# 0x26 Web3 Security Bulletin

*Crypto and web3 security insights, including tools, hacks, and regulations. *

By [W3SB](https://paragraph.com/@w3sb) · 2026-03-28

crypto, hacks, cybersecurity, security, regulations, ai, agentic

---

**TL;DR**

*   "These findings challenge the narrative that fully automated AI auditing is imminent." Dive into a re-evaluation of OpenAI's EVMBench results.
    
*   A JD Supra analysis of last week's SEC-CFTC joint guidance on crypto notes the release carries no force of law, is not binding in courts, and may be revised or withdrawn without formal rule-making; ouch.
    
*   Trail of Bits demonstrates how applying dimensional analysis, the same unit consistency checking used in physics, to DeFi smart contract arithmetic catches a class of bugs that traditional static analysis tools systematically miss.
    
*   Chainalysis Solana dev platform shifts compliance from a post-launch operational add-on to a native development primitive.
    
*   Going the extra mile: Hacken's guide to running OpenClaw AI agents on Aleph Cloud's decentralized TEE infrastructure.
    
*   Over $70 million in deal news with OmniPact, Ironlight and others.
    
*   Lastly, I've 10x'ed my dev skill skills with Cursor and a small agent swarm. But they are working faster than I am. For those building agentic systems the struggle is real. Check out Nico's ([Nicolas Lidzborski](https://www.linkedin.com/in/nicolaslidzborski/)) [unprompted presentation](https://www.linkedin.com/posts/nicolaslidzborski_home-activity-7435090475285561344-qZdH?utm_source=share&utm_medium=member_desktop&rcm=ACoAAABNkw8B-lt2_tPUrVpPVltahUhuNRnHEPI) covering a Plan, Validate, and Execute pattern for high-stakes actions.
    

[Subscribe](https://paragraph.com/@w3sb/subscribe)

Insightful
==========

**Trail of Bits Releases Dimensional Analysis Claude Plugin**

Benjamin Samuels at Trail of Bits releases a Claude MCP plugin that automates dimensional type annotation for Solidity and DeFi code, achieving 93% recall against a benchmark dataset of real audit findings versus 50% for baseline LLM prompts without the plugin. The tool integrates directly into Claude's reasoning pipeline, annotating code with inferred dimensional types and flagging mismatches as structured findings, enabling auditors to apply dimensional analysis at the speed of static tooling rather than manual review, while retaining human judgment for validation. ([Trail of Bits](https://blog.trailofbits.com/2026/03/25/try-our-new-dimensional-analysis-claude-plugin/))

**Hacken's Defense Guide for AI Agents Running on Aleph Cloud**

Hacken delivers a practitioner-grade hardening guide for OpenClaw AI agents deployed on Aleph Cloud's decentralized TEE infrastructure. They cover tool permission scoping, system prompt injection defense, output validation, memory isolation between agent sessions, and network egress controls that prevent compromised agents from exfiltrating data or executing unauthorized transactions. The guide is framed around a defense-in-depth philosophy specifically adapted for autonomous agents operating in decentralized compute environments where traditional cloud security controls are not available and the attack surface includes both the agent's reasoning process and its execution environment. ([Hacken](https://hacken.io/insights/openclaw-hardening/))

Companies in the news
=====================

**$1M Bug Bounty Targeting Web2 and Web3 Infrastructure**

Cantina announces the $1 million Paxos bug bounty program covering both on-chain smart contract infrastructure and off-chain Web2 systems including Paxos's custody, settlement, and stablecoin issuance platforms. The program represents a deliberate expansion of Paxos's security perimeter beyond smart contract scope to include the API gateways, authentication systems, and internal services that underpin regulated digital asset infrastructure, reflecting a broader industry recognition that the most material risks for institutional-grade protocols increasingly originate from Web2 attack surfaces rather than on-chain logic. ([Cantina](https://cantina.xyz/blog/announcing-the-1m-paxos-bug-bounty-program-on-cantina))

**Chainalysis Joins Solana Developer Platform**

Chainalysis announces its integration into the Solana developer platform, making its transaction screening and wallet risk scoring APIs natively accessible to all developers building applications on Solana without requiring separate enterprise contracts or compliance infrastructure. The integration means that dApps, wallets, and exchanges launching on Solana can embed AML/CFT screening at the point of wallet connection and transaction submission, a shift from compliance as a post-launch operational add-on to compliance as a native development primitive accessible from day one of deployment. ([Chainalysis](https://www.chainalysis.com/blog/solana-developer-platform-real-time-compliance/))

Gimme the loot
==============

**Solv Protocol: Double Mint via ERC-3525 Callback Path**

Taichi Audit describes an exploit on BitcoinReserveOffering where ERC-3525 mint callbacks let wrapped shares credit twice, inflating balances redeemed for underlying assets. Reported losses sit around single-digit millions USD. The case is a warning on wrapper contracts that mix callback-heavy token standards with vault accounting. ([Taichi Audit](https://taichiaudit.com/blog/solv-protocol-hack-analysis))

[SlowMist stats this week](https://hacked.slowmist.io/statistics/?c=all&d=2026)
-------------------------------------------------------------------------------

Total 2026 hack events: 39

The total amount of money lost this year: $119,826,414

![](https://storage.googleapis.com/papyrus_images/73edb87b0aefbb74e16ebebe3010cd9ae29e88d5a1358b473c0f22453643f2d9.png)

We must have regulations
========================

**SEC-CFTC Joint Guidance Analysis**

JD Supra has a detailed practitioner analysis of the March 17, 2026 SEC-CFTC joint interpretive release, which establishes five classification categories for crypto assets: digital commodities (including Bitcoin, Ethereum, Solana, XRP, Cardano, and seven others), digital collectibles (NFTs, meme coins), digital tools (utility tokens, credentials), stablecoins, and digital securities. The guidance supersedes the SEC's 2019 Howey framework, confirms that mining, staking, wrapped tokens, and standard airdrops are not securities transactions, and clarifies that a non-security crypto asset can still be sold subject to an investment contract if the issuer makes forward-looking promises of essential managerial effort. The review cautions market participants that the release carries no force of law, is not binding on courts, and may be revised or withdrawn without formal rulemaking, leaving meaningful residual legal uncertainty until Congress codifies the framework through market structure legislation. ([JD Supra](https://www.jdsupra.com/legalnews/sec-and-cftc-issue-landmark-joint-1362567/))

**Hong Kong to Issue Its First Licensed Stablecoin Approvals**

The Hong Kong Monetary Authority is preparing to grant its first stablecoin issuer licenses under a regulatory framework enacted on August 1, 2025, with between 36 and 77 applications filed late last year and Financial Secretary Paul Chan confirming deployment focus on fiat-referenced stablecoins pegged to the Hong Kong Dollar and other major currencies. The HKMA's framework ranks among the most demanding globally, requiring a minimum HK$25 million in paid-up capital, segregated high-quality reserves, and at-par redemptions within one business day, with HSBC and Standard Chartered understood to lead the first wave of approvals. ([Coinfomania](https://coinfomania.com/hsbc-and-standard-chartered-eye-hong-kong-stablecoin-licenses/))

**The CLARITY Tracker**
-----------------------

![](https://storage.googleapis.com/papyrus_images/12609ae479763f0ef80055eaf58343a20736a847e27dcd654e7cc6d121d6caf2.png)

[Polymarket](https://polymarket.com/event/clarity-act-signed-into-law-in-2026)

VCs & funding
=============

**OmniPact Raises $50 Million**

Alex Johnson, Co-founder and CEO of OmniPact, announces a $50 million private funding round backed by an undisclosed consortium of institutional investors and family offices. Proceeds will be directed at finalizing security audits of core smart contracts, launching a testnet, building out cross-chain infrastructure, and expanding engineering capacity for real-world asset and AI agent transaction support. Founded in 2024, OmniPact replaces centralized intermediaries in peer-to-peer transactions of physical and digital assets by using smart contracts as on-chain guarantors, combining algorithmic custody with a decentralized arbitration module and on-chain reputation systems. ([Unchainedcrypto](https://unchainedcrypto.com/press-release/omnipact-secures-50-million-to-advance-trust-infrastructure/))

**Ironlight Group Closes $21 Million Series A**

Ironlight Group, an Austin-based fintech operating the first FINRA-approved Alternative Trading System with atomic on-chain settlement for tokenized securities, has closed a $21 million Series A backed by senior Wall Street executives including former TD Bank President and CEO Greg Braca, the Sei Development Foundation, and Laidlaw Private Equity. Proceeds will be used to scale Ironlight Markets' SEC Regulation ATS-compliant trading and distribution platform alongside Ironlight Technologies' settlement infrastructure, targeting tokenized private equity, structured products, fixed income, private credit, and real estate. ([PR Newswire](https://www.prnewswire.com/news-releases/ironlight-group-raises-21-million-series-a-to-expand-infrastructure-for-tokenized-securities-302714116.html))

**Utexo $7.5M Raise to Bring Native USDT Settlement to BTC**

Utexo, a Bitcoin-native execution and settlement infrastructure provider, has closed a $7.5 million seed round co-led by Tether, Big Brain Holdings, and Portal Ventures, with participation from Franklin Templeton, Maven11 Capital, Fulgur Ventures, and others. The platform combines Lightning Network's instant execution with the RGB protocol's privacy-preserving asset issuance layer, exposing both through a single API that allows payment operators to route USDT transactions over Bitcoin-native rails. It provides predictable fees settled in USDT, sub-second finality, and fully encrypted on-chain transactions that expose no counterparty or wallet address data. CEO Paolo Ardoino characterized the raise as addressing infrastructure that "has been missing" to make Bitcoin a viable production-grade settlement rail for dollar-denominated payments at scale. ([Chainwire](https://chainwire.org/2026/03/06/utexo-raises-7-5m-led-by-tether-to-launch-native-usdt-settlements-on-bitcoin/))

Research corner
===============

**Re-Evaluating EVMBench**

Researchers re-ran EVMBench-style evaluations across 26 agent configurations and four model families. Vulnerability-detection rankings moved when the dataset slice or settings changed. On real incidents, no agent completed end-to-end exploitation in the study’s setup even when raw detection rates looked high, which pushes back on treating autonomous auditing as production-ready. The authors want benchmarks tied more closely to exploitability and incident replay. ([arXiv](https://arxiv.org/abs/2603.10795))

**Where Automated Solidity Tools Fail**

A mixed-methods study benchmarks six widely used smart contract security analyzers on 653 real contracts. It reports high false positives (up to about 33%), a wide F1 range, and runtimes over ten minutes per contract in some cases. The paper argues that measurable performance deficiencies directly erode developer trust, and calls for precision improvements, better explainability, and usability redesigns as prerequisites for broader deployment in production security workflows. ([arXiv](https://arxiv.org/abs/2603.00890))

---

*Originally published on [W3SB](https://paragraph.com/@w3sb/0x26-web3-security-bulletin)*
