months with backing from Coinbase, Cloudflare, Google, and Visa. (AgentLISA)

Embedded Wallets as the Next Trading UX Default

Fireblocks argues that embedded, non-custodial wallets are becoming standard for trading apps that want faster asset listings and fewer custody bottlenecks. MPC-based keys, gas abstraction, and simple recovery flows keep users inside a platform while still giving them direct control over funds. (Fireblocks)

Cantina Launches Free DNS Monitoring for Early Threat Detection

Cantina’s free DNS Monitoring service is aimed at helping teams establish a baseline for DNS-related risks and detect early high-confidence threat signals. This works as a proactive layer before incidents escalate to user-facing issues. (Cantina)

Introducing Workflows: No-Code Automation for Data-Scientist-Level Blockchain Insights

Chainalysis announces Workflows for Data Solutions, a no-code automation platform that enables data-scientist-level blockchain insights without programming. The platform provides interactive no-code experiences that guide users through advanced blockchain analysis with a fill-in-the-blanks interface. Users can run complex analytical tasks in a few clicks without writing SQL or Python. The initial launch includes workflows for timing and amount analysis, threat actor network expansion via mutual counterparty analysis, and targeted wallet and cluster search. Technical users retain full SQL and Python access, while non-technical users gain analytical independence. Chainalysis plans to expand to hundreds of no-code workflows over time, with future integration of AI to orchestrate and combine individual workflows for end-to-end automation. (Chainalysis)

Gimme the loot

A few notable hacks from Rekt and other sources…

Victim Loses $282M in Bitcoin and Litecoin to Hardware Wallet Scam

A crypto holder lost over $282 million in Bitcoin and Litecoin on January 10, 2026, in what blockchain investigator ZachXBT identified as a hardware wallet social engineering scam. This is the largest individual crypto theft of 2026 so far, surpassing the previous record of $243 million set in August 2024. The attacker immediately began converting stolen assets into Monero through multiple instant exchanges, causing XMR's price to spike. Bitcoin was also bridged to Ethereum, Ripple, and Litecoin via Thorchain to obscure the funds' trail across multiple blockchain networks. (TradingView)

Saga EVM Hacked for Over $6M in ETH

Saga EVM was exploited, resulting in a loss of at least 2,000 ETH valued at around $6.8 million and the halting of the network. The attack involved unauthorized minting of Saga Dollar (D) stablecoins. The attacker bridged the tokens to Ethereum, bought over 2,000 ETH, and traded remaining stablecoins through Uniswap V4. The exploit originated in Saga's core infrastructure, not from Oku or Uniswap exchanges. Saga paused all activities at block height 6,593,800 to investigate the vulnerability. The protocol's TVL crashed from over $36M to $21M, and the D stablecoin de-pegged, falling to $0.75 from its usual $1 range. The ETH from the exploit remains in a single address and has not been moved or mixed. (Cryptopolitan)

Makina Incident Analysis

CertiK analyzes the January 20, 2026 exploit of DeFi protocol MakinaFi that resulted in the theft of 1,299 ETH, valued at approximately $4.13 million. The attacker used a large flash loan to manipulate prices. The exploit leveraged Makina's Caliber system, which uses these Curve functions as oracle references for calculating AUM and sharePrice. The attacker inflated the positional AUM through manipulated pool balances, then arbitraged the sharePrice increase to extract funds. As of January 21, 1,023 ETH remains in the attacker's wallet, and the team has offered a 10% bounty. (CertiK)

FutureSwap Hit Again by Reentrancy Exploit

A exploit against FutureSwap on Arbitrum, where an old reentrancy issue let an attacker over-mint LP tokens and later redeem them for about $74,000. The contract was previously abused in a similar way, raising questions about patch depth and monitoring. (BlockSec on X)

PyPI Package Impersonates SymPy to Deliver Cryptomining Malware

Kirill Boychenko reports that Socket's Threat Research Team identified a malicious PyPI package, sympy-dev, that impersonates SymPy, a widely used symbolic mathematics library with roughly 85 million downloads per month. The threat actor copied SymPy's project description and branding cues into the sympy-dev listing, increasing the likelihood of accidental installation. The package had four releases (versions 1.2.3 through 1.2.6), all containing malicious code and published on January 17, 2026. In its first day on PyPI, sympy-dev surpassed 1,000 downloads. The malicious code injects a downloader and in-memory execution routine into SymPy polynomial code paths. When invoked, the backdoored functions retrieve a remote JSON configuration, download a threat actor-controlled ELF payload, then execute it from an anonymous memory-backed file descriptor using Linux memfd_create and /proc/self/fd. In observed samples, the downloaded payloads are XMRig cryptominers that mine against threat actor-controlled Stratum endpoints. (Socket)

Total 2026 hack events: 14

The total amount of money lost by blockchain hackers is about: $41,359,400

We must have regulations

A Global Pivot Toward Innovation-First Crypto Policy

David Carlisle describes a shift from enforcement-led approaches toward frameworks that support crypto innovation, with more sandboxes, targeted exemptions, and cross-border coordination. Enforcement doesn’t disappear—fraud and sanctions risks remain central—but 2026 policy will focus more on enabling regulated participation and scaling compliant markets. (Elliptic)

US Sets the Pace for Stablecoin and Market-Structure Rulemaking

US policy momentum, pointing to stablecoin implementation timelines and ongoing debates over SEC/CFTC jurisdiction are key 2026 watchpoints. The US direction will shape global approaches, especially as banks deepen digital-asset involvement and compliance expectations harden around financial crime, consumer protection, and market integrity. (Elliptic)

Why Now is the Time for the UK to Lead the Global Fight against Crypto-enabled Fraud

Chainalysis reports that crypto-enabled fraud cost victims at least $14 billion globally in 2025, with sophisticated scams like pig butchering and AI-powered social engineering reshaping the threat landscape. The UK is investing over £150 million to transform Action Fraud into a new National Fraud and Cyber Crime Reporting service. Project WINTERPROOF, led by the National Economic Crime Centre, focuses on fighting fraudsters with an overseas nexus who target the UK. With data showing 75% of all fraud against UK individuals and businesses is either instigated or facilitated from abroad, the project emphasizes international collaboration with law enforcement agencies in high-risk jurisdictions. New regulations place unprecedented responsibility on financial institutions and crypto businesses to prevent fraud, creating opportunities for AI-powered prevention tools to transform the industry approach from reactive to proactive. (Chainalysis)

VCs & funding

Ledger Eyes US IPO at $4 Billion-Plus Valuation

Ledger, the Paris-based crypto security company, is preparing for a US IPO that could value the firm at more than $4 billion, according to the Financial Times. The hardware wallet maker is working with Goldman Sachs, Jefferies, and Barclays on the deal, which could take place as soon as this year. CEO Pascal Gauthier told the FT that "money is in New York today for crypto, it's nowhere else in the world, it's certainly not in Europe." Rising demand from security-conscious crypto investors drove Ledger to a record in 2025, generating triple-digit millions in revenue. Ledger has sold over 7 million devices worldwide and reached a $1.5 billion valuation after its 2023 funding round. (TradingView)

Research corner

An Ontology of Defects for Ethereum and its Smart Contracts

Michele Pasqua, Sofia Mari, Ferdinando Santoro, and Mariano Ceccato propose a knowledge base of Ethereum defects covering security vulnerabilities and code flaws. The work includes a systematic literature review, a hierarchical tag system for classification, and an ontology for searching and learning about Ethereum defects. The team also built EDOV, a visualization tool for navigating the ontology, performing search queries, and viewing defect details including examples of defective and fixed code. The ontology includes descriptions, code examples, and mitigation strategies for each defect. The research addresses the lack of comprehensive resources for developers and researchers working with Ethereum smart contracts, providing a unified source of information on defects affecting Ethereum and its smart contracts, their root causes, impact, and mitigation strategies. (Science Direct)