# 0x25 Web3 Security Bulletin 

*Crypto and web3 security insights, including tools, hacks, and regulations. *

By [W3SB](https://paragraph.com/@w3sb) · 2026-03-20

web3, cybersecurity, hacks, regulations, crypto

---

**TL;DR**

*   We don't have CLARITY, but we have clarity. A joint interpretation on crypto assets was released by the SEC and CFTC, covering everything from airdrops to wrapping non-security assets.
    
*   S&P Dow Jones Indices licenses its brand for first official S&P 500 perp to trade on Hyperliquid and QuillAudits goes deep on Hyperliquid's architecture.
    
*   Cantina demonstrates how attackers bypass MFA entirely by replaying authenticated sessions.
    
*   Tool roll: OnboardMe replaces multi-file IDE navigation with a single scrollable execution flow view per smart contract entry point.
    
*   The week's Research corner highlights two privacy preserving approaches: one uses encrypted attributes, while the other uses ZK proofs.
    
*   Lastly, for my project I had my AI agent perform end-to-end testing of the client app while streaming nine AWS CloudTrail sources to validate both front-end and back-end functionality at the same time. And then it wrote a report. These are the times we live in.
    
    [Subscribe](https://paragraph.com/@w3sb/subscribe)
    

Insightful
==========

**Deep Dive into Hyperliquid's Architecture**

QuillAudits examines Hyperliquid's architecture beyond its headline perpetuals exchange, analyzing the security surface of its custom L1 validator consensus, HIP-1 spot token standard, and native vault mechanics. The post identifies validator key management, oracle manipulation in thin spot markets, and cross-margin liquidation cascades as the three most significant risk vectors for a protocol whose institutional adoption trajectory demands enterprise-grade security scrutiny. ([QuillAudits](https://www.quillaudits.com/blog/blockchain/hyperliquid-security-beyond-orderbooks))

**Threat Modeling for Canton-Based Applications**

> Canton with Daml provides a distributed ledger protocol for privacy-preserving, multi-party workflows, with smart contracts that define business logic and authorization rules.

Halborn delivers a threat modeling guide for enterprise blockchain applications built on the Canton protocol a privacy-preserving distributed ledger used by financial institutions. The post maps Canton's unique privacy guarantees and sub-transaction model against standard threat modeling frameworks, identifying trust boundary mismatches, participant authorization flaws, and off-ledger component compromise as the highest-priority risk categories for development teams building regulated financial infrastructure on Canton. ([Halborn](https://www.halborn.com/blog/post/threat-modeling-for-canton-based-applications))

**Infostealers: The Session Replay Kill Chain**

Paul at Cantina maps the full attack chain from initial infostealer infection through stolen browser session token replay to complete cloud identity takeover. He demonstrates how attackers bypass MFA entirely by replaying authenticated sessions rather than compromising credentials. The post provides detection signals, automated revocation playbooks, and architectural controls for breaking the chain at each stage before an attacker achieves persistent cloud access. ([Cantina](https://cantina.xyz/blog/infostealers-session-replay-cloud-takeover))

**Blockchain Security's Challenges: From Reactive to Systemic**

Nethermind Security argues that the blockchain security industry has hit a structural ceiling on reactive audit-based defenses, and that meaningful loss reduction requires systemic shifts: formal verification at scale, continuous monitoring as a standard post-deployment requirement, and incident response infrastructure built before exploits occur rather than assembled under fire. ([Nethermind](https://www.nethermind.io/blog/blockchain-security-strategic-challenges-now-and-ahead))

**OnboardMe: Execution Flow Viewer for Solidity Smart Contracts**

The infosec-us-team releases OnboardMe, an experimental open-source tool that replaces multi-file IDE navigation with a single scrollable execution flow view per smart contract entry point. It displays every internal function call, state variable read/write, and access control check on `msg.sender` in one unified panel. Built with Slither and Python, it supports both local Foundry projects and deployed contracts across 50+ chains via a local web UI or CLI, with a fully keyboard-centric workflow. ([infosec-us-team on GitHub](https://github.com/infosec-us-team/onboardme))

Companies in the news
=====================

**Lit Protocol v3 "Chipotle" is for the AI Agent Era**

Team Lit announces Chipotle, a ground-up architectural rebuild of Lit Protocol that replaces multi-node threshold cryptography with single-machine TEE execution and moves key management fully on-chain, delivering programmable signing and encryption through a standard REST API instead of requiring an SDK. The result is dramatically lower latency, lower cost, and native accessibility for AI agents, curl commands, and any HTTP-capable runtime via a pay-per-request model using $LITKEY on Base. ([Lit Protocol](https://spark.litprotocol.com/introducing-lit-protocol-v3-chipotle/))

Gimme the loot
==============

**$50M Gone in One Bad Swap: CoWSwap Solver Picks a $73K Pool**

Rekt.news covers the incident in which Aave's frontend routed a $50M AAVE liquidation through CoWSwap, where a solver selected a $73,000 liquidity pool for the trade, resulting in catastrophic price impact that returned only 327 AAVE. Every warning fired, every contract functioned as designed, and MEV bots cleaned up the remainder the next block. A full fee refund is planned, but the event exposes a structural gap in how DEX aggregators handle edge-case trade sizes. ([Rekt](https://rekt.news/price-impact-kills)) and more from ([Halborn](https://www.halborn.com/blog/post/explained-crypto-whale-loses-50-million-in-flawed-swap-march-2026))

**Venus Protocol's Fourth Exploit: Nine Months in the Making**

Rekt.news reports that an attacker spent nine months methodically accumulating THE tokens on Venus Protocol, eventually reaching 3.67× the supply cap by bypassing the deposit mechanism with direct contract transfers. Then pumped THE token's TWAP price from $0.27 to $0.53 through illiquid on-chain pools. This enabled the attacker to borrow $3.7M across BTC, CAKE, and BNB, leaving $2.15M in bad debt on a protocol now rekt four times in five years. ([Rekt](https://rekt.news/venus-protocol-rekt4))

[SlowMist stats this week](https://hacked.slowmist.io/statistics/?c=all&d=2026)
-------------------------------------------------------------------------------

Total 2026 hack events: 38

The total amount of money lost this year: $119,826,414

![](https://storage.googleapis.com/papyrus_images/dc2b87ca6b23bb0770221735966f37ab078491d8faae61031ed4f84fb6680951.png)

We must have regulations
========================

**SEC and CFTC Publish Joint Interpretation on Crypto Assets**

On March 17, 2026, the SEC issued a Commission interpretation joined by the CFTC on how federal securities and commodity law apply to crypto assets and related activity. It covers airdrops, protocol mining and staking, wrapping non-security assets, how a non-security token can enter or leave an investment-contract analysis, and a taxonomy for digital commodities, collectibles, tools, stablecoins, and digital securities. Public statements stress that most crypto assets are not themselves securities and treat the document as interim clarity while Congress works on market-structure law. ([SEC](https://www.sec.gov/newsroom/press-releases/2026-30-sec-clarifies-application-federal-securities-laws-crypto-assets))

Check out the [All-In Podcast](https://allin.com/) with SEC's Paul Atkins and CFTC's Michael Selig for more details on how the agencies are working together for the future of finance.

[![](https://paragraph.com/editor/youtube/play.png)](https://www.youtube.com/watch?v=el6ObB60Fb4)

  

**U.S. Treasury Lays Out a Blueprint for Fighting Illicit Crypto**

The U.S. Department of Treasury's mandated GENIUS Act report identifies AI, digital identity, blockchain analytics, and APIs as the four priority technologies financial institutions should deploy to counter money laundering, DPRK theft, ransomware, and sanctions evasion, with $9B in reported 2024 fraud losses and $2.8B in DPRK digital asset theft since 2024 framing the urgency. Key legislative asks include a DeFi-specific AML/CFT actor classification framework and a novel "hold law" granting institutions a safe harbor to temporarily freeze suspected illicit digital assets pending investigation. ([US Treasury Dept](https://home.treasury.gov/system/files/246/GENIUS-Act-Illicit-Finance-Innovation-Congressional-Report-March-2026.pdf))

**The 2026 Regulatory Map Every DeFi Team Needs**

The DuelDuck Research Team publishes a comprehensive 2026 regulatory navigator mapping the simultaneous enforcement of the EU's MiCA frameworkagainst the US post-Gensler reset, where the GENIUS Act has delivered the first federal stablecoin framework and the CLARITY Act's Senate passage would finally resolve SEC/CFTC jurisdictional ambiguity. USDT remains MiCA non-compliant, fragmenting EU liquidity toward USDC, while DeFi protocols technically escape CASP classification only if they satisfy all three of MiCA Recital 22's unresolved "full decentralization" criteria — no legal entity as counterparty, no governance token-driven control, and no centralized front-end interface. ([Dual Duck](https://duelduck.com/blog/crypto-regulation-in-2026-navigating-mica-and-the-new-sec-landscape))

**The Global Fraud Summit 2026**

Chainalysis reports on the Global Fraud Summit 2026, where representatives from 40+ governments and international organizations convened to address the fragmented, jurisdiction-siloed approach to fighting large-scale fraud networks. The summit produced a joint declaration calling for shared intelligence infrastructure, cross-border asset recovery coordination, and mandatory blockchain analytics integration into national AML/CTF frameworks with crypto fraud networks explicitly named as a primary target. ([Chainalysis](https://www.chainalysis.com/blog/global-fraud-summit-2026/))

The CLARITY Tracker
-------------------

We are flatlining here.

[![](https://storage.googleapis.com/papyrus_images/1669fc4d1aa78e423b489f8d840383bcec3757e534677d4510f372612173ac45.png)](https://polymarket.com/event/clarity-act-signed-into-law-in-2026#DhkwEr04)

[Polymarket](https://polymarket.com/event/clarity-act-signed-into-law-in-2026#DhkwEr04)

Research corner
===============

**CONFETTY: Attribute-based Encryption Confidentiality**

Kryston et al. describe an open-source web platform for process-aware systems on public chains: contracts enforce public interactions while attribute-based encryption protects sensitive fields, mixing transparency with confidentiality. ([arXiv](https://arxiv.org/abs/2603.13900))

**Grant, Verify, Revoke: A Privacy-Preserving Compliance Pattern**

Supriya Khadka and Sanchari Das present a user-centric design pattern for regulated on-chain services that eliminates the binary choice between full identity disclosure to centralized intermediaries and total exclusion from regulated DeFi. The proposed three-phase pattern: grant selective credentials, verify on-chain without revealing underlying documents, and revoke attestations without platform dependency. The work draws on verifiable credentials and zero-knowledge proofs to support AML/KYC compliance without creating permanent on-chain identity links. ([arXiv](https://arxiv.org/abs/2603.15721))

---

*Originally published on [W3SB](https://paragraph.com/@w3sb/0x25-web3-security-bulletin)*
