<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>W3SB</title>
        <link>https://paragraph.com/@w3sb</link>
        <description>Crypto and web3 security insights, including tools, hacks, and regulations.</description>
        <lastBuildDate>Sat, 05 Sep 2026 23:12:38 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <image>
            <title>W3SB</title>
            <url>https://storage.googleapis.com/papyrus_images/2d636c4823f008bfbeba45f964abfea7ddf314da1d7f3cf57fc0ce0e19a4278b.jpg</url>
            <link>https://paragraph.com/@w3sb</link>
        </image>
        <copyright>All rights reserved</copyright>
        <item>
            <title><![CDATA[0x49 Web3 Security Bulletin]]></title>
            <link>https://paragraph.com/@w3sb/0x49-web3-security-bulletin</link>
            <guid>OBI6ujXBgf4o88TogBdV</guid>
            <pubDate>Sat, 05 Sep 2026 12:20:33 GMT</pubDate>
            <description><![CDATA[Intelligence for Web3, digital asset infrastructure, and the capital shaping the industry.]]></description>
            <content:encoded><![CDATA[<p>TL;DR</p><ul><li><p><strong>Trends &amp; Markets:</strong> Browser extensions are being weaponized as wallet drainers, tokenized assets face weekend pricing risks, and Chainalysis is expanding coverage to include support for HyperEVM.</p></li><li><p><strong>Exploits &amp; Incidents:</strong> A $75M exploit hit Tectonic via illiquid collateral manipulation, and an unchecked integer cast in Notional Finance led to a $1.73M drain.</p></li><li><p><strong>Policy &amp; Regulation:</strong> Russia's new comprehensive cryptocurrency regulatory regime has officially taken effect.</p></li><li><p><strong>Capital Allocation:</strong> <strong>Firelight</strong> raised $8M to build decentralized insurance for DeFi, and YC's <strong>Verdict Machine</strong> launched AI-native cybersecurity for institutional digital assets.</p></li><li><p><strong>Applied Research:</strong> Recent papers introduce a dataset mapping smart-contract CVEs to code, a graph-based blockchain screening system, and LLM-generated vulnerability benchmarks.</p></li></ul><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></p><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis</h1><p><strong>Nineteen Browser Extensions Shipped a Wallet Drainer</strong></p><p>Socket’s Karlo Zanki tracks 18 Chrome extensions and one Edge add-on that are capable of stealing browser information, account sessions, credentials, and cryptocurrency-related data. Several legitimate extensions were reportedly acquired and later updated with modular malware targeting services including Coinbase, Binance, Kraken, OKX, MetaMask, and others. The campaign demonstrates how browser-extension supply chains can bypass assumptions users make about previously trusted software and gain privileged access to authenticated sessions. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://socket.dev/blog/chrome-edge-extension-wallet-drainer">Socket</a>)</p><p><strong>Weekend Oracle Gaps Create Risk for Tokenized Stocks</strong></p><p>The QuillAudits team examines a mismatch between 24/7 tokenized-equity trading and price feeds that still depend on traditional market hours. For example Coinbase-issued tokenized stocks can continue moving on Base while underlying reference prices may remain frozen over weekends, potentially leaving DeFi protocols with stale collateral valuations. The analysis argues that bringing equities onchain requires risk models designed around both blockchain-native markets and the operating schedules of traditional finance. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.quillaudits.com/blog/rwa/coinbase-chainlink-oracle-risk">Quill Audits</a>)</p><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements</h1><p><strong>Chainalysis Adds HyperEVM Monitoring</strong></p><p>Chainalysis announces support for HyperEVM, extending compliance and investigative tooling to Hyperliquid’s EVM-compatible environment. The integration automatically covers ERC-20 and ERC-721 assets and makes HyperEVM activity available through KYT, address screening, and Reactor. For exchanges and other regulated businesses interacting with the ecosystem, the release expands transaction monitoring and tracing without requiring individual integrations for each token. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/chainalysis-supports-hyperevm-with-automatic-token-support/">Chainalysis</a>)</p><p><strong>Non-Financial Companies Need More Than a Stablecoin Wallet</strong></p><p>Itai Turbahn argues that stablecoin adoption by mainstream companies creates requirements far beyond simply holding and transferring tokens. Enterprises need screening, asset conversion, routing, retries, reconciliation, policy enforcement, and multi-chain connectivity behind the wallet interface. The article frames wallet infrastructure as an operational abstraction layer that lets non-financial companies use blockchain rails without rebuilding treasury, payments, and compliance systems around blockchain-specific mechanics. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fireblocks.com/blog/stablecoin-wallet-non-financial-companies">Fireblocks</a>)</p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents</h1><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>2026 hacks: 249</p><p>Total amount lost in 2026: $1,303,451,456</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/6afd7350c5af8ad114c6bac57c35582bfe3cee6e5734fd7bef154b81d2730065.png" alt="" class="image-node embed"></figure><p><strong>Tectonic’s Illiquid Token Becomes a $75M Attack Vector</strong></p><p>Rob Behnke examines the Tectonic exploit on Cronos, where an attacker drove the thinly traded TONIC token roughly 100× higher before using the inflated asset as collateral across lending markets. Approximately $75 million was borrowed, although only a fraction escaped before Cronos validators halted the network and rolled back state. The incident demonstrates how low-liquidity collateral can turn market manipulation into a protocol-wide solvency threat. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.halborn.com/blog/post/explained-the-tectonic-hack-august-2026">Halborn</a>)</p><p><strong>Notional’s Integer Cast Turns $1.73M of Debt Into Zero</strong></p><p>Anmol explains how an unchecked uint128 conversion in Notional Finance caused debt equal to 2^128 to truncate to zero during a solvency check. The attacker fabricated fCash claims, withdrew roughly $1.73M in DAI and USDC, converted the proceeds to ETH, and routed funds through Tornado Cash. The incident highlights how seemingly simple narrowing casts can undermine an otherwise complex financial risk model. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.quillaudits.com/blog/hack-analysis/notional-finance-integer-overflow-exploit">Quill Audits</a>)</p><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation</h1><p><strong>Russia’s Comprehensive Crypto Regime Takes Effect</strong></p><p>Russia’s new cryptocurrency framework entered into force September 1, bringing crypto trading into a regulated structure overseen by the Bank of Russia. Trading must move through authorized intermediaries, while non-qualified retail investors face knowledge-testing requirements and annual purchase limits. The framework continues Russia’s prohibition on domestic cryptocurrency payments while creating regulated pathways for investment and certain international uses. Existing market participants have a transition period extending into 2027. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://theindustryspread.com/russia-crypto-market-law-1194918-8-september-1/">The Industry Spread</a>)</p><h1 id="h-capital-allocation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Capital Allocation</h1><p><strong>Firelight Raises $8M to Offset DeFi Risks</strong></p><p>Firelight closed an $8M seed led by Gumi Cryptos Capital, with Maven 11, Metalayer, Joint Effects, and Tribe Capital.</p><blockquote><p>Firelight is a decentralized cover protocol that protects onchain capital against protocol, smart contract and economic risks.</p></blockquote><p>The team is starting with XRP first, then bitcoin and XLM. Flare is named as a backer; staked XRP is the initial capital. The protocol and first integrations are scheduled for September. Claims would be checked onchain by GFX Labs, Hypernative, Credora, Native, and Cyfrin. CEO Anthony DeMartino previously ran Coinbase Risk Strategies; CSO Connor Sullivan came from Fireblocks. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://firelight.finance/articles/firelight-protocol-raises-8-million-to-build-cover-infrastructure-for-defi">Firelight</a>)</p><p><strong>Verdict Machine Launches AI-Native Security for Institutional Crypto</strong></p><p>Y Combinator introduced <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://verdictmachine.com/">Verdict Machine</a>, an S26 startup building AI-powered cybersecurity for financial institutions managing digital assets. Founded by former Check Point blockchain-security leaders, the company maps an institution’s onchain environment, assesses cyber risk, generates tailored controls, and evaluates transactions before execution. Verdict Machine says it already has POCs with asset managers and digital-asset infrastructure providers and is being evaluated by major banks, positioning it as a new entrant in institutional onchain security. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.ycombinator.com/companies/verdict-machine">Y Combinator</a>)</p><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research</h1><p><strong>A New Dataset Maps Smart-Contract CVEs to Real Code</strong></p><p>Monika di Angelo and Gernot Salzer introduce CVE-Smart-Contracts, a curated dataset connecting hundreds of CVE records with deployed Ethereum contracts and, where available, vulnerability labels and source locations. The collection includes source code and bytecode and is intended to support reproducible evaluation of analysis and repair tools. Importantly, the dataset preserves CVE claims rather than treating every original vulnerability report as independently revalidated ground truth. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2609.01186">arXiv</a>)</p><p><strong>Blockchain Screening Without Known Bad-Address Labels</strong></p><p>Yury Korolev presents a graph-based blockchain screening system operating across 835M addresses and 15.8B transaction edges on five EVM chains. Instead of relying solely on sanctions lists or known labels, the model scores addresses from their position in the transaction graph and transfers detection capabilities to previously unlabeled chains. Tests on Base, Arbitrum, and Gnosis show strong recall, although adversarial simulations also identify blind spots against synthesized behavior. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2609.03036">arXiv</a>)</p><p><strong>LLMs Generate Smart-Contract Vulnerabilities for Security Testing</strong></p><p>Luca Migliaccio, Roberto Natella, Naghmeh Ivaki, Nuno Laranjeiro, and Marco Vieira explore using LLMs to automatically inject vulnerabilities into Solidity contracts, creating ground-truth datasets for evaluating security tools. Nearly 1,000 variants targeting 49 OpenSCV vulnerability classes produced 32 validated vulnerable contracts covering 25 classes. Testing three static analyzers against the dataset revealed complementary but incomplete detection coverage, suggesting LLM-generated vulnerabilities could expand security benchmarks despite significant reliability and scalability limitations. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2609.02624">arXiv</a>)</p>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>hacks</category>
            <category>security</category>
            <category>web3</category>
            <category>cybersecurity</category>
            <category>policy</category>
        </item>
        <item>
            <title><![CDATA[0x48 Web3 Security Bulletin ]]></title>
            <link>https://paragraph.com/@w3sb/0x48-web3-security-bulletin</link>
            <guid>XrJSF06HUqFWWDwGCdl6</guid>
            <pubDate>Fri, 28 Aug 2026 11:19:05 GMT</pubDate>
            <description><![CDATA[Intelligence for Web3, digital asset infrastructure, and the capital shaping the industry. ]]></description>
            <content:encoded><![CDATA[<p>TL;DR</p><ul><li><p><strong>Compliance &amp; Infrastructure</strong>: Research argues permissionless chains can meet AML requirements at the application layer, while Fireblocks details data sovereignty controls for EU institutions.</p></li><li><p><strong>Vulnerabilities &amp; Exploits</strong>: A Term Finance governance capture drained $8.5M, an expired Tornado Cash domain enabled a massive phishing campaign, and a supply-chain zero-day exposed Trezor customer data.</p></li><li><p><strong>Preventative Security</strong>: New tools are moving defense upstream, with Forta introducing pre-execution screening for OP Enterprise and ChainPatrol embedding phishing detection at the registrar level.</p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis</h1><p><strong>Permissionless Blockchains Can Meet Financial-Integrity Requirements</strong></p><p>Rebecca Rettig, Omid Malekan, and Michael Mosier argue that regulated financial institutions do not inherently need permissioned blockchains to satisfy AML, CFT, and sanctions obligations. The paper proposes placing compliance and risk-management controls at the application layer rather than attempting to control the underlying validator network. It also addresses concerns including illicit-actor exposure, transaction privacy, asset provenance, and regulatory auditability, presenting a framework for institutions seeking to use open blockchain infrastructure without abandoning financial-integrity controls. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=7343938&amp;utm_source=chatgpt.com">SSRN</a>)</p><p><strong>What the First 24 Hours After an Exploit Should Look Like</strong></p><p>Quantstamp lays out an incident-response checklist focused on the period when every block can increase losses. Immediate priorities include pausing affected functionality, contacting exchanges with attacker addresses, moving internal coordination away from potentially compromised channels, issuing a minimal public acknowledgment, and bringing in forensic tracing expertise. The broader message is operational: protocols need emergency authority, communications procedures, exchange contacts, and investigation capabilities established before an exploit starts. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://quantstamp.com/incident-response-guide">Quantstamp</a>)</p><p><strong>Verifying powdr’s zkVM Acceleration</strong></p><p>A zkVM can prove a program ran correctly without anyone re-running it, but the prover pays for every instruction. <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://powdr.org/">powdr</a> finds hot stretches of code and collapses them into one smaller circuit, the way a compiler fuses a loop. If that rewrite is too loose, a rollup could accept a fake state change. If it is too tight, an honest block might fail to prove. Certora’s tool compares the circuit before and after each rewrite. On Keccak and a Reth Ethereum-client trace it proved 99.0% and 98.7% of 6,627 checks, found no real mismatches, and caught one timestamp-overflow edge case that was not exploitable. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.certora.com/blog/formal-verification-powdr-autoprecompiles">Certora</a>)</p><p><strong>AI Is a Solidity Pair Programmer, Not a Security Architect</strong></p><p>Andrei Toma argues that AI assistants can accelerate Solidity development through scaffolding, tests, documentation, and implementation support, but their output inherits the same security risks as any other generated code. The recommended model keeps developers responsible for architecture and threat modeling while subjecting AI-generated contracts to manual review, testing, and verification. For smart contracts, productivity gains do not change the underlying requirement: every generated assumption involving money or authorization still needs independent validation. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.nethermind.io/blog/trust-but-verify-pair-programming-with-ai-for-secure-smart-contracts">Nethermind</a>)</p><p><strong>Stablecoin Freeze Keys Are a Neobank Dependency Risk</strong></p><p>Anmol notes that crypto neobanks are relying on stablecoin administrative powers they do not control, including freezing, minting, and contract upgrades. Reserve quality therefore captures only part of the risk. Teams should inventory the stablecoins underpinning customer balances and settlement, identify who controls privileged functions, and test what happens operationally if balances suddenly become non-transferable. The article reframes stablecoin administration as a concentration and business-continuity problem rather than merely a token or reserve-management issue. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://quillaudits.com">quillaudits.com</a>)</p><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements</h1><p><strong>Forta Brings Pre-Execution Screening to OP Enterprise</strong></p><p>Forta Firewall now has an <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://optimism.io/op-enterprise">OP Enterprise</a> transaction-screening option, with Kraken’s Ink becoming its first adopter. The integration places security evaluation directly in the sequencer path, allowing selected modules to examine transactions before block construction for risks such as sanctioned addresses, scams, and exploits. Forta says evaluations complete in under 10 milliseconds, while applications inherit the protection without contract or SDK changes. The model shifts security controls from post-execution detection toward preventative transaction admission. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.forta.org/blog/forta-firewall-on-op-enterprise-a-sequencer">Forta</a>)</p><p><strong>ChainPatrol Moves Phishing Detection Upstream to Registrars</strong></p><p>ChainPatrol Team reports that Realtime Register has embedded ChainPatrol intelligence directly into its Abuse Monitoring platform and made it available to resellers without additional cost. Early detections included a convincing fake wallet and cloned prediction-market site. More importantly, threat clustering allows registrars to identify related malicious domains and suspend infrastructure before campaigns mature, moving Web3 phishing defense upstream from individual wallets and users toward the domain-registration layer. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://chainpatrol.com/blog/realtime-register-chainpatrol-integration">ChainPatrol</a>)</p><p><strong>Fireblocks Details EU Data Sovereignty and Customer Key Control</strong></p><p>Ana Santillan addresses how European financial institutions should evaluate jurisdiction, signing authority, data residency, continuity, and vendor dependence in digital-asset infrastructure. Fireblocks says its EU SaaS environment operates across four European countries, while customers retain sole transaction-signing authority under both MPC and HSM deployment models. The article’s central security argument is architectural: regulatory or operational disruption affecting the service provider should not translate into unilateral provider access to customer private keys or digital assets. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fireblocks.com/blog/jurisdiction-data-sovereignty-eu-banks">Fireblocks</a>)</p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents</h1><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>2026 hacks: 241</p><p>Total amount lost in 2026: $1,215,897,597</p><p><strong>Phishing with an Expired Tornado Cash Domain</strong></p><p>Wu Blockchain reports that a user followed a bookmarked link to the old official tornado[.]cash domain and landed on a phishing frontend. The domain had expired after the team did not renew it under OFAC sanctions; attackers then registered it and stole deposit credentials. 1,010 ETH left within 12 hours. The same group has allegedly taken nearly 4,000 ETH this way over the past 12 months. A same-day Wu follow-up cites on-chain analyst Specter arguing the purported victim may himself be a threat actor and that the drained funds may be illicit. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/WuBlockchain/status/2090396627257503764">WuBlockchain on X</a>))</p><p><strong>Provenance Blockchain Bug</strong></p><p>A bug existed in Provenance Blockchain (Cosmos SDK) prior to v1.28.0. <code>AddAccess</code> treated a caller as admin if they controlled 100% of a marker’s circulating supply, but <code>accountControlsAllSupply</code> compared the bank balance to the marker struct’s stored supply, which stays 0 for non-fixed markers. Any zero-balance account could therefore grant itself admin, mint, and withdrawal permissions in two transactions. The attack in two transactions: grant admin, then mint or withdraw. At discovery, 82 mainnet markers were exploitable, including escrow holding about $500,000 of nhash. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://blog.trailofbits.com/2026/08/25/state-divergence-enables-unauthorized-access/">Trail of Bits</a>)</p><p><strong>Term Finance Governance Capture Drains $8.5M</strong></p><p>An attacker turned roughly half an ETH into effective control of Term Finance’s sparsely participated governance, securing about 91% of voting power in the ETH Meta Vault and total control across several USDC vaults. The resulting proposals disabled the delay mechanism, installed attacker-controlled strategies, and drained roughly 2,843 WETH and 1.68M USDC. The core Yearn-based vault code was not exploited; the failure was governance design combined with near-zero participation. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rekt.news/term-labs-rekt?utm_source=chatgpt.com">rekt</a>)</p><p><strong>Pendle's PT-reUSD Oracle was Misconfigured and Exploited</strong></p><p>kanveuler’s post reconstructs an Ethereum Morpho incident on the PT-reUSD-10DEC2026 / USDC and USDT markets. Wallet <code>0x854e…690d</code> spent 320,000 SY-reUSD across 11 <code>swapExactSyForYt</code> trades in nine minutes. That moved a 900-second Pendle TWAP. The Ojo wrapper takes the lower of that TWAP and a linear maturity discount, so a depressed Pendle price became the oracle. The oracle fell 51 bps at the last buy, then 277 bps as the window rolled. Thirty-three liquidations repaid about $36.1M of debt, seized 38.6 million PT, and paid a 2.62% bonus. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hackmd.io/@kanveuler/BJe_n1ivGe">Hackedmd</a>)</p><p><strong>Trezor Customer Data Exposed Through a Supply-Chain Zero-Day</strong></p><p>Rob Behnke reviews the Trezor/ShipMonk breach, where approximately 14,000 customers had shipping or other personal information exposed even though Trezor hardware wallets themselves were unaffected. The compromise traced back to CVE-2026-72898, a CVSS 10.0 SQL-injection flaw in ShipMonk’s Metabase deployment that was exploited as a zero-day. The resulting data significantly strengthens phishing and impersonation opportunities against hardware-wallet owners, reinforcing the physical and social-engineering consequences of third-party data exposure. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.halborn.com/blog/post/explained-the-trezor-shipmonk-breach-august-2026">Halborn</a>)</p><h1 id="h-capital-allocation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Capital Allocation</h1><p><strong>Beldex Raises $8 Million for Privacy Tooling and AI</strong></p><p>Beldex raised $8 million led by Sigma Capital, with NTC, Nxgen, Digital Consensus Fund, and EAK Ventures. The privacy-focused blockchain company plans to invest in confidential applications, encrypted AI-agent identities, developer tooling, protocol security, zero-knowledge systems, quantum-safe cryptography, secure memory for agent payments and BNS identities. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://beldex.io/blog/beldex-raises-8-million-to-build-privacy-infrastructure">Beldex</a>)</p><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research</h1><p><strong>Bitcoin, Ethereum and Solana Face Different Post-Quantum Migration Problems</strong></p><p>Aleksei Kodukhov reviews how cryptographically relevant quantum computers could threaten major blockchain systems relying on elliptic-curve signatures. The paper distinguishes at-rest, on-spend, and on-setup attack models and examines the particular exposure of Bitcoin, Ethereum, and Solana. It then surveys migration options, including NIST-standardized post-quantum signatures and ecosystem-specific approaches under development. The research frames quantum preparedness less as a single cryptographic upgrade than as a migration problem involving exposed keys, transaction models, compatibility, and economic risk. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2608.22924">arXiv</a>)</p><p><strong>Blockchain and Zero Knowledge Add Verifiable Trust to RAG</strong></p><p>Baixiang Liu, Haotian Che, and Yuan Li propose TrustRAG, a blockchain-backed architecture intended to prevent tampering with documents and credibility scores used by retrieval-augmented AI systems. Expert committees evaluate content through a zero-knowledge protocol, while secure multiparty computation combines private assessments into verifiable trust scores. Hash commitments distributed across chains create an auditable record, allowing clients to detect altered or removed content and independently reproduce rankings. The work applies blockchain security primitives to AI data provenance rather than cryptocurrency itself. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2608.20097">arXiv</a>)</p>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>security</category>
            <category>web3</category>
            <category>cybersecurity</category>
            <category>hacks</category>
            <category>research</category>
        </item>
        <item>
            <title><![CDATA[0x47 Web3 Security Bulletin ]]></title>
            <link>https://paragraph.com/@w3sb/0x47-web3-security-bulletin</link>
            <guid>M1gChlb3eGczuNtWFcG2</guid>
            <pubDate>Sat, 22 Aug 2026 16:27:09 GMT</pubDate>
            <description><![CDATA[Intelligence for Web3, digital asset infrastructure, and the capital shaping the industry.]]></description>
            <content:encoded><![CDATA[<p>TL;DR</p><ul><li><p>Chainalysis draws a hard line between deterministic wallet clustering and predictive ML signals, a useful reminder that attribution claims need to be reproducible and auditable.</p></li><li><p>AI-assisted audit work is improving fastest when protocol-specific context and expert triage stay in the loop, as Nethermind’s Lido Evergreen pilot showed.</p></li><li><p>This week’s operational theme is latency: RWA freeze controls, TradFi Hyperliquid approval workflows, and Harmony’s rollback all point to governance models that must act faster than manual review cycles.</p></li><li><p>Researchers investigating Telegram's new Mini Apps found a particularly serious issue in Telegram’s official Wallet, where exposure of a recovery mnemonic could potentially lead to complete wallet compromise. After responsible disclosure, Telegram introduced two secure-storage APIs, and subsequent testing confirmed that the official wallet no longer stored its mnemonic phrase in plaintext.</p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis</h1><p><strong>Don't Cluster Wallets with a Predictive Model</strong></p><p>Wallet segments are Tier 1 intelligence claims that must be deterministic, reproducible, and auditable. Predictive models fail that bar even when they are accurate, because the rules are learned from training data and can shift when the data does. Chainalysis keeps machine learning for Tier 2 work, lead generation, anomaly detection, and <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/product/alterya/">Alterya</a> scam scoring, and treats those outputs as signals that still need a human check. Backing up this process, they point to the 2024 Daubert ruling in <em>United States v. Sterlingov</em>, which tested heuristic clustering, not model output as fact. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/ml-role-in-blockchain-intelligence/">Chainalysis</a>)</p><p><strong>Protocol Context Makes AI Auditing More Useful</strong></p><p>The four-week Lido Evergreen initiative covered roughly 19,000 lines of already-audited core code using AuditAgent, AgentArena, protocol-specific documentation, and human researchers. Adding Lido-specific context raised AgentArena coverage from 67% to 83% and 44% to 78% across two test clusters. The strongest overall coverage came from combining AI agents with expert researchers, reinforcing that specialized context and human triage remain important even as autonomous security tooling improves. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://nethermind.io/blog/piloting-continuous-ai-augmented-security-on-lido-core">Nethermind</a>)</p><p><strong>RWA Freeze Policies Need to Move in Seconds</strong></p><p>Forta argues that programmable real-world assets need pre-authorized incident controls rather than purely manual freeze decisions. During the Gravity Bridge exploit, stolen PAXG remained in the attacker’s publicly visible wallet for 27 minutes before being converted to WETH despite being technically freezable. Forta proposes narrowly defined automatic triggers, temporary 72-hour freezes, transparent appeal procedures, and sub-minute execution, moving human review from the initial emergency response to determining whether the intervention should remain in force. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://forta.org/blog/should-rwa-issuers-freeze-stolen-assets-automatically">Forta</a>) </p><p><strong>Three Bugs Found Outside CompCert’s Proof Boundary</strong></p><p>Cantina reports that its Apex system reproduced three defects around the formally verified CompCert compiler: Win64 register-state corruption, an incorrect C front-end struct layout, and assembly injection through a crafted filename. The findings do not invalidate CompCert’s core correctness theorem; instead, they occurred in parsing, target modeling, or output layers outside the proof boundary. The research illustrates an important limitation of formal verification: verified components remain dependent on surrounding code and assumptions that may themselves be vulnerable. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.cantina.security/blog/how-we-found-three-bugs-in-a-compiler-proven-correct">Cantina</a>)</p><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements</h1><p><strong>Human Sign-off Cannot Keep Up with Sub-second Hyperliquid Blocks</strong></p><p>Fireblocks recommends defining venue, asset, position-size, transfer, and destination policies before trading begins so compliant transactions can execute automatically within those boundaries. The model moves humans from approving individual time-sensitive actions to establishing policy beforehand, preserving governance without allowing approval latency to create liquidation exposure. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fireblocks.com/blog/institutional-approval-workflows-hyperliquid">Fireblocks</a>)</p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents</h1><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>2026 hacks: 232</p><p>Total amount lost in 2026: $1,198,033,060</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/48eb56d377ae991b2faedce11921191a23573a0205006a0ec34f5d874f427aae.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAICAIAAAAX52r4AAAACXBIWXMAABYlAAAWJQFJUiTwAAAB0klEQVR4nGOYNm1aXV3dqVOn/v///w0VvH/37tzJk3/+/j138uTZE8f+/P37jXTA0NbWlpaWtn79+m/fvr1FAp+/fDl/9qyPjc2fv39bKysqcnL+/P37/Nmzt6QAkAV1dXVxcXHLly/HaoGToeGfv38biosrc7LItGD58uV1dXVYfXDi2DFrTc0/f/9W5eYWpiaTacH69evb2tp27Njx////9+/evX/3DhJ2f/7+vXjurLWm5v///6tyc4vTUiAKMEMZvyBDX19fWFjY+vXr/////+v371+/f3/+8uXzly+/fv8+tG+fmZoaxAdZcXF//v599+4dRBYP+vP37/6dOzOjIiGJgmHHjh3dPT0zpkzZtX7d5I72ptLS9+/ePXv06ODuXQumTJbjYPv//7+Dvr6Dvv7///8vnDpx/9bNE4cOXTx9+uLp088ePbpx6WJvY+Ozx08unj69Z8uWU0eOLJ49a3Jrq6qwyM8fP96/e8fw////+fMXmBvoe1hbMjAwGCgrhfn5hnh52Rjqi7Iye9nb+ru7q0lJacrJeTg4hHl7q0pL+zk6SgsImGlpZScnK4qLq0lJmWhrp0ZHCzEw6CgocDAw8DMwuFhammhrz5s9GwBOtkSixqfAGQAAAABJRU5ErkJggg==" nextheight="572" nextwidth="2216" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Aeternum Parks its C2 on Polygon Contracts</strong></p><p>Aeternum, a C++ Windows botnet loader, reads command-and-control data from Polygon smart contracts instead of attacker-owned servers. Infected hosts send JSON-RPC <code>eth_call</code>s to public RPC endpoints. The campaign fingerprint is function selector <code>0xb68d1809</code> (<code>getDomain()</code>), which returns an XOR key and a Base64-encrypted domain. </p><div data-type="twitter" tweetid="2090165682545516615">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/Unit42_Intel">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/def204bce2317c5da5a8e2d6c2436266779ee6baabcad0e75a3ccae3ebe22626.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/Unit42_Intel" class="twitter-displayname">Unit 42</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/Unit42_Intel" class="twitter-username">@Unit42_Intel</a></p>
    
            </div>
            <a href="https://twitter.com/Unit42_Intel/status/2090165682545516615" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      Aeternum botnet leverages smart contracts on the Polygon blockchain to store and retrieve C2 instructions. Querying public RPC endpoints allows infected endpoints to execute immutable commands and evade takedowns. Read our full analysis: <a class="twitter-content-link" href="https://t.co/X0oEPwzs5q" target="_blank">bit.ly/45pDx6D</a> 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/1b6449f711481f8b8acb63dece89588ddf16c4b19ad21057493f66b299cdcde7.jpg"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/Unit42_Intel/status/2090165682545516615" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            35
          </a>
          <a target="_blank" href="https://twitter.com/Unit42_Intel/status/2090165682545516615"><p>7:55 PM • Aug 19, 2026</p></a>
        </div>
    
  </div> 
  </div><p>Operators rotate that value with admin-only <code>updateDomain</code> (<code>0xb249cd2d</code>). Samples drop XWorm, XMRig, and stealers, then exfiltrate over Telegram. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/">Palo Alto Networks</a>)</p><p><strong>Harmony Will Rewind to Aug 11 and Drop Over 100k Transactions</strong></p><p>Harmony has decided to rollback the chain after last week’s forged ONE mint. Validators are to restore shard 0 block 92,730,034 and shard 1 block 94,978,278 (both 23:25:37 UTC on August 11) and restart from replacement databases. </p><div data-type="twitter" tweetid="2090307607424864705">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/harmonyprotocol">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/567e7e52ddca0306743ebbdaad5a3647b0d7ae25b9bf4b3eaec5e4239bd31ed8.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/harmonyprotocol" class="twitter-displayname">Harmony 💙</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/harmonyprotocol" class="twitter-username">@harmonyprotocol</a></p>
    
            </div>
            <a href="https://twitter.com/harmonyprotocol/status/2090307607424864705" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      We reached quorum for both shard 0 and shard 1. Rollback stage 2 GO is active. <br><br>Validators who completed Stage 1: please follow this GO guide:<br><br><a class="twitter-content-link" href="https://t.co/cOcya6QWN8" target="_blank">github.com/harmony-one/ha…</a><br><br>We will update everyone after confirming the recovered network is healthy, and blocks are being produced and
      
      
        <a class="twitter-card-link" href="https://t.co/cOcya6QWN8" target="_blank">
          <div class="twitter-media twitter-summary-large-image">
            <img src="https://storage.googleapis.com/papyrus_images/4036b8399f8efc0730b08e1db626be6c8259a65391419502e0e2807a8156dc64.jpg">
            <div class="twitter-summary-card-text">
              <span>github.com</span>
              <h2>harmony/docs/recovery/validator-todo-go.md at rollback-92730034 · harmony-one/harmony</h2>
              <p>The core protocol of harmony. Contribute to harmony-one/harmony development by creating an account on GitHub.</p>
            </div>
          </div>
        </a>
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/harmonyprotocol/status/2090307607424864705" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            117
          </a>
          <a target="_blank" href="https://twitter.com/harmonyprotocol/status/2090307607424864705"><p>5:19 AM • Aug 20, 2026</p></a>
        </div>
    
  </div> 
  </div><p>Client v2026.1.2 rejects the exploit block hashes. The discarded shard-0 window is 141,628 blocks, 109,126 regular transactions, and 315 staking transactions. Harmony said selective replay was unsafe: balances, nonces, and contract state would not match. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://cointelegraph.com/news/harmony-plans-rollback-transactions-one-exploit">Cointelegraph</a>)</p><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation</h1><p><strong>SEC Proposes Regulation Crypto Assets</strong></p><p>The SEC issued proposed rule S7-2026-27, its first crypto-specific offering regime. Two exemptions from Securities Act registration: a startup path of up to $5 million over four years, and a fundraising path of up to $75 million in any 12-month period. Issuers still file principles-based disclosures and remain under antifraud rules. A conditional safe harbor would treat the investment contract as ended once promised managerial efforts have ceased, so the token would no longer sit under that Howey wrapper. Subpart E would preempt state registration for qualifying purchasers. Comments run 60 days after Federal Register publication. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.sec.gov/rules-regulations/2026/08/s7-2026-27">SEC</a>) </p><p><strong>FASB: When a Stablecoin Can Sit in Cash Equivalents</strong></p><p>On August 18 the Financial Accounting Standards Board proposed an Accounting Standards Update that leaves the cash-equivalent definition unchanged and adds examples. A qualifying token needs an on-demand contractual right to redeem directly with the issuer for a known cash amount, plus at least one-to-one segregated reserves in short-term, highly liquid assets. An active secondary market is not enough if the holder cannot redeem with the issuer. Reserves of crypto and gold fail the example. Entities may still choose not to present a qualifying token as cash. Comments close November 19. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fasb.org/news-and-meetings/in-the-news/fasb-seeks-public-comment-on-proposal-to-enhance-cash-equivalents-disclosures-and-clarify-the-cash-equivalents-evaluation-for-certain-digital-assets-425287">FASB</a>) </p><p><strong>Austria Fines Bitpanda for MiCA Violations</strong></p><p>Austria's Financial Market Authority fined Bitpanda GmbH €70,000 for violations of the EU's Markets in Crypto-Assets Regulation. The regulator found that Bitpanda failed to submit a required crypto-asset whitepaper at least 20 working days before publication and distributed marketing materials before the whitepaper was published. The communications also omitted required MiCA disclosures and contact information. The sanction is legally binding, making it a notable example of MiCA moving from implementation into active enforcement. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fma.gv.at/bekanntmachung-fma-verhaengt-sanktion-gegen-die-bitpanda-gmbh-wegen-verstoessen-gegen-die-micar/">FMA Osterreich</a>)</p><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research</h1><p><strong>0xPass Splits Cross-Chain Account Trust Across Layers</strong></p><p>Bernardo David, Keon Kim, and Krish Chelikavada propose 0xPass, a modular architecture for cross-chain accounts that separates request orchestration, transaction solving, and signing. Threshold signatures prevent any single transaction node from possessing the complete signing key, while constrained delegation, policy enforcement, recovery, distributed key generation, and auditable communications provide additional controls. A staged deployment model is designed to move implementations progressively from centralized operation toward more permissionless infrastructure without discarding authorization safeguards. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2608.18359">arXiv</a>)</p><p><strong>Telegram Mini Apps Expose Crypto Wallet Secrets</strong></p><p>Andrea Ciccotelli, Federico Zappone, and Roberto Di Pietro analyze security weaknesses in Telegram Mini Apps handling cryptocurrency assets. Of 37 applications examined, 30 contained vulnerabilities involving plaintext secrets, recoverable encryption, or replayable tokens. Telegram’s official wallet initially exposed its recovery mnemonic in plaintext, potentially enabling account compromise. Following responsible disclosure, Telegram introduced secure-storage APIs, and the researchers confirmed that the official Wallet no longer exposed the mnemonic. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2608.17538">arXiv</a>)</p>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>security</category>
            <category>cybersecurity</category>
            <category>regulations</category>
            <category>hacks</category>
        </item>
        <item>
            <title><![CDATA[0x46 Web3 Security Bulletin]]></title>
            <link>https://paragraph.com/@w3sb/0x46-web3-security-bulletin</link>
            <guid>xpNkUWRFp6OsnbkRWkM7</guid>
            <pubDate>Fri, 14 Aug 2026 14:18:23 GMT</pubDate>
            <description><![CDATA[Intelligence for Web3, digital asset infrastructure, and the capital shaping the industry.]]></description>
            <content:encoded><![CDATA[<p>TL;DR</p><ul><li><p>AI is flooding bug bounty programs with more reports, but Coinbase’s Stellar fee-bump case shows high-context human research still catches the hard protocol edge cases.</p></li><li><p>Physical attacks on crypto holders are now a material self-custody risk, with 2026 losses already above $30M and home invasions making up a large share of reported incidents.</p></li><li><p>Regulated stablecoin issuers are moving beyond point-in-time audits toward continuous monitoring for supply changes, privileged actions, upgrades, sanctions exposure, and incident response.</p></li><li><p>FATF is making clear that “decentralized” is not a magic word; control, influence, admin power, governance concentration, and economic benefit remain the real tests.</p></li><li><p>Sanctions and fraud enforcement remain active, with OFAC-linked exchange activity and the alleged Goliath Ventures Ponzi showing how crypto rails still intersect with old-school financial crime.</p></li><li><p>Research is pushing toward safer autonomous on-chain agents and better ways to measure decentralization, both of which matter as protocols become more agent-driven and claims of resilience get harder to verify.</p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis</h1><p><strong>AI Floods the Bug Bounty Queue but Humans Still Find the Hard Bugs</strong></p><p>Coinbase’s Consumer Protection Tuesday post says bug reports are on track to triple year over year after doubling the year before, while valid reports fell from 14% in 2024 to 4% this year. The firm is pushing AI through its own vuln pipelines for commodity issues and refocusing the public bounty on high-ingenuity finds. Case in point: Talaria’s Joe Almeida and Anh Nguyen reported a Stellar fee-bump reconciliation flaw—under some conditions a wrapped withdrawal could look failed internally after it had already succeeded onchain, risking a double-count. No customer funds were hit. AI missed that edge case but flagged a milder related deposit bug. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.coinbase.com/en-it/blog/consumer-protection-tuesday-ai-and-human-expertise">Coinbase</a>)</p><p><strong>Physical Crypto Attacks Exceed $30M in 2026</strong></p><p>Violent attacks against cryptocurrency holders have already stolen more than $30M in 2026, following a record $58M in 2025. Home invasions now represent 37% of reported incidents, while on-chain tracing reveals attackers ranging from opportunistic criminals using centralized exchanges to more sophisticated groups employing laundering infrastructure. The findings reinforce physical security and operational privacy as increasingly important components of self-custody risk. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/violent-crypto-wrench-attacks-2026/">Chainalysis</a>) </p><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements</h1><p><strong>Hacken Adds Continuous Monitoring to AllUnity’s EURAU Stablecoin</strong></p><p>Hacken describes AllUnity’s integration of its Extractor monitoring platform into the regulated EURAU stablecoin infrastructure. The system monitors token supply, privileged governance actions, contract upgrades, large transfers, sanctions exposure, and cross-contract attacks while supporting automated mitigation. The deployment illustrates how regulated stablecoin issuers are extending security beyond audits toward continuous on-chain monitoring and incident-response controls. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacken.io/case-studies/real-time-stablecoin-monitoring-for-allunity/">Hacken</a>)</p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents</h1><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>2026 hacks: 227</p><p>Total amount lost in 2026: $1,194,196,610</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/2b482c4c19977080ff771307f7ed0393d6a86e790384bfbf2a400f3e98d0de4c.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAICAIAAAAX52r4AAAACXBIWXMAABYlAAAWJQFJUiTwAAABtElEQVR4nJ2R4SsDcRjHH0V5oVhe2BqJE6GEcbzYsleGqIlNofBmeWN7t3f2B1Dbu4s3XlCu6FwhXdaI9spasmTdi7ukdVIc2XXN7n79pEOiKb59X3x7nno+9X2Aoii/389xHMZY/aHTaPRRlnWE6LW1R1lW/y6gaToUCrEs+w1g3HWR3deiqCPkaGm5laT/AMLhsM/no2laVdVMJvPwoVtJymsa2dCQvrrKa1pHba0oCA9/1BuAoiiv11sI0FZTYwBaLZZ/AliW/aWiZrNZ4HkjFKqo0G+MOXAcFwwGmZ0djHFWUfKaZsCziqIjVFdRfp5M6ggRJpMoCFlFkWXZ2Br+mj+tIxTjuDm3G2P8DthYXz9gmNVIZDEQUFX1+enpJHp4mUxWF8FFInEtigBwf3cn8Lx0cyPwfDqVSqdSAs+/5HLs5sbu9tZLLneRSMRjsej+3gHDrCwvdRGEjhBgjI+Oj+0k2d/TCwD1lZWzHs+A0zk5MlxVWtpns02Nup0k2Wi22G22ieEhl8PRZLWOuVxFAPPT02ODg9ayMkdnZx/ZPecZLwFoJ4higGpTxcLMzFk8/gq2ME0GAjx+sgAAAABJRU5ErkJggg==" nextheight="564" nextwidth="2206" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Coinsbuy Wallets Drained $7.9M+</strong></p><p>More than $7.9M was drained from wallets associated with B2B crypto payment processor Coinsbuy across Ethereum and TRON. Some of the stolen assets were converted toward Monero through exchanges, while ChangeNOW reportedly helped freeze a six-figure amount. Coinsbuy temporarily suspended deposits and withdrawals before restoring service. </p><div data-type="twitter" tweetid="2086693306851840323">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/BlockWatchdog">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/8ed55488d744a9d05fb3daae7e917b0915f1a3a70cad26d249b64c3678bbc722.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/BlockWatchdog" class="twitter-displayname">BlockWatchdog</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/BlockWatchdog" class="twitter-username">@BlockWatchdog</a></p>
    
            </div>
            <a href="https://twitter.com/BlockWatchdog/status/2086693306851840323" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      <img class="twitter-emoji" draggable="false" alt="🔴" src="https://abs-0.twimg.com/emoji/v2/72x72/1f534.png"> COINSBUY — $8.07M drained<br><br>Coinsbuy refilled the wallets it was robbed from. 12 hours later $3.93M went back into the same ten addresses — seven matched to within 0.05% of each loss. It is still sitting there.<br><br>That only makes sense if the team does not believe the private
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/BlockWatchdog/status/2086693306851840323" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            12
          </a>
          <a target="_blank" href="https://twitter.com/BlockWatchdog/status/2086693306851840323"><p>5:57 AM • Aug 10, 2026</p></a>
        </div>
    
  </div> 
  </div><p><strong>Harmony Mints 4B ONE </strong></p><p>Harmony confirmed an exploit after analyst Juiceberg flagged roughly 4B unauthorized ONE minted, which is about 26% of supply, via empty blocks. Juiceberg said ~2.8B reached exchanges and ~97% of the mint was already on exchanges or sold; ONE fell ~37% to about $0.00077. </p><div data-type="twitter" tweetid="2087353885765620127">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/the_juice_berg">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/c12d2f96a0590f95cf9c8b401179c4aeb447a7be552ef0e59e2c28b24a92c05e.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/the_juice_berg" class="twitter-displayname">Juiceberg</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/the_juice_berg" class="twitter-username">@the_juice_berg</a></p>
    
            </div>
            <a href="https://twitter.com/the_juice_berg/status/2087353885765620127" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      Harmony exploited as on-chain data reveals unauthorized 4B ONE mint (26% of supply) via empty blocks, with 2.8B quickly funneled to exchanges as price crashed while totalSupply endpoint hides the inflation $ONE
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/the_juice_berg/status/2087353885765620127" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            74
          </a>
          <a target="_blank" href="https://twitter.com/the_juice_berg/status/2087353885765620127"><p>1:42 AM • Aug 12, 2026</p></a>
        </div>
    
  </div> 
  </div><p>Harmony paused its bridge, shipped a patch to stop further minting, and asked exchanges to freeze four named wallets, but has not confirmed the mint size or root cause. Decrypt notes a rollback would undo the attack and every legitimate transaction after it. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://decrypt.co/375390/harmonys-one-sinks-37-after-attacker-mints-4-billion-tokens">Decrypt</a>)</p><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation</h1><p><strong>FATF: “Decentralised” is a Claim to Test </strong></p><p>FATF’s July 2026 Targeted Report on Regulatory Challenges from DeFi clarifies that Recommendation 15 still applies where a natural or legal person has “control or sufficient influence.” </p><div data-type="callout" type="info"><link rel="preload" as="image" href="https://paragraph.com/editor/callout/information-icon.png"><div class="callout-base callout-info" data-node-view-wrapper="" style="white-space:normal"><img src="https://paragraph.com/editor/callout/information-icon.png" class="callout-button"><div class="callout-content"><div><p><strong>FATF Recommendation 15</strong> is the “New Technologies” standard. In short: countries and firms must identify, assess, and mitigate ML/TF risks from new products, practices, and tech—including crypto.</p><p>Since 2018–2019 updates, it is the main FATF rule that pulls <strong>virtual assets (VAs)</strong> and <strong>virtual asset service providers (VASPs)</strong> into the AML/CFT framework. It requires that VASPs be:</p><ul><li><p>licensed or registered</p></li><li><p>supervised for AML/CFT</p></li><li><p>held to the same core obligations as traditional financial institutions (CDD, record-keeping, suspicious transaction reporting, sanctions screening, and—via the Interpretive Note—the Travel Rule under Rec 16)</p></li></ul><p>That is why the DeFi report keeps citing R.15: if someone has “control or sufficient influence” over a DeFi arrangement and does VASP-like activity, that person is in scope under Recommendation 15—not because DeFi got its own new rule.</p></div></div></div></div><p>Three buckets: identifiable controllers; centralized in practice but hard to name; and truly decentralised. The Standards cover the first two; smart contracts themselves are not VASPs. Centralised elements “frequently persist” via governance-token concentration, admin privileges, upgrades, economic benefits, and infrastructure influence. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fatf-gafi.org/content/dam/fatf-gafi/reports/targeted-report-decentralised-finance-2026.pdf.coredownload.pdf">FATF</a>)</p><p><strong>OFAC Targets Crypto Exchanges Linked to Iran’s Regime</strong></p><p>OFAC issued sanctions against Shelbit, its operator Siavash Kayvanpour, associated businesses, and Iranian exchange Aban Tether. Elliptic identified tens of millions of dollars flowing between Shelbit and Iranian entities, including approximately $71.8M connected to Central Bank of Iran funds, as well as direct transfers involving IRGC-attributed addresses. The findings illustrate how blockchain intelligence can identify sanctions exposure beyond wallet addresses explicitly published by regulators. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.elliptic.co/insights/ofac-sanctions-shelbit-and-other-entities-associated-with-iranian-regime/">Elliptic</a>) </p><p><strong>SEC and CFTC Target Alleged $400M Crypto Ponzi</strong></p><p>The CFTC and SEC filed parallel civil actions against Goliath Ventures and CEO Christopher Delgado, alleging hundreds of millions were raised for purported crypto liquidity-pool and trading strategies but instead used for Ponzi payments and personal spending. The CFTC says roughly 1,600 customers contributed at least $397M, while the SEC alleges more than $425M was raised from over 1,300 investors. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.cftc.gov/PressRoom/PressReleases/9280-26">CFTC</a>) </p><h2 id="h-legislative-watch" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Legislative Watch</h2><p><strong>Democrats Warn SEC and CFTC May “Jump around Congress” </strong></p><p>Politico reported that with the CLARITY Act stalled before recess, SEC Chair Paul Atkins and CFTC Chair Michael Selig are positioned to drive crypto policy from the agencies. Democrats, including critics who say the regulators are too industry-friendly, frame the coming rule slate as an end-run around months of legislative bargaining. The SEC’s August 14 meeting is set to vote on proposing “Regulation Crypto,” a tailored offering regime for certain crypto investment contracts; broader agendas include transfer-agent rules and a rethink of 2005 stock-trading rules. With no Democratic commissioners at either agency, new proposals can move faster, but that also sharpens Capitol Hill scrutiny, including Democratic demands for more balanced commission panels tied to CLARITY talks. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.politico.com/news/2026/08/10/democrats-brace-wall-street-regulators-crypto-plans-01031371">Politico</a>)</p><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research</h1><p><strong>ChainClaw Adds Safety Guardrails for Autonomous On-Chain Agents</strong></p><p>Researchers introduce ChainClaw, a blockchain-native agent framework built on OpenClaw. It adds transaction simulation, policy checks, live chain-state monitoring, event-driven execution, and guarded signing to reduce risks from irreversible autonomous transactions. Testing across transfers, approvals, swaps, and malicious transaction scenarios showed stronger safety and task completion than general-purpose agent frameworks including ReAct, LangChain, and OpenClaw. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2608.05790">arXiv</a>)</p><p><strong>Researchers Propose New Metrics for Measuring Decentralization</strong></p><p>Jakub Kacper Szeląg, Aydin Abadi, and Mohammad Naseri argue that blockchain research lacks a sufficiently rigorous, portable definition of decentralization. Their graph-based ontology separates decentralization from simple distribution of infrastructure or trust and introduces two quantitative measures, Void Tolerance and Imperviousness. Applying the framework to blockchain and other distributed architectures produces more consistent comparisons than existing definitions, potentially giving protocol-security researchers better tools for evaluating concentration and resilience claims.  (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2608.09748">arXiv</a>)</p><br><br>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>hacks</category>
            <category>regulations</category>
            <category>security</category>
            <category>cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[0x45 Web3 Security Bulletin]]></title>
            <link>https://paragraph.com/@w3sb/0x45-web3-security-bulletin</link>
            <guid>Qf1X2UZc1ezBalBR7LIg</guid>
            <pubDate>Sat, 08 Aug 2026 11:15:04 GMT</pubDate>
            <description><![CDATA[Intelligence for Web3, digital asset infrastructure, and the capital shaping the industry.]]></description>
            <content:encoded><![CDATA[<p>TL;DR</p><ul><li><p>Crypto’s attack surface keeps moving outside audited code: privileged access, signers, weak seed generation, developer tooling, and operational controls are doing as much damage as smart-contract bugs.</p></li><li><p>The COLDCARD weak-seed incident is now the week’s defining custody story, with roughly 1,816 BTC tied to predictable seed generation.</p></li><li><p>Market infrastructure is consolidating around investigation, authorization, and policy layers: Chainalysis inks a deal with Penlink, Magic moves to becoming Newton Labs, and onchain transaction approval moving closer to real-time risk control.</p></li><li><p>Regulators are tightening the perimeter globally, with Russia, South Africa, the CFTC, and the SEC, all pointing toward more explicit rules for custody, trading, collateral, vaults, and cross-border flows.</p></li><li><p>Applied research is highly relevant this week: wallet recovery, agent transaction safety, and decentralized attestation all map directly to the same operational security failures showing up in incidents.</p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis</h1><p><strong>Crypto’s Biggest Attack Surface Is Outside the Code</strong></p><p>Rekt argues that some of 2026’s largest crypto losses have bypassed audited smart contracts entirely by targeting privileged access, signers, credentials, and human trust. Drift and KelpDAO illustrate how compromised operators and sustained social engineering can defeat systems whose core contracts remain intact. The analysis positions audits as necessary but incomplete, calling for stronger key management, multi-party authorization, withdrawal delays, and operational security around the people and infrastructure controlling transactions. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rekt.news/wrong-attack-surface">Rekt</a>)</p><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements</h1><p><strong>Penlink Pulls Chainalysis Data into its Investigation Suite</strong></p><p>Chainalysis announced a partnership with <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.penlink.com/">Penlink</a>. The company builds an AI-powered digital intelligence platform for law enforcement, government, and enterprise investigators. It combines digital evidence, open-source intelligence, live communications monitoring, and data analytics in one workflow so teams can collect, analyze, and act on investigative data in real time. Investigators can submit wallet addresses inside Penlink, get entity attribution and risk context from Chainalysis, enrich against OSINT and dark-web hits, then open Reactor in one click when they need deeper onchain tracing. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/penlink-integration-blockchain-intelligence-august-2026/">Chainalysis</a>) </p><p><strong>Magic Labs Becomes Newton Labs </strong></p><p>Sean Li says Magic Labs has sold its embedded-wallet business to Kraken parent Payward and is becoming <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://newton.xyz/">Newton Labs</a>, concentrating exclusively on Newton Protocol. From August 1, Payward began servicing Magic’s wallet customers, while Newton Labs shifted toward an authorization layer that evaluates compliance, security, identity, and risk policies before onchain transactions settle. The deal separates a wallet infrastructure business that powered more than 60 million wallets from a newly focused Web3 transaction-security and policy company. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.linkedin.com/pulse/becoming-newton-labs-sean-l-eaa0c?utm_source=chatgpt.com">LinkedIn</a>)</p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents</h1><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>2026 hacks: 221</p><p>Total amount lost in 2026: $1,182,730,626</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/829ebf20bf1d8ff9ad5e820a32e4f6b8bbb7d6695548c576eea9c5b1e3279d45.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAJCAIAAADcu7ldAAAACXBIWXMAABYlAAAWJQFJUiTwAAAB+UlEQVR4nJVSUUhTYRT+H4IefBOKHnxyGAphM9YKpDV8MH0QoeklrSYIEfnig1BuJHcMmko2G8Jle7pmD4NL+XubjN2GjV1ijPnShj3ao03o/ldKfqa7P0fWX0OKgvtxHj7OOfDxfeegTCYjSVKlUgEA+m+YhFD7AAAky7IgCJIkUUqNU/i6t3dcr4dmZoqFgsXYpM9XLBR+HB4adtAQyOfzkUgEY/yHA5MQALjlvvpBy3BS1HWLMdsOksmkIAiyLP/twGKsz+lMq6rFWG9XZ07TbDr4BsAQxvg/Ar1dnRuKYjHmcrTnNO24XrcdUalUakZkGIZJyO9qjF2O9g1F4SSnaRZjpxZ+VfMFmo9gEmIYRmJp6fvBQeMGfr//7fo6AOxXq+XtbfgJfoNLbW1pVQUAR2trUdf5yGKME84ppfvVKm8e1WpHtRoXvt5x0SQEUUoxxhNjYwNu9xmEWhCanZ4Ozz55dP+ux9nTcf7c6ED/s7mnCKGH98YfT009GL8z6fMNeW8O93lHBwcXRHHI47mA0ItweGLk9o3L3V7XlbMI9V9ztyD0ZXcXAcCncjkajX7U9WAg8E5VE/H4y+XoZioVDAS2stnni4uv19ZkWV6Jxd4oSkgU36fTc8Hgq9XVlVgsEY9vplIhUdzKZkOiyJt8c2F+/vPOzgmDYZ1MBe2P3gAAAABJRU5ErkJggg==" nextheight="612" nextwidth="2246" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Weak COLDCARD Seeds Lead to ~$116M in Losses</strong></p><p>From July 30, attackers brute-forced predictable Coldcard-generated seeds and swept single-signature wallets across the Bitcoin network. TRM’s August 5 write-up cites Galaxy Research’s running tally at about 1,816 BTC (~$116M) across more than 5,200 addresses in at least four waves. The first sweep moved ~594 BTC from ~500 wallets in about 25 minutes. </p><div data-type="twitter" tweetid="2085126271042830608">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/chainalysis">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/c81712fd55445db4be33fb6bbaf5a98d7b2872ca449ea74a1ab41b56fdaf8ad6.png">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/chainalysis" class="twitter-displayname">Chainalysis</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/chainalysis" class="twitter-username">@chainalysis</a></p>
    
            </div>
            <a href="https://twitter.com/chainalysis/status/2085126271042830608" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      Independent Coldcard attackers are draining victims in the ongoing campaign. Their distinct on-chain strategies distinguish them. Chainalysis is monitoring the following, and more:<br><br>Type 1: The first wave of attacks: Victim wallets →  attacker wallet → consolidation wallet, 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/13b903c8f066074934efc3682dd7664c1725553b70cb382a27086163f0ba7b23.jpg"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/chainalysis/status/2085126271042830608" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            108
          </a>
          <a target="_blank" href="https://twitter.com/chainalysis/status/2085126271042830608"><p>10:10 PM • Aug 5, 2026</p></a>
        </div>
    
  </div> 
  </div><p>CoinDesk and Protos covered the same timeline as The Block's analysis. TRM sees little laundering so far, one Wasabi deposit and a Tornado Cash hop, and has not named an actor. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack">TRM</a>)</p><p><strong>XCSSET Turns Compromised Xcode Projects Into a Crypto Threat</strong></p><p>Bill Toulas reports that XCSSET v40 is spreading through compromised Git repositories and Xcode projects, infecting developers when malicious projects are built and then propagating into additional source code. Its 17 modules include credential theft, keylogging, browser hijacking, and data exfiltration. A new Chrome hijacker can intercept cookies, credentials, and MetaMask transactions and manipulate payments in real time, combining developer supply-chain compromise with cryptocurrency theft. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.bleepingcomputer.com/news/security/new-xcsset-variant-targets-macos-devs-via-compromised-xcode-projects/">BleepingComputer</a>)</p><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation</h1><p><strong>Russia Signs Comprehensive Crypto Market Law</strong></p><p>Russia enacted its first comprehensive framework governing cryptocurrency trading, custody, mining and digital-asset intermediaries. Exchanges will ultimately require registration and minimum capital, while non-qualified investors face annual purchase limits and suitability testing. Domestic crypto payments remain prohibited, but the legislation permits specified uses including foreign-trade settlements. Banks must also block transfers suspected of involving unauthorized crypto exchanges. The law’s core provisions take effect September 1, 2026. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://tass.com/economy/2168907">TASS</a>)</p><p><strong>CFTC Signals Push for Stablecoin Collateral and Perpetual Futures</strong></p><p>Michael S. Selig says the CFTC is exploring how regulated stablecoins can be used as collateral while expanding its approach to perpetual futures and round-the-clock markets. The chairman highlighted the agency’s approval of a bitcoin perpetual futures contract and argued that U.S. derivatives regulation should evolve alongside increasingly automated, digital markets rather than wait for international consensus. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.cftc.gov/PressRoom/SpeechesTestimony/seligstatement080626">Commodity Futures Trading Commission</a>) </p><p><strong>SEC Examines Regulatory Pathways for Onchain Vaults</strong></p><p>SEC Crypto Task Force Staff met with <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.birchhill.io/">Birch Hill Holdings</a> and legal counsel to discuss how onchain vault structures intersect with federal securities laws. The discussion covered registration and exemption pathways, investment-adviser treatment for actively managed vaults, qualified-custodian requirements and tokenized credit infrastructure. The meeting did not produce new rules, but provides another indication of how the SEC is working through practical regulatory treatment of institutional DeFi structures. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.sec.gov/files/ctf-memo-birch-hill-holdings-inc-cooley-llp-chapman-cutler-llp-080326.pdf">SEC</a>)</p><p><strong>South Africa Proposes Cross-Border Crypto Controls</strong></p><p>South Africa’s National Treasury and South African Reserve Bank published a draft Crypto Assets Manual establishing proposed requirements for cross-border crypto transactions. Transfers between domestic and offshore CASPs, or from domestic CASPs to non-custodial wallets, would trigger FinSurv reporting. The framework also addresses CASP authorization, transaction permissions and administrative responsibilities, with the government aiming to reduce regulatory arbitrage and improve detection of illicit financial flows. Comments close September 30. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.resbank.co.za/en/home/publications/publication-detail-pages/media-releases/2026/crypto-assets">South African Reserve Bank</a>)</p><h2 id="h-legislative-watch" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Legislative Watch</h2><p><strong>Senate Punts Clarity Vote into September</strong></p><p>Majority Leader John Thune confirmed late on August 6 that the Senate will not take up the Clarity Act before August recess. Supporters had wanted an initial vote this week; Thune may still file cloture to queue the bill, but floor action is now expected when the chamber returns in September. Democrats refused a time agreement that would have cleared a path to a vote, citing unfinished talks on Trump-family crypto ethics language, law-enforcement concerns, and the Agriculture Committee commodities title. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.politico.com/live-updates/2026/08/06/congress/senate-republicans-expect-to-depart-without-taking-up-crypto-bill-01028473">POLITICO</a>)</p><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research</h1><p><strong>Zero-Knowledge Recovery for Compromised Bitcoin and Ethereum Wallets</strong></p><p>Mehmet Sabir Kiraz and Suleyman Kardas introduce Z-SCAPE, a recovery protocol for self-custodial wallets whose seed-generation entropy has been compromised. Users establish an independent recovery credential before an incident and later prove ownership in zero knowledge without revealing personal records, recovery secrets, or compromised private keys. The design prevents replay and destination-substitution attacks and includes integration mechanisms for both Bitcoin and Ethereum. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://eprint.iacr.org/2026/1621">IACR Eprint Archive</a>) </p><p><strong>Safety Invariants for Agents Moving Assets Onchain</strong></p><p>Zhaoming Yin proposes seven safety invariants for autonomous agents executing irreversible blockchain transactions. The framework targets failures including incorrect chain or address selection, ambiguous transaction outcomes, retries, and duplicated execution, guaranteeing that ledger effects either do not occur or match the rendered transaction exactly once. Testing covered 60 adversarial scenarios, while the deployed system recorded 108 production operations across eight chains. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2608.00783">arXiv</a>)</p><p><strong>Blockchain Coordinates Continuous Attestation for AI Agents</strong></p><p>Adam Zahir, Vincent Lefebvre, Mark Angoustures, Milan Groshev, and Carlos J. Bernardos present D-MUTRA, a decentralized remote-attestation framework for multi-agent systems. Agents continuously measure their runtime integrity and verify peers while a smart contract coordinates and records the process. A proof of concept using private Ethereum/Hyperledger Besu with ROS/Gazebo robots detected malicious software modifications with low application overhead, providing a software-based alternative to centralized attestation infrastructure. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2608.01938">arXiv</a>) </p><br>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>regulations</category>
            <category>hacks</category>
            <category>web3</category>
            <category>security</category>
            <category>cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[0x44 Web3 Security Bulletin]]></title>
            <link>https://paragraph.com/@w3sb/0x44-web3-security-bulletin</link>
            <guid>y1n8pw36W4ylaDxalhoO</guid>
            <pubDate>Fri, 31 Jul 2026 13:51:45 GMT</pubDate>
            <description><![CDATA[Intelligence for Web3, digital asset infrastructure, and the capital shaping the industry.  ]]></description>
            <content:encoded><![CDATA[<p>TL;DR</p><ul><li><p>Digital-asset security is becoming a continuous governance problem: Fireblocks, Elliptic, and Chainalysis all point towards requiring systems that can prove controls, permissions, and compliance effectiveness in real time, not just during audits or supervisory reviews.</p></li><li><p>Protocol security still fails at the application boundary. Uniswap v4 hooks, bridge withdrawals, DAO governance, and state-invariant transaction spam all show the same pattern: the base layer may behave correctly while custom logic, assumptions, incentives, or validation gaps create the actual exposure.</p></li><li><p>The incident picture stayed heavy: AFX Trade lost roughly $24.15M after hot-validator signatures cleared its Arbitrum custody bridge, VerusCoin’s bridge verified withdrawals without economic backing, and Triple-A contained unauthorized access to company treasury wallets while keeping client funds isolated.</p></li><li><p>Wallet and custody risk is not just private-key theft. Coinkite’s COLDCARD RNG advisory shows why seed-generation provenance matters, while Ledger’s agent stack and Fireblocks’ operating model point toward policy-controlled workflows where humans, agents, and infrastructure each have constrained authority.</p></li><li><p>Security tooling is moving from detection to resolution. Cantina’s Clarion launch, CyberScope’s audit-prep guidance, TAC InfoSec’s Safehouse deal, and V12’s AI-assisted vulnerability research all reinforce that finding issues is no longer enough; teams need faster prioritization, remediation, and verification.</p></li><li><p>The longer-term risk horizon is getting real: quantum migration gaps, privacy-chain compliance models, and AI-discovered vulnerabilities are shifting Web3 security from isolated exploit response toward infrastructure resilience, governance design, and programmatic proof that controls work under stress.</p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis</h1><p><strong>Digital-Asset Scale Requires Continuous Governance</strong></p><p>Fireblocks argues that operational risk shifts from key custody to configuration drift as digital-asset businesses grow. The recommended model combines continuous policy and permission monitoring, audit-ready reconciliation, embedded wallet abstractions, and policy-controlled batching, swaps, staking, and DeFi access. Security and audit evidence should emerge from routine operations rather than manual preparation before reviews. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fireblocks.com/blog/run-digital-assets-at-scale">Fireblocks</a>)</p><p><strong>Seven Ways Uniswap v4 Hooks Fail</strong></p><p>Nicolas Donboly identifies seven recurring security failures in Uniswap v4 hooks, including unrestricted callbacks, malicious pool selection, broken internal accounting, mismatched address permissions, and unsafe shared state. The analysis stresses that PoolManager settlement guarantees do not validate application-specific assumptions, leaving hook developers responsible for authorization, accounting, integrations, and failure handling. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://blog.trailofbits.com/2026/07/30/building-secure-uniswap-v4-hooks/">Trail of Bits</a>) </p><p><strong>US Crypto Oversight Shifts Toward Outcomes</strong></p><p>Peter Phelan notes that US digital-asset regulation is moving beyond procedural checklists toward demonstrable effectiveness, continuous monitoring, and coordinated supervision. He points to the passage of stablecoin legislation and updated model-risk guidance as evidence that institutions will increasingly need to prove their compliance systems work in practice, particularly when AI and on-chain data influence risk decisions. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.elliptic.co/insights/how-us-crypto-regulation-is-being-rewritten-in-2026/">Elliptic</a>)</p><p><strong>Prepare the Code Before the Audit</strong></p><p>CyberScope recommends freezing the codebase, documenting intended behavior, expanding test coverage, running static analysis, and removing dead or confusing code before an audit begins. These steps reduce time spent reverse-engineering project intent and allow paid reviewers to concentrate on complex vulnerabilities that automated tools and routine testing are less likely to detect. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.cyberscope.io/blog/how-to-prepare-for-a-smart-contract-audit">CyberScope</a>) </p><p><strong>Privacy Chains Require Different Compliance Models</strong></p><p>Chainalysis Team divides blockchain privacy into four models: permissioned transaction sharing, shielded pools, encrypted extensions, and private smart-contract execution. Each exposes different information and requires different monitoring arrangements. The analysis concludes that compliance teams cannot apply one universal privacy-chain methodology across networks such as Canton, Zcash, Solana, and Aztec. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/privacy-blockchain-compliance/">Chainalysis</a>)</p><p><strong>FYI: DeFi Security Summit 2026</strong></p><div data-type="twitter" tweetid="2079245146357633405">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/summit_defi">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/72369d2c36e9d98b6cc9219dd98cadb613780a3fc71c01de67b236d7103a2407.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/summit_defi" class="twitter-displayname">Defi Security Summit</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/summit_defi" class="twitter-username">@summit_defi</a></p>
    
            </div>
            <a href="https://twitter.com/summit_defi/status/2079245146357633405" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      DSS 2026 Call for Speakers deadline extended to August 15.<br><br>We’re giving researchers, auditors, protocol engineers, and security teams more time to submit talks, tools, and technical work for Mumbai.<br><br>Apply to speak: <a class="twitter-content-link" href="https://t.co/Fx2BfC7QpU" target="_blank">defisecuritysummit.org/apply-to-speak</a><br><br>DSS 2026 | Edition #5 | Mumbai, India 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/df0eb7baa4c82f732bc2dd26911c11333ca88126f8e531bcde86903e88cc517b.jpg"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/summit_defi/status/2079245146357633405" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            21
          </a>
          <a target="_blank" href="https://twitter.com/summit_defi/status/2079245146357633405"><p>4:40 PM • Jul 20, 2026</p></a>
        </div>
    
  </div> 
  </div><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements</h1><p><strong>Cantina Moves From Detection to Resolution</strong></p><p>Cantina says security programs increasingly fail after vulnerabilities are discovered, as remediation queues and handoffs give attackers time to act. Its newly launched Clarion platform is designed to prioritize findings, coordinate remediation, and verify fixes using agentic workflows. The company also announced new funding that brings its total raised to $16.5M. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://cantina.xyz/blog/the-next-chapter-of-cantina">Cantina</a>) </p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents</h1><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>2026 hacks: 213</p><p>Total amount lost in 2026: $1,086,629,393</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/64340b32c9a95d5d1cfc6abd765e2b40a868ce14a9efa6fe4956a3263f8c4594.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAICAIAAAAX52r4AAAACXBIWXMAABYlAAAWJQFJUiTwAAABtElEQVR4nK3RbygDcRgH8N8b/15hXrDyLyVpxdLywnlhmEwjkj9JXkhT0rU3U97ci703b7RaTspax6JTpEmpaS90RblESxvWOje6o+4acb8eaRKikG/Pi6eepz49PYhlWZIkWZaVvkosGj06PFRU9fTkZHc7qKiq9JsAAGIYhiRJj8eTSCQ+jR+fnrbW2b42i4ZxwOfrMTdpGF8Jwn8C64GV9vp6DWM/TdsI4i9AMBikKOo7IODzNdXUAAA9N2cxmf4ChEIht9vNMIwkSamPAYCN1dU04Kdpi8kEALeynPpxXgGKouiFhTtFUVT1/Rs1jJeXluoqKgBg0eslDAYN4+ubG0VVZVl+v/zWp5u3egE4jktfsOb372xuuJzOpCgmRfFKEI4PDmZcrtqSUgCYnpyoLioCgItYTIjHhXg8Gomc8vzl+cXDfYoLh72zswA4Golw4fD+3h4zT5+fnb0AAMDzfHenzdrYiBDSZ2YQRmOv1eqw2/U52QO2juL8PMo5VZiVWanXO+z2qpLi0cEBHUKOsTEdQl2tLSP9/aUFOkN5WXNDw/jwUC5CXWYzQogw1iZF8Rmk700Aa+1qEgAAAABJRU5ErkJggg==" nextheight="582" nextwidth="2246" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>AFX Trade Loses $24.15M </strong></p><p>On July 22 Blockaid flagged a drain of about 24.15M USDC from AFX Trade’s own Arbitrum custody bridge. Rekt reports five hot-validator signatures met the roughly two-thirds quorum; the contract released funds after a 200-second dispute window with no challenge. Arbitrum’s native bridge was unaffected. Stolen USDC moved via CCTP to Ethereum, filled through UniswapX into ~12,467 ETH, then fragmented. AFX offered a 30% bounty for a 70% return. Rekt notes Zellic had audited the bridge about 49 days earlier; zeroShadow and SEAL later said the pattern may link to UNC4899 / TraderTraitor. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rekt.news/afx-trade-rekt">Rekt</a>)</p><p><strong>VerusCoin’s Bridge Verified an Unfunded Withdrawal</strong></p><p>A Rekt investigation finds that VerusCoin’s Ethereum bridge lost $7.54M after accepting valid signatures and proofs for withdrawals that lacked economic backing. The exploit used a different implementation gap from the bridge’s $11.6M May incident, but crossed the same trust boundary: authenticity was proven without confirming that the underlying assets existed. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rekt.news/veruscoin-rekt">Rekt</a>)</p><p><strong>Triple-A: Unauthorized Access Hit Company Treasury </strong></p><p>On July 27 Triple-A said it found unauthorized access on July 25 to wallets holding its own digital assets at Triple A Technologies Pte. Ltd. The incident was contained; services ran normally after about three hours in maintenance. Client funds were not affected, Triple-A does not custody client crypto; client money sits in separate trust accounts with safeguarding institutions that were not exposed. Impact is limited to operational treasury accounts and is being absorbed from reserves. The firm is working with cybersecurity and blockchain forensics specialists and Singapore authorities. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.triple-a.io/newsroom/official-statement-regarding-recent-wallet-activity">Triple-A</a>)</p><p><strong>Coinkite Warns COLDCARD Seeds May Have Weak Device RNG</strong></p><p>Coinkite’s advisory says seeds generated on Mk3 firmware 4.0.1 (March 2021) or later may put funds at risk; Mk4, Mk5, and Q seeds made before fixed firmware had about 72 bits of entropy instead of the expected 128. Fixed builds are out: Mk4/Mk5 need 5.6.0+, Q needs 1.5.0Q+; a firmware update does not repair an existing seed. </p><div data-type="twitter" tweetid="2083074854190985535">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/lookonchain">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/e0254e83c56c31202a90c9052ab3caef76802ea71138f995758687ca2ce4b2eb.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/lookonchain" class="twitter-displayname">Lookonchain</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/lookonchain" class="twitter-username">@lookonchain</a></p>
    
            </div>
            <a href="https://twitter.com/lookonchain/status/2083074854190985535" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      More than $38M has been stolen due to a Coldcard wallet vulnerability.<img class="twitter-emoji" draggable="false" alt="⚠️" src="https://abs-0.twimg.com/emoji/v2/72x72/26a0.png"><br><br>Funds from around 500 wallets were transferred to wallet bc1qnk, totaling 594.48 $BTC ($38.2M).<br><br>Stay safe.<br><br><a class="twitter-content-link" href="https://t.co/gUmUfQLvdb" target="_blank">arkm.com/explorer/addre…</a><br><a class="twitter-content-link" href="https://t.co/Bg2XS39mWh" target="_blank">blog.coinkite.com/coldcard-mk3-s…</a> 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/c41debfefc17df16a26d6da8c0fe0e294c528d3c23024ae137bde5480fa353f7.jpg"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/lookonchain/status/2083074854190985535" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            702
          </a>
          <a target="_blank" href="https://twitter.com/lookonchain/status/2083074854190985535"><p>6:18 AM • Jul 31, 2026</p></a>
        </div>
    
  </div> 
  </div><p>Users who added ≥50 private dice rolls when creating the seed are not considered at risk from this RNG bug alone. TAPSIGNER, OPENDIME, and SATSCARD are unaffected. Coinkite tells affected holders to migrate carefully to a new seed on patched hardware (or interim BIP-39 passphrase / dice-only paths on Mk3).  (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/">Coinkite</a>) </p><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation </h1><p><strong>Will the Clarity Act be Signed Before the August Recess?</strong></p><p>Senate leaders have not yet filed cloture on the Clarity text before the August 8 recess.  On July 28 SEC Chair Paul Atkins said the agency is giving Congress technical assistance and told CNBC it is “ready, willing and able” to address covered issues under existing authority if legislation fails. </p><div data-type="twitter" tweetid="2082190857336205486">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/SECPaulSAtkins">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/af40d02dbbd58ddcc136e436c831f3899b3fbb0a839b1f52853fc82709424ad8.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/SECPaulSAtkins" class="twitter-displayname">Paul Atkins</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/SECPaulSAtkins" class="twitter-username">@SECPaulSAtkins</a></p>
    
            </div>
            <a href="https://twitter.com/SECPaulSAtkins/status/2082190857336205486" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      I am committed to supporting Congress in advancing the CLARITY Act, including providing technical assistance.<br><br>American leadership in the digital finance revolution means matching the energy of American innovators with a regulatory framework worthy of them. 
      <div class="twitter-media">
      <img class="twitter-image" src="https://pbs.twimg.com/amplify_video_thumb/2082155871686066176/img/K30ES3O3kPQxY8_K.jpg">
    </div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/SECPaulSAtkins/status/2082190857336205486" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            3,664
          </a>
          <a target="_blank" href="https://twitter.com/SECPaulSAtkins/status/2082190857336205486"><p>7:46 PM • Jul 28, 2026</p></a>
        </div>
    
  </div> 
  </div><p>He still prefers statute; agency rules alone cannot grant the CFTC nationwide digital-commodity spot authority. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://crypto.news/clarity-act-merged-draft-what-is-in-it/">Crypto News</a>)</p><p><strong>MiCA Staff Competence Rules Take Effect</strong></p><p>European Securities and Markets Authority’s MiCA knowledge-and-competence guidelines became applicable on July 28. Crypto-asset service providers must assess and document the qualifications of employees who inform or advise clients, maintain ongoing training programs, and apply higher competence standards to advisory personnel. The change makes employee capability and professional development an auditable supervisory requirement for regulated crypto firms across the EU. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.esma.europa.eu/sites/default/files/2026-01/ESMA35-24871704-2922_Guidelines_for_the_criteria_on_the_assessment_of_knowledge_and_competence_under_MiCA.pdf">ESMA</a>) </p><p><strong>Canada Proposes Crypto Platform Fee Model</strong></p><p>CIRO opened consultation on a dedicated regulatory fee model for crypto trading platforms on July 30. The proposal would create a more explicit framework for allocating the costs of supervising registered platforms, adding a new operational consideration for crypto businesses entering or remaining in Canada’s regulated investment market. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.osc.ca/en/industry/market-regulation/self-regulatory-organizations-sro/canadian-investment-regulatory-organization-ciro/ciro-rule-review/request-comment-22">Ontario Securities Commission</a>)</p><h1 id="h-capital-allocation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Capital Allocation</h1><p><strong>TAC InfoSec Signs Safehouse Acquisition Deal</strong></p><p>TAC InfoSec, whose CyberScope subsidiary provides Web3 security and smart-contract auditing, signed a binding term sheet to acquire 100% of Israel-based Safehouse Technologies. The proposed transaction would expand TAC from enterprise and Web3 security into consumer cybersecurity. The deal remains subject to due diligence, regulatory requirements, and definitive agreements, with completion targeted within three months. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://nsearchives.nseindia.com/corporate/TAC_24072026110047_TAC_Safehouse_Acquistion_PR.pdf">TAC Security Release</a>)</p><p><strong>V12 Announces $10M Seed </strong></p><p>V12 closed a $10M seed led by Electric Capital, with ZachXBT, samczsun, Walden Yan, and others. Earlier this month its agent autonomously found a major-blockchain bug putting more than $100M at risk and took a $2.5M bounty, the largest the team says an AI agent has received. The post frames V12 as a white-box vulnerability research tool, not black-box pen-testing. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/v12sec/status/2082890648374424012">V12 on X</a>)</p><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research</h1><p><strong>DAO Attacks Without Smart-Contract Bugs</strong></p><p>Vabuk Pahari and colleagues analyze governance contracts across 48 active Ethereum DAOs and identify “governance attacks” that exploit mechanism design rather than implementation vulnerabilities. The study examines how voting systems, veto powers, execution paths, and off-chain dependencies balance decentralization against security, fairness, privacy, and operational flexibility. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2607.26204">arXiv</a>)</p><p><strong>Blockchain Spam That Changes Nothing</strong></p><p>Vabuk Pahari, Johnnatan Messias, and Christof Ferreira Torres identify nearly 1.4 billion state-invariant transactions across Ethereum, Optimism, and Base, transactions that consume network resources without changing ledger state beyond fees. The study associates much of the activity on Layer 2 networks with speculative MEV and finds that address poisoning represents a substantial portion of Ethereum’s non-reverted state-invariant traffic. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2607.24172">arXiv</a>)</p><p><strong>Digital Assets Face a Quantum Migration Gap</strong></p><p>Lee Reiners argues that regulated finance is adopting quantum-vulnerable blockchain infrastructure faster than policymakers are establishing migration requirements. The paper frames exposed keys protecting Bitcoin, Ethereum, stablecoins, custody systems, bridges, and tokenized assets as a potential financial-stability risk, and proposes a federal quantum-resilience perimeter for institutions interacting with digital assets. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=7176419">SSRN</a>)</p><br><br>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>security</category>
            <category>cybersecurity</category>
            <category>regulations</category>
            <category>hacks</category>
        </item>
        <item>
            <title><![CDATA[0x43 Web3 Security Bulletin]]></title>
            <link>https://paragraph.com/@w3sb/0x43-web3-security-bulletin</link>
            <guid>IliJaXym1wST205WQCwV</guid>
            <pubDate>Fri, 24 Jul 2026 07:59:29 GMT</pubDate>
            <description><![CDATA[Intelligence for Web3, digital asset infrastructure, and the capital shaping the industry.]]></description>
            <content:encoded><![CDATA[<p>TL;DR </p><ul><li><p>Coinbase is treating post-quantum migration as a long-lead infrastructure program: PQ-CoreKMS, Stanford Bitcoin workshops, and the Bitcoin Security Consortium all point to years of engineering before the risk becomes urgent.</p></li><li><p>Herd Labs shows where DeFi risk tooling is headed: live asset-liability graphs that map token contagion across reserves, wrappers, lending markets, and off-chain exposure.</p></li><li><p>The incident picture stayed ugly: Allbridge lost roughly $1.65M to Solana pool manipulation, while Ostium reopened after a 23.8M USDC vault drain tied to a malicious price update.</p></li><li><p>Policy momentum continued with updated CLARITY Act text adding ethics constraints for officials issuing tokens, while Japan and Russia moved their own crypto market-structure rules forward. </p></li><li><p>Cyclops’ $20M Series A is another signal that stablecoin payments are moving from crypto-native tooling into financial infrastructure: the company is selling a single API for settlement, payins, payouts, and treasury.</p></li><li><p> In research: KASS (Knowledge-Augmented Attack Synthesis and Simulation) generated working smart-contract exploits for 94.23% of tested contracts, while new x402 research warns that facilitator validation bugs could become shared infrastructure risk across many paid APIs and agent workflows.</p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis</h1><p><strong>Coinbase Outlines PQ-CoreKMS, Bitcoin Workshops, and a Security Consortium </strong></p><p>Coinbase's Independent Advisory Board on Quantum Computing and Blockchain is driving three workstreams. CoreKMS, which protects about 99.9% of custodied assets via MPC, gets a post-quantum track: PQ-CoreKMS aims for an automated signing pipeline within a year (enclaves, secret-sharing, threshold crypto for any PQ signature scheme), then full lattice MPC over two to three years, plus a company-wide crypto inventory and migration triggers. </p><div data-type="twitter" tweetid="2080270053413658972">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/TheBlockCo">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/ce1b0b752e76a4a9701c8fa242270d9cb82bdc63728e6473ac86b2902aef460a.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/TheBlockCo" class="twitter-displayname">The Block</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/TheBlockCo" class="twitter-username">@TheBlockCo</a></p>
    
            </div>
            <a href="https://twitter.com/TheBlockCo/status/2080270053413658972" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      THE BLOCK: Strategy launches Bitcoin Security Consortium with BlackRock, Coinbase, and others backed by $15M in member pledges.<br><br>The consortium's immediate focus is post-quantum cryptography research, addressing a threat years away but requiring long-term preparation. 
      <div class="twitter-media"><div class="twitter-two-images"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/5213070fc68fd2f77eee064297f7a6501122778f7c83df6a28c88f11675d5289.jpg"></div></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/TheBlockCo/status/2080270053413658972" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            24
          </a>
          <a target="_blank" href="https://twitter.com/TheBlockCo/status/2080270053413658972"><p>12:33 PM • Jul 23, 2026</p></a>
        </div>
    
  </div> 
  </div><p>Separately, Coinbase will co-host Bitcoin post-quantum sessions with Stanford starting in August, and as a founding member of the Bitcoin Security Consortium with BlackRock, Fidelity Digital Assets, Block, and others is donating and assigning engineers to open-source work such as <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://github.com/bitcoin/bips/blob/master/bip-0360.mediawiki">BIP-360</a>. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.coinbase.com/en-it/blog/what-coinbase-is-doing-to-prepare-for-post-quantum-cryptography">Coinbase</a>)</p><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements</h1><p><strong>Herd Labs Maps Token Contagion with Live Balance Sheet Graphs</strong></p><p>Andrew Hong at Herd Labs argues one-time token reviews no longer work: vaults can touch 300+ contracts, and the first five months of 2026 saw nearly a billion dollars in related losses (Resolv USR mint, Stream Finance multisig, KelpDAO rsETH bridge). Herd recursively expands each reserve and downstream wrapper into an asset–liability graph, assets are backing positions, liabilities are issued supply plus where that supply sits in Morpho, Pendle, Silo, Euler, and similar. </p><div data-type="twitter" tweetid="2069116399839006877">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/andrewhong5297">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/f903871b38b5a4c8fb81a65b362af213e8c3ab3e83ead7e3da32e5f80fa4d7a9.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/andrewhong5297" class="twitter-displayname">ilemi</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/andrewhong5297" class="twitter-username">@andrewhong5297</a></p>
    
            </div>
            <a href="https://twitter.com/andrewhong5297/status/2069116399839006877" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      new homepage <img class="twitter-emoji" draggable="false" alt="😇" src="https://abs-0.twimg.com/emoji/v2/72x72/1f607.png"> <br><br>an inventory of Herd's core offerings:<br>- Token balance sheets with risk reporting and monitoring (in beta)<br>- MCP/CLI block explorer (never manually browse etherscan again)<br>- Human readable contracts and transactions, with deeper data than any other platform 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/1b2c54c8b2a471cd90bb83b92986746ad519df4afa46d719123b7120353f77ac.jpg"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/andrewhong5297/status/2069116399839006877" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            40
          </a>
          <a target="_blank" href="https://twitter.com/andrewhong5297/status/2069116399839006877"><p>5:52 PM • Jun 22, 2026</p></a>
        </div>
    
  </div> 
  </div><p>For example, on InfiniFi’s iUSD, the graph shows ~43% of reserves in off-chain Fasanara Capital and ~52% of supply redeployed as siUSD, so an asset freeze turns into redemption pressure across those venues. AI agents are enabled to keep the graphs live. Herd also builds function-permission maps (for example who can mint USDC) and is beta-testing custom risk models with design partners. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://paragraph.com/@herd-labs/measuring-defi-contagion-through-token-wrappers-and-protocols">Herd Labs</a>)</p><p><strong>Ledger Tests Agent Stack for Human-Confirmed Crypto Workflows</strong></p><p>Ledger’s Agent Stack for AI-assisted crypto workflows: Device Management Kit Skills, Ledger Wallet CLI, Ledger Enterprise CLI, and Enterprise Multisig CLI, tested with more than 1,000 agents. Agents can read balances and history and draft actions inside Claude Code, Codex, Cursor, and similar tools, but the user must confirm on the Ledger device before a signature. Ledger lists prompt injection, autonomous execution, and agents with live resource access as the risks it is designing around; the 2026 roadmap adds agent identity, intents and policies, then proof of humanity. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://nftevening.com/ledger-wants-ai-agents-to-manage-crypto-without-holding-users-keys/">nft evening</a>)</p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents</h1><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>2026 hacks: 203</p><p>Total amount lost in 2026: $1,057,046,008</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/d80e6f61ef2d5ec95567528fc89d15e00263631b1c041717ddc4e89ce8c87acd.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAJCAIAAADcu7ldAAAACXBIWXMAABYlAAAWJQFJUiTwAAABwklEQVR4nGNYsWLF1KlTr1+//pUQeP706VfSAUNRUZGFhcX8+fO/fv366NGj1xgg2sf7yePHnz5/DnJxPnXixKfPn18TDUAWbNq0qaenZ9OmTf///8e0/8/fvwo8PK9fv/7z96+ZquqJI0f+/P1Lmg+qqqrw+ODT588yTEwQH+jJye7duZMcH1RVVeHxgSQDw5PHj//8/asnJ3to716SfdDT0xMQEDB//vw/f/9iOuHT58/8DAy3b936+fu3ipj4ptWrf/7+TZoP5s+fHxAQAPHBu7dvL5079x8MIC798/cvCwPD69ev////ryAgsAOs7M/fv3/+/oUw4Nwf378/f/oUzoV7lOH///+7d+8uKyqy09VVFhVlYGAoy8lur62dN3Wqqbp6cXo6AwNDe23tlO5OBgaG0oy02uLiwtTU9tpaHwe7pvJyVwvzpvLy2ZMmRPh6y7CzN1dVddTVuVqY+zjYeVpaTOxsB1mwadOm1ISExfPn+3l69nV1VZeXxUdFzZk+PdDPb8qkSQ11dbmZmX1dXbExMYvnz4+PikpPSmpraogJD4Noqa+qqq+qgigO9PPr6+rKSEsrzMs7e+rUu7dvAd9ClUXrwygOAAAAAElFTkSuQmCC" nextheight="592" nextwidth="2216" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><strong>Flash Loan Skews Allbridge Liquidity Pools</strong></p><p>Cross-chain bridge Allbridge Core was hit on July 19–20 when an attacker deployed a $1.12M USDC flash loan from Kamino to manipulate Solana USDC/USDT pool ratios. The maneuver drained approximately $1.65M before the team paused the protocol. Allbridge is now urging liquidity providers to withdraw and appealing to arbitrageurs to return profits for compensation. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://decrypt.co/373831/allbridge-pauses-cross-chain-protocol-after-1-65m-flash-loan-attack">decrypt</a>)</p><p><strong>Ostium to Reopen Trading Following the Vault Drain</strong></p><p>Ostium reopened trading Thursday July 23 after the vault exploit that removed nearly 23.8M USDC. Open positions and pending orders carry over and mark to the live price at reopen; take-profit, stop-loss, and limit orders already through their levels execute at 10:00 a.m. ET. </p><div data-type="twitter" tweetid="2079927945259348274">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/Ostium">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/9fe35fc562638363146f7e03f89ebc13c2d85713f33f45cf24ff986d783b6db7.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/Ostium" class="twitter-displayname">Ostium</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/Ostium" class="twitter-username">@Ostium</a></p>
    
            </div>
            <a href="https://twitter.com/Ostium/status/2079927945259348274" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      Trading on Ostium reopens Thursday, July 23 at 10:00am ET.<br><br>Below covers what happens to open positions, how trading comes back online, and a recovery plan update for liquidity providers.<br><br>What happens to positions at reopen<br><br>Open positions and pending orders will carry over as 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/4141d5c6cdd3a23bd67fc0e2cd27bda9d80b034de56d585aa42912d9acdc768f.jpg"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/Ostium/status/2079927945259348274" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            112
          </a>
          <a target="_blank" href="https://twitter.com/Ostium/status/2079927945259348274"><p>1:53 PM • Jul 22, 2026</p></a>
        </div>
    
  </div> 
  </div><p>New OLP deposits stay paused. Ostium said Mandiant, zeroShadow, Collisionless, and SEAL 911 are on the investigation, alongside exchanges, bridges, and stablecoin issuers. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://thedefiant.io/news/defi/ostium-to-reopen-trading-july-23-after-23-8m-vault-exploit">The Defiant</a>)</p><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation</h1><p><strong>New CLARITY Act Text Bars Officials from Issuing Tokens </strong></p><p>Senator Cynthia Lummis released <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.lummis.senate.gov/wp-content/uploads/Clarity-Act.pdf">updated Digital Asset Market Clarity Act</a> text merging Banking and Agriculture drafts. The ethics section would stop the president, vice president, members of Congress, federal judges, and their spouses from issuing or sponsoring digital assets for pay while in office through Jan. 20, 2029, force covered holdings into sale or a blind trust, and give DOJ civil power that can reach exchanges listing banned tokens. Democrats still want state attorneys general in the enforcement mix, and that fight is what most threatens a 60-vote Senate path before the August recess. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.lummis.senate.gov/press-releases/lummis-releases-updated-clarity-act-text/">Lummis Senate Gov</a>) </p><p><strong>Chainalysis: FATF’s 7th Crypto Report Card Says Laws are Ahead of Enforcement</strong></p><p>Chainalysis walks through FATF’s July 16 7th Targeted Update on VA/VASP standards. Among 147 jurisdictions, 86% have done VA risk assessments and 83% have Travel Rule laws, but 60% of those with Travel Rule statutes have taken no supervisory or enforcement action, and under 10% fully meet preventive AML/CFT measures. The FATF flags freeze-resistant proprietary stablecoins after a Cambodia-linked network issued one following a $29M issuer freeze, plus AI-amplified fraud, DeFi still largely unregulated (93% of jurisdictions have not identified qualifying DeFi arrangements), and expects VASPs to run wallet screening, analytics, and freeze/block capability as baseline compliance. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/fatf-7th-targeted-update-crypto-compliance/">Chainalysis</a>)</p><p><strong>Japan Puts Crypto Under FIEA and Clears a Path for ETFs</strong></p><p>Japan’s Diet moved crypto from a payments-centric Payment Services Act framework into the Financial Instruments and Exchange Act, with the new rules aimed at 2027. Issuers get disclosure duties; exchanges face stricter investor-protection and insider-trading rules; unregistered operators see maximum prison terms rise from three years to ten and fines from ¥3M to ¥10M. Spot crypto ETFs still need Investment Trust Act work, and a separate tax outline points to a flat ~20% crypto gains rate in 2028, down from rates that can hit 55%. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.coindesk.com/policy/2026/07/15/japan-reclassifies-crypto-as-a-financial-asset-paves-way-for-tax-cuts">CoinDesk</a>)</p><p><strong>Russia’s Duma Passes Crypto Trading Law</strong></p><p>Russia's State Duma adopted a comprehensive law governing cryptocurrency circulation, set to take effect September 1, 2026. The law lets both qualified and non-qualified investors trade cryptocurrencies through licensed intermediaries, caps annual purchases for non-qualified investors at 300,000 rubles, and still bans using crypto for domestic payments while allowing unrestricted use in cross-border trade settlements. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.cbr.ru/eng/press/event/?id=32724">Bank of Russia</a>)</p><h1 id="h-capital-allocation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Capital Allocation</h1><p><strong>MoonPay Buys Glide for Deposit Routing</strong></p><p>On July 16 MoonPay acquired Y Combinator-backed Glide in an all-equity deal; Glide’s four-person team joins MoonPay. Founded by former Robinhood Wallet engineers, Glide routes deposits across 100+ tokens and 30 chains into apps including Wallet in Telegram, Moonshot, and Paysafe. Terms were not disclosed. It is MoonPay’s sixth acquisition announcement of 2026. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://cointelegraph.com/news/moonpay-acquires-glide-strengthen-crypto-deposits">Cointelegraph</a>)</p><p><strong>Cyclops raises $20M Series A </strong></p><p>Cyclops announced a $20 million Series A led by Nava Ventures on July 15, with Coinbase Ventures, Castle Island Ventures, Circle Ventures, GPT Ventures, Lasagna Ventures, F-Prime Capital, OpenFX, and Global PayTech Ventures participating. The Miami team sells one API for stablecoin settlement, payins, payouts, and treasury to payments companies, and says it orchestrates specialist vendors rather than rebuilding every layer. The post cites volume growing 350% month over month, a partner licensing network of 100+ licenses, and hires from Coinbase, Fiserv, Shift4, JPMorgan, and Paysafe, including Coinbase’s former global CCO leading compliance. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.cyclops.io/post/cyclops-20m-series-a-building-the-new-backbone-of-global-payments">Cyclops</a>)</p><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research</h1><p><strong>Agentic Attack Synthesis and Simulation for Smart Contracts</strong></p><p>KASS, a multi-agent system that plans attacks from audit knowledge, emits constrained Foundry tests, and repairs failures with nested code and strategy loops. On 104 SmartBugs-Curated contracts it produced working exploits for 94.23% of cases, beating the authors’ same-protocol Claude Code baseline and earlier REX/AdvSCanner numbers on similar sets. It validated 9 of 11 CVE-tagged contracts and can drop static findings that never produce runnable impact. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2607.15673">arXiv</a>) </p><p><strong>x402 Facilitators are Shared Payment Infrastructure and Shared Risk</strong></p><p>This paper looks at x402, which extends HTTP 402 so APIs and AI agents negotiate payment and hand proof checks plus on-chain settlement to third-party facilitators. Those facilitators sit under many merchants at once, so one validation bug can hit many services. The authors argue live mainnet deployments are still poorly measured relative to how fast the protocol is being adopted. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2607.19545">arXiv</a>)</p>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>crypto</category>
            <category>hacks</category>
            <category>regulations</category>
            <category>security</category>
            <category>cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[0x42 Web3 Security Bulletin]]></title>
            <link>https://paragraph.com/@w3sb/0x42-web3-security-bulletin</link>
            <guid>7v5mCufrTIKGYJScrC4P</guid>
            <pubDate>Fri, 17 Jul 2026 09:42:54 GMT</pubDate>
            <description><![CDATA[Intelligence for Web3, digital asset infrastructure, and the capital shaping the industry. ]]></description>
            <content:encoded><![CDATA[<p>TL;DR</p><ul><li><p>Nethermind shows where AI belongs in audits: not replacing senior judgment, but catching mechanical inconsistencies humans can miss. The useful model is AI doing consistency work while auditors focus on attack paths, exploitability, and impact.</p></li><li><p>This week’s incidents are mostly control failures hiding inside trusted plumbing: Ostium’s oracle automation accepted future-dated reports, Bonzo’s verifier accepted a zero BLS key, and Injective’s compromised SDK used fake telemetry to steal wallet material.</p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://LI.FI">LI.FI</a> selected Hypernative to screen tokens across 60+ chains, adding approve-or-deny risk signals for every token routed through its liquidity infrastructure.</p></li><li><p>Policy and capital keep moving toward institutional rails: U.S./UK agencies are coordinating on digital assets and market structure, OFAC is turning stablecoin traceability into sanctions pressure, and Velocity’s $38M raise shows stablecoin treasury infrastructure is still getting funded. </p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis</h1><p><strong>AI’s Role in Security Audits</strong></p><p>Utku Kocakulak shows how Nethermind’s AuditAgent uncovered a subtle integer-overflow bug in accounting logic that multiple human audits had missed, simply by flagging a parenthesis mismatch between two near-identical calculations. The article argues that AI is best used for mechanical consistency checks, while senior auditors focus on attack-path analysis and impact, framing the future as “elite auditors augmented by AI” rather than AI replacing human expertise. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.nethermind.io/blog/where-ai-belongs-in-a-security-audit">Nethermind</a>)</p><p><strong>Blockchain Forks Explained: Soft vs Hard</strong></p><p>CyberScope explains how protocol upgrades create blockchain forks, distinguishing backward-compatible soft forks from hard forks that can split a network into competing chains with shared history but divergent rules. The article shows how governance processes and scheduled block-height activations determine whether changes become smooth upgrades or contentious chain splits with security and compliance implications for applications and exchanges. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.cyberscope.io/blog/blockchain-forks-explained">CyberScope</a>)</p><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements</h1><p><strong>LI.FI Integrates Hypernative Token Screening Across 60+ Chains</strong></p><p>LI.FI, the cross-chain liquidity router serving more than 1,000 integration partners, will use Hypernative Token Screening to flag scam tokens, rug pulls, and other fraudulent assets before they reach users. LI.FI screens its full token database and calls the Hypernative API whenever a new token is added, passing integrators a binary approve-or-deny recommendation alongside existing metadata. Hypernative scores contracts, holder concentration, DEX and CEX activity, deployer reputation, and social verification. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.hypernative.io/insights/blog/li-fi-selects-hypernative-to-screen-tokens-spanning-60-chains">Hypernative</a>)</p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents</h1><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>2026 hacks: 190</p><p>Total amount lost in 2026: $992,577,108</p><p><strong>Ostium Loses Over $18M After an Attacker Submitted Future-dated Oracle Reports</strong></p><p>An attacker pulled about $18M in USDC from Ostium's Arbitrum vault by abusing a registered PriceUpKeep forwarder in the protocol's Gelato price automation. Future-dated reports made losing trades look profitable and triggered the payout. Blockaid flagged the transaction. </p><div data-type="twitter" tweetid="2077405527428989363">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/blockaid_">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/7500dc4370bee4de3e033832aef828a1fa1f962fa7a0a773aebddf8c7dfe6e5a.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/blockaid_" class="twitter-displayname">Blockaid</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/blockaid_" class="twitter-username">@blockaid_</a></p>
    
            </div>
            <a href="https://twitter.com/blockaid_/status/2077405527428989363" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      <img class="twitter-emoji" draggable="false" alt="🚨" src="https://abs-0.twimg.com/emoji/v2/72x72/1f6a8.png"> Blockaid detected an <a class="twitter-content-link" href="https://twitter.com/Ostium" target="_blank">@Ostium</a> Vault exploit on Arbitrum.<br><br>An attacker used a registered PriceUpKeep forwarder and future-dated authorized oracle reports to create artificial trade profit, triggering a ~$18M USDC payout from the vault.<br>More details in <img class="twitter-emoji" draggable="false" alt="🧵" src="https://abs-0.twimg.com/emoji/v2/72x72/1f9f5.png">
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/blockaid_/status/2077405527428989363" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            379
          </a>
          <a target="_blank" href="https://twitter.com/blockaid_/status/2077405527428989363"><p>2:50 PM • Jul 15, 2026</p></a>
        </div>
    
  </div> 
  </div><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hack-trail.vercel.app/incident/ostium-olp">HackTrail</a> maps the drain, step-by-step: </p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/1fc9f7a2c534977a38e5b77ce4685fdc7197fcdaa26ac35227119b288fadb88a.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAATCAIAAAB+9pigAAAACXBIWXMAABYlAAAWJQFJUiTwAAAEOUlEQVR4nHVVXU/bVhjmchOtFiEF1SEQ4q84TsgH2BATIARWpyQmLZAySiRUodELaLcht2EXcQJFeNE2yTSwblFQU5ymfCRk2tZlFVtRLkDtJk3azS52t/+wH7DJOczyQiY9sp7zHsuP3/c873uahsfGqV6PjbQTBOlwuDDMgmJ4aPa2Ccb0+lYACIJUrgkatEszjDRE0+ziR31eH0mSVqtNFTj+5bf83uHyB8uCkBSEJM/HBCEpiilJSotianHxniimlpY+lKRNdddqtTUWIO1dKIbXRVk2OHd7YeHu8sTkTY4Ls2yA48IqwBI8QyEOEDOMQJChvb1DC0WA/3Sb5W50u7u7eyiG8eK4BcUsyS9y618+/en3Pwf9VzHM0tXltFptAA6Hy+FwaQkARdEM46UomqJon8/v8/kpilYEYBjuaDdpZXHc8nB1bf/5/v7z/UJ+7+yHV6+rZ6VS+c2bn3d386VSuVg8kuWCJKVluQAgSelMJivLBVFMyXKhUjkulcobG6LZDDfZnW6CIDHMAmCGERTD3bQHJ0g37WkzGE2Q0QgZjEZFW6draQi9vvViBIIMSgb31j/3B4Iup9vhcDFMf+2QLZ/l9r46/PaPv/4OR24NDg6NvssyjBckrgXLBhpGOC4M6qMI4IS17pARGE19ktp6tL31aPtZ5smB/AwUoeaiTUlKb2yIslzIZLKSlBaEJIhkMtnd3TyIFItHLBs4P+SLFkJglCRIBMGuXIGITqTd0GY0Kq+CxFVoK6NGdLoWCDIAO51nsBCaHBkYovs8LqebYbwEQaIIuvUgcWdu/sbE5LXg+Hszs/7hEY4LR6NzHBeORKbVJ8eFp6YiU1MRwKPRuUhkWv30uQCC1meAYvjKg49XE2s8H1t4/44gJKPROZ6P8Xxsfn6hRu4vLi4BUoOyFY8nQA/WC9y6Ghz2DqoZWAgriqDLU9E+NwXDKI4r1rJabcBggDSEGUZU5/xHwEbawbYKDLMclL/O7x0+zu7knirGr1ZPq9XTTCZbrZ5WKsf5/AEw+8lJ9eSkWiweFYtHPB+r+/dzgbH+oX7a091DORyuXrpXsSmCDticvYT9umewDTK89XazTtdy6dI7Ol1Lc/Pl5ubLWgI4ONvGs4jpoe02JQlQCjOM4Ljl5LuXL4vf/PrqLLeTe/GiojZtJpOtVI7j8USpVC6VyjX7boK+VX1ZL9ABIx2mTu2oQDE8OH59NHCNDXE+n39+Yob1j05M3oxEptWBwzBeAJX/7zQdG/AzfQyYXBRFgxL129wDzp7Z4UBnu0mvbzUY2oC7L94K2usBoF4gODTidrjAOAImQWA0l35clvdef/9jbif3cH1jNbEGWlQQkqBWopji+di/7Z1WW5rnY3WWaTLBaKcZMXWYtS7iV1ZmwpPi3fvBUDgeT3BcGMwiUA1AamN5WMPPx1GdwD/9KenUF7SWYwAAAABJRU5ErkJggg==" nextheight="1014" nextwidth="1752" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Ostium runs RWA perpetuals, had processed over $50 billion in volume, and raised $27.8 million, including a Series A co-led by General Catalyst and Jump Crypto. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi">CoinDesk</a>)</p><p><strong>Bonzo Lost $9M Because Supra's Verifier Treated Zero as a Valid BLS Key</strong> </p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://rekt.news">rekt.news</a> walked through the July 11 Bonzo Lend exploit on Hedera: Supra's pull-oracle verifier accepted a zeroed signature with a zeroed public key, the BLS identity element, so the pairing check passed without a real committee attestation. The attacker deposited about 250 SAUCE (a few dollars), inflated the SAUCE/wHBAR feed, and borrowed roughly $9.05 million in USDC and wrapped HBAR in eight seconds. Supra said the broken verifier had been live for about two years; an identity-element check alone would have stopped it. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rekt.news/bonzo-finance-rekt">rekt</a>)</p><p><strong>Injective SDK NPM Package Steals Wallet Keys via Fake Telemetry </strong></p><p>Socket reported July 9 that <code>@injectivelabs/sdk-ts@1.20.21</code> was published from a compromised Injective Labs contributor GitHub account with hooks on <code>fromMnemonic</code> and <code>fromHex</code> that log keys and mnemonics through a fake <code>trackKeyDerivation</code> telemetry path. The payload base64-encodes the material and POSTs it to an obfuscated Injective public gRPC-web endpoint so traffic blends with normal SDK use; 17 other <code>@injectivelabs</code> packages at 1.20.21 pinned the malicious SDK. The account owner reverted within about an hour and shipped clean 1.20.23, but npm only deprecated 1.20.21 after 310 downloads, and GitHub release artifacts remained available. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://socket.dev/blog/compromised-injective-sdk-npm-package">Socket</a>)</p><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation</h1><p><strong>U.S. and UK Release Transatlantic Taskforce Recommendations on Digital Assets and Capital Markets</strong></p><p>The U.S. Department of the Treasury and HM Treasury published July 14 the Transatlantic Taskforce for Markets of the Future recommendations, co-announced by Secretary Scott Bessent and Chancellor Rachel Reeves after the September 2025 State Visit. On digital assets, BoE, CFTC, FCA, and SEC staff will seek common approaches to tokenized-securities settlement finality and whether stablecoins or tokenized money market funds can serve as CCP margin collateral; the governments also backed a multi-money mix of stablecoins, tokenized deposits, and other digital money, plus a Basel review of cryptoasset prudential standards. The same day they issued a joint stablecoin statement affirming 1:1 high-quality reserves, reserve segregation, and work toward cross-border market access without mutual recognition of each other's licenses. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://home.treasury.gov/system/files/136/TTMFRecommendations.pdf">U.S. Department of the Treasury</a>)</p><p><strong>OFAC Freezes $131M in Iran Central Bank Stablecoins</strong></p><p>OFAC expanded sanctions on Iran’s Central Bank by designating four crypto wallets that together received $165M in stablecoins, prompting Tether to immediately freeze $131M in balances. The analysis shows how Iran’s reliance on stablecoins for sanctions evasion and funding has become a vulnerability, with nearly $475M in Central Bank-linked Tether now blocked and on-chain tracing revealing upstream institutional liquidity providers and payment processors. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/ofac-sanctions-iran-central-bank-crypto-wallets-freezing-131m-in-stablecoins">Chainalysis</a>) </p><h2 id="h-legislative-watch" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Legislative Watch</h2><div data-type="twitter" tweetid="2077019696449061176">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/SenLummis">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/0a3751ef66537911812f0b750ac7b416d2e54c3cf1a823388aa33173041150c0.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/SenLummis" class="twitter-displayname">Senator Cynthia Lummis</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/SenLummis" class="twitter-username">@SenLummis</a></p>
    
            </div>
            <a href="https://twitter.com/SenLummis/status/2077019696449061176" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      We've been working on the Clarity Act every day for 10 months, and we'll introduce bill text in the next few days — it's time to land this plane. This is about helping law enforcement fight illicit finance, passing consumer protections and keeping these markets onshore in the US. 
      <div class="twitter-media">
      <img class="twitter-image" src="https://pbs.twimg.com/amplify_video_thumb/2077018815272026112/img/EJU9IT-AFnxADI0W.jpg">
    </div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/SenLummis/status/2077019696449061176" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            7,794
          </a>
          <a target="_blank" href="https://twitter.com/SenLummis/status/2077019696449061176"><p>1:17 PM • Jul 14, 2026</p></a>
        </div>
    
  </div> 
  </div><h1 id="h-capital-allocation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Capital Allocation</h1><p><strong>Velocity Raises $38M Series A </strong></p><p>Velocity announced July 14 a $38M Series A led by Dragonfly and FirstMark, with Activant Capital, Capital One Ventures, QED Investors, Coinbase Ventures, Wintermute Ventures, and Ripple participating, bringing total capital raised to nearly $50M since May 2025. The London-based stablecoin treasury and settlement platform targets CFOs and treasury teams at merchants, payment providers, fintechs, and financial institutions, combining stablecoin rails with local banking, compliance, custody, and settlement orchestration. Funding will expand its banking and payments network, product work, and regulatory capabilities as enterprises push stablecoins into liquidity management and cross-border settlement. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.velocity.xyz/blog-post/series-a">Velocity</a>)</p><br>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>security</category>
            <category>crypto</category>
            <category>cybersecurity</category>
            <category>regulations</category>
            <category>hacks</category>
        </item>
        <item>
            <title><![CDATA[0x41 Web3 Security Bulletin]]></title>
            <link>https://paragraph.com/@w3sb/0x41-web3-security-bulletin</link>
            <guid>wUJg4fIqDLeLlCwZn7s0</guid>
            <pubDate>Fri, 10 Jul 2026 09:24:42 GMT</pubDate>
            <description><![CDATA[Intelligence for Web3, digital asset infrastructure, and the capital shaping the industry.]]></description>
            <content:encoded><![CDATA[<p>TL;DR</p><ul><li><p><strong>Security failures are moving beyond smart contracts.</strong> This week’s incidents show losses coming from governance capture, stale accounting assumptions, weak wallet generation, and frontend or operational control gaps. </p></li><li><p><strong>Governance is now an attack surface.</strong> BonkDAO's $20M loss shows that attackers can drain treasuries through vote buying and proposal execution without exploiting contract code.</p></li><li><p><strong>Accounting assumptions can become exploit paths.</strong> Summer.fi’s vault drain shows how stale NAV inputs and deprecated strategy components can turn into direct user losses.</p></li><li><p><strong>Wallet generation failures are still catastrophic.</strong> Ill Bloom is a reminder that weak randomness can leave keys enumerable for years, across multiple chains, before users know they are exposed. </p></li><li><p><strong>Regulation is turning into infrastructure pressure.</strong> The UK, EU, SEC, and Kraken stories all point toward the same future: stablecoins, custody, trading, and exchange operations will need banking-grade controls and clearer supervisory models.</p></li><li><p><strong>Institutional capital is backing regulated crypto rails.</strong> Paradigm and EDX show that serious money is still flowing into digital-asset infrastructure, especially where security, compliance, and market structure can support larger institutions.</p></li><li><p><strong>Privacy is becoming a wallet-layer problem.</strong> Browser-extension research shows that users can be deanonymized through RPC routing, fingerprinting, and telemetry even when on-chain activity appears pseudonymous.</p></li><li><p><strong>The strongest teams will connect research to controls.</strong> Formal verification, blockchain attack taxonomies, wallet privacy studies, and chain-abstraction work only matter if they become tests, monitoring, governance rules, and design requirements. </p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis</h1><p><strong>From CertiPlonk to zkVMs: Verifying RISC‑V Conformance</strong></p><p>Nethermind’s research team explains how CertiPlonk‑style formal verification scales to three RISC‑V zkVM implementations: OpenVM, Brevis Pico, and Plonky3’s Poseidon2, by modeling buses in Lean and proving per‑opcode equivalence theorems. The post shows that once memory consistency is derived formally, proofs can be reused across forks, turning labor‑intensive circuit audits into reusable assurance for production zk systems. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.nethermind.io/blog/from-certiplonk-to-zkvms-shared-methodologies-for-verifying-risc-v-conformance">Nethermind</a>) </p><p><strong>Questions About AI in Compliance That Nobody Can Answer </strong></p><p>Elliptic explores unresolved questions around deploying AI in financial crime compliance, including accountability, explainability, and regulatory expectations for model governance. </p><blockquote><p>If a regulator examined your AI governance tomorrow, what would it actually show? How well documented is it and how effective has it been at stopping bad things from reaching your organization?</p></blockquote><p>The post argues that while AI can enhance detection, institutions still lack clear answers on liability, audit trails, and how supervisors will assess AI‑driven decision‑making. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.elliptic.co/blog/the-questions-about-ai-in-compliance-that-nobody-can-answer-yet">Elliptic</a>)</p><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements</h1><p><strong>Breadth, Depth, and Quality in Blockchain Analytics</strong></p><p>Chainalysis argues that comparing blockchain analytics vendors purely by cluster count misses what matters most: how addresses are grouped and how reliably those clusters are attributed to real‑world entities. The article urges compliance teams to ask whether groupings are deterministic, auditable, and structurally independent of labels, and if operator–beneficiary distinctions are captured to avoid false positives in investigations. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/comparing-blockchain-analytics-vendors/">Chainalysis</a>) </p><p><strong>EMURGO Steps Down from Cardano Pentad Governance After SecondFi Exploit</strong></p><p>EMURGO, one of Cardano's three founding entities and developer of the SecondFi wallet, is leaving the Pentad governance coalition to focus on recovering user funds from last month's exploit. The group said stepping aside reflects accountability owed as a founding entity while it runs a dedicated asset-recovery team. </p><div data-type="twitter" tweetid="2074074175485165989">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/emurgo_io">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/722c887a4379914229a577010224c0508a919feeb6fa2aca5f43f17d5fc84557.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/emurgo_io" class="twitter-displayname">EMURGO</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/emurgo_io" class="twitter-username">@emurgo_io</a></p>
    
            </div>
            <a href="https://twitter.com/emurgo_io/status/2074074175485165989" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      <a class="twitter-content-link" href="https://t.co/bTjxCIgt7v" target="_blank">x.com/i/article/2074…</a>
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/emurgo_io/status/2074074175485165989" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            177
          </a>
          <a target="_blank" href="https://twitter.com/emurgo_io/status/2074074175485165989"><p>10:13 AM • Jul 6, 2026</p></a>
        </div>
    
  </div> 
  </div><p>Pentad, formed earlier in 2026, coordinates treasury-backed infrastructure work among Input Output Global, the Cardano Foundation, Intersect, the Midnight Foundation, and EMURGO. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.theblock.co/post/407593/cardano-founding-entity-emurgo-steps-down-pentad-governance-role-wallet-exploit">The Block</a>)</p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents </h1><p><strong>BonkDAO Loses $20M to a Malicious Governance Vote</strong></p><p>BonkDAO, the DAO behind Solana memecoin BONK, said a malicious governance proposal drained an estimated $20M in BONK from its treasury all without touching contract code. BonkDAO said the attacker bought BONK on exchanges ahead of the vote, the DAO has notified law enforcement, and is working with exchanges, bridges, and the Solana Foundation on recovery. The attack follows a June Balancer governance takeover that drained $1.58M, adding to a run of  governance-linked losses in 2026. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://thedefiant.io/news/hacks/bonkdao-treasury-drained-of-20m-via-malicious-proposal">The Defiant</a>)</p><p><strong>Chainalysis Traces BonkDAO Heist into a Shadow "BONK 2.0" Multisig</strong></p><p>Chainalysis found that the wallet behind BonkDAO's governance attack parked roughly $19M of stolen BONK in a new multisig it calls "BONK 2.0," controlled by the malicious voter, the exploiter wallet, and a third financially linked address. </p><div data-type="twitter" tweetid="2074315255317155987">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/chainalysis">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/c81712fd55445db4be33fb6bbaf5a98d7b2872ca449ea74a1ab41b56fdaf8ad6.png">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/chainalysis" class="twitter-displayname">Chainalysis</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/chainalysis" class="twitter-username">@chainalysis</a></p>
    
            </div>
            <a href="https://twitter.com/chainalysis/status/2074315255317155987" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      BONK DAO’s $20 million loss saw the attacker put millions of dollars on the line. Our investigation maps out the financial coordination behind today’s governance attack, from the days-long BONK spree that preceded it to the liquidation rush that followed. <img class="twitter-emoji" draggable="false" alt="🧵" src="https://abs-0.twimg.com/emoji/v2/72x72/1f9f5.png"> 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/055a79f7970db2da5127dd2360d110c4997e3701e1589b15af66769fe1b39eab.jpg"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/chainalysis/status/2074315255317155987" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            35
          </a>
          <a target="_blank" href="https://twitter.com/chainalysis/status/2074315255317155987"><p>2:11 AM • Jul 7, 2026</p></a>
        </div>
    
  </div> 
  </div><p>The firm traced a June 30 treasury-drain proposal, $8M in exchange purchases plus DeFi borrowing on July 4–5 to reach the 1% BONK vote threshold, and a July 6 execution that sent about $188,000 to an exchange before the rest landed in the shadow DAO treasury. An hour after the drain, the voter wallet sold $5.3M of its voting stake. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://thedefiant.io/news/hacks/bonkdao-attacker-moves-19m-loot-into-new-bonk-2-0-dao">The Defiant</a>)</p><p><strong>Summer.fi Post-mortem Blames Stale NAV Pricing for $6M Vault Drain</strong> </p><p>Summer.fi said in an X post-mortem that on July 6 an attacker manipulated share prices on two Lazy Summer Protocol USDC vaults on Ethereum mainnet and extracted about $6.04M of depositor value in one atomic transaction. </p><div data-type="twitter" tweetid="2074214443261509721">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/summerfinance_">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/cb0d8cb4b7f9a31b988c2127195a9e79a0b5331d190d54adfed6551ab291c5b5.png">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/summerfinance_" class="twitter-displayname">Summer.fi ☀</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/summerfinance_" class="twitter-username">@summerfinance_</a></p>
    
            </div>
            <a href="https://twitter.com/summerfinance_/status/2074214443261509721" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      <img class="twitter-emoji" draggable="false" alt="⚠️" src="https://abs-0.twimg.com/emoji/v2/72x72/26a0.png"> Security Notice<br>We identified an active exploit affecting the Lazy Summer Protocol earlier today. As a precaution, Guardians have paused all vaults and set deposit caps to zero across networks.<br><br>The situation is being actively assessed. Please do not interact with the protocol
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/summerfinance_/status/2074214443261509721" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            24
          </a>
          <a target="_blank" href="https://twitter.com/summerfinance_/status/2074214443261509721"><p>7:30 PM • Jul 6, 2026</p></a>
        </div>
    
  </div> 
  </div><p>The team attributed the loss to donating Silo "Varlamore" tokens that still carried stale November 2025 Stream Finance valuations into a strategy module slated for removal but still counted in net asset value, inflating the share price roughly 9.5% before the attacker redeemed about $71M against a $64.8M deposit. Summer.fi paused all vaults via the DAO Guardian multisig.  (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/summerfinance_/status/2074522409869115468">Summer.fi on X</a>)</p><p><strong>Analysis: Ill Bloom Weak-seed Wallet Drainer </strong></p><p>Ill Bloom documents a wallet-generation flaw where weak randomness during recovery-phrase creation left keys enumerable across Bitcoin, Ethereum, Tron, Rootstock, and Polygon. As of June 30 Coinspect tracked 2,114 active addresses in its first exposed set; a coordinated May 27 sweep drained 431 accounts for about $3.14M, mostly Bitcoin ($2.57M). </p><div data-type="twitter" tweetid="2073935687770890458">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/coinspect">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/0f84346090cbe18e82a4d9ccb1a8858d477c9963d0fef9bfdc8166389cb93d54.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/coinspect" class="twitter-displayname">Coinspect Security</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/coinspect" class="twitter-username">@coinspect</a></p>
    
            </div>
            <a href="https://twitter.com/coinspect/status/2073935687770890458" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      Today we are publishing the first Ill Bloom findings:  affected-address checker + on-chain analysis to help users identify exposed addresses and protect their assets.<br><img class="twitter-emoji" draggable="false" alt="🔗" src="https://abs-0.twimg.com/emoji/v2/72x72/1f517.png"> <a class="twitter-content-link" href="https://t.co/U0b4f3jtgz" target="_blank">illbloom.org</a><br><img class="twitter-emoji" draggable="false" alt="⚠️" src="https://abs-0.twimg.com/emoji/v2/72x72/26a0.png"> We will never ask for seed phrases, private keys, signatures, or approvals, or ask
      
      
        <a class="twitter-card-link" href="https://t.co/U0b4f3jtgz" target="_blank">
          <div class="twitter-media twitter-summary-large-image">
            <img src="https://storage.googleapis.com/papyrus_images/aab12628a0a1c7103b3425e98fafbed1e604a40e6e410c10d901a8f0d7388e57.jpg">
            <div class="twitter-summary-card-text">
              <span>illbloom.org</span>
              <h2>Ill Bloom Disclosure</h2>
              <p>Ill Bloom is an actively exploited wallet generation vulnerability that can let attackers take control of affected crypto wallets and drain funds.</p>
            </div>
          </div>
        </a>
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/coinspect/status/2073935687770890458" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            74
          </a>
          <a target="_blank" href="https://twitter.com/coinspect/status/2073935687770890458"><p>1:02 AM • Jul 6, 2026</p></a>
        </div>
    
  </div> 
  </div><p>Peak historical exposure hit roughly $12.56M in April 2022. New weak-key wallets kept receiving funds through 2025 and into 2026, and Coinspect says the count is still rising. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://illbloom.org/articles/chain-analysis/">Ill Bloom</a>)</p><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>2026 hacks: 187</p><p>Total amount lost in 2026: $983,248,608</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/5e120c76e97959d896bfc2188bcde2753cc82bac0fc3bfca4d9a8e67dfce2375.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAICAIAAAAX52r4AAAACXBIWXMAABYlAAAWJQFJUiTwAAABw0lEQVR4nJWRPUgbYRjHny4OLmaoIcUvBKHoIn5UtEg1NuggGO2QVCgHiR8hMRla8RSHW9xj19LCOx66ZHF4Bwc5BKMHJQkhaXImKRIuOBiHezmi3stTJEuhDZof/+nhDz8e/iDLsiiKlFJENBuQuIjfVqsW53FFOVNOLM5vq1XzeQAhRBAEQohpmuVy+eYfDMbG+vqymYzF+W4k8sXvtziv6PrNM3gURKNRj8fTSFDRdYOxoe7uumA7FNwKBJoTUEpFUZRl2TTN/5YMxvodjrrg89rK5vpq0wJJkmKxWKMNLM77HY7fxSIihgRhKxBAxOY2cLvdhBBENBi7f3gwGPs7rFbrbGkpFgoW52te7044bHFe/+zJWJzDqaJIknR4cCB//5FUVd/i4vHR0XVFL+Ry+tXVt/39fDr9EqCUzyFir61tOxS8q9Xy6XRJ07KpVFJVM8lE4iKeTaWuK3pSVb/u7ZU07fJXtqRpP8/PAREppbNOp3N4xAbQBvC6q3NuampleXly9M274aGJwcGxgYFPSx8W5mYBoMfeLkbCHTbb48X1/lVrq2d+HgD8H73T4+MLLtcLgJm3Exs+X4/dHvT7/gDDu0sEZ3PZhgAAAABJRU5ErkJggg==" nextheight="574" nextwidth="2206" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation</h1><p><strong>How the UK’s Stablecoin Rules Came Together</strong></p><p>Elliptic traces the policy and consultation process that led to the UK’s stablecoin rules, from early proposals to final regulatory texts. The article focuses on how industry feedback, prudential concerns, and consumer‑protection goals shaped the final regime, giving compliance leaders useful context for upcoming supervision. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.elliptic.co/blog/how-uk-stablecoin-rules-came-together">Elliptic</a>) </p><p><strong>SEC Schedules Three Crypto Rulemakings for 2026 Agenda</strong></p><p>The SEC placed three crypto-focused items on its 2026 Unified Regulatory Agenda, each at proposed-rule stage with a July target for notices of proposed rulemaking. The Crypto Assets rule (RIN 3235-AN38) would address digital-asset offers and sales, potentially including exemptions and safe harbors. A broker-dealer item (RIN 3235-AN48) would amend net-capital and customer-protection rules for crypto custody, and Crypto Market Structure Amendments (RIN 3235-AN49) would cover trading on alternative trading systems and national exchanges. Congress is still negotiating the CLARITY Act ahead of an August recess deadline. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://thedefiant.io/converge/regulation/sec-adds-three-crypto-rules-to-2026-regulatory-agenda">The Defiant</a>) </p><p><strong>EU Plans MiCA Revision in 2027 to Cover non-EU Stablecoin Issuers</strong> </p><p>The European Union will revisit Markets in Crypto-Assets regulation as early as 2027, with EU diplomats saying a reopening looks unavoidable after MiCA's July 1 licensing cliff and pressure from U.S. stablecoin policy under the GENIUS Act. The European <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://finance.ec.europa.eu/regulation-and-supervision/consultations-0/targeted-consultation-review-mica-regulation_en">Commission is consulting stakeholders through September 30</a> on extending rules to non-EU issuers serving European customers, tokenized payments, and deposits. Diplomats cited ECB concerns and the complexity of regulating dollar-backed stablecoins with multiple issuers, as the transatlantic regulatory gap widens. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.euronews.com/my-europe/2026/07/08/exclusive-eu-to-revise-crypto-rules-in-2027-amid-trumps-push-for-digital-assets">Euronews</a>) </p><p><strong>Kraken Pursues Full European Banking License </strong></p><p>Kraken is seeking a full banking license in Europe, with Lithuania as the target jurisdiction, following the same specialized-bank path Revolut took in 2018 through the Bank of Lithuania. A person familiar with the plans said Payward, Kraken's parent, is building licenses globally over the next decade through acquisitions or de novo applications; Kraken Financial already gained Federal Reserve payment-rail access in March 2026 and VARA authorization in the UAE in May. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.coindesk.com/business/2026/07/07/crypto-exchange-kraken-is-trying-to-become-a-bank-in-europe">CoinDesk</a>)</p><h2 id="h-legislative-watch" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Legislative Watch</h2><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/99f2adbe56856e439ae433c9b3a2e59316b54f2ded5b0269398e57e1704640bb.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAARCAIAAAAzPjmrAAAACXBIWXMAAAsTAAALEwEAmpwYAAADJklEQVR4nLWUf0gTYRjHD/onif6YkEL7QySwP4zUoD/yj6gRKoZEhKJYqYNMHEYgTZNxbIQbuSXRVNSROsFGaT+0FLZlykImhpeL3YJ5guzSuZtLdx52S9wTtzeuqYiW9OE43vfe932+z/M+z3NYQuJxLEZoOeSdpSiK+uJ2w+6E9w0AUBSFiRSX3DiccPTCxYtZWWcUCkVOTk5JSUmZQLlCoaivr8/Ly0tLO+l0OmHf0DSN3SwtRAJ1dcqkY4mpqakZmZlSqRTDMIlEkp6eLpVKk5OTZTLZsaQkDMMIgvg7gbfDYw+aOi39IxptW0/foMvlWV7y/4xE4F8Jx2CYIACQpAdr7eiTV6mUDfrcK7cKCqvNvQNTY6NLi35+F2AvbLb34+MOm82+FGBsNjuGsvGfIAgCY5jgZjTK8xH0bPzc4NY4luUAgOcj4nsnaP/eAmIESAYA7GOTlv4R0kN5Z+eRoc1oVFRCYwBYWWVZlhNPid+3C+Aao4/2x3vU+2yo2WhWN7ZW1qhJD+Vyez/PeHg+4qP9PtqPgltZDavUT67L60SNbeGuc+u/BW7X4MNWBwCoG1vlVaqFhUBbp+VOrVaSkj1NkDqDSdlgaOmwWO0Ttff1XeZXaLPOYDp7vkiSkl1cfk+jbZsmSDFcMeI/Ahh2AgAyzl0tKKzGNcaHj57Kq1SY5BQAtJueU3M+WX5FZ/fAi5dWl9v7emgUXePnGU+ACTUbzUekZ0+czlU2GHy03+X2AkCACTk+fooJzAh9cCgps7PrxbhjKsCEVlZZAHjc0jv47oMYsmNimmU5NLbaJ2T5FTqDCflIzflEpcoadVFZrc5gajaaL12Wr//ghQgAoKXDIq9SCRf3gxfLKf5ON6NRMZksy+kMpm1lxvMRdHbet6hs0F8rvavRtq2ssiRJClXE85FwmI0NhD5Ctrg1bmtF8ltrdPtUdGszGg0GvyMPnM5JIQIEwzDxTUfTdLwJJm6VZbmdq8giywo9JE6FHBAEYY3x1eNhmOBSIEDT38JhIRMHR/jZ4TheEAPH8e7unvb29odN+jdDQyRJEgeDJEmr1foLkuVLP6HTcxAAAAAASUVORK5CYII=" nextheight="988" nextwidth="1888" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://polymarket.com/event/clarity-act-signed-into-law-in-2026">Polymarket</a>)</figcaption></figure><h1 id="h-capital-allocation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Capital Allocation</h1><p><strong>Paradigm Closes $1.2B Fourth Fund Across Crypto, AI, and Robotics</strong> </p><p>Paradigm raised a $1.2B Fund IV to back founders at the frontier of crypto, AI, robotics, and other emerging tech. The firm named crypto bets including Hyperliquid, Stripe co-founded stablecoin blockchain Tempo, and prediction-market platform Kalshi, alongside non-crypto portfolio companies such as Zipline, SendCutSend, True Anomaly, and Nous Research. Paradigm also highlighted open-source work on blockchain tooling (Foundry, Reth), agent infrastructure (Centaur), and the EVMbench smart-contract security benchmark built with OpenAI. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.paradigm.xyz/writing/announcing-our-fourth-fund">Paradigm</a>) </p><p><strong>EDX Markets Raises a $76M Series C </strong></p><p>EDX Markets closed a $76M Series C led by Japan's SBI Holdings to expand institutional trading, clearing, and settlement infrastructure. CEO Tony Acuña-Rohter said SBI's global financial network will help scale regulated digital-asset products; SBI chairman Yoshitaka Kitao cited EDX's compliance-focused platform as a foundation for institutional adoption alongside SBI's yen stablecoin JPYSC and U.S. dollar stablecoin handling. EDX, backed by Citadel Securities, Fidelity, and Charles Schwab, recently launched FlowConnect crypto-as-a-service and filed to establish EDX Trust as a proposed OCC national trust bank. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.prnewswire.com/news-releases/edx-markets-closes-76-million-series-c-funding-round-led-by-sbi-holdings-to-enhance-institutional-digital-asset-infrastructure-302819428.html">PRN</a>)</p><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research</h1><p><strong>Browser-extension Wallets Leak Privacy </strong></p><p>Researchers audit privacy threats in Web3 browser-extension wallets, documenting how extensions expose browsing patterns, RPC endpoints, and transaction metadata that can deanonymize users even when on-chain activity looks opaque. The authors propose wallet-side mitigations including stricter RPC routing and reduced third-party telemetry. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2607.06141">arXiv</a>)</p><p><strong>A Survey Maps Blockchain Attack Surfaces from Cryptography to Apps</strong> </p><p>Researchers publish a cross-domain taxonomy of blockchain attacks and defenses, spanning the data and cryptographic layer, network and consensus layers, smart-contract execution, and application logic. The paper links historical incidents to recurring failure classes including key compromise, eclipse attacks, and cross-layer trust assumptions. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/html/2607.06593v1">arXiv</a>) </p><p><strong>Crossroads: A Smart Contract Layer for Chain-Abstracted Assets</strong></p><p>James Austgen, Dani Vilardell, and Ari Juels present Crossroads, a smart contract layer designed to secure assets that move across chain-abstraction protocols, a growing category in multi-chain DeFi. The paper addresses new attack surfaces created as ecosystems increasingly bridge assets between Ethereum, Solana, and other major chains. Their design offers a security-first approach to an area that has seen frequent bridge exploits. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://arxiv.org/abs/2607.06525">arXiv</a>)</p>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>crypto</category>
            <category>hacks</category>
            <category>security</category>
            <category>cybersecurity</category>
            <category>regulations</category>
        </item>
        <item>
            <title><![CDATA[0x40 Web3 Security Bulletin]]></title>
            <link>https://paragraph.com/@w3sb/0x40-web3-security-bulletin</link>
            <guid>D0W7zPnPaWFwbUHhyFf0</guid>
            <pubDate>Fri, 03 Jul 2026 08:43:01 GMT</pubDate>
            <description><![CDATA[Intelligence for Web3, digital asset infrastructure, and the capital shaping the industry.]]></description>
            <content:encoded><![CDATA[<p>TL;DR</p><ul><li><p><strong>Exploit mechanics are getting clearer, but losses are still operational.</strong> OpenZeppelin’s latest bug digest and TRM’s H1 data both point to the same lesson: smart contract flaws matter, but the expensive failures still cluster around keys, infrastructure, phishing, and weak operational controls.</p></li><li><p><strong>Tokenized markets are moving from thesis to infrastructure.</strong> Robinhood’s L2 push for tokenized equities shows major brokerages are no longer treating onchain assets as a side product. The next competitive layer is 24/7 execution, settlement, and automated trading workflows.</p></li><li><p><strong>Regulators are turning crypto into an operating environment.</strong> The UK’s finalized crypto regime and Hong Kong’s institutional-market strategy are less about “whether crypto is allowed” and more about custody, disclosures, stablecoins, market abuse, and who can operate at scale.</p></li><li><p><strong>Frontend and supply-chain risk remain underpriced.</strong> The Polymarket user losses are a reminder that users can lose funds even when core contracts are not the failure point. Web app integrity, vendor controls, and approval hygiene are now part of protocol security.</p></li><li><p><strong>Audit findings need better translation into loss prevention.</strong> The strongest research this week reinforces a familiar gap: knowing vulnerabilities exist is not the same as reducing exploitability, especially when attacker paths depend on governance, deployment, monitoring, and human behavior.</p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis</h1><p><strong>OpenZeppelin Bug Digest #9 </strong></p><p>OpenZeppelin's June 30 Notorious Bug Digest #9 covers recent vulnerability classes including rule-downgrade bugs, zero-knowledge circuit misconstraints, and the Aftermath exploit pattern. The digest links public audit findings to live mainnet failures, giving developers a quick reference for recurring 2026 exploit mechanics. The useful signal here is pattern recognition: teams can map audit findings against live exploit paths before they show up in their own deployments. For builders, this is a reminder that “known class of bug” should translate into test cases, monitoring rules, and upgrade playbooks. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.openzeppelin.com/news/the-notorious-bug-digest-9">OpenZeppelin</a>) </p><p><strong>Blockchain Development for Builders and Businesses</strong></p><p>Cyberscope clarifies that “blockchain development” spans core protocol engineering, smart contract and dApp work on existing networks, and enterprise integrations on permissioned chains. The article breaks down fundamental components such as consensus, data structures, smart contracts, and stresses that modern practice increasingly includes security, tooling and compliance considerations as blockchains move from niche experiments into finance, gaming, identity and infrastructure. As blockchain work becomes normal software infrastructure, security can’t sit off to the side as a final audit step. Teams entering the space need to treat consensus choices, contract design, key management, and compliance as architecture decisions from day one. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.cyberscope.io/blog/blockchain-development">Cyberscope</a>)</p><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements</h1><p><strong>Robinhood Launches L2 for Tokenized Stocks </strong></p><p>Robinhood launched Robinhood Chain, an Ethereum layer-2 for 24/7 tokenized equities, perpetuals via Lighter, and AI-agent trading workflows. The move extends Robinhood from brokerage into onchain market infrastructure as regulated venues race to host real-world assets and automated execution on public chains.  Tokenized equities are becoming a venue and workflow competition, not just a product wrapper. The security question moves from “can assets be represented onchain?” to whether settlement, custody, automation, and market controls can survive real brokerage-scale usage. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.coindesk.com/business/2026/07/01/robinhood-rolls-out-public-blockchain-as-it-expands-deeper-into-crypto">CoinDesk</a>)</p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents</h1><p><strong>TRM H1 2026 Hacks </strong></p><p>TRM Labs reported that the first half of 2026 saw 207 separate hacks, more than double the 83 in H1 2025, while stolen funds fell to $972 million from $2.3 billion. Smart contract exploits made up 125 incidents but a small slice of dollar losses; infrastructure and key-compromise attacks drove about 76% of value stolen on just 15% of events. North Korea-linked activity accounted for roughly $643 million, mostly April's Drift and KelpDAO thefts. TRM cautions the lower total reflects fewer mega-heists, not weaker attackers. The incident count is rising even as headline losses fall, which means attacker activity is broadening rather than fading. Security teams should keep smart contract review in place, but the money is still being lost through keys, infrastructure, access paths, and operational failures. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.trmlabs.com/resources/blog/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion">TRM Labs</a>) </p><p><strong>Polymarket Users Lose $3M Supply-Chain Attack</strong></p><p>Polymarket will reimburse users after attackers injected malicious JavaScript through a compromised third-party frontend vendor, tricking fewer than 15 accounts into approving roughly $3M in ParyonUSD. </p><div data-type="twitter" tweetid="2070152064051605517">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/SpecterAnalyst">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/45a4924b6eceb5f6d224223118d602233b9c1670bb13c661858585bacea1f4b3.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/SpecterAnalyst" class="twitter-displayname">Specter</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/SpecterAnalyst" class="twitter-username">@SpecterAnalyst</a></p>
    
            </div>
            <a href="https://twitter.com/SpecterAnalyst/status/2070152064051605517" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      It appears there may be a phishing attack targeting Polymarket users, with estimated losses of $2.94M so far.<br><br>The attacker has drained funds from 11+ victim wallets holding PUSD, swapped the stolen assets for ETH, and consolidated the proceeds into the following address: 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/e54e30403d50aaa5b89fae0a9ef3f6dad62263252e91a6f26dfe2ef46e30f169.jpg"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/SpecterAnalyst/status/2070152064051605517" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            73
          </a>
          <a target="_blank" href="https://twitter.com/SpecterAnalyst/status/2070152064051605517"><p>2:28 PM • Jun 25, 2026</p></a>
        </div>
    
  </div> 
  </div><p>PeckShield said stolen funds were bridged from Polygon to Ethereum and swapped into about 1,893 ETH. Polymarket confirmed its own servers were not breached, a reminder that prediction-market risk often sits in the web app even when contracts are fine. This is exactly the kind of loss pattern that gets missed when teams define protocol security too narrowly. Frontend integrity, third-party code, wallet approvals, and user transaction context are now part of the security boundary. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://thedefiant.io/news/hacks/amlbot-polymarket-phishing-3-1-million-11-wallets-ethereum">The Defiant</a>)</p><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>2026 hacks: 182</p><p>Total amount lost in 2026: $955,864,608</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/5208261974a841728f4f17b0c46aec8730ff35dd62d60f7c46bbb8a35be2a92a.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAICAIAAAAX52r4AAAACXBIWXMAABYlAAAWJQFJUiTwAAABsklEQVR4nJWRS0gCYRDH92J0qi69LkUUWhAEPba0Qy+yjBQi2ktkBJY9pTyYJ0sWPARJp71EZ0/2QYoYROHSIVwKDCFUQhBZ69B6KD4M9mMiFipCzH4Mw8AM/Bj+FMdxNpstEokAAC5GXpIugkGMsUxIyO+/4XmZEFweAEAhhFwuVzgcLiGg21rzkgQAVoY52N8DgLwklSvwer1msxkhhDF+KUZOFDsaGnKiKBOywsyxTqdMSE4UX8oAY0xxHMcwjM/nKyHQ1NcrggWj0WW3/0+AEHI4HKU/aKqsyGazMiEWZm7bYvlT8LX9FlxeXQGAkp5MyM/CGLfUVL++vQHA7vqafXlZSevXWdH6zCAajXo8nmAgcMSyNzw/Qfedn52JmUwyHhczmUO3O51MNFJUTBAAoF+tmaTp90IhJggP9/fJeDx6zcfubi9DoZggpFOp56enI5b1nRw/JhLpVOq9UKAAwH96ajQY5k2mWpWqr6O9S62e1o/vWK3DWu2MXj+s1U6NjKwumpWhsarKsbU5qtMN9nRvLC3VqlRKnzUYGJNpYmhobIBurqtz2rZ6OzuDgcAH0vBRZzwk+FYAAAAASUVORK5CYII=" nextheight="572" nextwidth="2224" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation </h1><p><strong>Hong Kong is Attracting Institutional Capital</strong></p><p>Elliptic explains that Hong Kong’s licensing regime for exchanges and custodians, tokenized securities pilots, and emerging stablecoin frameworks have moved the city from experimentation into a market-building phase. The piece argues that clear rules, operational exchanges and regulated tokenization are now drawing institutional capital, while supervisors continue to prioritize AML, suitability and robust custody over speculative yield products. Hong Kong is showing how regulation can become market infrastructure when licensing, custody, tokenization, and stablecoin rules move together. For institutions, the differentiator is shifting from crypto exposure to whether venues can meet operational and supervisory standards. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.elliptic.co/blog/why-hong-kongs-crypto-regulation-is-drawing-institutional-capital">Elliptic</a>) </p><p><strong>UK's FCA Finalizes Crypto Regime </strong></p><p>The FCA published June 30 a package of five policy statements (PS26/9 through PS26/13) completing its cryptoasset rulebook under the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026, passed February 4. The regime covers stablecoin issuance, trading platforms, custody, staking, lending, admissions and disclosures, and a crypto market-abuse framework. The full regulated scope takes effect October 25, 2027. The UK is moving crypto firms into a much more explicit authorization, prudential, and market-abuse environment. Operators now have a real implementation clock, and the firms that treat this as an operating model change will be better positioned than those treating it as paperwork. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fca.org.uk/publications/policy-statements/cryptoasset-regime">FCA</a>)</p><h2 id="h-legislative-watch" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Legislative Watch</h2><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/3a77bd7b22761326eec2b036af9bf84fb0c6e2d562cfc4fe8f8d887f74c13400.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAQCAIAAAD4YuoOAAAACXBIWXMAAAsTAAALEwEAmpwYAAADHUlEQVR4nK1UzU8TQRSfq6nxomkiJlw49A+QePHWRA8mhoMmGr8OclD8QjhgEBIhUAg2AZt0D6UihlYaWkiFLIavxNKkNixFWOJ2q2yr7EZaBQa63YXuEjpmd6FuWhLR+MtmMm/2zbz5/d57AwA4DlSwLDe/QC4tMTMEgf4TIIQgj2vXbwEADIZjpaWlp8vLAQAlJafKysqMRqPJZDKbzQbDUQBAKBRCCEmSdNgAs+HgyRNH6mruR6OfhoYGXC7X8MiIw+Gor693u91er9fhcPj9fhzHOzs77XY7hPDvGPjxwJXKxpaOlxcuPTJfrPIOjs1Nv+c30/+miSRJNB1bSSZZllNHFqRSP4nZxSgdnydjoTC5kvyxsbYqCoKkAu2roZl/VEaSJCpKM0ycpmMME2cYBhy4R5Z38h9STW19N5fbzeWKfQr8NagB4koAbU/+N58RvydX9d6yOtnN5QoWC07ch+KmsVFysA43t7OyPgBFJzCnj44lel6/hTAtyzuSJBVTQQhNhz5CqGTrwEgsyykS1TXa6FhCzXia5VIKtTjXZe+32lxWm6vXjbNcyoZ5BGFrgfxMRKhQmNTOsjx/daOysfJBSzK1pr9iXsM9BjbM09CMIYTuPm47X3FveDTYZu154x0DxjMUnRgeDXa86BsYnGiz9vb1485ePxGhmDgnyztNlu6BwYmqmvbap10VV2u77P2Ruahevb0cYE4fACZZ3rHaXJjTNzwaDIVJr3/q7LnbCk0ulUytERGqoRkThC1y8QufEd9NfqDoxFRgr+FtmKfJ0v3kmR1z+py9fo93nM+I29msIIgKAz4jVNW0NzRj6qrCFCH0lU1StKKbrKqxnc3qU4o5fZdv1jFxTnPQ8oQQCoVJjXFDM3bnoWVxMar0gXZNj3dcz+7AwkX7oyBsrcPN4prOVyNFJ6pq2okIlc2KSpmqrZCDcCPN85qp3gvqi0cQxEwmky9WCNNr6+v68k/zvN6UJIlR8bvRChq1wCxgVtzVBaYgiHtvUSAQqK6ubm214Dg+v0DOEMT4+OS35WX983AYFKuqBfgFKwYvp3S6HAcAAAAASUVORK5CYII=" nextheight="962" nextwidth="1904" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://polymarket.com/event/clarity-act-signed-into-law-in-2026">Polymarket</a>)</figcaption></figure><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research </h1><p><strong>Four-year Study Finds Audit Findings Don't Match Losses</strong></p><p>Stefan Beyer's arXiv paper analyzes Web3 security from January 2022 through March 2026, combining 23,818 public audit findings from 22 firms with 218 Rekt documented exploits totaling roughly $7.76B. Critical and High audit findings held steady at 15–17% each year, but loss categories diverged sharply: private-key compromise, phishing, and social engineering drove about 49.6% of dollar losses while barely appearing in published audit output. Losses were also heavily concentrated: the eight largest incidents accounted for 50.6% of cumulative damage and the top twenty for 71.4%.  (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2606.15465">arXiv</a>)</p>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>security</category>
            <category>cybersecurity</category>
            <category>crypto</category>
            <category>hacks</category>
            <category>regulations</category>
        </item>
        <item>
            <title><![CDATA[0x39 Web3 Security Bulletin]]></title>
            <link>https://paragraph.com/@w3sb/0x39-web3-security-bulletin</link>
            <guid>Ki5kEhLBhT77FAVNvLlu</guid>
            <pubDate>Fri, 26 Jun 2026 06:43:41 GMT</pubDate>
            <description><![CDATA[Intelligence for Web3, digital asset infrastructure, and the capital shaping the industry.  ]]></description>
            <content:encoded><![CDATA[<p><strong>TL;DR</strong></p><ul><li><p>Base’s two-hour mainnet stall showed that L2 security is also a liveness and resilience problem: invalid-block handling, sequencer design, client diversity, and upgrade discipline now matter as much as exploit prevention.</p></li><li><p>Nethermind reviews how institutional privacy is moving from theory to implementation, with ZK proofs, shielded pools, FHE, TEEs, and MPC giving public-chain finance a path toward confidentiality, verifiability, and selective disclosure.</p></li><li><p>Hypernative’s rebrand points to a maturing onchain security market, where institutions want continuous monitoring, transaction guardrails, wallet protection, fraud detection, RBAC, MFA, and audit logs in one control layer.</p></li><li><p>SecondFi’s $20M wallet loss was a pure fundamentals failure: predictable Ed25519 nonce generation turned ordinary signatures into private-key exposure, reinforcing the need for hardened crypto libraries and strict wallet security review.</p></li><li><p>Bridge and cross-chain assumptions failed again, with Secret Network and Taiko incidents showing how missing source-channel checks or forged message proofs can convert verification gaps into real asset loss.</p></li><li><p>Policy pressure is tightening around the operating layer: TRM traced billions between CoinEx and sanctioned Iranian exchanges, stablecoin issuers face banking-style customer identification rules, and Binance is still searching for a viable MiCA path.</p></li><li><p>Applied research is raising the stakes on both offense and compliance, with new work showing LLMs can generate smart contract exploits across vulnerability classes while ZK compliance schemes try to preserve privacy without weakening authorization.</p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis </h1><p><strong>Base Mainnet Stalled for Hours After Invalid Block </strong></p><p>On June 25 Coinbase's Base L2 halted block production in what the team called a "Mainnet Chain Stall" and "Unsafe Head Stall," with deposits, withdrawals, and client software affected for roughly two hours. Base isolated a consensus problem that sequenced an invalid block after block 47,806,542, stopping subsequent block building; <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/jessepollak/status/2070299820171075981?s=20">Jesse Pollak</a> said funds were safe and the issue was not a security exploit. </p><div data-type="twitter" tweetid="2070182021746294932">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/buildonbase">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/eb4ce200700cced5dd5846cd999bd8b1d11bbe96abd824e487f2ece49ac523bb.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/buildonbase" class="twitter-displayname">Base Build</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/buildonbase" class="twitter-username">@buildonbase</a></p>
    
            </div>
            <a href="https://twitter.com/buildonbase/status/2070182021746294932" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      Base Mainnet is currently halted while the team works on an issue with block production.<br><br>All funds are secure, and we’ll update below once resolved.<br><br>Appreciate the patience while we get it fixed.
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/buildonbase/status/2070182021746294932" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            885
          </a>
          <a target="_blank" href="https://twitter.com/buildonbase/status/2070182021746294932"><p>4:27 PM • Jun 25, 2026</p></a>
        </div>
    
  </div> 
  </div><p>EtherWorld frames the outage as a liveness failure, not a safety breach, and notes it landed the same day as the scheduled Beryl upgrade. The article argues the incident renews questions about OP Stack sequencer centralization, client diversity, and whether L2 reliability can match adoption on one of Ethereum's busiest rollups. The security lesson is operational rather than exploit-driven: rollups need liveness, client diversity, upgrade discipline, and clear failover paths before they can credibly carry institutional-scale activity. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherworld.co/base-mainnet-temporarily-halts-block-production-after-invalid-block/">EtherWorld</a>)</p><p><strong>Institutional Privacy on Public Blockchains Gets Practical</strong></p><p>Stefano De Angelis outlines how institutions can use shielded pools, zero-knowledge proofs, FHE, TEEs, and MPC to achieve private transfers and computations on public chains without sacrificing verifiability. The article argues that privacy is a hard requirement for on-chain finance, but must be paired with selective disclosure, access control, and standardized tooling to satisfy regulators and operational constraints. This matters because privacy is becoming a control layer, not a feature request: institutions need confidentiality, selective disclosure, auditability, and access control to coexist on public rails. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.nethermind.io/blog/institutional-privacy-on-public-blockchains-technical-foundations-challenges-and-the-path-to-adoption">Nethermind</a>) </p><p><strong>DePINs Bring Crypto Incentives to Real-World Infrastructure</strong></p><p>CyberScope introduces decentralized physical infrastructure networks (DePINs) as token-incentivized systems where ordinary users deploy hardware to provide wireless coverage, storage, compute, or sensor data. The article highlights proof-of-physical-work schemes, security challenges like Sybil attacks and node compromise, and argues DePINs will likely coexist with traditional cloud as a cost-effective, censorship-resistant layer for specific workloads. The security baseline for DePINs is physical-world trust: protocols have to prove nodes are real, data is authentic, incentives are not gameable, and compromised hardware cannot poison the network. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.cyberscope.io/blog/what-are-depins">CyberScope</a>)</p><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements</h1><p><strong>Hypernative Rebrands as Institutional Onchain Security Layer</strong></p><p>Hypernative announced that it is refreshing its brand and product naming to match a customer base that now spans crypto-native protocols, Layer 1 teams, and traditional financial institutions building tokenized funds and stablecoin programs. The company says its platform monitors more than $100B in digital assets across 75+ chains for 350+ organizations and has helped prevent over $3B in onchain losses. The rebrand groups capabilities into lifecycle-stage applications including onchain monitoring, transaction guard, fraud prevention, wallet protection, and screening. The product includes shared ML detection infrastructure with 300+ risk agents. New enterprise features include MFA, RBAC, and audit logs. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hypernative.io/insights/blog/a-new-look-for-hypernative-built-for-the-age-of-institutional-onchain-finance">Hypernative</a>)</p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents</h1><p><strong>SecondFi Wallet Flaw Results in $20M Loss Across 374 Wallets</strong></p><p>SecondFi said June 25 that the root cause was confined to its native Cardano web wallet generation software, with on-chain analysis estimating roughly 16 million ADA in losses from a sophisticated automated attack between June 21 and 23. The team identified two attackers: one drained 171 wallets in two waves via three collection addresses, the other swept 203 wallets in a third wave, with about 4.02 million ADA still sitting in Attacker B's flagged collection address. SecondFi put the platform in secure maintenance mode, took a balance snapshot, and said it is working with IOG, the Cardano Foundation, Intersect, and SundaeSwap while an independent security firm validates findings. The team warned the flaw is address-level and urged affected users to follow official recovery steps rather than importing seed phrases elsewhere. The incident is a reminder that wallet software is security-critical infrastructure: one flawed signing implementation can turn ordinary user activity into private-key exposure at scale. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/secondfiapp">SecondFi on X</a>) </p><p><strong>Root Cause Analysis of SecondFi's Ed25519 Nonce Flaw </strong></p><p>SecondFi's Cardano web wallet derived Ed25519 signing nonces from the public transaction message alone (<code>k = H(M)</code>) instead of from a secret seed. Because Ed25519 signatures publish <code>R</code> and <code>s</code> on-chain, anyone could recompute <code>k</code>, plug into <code>a = (s − k) / H(R, A, M)</code>, and recover the private key from a single signed transaction, worse than classic nonce reuse, which typically needs two signatures. The failure was custom wallet signing logic, not a Cardano protocol bug; audited libraries like libsodium derive nonces from secrets and prevent this class of leak entirely. The fundamental failure was cryptographic hygiene: teams should use battle-tested signing libraries, avoid custom nonce logic, and treat key-generation code as a high-assurance control surface. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/solidsnakedev/status/2070184577843556838?s=20">Jonathan on X</a>)</p><div data-type="twitter" tweetid="2070184577843556838">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/solidsnakedev">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/110645fae51ab5cb4a78d7f6de15a6ff3f39a72eb7f28fe1d679573a9ebe3273.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/solidsnakedev" class="twitter-displayname">Jonathan</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/solidsnakedev" class="twitter-username">@solidsnakedev</a></p>
    
            </div>
            <a href="https://twitter.com/solidsnakedev/status/2070184577843556838" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      The signing math<br><br>When you sign a message with Ed25519, two values get published on-chain as your signature: R and s. <br><br>They're computed like this:<br>- R = k · G  (k = the secret nonce, G = a fixed public point)<br>- s = k + H(R, A, M) · a<br><br>Where:<br>- k = the nonce (must be secret)<br>- a
      
      
      <div class="twitter-quoted">
       
  <div class="twitter-quoted twitter-embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/P3b7_">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/e1a9bbc65d979681030c7fa135a8ecef19199979b4911c8ad6bade25e4be1a42.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/P3b7_" class="twitter-displayname">Charles Guillemet</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/P3b7_" class="twitter-username">@P3b7_</a></p>
    
            </div>
            <a href="https://twitter.com/P3b7_/status/2070121675102863721" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      <img class="twitter-emoji" draggable="false" alt="🚨" src="https://abs-0.twimg.com/emoji/v2/72x72/1f6a8.png">SecondFi: more than $20M stolen, or taken hostage - When the nonce is predictable, the key is public.<br><br>Last Tuesday, SecondFi wallets were drained at scale. Users were doing nothing exotic, just signing transactions like any other day. Then the funds were gone.<br><br><img class="twitter-emoji" draggable="false" alt="▶️" src="https://abs-0.twimg.com/emoji/v2/72x72/25b6.png">What 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/1b9b79c3e22bb1647984d549301be146ab82d130d96448ad99404a0d920c974d.jpg"></div>
      
       
    </div>
    
  </div> 
  
    </div> 
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/solidsnakedev/status/2070184577843556838" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            133
          </a>
          <a target="_blank" href="https://twitter.com/solidsnakedev/status/2070184577843556838"><p>4:37 PM • Jun 25, 2026</p></a>
        </div>
    
  </div> 
  </div><p><strong>JaredFromSubway MEV Bot Drained for $15M </strong></p><p>The JaredFromSubway sandwich bot lost roughly $15M when an attacker fed it fake profitable pools, accumulated ERC-20 approvals up to 92 WETH on helper contracts, then called transferFrom on WETH, USDC, and USDT balances. The lesson here is that automated trading systems are still approval, simulation, and adversarial-input systems; if they trust fake opportunities, attackers can turn speed into liability. Quit's X thread covers the details step by step. </p><div data-type="twitter" tweetid="2068503394839634268">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/0xQuit">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/93412dcb75f3d073686cc8ebb14b429314999a8f36ca9eb4d7409bb58819cc85.png">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/0xQuit" class="twitter-displayname">Quit</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/0xQuit" class="twitter-username">@0xQuit</a></p>
    
            </div>
            <a href="https://twitter.com/0xQuit/status/2068503394839634268" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      If you've been in this space long enough, you have probably been sandwiched by jaredfromsubway.<br><br>No doubt you've heard of him.<br><br>Today, he was beaten at his own game to the tune of ~$14M.<br><br>1/<img class="twitter-emoji" draggable="false" alt="🧵" src="https://abs-0.twimg.com/emoji/v2/72x72/1f9f5.png">
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/0xQuit/status/2068503394839634268" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            1,350
          </a>
          <a target="_blank" href="https://twitter.com/0xQuit/status/2068503394839634268"><p>1:16 AM • Jun 21, 2026</p></a>
        </div>
    
  </div> 
  </div><p><strong>Secret Network Details Axelar IBC Bridge Exploit </strong></p><p>Secret Network's forum post says an attacker exploited the <code>ics20-for-axelar</code> contract on June 10 by opening a permissionless IBC channel from a counterfeit chain, minting about $4.67M in unbacked saTokens (saUSDT, saUSDC, saWETH, and four others) in six minutes, then redeeming them through the real Axelar bridge to drain escrow reserves in roughly 18 minutes. The bug dates to a 2023 escrow-to-mint rework that dropped source-channel authentication; a March 2026 migration carried the flaw forward. Secret was not told until June 17. Proceeds moved via Osmosis to Ethereum and BSC, swapped to about 2,349 ETH on CoW Protocol, and cashed out mainly through ChangeNOW and KuCoin; roughly $770,000 remains on Axelar, which Secret says Axelar declined to freeze. Native SCRT, Noble USDC, and other IBC bridges were unaffected. This is a bridge-authentication failure in plain terms: cross-chain systems must verify source channels, message provenance, and migration safety because one missing check can mint unbacked assets into real liquidity. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://forum.scrt.network/t/security-incident-axelar-secret-ibc-bridge-exploit-june-10-2026/7995">SCRT</a>) </p><p><strong>Taiko L2 Loses $1.7M to Forged Bridge Message Proofs</strong> </p><p>Taiko halted block production after an attacker exploited bridge message-proof verification, registering fraudulent withdrawals on Ethereum L1 without legitimate MessageSent events on the rollup. </p><div data-type="twitter" tweetid="2068858818352865626">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/taikoxyz">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/d7e5f872e722a0e68bd07f641cb30615b51d9160411b60e0635385db3287e13b.png">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/taikoxyz" class="twitter-displayname">Taiko.eth 🥁</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/taikoxyz" class="twitter-username">@taikoxyz</a></p>
    
            </div>
            <a href="https://twitter.com/taikoxyz/status/2068858818352865626" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      <img class="twitter-emoji" draggable="false" alt="⚠️" src="https://abs-0.twimg.com/emoji/v2/72x72/26a0.png"> Security Notice<br><br>1/2: We have confirmed a compromise of Taiko’s chain state verification mechanism. As a result, the security assumptions of all bridges deployed on Taiko can no longer be relied upon.<br><br>We are actively coordinating with the Security Council and ecosystem
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/taikoxyz/status/2068858818352865626" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            129
          </a>
          <a target="_blank" href="https://twitter.com/taikoxyz/status/2068858818352865626"><p>12:49 AM • Jun 22, 2026</p></a>
        </div>
    
  </div> 
  </div><p>Losses totaled about $1.7M before the team paused the L1 bridge and ERC20Vault. Taiko urged users to exit bridges immediately and asked exchanges to suspend TAIKO deposits. The Taiko exploit reinforces that bridge proofs are core security assumptions; when state verification fails, every dependent bridge and withdrawal path becomes suspect. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.theblock.co/post/405486/taiko-confirms-exploit">The Block</a>)</p><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>2026 hacks: 175</p><p>Total amount lost in 2026: $948,394,808</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/32539d5eb985ae6767a1b68e9ce00da2b78efc2a77dc1733512302d8ee5bd982.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAICAIAAAAX52r4AAAACXBIWXMAABYlAAAWJQFJUiTwAAABtUlEQVR4nGNYsWJFZmbmihUrXuMGVy5dOrR37+vXrz99/jx7ypQrly59+vz5NRHg69evDBALpk6dikvRn79/Z0zo97a2+vn795+/fzUkJHZu3vzz929iLZg6dWpERERPTw8eC5qrqjwtLf78/UuOBfPnzydoQW1xsYuZKcQCJUGBnZs3//n7l1gLNm3ahCeInjx+/Ofv3/rSYkcTE4gFMmysOzZtwm/Bk8ePERbs3r27qKho6bJl//////P37////79+/Qox68/fv1+/fv3//39Fbm6Er/d/MJBhZz+0dy9EMUQ9XDEm+v//P8O5c+d6enrmz5/fUVe3c/Pm0oy0orSUJw8e3L19+/nTp5tWr96ydk1cYKCPg92P799vXr3KwMCwafXq50+fXrl06e7t20f37Tu0d++lc+c2rlp19/btm1evPn/6ND0q6sSRIzevXgX54P///6fPnLGztAxwdWZkYNBWVJQVFTbX1U2KjLAyMorw9RZlY/NzcTHS1Aj18nazsWFgYIgNDtZSVvZ1djTS1PB2ctRUUNDXUDdUV1eXk4sNDjbS1ORiYDDS1LA0NHj39i0ARYg/Ei0dbvoAAAAASUVORK5CYII=" nextheight="582" nextwidth="2244" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation</h1><p><strong>TRM Traces $3.84B Between CoinEx and Sanctioned Iranian Exchanges</strong></p><p>TRM Labs reported that blockchain-verified flows between global exchange CoinEx and more than 60 Iranian platforms totaled $3.84B over seven years, including $2.7B with Nobitex at roughly $1M per day. CoinEx's illicit-volume share is nearly 8%, against a 0.3% threshold typical of compliant venues. TRM also traced $67M from the Central Bank of Iran through a multi-chain "National–Tether" laundering playbook ending at CoinEx off-ramps, plus $154M in ViaBTC mining payouts to Nobitex-linked wallets that supplied emergency liquidity after a 2025 cyberattack. The compliance takeaway is that blockchain transparency only helps when exchanges, issuers, and off-ramps convert visibility into controls, sanctions screening, and accountable transaction monitoring. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.trmlabs.com/resources/blog/how-coinex-became-irans-primary-gateway-to-global-cryptocurrency-markets">TRM Labs</a>)</p><p><strong>Stablecoin Issuers are Facing Banking Compliance Requirements</strong></p><p>FinCEN, OCC, the Fed, FDIC, and NCUA proposed a GENIUS Act rule requiring permitted payment stablecoin issuers to maintain formal customer identification programs under the Bank Secrecy Act. The rule would cover direct issuer relationships like issuance, redemption, custody, and authorized digital asset services, while carving out ordinary secondary-market transfers and smart-contract-only interactions. The operational signal: stablecoin compliance is being designed around issuer-controlled entry points, not a blanket KYC obligation for every wallet-to-wallet payment. The rule shows where stablecoin regulation is likely to land first: issuer-controlled touchpoints, custody, redemption, and authorized services, rather than every peer-to-peer transfer. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.federalregister.gov/documents/2026/06/22/2026-12460/permitted-payment-stablecoin-issuer-customer-identification-program">Federal Register</a>) </p><p><strong>Binance Searches for New MiCA Path </strong></p><p>Reuters reported June 24 that Binance Europe head Gillian Lynch said the exchange is not leaving the EU after Greece reportedly rejected its MiCA license bid, and is exploring other member-state routes. ESMA said firms without authorization must wind down EU activities in an orderly way. Sources cited concerns over past AML penalties, corporate structure, and executive backgrounds. Binance has roughly one week before its current EU permission expires. The MiCA setback matters because licensing is becoming an operational security signal: governance structure, AML history, executive accountability, and control maturity now affect market access. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.reuters.com/business/finance/binance-vows-stay-europe-despite-licence-setback-2026-06-24/">Reuters</a>)</p><h2 id="h-legislative-watch" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Legislative Watch</h2><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/9fd6c9b48fd5ad946fdf7f459e4692a6cc2f5dbe2b739ec79a740a7208542a54.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAQCAIAAAD4YuoOAAAACXBIWXMAAAsTAAALEwEAmpwYAAAC40lEQVR4nK1UTW8SQRieIzcvHnvwUOOvEBMPTeqhBz14MvHiRy9NaWLUGFohKaglETTQpqA0WUwjhmKaeqApSyzW4KZ8iFspW1iqLJEhZantLtKhMIZdwO22mrTxyRxmZt933o/neReADiCEq9HY52RyNRrD/wk8z3ffB1rtBQBAb+/Znp4ejUYDADgl4YwErVYLANBoNBzHHS/ASnhpoP/iwts3iXjc7/eRJBmJRGbc7unp6YAC4XCYIAiSJI9dweRL/03dowkbcb7/1rXbhnl/IBWlqmIVnwgIIZpe49oosGwOlEpbX2iGzXFJeiNJb/D8T3QUsOQsb/4dgGXZ7/l8Os2wbK4V4LBRo9lEqH7ihTuQY4BGs9loNqXg7c8I1ZlsHqF6bU+dr2ypyLflorpUc1CEZVHqeDdAnoMTNgIhZLER8cQ6QnVBEFXZycfaHgqFY920VHVkslmWZcHdh/YfxS2McRGW08w3jHGhUPJ4A6PjTrdn4ZnjNUJ1q302ld4swvLKx0QoHGOyeYzxFr89fO/ppSvDBrOrCMuCICrD/KnA4fTpjVMY4zv65wNXRxZJ6rGViFD06XP9bs8CmyuYLO4PkeTouHP+3bLVPpukM6FwaxKj8dSLmXnvXNBgdg2OPNEbpwxml5ziAQ70xqlTvX2Vyo7VPuudCy6SVISimWy+7/JQks5gjFPpTYzxfYODzRXYXEEUq/HEejSeWgpRRViW3zJZ3A6nz2RxT9gI71zQ4w3U9lqSa3PwwDhpMLt+1Wrd0nZ2Bfn1Rof/bgcwxqJYvTFkknhqd39XqMr7T9GvEYp2OH3XB40Mk+E4riXTJJ1ZJCmM8X59X9aoSir4EHZ2BVkaSs6VBvRaVhBECEtAUgjCuFmpbAuC0BmsunzECt4qlW2lTso831WXtJDkrlQRe2DQZCPFUT0EqhtlS//m0uLA43ml0+lGx8beLy/HYvFgkAwGSQjhkT+M4wJC+BvSfDwSmOcTcwAAAABJRU5ErkJggg==" nextheight="976" nextwidth="1896" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://polymarket.com/event/clarity-act-signed-into-law-in-2026">Polymarket</a>)</figcaption></figure><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research</h1><p><strong>LLM Exploit-generation Benchmark Across 23 Smart Contract Vulnerability Classes </strong></p><p>The June paper introduces a data-centric benchmark using Foundry/Forge harnesses to test whether large language models can generate working exploits for 23 documented blockchain vulnerability types. Results show how automated offensive tooling may compress attacker reconnaissance timelines. The research shows that attacker automation is getting cheaper; smart contract teams need better pre-deployment testing, exploit simulation, and secure-by-default patterns before AI compresses the attack cycle further. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2606.15123">arXiv</a>)</p><p><strong>Zero-Knowledge Compliance for Ethereum Transactions</strong></p><p>Supriya Khadka and Sanchari Das introduce Selective Disclosure Authorization Schemes (SDAS), a new primitive for privacy-preserving regulatory compliance on public ledgers. Their ZK-Compliance prototype on Ethereum binds zero-knowledge proofs to the on-chain sender, preventing proof reuse and front-running while keeping user attributes private, with browser-side proving and on-chain verification kept practical for real-world deployment. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2606.20760">arXiv</a>)</p>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>security</category>
            <category>cybersecurity</category>
            <category>crypto</category>
            <category>exploits</category>
            <category>regulations</category>
        </item>
        <item>
            <title><![CDATA[0x38 Web3 Security Bulletin]]></title>
            <link>https://paragraph.com/@w3sb/0x38-web3-security-bulletin</link>
            <guid>j44pLCCaD7wMIkSjF72B</guid>
            <pubDate>Fri, 19 Jun 2026 05:25:04 GMT</pubDate>
            <description><![CDATA[Intelligence for Web3, digital asset infrastructure, and the capital shaping the industry.  ]]></description>
            <content:encoded><![CDATA[<p><strong>TL;DR</strong></p><ul><li><p><strong>Audits are becoming continuous, not ceremonial:</strong> CyberScope’s audit-cadence guidance, AuditVault’s reusable finding library, and the latest research all point the same way: security work has to track code changes, TVL, integrations, and attacker learning curves.</p></li><li><p><strong>The audit gap is now measurable:</strong> Stefan Beyer’s research pairs 23,818 audit findings with 218 real exploits and shows the uncomfortable truth: audits catch code risk, while nearly half of dollar losses now come from human-vector failures like key theft, phishing, governance, and supply-chain compromise.</p></li><li><p><strong>Humanity Protocol is still the cleanest warning shot:</strong> Seven production keys on one compromised laptop turned into a $36M mint-and-dump, ProxyAdmin takeover, token migration, and compensation scramble. </p></li><li><p><strong>Bridge risk keeps hiding in old assumptions:</strong> Gravity Bridge lost $5.4M through denom-mapping poisoning, while Aztec’s deprecated immutable bridges lost about $4M across two drains. Legacy bridge logic and residual TVL remain dangerous long after the product story moves on.</p></li><li><p><strong>Compliance infrastructure is moving deeper into the stack:</strong> OFAC-aware monitoring, Elliptic’s accuracy-first intelligence model, NYDFS-EBA stablecoin coordination, and Coinbase’s licensed brokerage/derivatives push all show the same pattern: compliance is becoming product architecture.</p></li><li><p><strong>MiCA is forcing the issue in Europe:</strong> Binance’s reported Greek license setback, the June 30 deadline, and cross-border stablecoin supervision are turning regulatory posture into a market-access control. The question is no longer whether crypto firms want licenses; it is whether they can operate without them.</p></li><li><p><strong>Institutional rails keep absorbing crypto primitives:</strong> Fireblocks is tightening staking operations for large ETH holders, Trace Finance raised $32M for regulated cross-border settlement, and Coinbase is expanding into stocks, derivatives, prediction markets, advisory, and tokenized equities. The crypto capital stack is getting more regulated, not less.</p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis </h1><p><strong>How Often Should Smart Contracts Be Audited?</strong></p><p>CyberScope argues that audits are not a one‑off checkbox but a recurring process tied to code changes, TVL milestones and evolving attack techniques. Pre‑deployment audits are described as non‑negotiable, with follow‑up reviews recommended after significant logic changes, governance upgrades, major integrations, or when TVL crosses preset thresholds. The article also urges teams to pair annual audits with continuous on‑chain monitoring and public bug bounties so that operational security keeps pace with growing capital at risk. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.cyberscope.io/blog/how-often-should-smart-contracts-be-audited">Cyberscope</a>) </p><p><strong>OFAC and Crypto Crime </strong></p><p>This research catalogues all OFAC Specially Designated Nationals (SDNs) with known crypto addresses, showing how sanctions authorities are increasingly targeting wallets linked to ransomware gangs, darknet markets, terror groups and nation‑state actors. It highlights patterns in address reuse and laundering typologies and argues that financial institutions need SDN‑aware blockchain monitoring to avoid indirect exposure. Sanctions risk now moves through wallets, bridges, services, and counterparties, which means compliance teams need address-level intelligence baked into transaction monitoring before exposure becomes indirect liability.(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/ofac-sanctions/">Chainalysis</a>)</p><p><strong>AuditVault Builds an Obsidian Security Knowledge Base</strong> </p><p>Auditware released <a target="_blank" rel="noopener noreferrer" class="dont-break-out" href="https://github.com/Auditware/AuditVault">AuditVault</a>, an MIT-licensed Obsidian vault that links high- and critical-severity audit findings with DeFi hack post-mortems. The repo ingests Solodit/Cyfrin, Frankcastleauditor, Auditware audits, and Rekt leaderboard data into <code>findings/</code>, <code>hacks/</code>, <code>protocols/</code>, and <code>auditors/</code> folders, with hand-curated taxonomy in <code>classifications/</code>. Each entry carries 10+ tag axes covering severity, language, chain, sector, vulnerability pattern, impact, trigger, and fix type. A builtin crawler, <code>vault-admin/crawler/</code>, refreshes sources and retags new content. The useful shift is institutional memory: auditors and builders can stop treating every finding as isolated and start querying prior exploit patterns, fixes, and protocol failures as reusable security knowledge. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://github.com/Auditware/AuditVault">GitHub AuditVault</a>) </p><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements </h1><p><strong>Fireblocks Raises the Bar for Institutional ETH Staking</strong></p><p>Fireblocks describes how its new ETH Staking Link standardizes validator integrations and expands support from two to five staking providers, adding Blockdaemon, P2P and MAVAN alongside existing Figment and Kiln. The article explains that post‑Pectra “compounding validators” now support auto‑compounding rewards, top‑ups, partial withdrawals and balances up to 2,048 ETH per validator, simplifying operations for large institutional positions. It also notes that institutions can mix native staking with Lido liquid staking, while Fireblocks enforces policy controls across all staking workflows. As ETH staking becomes institutional infrastructure, custody policy, validator operations, withdrawals, and provider diversification become part of the control plane, not back-office plumbing.  (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fireblocks.com/blog/insitutional-eth-staking">Fireblocks</a>)</p><p><strong>How Elliptic Scales Its Intelligence Without Sacrificing Its Accuracy</strong></p><p>Elliptic explains how it expands blockchain intelligence coverage, adding more assets, services, and risk typologies, while maintaining low false‑positive rates through layered machine learning, analyst review and feedback loops. The post argues that accuracy is critical for compliance teams facing regulatory pressure and that poorly tuned analytics can create both missed‑risk and de‑risking problems. More coverage is only useful if it does not drown compliance teams in false positives; bad attribution can miss real risk or cut off legitimate users. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.elliptic.co/blog/how-elliptic-scales-intelligence">Elliptic</a>)</p><h1 id="h-capital-allocation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Capital Allocation </h1><p><strong>Trace Finance Raises $32M Series A </strong></p><p>Trace Finance announced on June 17 a $32M Series A led by CoinFund, with Coinbase Ventures, Haun Ventures, Jump Capital, Paxos, HOF Capital, Chainlink Labs, and others participating. The U.S.-based cross-border payments firm says it has processed more than $10B in institutional volume and is a core infrastructure provider for four of the largest global payment companies operating in Latin America, including dLocal. CEO Bernardo Brites said the round will deepen FX, banking connectivity, compliance, and settlement rails as new rules push institutional flows toward regulated infrastructure. Trace plans to expand in the U.S., Brazil, LatAm, and APAC, with new stablecoin-based settlement products in development. Stablecoin settlement is moving from crypto-native rails into regulated cross-border payments, where banking access, FX coverage, and compliance controls decide who wins distribution. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.tracefinance.com/series-a#announcement">Trace Finance</a>)</p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents </h1><p><strong>Humanity Protocol’s “Trust Layer” Unravels in $36M Key Compromise</strong></p><p>Rekt News recounts how Humanity Protocol, a proof‑of‑humanity project pitched as “the trust layer of the internet,” lost 447 million H tokens after seven production keys ended up on one malware‑infected laptop, enabling an attacker to seize its ProxyAdmin and mint on BSC. The post walks through DPRK‑style spear‑phishing, mint‑and‑dump flows that realized about $36.4M, competing theories over whether it was a staged rug or pure key leak, and the rushed recovery: a new ERC‑20 H, a compensation portal, and a short window for holders to migrate. This is the recurring Web3 failure mode: sophisticated protocol branding sitting on fragile operational security, where one compromised endpoint can become a governance, minting, and migration crisis. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rekt.news/humanity-protocol-rekt">Rekt</a>)</p><p><strong>Gravity Bridge $5.4M Exploit Analysis</strong></p><p>QuillAudits’ post‑mortem explains how an attacker minted worthless tokens on Osmosis, poisoned Gravity Bridge’s token registry with a fabricated denom string, and then used that mis‑registered asset to withdraw about $5.4M in real tokens. The analysis walks through the flawed validation logic, the cross‑chain impact and the defensive lessons for bridge designers around registry hardening and stricter on‑chain checks. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.quillaudits.com/blog/hack-analysis/gravity-bridge-demon-mapping-poisoning">QuillAudits</a>)</p><p><strong>Aztec’s Deprecated Bridges Lose $4M Across Two Exploits</strong></p><p>Protos reported that Aztec Labs' sunset Aztec Connect and Private Rollup Bridge contracts were drained twice in one week for about $4M combined. </p><div data-type="twitter" tweetid="2067511785637163354">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/AztecLabs_">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/42c9211cff2b2b9987410fbb66fe6ead9a9618db0bc79365c5ce22be41607247.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/AztecLabs_" class="twitter-displayname">Aztec Labs</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/AztecLabs_" class="twitter-username">@AztecLabs_</a></p>
    
            </div>
            <a href="https://twitter.com/AztecLabs_/status/2067511785637163354" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      We are investigating a potential exploit affecting a deprecated Aztec payments product from 2021. ~$2m was transferred from the immutable smart contract in transaction:<br><br><a class="twitter-content-link" href="https://t.co/FS4JoNnfiJ" target="_blank">etherscan.io/tx/0xab306cd21…</a><br><br>The deprecated product is an immutable stage 2 rollup that was sunset in 2022.
      
      
        <a class="twitter-card-link" href="https://t.co/FS4JoNnfiJ" target="_blank">
          <div class="twitter-media twitter-summary-large-image">
            <img src="https://storage.googleapis.com/papyrus_images/91ab19d6d7bb2df219d793cbf593acb791a31750026c2ef24ee88b9618becb37.png">
            <div class="twitter-summary-card-text">
              <span>etherscan.io</span>
              <h2>Ethereum Transaction Hash: 0xab306cd218... | Etherscan</h2>
              <p>Transfer 1,158 ETH to 0x6952d924...36F78E97F | Success | Jun-17-2026 06:34:47 PM (UTC)</p>
            </div>
          </div>
        </a>
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/AztecLabs_/status/2067511785637163354" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            40
          </a>
          <a target="_blank" href="https://twitter.com/AztecLabs_/status/2067511785637163354"><p>7:36 AM • Jun 18, 2026</p></a>
        </div>
    
  </div> 
  </div><p>BlockSec attributed both incidents to public input binding flaws in escape-hatch logic. Aztec stressed the contracts are immutable legacy code from 2021–2023, but residual TVL in deprecated systems remains a recurring 2026 bridge-loss theme, with 14 bridge exploits and more than $340M stolen year to date per Protos' tally. If old immutable contracts still hold value, they remain live attack surface with fewer defenders watching. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://protos.com/aztec-network-hit-by-second-hack-this-week-as-escapehatch-drained-of-2m/">Protos</a>)</p><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>2026 hacks: 164</p><p>Total amount lost in 2026: $929,947,808</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/56aec60f961c8742029f4a391808d812ac07d8ce0f2d4a97767a19e7d6586bac.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAJCAIAAADcu7ldAAAACXBIWXMAABYlAAAWJQFJUiTwAAABzklEQVR4nGPYsmXL/Pnz792794U2gGHKlCnJyckrV678//8/LkV//v6dPXnylrVr//z9++fv39ykpN1bt/75+5coC3Jzc/X09Lq6ur58+fISG3j44MGfv3/NtTSzEhL+/P378/dvBQH+af29f/7+ffjgwUu8AGRBV1dXYGDg/PnzcfngzevX////t9bRKcnM/P///5+/f5XFxGZPnvz///83r18T9sHKlSujoqIIWmCurp6XmgqxQIaXd0JHB7EWNDY2mpubEwwiZTGxnORkSByIMzK21dUTG0Tz58/38PBYtnw5xHUQJ0MMgqAvX778//9fU0YG4oP////L8PL2trVBfAxRA9GLFTHcu3dv/vz5E/r6yrMy+9tbI/18pNlZz544fvTAgROHDl25cCHEw+PCqVOSLEyxgYH3b986euAAAwNDSkTE/du3tqxdu37VygunTnXU121Zu3bFooWtVVVHDxzYvXXr/du3rHV0mioqGP7//79y5UpNVdXMxCQRbk4tFRUXW1sGBobKoiItFZXYsDAfN1chTs6c5GQlGRkvF5cwf38GBoac5GR1JSVLY2NfNzclGZnMxAQhTk5LY2M7MzM2qKwiHwPDwb27AYF4iEgd9Pk1AAAAAElFTkSuQmCC" nextheight="596" nextwidth="2200" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation </h1><p><strong>Binance May Lose EU MiCA License </strong></p><p>Reuters reported June 16 that Binance's application to Greece's Hellenic Capital Market Commission is set for rejection, which would end its ability to serve EU clients after the June 30 MiCA deadline. Binance said on X it will minimize user disruption and argued HCMC had not signaled noncompliance. </p><div data-type="twitter" tweetid="2066893883875664366">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/binance">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/825a05a18dd4ed4495d5df29cd54cc33a5543f748776d1a00d0d422144765fa1.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/binance" class="twitter-displayname">Binance</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/binance" class="twitter-username">@binance</a></p>
    
            </div>
            <a href="https://twitter.com/binance/status/2066893883875664366" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      Binance remains committed to its European users and will continue to operate in compliance with applicable law.
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/binance/status/2066893883875664366" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            1,854
          </a>
          <a target="_blank" href="https://twitter.com/binance/status/2066893883875664366"><p>2:41 PM • Jun 16, 2026</p></a>
        </div>
    
  </div> 
  </div><p>The case tests whether the EU can force the world's largest exchange out of the bloc or push activity offshore. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="  https://www.reuters.com/business/finance/binance-set-lose-eu-licence-bid-permission-offer-services-bloc-sources-say-2026-06-16/">Reuters</a>)</p><p><strong>NYDFS and EBA Sign Stablecoin Supervisory Cooperation MoU</strong> </p><p>NYDFS and the European Banking Authority signed a non-binding memorandum of understanding on stablecoin supervision, effective after signatures by Acting Superintendent Kaitlin Asrow on April 27, 2026 and EBA Chair François-Louis Michaud on May 13, 2026. Under MiCA Article 126, the pact lets regulators share confidential data on issuers active in both jurisdictions, including reserve composition, holder counts, qualifying shareholders, ICT incidents, and material infringements, with quarterly standing exchanges. Authorities may join each other's on-site inspections and coordinate crisis responses. NYDFS may onward-share with the Fed, OCC, and FDIC; EBA may share with EU MiCA and AML supervisors. EBA judged NYDFS professional-secrecy standards equivalent to MiCA. Stablecoin supervision is becoming cross-border by design; issuers active in multiple jurisdictions should expect reserve, holder, incident, and governance data to move between regulators. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.dfs.ny.gov/system/files/documents/2026/06/mou_06022026_dfs_stablecoin.pdf">New York State Department of Financial Services</a>) </p><p><strong>Coinbase Expands Licensed Brokerage and Derivatives Footprint</strong> </p><p>Coinbase's June 16 system update pushes deeper into regulated markets. U.S. stocks and stock options run through Coinbase Capital Markets Corp, a FINRA/SIPC member with APEX Clearing custody. U.S. futures, crypto options, and prediction markets sit under NFA member Coinbase Financial Markets. Coinbase says it is the first CFTC-approved venue offering global regulated crypto derivatives, including options, to Americans. Coinbase Advisor rolls out as an SEC-registered RIA and NFA-registered CTA for Coinbase One members. Tokenized stocks with 1:1 equity rights launch next month for non-U.S. customers only. The Developer Platform cites 80 regulatory licenses for a custodial offering aimed at partners such as Klarna and Webull. Coinbase is positioning itself less like a crypto exchange and more like a regulated financial platform that can bundle spot, derivatives, equities, advisory, custody, and tokenization. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.coinbase.com/en-it/blog/system-update-take-control-of-your-money-with-coinbase">Coinbase</a>)</p><h2 id="h-legislative-watch" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Legislative Watch </h2><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/19c50f7ddcd16a43a7df8cee8089829397a20e93478ab48ffbb7258f09cc4404.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAQCAIAAAD4YuoOAAAACXBIWXMAAAsTAAALEwEAmpwYAAADAUlEQVR4nKWUUUgTcRzH/+9lT4Eg5INvvfVQvvdWVA+R0kOERC8+FFKgILGEBJWwFAkJR01QRo7mcJYy3UwOd8vN1U62Oe/mdin/iXfr7tx5y/1v7h/bX69rRGh9+HNw//v+ft//7//7cQCAM6BCIPA5GAolWNbvD2ATCCHylCuQ12OCEAIXLl4iBreamgEAp06frq2tra+vBwDU1NTU1dUBABoaGhobG4ksFosZrscyiK4y165eeWsdkWUlvLKyHFxOpdM0TTudzkiFUAWO4yCEHMcd//iHBuMTnqZ7lp6BsRu322/e7Zz1LLFfQ/l8/kSJDBBC8fhaPL6WSqcTLAshBJqW3xGyO0IWZkSe31YUVd3dPdFFVwFhRpIkQRAghKKYBX/MhZD+zwsfwfPfBEH4ZWBWcMktmBER0vcLv9kbgoNSybxzUCohpBf1olmsVQBcckvTfpAYosMYW0fdK5GEjwrbxj+KoowxFkTJSI0QMgwkOTfjoRVFNc5nfIIwU66gu8+2zm0SaSAU24ICxnh+IWh3zA0OOyYmfa5pSpJz3X02RVGj8ZSPCn+ivpAQmBFbWrsftL9o6xiIxjckOUeKJk6HFcx46Dv3uzDG4xOe5pYnI7YpknfENnX2/HWMsd0xZx11Rxj2cedQIBQbtk4KokTRDMY4mYZO92IgFHO4FlofPe989rqr982Mx48x3i+gVJovV+CjwuDcZZgRHa4FimbWuU0uuanu5a2j7sFhB8ZYUdT9QkFR1P4hO0I6KdFHhX1UOBrfiMZT5ELcs0tTHyjXNNU/ZB9752l/+irB8bpeKDf5vXuxrWNAknOkaSRAFGVy+8g0IUW9SARFvfiw46XTvagoatWAfJd2mVWO57cT7Ea5AoxL6l4+wrDks2Fgbhehan7IaJgxZuRIj8o9MI0pkmXFbCCKWfPxNS1PBMYSxay6p5l3DEF51rkkhBmgaZpQgTSd2Bp/0KozVu2gCn8XAJr2WyyWnp5er9fLMKvBYHDe64MQGvH/g6ZpPwFgt0nHmmli7AAAAABJRU5ErkJggg==" nextheight="964" nextwidth="1912" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://polymarket.com/event/clarity-act-signed-into-law-in-2026">Polymarket</a>)</figcaption></figure><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research </h1><p><strong>Audit Findings and Exploit Losses Measure Different Risks </strong></p><p>Stefan Beyer's June 13 paper pairs 23,818 public audit findings from 22 firms with 218 Rekt-documented exploits totaling about $7.76B from January 2022 through March 27, 2026. Audit output stayed stable: Critical-plus-High findings held in a 15–17% band, and logic, access control, and input validation dominated reports. Losses shifted after 2022: human-vector attacks (key theft, phishing, supply chain, governance) took 49.6% of dollar damage but almost no audit share. Access control was the only top category on both sides. Eight incidents drove 50.6% of losses. Beyer concludes code audits and operational-security reviews are complementary, not interchangeable. The paper gives data to something security teams already feel: smart-contract audits reduce code risk, but they do not cover the operational failures driving a large share of losses. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2606.15465">arXiv</a>)</p><p><strong>Web3 Security’s Blind Spot: Off-Chain Failures and Audit Gaps</strong></p><p>Tarkan Yavas and Arslan Brömme argue that Web3 security research still over-focuses on smart contracts while real losses often come from off-chain systems, key management, governance, and human workflows; their incident-based study maps major breaches to Web2 security frameworks and calls for blockchain-specific information security management systems controls. Web3 security programs need to look more like full information-security programs, with controls for people, keys, vendors, governance, and operations, not just Solidity review. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2605.18484">arXiv</a>)</p>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>security</category>
            <category>cybersecurity</category>
            <category>regulations</category>
            <category>hacks</category>
            <category>exploits</category>
            <category>tools</category>
        </item>
        <item>
            <title><![CDATA[0x37 Web3 Security Bulletin ]]></title>
            <link>https://paragraph.com/@w3sb/0x37-web3-security-bulletin</link>
            <guid>JapE79lMct5Jk5qIkKgh</guid>
            <pubDate>Fri, 12 Jun 2026 10:34:45 GMT</pubDate>
            <description><![CDATA[Security intelligence for Web3, digital asset infrastructure, and the capital shaping the industry. ]]></description>
            <content:encoded><![CDATA[<p>TL;DR</p><ul><li><p>Pashov’s Solidity Auditor v3 is the most interesting AI-security signal this week: it reportedly found 14 of 17 documented high and medium findings in a cross-chain DEX contest in under 20 minutes. That is capability validation, not a reason to replace expert review.</p></li><li><p>Humanity Protocol is the cleanest operational lesson: the incident was not a smart-contract bug, but exposed private keys, compromised Safe control, and bridge/admin risk. Web3 still breaks at key management and governance.</p></li><li><p>Chainalysis flagged roughly $36.7M stolen from unverified smart contracts across Truebit, Trusted Volumes, Aperture Finance, and Ekubo. Closed-source bytecode is not a security boundary when attackers can decompile, diff, and reason through deployed contracts.</p></li><li><p>Visa and Mastercard both moved deeper into agentic and machine-driven payments, with stablecoins, tokenized credentials, fraud signals, and multi-rail settlement becoming part of the payment stack. The agent-commerce story is moving from demo layer to infrastructure layer.</p></li><li><p>Joe Lubin said Ethereum could become a fully zero-knowledge-proof-based protocol within three to five years, with ZK work improving both Layer 1 performance and composability across Layer 2s. The practical security question is whether real-time proving, atomic execution, and cross-L2 liquidity can mature without creating new trust, governance, or implementation risks.</p></li><li><p>Regulators kept tightening the perimeter around crypto markets, stablecoins, prediction markets, sanctions, and platform obligations. The practical takeaway for builders is that compliance design is becoming part of product architecture, not a legal afterthought.</p></li><li><p>In research, Alireza Kavousi, István András Seres, and Zhipeng Wang propose Proof of Source of Funds, a zero-knowledge framework for proving cryptoasset provenance without exposing a user’s full transaction graph, counterparties, or source addresses. The important shift is from platform-side surveillance to user-side proof: protocols can verify that funds came from compliant sources with constant-time checks, while users preserve more financial privacy.</p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis</h1><p><strong>Joe Lubin Sees ZK-based Ethereum </strong> </p><p>The Block interviewed Consensys CEO Joseph Lubin, who said Ethereum could become a fully zero-knowledge-proof-based protocol within three to five years as Lean Ethereum work and real-time ZK proving on Layer 2s mature. Lubin defended the rollup-centric roadmap as an exploration phase that will converge through synchronous ZK composition across networks like Linea and Gnosis, potentially unifying liquidity without traditional bridges. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.theblock.co/post/404185/ethereum-fully-zero-knowledge-proof-based-protocol-3-to-5-years-joe-lubin">The Block</a>)</p><p><strong>Pashov Releases Solidity Auditor v3 </strong></p><p>Pashov Audit Group published <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://github.com/pashov/skills">Solidity Auditor v3</a>, an AI security skill for smart contract review, reporting that it caught 14 of 17 documented high and medium findings (82.4% recall) in the eight-day cross-chain DEX contest in under 20 minutes. This was against five highs and twelve mediums found by roughly 100 human researchers over the contest window. The v3 update adds shared Feynman, Socratic, and inversion reasoning steps plus three “gap hunter” agents. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.pashov.com/solidity-auditor-v3">Pashov</a>)</p><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements </h1><p><strong>Visa Pushes Agentic Commerce, Tokens, and Stablecoins</strong></p><p>Visa announced at Visa Payments Forum 2026 in San Francisco a bundle of AI, token, and stablecoin capabilities for programmable commerce. Chief Product &amp; Strategy Officer Jack Forestell framed AI as reshaping transaction initiation and stablecoins as modernizing settlement. New pieces include Agent Score (with New Generation) for merchant agent-readiness, an Agentic Directory of verified agents and merchants, an OpenAI partnership for agentic payments, and a Large Transaction Model trained on billions of transactions for fraud and authorization. Visa also detailed token context and assurance signals, bank tokenized-deposit infrastructure, expanded stablecoin settlement (about $7 billion annualized on VisaNet as of March 2026), and 160-plus stablecoin-linked card programs live or in development. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.businesswire.com/news/home/20260610464331/en/Visa-Announces-New-AI-Stablecoin-and-Token-Innovations-to-Power-Intelligent-Programmable-Commerce-at-Visa-Payments-Forum">Business Wire</a>)</p><p><strong>Mastercard Launches Agent Pay for Machines </strong></p><p>Mastercard said on June 10 that it introduced Agent Pay for Machines (AP4M), extending its 2025 Agent Pay program to permission, orchestrate, and settle continuous micro- and machine-driven payments at low latency across its network. The service covers credentialing via Verifiable Intent, programmatic spending limits, high-frequency transacting among verified participants, and guaranteed multi-rail settlement across cards, bank accounts, and stablecoins. Chief product officer Jorn Lambert framed the launch as infrastructure for agent-to-agent commerce at volumes and ticket sizes traditional checkout rails were not built for. More than 30 partners, including Adyen, Coinbase, Stripe, Cloudflare, OKX, Polygon Labs, and the Solana Foundation, are supporting adoption, with broader access planned later in 2026. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.mastercard.com/us/en/news-and-trends/press/2026/june/mastercard-launches-agent-pay-for-machines.html">Mastercard</a>) </p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents</h1><p><strong>Humanity Protocol Loses Over $30M</strong></p><p>Humanity Protocol’s <a target="_blank" rel="noopener noreferrer" class="dont-break-out" href="https://humanityprotocol.notion.site/H-Token-Incident-Update-37ab0ec467a781d7af06e7dcedd66852">incident update</a> on June 9 describes coordinated attacks on June 8–9 across Ethereum and BSC after malware on a colleague’s machine exposed seven private keys. An admin hot wallet lost 6.05M H; three compromised ETH Safe keys transferred bridge ProxyAdmin to an attacker who upgraded the bridge and swept ~141.2M H; three separate BSC Safe keys enabled a malicious implementation and three 100M H mints, inflating BSC supply from ~141M to ~441M. The team said no smart-contract bug was involved, only stolen signing keys, and that BSC ProxyAdmin remains attacker-controlled with further mints possible. ETH H token and the Arbitrum bridge were unaffected; a victim recovery program and external forensics are underway.</p><div data-type="twitter" tweetid="2064167144120877127">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/Humanityprot">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/c8e95fe2c0531ab2c68dae6842c29a6f3ebc2e3755c528f0afba33afccddc30d.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/Humanityprot" class="twitter-displayname">Humanity</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/Humanityprot" class="twitter-username">@Humanityprot</a></p>
    
            </div>
            <a href="https://twitter.com/Humanityprot/status/2064167144120877127" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      We're aware of a security incident involving the compromise of private keys belonging to a member of the Humanity Foundation. The safety of our community is our top priority, and we want to be fully transparent about what we know.<br>As a precaution, please do NOT interact with the
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/Humanityprot/status/2064167144120877127" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            422
          </a>
          <a target="_blank" href="https://twitter.com/Humanityprot/status/2064167144120877127"><p>2:06 AM • Jun 9, 2026</p></a>
        </div>
    
  </div> 
  </div><p><strong>Key Management Was the Failure Mode</strong></p><div data-type="twitter" tweetid="2064729401494004001">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/rezosh">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/6715b8059c7a91f9f35da58d422dc2989a54281b442e7c8c83c93ebebf4883b3.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/rezosh" class="twitter-displayname">Rezo🛡₿RRR</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/rezosh" class="twitter-username">@rezosh</a></p>
    
            </div>
            <a href="https://twitter.com/rezosh/status/2064729401494004001" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      The Humanity Protocol (in two parts) hack wasn't a sophisticated smart contract exploit, it was private keys on a laptop, and by then, the project had already spent weeks building exactly the kind of shady-shitty-dirty exit-liquidity structure that usually ends badly.<br><br>Part One: 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/27ede0860c611823691a4e75bad09fb88d67948f2f9436d83877c655f41a0684.jpg"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/rezosh/status/2064729401494004001" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            6
          </a>
          <a target="_blank" href="https://twitter.com/rezosh/status/2064729401494004001"><p>3:20 PM • Jun 10, 2026</p></a>
        </div>
    
  </div> 
  </div><p><strong>Chainalysis Flags $36.7M Stolen from Unverified Smart Contracts</strong></p><p>Chainalysis reports attackers drained about $36.7M from four DeFi protocols whose production contracts were never verified on block explorers: Truebit ($26.2M), Trusted Volumes ($5.9M), Aperture Finance ($3.2M), and Ekubo ($1.4M). Closed-source bytecode no longer deters skilled attackers when decompilers and LLMs can triage vulnerabilities at scale, and unverified code often sits outside bug bounty scopes. The firm advises verifying implementations (including proxy backends), extending bounty coverage, and adding real-time on-chain monitoring when source is withheld. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/attackers-exploiting-unverified-smart-contracts/">Chainalysis</a>) </p><p><strong>Halborn Dissects Syscoin Bridge SPV Parsing Failure</strong> </p><p>Halborn's postmortem on the Syscoin bridge hack explains that an attacker minted roughly 5B SYS (~$10M) on the UTXO side without a matching burn on NEVM. The flaw was not broken SPV cryptography but a parsing error in the bridge relay that treated a malformed proof as valid for a nonexistent burn. Halborn compares the pattern to the 2022 Nomad bridge incident: implementation logic, not the underlying proof system, failed. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.halborn.com/blog/post/explained-the-syscoin-bridge-hack-june-2026">Halborn</a>)</p><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>2026 hacks: 162</p><p>Total amount lost in 2026: $927,702,808</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/e94ff5c7a278cdb941dd34646b685dda6138bec869f9f6c6d60d93b7a65c0e05.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAICAIAAAAX52r4AAAACXBIWXMAABYlAAAWJQFJUiTwAAABq0lEQVR4nJWRu0srQRSHT6MIksJKg2ChgtpYBB8xybUwi7BBRHyEJRCz+IrRvRAVFbex2E7TTusfsVoIIQHfEtFC0ELRIrNLimW2yLLdDiM6ECz06v2Y4hS/wzc/DiCEJElCCFnfU3Wc21LptlTi87GunxYKVcexfsJ1XUAIybKsaVq5XP4yZGDsUfpXltOJhEepR+mkEF1fWvAoNTD+D8F3IeNDoKSSyYnxmiC7+GuBruuqquZyuX83WJCkuChyQSwSWUmlfivI5/OapvEbuF9hE8IYSycScVFkH/AGjDGbEPcn3htkMpm9/f2q4/Dnui4f+Ekty2KMzcdnYsN/eIO4KCanpjxKP3/2c76GRykUCwVVVRFCV2cn+aPD6/Pz7NxcxTQrpmkTYhNyUSzi15eNdHqwu5s36OvsFAb6GWMGLhsYGxhXTPPl+ckm5P7urrZ7c3l5gBAwxh4eHyPB4Oz0JAB0+Ft8AO0t/i1lNdDTs60oTQBDvb3jgtAEsK0oQjjsb2ysA1iWU2MjI11tbTtr2eaG+mgwGAoEWn2+0XAoGgrtbm4CwHRMfAOMXT64fTkmCQAAAABJRU5ErkJggg==" nextheight="588" nextwidth="2214" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation </h1><p><strong>NYDFS Proposes GENIUS Act-aligned Stablecoin Regulation</strong></p><p>Acting Superintendent Kaitlin Asrow of the New York Department, proposed a formal stablecoin rule building on DFS’s June 2022 guidance and aligning with federal requirements under the GENIUS Act. The proposal keeps prior dollar-stablecoin standards on backing, redeemability, permissible reserves, and independent audits, and adds Treasury-aligned provisions such as caps on reserves held with any single custodian and mandatory risk-management programs covering internal controls, information security, insider transactions, and service-provider arrangements. A 10-day pre-proposal comment period opened June 9, followed by a 60-day period after State Register publication. The final rule would take effect with the GENIUS Act, with a one-year transition for existing New York-licensed issuers; until then, DFS stablecoin guidance remains in force. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20260609">NY Department of Financial Services</a>)</p><p><strong>CFTC Proposes Prediction-market Contract Boundaries</strong> </p><p>The CFTC released a 267-page proposed rule distinguishing permissible event contracts, including sports, from restricted event contracts like terrorism, assassination, and war markets. Chair Michael Selig said additional rule makings are coming. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.cftc.gov/media/14151/NPRM_PredictionMarkets060926/download">CFTC</a>)</p><div data-type="twitter" tweetid="2064700256021815506">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/ChairmanSelig">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/9d1bbecb9782eb63956c8271d24a2030d994ead9eddaa9c216b9e382b7546b14.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/ChairmanSelig" class="twitter-displayname">Mike Selig</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/ChairmanSelig" class="twitter-username">@ChairmanSelig</a></p>
    
            </div>
            <a href="https://twitter.com/ChairmanSelig/status/2064700256021815506" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      I'm pleased to announce that today, the <a class="twitter-content-link" href="https://twitter.com/CFTC" target="_blank">@CFTC</a> is officially seeking public comment on a structured framework for evaluating the types of events that may underpin contracts traded on prediction markets.<br><br>This proposal would give the CFTC durable, transparent rules of the road to
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/ChairmanSelig/status/2064700256021815506" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            321
          </a>
          <a target="_blank" href="https://twitter.com/ChairmanSelig/status/2064700256021815506"><p>1:24 PM • Jun 10, 2026</p></a>
        </div>
    
  </div> 
  </div><p><strong>SEC Crypto Task Force Continues Receiving Industry Input</strong></p><p>As recently as June 5th the SEC's Crypto Task Force was still accepting written input from industry stakeholders, including submissions on privacy-preserving verification for autonomous systems. These efforts reflect an ongoing open-door policy under Chairman Paul Atkins, a sharp departure from the enforcement-first posture of the prior administration. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.sec.gov/featured-topics/crypto-task-force/crypto-task-force-written-input">SEC</a>)</p><p><strong>EU Proposes 21st Russia Sanctions Package </strong></p><p>European Commission President Ursula von der Leyen said that the EU’s 21st Russia sanctions package extends transaction bans to 31 additional Russian banks and 20 third-country banks, crypto platforms, and oil traders accused of serving sanctioned Russians or circumventing EU measures. For the first time, Brussels would gain authority to impose a full third-country ban on crypto-asset services from jurisdictions hosting platforms that help Russia evade sanctions. Vice President Kaja Kallas said the package also bans transactions on 11 crypto platforms. Member states must approve the measures before they take effect. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://ec.europa.eu/commission/presscorner/detail/en/statement_26_1314">European Commission</a>)</p><h2 id="h-legislative-watch" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Legislative Watch </h2><p><strong>House Crypto Tax Hearing Shows Partisan Split</strong> </p><p>The Block covered a June 9 House hearing on digital-asset taxation where lawmakers disagreed on how quickly to move on standalone crypto tax bills, versus waiting for broader market-structure legislation such as the CLARITY Act. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.theblock.co/post/404187/house-crypto-tax-hearing-legislation">The Block</a>)</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/4b6ba1270274f7f554104f11681b72869204d90407140e4388ecf923d7bf2ac3.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAARCAIAAAAzPjmrAAAACXBIWXMAAAsTAAALEwEAmpwYAAADF0lEQVR4nK1U30sUURS+MG8bQRL4EPhYUdBfED4GJfakr5IUYYU/KMqwgjRbMiVKaF9cbCSHJCXHldUQbdmk1XAtd4x1Nndc2lGcHdi5jM2sO/cO7o3da5OtJFh9D5czM2fOd893v3PB0PAoAODQkaMIIRvjrGUhhMj/AzhcdhwUcOVqU2Xl+QftD2trazmO43me4ziWZQcHB3me9/v9TU1NLS0tkiTtj4BlvZSgo+MRAODgAdeJkycZhgEAuFwuhmFcLldJSUl5eTnDMKWlpeFweH8Eqqo9ff5qfHImEAzPzH1ZW1Ozm5u2bZO/hWlm0E/kCaJiov5mp7vzRXVNc/m5y9zAaHRudn1tLWtZhmEghIwCnGDv6gihD6GQICwuRCILkQiEEOz9A8b7bgVjm25/XVFMMwMwtk1zk65ZC2Ns2zi/Zi28kwP/mQljeyuX250gy7JhGPkOnG8Y2zSOxZOD/BQhZG4+WpRACNnK5YoINKjT97QCTYMQIoTAsC/gVHEKKal0q7snKiZa3T1d3f0Y28LiclRMEEJUVdOgLq2sOtXHJ2futnlCs0KRsKmUmpfofejz42cvCSEa1FvdPR7vkAZ13h9kOX9FVeOwLxARvo5PznhZnuX8sx8F39h0/+u3U8G5+U9LhJComDhb1dB8r7uiqpHl/MO+QCyeFGP5rawrSl4ieTUFwDEIN3xj0xevPej2DHhZ3uMdmpicLTtVSZvzsjyEG16Wv3HnqQZ139i0BvVAMD8QUTEhraxmLaxB/W6b50Ld/YZbXZfq25VUOpVSs5YFNKifPnPxzcg7/0RIg/p3I0PblFZWe/tGdmodiyep1lSB96HPdQ3u3r4R6hGaoKTSppkJBMPVNc2iuIyQlT9kVdWu334SiyeLLEFjUgjo6DmPlNI3Nk3VKPLIb4eMEDLNDCG5gnctx8XOTJJdBt95kgihIo8hhKjFvyWT2zZ1UDSou0fXMIzCbraxlculNa3o9qVj/6uDpaUlroBgMChJK6IYE4RFWd524b8DyLJMb2NBENYVJR6XRDGW1rT/RfADHM+Zgq6PDoYAAAAASUVORK5CYII=" nextheight="1012" nextwidth="1928" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://polymarket.com/event/clarity-act-signed-into-law-in-2026">Polymarket</a>)</figcaption></figure><h1 id="h-capital-allocation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Capital Allocation </h1><p><strong>Helius Acquires Light Protocol to Build Solana Privacy Layer</strong></p><p>Helius announced that it is acquiring Light Protocol, the Solana privacy team behind original ZK syscalls (<code>sol_poseidon</code>, <code>alt_bn128</code> operations) and ZK Compression, which the company says can cut onchain state costs by up to 1000x. Light engineers will join Helius to ship a programmable onchain privacy layer for Solana covering encrypted balances, payments, and markets with auditability and selective disclosure for institutions. CEO Jorrit Palfner said joining Helius provides the engineering depth and distribution to make privacy the default. Helius framed privacy as a prerequisite for Solana to host traditional-finance workloads rather than surveillance-scale transparency alone. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.helius.dev/blog/light-protocol-acquisition">Helius</a>)</p><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research </h1><p><strong>Proof of Source of Funds for Onchain Asset Provenance</strong></p><p>Researchers propose Proof of Source of Funds (PoSoF), a cryptographic framework that lets users prove deposits come only from compliant sources via zero-knowledge proofs instead of relying on inclusion lists or centralized chain analytics. Platforms verify admission in constant time, about 1.5 ms (~800k gas) on an Ethereum-compatible prototype, while the user’s intermediate transaction graph stays private. The design models UTXO and account ledgers as a unified temporal DAG, extracts a compliant sub-DAG, and uses Incrementally Verifiable Computation so proofs update in roughly 1.8 seconds per new transaction. The authors argue this moves monitoring burden off DeFi and privacy protocols onto user-side provenance with formal security properties. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2606.10172">arXiv</a>)</p><p><strong>GiAnt Corpus for Automated Smart Contract Auditing </strong></p><p>Authors introduce GiAnt (GPT-assisted Auditing Dataset Construction), a framework that distills structured vulnerability data from real-world audit reports to overcome manual curation limits and weak granularity in existing benchmarks. GiAnt applies divide-and-conquer extraction with chain-of-thought parsing on Code4rena reports, then uses an LLM-as-judge step for quality control. Running on 388 reports produced the GiAnt Corpus with 7,711 findings across five severity levels. The team benchmarks four LLMs on vulnerability detection, code summarization, mitigation recommendation, and gas optimization to set baselines for automated auditing research. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2606.07363">arXiv</a>)</p><p><strong>Web3 Security Failures Aren't On-Chain — They're Human</strong></p><p>Tarkan Yavas and Arslan Brömme argue in this incident-based analysis that the dominant security failures in Web3 originate not from smart contract bugs, but from off-chain systems and organizational processes. Examining high-profile breaches including Bybit (2025, ~$1.5B), Ronin Network (2022), and DMM Bitcoin (2024, ~$300M), the authors map failure patterns to OWASP and ISMS frameworks. Their key finding: existing generic security control catalogues fail to address cryptographic key management, signer governance, and human-in-the-loop risks specific to blockchain environments. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2605.18484">arXiv</a>)</p>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>security</category>
            <category>cybersecurity</category>
            <category>regulations</category>
            <category>hacks</category>
            <category>crypto</category>
        </item>
        <item>
            <title><![CDATA[0x36 Web3 Security Bulletin ]]></title>
            <link>https://paragraph.com/@w3sb/0x36-web3-security-bulletin</link>
            <guid>eU1M48DnKiUIlPMQ9JDF</guid>
            <pubDate>Fri, 05 Jun 2026 11:30:51 GMT</pubDate>
            <description><![CDATA[Security intelligence for Web3, digital asset infrastructure, and the capital shaping the industry.]]></description>
            <content:encoded><![CDATA[<p><strong>TL;DR</strong> </p><ul><li><p><strong>Zcash had the nightmare bug:</strong> A critical Orchard circuit flaw could have allowed unlimited undetectable counterfeit ZEC since 2022. The emergency fork is done, but privacy means the chain cannot prove whether it was exploited.</p></li><li><p><strong>Privacy wrappers met issuer reality:</strong> Circle froze, and then a court unfroze, roughly $12.5M in Zama’s cUSDC contract. The lesson: confidential balances still inherit stablecoin issuer, court-order, and pooled-contract risk.</p></li><li><p><strong>Agentic payments are no longer theoretical:</strong> x402 payments on Base crossed 100M transactions in nine months, while new research highlights x402 risks, including payment-proof substitution, race conditions, and resource leakage.</p></li><li><p><strong>May’s exploit pattern shifted toward trust layers:</strong> NOMINIS tracked $124.9M stolen across 11 major incidents, with bridges, admin keys, operational wallets, and access controls doing more damage than classic smart-contract bugs.</p></li><li><p><strong>Gravity Bridge is the headline bridge failure:</strong> A poisoned denom registry mapping let attackers drain about $5.4M without compromising validator keys, proving again that bridge metadata and claim paths need the same scrutiny as signatures.</p></li><li><p><strong>Regulators are compressing the calendar:</strong> Europe is debating stablecoin competitiveness, Australia has a June 30 AFSL deadline, the UK is moving toward September 2026 crypto authorization, and U.S. market-structure politics are back on the clock.</p></li><li><p><strong>Privacy infrastructure is attracting capital and scrutiny:</strong> SOL Strategies bought HoudiniSwap for $18M, while Zcash, Zama, Houdini, and quantum-risk research all point to the same tension: privacy is becoming investable, regulated, and much harder to threat-model.</p><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div></li></ul><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis</h1><p><strong>Zooko Discloses Critical Orchard Counterfeiting Bug in Zcash</strong></p><p>Zooko Wilcox, Jason McGee, and Taylor Hornby said in a June 4 X article that Taylor Hornby found a critical soundness flaw in Zcash’s Orchard circuit on May 29 while auditing for Shielded Labs, using Anthropic’s Opus 4.8 alongside traditional review. The under-constrained elliptic-curve check could have minted unlimited undetectable counterfeit ZEC inside Orchard since the pool went live in May 2022. Hornby built a working exploit in regtest; ZODL coordinated an emergency soft fork on June 2 and NU6.2 on June 3 to disable then re-enable Orchard with a fixed verifying key. Privacy means cryptography cannot prove whether mainnet was exploited before the fix. Shielded Labs argues prior abuse is unlikely but proposes a follow-on upgrade with turnstile accounting to let anyone verify supply integrity. $ZEC is down ~30% on the news, shedding ~$4B of market cap. </p><div data-type="twitter" tweetid="2062644925590900980">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/zooko">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/2209b43144d73c0b7f9c290e1d559b5825c529b809a0dac3aaf5e9ce7a6e2923.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/zooko" class="twitter-displayname">zooko🛡🦓🦓🦓 ⓩ</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/zooko" class="twitter-username">@zooko</a></p>
    
            </div>
            <a href="https://twitter.com/zooko/status/2062644925590900980" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      <a class="twitter-content-link" href="https://t.co/v7BiOdzU9E" target="_blank">x.com/i/article/2062…</a>
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/zooko/status/2062644925590900980" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            1,671
          </a>
          <a target="_blank" href="https://twitter.com/zooko/status/2062644925590900980"><p>9:17 PM • Jun 4, 2026</p></a>
        </div>
    
  </div> 
  </div><h2 id="h-usdc-freeze-then-reversal" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">USDC Freeze, Then Reversal </h2><p><strong>Circle Freezes $12.6M in Zama’s cUSDC Contract</strong> </p><p>The Block reported that a federal judge ordered Circle to blacklist Zama’s confidential USDC wrapper on May 30, freezing about $12.6M  in a pooled contract tied to an Overnight Finance treasury dispute. Plaintiffs including Patagon Management alleged founder Maxim Ermilov moved more than $15M ahead of an OVN holder vote to liquidate the treasury. Zama CEO Rand Hindi said the pool was collateral damage and paused cUSDC, cUSDT, and cWETH contracts while investigating. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.theblock.co/post/403091/court-ordered-circle-freeze-traps-12-6-million-in-zama-cusdc-contract-amid-overnight-finance-suit">The Block</a>)</p><p><strong>Paolo Caversaccio Critiques Zama Privacy Tradeoffs </strong></p><p>Security researcher Paolo Caversaccio posted on X after Circle blacklisted Zama’s confidential USDC contract, questioning how much privacy the cUSDC wrapper provides when issuer-level freezes can immobilize an entire pooled contract. The thread feeds the debate over whether confidential balances on public chains reduce traceability without shifting trust to stablecoin issuers and court orders. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/pcaversaccio/status/2061567394716528959">Paolo Caversaccio on X</a>)</p><p><strong>US Court Lifts Circle Freeze on Zama's $12.5M cUSDC Contract</strong></p><p>A federal judge in California's Northern District reversed the temporary restraining order that had pushed Circle to blacklist Zama's confidential USDC (cUSDC) wrapper. The underlying fraud suit continues; only the blanket contract freeze was lifted. The Defiant frames this as the first court-ordered Circle contract-level blacklist in a private civil dispute to be unwound through litigation, and notes that contract owners and innocent depositors can be heard quickly when a pooled freeze sweeps in third parties. Zama pledged "transitive compliance" so future Circle freezes on a specific USDC address propagate only to that address's cUSDC balance, plus a compliance council, KYT vendor integrations, and industry-group participation. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://thedefiant.io/news/defi/us-court-lifts-circle-freeze-zama-cusdc-three-day-lockout">The Defiant</a>)</p><div data-type="twitter" tweetid="2061847281981333943">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/DefiantNews">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/5a41abc20a0932e1416611383adab68d01307e5f403cfb62cbf928b9879acc74.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/DefiantNews" class="twitter-displayname">The Defiant</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/DefiantNews" class="twitter-username">@DefiantNews</a></p>
    
            </div>
            <a href="https://twitter.com/DefiantNews/status/2061847281981333943" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      ZAMA'S PRIVACY USDC WAS UNFROZEN<br><br>A federal judge reversed Circle's $12.5M cUSDC blacklist on @Zama's privacy protocol after a three-day freeze, restoring access to depositors caught in a civil dispute.<br><br>Read more here:<br><a class="twitter-content-link" href="https://t.co/MuaXxDOmFF" target="_blank">thedefiant.io/news/defi/us-c…</a> 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/e55d0cd9b289a023cd9e6e9b26c118e5b861b20d1bf06c5516517d413b643598.png"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/DefiantNews/status/2061847281981333943" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            63
          </a>
          <a target="_blank" href="https://twitter.com/DefiantNews/status/2061847281981333943"><p>4:27 PM • Jun 2, 2026</p></a>
        </div>
    
  </div> 
  </div><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements</h1><p><strong>Nine Months in: 100 million x402 Agentic Payments on Base</strong></p><p>Chainalysis reported that agentic payments on Base crossed 100 million transactions in roughly three quarters, surging from near-zero in Q3 2025 before cooling in early 2026. The post treats x402 as a machine-to-machine settlement rail and a monitoring surface for unauthorized agent spend. Security teams should watch HTTP-native payment flows alongside traditional wallet screening as volume scales. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/x402-agentic-payments-adoption/">Chainalysis</a>) </p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents</h1><p><strong>May’s Crypto Exploits Shift From Megahacks to Bridges and Keys</strong></p><p>NOMINIS’ latest monthly report tallies $124.9 million stolen across 11 major incidents in May, a 79% drop from April’s roughly $585.6 million but still heavily DeFi‑driven. Cross-chain bridges accounted for 42% of top attacks, while compromised admin keys, operational wallets, and broken access controls produced the largest single losses. The report warns that attackers are pivoting from classic contract bugs to the trust layers—bridges, signers, and privileged infrastructure—that bind ecosystems together. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.nominis.io/insights/nominis-monthly-report-crypto-exploits-and-attacks-in-may-2026">NOMINIS</a>)</p><p><strong>Gravity Bridge Drained via Poisoned Denom Registry Mapping</strong> </p><p>Rekt News explains how Gravity Bridge lost about $5.4M on May 29 without compromising validator keys. The attacker minted worthless tokens on Osmosis, IBC-transferred them to Gravity chain, then called permissionless <code>deployERC20()</code> on Ethereum with fabricated <code>cosmosDenom</code> strings that embedded real custody contract addresses. Validators signed withdrawal batches that mapped through a poisoned registry to genuine USDC, USDT, WETH, and PAXG in bridge custody. Rekt attributes the failure to missing collision checks in <code>handleErc20Deployed</code>; a lookup existed elsewhere in the codebase but was not invoked on the claim path, plus predictable IBC denom metadata that satisfied validation. Proceeds moved through Tornado Cash. The bridge was halted May 30. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rekt.news/gravity-bridge-rekt">Rekt</a>)</p><p><strong>Alephium Bridge Drained via Forged Guardian Messages</strong></p><p>BeInCrypto reported that Alephium’s Wormhole-fork TokenBridge lost about $815,000 in seven minutes on May 30 when an attacker submitted malicious cross-chain messages that guardians signed. The team said private keys were not compromised and that the flaw was in message validation before signing. Blockaid and SEAL_911 assisted the response. The bridge remains offline. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://beincrypto.com/alephium-bridge-exploit-forged-messages/">BeInCrypto</a>)</p><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>Total 2026 hack events: 151</p><p>Total amount lost this year: $905,221,838</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/4b59dfa90efdc22e75e6a1ba447c201cf928d5bf3169079b0a728a6ac501f68c.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAICAIAAAAX52r4AAAACXBIWXMAABYlAAAWJQFJUiTwAAABtklEQVR4nJWRP0gCYRjGbw0qcLHIpKDAIQuLIqSQsz8WEVQQtwQ2SkMHFtxQ6BK1xi0uDhc6HB3FNUR80T8Uh2h0Mbm047DThs8Gr4/K+/gihIgGrYdneHh5H37wvpQgCCzLAgAIIaiuzo6Pa8HEWM3nozxvYly/ghCiRFHkOE6W5YYAZ0cHhLAGuD4HEy4XIeSlXG4AiEQifr9fFEWEEKyrHoulUChACD+q1RNJ8vQPmBgXdb1O5QsgCALDMP8FSPH4XwEAgHA43OgHBkKox2Ip6jpCiBByFI/RQ4N/OhEAgGVZWZZNjCuGYbx+TSuG8csf1Wp3a4uiKBXDMDGWYgfToyMmxhDC753v4s9AJRIJjuOkw8PU1VWU5x/uM8uTk3eplJrP6ZpWc5Tnn0slR1vb5enpc6lECJ4fH3d22t7f3nLZ7JOmZtJpXdNuk8lcNqtrWvLiQlUenjT1pQwpQsj1zc0UTYeCwS6rdczlmnK725ub93d2F2Zm/AyzvbnRRFF7odBwX9/K0uLO9pbP45nzerus1rXVVW59vddmCwYCszTtsNuDgcCw07nk8815vbTb/agon7enWKRZoswqAAAAAElFTkSuQmCC" nextheight="572" nextwidth="2212" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(SlowMist)</figcaption></figure><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation </h1><p><strong>ECB’s Schnabel Pushes Digital Euro as Stablecoin Counterweight</strong></p><p>ECB executive board member Isabel Schnabel’s June 1 speech in Seoul warned that stablecoins pose monetary-policy and dollar-dominance risks, with nearly $300 billion in circulation concentrated in USDT and USDC. Schnabel argued central banks should regulate stablecoins and offer retail CBDCs such as the digital euro. The digital euro is targeted for potential issuance around 2029. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.theblock.co/post/403142/digital-euro-stablecoin-risks-ecb">The Block</a>)</p><p><strong>Coinbase Urges MiCA Tweaks for Euro Stablecoins </strong></p><p>Katie Harries argued that the European Commission should adjust the European Commission to adjust MiCA implementation so euro-denominated stablecoins can compete with dollar tokens. Specifically she argues the Commission should loosen reserve rules (less concentration in commercial bank deposits), allow non-interest rewards (cashback, loyalty), and improve the multi-issuance model for global liquidity. Compliance teams should read it alongside the July 1 licensing cliff and the Commission’s broader MiCA review. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.coinbase.com/blog/making-europes-crypto-markets-more-competitive">Coinbase</a>) </p><p><strong>UK FCA's Crypto Consultation Closed June 3</strong></p><p>On June 3, the UK's Financial Conduct Authority concluded its consultation on the regulatory perimeter for crypto asset activities, covering stablecoin issuance, trading platforms, custody, and staking. The FCA confirmed final rules will be published this summer, with full regulatory authorization for crypto firms opening in September 2026 ahead of a formal regime launch in October 2027. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fca.org.uk/news/press-releases/fca-consults-guidance-uk-future-crypto-regime">FCA</a>)</p><p><strong>CFTC Clears Coinbase to Offer Deribit Perps as Foreign Futures</strong></p><p>The CFTC Market Participants Division issued an interpretive letter and no-action relief on May 29 in response to Coinbase Financial Markets (CFM). Staff confirmed Deribit perpetuals may be categorized as foreign futures under Regulation 30.1, leaning on the same-day Kalshi BTC PERP order for domestic bitcoin perpetuals. Subject to nine conditions, staff will not recommend enforcement if CFM posts customer-owned digital commodities and payment stablecoins with Bermuda affiliate Coinbase Bermuda to margin foreign futures and options on Deribit FZE, including when the broker re-uses collateral for Deribit margin. The relief is staff-only, not Commission rulemaking, and is limited to perpetuals structured like Deribit’s on digital commodities with active spot markets. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.cftc.gov/PressRoom/PressReleases/9241-26">CFTC</a>)</p><p><strong>Senator Lummis Warns Delayed Clarity Act Could Push Regulation to 2030 </strong></p><p>Senator Cynthia Lummis argues that failure to pass the Clarity market-structure bill now could defer comprehensive U.S. crypto regulation until 2030, intensifying lobbying from industry groups ahead of Senate Banking Committee action. </p><div data-type="twitter" tweetid="2060381902670819481">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/SenLummis">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/0a3751ef66537911812f0b750ac7b416d2e54c3cf1a823388aa33173041150c0.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/SenLummis" class="twitter-displayname">Senator Cynthia Lummis</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/SenLummis" class="twitter-username">@SenLummis</a></p>
    
            </div>
            <a href="https://twitter.com/SenLummis/status/2060381902670819481" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      The next window for digital asset legislation after this Congress is likely 2030. Until then, developers remain exposed with no legal protections, and law enforcement remains without the tools to hold bad actors accountable. The Clarity Act solves both.
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/SenLummis/status/2060381902670819481" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            6,073
          </a>
          <a target="_blank" href="https://twitter.com/SenLummis/status/2060381902670819481"><p>3:25 PM • May 29, 2026</p></a>
        </div>
    
  </div> 
  </div><p><strong>Australia's June 30 AFSL Deadline Looms for ~400 Crypto Platforms</strong></p><p>With just weeks remaining, Australia's <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.aph.gov.au/Parliamentary_Business/Bills_Legislation/Bills_Search_Results/Result?bId=r7411">Corporations Amendment (Digital Assets Framework) Bill</a>, passed April, now requires crypto platform operators to obtain an Australian Financial Services License by June 30, 2026. An estimated 400 platforms face the compliance deadline, making it one of the most consequential near-term enforcement triggers in the APAC region. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.coca.xyz/post/apac-regulators-align-on-crypto-deadlines-for-q2-2026">Coca</a>) </p><h2 id="h-legislative-watch" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Legislative Watch</h2><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/9cae528700363ab43be0262fde749d8c352a0824e4338143b013ac101d3e1d09.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAQCAIAAAD4YuoOAAAACXBIWXMAAAsTAAALEwEAmpwYAAADAElEQVR4nJ1Uz08TQRSeHkwwHnrlT+DgQROIF0+evHgxMR4kkQsHvJhIKkFtCESMMTEhFhu1MY2mkVRTwdKKEGmhW0KtdEu2i9ut7ZZaCNsqu/0xu5Rp6Zjt6KYUNIEvk8nmzdv3zffemwcAMIAGWHZtJULzfGIlQuPDgBrARwQ4ccpICDq7ugAA7e3tAIC2tjYAgNFoNBgMxgY6OjqImyRJRyP4+mXpXOfZl7bxSkVlmNVQaDmZSlEU5XQ6Y7EY/RfxeJym6VgsdmQFz+2Tt4fG791/cfr8tSvX73x4/zH9bQ0fFxAqLLuWTKUEIc3ziWKhCCBUZLkg5n4K6c1MVpTlgqooJOPHIEAI/chubIniRgMQQnCo3169jlCV7KixGj9rlr16XffRl+6mn2KMOY5rJSCuJBbDJvfq9VIZEgtBrVrTw+2/ePXgDiHUaiCkN0tl7av5FrJcevj4FYSK3eGZ/rT0SyoQY0toXZMsl9yexVIZNqsRBEFTYB55xrBJjLGiqHwiQzMJjLGY256cXrDaXFaba+LtrNsbyGTFsacTQnpTzG3P+cKhMOunaFkuYYz9FG0yW3r6RvoHxzh+PbuR26fA7Q109w5hjCNR7mrP3f7BMT9FDw5b+USmu3fowqUbGGO7w2N3eDh+3WS2zAci7ybn53zhfF4KhhiM8czc8mKQDoYYu8MzOGzt7h2y2lwXL9+M0AxCCITCLDh5RlFU15RvZm45EuUSqayQ3pSkoslsmZ0PYYwlqViGqqKoT6zOfF6S5ZIkFRVFnZxe4Ph1tzdQhipJ2md/mNC/fuOFEGoECFVdUz6T2cKw3/USkYJnN3KV3T/Nqme/Vq2RU4xxdDXed+tRKMzqeW8ukiCkdyoVrYsquygS5RRFPbQX8f5uIRbd3tJOeisiVJUkSVOgO+3V68TU/GqkA5NHlgstsbZEkcjSASHcqVQEIQ2hAiCEOQ15MiwRQiR3OseBV9iK//sAn883MDAwOvqAoiguzgcCwWAweNSR+Q9iLTG/AV11S2uqJnrbAAAAAElFTkSuQmCC" nextheight="974" nextwidth="1924" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://polymarket.com/event/clarity-act-signed-into-law-in-2026">Polymarket</a>)</figcaption></figure><h1 id="h-capital-allocation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Capital Allocation </h1><p><strong>SOL Strategies Closes $18M Acquisition of Privacy Swap Platform Houdini</strong></p><p>SOL Strategies completed its acquisition of HoudiniSwap LLC on June 1, 2026, a non-custodial, privacy-focused cross-chain swap aggregator, for a total of USD $18 million in a mix of cash and common shares. The deal marks a significant strategic move for SOL Strategies as it expands its crypto infrastructure footprint into the privacy and cross-chain space. That puts SOL Strategies deeper into two areas attracting growing attention from both regulators and security researchers: privacy and cross-chain infrastructure. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://solstrategies.io/press-releases/sol-strategies-announces-definitive-agreement-to-acquire-houdini-swap-expanding-privacy-focus-and-acquiring-diversified-revenue-streams">SOL Strategies</a>) </p><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research</h1><p><strong>Researchers Formalize Logic Flaws in x402 Payment Systems</strong></p><p>Ling, Huang, Chen, Zhou, Wu, and Wang submitted the first comprehensive security analysis of the x402 ecosystem. The paper defines five security invariants and shows failures in transactional atomicity and cryptographic context binding, including cross-resource substitution of payment proofs and race conditions that duplicate paid services. On production middleware they measured resource leakage ratios up to 100% against dynamic authorization schemes. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2605.30998">arXiv</a>)</p><p><strong>Securing Elliptic Curve Cryptocurrencies Against Quantum Threats</strong></p><p>The paper examines how Shor's algorithm could threaten ECDSA-protected assets on Bitcoin and Ethereum. The study notes Bitcoin's base layer is relatively resilient, but highlights that scaling solutions like Ethereum's Data Availability Sampling and certain privacy mechanisms introduce new quantum-attack surfaces that urgently need post-quantum cryptographic upgrades. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2603.28846">arXiv</a>)</p><br><br>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>security</category>
            <category>hacks</category>
            <category>regulations</category>
            <category>crypto</category>
            <category>cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[0x35 Web3 Security Bulletin]]></title>
            <link>https://paragraph.com/@w3sb/0x35-web3-security-bulletin</link>
            <guid>nm2r0YUnYQFnfkNGanp4</guid>
            <pubDate>Fri, 29 May 2026 09:11:52 GMT</pubDate>
            <description><![CDATA[Security intelligence for Web3, digital asset infrastructure, and market capital flows.]]></description>
            <content:encoded><![CDATA[<p><strong>TL;DR</strong></p><ul><li><p><strong>DeFi’s AI-security anxiety is getting louder:</strong> OpenZeppelin co-founder Manuel Aráoz said he now treats all of DeFi as unsafe because coding agents are getting very good at finding smart-contract bugs. OpenZeppelin pushed back, and others noted recent losses still look more like operational failures than novel contract logic.</p></li><li><p><strong>Compliance is becoming an engineering problem:</strong> Chainalysis and Elliptic both point to the same gap: crypto firms still over-focus on direct wallet hits while under-investing in counterparty risk, sanctions refresh cadence, travel-rule data quality, and alert triage.</p></li><li><p><strong>Stablecoins keep moving toward the TradFi banking stack:</strong> SoFi launched SoFiUSD on Ethereum and Solana, while the FDIC proposed BSA and sanctions compliance rules for permitted payment stablecoin issuers under the GENIUS Act.</p></li><li><p><strong>Tokenized assets are getting more institutional:</strong> Aptos and Archax are bringing 100+ tokenized real-world assets onchain. The hard part will not be chain throughput; it will be issuance, redemption, oracle integrity, and permissioned transfer controls.</p></li><li><p><strong>Echo Protocol is the headline loss:</strong> A compromised admin key was used to mint about $76.7M in unbacked eBTC, then swap and bridge it out. Once again, the exploit reads less like a clever DeFi primitive bug and more like failed mint-authority control.</p></li><li><p><strong>The week’s smaller incidents:</strong> RetoSwap lost about $2.7M through Haveno multisig ACK spoofing, StablR depegged after a suspected $2.8M+ mint exploit, and Polymarket lost roughly $573K-$700K from an internal operational wallet tied to an old private key. </p></li><li><p><strong>Capital is flowing into trust infrastructure:</strong> Didit raised $7.5M for identity and fraud APIs, Squid raised $6M for cross-chain routing, Blocknative joined Deloitte, and Zama acquired TokenOps for confidential token distributions and vesting.</p></li><li><p><strong>The research corner gets darker:</strong> New work on deniable covert asset transfers shows how staged MEV can hide value movement inside ordinary-looking DeFi activity; while smart-contract security research keeps pushing beyond detection toward semantics, repair, robustness, and real-time monitoring.</p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-current-outlook" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Current Outlook</h1><p>The story has become less about any single exploit and more about the shape of the system around it. The incidents still matter, but the patterns match the need for holistic security. Web3 is becoming a control-design problem across protocols, wallets, agents, stablecoins, compliance systems, and operational infrastructure. It has moved out of the narrow “smart contract bug” frame and into a broader problem set.</p><p>The exploit data still matters. Wasabi, Ekubo, TAC, Verus, THORChain, Transit, TrustedVolumes, Echo Protocol, RetoSwap, StablR, and Polymarket all point to the same operational reality: losses are not coming from one failure class. They are coming from admin keys, bridge logic, deprecated contracts, wallet setup flows, mint authority, authorization checks, third-party dependencies, and weak separation between operational funds and user funds. SlowMist’s 2026 figures show the industry has incurred roughly $80M additional losses over the past four weeks. This follows April 2026 losses of over $600M, which pointed toward the largest losses ever in a single month for DeFi.</p><p>AI is making that problem harder, not simpler. MCP risk, AI-assisted scanners, prompt-injection attacks against agents, ExploitGym, ExploitBench, and Manuel Aráoz’s warning that coding agents are unusually good at finding smart-contract bugs all land on the same point: the asymmetry is getting worse. Defenders need comprehensive coverage. Attackers need one viable path. Vitalik’s formal verification argument offers the more constructive answer: AI does not make trustless systems impossible, but it raises the bar for smaller verified cores, better specifications, sandboxed edge systems, and continuous monitoring around the parts that cannot be fully proven.</p><p>Regulation is also getting more operational. Veda’s custody argument, CLARITY Act movement, Consensys’ GENIUS Act pushback, FDIC stablecoin rulemaking, Chainalysis compliance benchmarks, and Elliptic’s screening-layer argument all show the market moving from broad policy slogans into implementation detail. The practical question is no longer whether Web3 gets regulated. It is whether firms can prove they understand indirect exposure, sanctions refresh cadence, travel-rule data quality, mint authority, reserve attestations, and counterparty risk before those gaps become either enforcement issues or exploit narratives.</p><p>Capital is moving toward the same set of problems. MoonPay bought Sodot for key management. Elliptic raised $120M for on-chain intelligence. Fireblocks is pushing agentic payments. SoFi launched SoFiUSD. Aptos and Archax are bringing tokenized assets onchain. Didit raised for identity and fraud infrastructure, Zama acquired TokenOps for confidential token operations, and Blocknative joined Deloitte for transaction orchestration. Taken together, the market is funding trust infrastructure: identity, monitoring, payments, key management, regulated tokenization, and the operational plumbing around digital assets.</p><p>Meanwhile, crypto neobanks raising $200M with no CISOs remains the warning shot. The money is arriving faster than the security operating model.</p><p>Web3 security requires continuous control design across protocols, wallets, agents, stablecoins, bridges, compliance systems, and capital flows. The required security posture must be able to prove, programmatically, who can mint, who can move funds, what an agent can touch, how compliance alerts are triaged, where operational wallets are separated, and how the system behaves when one dependency fails.</p><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis</h1><p><strong>OpenZeppelin Co-founder Manuel Aráoz Calls DeFi Unsafe</strong></p><p>Manuel Aráoz, co-founder of OpenZeppelin, posted on X that he now treats all of DeFi as unsafe. Coding agents, he argues, are unusually good at finding smart-contract bugs, while defenders must patch every flaw and attackers need only one path to move funds. </p><div data-type="twitter" tweetid="2059413451265441990">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/maraoz">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/5621adbe56d4de4aae11d5c43e1e499468b5479123676c883aca160dcd9ed7f4.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/maraoz" class="twitter-displayname">Manuel Aráoz</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/maraoz" class="twitter-username">@maraoz</a></p>
    
            </div>
            <a href="https://twitter.com/maraoz/status/2059413451265441990" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      PSA: I now consider *all* of DeFi unsafe.<br><br>Coding agents are superhuman at finding vulnerabilities, and smart contract security is too asymmetric: defenders need to fix every bug while attackers need just one exploit to steal funds.
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/maraoz/status/2059413451265441990" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            1,746
          </a>
          <a target="_blank" href="https://twitter.com/maraoz/status/2059413451265441990"><p>11:16 PM • May 26, 2026</p></a>
        </div>
    
  </div> 
  </div><p>OpenZeppelin was quick with its own take noting that Aráoz’s left as CTO in 2019.</p><div data-type="twitter" tweetid="2059662515039354972">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/OpenZeppelin">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/04ab5315e379a8c95425e84d386854ca135b0d14c0d4f362e825478e931fe5b5.png">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/OpenZeppelin" class="twitter-displayname">OpenZeppelin</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/OpenZeppelin" class="twitter-username">@OpenZeppelin</a></p>
    
            </div>
            <a href="https://twitter.com/OpenZeppelin/status/2059662515039354972" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      Recent posts by Manuel Aráoz on AI and DeFi security have been widely circulated, and customers have asked whether they reflect OpenZeppelin's position. They do not.<br><br>Manuel co-founded OpenZeppelin and served as the company’s CTO until 2019 when he left the company.
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/OpenZeppelin/status/2059662515039354972" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            527
          </a>
          <a target="_blank" href="https://twitter.com/OpenZeppelin/status/2059662515039354972"><p>3:46 PM • May 27, 2026</p></a>
        </div>
    
  </div> 
  </div><p>The Block reported the post landed the same week as key-compromise hits on Stake DAO and Polymarket. Marc Zeller and banteg pushed back, noting most recent losses trace to operational security and parameter mistakes rather than novel contract logic. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.theblock.co/post/402687/openzeppelin-founder-all-defi-unsafe">The Block</a>)</p><p><strong>Chainalysis Benchmarks Crypto Compliance Blind Spots</strong></p><p>Chainalysis released its Crypto Compliance Programs in 2026 report on how exchanges and VASPs detect indirect exposure to illicit flows. Many programs still over-index on direct wallet hits and under-invest in counterparty clustering, travel-rule data quality, and sanctions-screening refresh cadence. For security teams, the report maps where compliance tooling fails before an on-chain incident reaches public exploit trackers. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/crypto-compliance-program-benchmark-2026/">Chainalysis</a>) </p><p><strong>Screening, Not Headcount, Should Absorb Most Crypto Alerts</strong></p><p>Elliptic explains that about 95% of crypto transaction monitoring alerts are operational triage, not full-blown investigations, and argues they should be resolved at the screening layer using tools like Elliptic Lens rather than pushed into expensive forensic workflows by default. By surfacing risk graphs, customer context, and AI-assisted summaries directly in the screening view, teams can clear routine alerts quickly, reserve deep investigations for complex laundering or recovery cases, and scale monitoring without linearly scaling staff costs. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.elliptic.co/blockchain-basics/what-is-crypto-transaction-monitoring">Elliptic</a>)</p><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements </h1><p><strong>SoFi Launches SoFiUSD on Ethereum and Solana</strong> </p><p>SoFi became the first U.S. nationally chartered bank to issue a member-facing stablecoin, <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.sofi.com/crypto/sofiusd/">SoFiUSD</a>, on Ethereum and Solana. The launch follows the GENIUS Act stablecoin framework and puts SoFi in the same race as other bank and fintech issuers building on-chain dollar rails. Reviewers should watch reserve attestation, mint/burn key custody, and bridge representations as the token leaves SoFi’s app. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://cryptobriefing.com/sofi-first-us-bank-stablecoin-ethereum/">Crypto Briefing</a>) </p><p><strong>Aptos and Archax Bring 100+ Tokenized Assets Onchain</strong> </p><p>Aptos Foundation and FCA-regulated exchange Archax said more than 100 tokenized real-world assets will trade through Archax’s engine on Aptos. CryptoBriefing framed it as regulated tokenization infrastructure on a high-throughput L1. Issuance and redemption workflows, oracle feeds, and permissioned transfer rules will matter as much as chain TPS for institutional adopters. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://cryptobriefing.com/aptos-archax-tokenized-assets-integration/">Crypto Briefing</a>)</p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents </h1><p><strong>Echo Protocol Loses $76.7M </strong></p><p>BeInCrypto’s autopsy describes how Echo Protocol’s admin key was used to mint about $76.7M of unbacked eBTC, then swap and bridge it out. The loss reads as operational key control failure, not a novel DeFi primitive bug. Restaking and synthetic BTC wrappers stay high-value targets whenever one key can inflate supply. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://beincrypto.com/autopsy-of-the-echo-protocol-hack/">Be In Crypto</a>)</p><p><strong>Halborn Explains RetoSwap’s Haveno multisig ACK Spoof</strong> </p><p>Halborn’s May 25 post walks through the RetoSwap hack that drained about $2.7M in Monero from users of the Haveno-based swap interface. The attacker spoofed ACK messages in Haveno’s 2-of-3 multisig trade flow, registered as an arbitrator, and redirected settlement. The flaw sits in third-party wallet setup, not RetoSwap’s own contracts. Projects bundling external wallet stacks should treat message-authentication gaps as supply-chain risk. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.halborn.com/blog/post/explained-the-retoswap-hack-may-2026">Halborn</a>)</p><p><strong>StablR EURR and USDR Depeg After Suspected $2.8M Exploit</strong></p><p>MiCA-compliant stablecoin issuer StablR lost more than $2.8M when attackers exploited a contract weakness to mint unbacked EURR and USDR, triggering a sharp depeg. </p><div data-type="twitter" tweetid="2058520949075386683">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/StablREuro">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/2739429184649a128c055d4ded7b6a0787af5b59ede62c4ed33674e81c349e02.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/StablREuro" class="twitter-displayname">StablR</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/StablREuro" class="twitter-username">@StablREuro</a></p>
    
            </div>
            <a href="https://twitter.com/StablREuro/status/2058520949075386683" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      Security update: We have identified an exploit affecting  StablR and are actively working to contain it and minimize impact.<br><br>Protecting our users and your funds is our top priority.<br><br>We'll share verified details and next steps as soon as possible.
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/StablREuro/status/2058520949075386683" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            29
          </a>
          <a target="_blank" href="https://twitter.com/StablREuro/status/2058520949075386683"><p>12:10 PM • May 24, 2026</p></a>
        </div>
    
  </div> 
  </div><p>ZachXBT and other researchers flagged the flow on-chain. Compliance branding does not substitute for mint-authority hardening and on-chain reserve proofing. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://cryptobriefing.com/stablecoin-issuer-stablr-hit-suspected-3m-smart-contract-exploit-zachxbt/">Crypto Briefing</a>) </p><p><strong>Polymarket Internal Top-up Wallet Drained </strong></p><p>Polymarket’s internal operational wallet, note not user trading balances, lost roughly $573K–$700K in a private-key compromise on Polygon. ZachXBT linked suspicious flows involving Polymarket’s UMA adapter contract. Polymarket said customer funds were unaffected. </p><div data-type="twitter" tweetid="2057768173915484505">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/devjoshstevens">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/47082fdb3bcd4397229c7639875afadf8dfcdd7a36486d460bc6c7a01de691a3.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/devjoshstevens" class="twitter-displayname">Josh</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/devjoshstevens" class="twitter-username">@devjoshstevens</a></p>
    
            </div>
            <a href="https://twitter.com/devjoshstevens/status/2057768173915484505" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      No polymarket or UMA contracts have been exploited. All user funds are safe, and using <a class="twitter-content-link" href="https://t.co/7bOD8pgjQC" target="_blank">Polymarket.com</a> is safe, so business as usual. <br><br>We had a 6-year-old private key that was compromised. This was in the internal top-up config, which is why funds were being sent to it.
      
      
        <a class="twitter-card-link" href="https://t.co/7bOD8pgjQC" target="_blank">
          <div class="twitter-media twitter-summary-large-image">
            <img src="https://storage.googleapis.com/papyrus_images/148668a5549c005ad8fb52cf8719d5da7f86e8bbe57f2d33f6e593ca67d31e47.png">
            <div class="twitter-summary-card-text">
              <span>polymarket.com</span>
              <h2>Polymarket | The World's Largest Prediction Market™</h2>
              <p>Polymarket is the world's largest prediction market, allowing you to stay informed and profit from your knowledge by trading on future events across various topics.</p>
            </div>
          </div>
        </a>
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/devjoshstevens/status/2057768173915484505" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            401
          </a>
          <a target="_blank" href="https://twitter.com/devjoshstevens/status/2057768173915484505"><p>10:18 AM • May 22, 2026</p></a>
        </div>
    
  </div> 
  </div><p>Prediction-market operators still need strict separation between hot operational wallets and user escrow. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://decrypt.co/368740/polymarket-hit-by-internal-top-up-wallet-exploit-700k-drained">decrypt</a>)</p><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>Total 2026 hack events: 125</p><p>The total amount of money lost this year: $883,882,604</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/80b2f8f8b6b47e8b020bec6818140171a5586be7fc956309255ac192d1d06e92.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAJCAIAAADcu7ldAAAACXBIWXMAABYlAAAWJQFJUiTwAAACBUlEQVR4nIVQz2vTYBj+bv4FW2EHL2VQRUVwQyc7WGNHaRiVwWAdW0awtbaWQCJWGDQ7meQgKcWS+aMbgxIDXUagLQPZEOJhuIuHXgvDU9qCJgdHD2s+XrHRMgZdH77D93zf+7zv+zzIMAxZlk3T7I6CY9vnaafd/nFyMlKFZFmORqPZbPbXcLQs66zXW52fr+n6Wa/XsiwX49fr6y+exl2MW5Y1TPh3gGmaWh8eH7a7i/GU37+nqi7Gjm0DAJdIZKhVALjg7KIDRVEoihIE4fJwAGDK76/uVryOAMAmnqQpavQA0zQFQVAU5fKIXIyvT0xUymUvExfjZZJ8trIyOiJN0xiGkUTRsW3Hts9/e9Sx7ZZlAcDk+FhN1wGg024DwMIj4jlNe3RQP5B4l38OeJ4vbW25GLsYQx8/Ox0A8F7c/2dyfOzb0REA/D49BYBlMpJjWQDodrueatBhIAEA1Gw2DcN4yXGH9Xp4Zkba2OA5zoeQkMvtqWpN17Xt7ejDB1/2968g9FYSD+v1mq6rpRJCaO7uva8HB9XdSvnjh6IkefXZdPp9Pv+5WuU57vvxMQKARqMRIojNQmGBJMlQKBOP37l5I0nTTCoVnJ3NS9KtQOAVy2aSyXC/LEwQSZpeWly8Pz29WSg8jkTWYjEmlZoLBj/t7Ny+FliLLb0Rxas+37ti8Q8Y+ZrdQXlfUgAAAABJRU5ErkJggg==" nextheight="570" nextwidth="2108" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist</a>)</figcaption></figure><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation </h1><p><strong>FDIC Proposes Bank Secrecy Act for Stablecoin Issuers </strong></p><p>The FDIC board approved <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fdic.gov/board/bank-secrecy-act-and-sanctions-compliance-standards-fdic-supervised-permitted-payment ">a notice of proposed rulemaking</a> on May 22, 2026, to implement Bank Secrecy Act and sanctions compliance standards for FDIC-supervised permitted payment stablecoin issuers under the GENIUS Act. The proposal would require those issuers to follow FinCEN and OFAC AML/CFT, sanctions, and reporting rules, with supervision and enforcement aligned to FinCEN. The issuers targeted are subsidiaries of FDIC-insured state nonmember banks and state savings associations approved to mint payment stablecoins. Comments are due 60 days after Federal Register publication. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fdic.gov/news/press-releases/2026/fdic-board-approves-proposal-address-bank-secrecy-act-and-sanctions">FDIC</a>)</p><h2 id="h-legislative-watch" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Legislative Watch </strong></h2><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/c29240c0f03ebbb8023cd2b48d9ed42a8959e4da772a24b0d280f12df8a7d05f.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAQCAIAAAD4YuoOAAAACXBIWXMAAAsTAAALEwEAmpwYAAADAklEQVR4nK1TXU/TUBg+yf6AV8QL3U298CdI1Hjlf1BCYoQLAvHCAPECMIBkJsOEZSZLEJQRVyXiRyEB4hyaQRwlZcIOUjrYRkKH9Ey3Cms31jbsmO5ImSMQNL5pmub9fJ6+zwsAOANKti1JSxG4HotBuIz/nwHLrly9BgCgKMpms1EUBQCw2+1VVVUURdnt9urqagCAzWZDCJ3ccb9Y/GMA/MJevHDO6ehkQ5/7+z0+n49hmL6+vtbWVpqmvSWjaXp0dNTpdNI0/dcMnnjftdx/3ON8evl6XVOLc2rcn1hZwf9qmqYJQlQUkwghURQVRQHxhAjh6hKMzoQWQyxE6HtOVbXjDZ9iQDyeEIToeixmDjiatF8skkfXDfLWdYOEiKcirSLfivI8bw4gLtKlvFc0tplVcrpuqGreqjkBu4VG0zTyTegCCaWzSo7UkwF7BR1j7KUn/AFWlncfuX2rQuIgVNB1wzDMeguZxWA6yBE0JFkQoiaDex3uCFzDGO8VdAmleWGDkPgUXBj0Mm7PyLPhMc/g66ySi8A1R+8QxjieSLLzkJ2HIRaqqgkuq+RuNXQ2t7ka7j6c476mUplSExMBmAkt1tZ37BeLYhI1t7nq7/T4A6zbM/LqzQcuzIOzlxYigphEbs/I+OQsF+ab21xcmH8x+n46yH2TfoRYSEY6XcPR2GaXY2DQy9Q1PWjv9kC4nFNVEIFrAJxX1fz45OzzlxNcmJ8OchG4lpF3mIngjdtt5AfGE0nDMCSUbu/26LqxtZXKyDtZJTc+OSsm0UxoUUJpsgxe2OhyDIRYuJvNmgxUNT/oZRy9Q1OBOYyxtVKMsZhEW1spa73WksqVw4X52vqOt2MfVTVPEvYKOtnioUyzSm4qMJeRdyw9WE31A1GVi7jCo6qm2CpydN1QFMVkoGnaXqGAsQlHln8qilIOMJ3JlKKHlZqmybJs3QEhhFBK07TyQozxbxVV3OHRyzxB++Vpx10JYBimsbHxZk0NwzD8quD3B/z+wLYknabvaewX1+FCVJZqgfIAAAAASUVORK5CYII=" nextheight="978" nextwidth="1924" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://polymarket.com/event/clarity-act-signed-into-law-in-2026">Polymarket</a>)</figcaption></figure><h1 id="h-capital-allocation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Capital Allocation </h1><p><strong>Didit Closes $7.5M Seed for Unified Identity and Fraud API</strong> </p><p>Didit announced on May 26, 2026 that it raised $6M in a new round, bringing total funding to $7.5M, with Y Combinator, Pioneer Fund, Orange Collective, and others participating. The company pitches a single API covering KYC, KYB, transaction monitoring, and wallet screening, aimed at crypto exchanges and fintechs that otherwise stitch separate identity and fraud vendors together. Didit claims profitability, 30%+ month-over-month growth, and more than 2,000 customers, and highlights agent-driven integration via MCP-style workflows. Spain’s Treasury, CNMV, and SEPBLAC are cited as having assessed its verification tech against in-person standards. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://didit.me/blog/didit-7-5m-seed-infrastructure-identity-fraud/">Didit</a>) </p><p><strong>Squid Raises $6M from Ripple and North Island Ventures</strong> </p><p>The Block reports on cross-chain router Squid closed $6M in strategic funding from Ripple and North Island Ventures, bringing total raise to $13.5M ahead of a consumer-facing product. Bridge and routing startups keep getting funded even as exploit losses mount elsewhere. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.theblock.co/post/402394/ripple-north-island-ventures-squid-crypto-funding">The Block</a>) </p><p><strong>Blocknative Joins Deloitte </strong></p><p>Blocknative announced its team has joined Deloitte to work on Web3 and agentic-AI infrastructure at enterprise scale. Founder Matt Cutler said the company spent nearly a decade on mempool visibility, gas estimation, transaction orchestration, and MEV-related tooling used by wallets, L2s, and DeFi teams. Production customers should plan migration now: Blocknative API services and Gas Network will keep running through June 19, 2026, then stop responding. Blocknative Corporation is winding down operations; the site notes it has not been fully updated to reflect the transition. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.blocknative.com/">Blocknative</a>) </p><p><strong>Zama Acquires TokenOps for Confidential Token Vesting </strong></p><p>Zama announced on May 20, 2026 that it acquired TokenOps, a token lifecycle platform that has handled more than $2B in distributions, vesting, and compliance workflows. The deal folds TokenOps into <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://github.com/zama-ai/fhevm">Zama’s Fully Homomorphic Encryption (FHE) stack</a> via the ERC-7984 confidential token standard so vesting schedules, airdrops, and recipient data can stay encrypted onchain, while issuers retain audit paths for regulators. Zama cited prior deployments including $KAIO’s institutional RWA distributions and planned confidential $ZAMA vesting on Ethereum. TokenOps will keep operating as an independent brand for issuers across chains. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.zama.org/post/zama-acquires-tokenops-confidential-compliant-token-distributions-airdrops-vesting">Zama</a>)</p><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research</h1><p><strong>Extending Blockchain Untraceability with Plausible Deniability</strong></p><p>Researchers propose deniable covert asset transfers via staged MEV. Park et al.’s asks whether blockchain transfers can hide inside ordinary DeFi activity, not just anonymity sets like mixers. They define Deniable Covert Asset Transfer (DCAT): staged sandwich and arbitrage flows where the sender looks like a routine MEV loser and the receiver like a routine winner. Prototypes on Ethereum and Arbitrum passed standard MEV detectors and unlinked sender/receiver in tested forensic setups. Because extreme losses follow power laws in the wild, the authors add a multivariate statistical triage method to rank suspicious cases for manual review rather than rely on fixed thresholds. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href=" https://arxiv.org/abs/2605.13132">arXiv</a>) </p><p><strong>Smart Contract Security Beyond Detection</strong></p><p>Tamer Abdelaziz frames smart contract security and research agenda beyond vulnerability scanners. He groups four active directions: foundation-model semantic reasoning, automated repair with formal validation, adversarially robust ML detectors, and real-time transaction-level exploit monitoring at chain scale. The paper ties those themes to recent work on where analyzers systematically fail and on scalable malicious-Ethereum-transaction detection (TxLens). It cites CertiK’s 2025 tally of 630 Web3 incidents and about $3.35B in losses to argue detection alone is insufficient without semantics, repair, robustness, and streaming deployment constraints. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2605.09124">arXiv</a>)</p><br>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>security</category>
            <category>cybersecurity</category>
            <category>hacks</category>
            <category>exploits</category>
            <category>regulations</category>
        </item>
        <item>
            <title><![CDATA[0x34 Web3 Security Bulletin ]]></title>
            <link>https://paragraph.com/@w3sb/0x34-web3-security-bulletin</link>
            <guid>UkV3rGnQ3oufhTdHPM7x</guid>
            <pubDate>Fri, 22 May 2026 16:28:35 GMT</pubDate>
            <description><![CDATA[Crypto and web3 security insights, including tools, hacks, and regulations.]]></description>
            <content:encoded><![CDATA[<p><strong>TL;DR</strong></p><ul><li><p><strong>Zero CISOs at the wheel:</strong> Six crypto neobanks raised $200M this quarter, yet none have hired security leadership.</p></li><li><p><strong>AI for Formal Verification:</strong> Vitalik argues that AI-assisted bug finding doesn't kill trustless systems; it makes formal verification cheap enough to secure core logic.</p></li><li><p><strong>Major Drains:</strong> Over $23M lost across the Verus-Ethereum bridge ($11.58M) and THORChain ($11M), plus a $440k prompt injection attack on Bankr's AI agent.</p></li><li><p><strong>Policy Pushback:</strong> Consensys formally challenged the FDIC’s GENIUS Act stablecoin draft, arguing against broad bans on yield and broker-dealer treatment for self-hosted wallets.</p></li><li><p><strong>AI Exploitation Benchmarks:</strong> New research (ExploitGym, ExploitBench) shows models like GPT-5.5 successfully chaining exploits for arbitrary code execution on real browser engines and kernels.</p><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div></li></ul><h1 id="h-industry-trends-and-analysis" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Industry Trends &amp; Analysis</h1><p><strong>Six Crypto Neobanks Raised $200M in 90 Days None Have a CISO</strong></p><p>QuillAudits reports that six crypto neobanks collectively raised $200M in under 90 days in early 2026, yet none has appointed a Chief Information Security Officer. The piece argues that security leadership is being treated as optional infrastructure at the precise moment these platforms are accumulating the largest attack surfaces in Web3's history. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.quillaudits.com/blog/web3-security/neobanks-ciso-problem">QuillAudits</a>)</p><p><strong>Vitalik Buterin on AI-assisted Formal Verification for Ethereum</strong></p><p>Vitalik Buterin’s May 18 essay treats formal verification as machine-checkable mathematical proofs, often written in Lean alongside low-level implementations such as the evm-asm RISC-V EVM project. He argues AI lowers the cost of generating code and proofs together, which makes end-to-end verification more practical for STARKs, ZK-EVMs, post-quantum signatures, and consensus. The post rejects the idea that better AI bug-finding makes trustless systems impossible, but stresses limits: wrong specifications, partly unverified components, and hardware side channels. His model is a small, heavily verified secure core with sandboxed, higher-risk edge software around it.  </p><div data-type="twitter" tweetid="2056354141832626487">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/VitalikButerin">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/3c41fc6917d326c85e511a3f4ff4446c765834bce7ef928e3ed340acf917bce9.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/VitalikButerin" class="twitter-displayname">vitalik.eth</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/VitalikButerin" class="twitter-username">@VitalikButerin</a></p>
    
            </div>
            <a href="https://twitter.com/VitalikButerin/status/2056354141832626487" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      Many people have claimed that with AI-assisted bug finding, secure code (and hence trustless anything) will be impossible.<br><br>I have a much more optimistic take, and AI-assisted formal verification is a major part of the reason why:<br><br><a class="twitter-content-link" href="https://t.co/0ceMBZ6uqj" target="_blank">vitalik.eth.limo/general/2026/0…</a>
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/VitalikButerin/status/2056354141832626487" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            2,498
          </a>
          <a target="_blank" href="https://twitter.com/VitalikButerin/status/2056354141832626487"><p>12:40 PM • May 18, 2026</p></a>
        </div>
    
  </div> 
  </div><p><strong>Runtime Verification: The Risk of Open Source Code and What History Still Teaches</strong></p><p>Runtime Verification revisits historical open source vulnerabilities to argue that lessons from well-known past incidents remain underapplied in modern Web3 development. The piece contends that dependency risk and supply chain exposure are systemic properties of open source ecosystems, not one-off events, and that formal verification offers a structural answer to a structural problem. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://runtimeverification.com/blog/the-risk-of-open-source-code-what-the-past-still-teaches-us">runtime verification</a>)</p><p><strong>Stacy Muur Expands On Practical Web3 Security Tooling</strong></p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/stacy_muur?s=20">Stacy Muur</a> quoted  <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/Faycytw/status/2054563918278750549?s=20">Faycy_crypto's</a> “50+ security tools” list and added her own stack: Safe multisig, Etherscan’s approval checker, Tenderly simulation, Token Sniffer, ishoneypot, GoPlus, Chainabuse, DeFi scanner, Blockaid, and Blowfish (now part of Phantom). (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/stacy_muur/status/2055728499085005085">Stacy Muur on X</a>) </p><p><strong>ChainPatrol: 10 Essential Security Practices for Web3 Users in 2026</strong></p><p>Umar Ahmed of ChainPatrol catalogues 10 security practices Web3 users should adopt in 2026, covering wallet hygiene, phishing recognition, hardware key use, approval management, and the emerging threat of AI-assisted social engineering. The piece is framed around the observation that attacks on crypto users have matured into a structured industry with tooling, playbooks, and measurable returns on investment for attackers. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://chainpatrol.com/blog/10-essential-security-practices-for-web3-users-in-2026">ChainPatrol</a>)</p><h1 id="h-market-movements" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Market Movements </h1><p><strong>Fireblocks Powers Agentic Payments Future for PSPs and Fintechs</strong></p><p>Fireblocks' product update introduces an Agentic Payments Suite designed for payment service providers and fintechs. The announcement reflects the company's view that AI agents are already transacting on users' behalf across real financial rails, and that infrastructure for autonomous wallet-connected agents must be purpose-built rather than adapted from existing custody tools. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fireblocks.com/blog/agentic-payments-suite-psp-fintech">Fireblocks</a>) </p><p><strong>Elliptic Integrates With Kaia to Reach 250 Million Users Across Asia</strong></p><p>Elliptic announced on May 20 an integration with Kaia — the blockchain powering KakaoTalk and LINE's Web3 applications — bringing Elliptic's transaction monitoring and compliance tooling to a network that serves approximately 250 million users across Asia. The partnership extends Elliptic's footprint into a consumer blockchain segment that has historically operated with limited compliance infrastructure. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.elliptic.co/blog/elliptic-integrates-with-kaia-to-reach-250-million-usershttps://www.elliptic.co/blog/elliptic-integrates-with-kaia-to-reach-250-million-users">Elliptic</a>)</p><h1 id="h-exploits-and-incidents" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Exploits &amp; Incidents </h1><p><strong>LayerZero Publishes KelpDAO Post-mortem with Mandiant and CrowdStrike</strong></p><p>LayerZero completed a post-mortem on the April 18 KelpDAO rsETH incident with Mandiant and CrowdStrike, publishing an executive summary and full report. The company describes working with hundreds of partners over four weeks to review DVN and RPC posture, attributes the operation to DPRK-linked TraderTraitor (UNC4899), and argues the core protocol was not exploited while 1-of-1 DVN setups created unacceptable risk.  (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://layerzero.network/publications/kelpdao-incident-report.pdf">LayerZero</a>) </p><p><strong>Community Pushback on LayerZero's Report</strong></p><p>Kelp and researchers dispute that 1-of-1 DVN was Kelp’s reckless choice alone; LZ previously admitted fault for allowing its DVN as sole verifier for high-value apps; ~47% of OApps reportedly shared 1-of-1 DVN; open question whether Kelp downgraded from 2-of-2. (<a target="_blank" rel="noopener noreferrer" class="dont-break-out" href="https://www.coindesk.com/tech/2026/04/20/kelp-dao-claims-layerzero-s-default-settings-are-what-actually-caused-the-usd290-million-disaster">CoinDesk</a>, <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://layerzero.network/blog/an-overdue-apology">LayerZero</a>, <a target="_blank" rel="noopener noreferrer" class="dont-break-out" href="https://oakresearch.io/en/analyses/investigations/kelp-dao-hack-full-picture-of-292-million-disaster">OAK</a>) </p><p><strong>Bankr AI Agent Drained via Prompt Injection on Base</strong></p><p>The AI-powered crypto trading platform Bankr on Base suffered a social engineering attack via prompt injection, using malicious Morse code inputs to trick the Grok-powered agent into executing unauthorized transactions. Fourteen user wallets were compromised, with approximately $440,000 stolen. Bankr suspended affected functionality and pledged full reimbursement from its treasury. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/en/">SlowMist</a>)</p><p><strong>Verus–Ethereum Bridge Drained for $11.58M</strong> </p><p>Blockaid said its exploit detection system flagged an ongoing drain on the Verus–Ethereum bridge at roughly $11.58M. PeckShield sized the take at 103.6 tBTC, 1,625 ETH, and 147,000 USDC swapped into about 5,402 ETH sitting in <code>0x65Cb8b128Bf6e690761044CCECA422bb239C25F9</code>. PeckShield also flagged abnormal outflows to Verus from bridge contract <code>0x71518580f36FeCEFfE0721F06bA4703218cD7F63</code>. Investigators describe a source–destination economic binding gap: exports can commit to payout data without matching reserves, in the same class as Wormhole and Nomad-style failures. Blockaid has pointed to missing source-amount validation in <code>checkCCEValues</code> as a fix. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/blockaid_/status/2056176541785034803">Blockaid on X</a>) </p><p><strong>THORChain Pauses After $11M Asgard Vault Drain</strong> </p><p>TRM Labs reported that an attacker drained more than $11M from THORChain in a single coordinated event across at least nine chains: Bitcoin, Ethereum, BSC, Base, Avalanche, Dogecoin, Litecoin, Bitcoin Cash, and XRP. That figure is slightly higher than the ~$10.7M–$10.8M cited elsewhere because TRM counts additional native-chain outflows, not only the BTC/ETH/BNB/Base bundle ZachXBT and PeckShield highlighted first. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.trmlabs.com/resources/blog/thorchain-exploit-drains-usd-11m-across-at-least-nine-chains-what-trm-knows-now">TRM</a>)</p><p><strong>TrustedVolumes Loses $5.87M to Broken Authorization Check</strong></p><p>A permissionless signer function and broken authorization check in TrustedVolumes' closed-source RFQ swap proxy contract allowed an attacker to drain $5.87 million in a single transaction. The team had not posted publicly in over a year prior to the incident. 1inch confirmed its protocol and user funds were unaffected. A bug bounty line remains open. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rekt.news/trustedvolumes-rekt">Rekt</a>)</p><p><strong>Transit Finance Loses $1.88M via Deprecated 2022 TRON Contract</strong></p><div data-type="twitter" tweetid="2054537423405933016">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/PeckShieldAlert">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/2be579b2f8961c1c685ca6acd9e83ceca3aa2147f92106d0d5b4f9f252e44f09.png">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/PeckShieldAlert" class="twitter-displayname">PeckShieldAlert</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/PeckShieldAlert" class="twitter-username">@PeckShieldAlert</a></p>
    
            </div>
            <a href="https://twitter.com/PeckShieldAlert/status/2054537423405933016" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      <a class="twitter-content-link" href="https://twitter.com/hashtag/PeckShieldAlert" target="_blank">#PeckShieldAlert</a> <a class="twitter-content-link" href="https://twitter.com/TransitFinance" target="_blank">@TransitFinance</a> seems to have been hacked for ~$1.88M<br><br>The stolen funds are currently sitting in the following address in $DAI:  0x8a634DfA2609358849D7D65FFA270C8A57a8abA5 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/be4a197a1ce12e16fcf0c633b8046ba1a800a3e9c20c831798138eb8ef5a095e.jpg"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/PeckShieldAlert/status/2054537423405933016" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            128
          </a>
          <a target="_blank" href="https://twitter.com/PeckShieldAlert/status/2054537423405933016"><p>12:21 PM • May 13, 2026</p></a>
        </div>
    
  </div> 
  </div><p><strong>Official Follow Up from Transit</strong></p><div data-type="twitter" tweetid="2054559075384590681">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/TransitFinance">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/32141f1088ef0ac2897276bced4e386809eb0c7803333f8e00bffc063c1ca124.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/TransitFinance" class="twitter-displayname">Transit</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/TransitFinance" class="twitter-username">@TransitFinance</a></p>
    
            </div>
            <a href="https://twitter.com/TransitFinance/status/2054559075384590681" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      <img class="twitter-emoji" draggable="false" alt="📣" src="https://abs-0.twimg.com/emoji/v2/72x72/1f4e3.png"> Transit Announcement<br><br>Regarding a recent incident related to historical legacy risks, we would like to share the following update:<br><br><img class="twitter-emoji" draggable="false" alt="1️⃣" src="https://abs-0.twimg.com/emoji/v2/72x72/31-20e3.png"> Cause of the Incident<br><br>The issue was related to an early-version smart contract previously deployed on TRON. Although this legacy contract had
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/TransitFinance/status/2054559075384590681" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            10
          </a>
          <a target="_blank" href="https://twitter.com/TransitFinance/status/2054559075384590681"><p>1:47 PM • May 13, 2026</p></a>
        </div>
    
  </div> 
  </div><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist Stats this Week</a></h2><p>Total 2026 hack events: 115</p><p>The total amount of money lost this year: $865,071,984</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/4a051b53abe86e467c1084eb39ddab534fb5d1592f92f388fa55d836159a8fc7.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAJCAIAAADcu7ldAAAACXBIWXMAABYlAAAWJQFJUiTwAAAB7UlEQVR4nGO4fv36pk2bHj169J82gGHFihWZmZk9PT2v8YInjx//+fu3qbx8z47tnz5/hoj8/P073MPj7KlTEBFMALJg6tSpHh4eVVVVBC34//+/mrh4U2Xln79/nzx+DLFAiIHh0IF9+CzYtGlTUVFRT0/PV7zg3du3////11dUmNzV9f///3dv3757+/bP378SDAxnT5368/cvVl0gC44cOdLc3Dx16tTXr18TtEBHVhbNAlGCFmzatCkiIoJgEN29ffv///8qYuK1xcWQIHr9+vXHTx95wRbgC6Ldu3dHREQ0Nzf//P37z9+/EPTu7dvnT5/+////z9+/EHGIc0xUVJoqK//////p82eIMilmptevX//8/RtZ+8/fvyF6QRZ8/fr13v175aVlxw8fdLUwry0untzV5WxhYaKmNqGjY/2qVYf27p0/c6ajicnNq1cNVFRiA/z27tx5aO/enZs32xjqMzAwLFuw4NCe3Vs3rJ85adLCWTPmz5x5+tixuJCgyV1dP75/Z/j///+jR4/8fXwmd3VFBAdHhoR0tjTZWVr2trWFBQYG+/i0NTQ42dhUl5YmR0alJMRP6e+1NTNra2gI9fOLiYiYMmmStalpc1VVdEhwWGBAdWmpk43N7ClT3BwdokND3719CwDey6BZJ3yixwAAAABJRU5ErkJggg==" nextheight="620" nextwidth="2234" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist</a>)</figcaption></figure><h1 id="h-policy-and-regulation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Policy &amp; Regulation </h1><p><strong>Consensys Urges FDIC to Narrow GENIUS Act Stablecoin Rules</strong></p><p>Consensys filed its <a target="_blank" rel="noopener noreferrer" class="dont-break-out" href="https://consensys.io/blog/fdic-genius-act-stablecoin-comment">formal FDIC comment</a> on payment stablecoin rules under the GENIUS Act, alongside earlier <a target="_blank" rel="noopener noreferrer" class="dont-break-out" href="https://consensys.io/blog/commentary-to-treasury-department-regulation-of-stablecoin-issuance-and-distribution">OCC</a> and Treasury filings on state “substantial similarity.” <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/BillHughesDC/status/2056751349912478112?s=20">Bill Hughes</a>’s team argues the draft overreaches on yield: a rebuttable presumption against “related third parties” would ban ordinary distribution and brand deals Congress left out of the statute, and Consensys proposes a four-part agency test instead. The letter asks the FDIC to keep non-custodial wallets outside broker-dealer treatment when users earn DeFi protocol yield on their own, preserve supervisory discretion (including multi-brand issuance) rather than cliff-edge mandatory penalties like the OCC draft, and use technology-neutral definitions for ledgers and smart contracts while judging cross-chain stablecoins by the holder’s legal claim, not the bridge mechanism. Consensys frames the comment as the opening move in a decade-long federal stablecoin framework.</p><div data-type="twitter" tweetid="2056713071033303523">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/Consensys">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/aeaf96887014ff763042eecf089e399d680c67814babf28c92a3c237d3c2d4b2.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/Consensys" class="twitter-displayname">Consensys.eth</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/Consensys" class="twitter-username">@Consensys</a></p>
    
            </div>
            <a href="https://twitter.com/Consensys/status/2056713071033303523" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      Consensys has filed a comment on the <a class="twitter-content-link" href="https://twitter.com/FDICgov" target="_blank">@FDICgov</a>'s GENIUS Act proposal, outlining four areas that need refinement.<br><br>This filing, alongside our OCC and Treasury comments, marks the start of a broader conversation with federal banking agencies on getting the GENIUS Act rules right.
      
      
        <a class="twitter-card-link" href="https://t.co/9zQA8e4Wbl" target="_blank">
          <div class="twitter-media twitter-summary-large-image">
            <img src="https://storage.googleapis.com/papyrus_images/34bb3e3615fd6fef2a503d56be68e1e478a43aaa5688a176f8d2e0328473a68f.jpg">
            <div class="twitter-summary-card-text">
              <span>consensys.io</span>
              <h2>Consensys files comment on FDIC's GENIUS Act proposal | Consensys</h2>
              <p>Consensys files new comment letter on the FDIC's proposed GENIUS Act rule, addressing yield prohibitions, non-custodial wallet carve-outs, supervisory discretion, and crosschain definitions.</p>
            </div>
          </div>
        </a>
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/Consensys/status/2056713071033303523" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            55
          </a>
          <a target="_blank" href="https://twitter.com/Consensys/status/2056713071033303523"><p>12:26 PM • May 19, 2026</p></a>
        </div>
    
  </div> 
  </div><h2 id="h-legislative-watch" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><strong>Legislative Watch</strong></h2><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/1efc7b4c661e40c024fa749056489df76c9405079920319edd4c8e2483089740.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAARCAIAAAAzPjmrAAAACXBIWXMAABYlAAAWJQFJUiTwAAADEklEQVR4nK1U30tTURw/UBA++BfUgxAIPtlbM7k9DMoXQYcgvdkgoQQlQ9AXtZi/KRNRCbU21GnMXznW0rqGXsU5RI3lhtvMncl+mTvXzePUu3AnrqeuY5qh+OFy+d5zv9/v5/vzAACSwBEQ4h0OJ4Rw1e4gcRAEIeHzXAAS8vLyr1y9xjB309PTFQpFWlqaTCbLysrKPoJSqZTL5cnJyX19fSdZzwBQVZcDAFJvXq+vr83IuK1Q5Obk5jIMAwCQyWTZ2dlyuZxhGKVSyTBMSkoKy7LnIxgYnKh7pdYbuaqajo63QzOzCz+9nl/RKLkQBEFACOEjhMJhsUS9A4aSsoa2zvdFz+pKyhoNhq8/bJatzc1/1ZScCb8/MDXNzZnml5aW5+fNCPHgzHCi0vsCWHe5xAwEIZrwEBKjfjHelZgkssNY7L8BUcHj9YoE8THGcRDLirO9U0cIGWfnwjv4MBZLsD+ViedDGEforz8ELW1ah9MtGewfCFSw2V1Py18G0XZDs/p5zZvJ6QVCiOHTjNW69tfRbiAQDKJtybXJbGloftfeqaOHCCGRoKFZ/eHjFNXQDU2oGrsWl23Q7RscZU1my8PH1YXFqs0tvlszOjm90NKm7R0wQLdveGxSo9Xrjdw4OwfdPkIIN7t4P+eJbmjizr2CqpoOh9Pt8Xr2Dg6AbmgCgFRCyLfvq4+KXlRUt3apR7rUI02vNRhHbmXmPygoJ4SYzBaNVk8IqW3qLixWYRzp1oyGd7DN7jKZLbSkVLBa1xaXbd2a0VB4W8zAsuJMupFpta719Bt8/q116MU4sn8gjmMgEFQ1dtF8pdLb7C7LipMQgnGEEBJE2z39horqVo1WT6tHNYfHJo+b7HC6C4tVtMq0B1K3MY6c7C1tknQC3b6WNi3Ph+LHWhCiPp+PjqkIng/tRfZOrpIgeklcrlM346TacQaSDca78bN/dIIRQgkTTG+ChMH3+wMY78arQbghEkAIWZblOA5CiBDyeL0QblD7SwEwGo2lpaWVlZUsy67a7Rw38/kLC+HGZRH8BphchZfQ/w3vAAAAAElFTkSuQmCC" nextheight="1020" nextwidth="1938" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://polymarket.com/event/clarity-act-signed-into-law-in-2026">Polymarket</a>) </figcaption></figure><h1 id="h-capital-allocation" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Capital Allocation </h1><p><strong>Foundation Devices Raises $6.4M for Passport Prime and AI Authorization</strong> </p><p>Foundation closed $6.4 million led by Fulgur Ventures with Arche Capital, bringing total funding to $16.5 million, and opened general sales for Passport Prime plus wider KeyOS SDK access. The pitch is hardware-enforced “human authority” for high-stakes decisions, including AI agent authorization, beyond Bitcoin custody alone. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://foundation.xyz/blog/foundation-raises-6-4m-human-authority-hardware-launch">Foundation</a>) </p><p><strong>Cycles Raises $6.4M Seed for Private Crypto Clearing</strong> </p><p>Cycles raised $6.4 million led by Blockchange Ventures, with Coinbase Ventures, Compound VC, and Primitive Ventures, to net obligations across venues before settlement. The pitch is collateral stuck across exchanges and OTC desks. Security work shifts toward clearing membership, surveillance, and settlement finality rather than on-chain bridge logic alone. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://cycles.money/blog/cycles-raises-8-7-million">Cycles</a>)</p><h1 id="h-applied-research" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Applied Research </h1><p><strong>ExploitGym Tests Whether Agents Can Turn PoVs into Working Exploits</strong> </p><p>The ExploitGym gives agents proof-of-vulnerability inputs and asks for flag-capturing exploits across 898 real-world instances in userspace, Google's V8 JavaScript engine, and the Linux kernel. With standard defenses off, Claude Mythos Preview with Claude Code solved 157 instances and GPT-5.5 with Codex CLI solved 120 within two hours; turning defenses on cut rates but did not eliminate wins.  (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2605.11086">arXiv</a>)</p><p><strong>ExploitBench Ranks LLMs on Browser-engine Exploitation </strong></p><p>ExploitBench scores models on a ladder from crashing WebAssembly bugs through arbitrary code execution on V8-class targets. Only GPT-5.5 reached full arbitrary code execution on one public Wasm bug under the primary setup; a non-public Mythos Preview reference hit that bar on 18 of 41 bugs. Wasm type-confusion progress is ahead of JIT compiler cases, a useful split when prioritizing which engine bug classes still resist automated chaining. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/html/2605.14153v1">arXiv</a>)</p><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><br>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>crypto</category>
            <category>security</category>
            <category>cybersecurity</category>
            <category>regulations</category>
        </item>
        <item>
            <title><![CDATA[0x33 Web3 Security Bulletin]]></title>
            <link>https://paragraph.com/@w3sb/0x33-web3-security-bulletin</link>
            <guid>eIJR7ponlqY2gtQnIqYy</guid>
            <pubDate>Fri, 15 May 2026 09:56:53 GMT</pubDate>
            <description><![CDATA[Crypto and web3 security insights, including tools, hacks, and regulations. ]]></description>
            <content:encoded><![CDATA[<p><strong>TL;DR</strong></p><ul><li><p><strong>Nethermind</strong> breaks down frontrunning, MEV, and sandwich attacks with the kind of practical detail builders can actually use. </p></li><li><p><strong>Arkham’s research team</strong> adds the investigator lens with a guide to crypto crime patterns, from pig-butchering to ransomware and exchange hacks.</p></li><li><p><strong>The Enterprise Ethereum Alliance Privacy Working Group</strong> published its first enterprise privacy map for Ethereum, giving security architects a cleaner view of ZK, TEE, garbled circuits, and modular privacy options. </p></li><li><p><strong>The Ethereum Foundation</strong> also launched Clear Signing, a serious push to make wallet approvals readable before users hand over the keys.</p></li><li><p><strong>Lido’s Network Expansion Committee</strong> explained why Chainlink CCIP is becoming the official cross-chain rail for wstETH, with rate limits, verifier sets, mint caps, and emergency levers doing the heavy lifting. </p></li><li><p><strong>Notable Capital’s Rising in Cyber 2026</strong> map is worth a look too, especially as more tradsec companies start showing up in web3-adjacent workflows like Oligo and Endor Labs.</p></li><li><p><strong>Quantstamp’s April 2026 Security Beat</strong> is grim but useful: $635M lost across 28 crypto incidents, with Web2 supply-chain problems bleeding directly into Web3 risk. The Axios npm compromise, Vercel third-party breach, and active CVEs are a reminder that protocol security does not stop at the smart contract boundary.</p></li><li><p><strong>The Senate Banking Committee</strong> published a draft of the CLARITY Act ahead of committee review. The draft passed with a vote of 15–9 to advance to the full Senate. Next up, is the real test of whether Congress can turn “regulatory clarity” from a slogan into operating rules. </p></li><li><p><strong>Elliptic</strong> raised a $120M Series D at a $670M valuation, a strong signal that enterprise on-chain intelligence is becoming core infrastructure for banks, exchanges, payments firms, and government teams.</p></li><li><p>In research, <strong>Tamer Abdelaziz’s <em>Smart Contract Security Beyond Detection</em> on arXiv</strong> argues the field has to move past “find the bug” tooling. The next frontier is semantic reasoning, automated repair with formal guarantees, adversarially robust detectors, and real-time exploit monitoring at blockchain scale. </p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-insightful" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Insightful </h1><p><strong>Frontrunning in Web3 and Understanding MEV</strong></p><p>Nethermind published a practical breakdown of frontrunning, MEV, and sandwich attacks in AMMs. The post shows how bots exploit mempool visibility and weak slippage controls, with concrete code examples and developer fixes. It serves as both an educational reference and a remediation guide for teams building or auditing AMM integrations. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.nethermind.io/blog/frontrunning-in-web3-and-understanding-mev">Nethermind</a>)</p><p><strong>Arkham Publishes a Guide to Crypto Crime</strong></p><p>Arkham’s research team published a guide that walks through how pig-butchering scams, rug pulls, ransomware, and exchange hacks tend to look on-chain, and how investigators trace money after the fact. It is a great read and provides practical methods you can implement to upgrade your analysis framework based on the search patterns top teams use when deciding whether an alert is worth escalating.</p><div data-type="twitter" tweetid="2053718714470834595">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/arkham">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/c3527f0ac7dee1b8c9cc1477bbdc5a771b85424f4ef738d96ac623ea0fa947fa.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/arkham" class="twitter-displayname">Arkham</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/arkham" class="twitter-username">@arkham</a></p>
    
            </div>
            <a href="https://twitter.com/arkham/status/2053718714470834595" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      GUIDE TO CRYPTO CRIME<br><br>Crypto crime includes everything from pig butchering scams and rug pulls to ransomware and exchange hacks.<br><br>Our research team wrote a guide on how crypto crime works, and how on-chain intelligence can help track illicit activity. Check it out below: 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/ac3c8c4e418d6d07349f0ce5bdc481651e5bd1fda487e335909271571e6eae35.png"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/arkham/status/2053718714470834595" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            241
          </a>
          <a target="_blank" href="https://twitter.com/arkham/status/2053718714470834595"><p>6:07 AM • May 11, 2026</p></a>
        </div>
    
  </div> 
  </div><p><strong>Spiral and Block introduce Loupe: AI-assisted Scanner </strong></p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://spiralbtc.substack.com/p/meet-loupe-ai-powered-vulnerability">Spiral describes Loupe</a> as scanning-as-a-service for FOSS Bitcoin repositories: Block and Spiral run early scans, disclose findings to maintainers, then widen coverage as communication paths mature. The authors say they will only ship reports backed by demonstrable test cases to avoid drowning maintainers in noise, and they expect projects to bring their own model keys once the workflow stabilizes. Named early participants include Bitcoin Core, BDK, LDK, rust-bitcoin, Cashu, Blockstream Jade, bitcoinj, and SRI. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://github.com/project-loupe/loupe">Loupe on GitHub</a>) </p><p><strong>EEA Privacy Working Group Ships its First Enterprise Privacy Map for Ethereum</strong></p><p>The Enterprise Ethereum Alliance announced a report titled “<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://entethalliance.github.io/wg-privacy/privacy-report.html">State of Privacy on Ethereum for Enterprise</a>,” built with seven member organizations and presented as a single map of how enterprises handle confidentiality on public Ethereum. </p><div data-type="twitter" tweetid="2054232421411983537">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/EntEthAlliance">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/3e7552047b0a23c31dd9b5b634ae0f06c44491ac28701635106cf5bcc6754158.png">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/EntEthAlliance" class="twitter-displayname">Enterprise Ethereum Alliance | eea.eth</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/EntEthAlliance" class="twitter-username">@EntEthAlliance</a></p>
    
            </div>
            <a href="https://twitter.com/EntEthAlliance/status/2054232421411983537" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      7 solutions profiled in depth:<br><br><a class="twitter-content-link" href="https://twitter.com/AppBlockchain" target="_blank">@AppBlockchain</a> - Silent Data (TEE)<br><a class="twitter-content-link" href="https://twitter.com/Consensys" target="_blank">@Consensys</a> - Linea Enterprise (ZK + TEE)<br><a class="twitter-content-link" href="https://twitter.com/COTInetwork" target="_blank">@COTInetwork</a>: Garbled Circuits (GC)<br><a class="twitter-content-link" href="https://twitter.com/EYnews" target="_blank">@EYnews</a>: Nightfall (Zero-Knowledge)<br>@kaleido_io: Paladin (Modular Privacy)<br><a class="twitter-content-link" href="https://twitter.com/0xPolygon" target="_blank">@0xPolygon</a>: Polygon CDK<br><a class="twitter-content-link" href="https://twitter.com/zksync" target="_blank">@zksync</a> / Matter Labs: Prividium (ZK)
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/EntEthAlliance/status/2054232421411983537" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            52
          </a>
          <a target="_blank" href="https://twitter.com/EntEthAlliance/status/2054232421411983537"><p>4:09 PM • May 12, 2026</p></a>
        </div>
    
  </div> 
  </div><p>For security architects, it is a rare attempt to line up vendor stacks, legal constraints, and on-chain privacy techniques in one place instead of scattered blog posts. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://entethalliance.github.io/wg-privacy/privacy-report.html">EEA</a>) </p><p><strong>The Breaking Point of Ethical Security Research</strong></p><p>BlockThreat examines a growing tension in the blockchain industry: years of investment in cultivating a community of skilled security researchers, followed by systematic undervaluation of their work and compensation. Peter Kacherginsky argues that the current model is unsustainable and risks driving the most capable defenders out of the ecosystem at exactly the wrong time. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://blockthreat.com/the-breaking-point-of-ethical-security-research/">BlockThreat</a>)</p><p><strong>AI Is Making Software Harder to Secure, Not Easier</strong></p><p>Runtime Verification notes that the proliferation of AI-generated code is systematically degrading software security posture. Their post examines how AI coding tools produce code that passes surface-level tests while introducing subtle logical vulnerabilities that evade standard review and why formal methods are becoming more necessary, not less, in an AI-assisted development environment. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://runtimeverification.com/blog/ai-is-making-software-harder-to-secure">runtime verification</a>)</p><p><strong>Ethereum Foundation Launches Clear Signing to Reduce Blind-signing risk</strong></p><p>The Ethereum Foundation announced Clear Signing, a push to replace opaque <code>calldata</code> approvals with structured, human-readable descriptions of assets in motion, counterparties, and permissions. Public write-ups tie the effort to <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://eips.ethereum.org/EIPS/eip-7730">ERC-7730</a>-style transaction descriptors, an attestation layer for descriptor integrity, and a public registry reviewed by security researchers, with several major wallets and custody vendors listed as collaborators. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://blog.ethereum.org/2026/05/12/clear-signing-announcement">Ethereum Foundation</a>) </p><h1 id="h-companies-in-the-news" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Companies in the news</h1><p><strong>Lido Explains Why They Chose Chainlink CCIP</strong></p><p>The Network Expansion Committee is making Chainlink CCIP plus the Cross-Chain Token standard the official cross-chain rail for wstETH, migrating supported chains in stages while keeping Direct Staking from existing L2s on the same infrastructure instead of bolting on yet another one-off adapter per network. Prior to this most multichain wstETH sat on DAO-recognized canonical bridges, so every destination had its own wiring, its own monitoring load, and (where exits were optimistic) roughly a week to pull liquidity back to Ethereum mainnet. With the move to CCIP Lido contributors emphasize protocol-level properties they are able to access by default, including: sixteen-plus independent verifiers per lane, per-lane rate limits that act like circuit breakers, lanes that only bridge between mainnet and a single destination instead of a meshed graph, issuer-owned mint caps and emergency levers, and off-chain monitoring. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://blog.lido.fi/cross-chain-security-principles-why-lidos-network-expansion-committee-chose-chainlink-ccip/">Lido</a>) </p><p><strong>Notable Capital Drops its 2026 “Rising in Cyber” Map</strong></p><p>Leaning into the tradsec toolkit here, but worth a mention as web3 goes more mainstream. <a target="_blank" rel="noopener noreferrer" class="dont-break-out" href="https://risingincyber.com/">Rising in Cyber</a> is Notable Capital’s annual microsite for 30 private cybersecurity startups the firm is highlighting as especially worth watching. The list is chosen with input from roughly 150 CISOs and senior security operators and grouped by funding stage (early $1M–$35M, mid $35M–$100M, late $100M+, with figures described as Q1 2026). Amongst this list, companies like <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.oligo.security/case-study/cryptocurrency-exchange">Oligo</a> and <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.endorlabs.com/learn/under-the-hood-mysten-labs-strategies-for-building-the-most-secure-blockchain">Endor Labs</a> are already tapping into the web3 space. Also see the linked “<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://cdn.prod.website-files.com/683e9eb1e0cd556143d63f65/6a0314625fef51541a99253f_2026RisinginCyberReport_FFinal.pdf">Rising in Cyber 2026</a>” report, which turns down the hype and focuses on the data. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://risingincyber.com/">Rising Cyber</a>)</p><h1 id="h-gimme-the-loot" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Gimme the loot </h1><p><strong>April 2026 Security Beat: Same Actors, New Targets</strong></p><p>Quantstamp's monthly security roundup for April 2026 tallies $635M lost across 28 crypto incidents in the month. Highlights include the compromise of the Axios npm package exposing an estimated 600,000 installs in three hours, a Vercel breach through a third party, and three major CVEs under active exploitation. The write up shows a continued blending of Web2 supply chain risk with Web3 protocol exposure. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://quantstamp.com/blog/april-2026-security-beat-same-actors-new-targets">Quantstamp</a>)</p><p><strong>TAC Cross-Chain Layer Exploited for $2.8M on TON Side</strong></p><p>SlowMist reports that TAC's cross-chain layer suffered an exploit on the TON side by an external attacker, resulting in a loss of approximately $2.8M across USDT, BLUM, and tsTON. The TAC token, TON, and all ERC-20 tokens bridged from Ethereum are unaffected. </p><div data-type="twitter" tweetid="2054620834879381870">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/TacBuild">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/111852874664bcaf556d16e0aa7c53cfbdad2a9ec0b255f57d827d783bcf653b.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/TacBuild" class="twitter-displayname">TAC (🫰,✨️)</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/TacBuild" class="twitter-username">@TacBuild</a></p>
    
            </div>
            <a href="https://twitter.com/TacBuild/status/2054620834879381870" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      Following the security incident, we identified an exploit on the TON side of the TAC crosschain layer that was carried out by an external attacker. The incident resulted in a loss of approximately $2.8M across USDT, BLUM, and tsTON.<br><br>The TAC token, TON and all ERC-20 tokens
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/TacBuild/status/2054620834879381870" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            68
          </a>
          <a target="_blank" href="https://twitter.com/TacBuild/status/2054620834879381870"><p>5:52 PM • May 13, 2026</p></a>
        </div>
    
  </div> 
  </div><p>The bridge has been paused while forensic analysis and remediation continue, with the team working with law enforcement and pledging to make users whole. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io">SlowMist</a>)</p><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>Total 2026 hack events: 102</p><p>The total amount of money lost this year: $825,293,017</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/604289e15b3df8cb43057c3ac69d29ac1f3dfd8d6f946cda27357a9f123e70c9.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAICAIAAAAX52r4AAAACXBIWXMAABYlAAAWJQFJUiTwAAABzElEQVR4nGOYP39+Zmbm/PnzXxMHdm/ZcvvWLTj35+/fOzZtWr148c/fvzEVf/36lWHq1KmZmZnNzc2PHj3Cb/STx4///P2rJCiwfuWKP3//wkUSQkNczcz+/P375PFjLBb09PQkJCT09PQQaYGKmOjCWTOQLUgKC/N1dMRpASSIiLdAR1529qQJEOMgIjH+AT4Odjgt2LRpU3NzMyQOvoLA5684wLu3b////6+vqNTf2vr///93b99CRJLCwkI93CEiaFr+//8PsqCqqmrq1KkvXr789PkzHH39+hXiik+fP8PJP3//GigpN5WXQ4IIIpIUFhbm6fn///8njx9DlMHVg3ywe/fuoqKi+fPnP3n8+M7166sXL/769evaJYuL0lJ+fP/+9evXJ48f/////9DevXt37vz//7+mtFRrRcX///+fP3369evXm1evijIwlOVk//n798f37xBvvXv79snjxz++f//x/TvD////r167ZmJg0FRe7mZtxcDAEBcSxMDAYKyu5ufiYmdqWpaT7e3kaKKh4WZt5e/u5ufioqeqkhwZlZ2UZGloEBsczMDA4OPklBwZZWVkVJGbq6+qamlokBEba2losHzJEgA7/kVy+42x+gAAAABJRU5ErkJggg==" nextheight="582" nextwidth="2196" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><h1 id="h-we-must-have-regulations" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">We must have regulations </h1><h2 id="h-clarity-on-the-move" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">CLARITY on the Move</h2><p><strong>Senate Banking Committee Published the Draft CLARITY Act Ahead of a Key Review this Week</strong></p><p>The bill is the most comprehensive US crypto market-structure package this far along, aimed at ending SEC vs. CFTC limbo by defining what counts as a commodity vs. a security and what exchanges, brokers, and custodians must do, with explicit carve-outs for non-custodial builders and validators on money-transmitter risk.</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/7a3a407cc4d9eb3a8f6b1d18f72234582b83a8b0c6b88d9ed7318b918b815184.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAPCAIAAAAK4lpAAAAACXBIWXMAABYlAAAWJQFJUiTwAAADIUlEQVR4nJ2UTWjTYBjHgwcPet1Bb4KfNz04LypuA78QQfCisOH04gco6GUIiujF21BBLVQng26F6lrXxaQfe7OkfdOnzWzWt32zTDuH1c3VbWSaTddRJZJEx8SB1R//Q/Ikef/v8zx5Xqal5fTuvU37Dxxua7u6fceu+l27jx0/ubfh4OEjxxqbDh44dLT1zNnGpkMnmltPNLeev3BpZ/2e6zduDakqxhhqgIkJIhtHHBqICqI/GArx0ftPnt68fR8hQZIkQRAAIB7vFwRBkhLYAQCU2rANmrZs3MwwGxhm6ypm22pmE8NcPn1KlCHMshzHcXyEZV/wPM/9FwOiyPxJ45aNc9XqkKrqvxjWR5ZUoBopFAqU/i7tTxGq9bE8kyP5D5OT2qviQqViWda3b9/HxmeKbz++HZ/WXk+MvJl89WZc1/XR4iilVFGUiYkJq2YEMWEbpNPp9vZ2hJBrEIuLSJRjSOxlo6HeSCQmRCNcfzzG8xxCqD8eH9Y0Vc0OaxohxK11pVKproRtQKhGacHr9XZ0dAQCAUVR0oOagNUE5KIoIyRfxsVBNibzSEFJNQHkWd9AOCr7ArFESjUMY9qhWq2umIHoGhCS83q9Pl+Xx/MQYzmTG+VQlkOqP4xRkkTEIYQL4dhgdygpZ0dmDHPGmCtPzxqz838tkW1gd4MQj8fj8/n8fr9pzmULYyhJ8vq7hcriQmXRNL/Ofp7/5Gj+i92n2vmZAaU0GAyxLGuapmVZwWBvV5c/EHjWE3zu9z8VBEFRMpIkJSQJY8yyLwDAuZMAUgCAMXbHhed555EEAO5StkGO5MvlMiEkn7cvLMtyVmERQpAd4cX82PupGve7vL2/lSiTzjx6/Kg71O3+gpQW3F3fuffg3MW2S1eu3bl7r1Qquf00HMrlsmEYpmkuRVbs80+DqY9TkIHc65wbpZR2dnZKktTQsG/tmjXr16+rq6vr6elRnfNH1/VisQgAqqqWSiX3PCCEVJwxWsEgmyNudv/UvRqx5yDcx2aUQRkAp1IpSKcgLQO4kjBeUhLLbnD5C8vlfrtcSZwK97E/ALl3dv1IEpuIAAAAAElFTkSuQmCC" nextheight="834" nextwidth="1746" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.congress.gov/bill/119th-congress/house-bill/3633">Congress.gov</a>)</figcaption></figure><p>The Senate Banking Committee reviewed the CLARITY Act on Thursday May 14th, the bill that would define SEC and CFTC jurisdiction over digital assets and establish a legal operating framework for US crypto markets. Banking groups pushed back on the compromise text on May 9. The next stage shapes the bill's trajectory toward Senate floor consideration and the White House's July 4 passage target.</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/d39331d709eb87f24702c76b7db3c62ae3f8a3118f43131971d36d036722dcee.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAARCAIAAAAzPjmrAAAACXBIWXMAAAsTAAALEwEAmpwYAAADAUlEQVR4nK2ST2zSUBzHu4vX3ZSTF2eyHbkpNw+ePHqYJjuYmCVbsixe1CzGuJlsmrCFsSAqmBEH2QILsIyhA8efAXNALETSDcqgc1ISilICa0d5BJ7pioTBWHT6TQ/t6+/1+/28fhHkwiXkWN9T5Bc09D2V8nh8AAD4n4Q0dOfuAIIgvb19IpFIIpF0dXWJRKLu7m6xWNzT0yORSMRiMYIgQ0NDEMI/T4CEgltXLl98+GDY7/88K5tRq97q9XqNRjMyMqJQKGQymUajUSgUer1epVKNj4/7/f6/IzBb3I+eKV7PmwdHpwZHpz5sbP8s/KjWquc6D1g8PCQIgjoWSZIMwyARbM9o/uT2oatrmzqD7SuGsyW2xJUYhgEddIYBTdMYtoPjcRyPR2N4jqaRTqMAVM6+YIeZxhdisRhP0Ok1hDCfL7LsUbvxGQRN3kA4g1aDZieNbu2jfRtCqDPYUmSGYdhOeVtWiP00AJVEMskTSOVaNBwVhrgy4MrgkKmnXjLYVq0eNBydfbWkM9jsziCE0LK+Jdzk88UMlSP20xFsrwGK7SQXFq1Pn7+Z167VCQLo7tiEUnBeNjum53TTczqaLpgsLp3BFsESN24NK9VGCOHCotVkcRlXnGaL2+UNbfpCSrXR7gzi8YMNV7ABPTahdHlD12/ej0QwniBFUghyNUPlUiQllWulcq3Z4t5wBdWalSj+LYIl+q71u7whCCEePxCyo+Ho7YHHDMNGsD2BftXqoekChDCA7qZICoBKNkuXyxxPwLJH/feeGEwOg8mRzdIZKgdApVqrCYnQcNSyvtX89467WIgnU81HT+ynX868n3jxzu4M5vNFYbHeImFOKtcumx0QQq7M17zlB8KTDYEQVmu1lv5gO8kAutt4rNZqjRaBEseVOB7nd7dO9IThywPaF08r1YntOB6vEzS1mJ9oicbwYtv6fsokAICm6eaNPAFBEDabzev1krzSFJUlCKJ987mFOJ3OyclJmUwWCAQTyWQoFPZ4fLmmIP9o8AsiCZ5nYxfNMQAAAABJRU5ErkJggg==" nextheight="998" nextwidth="1852" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://polymarket.com/event/clarity-act-signed-into-law-in-2026">Polymarket</a>)</figcaption></figure><p><strong>Senate Banking Clears CLARITY</strong></p><p>The Senate Banking Committee voted 15–9 to advance the Digital Asset Market Clarity Act to the full Senate. But the act isn't over the hill yet. The committee's text still has to merge with the Senate Agriculture companion from January and Democrats want ethics language tied to crypto holdings that didn’t make Thursday’s committee text. Clearing with 60-votes in the Senate still looks like a real fight. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://thedefiant.io/news/regulation/crypto-rallies-as-senate-committee-advances-market-structure-bill-to-full-senate">Defiant</a>)</p><p><strong>Consensys Counsel Flags a DeFi Securities Gap </strong></p><p>On X, Bill Hughes argued that a narrower securities question for DeFi is still under-discussed even while the industry cheers new SEC interpretive guidance on token taxonomy and Trading and Markets staff guidance on neutral crypto self-custody user interfaces. He points readers to a Consensys comment letter that asks the Commission for a safe harbor for certain self-custody software providers, which is directly relevant to wallet and trading-interface teams operating in the U.S. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://x.com/billhughesdc/status/2053997248929788396">Bill Hughes on X</a>)</p><h1 id="h-vcs-and-funding" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">VCs &amp; funding </h1><p><strong>Elliptic Closes $120M Series D at $670M valuation</strong></p><p>Elliptic announced a $120M Series D led by One Peak, with Nasdaq Ventures, Deutsche Bank, and the British Business Bank joining. The company is now marked at a $670M valuation and the round will fund enterprise on-chain analytics for banks, payments firms, exchanges, and government users. Elliptic reports screening more than one billion transactions weekly for 700-plus customers in 30 countries, with asset and entity coverage across 65-plus blockchains and AI-assisted triage layered on that dataset. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.elliptic.co/media-center/elliptic-secures-120-million-investment">Elliptic</a>) </p><p><strong>TheDAO Security Fund </strong></p><p>EtherWorld described a Giveth-hosted quadratic funding round backed by a 500 ETH matching pool from <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://qf.giveth.io/qf/ethereum-security">TheDAO Security Fund</a>, aimed at audits, tooling, and defensive research across Ethereum. The format matters because small security teams that rarely clear venture diligence can still earn matching weight if their work is broadly valued by contributors. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://etherworld.co/thedao-security-funds-first-funding-round-goes-live-with-over-1m-for-ethereum-security/">EtherWorld</a>)</p><p><strong>AmericanFortress Closes an $8M Seed for Quantum-resistant Transaction Security</strong></p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://americanfortress.io/">AmericanFortress</a> raised $8M to harden transaction signing against long-run quantum threats to classical elliptic-curve assumptions, including patent filings around alternative signing paths. </p><div data-type="twitter" tweetid="2051715859123704067">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/Americanfort_io">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/13b4cece512fa5f4062f4f506fd68d5ea9ecdbe6e1d4e39c24048a9a5cf331f9.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/Americanfort_io" class="twitter-displayname">AmericanFortress</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/Americanfort_io" class="twitter-username">@Americanfort_io</a></p>
    
            </div>
            <a href="https://twitter.com/Americanfort_io/status/2051715859123704067" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      Quantum computers will eventually be able to drain any wallet whose public key has been exposed on-chain. That's basically everyone.<br><br>We just filed the patent to fix it and raised $8M to make sure it gets built.<br><br>Quantum-resistant transaction signing, embedded directly into our 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/1d0cdcdbb62301970af582475f0542bcce23c3a974e24a0988e5ca19321601f3.jpg"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/Americanfort_io/status/2051715859123704067" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            864
          </a>
          <a target="_blank" href="https://twitter.com/Americanfort_io/status/2051715859123704067"><p>5:29 PM • May 5, 2026</p></a>
        </div>
    
  </div> 
  </div><p>Near-term exploit risk from quantum hardware is still remote, but custody and bridge architects use rounds like this to budget for trust-anchor rotations that take years, not weeks. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hackernoon.com/americanfortress-raises-$8m-to-defend-the-$483-billion-in-bitcoin-already-exposed-to-quantum-risk">Hackernoon</a>)</p><h1 id="h-research-corner" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Research corner</h1><p><strong>UniDetect Uses LLM Summaries to Flag Fraud </strong></p><p>The UniDetect preprint sketches a pipeline that turns raw transactions into short natural-language summaries plus graph features, then trains detectors on top; the authors report strong cross-chain zero-shot fraud metrics on benchmark datasets. Incident-response teams get an  example of where LLMs might replace bespoke parsers for new bridges or rollup variants. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2604.12329">arXiv</a>)</p><p><strong>Smart Contract Security Beyond Detection</strong></p><p>Tamer Abdelaziz outlines a maturing research agenda for smart contract security that pushes far beyond simple vulnerability detection. The paper maps four key directions: foundation-model-based semantic reasoning, automated repair with formal guarantees, adversarial robustness of learned detectors, and real-time exploit monitoring at blockchain scale. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2605.09124">arXiv</a>) </p><p><strong>LLMs as Smart Contract Auditors: Promising but Unreliable</strong></p><p>Susan Ștefan-Claudiu, Arusoaie Andrei, and Lucanu Dorel benchmark 15 large language models against a paired smart contract vulnerability dataset to assess whether AI can replace, or only complement, traditional static analysis tools like Slither. Their findings are sobering: LLMs suffer from significant lexical bias, inflated false positive rates, and inconsistent behavior under varied prompting strategies. The study concludes that hybrid LLM-plus-static-analysis pipelines are the most viable near-term path for secure Ethereum contract development. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2605.11163">arXiv</a>)</p>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>security</category>
            <category>cybersecurity</category>
            <category>hacks</category>
            <category>blockchain</category>
            <category>crypto</category>
            <category>regulations</category>
        </item>
        <item>
            <title><![CDATA[0x32 Web3 Security Bulletin ]]></title>
            <link>https://paragraph.com/@w3sb/0x32-web3-security-bulletin</link>
            <guid>2CSipWSNVhPYJB6cbqUM</guid>
            <pubDate>Fri, 08 May 2026 12:13:32 GMT</pubDate>
            <description><![CDATA[Crypto and web3 security insights, including tools, hacks, and regulations. ]]></description>
            <content:encoded><![CDATA[<p><strong>TL;DR</strong></p><ul><li><p>Does ZachXBT ever sleep? This week he teamed up with Tether, Binance, OKX and US law enforcement for a coordinated shutdown of BG Wealth Sharing Ponzi scheme. </p></li><li><p>Connect everything with MCP right? Maybe not, "MCP executes local commands before verifying whether those commands are legitimate." Rekt dives in on the protocol's shaky history and known flaws. </p></li><li><p>KelpDAO is out with their own post incident analysis. Hey it's just a $300M loss no need to point fingers right? Wrong, and Kelp wants to set the record straight. </p></li><li><p>Admin key compromise results in Wasabi protocol losing $5.9M. Multisig? Nah...we got this! </p></li><li><p>Probably a good time to dig into Veda's proposal which argues that non-custodial smart-contract vaults can satisfy SEC qualified custody rules and CFTC segregation requirements, if guardrails like "robust security and operational controls" are in place. </p></li><li><p>MoonPay has acquired Sodot, a crypto key management firm that secured over $50 billion in transactions and safeguarded 10+ million wallets. The deal forms the backbone of MoonPay Institutional, a new offering. </p></li><li><p>Your LLM just needs a little guidance, the paper "Tailored Prompts, Targeted Protection: Vulnerability-Specific LLM Analysis for Smart Contracts," outlines an approach using precise AST-based context extraction and vulnerability-specific prompt design to instantiate customized detectors for 13 prevalent vulnerability categories.</p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-insightful" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Insightful </h1><p><strong>ZachXBT Helps Bring Down the BG Wealth Sharing Ponzi </strong></p><p>ZachXBT reports the DSJ Exchange (DSJEX) / BG Wealth Sharing Ponzi scheme collapsed and claims $92M+ was laundered cross-chain from April 27 to May 3. His thread notes a joint effort with Tether, exchange security teams, and US law enforcement froze $41.5M+, and includes a screenshot describing a TRON USDT freeze action and impacted addresses.</p><div data-type="twitter" tweetid="2051645845993648517">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/zachxbt">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/ade202fe8421f365cdfc29b0bd1a8f672b737b45cfd7dba75afd05bfeecabad1.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/zachxbt" class="twitter-displayname">ZachXBT</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/zachxbt" class="twitter-username">@zachxbt</a></p>
    
            </div>
            <a href="https://twitter.com/zachxbt/status/2051645845993648517" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      1/ The $150M+ DSJ Exchange (DSJEX) / BG Wealth Sharing Ponzi scheme collapsed last week. From April 27 – May 3, illicit actors laundered $92M+ across chains to obscure the trail.<br><br>I helped lead an initiative with <a class="twitter-content-link" href="https://twitter.com/tether" target="_blank">@tether</a>, @Binance Security Team, @OKX, &amp; US law enforcement that 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/1acd1c21e7a60a2f7f4038ef76c35ffa3e6a18ccffec6cad77758ecd1eb36db6.jpg"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/zachxbt/status/2051645845993648517" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            1,861
          </a>
          <a target="_blank" href="https://twitter.com/zachxbt/status/2051645845993648517"><p>12:51 PM • May 5, 2026</p></a>
        </div>
    
  </div> 
  </div><p><strong>The AI Protocol Stack Nobody Audited</strong></p><p>Rekt News examines the security exposure introduced by the Model Context Protocol (MCP), an AI integration layer increasingly wired into crypto and any AI-first organization. The protocol has been exploited more than a dozen times since 2025, with one attacker reportedly using Claude to breach nine Mexican government agencies. The piece warns that crypto firms running MCP connections may be unknowingly exposing on-chain operations and internal communications to adversaries. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rekt.news/stack-nobody-checked">Rekt</a>) </p><p><strong>Cyfrin Launches Cygent BattleMode for Adversarial Smart Contract Testing</strong></p><p>Travis Montgomery at Cyfrin outlines Cygent's BattleMode feature, which runs adversarial simulations against smart contracts to determine which flagged vulnerabilities are actually exploitable. The post positions BattleMode as a shift away from traditional PDF-based audit reports toward continuous, evidence-based security engineering integrated directly into development workflows. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.cyfrin.io/blog/why-cygent-s-battlemode-changes-how-teams-test-smart-contract">Cyfrin</a>) </p><p><strong>QuillAudits: Deployer Wallets Are Zero-Day Vulnerabilities</strong></p><p>QuillAudits published a security advisory on April 29, 2026, arguing that deployer wallets used by Web3 founders represent persistent, unmitigated attack surfaces. The post outlines how a compromised deployer wallet can enable contract upgrades, fund drains, and full protocol takeovers, and presents concrete mitigations including wallet rotation, hardware signer enforcement, and post-deployment privilege revocation. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.quillaudits.com/blog/web3-security/deployer-wallet-security-attack-vectors">QuillAudits</a>)</p><h1 id="h-companies-in-the-news" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Companies in the news </h1><p><strong>Kelp Challenges LayerZero’s Post-Incident Claims</strong></p><p>Kelp published a  post about an April 18 incident it attributes to LayerZero Labs infrastructure, claiming $300M+ in losses across protocols and saying it blocked additional forged transactions after pausing contracts. It disputes LayerZero’s claim that a KelpDAO misconfiguration was the root cause, and points to the response timeline and third-party analysis.</p><div data-type="twitter" tweetid="2051754226351771772">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/KelpDAO">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/c3dda12f11cbd3b190997896a97822a495ef9b6555ca65decab2fc634d393d55.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/KelpDAO" class="twitter-displayname">Kelp</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/KelpDAO" class="twitter-username">@KelpDAO</a></p>
    
            </div>
            <a href="https://twitter.com/KelpDAO/status/2051754226351771772" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      <a class="twitter-content-link" href="https://t.co/LCwMS3cZUS" target="_blank">x.com/i/article/2051…</a>
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/KelpDAO/status/2051754226351771772" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            529
          </a>
          <a target="_blank" href="https://twitter.com/KelpDAO/status/2051754226351771772"><p>8:01 PM • May 5, 2026</p></a>
        </div>
    
  </div> 
  </div><h1 id="h-gimme-the-loot" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Gimme the loot </h1><p><strong>Wasabi Protocol Loses $5.9M in Admin Key Exploit</strong></p><p>Rekt News reports that Wasabi Protocol's admin key was compromised, enabling UUPS contract upgrades across over a dozen vaults on four chains, all without a multisig or timelock in place. The attack drained $5.9 million before users received any alert, capping what the publication calls DeFi's worst month on record. April 2026 saw a cascading series of exploits that exposed the industry's persistent governance gaps. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rekt.news/wasabi-protocol-rekt">Rekt</a>)</p><p><strong>Ekubo Protocol Suffers $1.4M Callback Exploit on Ethereum</strong></p><p>An attack on Ekubo Protocol's custom Ethereum extension contract on May 5, 2026. A flaw in the <code>IPayer[.]pay</code> callback allowed attackers to exploit prior ERC-20 approvals by routing through the Core locking mechanism, designating any approved user as the payer. Approximately $1.4 million was drained; users who had not granted token approvals to the V2 contract were unaffected.</p><div data-type="twitter" tweetid="2051757790805323983">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/blockaid_">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/7500dc4370bee4de3e033832aef828a1fa1f962fa7a0a773aebddf8c7dfe6e5a.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/blockaid_" class="twitter-displayname">Blockaid</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/blockaid_" class="twitter-username">@blockaid_</a></p>
    
            </div>
            <a href="https://twitter.com/blockaid_/status/2051757790805323983" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      Root Cause: <br><br>The Ekubo extension implements its IPayer[.]pay callback (selector 0x599d0714, gated to msg.sender == EkuboCore) by doing token.transferFrom(payer, Core, amount) where payer, token, and amount are forwarded straight from the lock payload- i.e. controlled by whoever
      
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/blockaid_/status/2051757790805323983" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            7
          </a>
          <a target="_blank" href="https://twitter.com/blockaid_/status/2051757790805323983"><p>8:15 PM • May 5, 2026</p></a>
        </div>
    
  </div> 
  </div><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>Total 2026 hack events: 91</p><p>The total amount of money lost this year: $805,554,514</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/de1e3bc3571e2392055e9ef54733f066676d73e7fdf1ea1afef690c92d53edda.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAICAIAAAAX52r4AAAACXBIWXMAABYlAAAWJQFJUiTwAAABsUlEQVR4nGOYP39+QkLC/PnzXxMHPn3+fOLIkbu3b6MJHtq7d+fmzZ8+f0YW////P8PUqVMTEhKam5uJMf3J48d//v5VExdfsXDBn79/kQVTIiKcTE3//P375PFjSi1Q4OebP3MmmgWZsTFOpqb///9Ht2D37t09PT1Tp079SgR49/bt////1cTF58+c+f//f2TBorQULxub////v3v7Fq4eakFzc3NPT8+jR4+I9IGmtFRzVRWmD1wtzLEE0YoVKyBBBLHz0+fPyOQnVAZEj6uFeU1BAcQCSKz+//+/qbzc3sjw////EEGILpAFR44caW5u7u/re3z//uljx1YvXnzz6tVL585lxsbs3rLl4/v3d2/fevX8+ZPHj3ds2rR7y5bff3572djEBvj9////+dOnd2/ffv706YkjRwLd3Ky1tZ48fvz86VOI+Mf37398/87w////e/fvmxgY1JeWulhbMzEwhHh5MjAwaCoomOvqGmho1BYXG2hoFGZmmuvqMjAwTOxslxYWDPP2KszIsADrsjQ0sLewkBAUFGVjqy8ttTIySoqMSIqM0FBUvHjhAgBkMkTCnkzAswAAAABJRU5ErkJggg==" nextheight="588" nextwidth="2238" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><h1 id="h-we-must-have-regulations" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">We must have regulations</h1><p><strong>Veda Urges SEC &amp; CFTC to Recognize Vaults as Compliant Custody</strong></p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://veda.tech/">Veda Tech Labs Inc.</a> submitted written input to the Joint SEC-CFTC Harmonization Initiative arguing that non-custodial smart-contract vaults can satisfy SEC qualified custody rules and CFTC segregation requirements, provided they eliminate unilateral withdrawal authority, embed programmatic redemption rights, and cryptographically segregate client assets. The firm proposes a seven-condition "guardrail" compliance pathway, including constrained governance and independent audits, and recommends coordinated rule making under the 2026 MOU to establish a unified vault-based custody standard across both agencies. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.sec.gov/files/sec-cftc-harmonization-initiative-written-input-veda-tech-labs-inc-032326.pdf">SEC</a>)</p><p><strong>US Treasury Proposal for Stablecoin Issuers </strong></p><p>A summary write-up covers a proposed US Treasury rule that would treat certain stablecoin issuers more like Bank Secrecy Act financial institutions. If enacted as described, teams should expect tighter requirements around KYC/AML controls, monitoring, and cooperation, especially at issuance and redemption choke points. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.moneylaunderingnews.com/2026/05/treasurys-proposed-rule-brings-stablecoin-issuers-into-the-bsa-framework/">Money Laundering Watch</a>)</p><p><strong>Chainalysis Breaks Down Crypto Sanctions and Illicit Payment Rails</strong></p><p>Chainalysis’ sanctions chapter in its 2026 Crypto Crime Report ties sanctions evasion to concrete patterns: which rails get used, what stablecoins show up, and where compliance pressure is likely to land (issuers, on/off-ramps, and service providers). </p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/90bf2afed56ef4b7115fa034800298e429c3e833e40a9c90d77d99a33f112b46.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAVCAIAAACor3u9AAAACXBIWXMAABYlAAAWJQFJUiTwAAAD7klEQVR4nK2VQWzbVBjH34UDAoE4cQM0IcEBCQl24VRUpCK0STtM7ABDQiAhEBIqh40BEt1W2kK3alU7JNailhIgk4FlyhI3WVrjJE4dJ26TuE2bkiyt2zTu0r3WlRWP17zkQ41LoE0Y3eB3sJ79rO+v7/++732IEEIbAY2gf36v/6FhEEopahjLNE1RFBVFkWU5FospipJKpRRFSSaT1kKWZUEQrKckSalUqmGcfxQghDgcDo/HY7PZGIZxu90ej2ewytDQ0MjIiMPhsNvtTqfTbrczDON0Ou8kQAgxDONfLTJN0zAMjLFhGPW7pa0SqWJWIYTsCABAOp0WBAHvplAHrqLr+p5dTdNIiSTE5PVr45FohK+iquqdLLorKrQCAIty1s/ygVBQkiSfz5fL5f4HgaJpLudXdF0HgKV4UhwdC4VFnucFQSgUCn9ZhDFWVdUybp/cNm+XoZySFKZ7OMFHAOBGOMA7fhImwqlUqnZIOwKapiWTSXw3FFZXi5ReONrUhNCFo02kXF6YHA+4GGEinMvlVFVVFMXK7B4tKtMSALB9b779OGL73gKAW8tTkyGve9THureRZdk0zXs/g3JVYIbrGPkUzXCdALCWVyLhMb9f8HjYdDpthd2xKJvNiqJYK8T6esV1rGr5TcOMOj8ZaEWi4yNaqaQX4uM86/X6NC2/r0ZrCNm5uEqlLVIBiLFtA60oxp4GgFgm4eI9AX9AkiSrCfZbphgXDGPTsoVubQGAUSzeWFqsAMS9ZwZaUdx7BgBCU1GX73ooEOQ4zjreXRnour5Hqbz9WiGkNPSN45pTAID5hcXp+QwAJFws096u5/EM11kTGBck5qo7LIY4jtuVgdUHsixjjG/VroSNjcWVlSItid7xJxF6Hj0yNzXV2XLw/QMPL8/PvvsYehEh9nxbgj938T0UZE4AgNsrDNt+Dgb9HMdls9kGFlkub3c9wLqm2fv6sjNzi7FAC0LHH0Q3M4kPnkWvIpSfm2QvHu5+HWUnr2SiX13uQEl+u4qGbVcGBn+IRMK/8ryVRIN5gG+uRoMcrVS4Sx3NCJ147gHTyA1+iH7perqo57y2ly733v97Mdd8+BmEkGv0x2PvHEcItRw7BACfne05ffbLSCScrWJNiB0BSmkm/Rspl7/vPHnoUXS1v33M8e3Bh9Cp115QZuMHnkLNLz8RiUZQFSEkWItXjryB0H3WGgCECSkqT2maRml5b5lSStPpzKaux5XZz8/1JmbmFtR8V/+IP6ysra1/3Nbd//V3GG/09F46eaod43Wfb+x8T6+qLiWU6Y6uLxLKtHX714Kapqnr+n/q5Hr+PqmsxrIE/gD1SMuiT/d83wAAAABJRU5ErkJggg==" nextheight="1014" nextwidth="1568" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>It reads like a threat-model document for policy-driven fraud and laundering, with links out to the underlying events it references. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/crypto-sanctions-2026">Chainalysis</a>)</p><p><strong>FCA Issues Operational Guidance for Firms Preparing for the UK Crypto Regime</strong></p><p>A practical checklist-style overview of what firms should do while preparing for the UK crypto-asset regime, including governance and authorization posture. Even if the content is non-technical, it drives the work that security and compliance teams end up doing: controls, documentation, and operational readiness. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fca.org.uk/firms/new-regime-cryptoasset-regulation/what-you-need-to-do">FCA</a>)</p><h2 id="h-and-we-have-clarity" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">And We Have CLARITY?</h2><p>Big spike in the odds this week. </p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/d7da6460b22edc32c64786b323357d742ecb769b4544978ae98042effc91e108.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAQCAIAAAD4YuoOAAAACXBIWXMAAAsTAAALEwEAmpwYAAACuklEQVR4nJ1Uz0sbQRSeg9BDzoIHDx5y7H8gPdRbL/0PpEdPFexJ2kvBFktpaUWtBaEpmLZRWQSLsdgG0jRbf+AmJg1JJLs2rskmsmt3xMxs8pZkSnZ0CUkE9WNYZt/75r33zZsZhC4Qi0k/f0U3t3aiUZE5IISAA8YYxlhVVU3T+O/V4cZHQ0NDCCGv19vX1+fxeBBCHo+np6ent7e3v79/cHAQITQwMIAxvl6C7U1x9OFoIi45ZZq6rgOApmmqqgIAuQCXct3ymwk+LKyNPZ559GTm7v3R4ZGJ8NbW8b9jdlNUa7VE8o+iHORkOScrGGMEABa1aBMWpVa1Vqs36u6CeqNxrQQAoOs6xtgwTkqlMqUUAdgAdhuv3mjwAY6LT9qMrbTW4QZRlANCCOpWxfn6CqFSPMsnFUI7OTxZZ33cyDuH9uWjCrHa2PybUwqz8ytVsGPJnM8fTGfzJj5jjJn4zMRnbWRXEGOMUgpgq+pRU8Hz1wuHapkzdMMsaHpETHC2ohTXvv3ekTKvpr8kU/Lnpe/JlEypFRBCK6sRAFsrGT/Cu+lsPhzd25EybsrJt5/GxqeLWpmxBgpH94ZHJqqOIyCEnr38+ObdUkRM+Bc3fP5gTimsBqO37zxw6rK+rosBIcTjTs0tJ1NyOpv3L24wxrL7h4pS5IUGhNChWj5XIMWzt7z3KLXE7ZQUz4rbKa1kKEqxQmhB0wHs2fmVgBDiW+E2Q8mX/IsbADallm6YjDGtZKwGozwl3wOMcbMHAHYyJU/NLbtR3D3lk3L5hOtzve5o4+uGOf70fURMaCWDMXaugPty8hG3th6J1u6xyw9b1yWOgtOmgg5r+1MDYBvGSbezCF3JGJ9y+998vqmAEIIdAIBznykhpDNWp4Ir2pEgCJOTL3w+XzqTicX2YrH4riTd4FG7DP8BzLtnxXq5gkQAAAAASUVORK5CYII=" nextheight="978" nextwidth="1904" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://polymarket.com/event/clarity-act-signed-into-law-in-2026">Polymarket</a>)</figcaption></figure><h1 id="h-vcs-deals-and-funding" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">VCs, deals &amp; funding </h1><p><strong>MoonPay Acquires Sodot to Launch Institutional Digital Asset Infrastructure</strong></p><p>MoonPay has acquired Sodot, a crypto key management firm that secured over $50 billion in transactions and safeguarded 10+ million wallets for clients including eToro, BitGo, and Exodus. The deal forms the backbone of MoonPay Institutional, a new platform offering self-hosted MPC key management, NYDFS-regulated custody, cross-chain liquidity across 200+ networks, and stablecoin infrastructure for banks, asset managers, and trading firms. Former acting CFTC Chairman Caroline D. Pham will lead the business. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.moonpay.com/newsroom/moonpay-institutional">Moonpay</a>)</p><h1 id="h-research-corner" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Research corner</h1><p><strong>Smart Contract Analysis with Vulnerability-Specific Prompting</strong></p><p>The authors propose “prompting by vulnerability class” for LLM-based smart contract analysis, aiming to improve detection signals compared to generic audit prompts. Their approach uses precise AST-based context extraction and vulnerability-specific prompt design to instantiate customized detectors for 13 prevalent vulnerability categories. The work is most applicable for teams building triage tooling or running structured scans across a fixed vulnerability taxonomy. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/html/2605.03697v1">arXiv</a>) </p><p><strong>V2E: Exploit Generation Based Confirmation </strong></p><p>V2E automates the exploit generation process through a novel combination of PoC generation, validation, and refinement. Speed to execution for audit teams is improved by workflows that separate theoretical findings from those that can be triggered and monetized. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2604.13611">arXiv</a>)</p><br>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>cybersecurity</category>
            <category>hacks</category>
            <category>regulations</category>
        </item>
        <item>
            <title><![CDATA[0x31 Web3 Security Bulletin]]></title>
            <link>https://paragraph.com/@w3sb/0x31-web3-security-bulletin</link>
            <guid>DM00qKjoDBR5jbSMb7aw</guid>
            <pubDate>Fri, 01 May 2026 08:03:36 GMT</pubDate>
            <description><![CDATA[Crypto and web3 security insights, including tools, hacks, and regulations. ]]></description>
            <content:encoded><![CDATA[<p><strong>TL;DR</strong></p><ul><li><p>Trail of Bits keeps innovating, check out Trailmark which turns source code into a queryable call graph with semantic metadata.</p></li><li><p>Nethermind's fine tuned AuditAgent shows 67% post-validation recall, outperforming Claude Opus 4.6 at 47% and GPT-5.2 at 38%.</p></li><li><p>Using AI agents in production with security-sensitive workloads? Check out Hacken's post on securing OpenClaw. </p></li><li><p>The news flow on the $290M KelpDAO keeps coming, as always great analysis from Rekt. Metrika also covers how real-time on-chain monitoring fits into the security controls required in DeFi. </p></li><li><p>Not your crypto: sanctions get real. The U.S. Department of the Treasury’s Office of Foreign Assets Control blocks $344M in Iran-linked assets, while the EU cracks down on Russia. </p></li><li><p>ILITY Network announced a $2M strategic round for a privacy-preserving cross-chain verification and ZK data interoperability stack.</p></li><li><p>In research, check out CONFETTY, an open-source web application that enforces data confidentiality in public blockchain environments without sacrificing transparency.</p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-insightful" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Insightful </h1><p><strong>Trailmark Turns Code into Graphs</strong></p><p>Trail of Bits released Trailmark, a library that turns source code into a queryable call graph with semantic metadata. It supports Solidity and other languages, and is aimed at questions like “can untrusted input reach this function?” and “what calls into this code path?” For smart contract auditors, it is another option for repeatable reachability checks and code-structure queries without wiring up a custom analysis pipeline. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://blog.trailofbits.com/2026/04/23/trailmark-turns-code-into-graphs/">Trail of Bits</a>) </p><p><strong>AuditAgent on EVMBench: 67% Recall vs. 47% for Claude Opus 4.6</strong></p><p>Nethermind ran its AuditAgent AI security tool across all 40 EVMBench repositories and published results showing 67% post-validation recall, outperforming Claude Opus 4.6 at 47% and GPT-5.2 at 38%. The post argues that recall-only benchmarking is insufficient and examines what the data reveals about the current state of AI-augmented security tooling. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.nethermind.io/blog/auditagent-on-evmbench-what-the-data-shows">Nethermind</a>) </p><p><strong>Hardening OpenClaw AI Agents on Aleph Cloud: A Step-by-Step Defense Guide</strong></p><p>Hacken published a tiered security hardening guide for deploying OpenClaw AI agents on Aleph Cloud. Drawing on its LLM red teaming and prompt injection research, the guide covers private VPS binding, filesystem allowlisting, credential encryption, MCP server supply chain hygiene, and monthly red team exercises. If you are using AI agents in production with security-sensitive workloads it's worth a read. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacken.io/insights/openclaw-hardening/">Hacken</a>)</p><p><strong>The Kelp–Aave Incident Shows how Bridge Risk Becomes Lending Risk</strong></p><p>Metrika’s write-up tracks how a failure in rsETH issuance and cross-chain verification flowed into Aave V3 through collateral deposits and fast borrowing. Aave’s contracts behaved as designed; the weak point was the trust boundary around bridged collateral. The post is details the on-chain timeline of events (drain → distribution → deposits → borrowing), the operational outcomes (freezes, utilization spikes, and governance-driven loss allocation) and how real-time on-chain monitoring fits into the security controls required in DeFi. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.metrika.co/blog/post-mortem-kelp-aave">Metrika</a>)</p><p><strong>European Police Dismantle €50M Crypto Investment Fraud Ring</strong></p><p>Austrian and Albanian authorities dismantled a criminal network running a large-scale cryptocurrency investment fraud operation that caused estimated losses exceeding €50M ($58.5M) to victims worldwide. The coordinated operation resulted in multiple arrests across both countries. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.bleepingcomputer.com/news/security/european-police-dismantles-50-million-crypto-investment-fraud-ring/">Bleeping Computer</a>)</p><h1 id="h-gimme-the-loot" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Gimme the loot</h1><p><strong>Rekt Covers the KelpDAO Bridge Attack</strong></p><p>DPRK-linked hackers poisoned LayerZero's DVN infrastructure by compromising RPC nodes, forging a bridge message, and releasing ~$290M in rsETH from KelpDAO in a single transaction without breaking a single line of code. Aave was left with hundreds of millions in bad debt. LayerZero has since decommissioned all affected nodes and confirmed DVN recovery. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rekt.news/kelpdao-rekt">Rekt</a>)</p><p><strong>Volo Protocol Loses $3.5M to Compromised Admin Key on Sui</strong></p><p>A private key compromise, likely via social engineering, enabled an attacker to drain approximately $3.5M from Volo's WBTC, XAUm, and USDC vaults on Sui. Volo detected the breach swiftly, froze all vaults, and coordinated with the Sui Foundation to recover nearly all funds, resulting in a net loss of just $60K, a notable case of effective incident response. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rekt.news/volo-rekt">Rekt</a>)</p><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>Total 2026 hack events: 71</p><p>The total amount of money lost this year: $777,004,028</p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/05bb0d4240e0449c2995f7f0752e619d7b2940ee89e27340397f7a676220dd31.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAJCAIAAADcu7ldAAAACXBIWXMAABYlAAAWJQFJUiTwAAAB+klEQVR4nJ2RwWvTcBTHc5iI7OhBnRN20k7xVrYdZiEdlmwgrKIlVCcFp1VM1aTrBj+2TE3a9ZCplBSsHRQ7BJn00DKEEbzt4D+wg9emw8OPdKwhpIf8eNL9pOa6fnmH9/2+w3sfHmMYhqIohmE4g6ptWX77++DAnzDFYpHjOEmSms0mPo1apukRUioU5qanPUJapkmTK+fO/tzb69g2xhgAGMMwiifCGJ/2cABYS6evXrgIAG3Losl5hvlRrwPAP4JKpcLzPEJoMAIkijdGR/0EI0NDlVLJI+Q/AUJI07TBCNYzmcnANT/B+OWRD9ksTXoE9MmaprVMs21Z/QNp7zhO39LyEwDA49j9OywLAJQAACavj69nMh4hfw4PPUKYRqPB87yiKB3bBoCu6zqOAwAeIY7j/Nrf71s4EW2Oj466rgsAyXj82cKCf8QGg+9WVugPegsAoGPbL1Opsq7Xd3bmQrfmb888TyTW0ulgIHCGYRSEkCh+3dr6mM9/+fypWi4jUbw5NvYqmdyt1WZDIXZigk6/b2/PTE1dGh5+dO/u+43sbq3Wdd3eAozxg3hclWVJePEkkcir6mwkUtL1p4uLb2R5Q1EiLLuZy8WiUUkQJEGIRef1QiHCsqosv06lljNLWlblwuHNXO4hz2ua9nZ1lQuHv1WrAOQv2VuUOOhd7zcAAAAASUVORK5CYII=" nextheight="582" nextwidth="2184" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><h1 id="h-we-must-have-regulations" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">We must have regulations</h1><p><strong>UK FCA Disrupts Suspected Illegal P2P Crypto Trading</strong></p><p>The FCA says it targeted eight London locations in a joint operation with HMRC and SWROCU to disrupt suspected unregistered peer-to-peer crypto trading. It issued cease-and-desist letters and gathered evidence for ongoing criminal investigations, describing unregistered P2P activity as a financial-crime risk under UK AML rules. The message is straightforward: OTC-style “informal” trading venues are squarely in scope for enforcement. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.fca.org.uk/news/press-releases/fca-leads-first-crackdown-illegal-crypto-trading">FCA</a>) </p><p><strong>ESMA Sets Expectations for MiCA’s July 1, 2026 Deadline</strong></p><p>The <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.esma.europa.eu/">European Securities and Markets Authority</a>’s statement clarifies supervisory expectations as MiCA transitional periods end across the EU on July 1, 2026. It expects unauthorized CASPs to have implemented wind-down plans by that date, including client off-boarding and asset transfers to authorized providers or self-hosted wallets. It also reiterates limits on third-country provision of MiCA services outside narrow reverse-solicitation cases. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.esma.europa.eu/sites/default/files/2026-04/ESMA75-113276571-1679_Statement_on_the_end_of_transitional_periods_under_MiCA.pdf">ESMA</a>) </p><p><strong>Record OFAC Action Blocks $344M in Iran-Linked Crypto Assets</strong></p><p>Chainalysis reports on the U.S. Department of the Treasury’s Office of Foreign Assets Control update on April 24 designation targeting a network of wallets and entities linked to the Central Bank of Iran and IRGC-affiliated actors. The action blocked approximately $344M in digital assets and named shipping firms and tanker vessels used as vehicles for sanctions evasion via cryptocurrency. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/central-bank-of-iran-designation-ofac-update-april-2026/">Chainalysis</a>)</p><p><strong>EU's 20th Sanctions Package Targets the Infrastructure of Crypto Evasion</strong></p><p>Elliptic examines how the EU's 20th Russia sanctions package goes beyond prior measures by directly targeting the underlying architecture of crypto-enabled sanctions evasion, naming specific exchange typologies and obfuscation methodologies for the first time. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.elliptic.co/blog/eu-20th-sanctions-package-targets-the-architecture-of-crypto-sanctions-evasion">Elliptic</a>) </p><h2 id="h-seeking-clarity" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Seeking CLARITY</h2><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/f43c5e63939ebc2cbf0fe37bdc75470df48047b59a11f463ca47242ac3dcba86.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAARCAIAAAAzPjmrAAAACXBIWXMAABYlAAAWJQFJUiTwAAADMklEQVR4nLVUTUgbQRQeaKEXhZ7iybS0Ry9ePPZQevLU0pIee5EetODPTXuwtf6gBbcgS8UaDHYjqFQDcamahM0I2YYk9WfVjZH4k121WTWZtG7U7IpO2azdhhVFCv2Yw+zbee/N9973BtwquQfy+D6/xPN8QhACbBChDP5XIISkP5BlGdy8XaInePLsOQCgtNRaXFRstd4BANzIw2q1WiyWsrKy8vJyAIDFYolGo1ck4DgOQuhyuZxOZzQaBdxs0FIEHj2oCLKB9rZ377s6P1MUSZI2m62pqamrq4sgiNbWVofDQZJkXV0dQRCyLF+fEAjPRRve9JD2L1W1bVX1HX2O8fXl5VQy+W/1kWU5IQiStCtJkihuaSWKxQWCdLpoxk65u8mhKS+bSe2n9vaUy4EvB0IoHI7wPM9xizzPp9JpgP8b1tbWNQaqenKcU1X1xFiFh7LZowP50LAXHjg9OyvcGJ/GMUnaPc7lNAamoKdnZ/rCGM+wcwOUG2PMr2z4A7OmHKp6oh8rtBhxfiSTGoMByu1hQpfR9AdmewfGVmIbM+xcS2e/nXJHFlYwxrG44INhPdz29u5xTt1J7m+KyeOcavgihLQEPhh+3fpRN22KyUBosZscGpuAGOMFbnV43Lu2uVPb2P2i+q24JcXiwqjLx69s9A6M9TnG/YHZneT+2AQcdfk8TIgNcjPsXEGJJEVRtBIBcNc9HcAYe5hQbWN3B+Hoc4xTI5OdHwaHRqcO5MOHj2sqbfW6p4cJ2Sn3gXyYzR5V2uoHh79ijO2UOxYXMMYuWruZjoQgaAwwxvcrnvb0jcTiAj3N7qczsbigKEo2e2Q0tqGJ2BT/TobRVQ8T0ttgNOZbeIn8NOpw0j4Y3khsnTP4eZClRiZf1rYj9MvUOjXvpsusUCGmfaGEFrjVls5+Fw2X+dg5A1U9MeRokqAOI6UJJvmZLKl0+lymhf/kPExuiqJI0u7FBHmpZEyzbczT+aDJsiyKIkJID5QvSO7q9+Ai9CdEv5wORVEQymgMIIQ1Na+qq6shhPMLnNfL0PRkQtAkcf3ojB8yfsiyQa+XmZ72Njc3RyIRmp4MsOxvPnCNfXp9DoEAAAAASUVORK5CYII=" nextheight="968" nextwidth="1814" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://polymarket.com/event/clarity-act-signed-into-law-in-2026">Polymarket</a>)</figcaption></figure><h1 id="h-vcs-and-funding" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">VCs &amp; funding</h1><p><strong>ILITY Network Raises $2M for ZK Data Interoperability</strong></p><p>ILITY Network announced a $2M strategic round for a privacy-preserving cross-chain verification and ZK data interoperability stack. If the project delivers, it would sit in the same “security plumbing” category as other attempts to reduce trust assumptions across cross-chain data paths. The announcement is clean example of funding flowing to privacy/security-adjacent infrastructure rather than apps.</p><div data-type="twitter" tweetid="2047310229524869595">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/ILITYfndn">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/8633b78f9df2ba156fe0544ec571421b6eb1ec62099bb55faea97771ea753c91.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/ILITYfndn" class="twitter-displayname">ILITY Foundation</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/ILITYfndn" class="twitter-username">@ILITYfndn</a></p>
    
            </div>
            <a href="https://twitter.com/ILITYfndn/status/2047310229524869595" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      We're excited to share that ILITY has raised $2M at a $21M valuation with strategic investment and partnership from <a class="twitter-content-link" href="https://twitter.com/animocabrands" target="_blank">@animocabrands</a>, <a class="twitter-content-link" href="https://twitter.com/dao_duck" target="_blank">@dao_duck</a> as well as other leading VC and angels <br><br>We are building the first L1 dedicated to private cross chain verification. By utilizing 
      <div class="twitter-media"><img class="twitter-image" src="https://storage.googleapis.com/papyrus_images/2a36d95d0f24ef138c20f2005bfb0a056939bdb0f39d90d9a08532ea66b07e7e.jpg"></div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/ILITYfndn/status/2047310229524869595" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            337
          </a>
          <a target="_blank" href="https://twitter.com/ILITYfndn/status/2047310229524869595"><p>1:42 PM • Apr 23, 2026</p></a>
        </div>
    
  </div> 
  </div><h1 id="h-research-corner" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Research corner</h1><p><strong>CONFETTY Brings Data Confidentiality to Public Blockchain Process Execution</strong></p><p>Researchers present CONFETTY, an open-source web application that enforces data confidentiality in public blockchain environments without sacrificing transparency. The platform uses smart contracts for public interaction enforcement alongside attribute-based encryption for fine-grained access control, bridging the gap between private permissioned chains and fully transparent public ledgers. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2603.13900">arXiv</a>)</p><p><strong>Blockchain and AI Security Synthesis Proposes Unified Evaluation Blueprint</strong></p><p>The paper synthesizes fragmented research on blockchain-AI security for intelligent networks into three lanes: (i) a taxonomy of blockchain-AI security for intelligent networks, (ii) integration patterns for verifiable and adaptive security workflows, and (iii) the Blockchain-AI Security Evaluation Blueprint (BASE), a reporting checklist spanning AI quality, ledger behavior, end-to-end service levels, privacy, energy, and reproducibility. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2604.06323">arXiv</a>)</p>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>security</category>
            <category>hacks</category>
            <category>tools</category>
            <category>regulation</category>
            <category>cybersecurity</category>
            <category>ai</category>
            <category>agents</category>
        </item>
        <item>
            <title><![CDATA[0x30 Web3 Security Bulletin]]></title>
            <link>https://paragraph.com/@w3sb/0x30-web3-security-bulletin</link>
            <guid>dFHRmlbYuxfgCClXbCml</guid>
            <pubDate>Fri, 24 Apr 2026 10:30:32 GMT</pubDate>
            <description><![CDATA[Crypto and web3 security insights, including tools, hacks, and regulations. ]]></description>
            <content:encoded><![CDATA[<p><strong>TL;DR</strong></p><ul><li><p>North Korea's Lazarus Group exploited KelpDAO's LayerZero bridge on April 18, stealing $292M. </p></li><li><p>Equally as shocking and being intensely debated: Arbitrum Security Council's emergency freeze of 30,766 ETH from the KelpDAO hacker. </p></li><li><p>Bybit CEO Ben Zhou discuses lessons learned and web3 incident response stemming from the 2025 $1.5B hack. </p></li><li><p>Did you order a hardware wallet to keep your funds safe? A Brazilian security researcher discloses a sophisticated counterfeit Ledger Nano S+ operation. </p></li><li><p>Inco announced a $5M strategic round and described "Inco Lightning" as a TEE-backed confidentiality layer. The funding round was led by Andreessen Horowitz Crypto Startup Accelerator (a16z CSX). </p></li><li><p>Mirage announced a seed round and a closed alpha for a privacy protocol that avoids shared mixer pools by using transaction-specific escrow and coordinated settlement. The round was led by&nbsp;Seed Club Ventures&nbsp;and&nbsp;Kyber Knight.</p></li><li><p>Dr. Kelly Coulter of Elliptic provides a practical guide for UK crypto firms preparing for FSMA authorization. She notes that firms using AI in compliance controls must be able to explain algorithmic outputs to regulators.</p></li><li><p>In research, AI-Powered Smart Certificates,<strong> </strong>Stefan Behfar and Jon Crowcroft propose AI-powered "smart certificates" as programmable, continuously learning trust artifacts that blend on-chain verifiability with off-chain ML signals. </p></li></ul><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><h1 id="h-insightful" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Insightful </h1><p><strong>Code is Law? Decentralized Protocols and DAOs? </strong></p><p>The Arbitrum Security Council's emergency freeze of 30,766 ETH from the KelpDAO hacker has ignited one of the most active "code is law" debates in years. Here's a breakdown of where the debate is hottest and who is saying what. </p><div data-type="twitter" tweetid="2046446942494802274">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/griffgreen">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/8b93d9cfb1a3dbff6b0150ee2eb5f0b5a008b113e12204d1e5ee0f5204179fb5.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/griffgreen" class="twitter-displayname">Griff Green - griff.eth</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/griffgreen" class="twitter-username">@griffgreen</a></p>
    
            </div>
            <a href="https://twitter.com/griffgreen/status/2046446942494802274" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      I'm a member of the Security Council &amp; I can tell you we did not make this decision lightly, there were countless hours of debates, technical, practical, ethical and political.<br><br>But all it takes for evil to triumph is for good men to do nothing, so today, we decided to do
      
      
      <div class="twitter-quoted">
       
  <div class="twitter-quoted twitter-embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/arbitrum">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/f191dd32e46686abfd7bf028e003b10985dbc20d827d4430dbd86d678fcfa263.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/arbitrum" class="twitter-displayname">Arbitrum</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/arbitrum" class="twitter-username">@arbitrum</a></p>
    
            </div>
            <a href="https://twitter.com/arbitrum/status/2046435443680346189" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      The Arbitrum Security Council has taken emergency action to freeze the 30,766 ETH being held in the address on Arbitrum One that is connected to the KelpDAO exploit. The Security Council acted with input from law enforcement as to the exploiter’s identity, and, at all times,
      
      
       
    </div>
    
  </div> 
  
    </div> 
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/griffgreen/status/2046446942494802274" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            2,450
          </a>
          <a target="_blank" href="https://twitter.com/griffgreen/status/2046446942494802274"><p>4:32 AM • Apr 21, 2026</p></a>
        </div>
    
  </div> 
  </div><p>What makes this debate unusually sharp is the <em>mechanism</em> Arbitrum used. Rather than simply freezing an address, the Security Council reportedly without possessing the hacker's private key, executed a transaction in the hacker's name, essentially impersonating the attacker to move the funds to a governance-controlled wallet. This means the debate isn't just about fund freezes — it's about whether a council can unilaterally rewrite chain state and issue transactions from any address. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.techflowpost.com/en-US/article/31233">TechFlow</a>) </p><br><table><colgroup><col><col></colgroup><tbody><tr><th colspan="1" rowspan="1"><p><strong>Camp</strong></p></th><th colspan="1" rowspan="1"><p><strong>Core Argument</strong></p></th></tr><tr><td colspan="1" rowspan="1"><p>Pro-freeze</p></td><td colspan="1" rowspan="1"><p>Emergency safeguards are a feature, not a bug. If the capability exists and isn't used to stop a nation-state theft, the chain fails its users. Hybrid security is the mature model.</p></td></tr><tr><td colspan="1" rowspan="1"><p>Anti-freeze</p></td><td colspan="1" rowspan="1"><p>The moment a council can move funds without a private key, permissionlessness is dead. Today it's a hacker; tomorrow it could be anyone. The precedent is more dangerous than the hack.</p></td></tr></tbody></table><br><p><strong>Lessons Learned from the $1.5B ByBit Hack and Web3 Incident Response</strong></p><div data-type="twitter" tweetid="2046432981221618122">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/TheBlockCo">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/ce1b0b752e76a4a9701c8fa242270d9cb82bdc63728e6473ac86b2902aef460a.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/TheBlockCo" class="twitter-displayname">The Block</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/TheBlockCo" class="twitter-username">@TheBlockCo</a></p>
    
            </div>
            <a href="https://twitter.com/TheBlockCo/status/2046432981221618122" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      "Security incidents and the threat of hackers is going to be a constant battle for crypto."<br><br><a class="twitter-content-link" href="https://twitter.com/Bybit_Official" target="_blank">@Bybit_Official</a> CEO <a class="twitter-content-link" href="https://twitter.com/benbybit" target="_blank">@benbybit</a> discusses lessons learned from last year's $1.5B hack, the TradFi takeover of the crypto industry, and more.<br><br>Watch the full interview with <a class="twitter-content-link" href="https://twitter.com/gazza_jenks" target="_blank">@gazza_jenks</a><img class="twitter-emoji" draggable="false" alt="👇" src="https://abs-0.twimg.com/emoji/v2/72x72/1f447.png"> 
      <div class="twitter-media">
      <img class="twitter-image" src="https://pbs.twimg.com/media/HGZkEGkbYAA66X3.jpg">
    </div>
      
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/TheBlockCo/status/2046432981221618122" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            30
          </a>
          <a target="_blank" href="https://twitter.com/TheBlockCo/status/2046432981221618122"><p>3:36 AM • Apr 21, 2026</p></a>
        </div>
    
  </div> 
  </div><p><strong>Fake Ledger Nano S+ Found Exfiltrating Seeds </strong></p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.reddit.com/user/Past_Computer2901/">Past_Computer2901</a>, a Brazilian security researcher and founder of High Code, discloses a sophisticated counterfeit Ledger Nano S+ operation sourced from a Chinese marketplace. The fake device uses an ESP32-S3 chip (with sanded markings) instead of Ledger's genuine ST33 Secure Element, runs non-existent firmware version "V2.1," stores seeds and PINs in plain text, and beacons to a C2 server at <code>kkkhhhnnn[.]com</code> — immediately exfiltrating any entered seed across ~20 supported blockchains. The operation spans five vectors: counterfeit hardware, a malicious Android APK signed with a debug certificate, a Windows .EXE, a macOS .DMG resembling AMOS/JandiInstaller campaigns, and an iOS TestFlight build. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.reddit.com/r/ledgerwallet/comments/1sm9w6z/supply_chain_alert_analyzing_a_highly/">Reddit</a>)</p><div data-type="callout" type="info"><link rel="preload" as="image" href="https://paragraph.com/editor/callout/information-icon.png"><div class="callout-base callout-info" data-node-view-wrapper="" style="white-space:normal"><img src="https://paragraph.com/editor/callout/information-icon.png" class="callout-button"><div class="callout-content"><div><p><strong>Ledger Official Link</strong><br>#StopTheScammers</p><h1 id="h-ongoing-phishing-campaigns" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.ledger.com/phishing-campaigns-status"><strong>Ongoing phishing campaigns</strong></a></h1></div></div></div></div><p><strong>Certora Hardens 1inch's Cross-Chain Commit-Reveal Swap Mechanism</strong></p><p>Ilya Leybovich of Certora describes the firm's security review of 1inch's cross-chain swap infrastructure, which uses a commit-reveal design to eliminate reliance on centralized bridges or complex oracle systems. Certora's review focused on timing window integrity, safety deposit alignment, and fee configuration accuracy, areas where small misalignments can result in stuck funds or broken incentives. The engagement highlights that protocol security is an ongoing discipline rather than a pre-launch checkbox. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.certora.com/blog/certora-x-1inch.crosschain-swaps">Certora</a>) </p><p><strong>Five Crypto Risk Typologies Every Financial Institution Must Know</strong></p><p>Elliptic outlines five key crypto financial crime categories that financial institutions face: drug-related money laundering, fraud and social engineering (including pig-butchering and AI deepfake scams), obfuscation via cross-chain laundering, sanctions evasion, and state-sponsored cyber theft. With over $21.8 billion laundered cross-chain since 2023, single-chain monitoring is no longer sufficient. Blockchain analytics covering multi-chain tracing, wallet screening, and indirect exposure detection is positioned as baseline compliance infrastructure for any FI engaging with digital assets. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.elliptic.co/blog/five-crypto-risk-typologies-every-financial-institution-needs-to-understand">Elliptic</a>) </p><p><strong>Hexens: Gröbner Bases in Cryptanalysis — Attacking Poseidon (Part 2)</strong></p><p>The Hexens team publishes Part 2 of their Gröbner basis cryptanalysis series, demonstrating an attack on a reduced-round Poseidon hash instance by recovering a preimage from its digest. Building on the algebraic machinery introduced in <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hexens.io/blog/groebner-basis-part1">Part 1</a>, the post walks through a practical polynomial system construction and shows how Buchberger's algorithm can be applied to break cryptographic hash functions under reduced-round assumptions. The work has direct relevance to ZK proof systems that rely on Poseidon for hashing. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hexens.io/blog/groebner-basis-part2">Hexens</a>) </p><p><strong>Wonderland CTF 2026: Fixed Deposits Challenge Results</strong></p><p>Runtime Verification announces the results of the Wonderland CTF 2026 Fixed Deposits challenge, a community competition designed to stress-test formal verification skills. The post covers the challenge outcomes and continues RV's pattern of using CTF events to surface rare bugs and advance formal methods tooling, including Kontrol and Simbolik, among the broader developer community. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://runtimeverification.com/blog/wonderland-ctf-2026">runtime verification</a>)</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://ctf.wonderland.xyz/leaderboard"><strong>Checkout the Wonderland CFT Leaderboard</strong></a><strong> and Solutions</strong></p><div data-type="twitter" tweetid="2046686602043506808">
  <div class="twitter-embed embed">
    <div class="twitter-header">
        <div style="display:flex">
          <a target="_blank" href="https://twitter.com/Wonderland">
              <img alt="User Avatar" class="twitter-avatar" src="https://storage.googleapis.com/papyrus_images/7fede4be880b0fc35ed540dac0ccf0548044d11c7c88f4df62e57bb1f2c62fe8.jpg">
            </a>
            <div style="margin-left:12px;margin-right:auto;line-height:1.2;">
              <a target="_blank" href="https://twitter.com/Wonderland" class="twitter-displayname">Wonderland</a>
              <p style="margin-top:2px;line-height:1;"><a target="_blank" href="https://twitter.com/Wonderland" class="twitter-username">@Wonderland</a></p>
    
            </div>
            <a href="https://twitter.com/Wonderland/status/2046686602043506808" target="_blank">
              <svg class="twitter-logo" width="20" height="20" viewBox="0 0 24 23" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path d="M0.256759 0L9.36588 12.1823L0.200012 22.0873H2.26348L10.289 13.4158L16.7728 22.0873H23.7935L14.1723 9.21978L22.7043 0H20.6409L13.2506 7.98633L7.27889 0H0.258127H0.256759ZM3.29035 1.52002H6.51495L20.7571 20.5673H17.5325L3.29035 1.52002Z" fill="currentColor"></path>
              </svg>
            </a>
          </div>
        </div>
      
    <div class="twitter-body">
      A few weeks ago at ETHCC, we ran the Wonderland CTF.<br><br>Solutions are now live <img class="twitter-emoji" draggable="false" alt="⚔️" src="https://abs-0.twimg.com/emoji/v2/72x72/2694.png"> <br><br>If you got stuck (or want to go deeper), this is the full breakdown.<br>
      
      
        <a class="twitter-card-link" href="https://t.co/1rgXRod3zC" target="_blank">
          <div class="twitter-media twitter-summary-large-image">
            <img src="https://storage.googleapis.com/papyrus_images/f8d541b9b8a2442357b53c234bf08d6ca0b27811f5b8a6943578b817a4f3c5a6.png">
            <div class="twitter-summary-card-text">
              <span>handbook.wonderland.xyz</span>
              <h2>EthCC 2026 CTF Solutions | Wonderland Handbook</h2>
              <p>An overview of the largest live crypto CTF in history hosted at EthCC 2026 with summaries of each challenge and links to official writeups of the solutions.</p>
            </div>
          </div>
        </a>
       
    </div>
    
     <div class="twitter-footer">
          <a target="_blank" href="https://twitter.com/Wonderland/status/2046686602043506808" style="margin-right:16px; display:flex; align-items:center;">
            <svg class="twitter-heart" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg">
              <path d="M20.84 4.61a5.5 5.5 0 0 0-7.78 0L12 5.67l-1.06-1.06a5.5 5.5 0 0 0-7.78 7.78l1.06 1.06L12 21.23l7.78-7.78 1.06-1.06a5.5 5.5 0 0 0 0-7.78z"></path>
            </svg>
            33
          </a>
          <a target="_blank" href="https://twitter.com/Wonderland/status/2046686602043506808"><p>8:24 PM • Apr 21, 2026</p></a>
        </div>
    
  </div> 
  </div><h1 id="h-companies-in-the-news" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Companies in the news </h1><p><strong>Certora Releases Prover Version 8.11.3</strong></p><p>Shane Runquist announces the release of Certora Prover Version 8.11.3, which includes a set of new features for the formal verification toolchain. The update continues Certora's regular cadence of improvements to its flagship Prover product, used to formally verify smart contracts across Ethereum, Solana, and Stellar. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.certora.com/blog/prover_v8.11.3">Certora</a>)</p><h1 id="h-gimme-the-loot" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Gimme the loot </h1><p><strong>Lazarus Group's $292M KelpDAO Bridge Exploit Dissected</strong></p><p>The Chainalysis Team details how North Korea's Lazarus Group exploited KelpDAO's LayerZero bridge on April 18, stealing ~$292 million in rsETH — not through a smart contract bug, but by compromising off-chain RPC nodes and DDoSing external validators to forge a phantom token burn. A 1-of-1 DVN configuration gave attackers a single point of failure. Rapid contract pausing and the Arbitrum Security Council's freeze of 30,766 ETH limited further damage. The incident underscores that cross-chain invariant monitoring, not just transaction-level scanning, is essential for bridge security. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/">Chainalysis</a>)</p><h2 id="h-slowmist-stats-this-week" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://hacked.slowmist.io/statistics/?c=all&amp;d=2026">SlowMist stats this week</a></h2><p>Total 2026 hack events: 67</p><p>The total amount of money lost this year: $762,115,414 </p><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/be3cfee2c78e6733ca397170778b9f32b5d5cd30a0de529d851dae0963e5e13f.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAJCAIAAADcu7ldAAAACXBIWXMAABYlAAAWJQFJUiTwAAABwElEQVR4nGM4d+5cT0/PkSNH/v///5Xa4P///wy7d+8uKirq6ekh25R3b9+mR0XB2f///28qL28qL/////+P799BFmRmZlZVVb0mFzx5/JiBgeH2rVsQ9p+/f7MSE2z09KEWbNq0KSEhgRILXr9+LcbAcPbUqU+fP0MsKMzMtNHT//P3L8gCSBz09PQ8evSIPNM/ff4sx8uzd+dOuAVVhYUIC3bv3o3HB1+/fiXSgk2rV//8/Rtugb2RIdSCI0eOJCQkNDY1/fn7F56QIIz///9fOnfu7u3b//////P3L0TBz9+/IWyIgj9///78/VtNXGLn5s1wXU3l5Yg4+P///6fPn0uKi2ZOmrRq8eLkyCgbQ/389PTkyKjY4GAZfr5IP7/ygoK+9talc+aUFxSsW7ZsQkdHdlKSgYpKeUHBmiVL60tLtRTkm8rLZ06aNHvKlKrCQk0FBW97h5a6uq9fv4Is+Pr1a0529rQJE6b09aUmJKxdsyY1IaGvq2vKpEl5ubkH9u2Nj4qqKC5etmCBn6fnsgULCrKyKoqLlyxaBOE21tS0tbZu27gxPipqSl9fRXFxUVHR3p07YyIiXr9+DQAxiJ0ion4FFwAAAABJRU5ErkJggg==" nextheight="606" nextwidth="2268" class="image-node embed"><figcaption htmlattributes="[object Object]" class="hide-figcaption"></figcaption></figure><h1 id="h-we-must-have-regulations" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">We must have regulations </h1><p><strong>UK Publishes Draft Amendments to the 2026 Cryptoassets Regulations </strong></p><p>The UK government published a policy note for a draft statutory instrument amending the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026. The note describes changes intended to smooth stablecoin payment services authorization and perimeter issues while broader payments reforms roll out, while keeping lending/borrowing activities in scope for FCA rulemaking. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.gov.uk/government/publications/policy-note-draft-statutory-instrument-amending-the-cryptoasset-regulations/draft-statutory-instrument-amending-the-financial-services-and-markets-act-2000-cryptoassets-regulations-2026-policy-note">GOV.UK</a>) </p><p><strong>UK FCA's New Cryptoasset Regime: What Your AML Framework Needs Now</strong></p><p>Dr. Kelly Coulter provides a practical guide for UK crypto firms preparing for FSMA authorization, which opens September 30, 2026. The FCA's expectations are a qualified Money Laundering Reporting Officer (MLRO), a structured Business-Wide Risk Assessment (BWRA), a Customer Risk Assessment aligned to that BWRA, and explainable transaction monitoring. These requirements are already enforced under current MLR registration and will carry forward. Firms using AI in compliance controls must be able to explain algorithmic outputs to regulators. Authorization windows open in September, leaving only months to shore up common weaknesses. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.elliptic.co/blog/getting-your-aml-framework-ready-for-the-fcas-new-cryptoasset-regime">Elliptic</a>)</p><h3 id="h-clarity-tracker-down" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">CLARITY Tracker Down! </h3><figure float="none" data-type="figure" class="img-center"><img src="https://storage.googleapis.com/papyrus_images/6f55de968e3c9a8c31dc4a4a3180de3895a386464c875949c8a4d89ad36dac68.png" blurdataurl="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAQCAIAAAD4YuoOAAAACXBIWXMAABYlAAAWJQFJUiTwAAAC+klEQVR4nKVUzWsTQRTf3lov+Rc8SUHw4sGDB/EgqIgehIp48yLiKaIgFKlgQcFWQVtUrKUk0iKSFhPRJjabuNmS3did2rVpPpqPNpuaTUl302Z2TWeTjCRjtyFt/fzxDsPvvXnv/d48hrLsP0g18EUUGYZNJFNe2o//AxDCVAPRaDSbzVKHDh8hBU6dPkNRVEfHPksDhGxra2tvb7dYLJ2dnYRxu90YY4TQXgUUReH5EM+H3G4PAIBaTie6zp8dfPywqCqRSBgAIbq4yHGcy+X6uoVoAxzHAQAghH8liPr4aeZEl/XW3WfHzl07cPTiiM0ZcL3dKBb/eUSRBhLJZCQay8kyhRBaXS2o6oairOfkAoRaWdcNwzCHgLYPxp8UyGZXiGUkSVWLVIu7Wqu1GEJG85nYzjDTzFSJZKqu4PeSY0tyfg1jXIJ6ebP1bZszkrMpFEKIEKJycqGgFFt6NM8Y46fDE8GZMMbYywjD9nfxpFRQ6i+EkFGCesWomBnNYoTJZlfy+Tw1ZHfaX08Stlqryfk1RVkXZiOE0TTdQ4c8dIiE8cKCa3LaNTmNMWY5sW9gNBJbIip9ARBPSl5G8AVACeoNBVpdQXkTnbxwnQnOkRZ67g8Nvhy/0TPAcqKHDvUNjAIxHoktXbpyp+vybYyxpukTLv+YY8rt5UpQ7+0fcTj9wmwEiPEXNifGOJn5RhSnUum6gvqq7j/e2z+CMXY4/UCMOz+wObnACwup9Eo8KSFkADF+9eYDXlgwJyNl82QaT56/8QUAKbwsyaTL914uncn9VIAxDkfTY46pe49sLCdijMubqGUjNU0no2gecfM7kfGat3JyYcju/AxECEv1AhWjoijrTHBO03Rz1XZufbVpYUwvWYoWkkSqahFCSDU56my1VvteLu9cVoTQXp8EaqCF2d4icpMEkXYURdk1i6ru/n+Yrq0kzTCoQCBgtVq7u7tpmp6fDwc5nqZ9u9b4BTKSxDDsjABYluX5kM3+anx8IsjxDMP+AIEJUHbx+GwsAAAAAElFTkSuQmCC" nextheight="976" nextwidth="1910" class="image-node embed"><figcaption htmlattributes="[object Object]" class="">(<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://polymarket.com/event/clarity-act-signed-into-law-in-2026">Polymarket</a>)</figcaption></figure><h1 id="h-vcs-and-funding" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">VCs &amp; funding </h1><p><strong>Inco Bets on TEEs Now and FHE Later for Confidential Onchain Apps</strong></p><p>Inco announced a $5M strategic round and described "Inco Lightning" as a TEE-backed confidentiality layer for existing chains, starting with Ethereum/Base. The release ties confidentiality to compliant payments and "private DeFi," and lists ecosystem work around confidential token standards and industry groups (including OpenZeppelin and Zama). The funding round was led by Andreessen Horowitz Crypto Startup Accelerator (a16z CSX). (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://blockchainwire.io/press-release/inco-raises-5m-in-strategic-round-led-by-a16z-csx-to-accelerate-web3-confidentiality-launches-inco-lightning-on-base-sepolia">Blockchain Wire</a>)</p><p><strong>Mirage Seed Round for "Pool-less" Private Stablecoin Transfers</strong></p><p>Mirage announced a seed round and a closed alpha for a privacy protocol that avoids shared mixer pools by using transaction-specific escrow and coordinated settlement. The pitch is "privacy without the stigma" of obvious privacy-system interactions, with settlement claims under two minutes on Ethereum mainnet and seconds on faster EVM networks. The team says it targets payroll and B2B transfers as much as retail payments. The seed round was led by&nbsp;Seed Club Ventures&nbsp;and&nbsp;Kyber Knight and others. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://chainwire.org/2026/04/15/mirage-announces-seed-round-and-closed-alpha-for-private-stablecoin-transfers/">Chainwire</a>)</p><h1 id="h-research-corner" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Research corner</h1><p><strong>AI-Powered Smart Certificates: Toward Adaptive Web3 Security</strong></p><p>Stefan Behfar and Jon Crowcroft argue that static, tool-centric defenses like MythX and PhishTank are structurally insufficient against today's cross-layer Web3 threats, from reentrancy exploits on Ethereum to large-scale DeFi manipulation. Their position paper, updated on arXiv this month, proposes AI-powered "smart certificates" as programmable, continuously learning trust artifacts that blend on-chain verifiability with off-chain ML signals across wallet, application, and smart contract layers. The framework targets phishing, Sybil attacks, API exploits, and smart contract vulnerabilities with real-time, automated response, a meaningful evolution beyond isolated auditing tools. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://arxiv.org/abs/2311.01956">arXiv</a>)</p><p><strong>MEV-ACE: Identity-Authenticated Fair Ordering for Proposer-Controlled MEV Mitigation</strong></p><p>MEV-ACE proposes a single-slot commit/open ordering protocol that binds participants to registered economic identities and uses threshold receipts plus VDF-delayed randomness. The paper argues this reduces unilateral proposer discretion for front-running, sandwiching, and censorship against admitted transactions under explicit cryptographic and economic assumptions, without requiring threshold decryption committees. (<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.arxiv.org/pdf/2604.07568">arXiv</a>)</p><div data-type="subscribeButton" class="center-contents"><a class="email-subscribe-button" href="https://paragraph.com/@w3sb/subscribe">Subscribe</a></div><br>]]></content:encoded>
            <author>w3sb@newsletter.paragraph.com (Woodrow Brown)</author>
            <category>web3</category>
            <category>security</category>
            <category>cybersecurity</category>
            <category>hacks</category>
            <category>exploits</category>
            <category>regulations</category>
        </item>
    </channel>
</rss>