29 Jun 2026, 15:50 UTC536 views4 reactionsread 7 August 2026 Quick one for the builders here. Polymarket lost ~$3M last week and it wasn't their contracts or servers.. a third-party script on their frontend got compromised and changed what users were signing. Same story as Badger, Ledger Connect Kit, Balancer, the npm drainers.
You can't fully control everything on your own domain, so it has to be monitored. That's what we've been building VANTAGE for, now in alpha with beta …
👌1👏1🤡1😁1
26 May 2026, 18:29 UTC943 views6 reactionsread 7 August 2026 hey folks, been getting quite a few messages around this so put it all together --> web3sec roadmap + AI-era path for anyone getting into this. drop improvements via PR if any, tried to make it short, clear and actionable.
https://x.com/__Raiders/status/2059294222600294845
❤2👏2👎1🔥1
14 May 2026, 06:33 UTC≈1,010 views3 reactionsread 7 August 2026 Hey everyone! Just a quick reminder that today is the last day to support our Ethereum security quadratic funding on Giveth.
If you can spare a $ in donation, it will be matched, which means we'll be able to continue doing awesome research and developing tools for the crypto community.
Web3sec news:
https://qf.giveth.io/project/web3secnews:-security-intelligence-newsletter
Digibastion:
https://qf.giveth.io/project…
👍1👏1🔥1
26 Apr 2026, 16:45 UTC≈1,000 views4 reactionsread 7 August 2026 Photo
hey fam, Web3Sec.News and DigiBastion.com both projects made it into the thedaofund Ethereum Security QF Round on Giveth 🎉
500 ETH matching pool, voting open until May 14.
Even $1 from a unique donor makes a real difference.
🔗 web3sec_news: https://qf.giveth.io/project/web3secnews:-security-intelligence-newsletter
🔗 DigiBastion: https://qf.giveth.io/project/digibastion:-dns-opsec-supply-chain-security
Full detai…
👏2⚡1❤1
15 Apr 2026, 18:16 UTC826 views1 reactionsread 7 August 2026 cow.fi got hijacked recently, so did hypurr.fi, and neutrl.fi - all in the same few weeks, all through DNS, none through code.
we saw someone also survive an attempted attack on our own domain. caught it in 30 seconds. here's the full breakdown:
✦ how the attack chain works (registrar → ns swap → valid cert → live phishing)
✦ our field report — what we did in the first 10 mins
✦ 4 attacker TTPs extracted from confi…
❤1
15 Apr 2026, 02:47 UTC566 views6 reactionsread 7 August 2026 Protecting Crypto Domains and Infra: A Guide to Defending Against DNS Hijacking and BGP Attacks
A detailed guide by vladimir
https://x.com/i/status/2044147555618173261
❤2👍2👏2
14 Apr 2026, 17:34 UTC513 views1 reactionsread 7 August 2026 For affected users:
Revoke everything at revoke.cash, focus on CoW Protocol router contracts.
Move funds out of any wallet connected to cow.fi today.
Stay safe.
https://x.com/__Raiders/status/2044106026321096751
👀1
14 Apr 2026, 17:34 UTC421 views1 reactionsread 7 August 2026 🚨 CONFIRMED: cow[.]fi (CoW Swap) is under an ACTIVE supply chain attack.
If you connected your wallet to cow.fi today — REVOKE ALL APPROVALS NOW. → revoke.cash
→ etherscan.io/tokenapprovalchecker
…
🤔1
14 Apr 2026, 02:51 UTC335 viewsread 7 August 2026 honoured to be selected for the ETHSecurity Badge holder
already heads down building at digibastion, dns security, live threat intel, supply chain and phishing tooling, opsec guides... a lot coming together
a lot of work ahead but excited to contribute to the DAO
https://x.com/i/status/2043883600152801651
13 Apr 2026, 17:47 UTC297 views4 reactionsread 7 August 2026 you're NOT even aware of the types of hacks & exploits POSSIBLE through third-party packages, existing code, binaries, SDKs, and projects whose code is NEVER visible - yet broadly TRUSTED and used.
and with vibe coding across AI tools and different LLMs, new attack surfaces are opening up that can lead to FULL infra compromise & data exfiltration.
give it 1-2 years & it'll click for most people.
everything is a ma…
👀1🤔1🤯1🫡1
12 Apr 2026, 16:10 UTC330 views5 reactionsread 7 August 2026 Photo
Been working on something quietly over the past few months.
I built an internal Domain and DNS security intelligence scanner to help teams stay protected from domain hijacking, DNS misconfigurations, registrar issues, and other overlooked risks.
This came from seeing the same thing again and again.
Critical domains getting compromised not because of complex exploits, but because of simple gaps in DNS or registrar s…
🔥2❤1👏1🙏1
10 Apr 2026, 08:03 UTC337 views5 reactionsread 7 August 2026 Photo
Most audit tools pattern match.
guardix maps your architecture first. invariants, assumptions, design decisions. then hunts for violations. Every finding is backed by a verified exploit.
audit runs are versioned. fix, re-audit, see exactly what changed.
1 free solidity audit after signup. If you've been vibe coding contracts, now's a good time to check what you're about to ship.
→ https://guardix.io
❤2👏1💩1🔥1
Showing the 12 most recent of 20 posts we hold for @web3secnews. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.