0x19 Web3 Security Bulletin

Crypto and web3 security insights, including tools, hacks, and regulations.

Insightful

Blockchain Privacy in 2026: Why It Matters, Privacy vs Anonymity, and Top Chains

DappRadar explains why blockchain privacy matters, how it differs from anonymity, and what's hard about it. It then surveys leading chains and protocols for privacy-preserving dApps, for anyone weighing privacy options in 2026. (DappRadar)

Formal Verification of Ethereum Execution for Cancun

Nethermind’s Formal Verification team has released an open-source formal model of the Ethereum Virtual Machine (EVM) and Yul in the Lean proof assistant. This model, aligned with the Cancun hard fork and validated against the official Ethereum test suite, provides a trustworthy semantic foundation for verifying smart contracts, clients, and zero-knowledge virtual machines (zkVMs). (Nethermind)

Securing zkEVM Optimizations with Formal Verification

Ilya Leybovich details Certora's work, supported by an Ethereum Foundation grant, to secure performance optimizations in zkEVM implementations. The project focuses on formally verifying "autoprecompiles," which are automatically generated, reusable zero-knowledge circuit components developed by Powdr Labs, to ensure they improve performance without introducing vulnerabilities. (Certora)

Stop Auditing Base Like Ethereum

QuillAudits argues that security auditors must stop treating Base chain projects exactly like Ethereum projects due to subtle differences in the execution environment. The guide highlights specific DeFi security considerations for Base, urging developers and auditors to account for Layer 2 nuances to prevent vulnerabilities. (QuillAudits)

RWA Protocol Audits and Specialized Security

The Cyfrin Team explains why auditing Real-World Asset (RWA) protocols requires specialized expertise beyond standard DeFi security practices. The post notes that securing tokenized physical assets involves unique challenges related to off-chain data integrity, legal enforceability, and the bridge between digital and physical ownership. (Cyfrin)

Companies in the news

Forta Firewall Expands to Cover Address Poisoning

Forta announces an expansion of its Firewall capabilities to detect and block address poisoning scams, where attackers generate lookalike addresses to trick users into sending funds to the wrong destination. This update aims to proactively protect users from one of the most persistent social engineering tactics in the Web3 ecosystem. (Forta)

Cube3 AI Also Weighs in on Real-Time Detection of Address Poisoning

Cube3's systems detected a $360,000 loss to address poisoning in real-time, noting a recent surge in this scam vector. The article emphasizes that these attacks exploit user habits of copy-pasting addresses and argues for the necessity of speed and real-time detection to prevent irreversible losses. (Cube3 AI)

Fireblocks Supports 150 Public Blockchains

Fireblocks announces it now supports 150 public blockchains, positioning itself as a market leader in blockchain coverage. This expansion aims to provide institutions with broader access to the decentralized ecosystem while maintaining enterprise-grade security and operational efficiency. (Fireblocks)

Gimme the loot

A few notable hacks from Rekt and other sources…

Step Finance Treasury Exploit Analysis

Rekt News covers the $27.3 million exploit of Step Finance, where an executive's compromised inbox served as the attack vector rather than a smart contract flaw. Despite having audited contracts and bug bounties, the protocol's treasury was drained of unstaked SOL, highlighting that human operational security remains a critical point of failure even when code is secure. (Rekt)

CrossCurve Bridge Exploited for $3 Million

SlowMist reports that the cross-chain liquidity protocol CrossCurve (formerly EYWA) suffered a $3 million loss due to a smart contract vulnerability. Attackers exploited a gateway verification bypass in the ReceiverAxelar contract using forged cross-chain messages to trigger unauthorized token unlocks. The protocol has since issued a security update and contained the exploit. (SlowMist)

Total 2026 hack events: 22

The total amount of money lost by blockchain hackers is about $104,929,400

We must have regulations

This Week's Regulatory Coverage Dives into PwC's 4th Annual Crypto Report

Global Regulatory Convergence - The 2026 report highlights a significant shift from policy design to implementation across major jurisdictions. Regulators are increasingly aligned on core principles such as reserve requirements, redemption rights, and AML/CFT compliance. This convergence is driven by international standard-setters like the FSB and FATF, fostering a more consistent global regulatory environment that reduces arbitrage opportunities and enhances market stability.

Stablecoin Regulation Maturity - Stablecoin frameworks have moved from theoretical discussions to operational reality. Major economies, including the EU (MiCAR), Singapore, and the US (GENIUS Act), have established clear licensing regimes. The focus has shifted to "co-opetition" between banks and fintechs, with regulations legitimizing private stablecoins and enabling shared infrastructure. This evolution is critical for the integration of digital assets into the broader financial system.

Institutional Adoption and Professionalization - Institutional involvement has crossed a "point of reversibility," with traditional financial entities embedding digital assets into their core operations. The crypto stack is professionalizing, with distinct layers for custody, execution, and settlement. This trend is supported by robust prudential rules and operational resilience standards (e.g., DORA in the EU), ensuring that digital asset service providers meet the same high standards as traditional financial institutions.

The Dollar’s Digital Future - The report underscores the continued dominance of the US dollar in the digital realm, with over 95% of stablecoins being dollar-denominated. However, the rise of non-USD stablecoins and regional payment networks presents a potential challenge to this supremacy. The future of the dollar as a reserve currency will increasingly depend on the interoperability of digital infrastructure and the ability of US policymakers to foster a competitive and compliant stablecoin ecosystem.

PwC's Global Crypto Regulation Report 2026

A Quick Primer on EU Crypto Regulation In 2026

Innreg's guide to EU crypto regulation in 2026 covers MiCA, the Transfer of Funds Regulation (TFR), and AMLD. It summarizes the main compliance rules for crypto and fintech firms in or targeting the EU. (InnReg)

Research corner

Towards Explainable and Trustworthy Cryptocurrency Wallet Signing

This paper treats wallet signing as an interpretability problem in secure interaction design. The authors ran studies on how users interpret real signing requests and where usability and security diverge. They suggest design changes for clearer, more trustworthy wallet flows. (arXiv)

Software Supply Chain Security of Web3

Martin Monperrus looks at software supply chain security challenges unique to the Web3 ecosystem. Monperrus analyzes where familiar Web2 supply chain risks meet immutable, high-stakes blockchain systems. The paper maps the threat landscape for dApps and smart contracts and suggests mitigations to harden Web3 systems. (arXiv)

Are Crypto Ecosystems (De)centralizing?

A CACM paper proposes a novel framework using Shannon entropy for studying centralization and decentralization over time. The author's propose that there are recent trends toward centralization, raising concerns about resilience, independence, and security. The work covers five ecosystems (Bitcoin, Ethereum, BNB, and others) and looks at how governance and infrastructure concentration shift. (ACM)