August 2026 – Tech Update

A public API, and the bugs we found auditing ourselves This month the API that’s been running internally for months went into testing with a real public surface: keys, scopes, signed webhooks, metered billing. Building it forced us to look hard at our own product, and that look turned up a cluster of real security […]
Lessons from reddit.com/r/defi (and r/blockchain)

Shared Library and Rounding Bugs Drain Hundreds of Millions. Hackers Don’t Care About Out of Scope In May and November of 2025, two of the year’s most expensive DeFi exploits had an uncomfortable amount in common. Neither one came down to a novel zero-day buried in core business logic. Both traced back to subtle arithmetic […]
Attack Your Own Protocol Before Someone Else Does

April 2026 was the worst month on record for crypto. Almost none of it was clever. Roughly 600 to 650 million dollars walked out the door in April. The worst month the industry has ever logged. Here is the part that should keep you up at night. It was not math. It was not some […]
The Blockchain Security Crisis (in 2026)

The state of play “In the rapidly evolving world of decentralised finance (DeFi) and web3, where billions of dollars pour through smart contracts and decentralised apps (dApps) daily, security should be the bedrock priority. Yet for an industry espousing transparency and trustless systems, the blockchain space has a glaring vulnerability – outdated, siloed security audits.“ […]
When Does a Smart Contract Audit Actually Expire?

An audit does not fail overnight. It expires quietly. Most Web3 teams treat “Was Audited” as a durable security signal. But a smart contract audit validates a specific version of code, under a specific set of assumptions. And those assumptions rarely stay static. So the real question isn’t whether audits are important. It’s this: When […]
Why Security Needs to Be a Process, Not an Event

The B-52 Stratofortress, a legendary long-range strategic bomber, had a rocky early history with several crashes and incidents. Introduced by Boeing in the 1950s, the B-52 was a complex aircraft for its time, pushing the boundaries of jet-powered heavy bombers. Before the widespread adoption of standardized pre-flight checklists – now a cornerstone of aviation safety […]
Sophisticated Phishing

This write up will look at a flavour of social engineering scam that’s been emerging in the current VC winter. Earlier this week we got connected on Telegram to somebody who claimed to work for https://fenbushi.vc/, a pioneering Asian crypto VC. After some initial discussion in Telegram, we agreed to schedule a call to take […]