# 0x9 Web3 Security Bulletin

*Crypto and web3 security insights, including tools, hacks, and regulations. *

By [W3SB](https://paragraph.com/@w3sb) · 2025-11-28

web3, crypto, security, cybersecurity, regulations, hacks, exploits

---

Insightful
==========

**Preparing Crypto for the Quantum Security Shift**

Chainalysis surveys the impact of quantum computing on today’s cryptography, explaining which blockchain primitives are at risk and what post-quantum migration could look like. The article emphasizes early inventory, risk mapping, and standards watching as core steps for exchanges and protocols planning long-term resilience. ([Chainalysis](https://www.chainalysis.com/blog/quantum-computing-crypto-security/))

**Intent Bridges: Where Value Leaks in Cross-Chain Designs**

Cantina analyzes “intent bridges,” showing how solver incentives, replay assumptions, and settlement paths can leak value or open new attack surfaces. The article argues for explicit threat models, robust validation of intents, and careful economic design to avoid transfers becoming exploitable cross-domain arbitrage engines. ([Cantina](https://cantina.xyz/blog/intent-bridge-security-failures))

**Cardano Blockchain Suffers Major Chain Split After Bug Exploitation**

On November 21, 2025, Cardano mainnet experienced a chain partition triggered by a malformed delegation transaction exploiting a deserialization vulnerability dating to 2022. The split created two divergent chains until Stake Pool Operators upgraded to node version 10.5.3, causing the valid chain to overtake the poisoned one. No user funds were compromised; retail wallets remained unaffected. Authorities are investigating the incident as a potential cyberattack, with Intersect planning a full retrospective to strengthen future QA processes. ([Intersect](https://intersectmbo.org/news/incident-report-network-partition-analysis-and-resolution-strategy))

**Vulnerabilities Disclosed in Widely-Used Elliptic JavaScript Library**

Trail of Bits publicly disclosed two vulnerabilities in the elliptic JavaScript library, which handles elliptic curve cryptography for over 10 million weekly downloads. The flaws, discovered using Wycheproof test vectors, stem from missing modular reductions and length checks that could enable signature forgery or prevent valid signature verification. One vulnerability remains unpatched despite a 90-day disclosure window ending in October 2024. ([Trail of Bits](https://blog.trailofbits.com/2025/11/18/we-found-cryptography-bugs-in-the-elliptic-library-using-wycheproof/))

**Chainalysis Tracks Russian Ransomware and Drug Crypto Flows**

Chainalysis details coordinated U.S., U.K., and Australian actions against Russian cybercrime infrastructure supporting global ransomware, alongside sanctions on crypto money-laundering networks tied to drug trafficking. The piece highlights how on-chain tracing supports sanctions, seizures, and infrastructure takedowns across multiple jurisdictions. ([Chainalysis](https://www.chainalysis.com/blog/ofac-targets-russian-cybercrime-infrastructure-ransomware-november-2025/))

Gimme the loot
==============

_A few notable hacks from_ [_Rekt_](https://rekt.news/) _and other sources…_

**Stick 'Em Up - San Francisco Home Invasion**

A November 2025 home invasion in San Francisco's Mission District highlights escalating violence targeting cryptocurrency holders. The incident, one of several crypto-related robberies in the Bay Area, reflects criminals' focus on wealthy digital-asset owners perceived as attractive targets. Law enforcement and community advocates warn that the intersection of cryptocurrency wealth and personal security vulnerabilities creates conditions for targeted violent crime, prompting calls for enhanced awareness and protective measures among crypto-asset holders. ([SF Standard](https://sfstandard.com/2025/11/25/mission-home-invasion-highlights-danger-crypto-related-violence/))

**Aerodrome Finance DNS Hijack Exposes Front-End Vulnerabilities**

On November 22, Aerodrome Finance, the largest DEX on Base with $400 million in TVL, suffered a DNS hijacking attack that compromised its centralized domains. The attackers redirected users to phishing sites designed to steal funds through malicious wallet prompts. While the smart contracts remained secure, the incident underscores the persistent risks of centralized web infrastructure in DeFi. Users were directed to decentralized ENS mirrors as safe alternatives. ([Halborn](https://www.halborn.com/blog/post/explained-the-aerodrome-finance-hack-november-2025))

**Libra Rug Pull Sees $61.5M Moved After Judge Unfreezes Funds**

On November 24, Rekt News reported that the Libra project converted $61.5 million USDC to SOL after a judge ordered the unfreezing of funds. The case spans two countries with zero arrests despite millions extracted across four separate crypto scams. The incident highlights the ongoing challenge of enforcement speed versus blockchain transaction speed in recovering stolen assets. ([Rekt](https://rekt.news/libra2))

**GANA Payment Suffers $3.1 Million Exploit via Private Key Leak**

The BSC-based payment platform GANA Payment was drained of $3.1 million on November 20, just nine days after launch. Attackers exploited a leaked owner private key combined with an EIP-7702 delegation vulnerability to manipulate the staking contract's reward mechanism. The stolen funds were laundered through Tornado Cash across both BSC and Ethereum networks. The token's value collapsed by over 90% following the breach. ([Halborn](https://www.halborn.com/blog/post/explained-the-gana-payment-hack-november-2025)) ([Rekt](https://rekt.news/gana-payment-rekt))

[SlowMist stats this week](https://hacked.slowmist.io/statistics/?c=all&d=2025)
-------------------------------------------------------------------------------

Total 2025 hack events: 184

The total amount of money lost by blockchain hackers is about

$2,898,299,055

We must have regulations
========================

**Cyfrin Explains MiCA for EU Crypto Builders**

Cyfrin unpacks the EU’s MiCA regime, outlining licensing requirements, timelines, enforcement risks, and how rules differ across stablecoins, DeFi, and NFTs. The article positions MiCA as both a compliance challenge and an opportunity for serious projects to signal credibility ahead of broader institutional adoption. ([Cyfrin](https://www.cyfrin.io/blog/mica-regulation-explained-a-guide-to-eu-crypto-compliance))

**November 2025 Regulatory Tightening Puts Web3 Security on Notice**

Cantina outlines a packed 2024–2027 regulatory roadmap, with ISO 27001:2022, PCI DSS v4.0, DORA, NIS2, NYDFS Part 500, SEC cyber rules, CIRCIA, MiCA, and the EU AI Act all raising the bar for crypto and fintech security. The article argues teams should stop chasing each rule separately and instead adopt a single, MDR-centric operating model tuned for Web3 to stay compliant and audit-ready. ([Cantina](https://cantina.xyz/blog/nov-2025-compliance-security-update))

**SEC Removes Crypto from 2026 Regulatory Priorities**

On November 17, 2025, the Securities and Exchange Commission's Division of Examinations released its 2026 examination priorities, and the document contains no mention of crypto, digital assets, or blockchain—marking a significant departure from previous years. The absence of cryptocurrency from this official document represents the first time since 2021 that digital assets and crypto have been removed from the priorities. ([SEC](https://www.sec.gov/newsroom/press-releases/2025-132-sec-division-examinations-announces-2026-priorities))

**And While Crypto isn't a "Priority" Regulatory Clarity is Underworks**

SEC Chairman Paul Atkins unveiled the next phase of Project Crypto in November remarks, signaling a shift from incremental staff guidance toward formal rulemaking. The agenda includes a "token taxonomy" distinguishing securities from non-securities, tailored exemptions for crypto distributions, "Regulation Crypto" proposals, and modernized market-structure rules. Expected 2026 deliverables include comprehensive asset classification frameworks and exchange trading standards, positioning the SEC to establish clearer regulatory guardrails for digital assets. ([Sidley](https://www.sidley.com/en/insights/newsupdates/2025/11/breaking-down-project-crypto-sec-chairman-atkins-outlines-next-phase-of-digital-asset-oversight))

**FSB Peer Review Exposes Uneven Crypto Implementation Across Jurisdictions**

The Financial Stability Board's October 2025 thematic peer review revealed significant gaps and inconsistencies in how jurisdictions implement its 2023 global crypto-asset framework. While crypto-asset regulation advanced, stablecoin oversight lags considerably. The report warns that incomplete, uneven implementation creates regulatory arbitrage opportunities and complicates oversight of the inherently global market, urging FSB members to prioritize full and consistent implementation. ([FSB](https://www.fsb.org/2025/10/fsb-finds-significant-gaps-and-inconsistencies-in-implementation-of-crypto-and-stablecoin-recommendations/))

**IOSCO Framework Progress on Tokenization Amid Ongoing Coordination Gaps**

IOSCO's thematic review of crypto and digital asset framework implementation, released alongside the FSB's October 2025 report, assessed how securities regulators globally adopt tokenization standards. The review identifies progress in fixed-income tokenization and regulatory coordination mechanisms, while highlighting remaining gaps in supervision and cross-border clarity. The complementary FSB-IOSCO findings underscore the need for harmonized approaches as digital finance infrastructure evolves. ([IOSCO](https://www.iosco.org/library/pubdocs/pdf/IOSCOPD809.pdf))

Research corner
===============

**ConneX Automates Cross-Chain Transaction Pairing for Enhanced Bridge Security Analysis**

Researchers from Nanjing University and Singapore Management University published ConneX, a novel system that automatically identifies corresponding transaction pairs across cross-chain bridges using LLM-assisted semantic analysis. The tool addresses critical opacity in cross-chain fund tracing by matching transactions through semantic quintuples (destination, chain, amount, asset type, timestamp), achieving 0.9746 F1 score accuracy. Successfully deployed on five major bridge platforms, ConneX traced $1 million in illicit funds from the Bybit hack, demonstrating practical utility for anti-money laundering and security analysis in Web3 ecosystems. ([arXiv](https://arxiv.org/pdf/2511.01393))

---

*Originally published on [W3SB](https://paragraph.com/@w3sb/0x9-web3-security-bulletin)*
