Listen to the Bulletin (beta ;-)
Call this the Post Quantum Edition of the Bulletin
The EF gets serious. Project Eleven snags $20M. And plenty of research to boot.
a16z Crypto Gets a Word in Too
Justin Thaler argues timelines to cryptographically relevant quantum computers (CRQCs) are overstated, unlikely before 2030s, distorting crypto migration priorities. Urges immediate hybrid post-quantum encryption against HNDL attacks but deliberate shifts for signatures/zkSNARKs due to size, bugs, and costs; blockchains like Bitcoin need planning. (a16z Crypto on X)
Bug Bounty-Grade Agentic Tooling
How an agentic system for vulnerability research that mirrors how auditors work was built. The agent maps the system, identifies attack surfaces, hypothesizes, verifies with deterministic tools, and proves impact. It reported over 10 bugs disclosed on Immunefi, HackenProof, and HackerOne, including a $250k finding. (Kritt.ai)
And More Context for Our Agentic Tools
Lit Protocol Decentralizes Web3 Key Management
How Lit Protocol eliminates single points of failure by sharding private keys across nodes using threshold cryptography, TEEs, and programmable access controls for secure signing and encryption in wallets, agents, and apps. (Stakely)
Neobank Security Best Practices: Fintech and DeFi
This post details a nine step process for through neobank security. It includes sections on securing third-party APIs, custodial assets and custodial key management with HSMs, mobile and web hardening, authentication, compliance, DevOps, smart contract risk, insider threats, and incident response. (Cantina)
Web3SOC for TradFi: De-Risking Digital Asset Adoption
Cantina presents Web3SOC as a maturity framework for banks, asset managers, and fintechs adopting digital assets. It scores operational, financial, security, and regulatory readiness and maps to NIST, SOC 2, and ISO 27001. (Cantina)
CDSecurity Drops 6 Checklists - Bridge, DEX, AMM Security And More
More Math - Josselin Feist on Getting Rounding Right
Notes on protocol rounding: why "round in favor of the protocol" is necessary but not simple, precision loss cancellation, and design and implementation strategies for smart contracts. (Josselin Feist on X)
Chainlink Privacy Standard for Smart Contracts
Chainlink announced a privacy standard for private smart contracts at scale on any blockchain. Computations run in TEEs for privacy and performance; decentralized oracles and cryptography keep data and logic confidential. (Chainlink on X)
OKX DEX $1M Onchain Bug Bounty on Cantina
OKX Labs launched a $1M onchain bug bounty with Cantina, focused on production mainnet smart contracts in the DEX routing stack. The program covers multi-ecosystem router implementations and related onchain components. (Cantina)
A few notable hacks from Rekt and other sources…
Saga $7M Exploit Exposes Ethermint-wide Bridge Flaw
Rekt details how a helper contract on SagaEVM forged IBC messages to mint $7M in Saga Dollar without collateral. The attacker redeemed yETH, yUSD, and tBTC, and bridge funds to Ethereum. This crashed the stablecoin 25% leading to a de-peg. Left in the wake is an Ethermint codebase vulnerability affecting multiple chains. (Rekt)
Waltio Taxes & Shady Business
Waltio, a French crypto tax tool with 80,000 users, suffered an un-communicated Q1 2025 hack stealing $550K in BTC from its treasury via a seed compromise, likely exposing customer emails and balances due to poor data segregation and logging. A January 2026 breach and October 2025 incident affected hundreds, fueling French crypto-targeted scams and attacks amid prosecutorial probes. (The Big Whale)
Total 2026 hack events: 19
The total amount of money lost by blockchain hackers is about
$61,929,400
Senate Ag Advances Crypto Market Structure Bill
On January 29, 2026, the U.S. Senate Agriculture Committee voted 12-11 along party lines to advance the Digital Commodity Intermediaries Act, granting CFTC authority over spot digital commodity markets, consumer protections, and intermediaries. A milestone first for a crypto bill clearing a Senate committee, it awaits Senate Banking input on SEC aspects amid Democrat ethics concerns. (Coin Desk)
UK Clamps Down on Crypto Sanctions Abuse
OFSI reports collaboration with the Crypto Cash Fusion Cell (CCFC) and partners like NCA, FCA, and Elliptic to disrupt sanctions evasion via crypto assets, tracing illicit funds and targeting UK-based offenders in a recent operation. The initiative emphasizes real-time intelligence sharing and treats crypto abuse equivalently to traditional currency exploitation. (Office of Financial Sanctions Implementation)
Project Eleven $20M Series A for Post-Quantum Crypto
Project Eleven closed a $20M Series A led by Castle Island Ventures with Coinbase Ventures, Fin Capital, Variant, and others. The firm builds post-quantum infrastructure for digital assets: yellowpages for Bitcoin, a post-quantum testnet for Solana with ML-DSA, and NIST-standardized PQ algorithm variants. (Project Eleven)
Qurrency: Quantum-Secure, Private, Auditable Digital Assets
Qurrency targets privacy, quantum security, and auditability for digital assets and CBDCs on EVM-compatible chains. It aims to resist "harvest now, decrypt later" and implements privacy-preserving UTXO-style token mechanisms with auditing. (Cryptology ePrint Archive)
Ethereum Smart Contract for Quantum Computing Threats
Nicholas J.C. Papadopoulos has published a paper that proposes a smart contract mechanism for Ethereum to address quantum threats: a verifiable proof-of-quantum-supremacy system that triggers quantum-secure fallback protocols when quantum computers can solve practical crypto problems. (arXiv)
Bitcoin Security Under Network Delays
A rigorous mathematical proof of Bitcoin's security under delays and adversarial conditions proves that honest blocks prevail when the honest mining rate exceeds the adversary rate even under a delay. (arXiv)
SoK: Privacy-Preserving Transactions in Blockchains
A recently revised paper systematizes privacy-preserving techniques in cryptocurrencies with native privacy. It defines and compares confidentiality, k-anonymity, full anonymity, and sender-receiver unlinkability, and evaluates trade-offs between privacy, scalability, and regulatory compliance. (Cryptology ePrint Archive)
TrX: Encrypted Mempools with BFT
MEV (Maximal Extractable Value) remains one of the most corrosive forces in blockchain systems, enabling frontrunning, sandwiching, and other manipulations that directly exploit users. The core culprit is the transparent mempool: validators see transactions before they are ordered. Encrypted mempools are a promising solution by hiding transaction contents until after ordering. (Cryptology ePrint Archive)


