Get Secured

INSIGHTS

Security4Web3
Blog.

Expert analysis of the latest vulnerabilities, security news, threat intelligence, and the evolving attack surface.

May 2026 Regulatory Compliance

DASP Compliance: What El Salvador's CNAD Requires From Digital Asset Service Providers

El Salvador's CNAD has materially strengthened its supervisory posture. Applications that passed in 2023 would be returned today. Here is what the DASP licence requires across entity structure, AML/CFT, cybersecurity documentation, and ongoing obligations, and where most applicants fall short.

Read More →
May 2026 Regulatory Compliance

MiCA Compliance: What Crypto-Asset Service Providers Must Demonstrate to Operate in the EU

MiCA has been fully applicable since December 2024. The grandfathering period ended July 2026. Firms without authorisation are now in breach. Here is what CASP authorisation requires, what the cybersecurity obligations are under MiCA and DORA, and where most applications fall short.

Read More →
May 2026 Regulatory Compliance

DORA Compliance Requirements: What Financial Entities and Crypto-Asset Service Providers Must Demonstrate

DORA has been in force since January 2025, applying to over 22,000 financial entities, including crypto-asset service providers. Here is what the five pillars require, who must comply, what the penalties are, and where most organisations fall short on documented evidence.

Read More →
May 2026 Regulatory Compliance

VARA Compliance: What the Updated Rulebooks Require From Dubai VASPs

VARA issued substantive rulebook updates in June 2025. Threat-led penetration testing is now mandatory. AML/CFT risk assessments are quarterly. The FATF Travel Rule is a hard requirement. Here is what VASPs must demonstrate, and where most programmes fall short.

Read More →
24 May 2026 Stablecoin Exploit

StablR EURR/USDR Exploit: Early Analysis of Reported Unauthorised Minting

Reports indicate a multisig owner key was compromised, owners replaced, and EURR/USDR minted on Ethereum. Nominal mint ~$10.4M, realised loss reported at $2.8M+. Root cause pending official confirmation.

Read More →
22 May 2026 Incident Response

Polymarket UMA CTF Adapter Incident on Polygon: Early Analysis

Polymarket investigated a Polygon incident affecting its UMA CTF Adapter admin wallet. Early reporting points to an internal operations private key compromise, with ~5,000 POL outflows every ~30 seconds and losses reported between ~$520K and ~$700K.

Read More →
Smart Contract Vulnerabilities
April 2025 Smart Contracts

Top 5 Smart Contract Vulnerabilities in 2025

Discover the most common smart contract vulnerabilities in 2025, from reentrancy to oracle manipulation. Learn how teams can mitigate risks and harden their smart contract security posture with proven practices.

Read More →
Web3 Threat Actors
February 2025 Threat Intelligence

Rug Pulls, MEV Bots & Darknet Threat Actors

Web3’s permissionless nature enables innovation, but also opens the door to complex security threats. We explore how on-chain forensics and investigation techniques trace rug pulls, MEV exploits, and actors lurking on the darknet.

Read More →
Bybit Hack
February 2025 Case Study

Inside the Bybit Hack: What Really Happened in Crypto’s Largest Heist

How North Korea’s Lazarus Group pulled off the $1.5B Bybit attack, and what it means for the future of Web3 security.

Read More →
18 April 2026 Bridge Security

KelpDAO rsETH Bridge Exploit: When “Verification” Becomes a 1-of-1 Trust Decision

On April 18, 2026, a forged LayerZero packet released 116,500 rsETH from Kelp’s Ethereum adapter, no corresponding burn on the source chain. Postmortem vs on-chain evidence.

Read More →
18 April 2026 Incident Report

LayerZero KelpDAO Postmortem: RPC Poisoning, DVN Failover, and the $292M rsETH Exploit

LayerZero Labs’ official report reveals the attack started on March 6 with social engineering and session-key harvesting, eventually producing a forged attestation that drained $292M.

Read More →
7 May 2026 DeFi Exploit

TrustedVolumes Exploit: RFQ Authorisation Mismatch Drained ~$5.87M

The contract checked permissions against one address, then debited funds from a different one, bypassing the entire RFQ trust model in a single transaction on Ethereum.

Read More →
May 2026 Bridge Security

MAP Protocol / Butter Bridge Exploit: Early Analysis of the ~1 Quadrillion MAPO Mint

Butter Bridge v3.1 appears to have been exploited via a message retry validation flaw, enabling an attacker to mint ~1 quadrillion MAPO and extract liquidity. Early analysis, root cause pending.

Read More →
15 May 2026 DeFi Exploit

THORChain Exploit: Early Analysis of the $11M+ Multi-Chain Drain

On May 15, 2026, THORChain suffered a multi-chain exploit across at least nine chains, with TRM Labs reporting $11M+ drained. Breaking analysis, official postmortem still pending.

Read More →
18 May 2026 Bridge Security

Verus Ethereum Bridge Exploit: Early Analysis of the $11.58M Drain

Reports cite 103.6 tBTC, 1,625 ETH, and ~147,000 USDC drained after the bridge accepted a forged import payload without validating equivalent source-side value.

Read More →
18 May 2026 DeFi Exploit

Echo Protocol eBTC Exploit: How an Admin Key Compromise Turned into an $816K Loss

An attacker minted 1,000 unbacked eBTC on Monad after gaining privileged access, nominal value $76.7M, realized loss ~$816K. Liquidity depth was the only thing limiting the damage.

Read More →