Independent Risk Infrastructure for Digital Assets (Super)Powered by @Hackenclub blockchain security expertise

Pinned Tweet
83 projects got exploited in Q2 2026. $755M gone because nobody could see risk in advance. Every one of those exploits was foreseeable: a missing control (key management, least-privilege, incident prevention) plus a market trusting the wrong evidence. Like a high-tier partner; a healthy TVL; an active timeline. People bought, deposited, allocated, and then got rekt. Not blaming them. All those signals describe a project's health. They tell you nothing about the risks that enable the exploit. And here's what changed: capital is no longer run by people; now, agents can route it too. Neither you nor a model can read every postmortem before allocating. So the market needs one number instead. That's the Probability of Loss: a 0-100 score computed from public data alone, built by reading historical failure patterns, a project's live parameters, and its likely attack paths. It just makes risk readable before you face the loss, not after. We released the CORE3 litepaper today: the what, the why, the how. Read it: core3.io/Litepaper_CORE3_Pro…
16
7
40
1,538
The cybersecurity component of @coingecko's Trust Score now uses CORE3 data for 166 centralized exchanges. The migration from CER.live to CORE3, @hackenclub's risk infrastructure layer, preserves continuity in a signal CoinGecko users already rely on. The exchanges' security scores are expected to move no more than 2%. CoinGecko continues to display penetration testing, bug bounty, and Proof of Reserves indicators. CORE3 has evolved internally from a standalone security evaluation into a broader risk intelligence framework covering Security, Solvency, and Transparency dimensions. Together, these indicators contribute to the Probability of Loss, which estimates the likelihood of an adverse event arising from a security breach, insolvency, or operational failure. This places cybersecurity evidence alongside solvency and disclosure data, supporting more consistent exchange due diligence and counterparty exposure decisions. See what changed: core3.io/blog/core-3-news/co…
1
15
277
Did 0% audit coverage contribute to the exploit of @harmonyprotocol? Harmony just had ~4B $ONE created from a consensus-layer exploit, ~26% of the circulating supply CORE3 Probability of Loss for Harmony is at 52/99 with low Security and Operational subscores What happened⬇️ This is Harmony’s third protocol-level security failure in four years and its second unauthorized-issuance event. Different exploit path, same risk domain: supply integrity. Current analysis points to two verification failures: cross-shard receipts could be replayed to credit a destination without debiting the source, while a pre-staking quorum check could be satisfied without a valid signer set. The result was phantom supply created at the protocol layer. Around 2.8B $ONE was routed toward centralized exchanges before containment. There was no automated minting circuit breaker, so stopping the exploit required validators to manually upgrade. For institutional review, the key diligence shift is straightforward: audit coverage must extend beyond smart contracts into consensus and client-level logic, because that is where this exploit occurred. Supply integrity also cannot rely solely on native chain reporting; it requires independent verification of issuance and state transitions. Finally, there must be enforceable, automated controls that can halt abnormal minting or issuance in real time, not just post-incident response. Probability of Loss (PoL) is the current risk read. Incidents like this are why that read has to move with the project, its controls, and the evidence behind them. Review Harmony’s risk profile on CORE3⬇️ bit.ly/pol_harmony
3
1
11
606
CORE3 supplied the security posture data on 1,427 Web3 digital asset issuers for Hacken's Q2 2026 report. And that’s the start of the bigger story for CORE3, for you, and for Web3. Starting this quarter, risk infrastructure becomes backed by the weight of @hackenclub's ecosystem with its 9-year track record of blockchain security & compliance. What doesn't change is Probability of Loss. Methodology remains publicly unchanged, independent, and replicable. The team behind previously CORE3 built CER.live, the cybersecurity score provider for @coingecko's CEX Trust Score, so we know what it takes to change the digital asset industry once more with actionable risk data. Measure risk, for the public good.
3
11
213
Recently, @kucoincom turned 9, and the CORE3 team attended the celebration at @tomorrowland. During the event, we heard and started countless conversations, including with the KuCoin team, on what today matters in the digital assets market: risk management, openness, self-assessment, and accountability. Symbolically, KuCoin’s Probability of Loss on CORE3 shows “99” for security, contributing to an overall PoL of 5.42. This places the exchange #1 ranked by the lowest risk exposure on our platform. A few moments from the celebration below. CORE3. Risk, measured in public.
2
1
15
248
An agent can be fully audited yet still allocate capital recklessly or manage risk effectively while remaining dependent on a single, fragile oracle. CORE3 contributed its evidence-based risk methodology and independently assessed agents to @owneydotapp alongside @CODESPECT, and @hackenclub to build the first Trust and Security framework for Agentic DeFi Yield across Security, Risk, and Robustness to make failure paths measurable 🔽
We are excited to share that we've just released our Trust and Security framework for Agentic DeFi, developed together with CODESPECT, CORE3, and Hacken. Check out the agent scores on risk.owney.app/ and read the full article here!
Article

It’s Time to Set the Trust and Security Standards for Agentic DeFi Yield

Authors: Wiebe Hendriks, Maciej P, Ondřej Tatýrek and Aimann Faiz A collaboration of Owney, CODESPECT, CORE3 and Hacken, Blockchain Security & Compliance with DeFi yield agent assesments of Zyfai,

1
2
15
621
44 out of 67 incidents in Q2 were smart contract exploits. So how do you know you won’t get hit next? CORE3’s security domain is built heavily around onchain security. Even a simple thing like smart contract audit is reviewed rigorously, giving you more information about it: scope, deployed versus audited code, unresolved findings, remediation, severity, and auditor tier. This separates a narrow contract review from coverage of the infrastructure that actually moves funds. Audit covers only one part of the whole security checklist, the remaining test the post-deployment controls: Bug bounty - a funded vulnerability disclosure path. Third-party monitoring - detection of abnormal calls, upgrades, or outflows. Prevention - timelocks, pauses, and circuit breakers that can contain loss. For institutions, the result is not an audit badge. It is a control map for pre-allocation screening, counterparty limits, and ongoing review. When evidence or controls change, the security read changes accordingly. Review the methodology on CORE3.io
4
2
5
957
The PoL score stayed; the data behind it got stronger. Funding through @Giveth helped us improve how risk is collected, reviewed, calculated, and delivered across CORE3. More human context Over 1,500 @Proof_Of_Voice reports now appear beneath project scores, providing readers with expert context alongside the underlying risk data. The reports can now be submitted through the website or Telegram Mini-App, making contributions easier and expanding project coverage every day. Cleaner project data Duplicate and empty bug bounty entries were removed. Audit records were standardized. Detector-collected evidence now fills key fields across token supply, contract verification, team transparency, KYC, regulation, insurance, and security certifications. Better comparisons Projects are now ranked both across CORE3 and within their own category, so protocols are compared against relevant peers. Exchange data covering penetration tests, bug bounties, and proof of reserves was also corrected and expanded. Stronger scoring infrastructure We improved the Probability of Loss engine, scoring logic, detector persistence, and data pipelines to ensure risk profiles are consistent and up to date. CORE3 for the agents Our public MCP server is already in production, allowing AI assistants to query CORE3 risk data directly. Thanks to @Giveth, @TheDAOfund, @wintermute_t, @Quantstamp, @CredShields, and the community donors who helped fund the work.
1
3
17
430
CORE3 data supports the Q2 report’s protocol-risk section While Public markets expect compliance-grade controls, Web3 industry answers with: • 55% - an active bug bounty • 26% - security audit on record • 9% - third party monitoring • 4% - all 3 at once Full report⬇️
Our Q2 2026 Security & Compliance Report has been released ⬇️ $763.9M was stolen across 67 incidents, the worst since Q2 2025. 88% of the losses came down to operations. Smart contracts were still the most common failure point, 44/67 incidents, but they accounted for just 11% of the funds lost. All of this happens as MiCA comes into force, where only about 20% of registered firms secured authorization, roughly 210 of the more than 1,200 that once declared intent. This quarter's report is built around one idea, the Architecture of Trust: how security, compliance, and risk intelligence together influence which teams institutions are willing to work with. Inside, we cover: ▫️MiCA/DORA and the GENIUS Act ▫️Stablecoin regulations ▫️AI regulation across the EU and US ▫️How allocators run due diligence ▫️What comes next in Q3 2026 As digital assets become more exposed to public markets, institutional capital increasingly follows issuers that can consistently demonstrate they remain safe and sound. Built with input from @chainlink, @moodysratings, @Bybit_Official, @SuiNetwork, @StellarOrg, @1MoneyNetwork, Abraxas Capital, @AlliumLabs, @svrn_ai, @EisnerAmper, DA Insured, @howdenlocaluk – alongside Hacken. Get your copy of the report: hackenio.cc/q2-2026-security…
1
9
314
A project that looked acceptable last quarter can become a material counterparty risk today. For institutions, the relevant signal is how the score changes after capital is deployed. Risk rarely stays static. New dependencies appear, audits become outdated, admin controls change, incidents expose weak controls, and unresolved findings accumulate. That's why Probability of Loss dynamics matter. A rising risk score should trigger a review: what changed, which control weakened, and whether the amount of capital you have allocated to that project remains appropriate given the higher risk. PoL score that continuously lowers means that risks have been addressed and mitigated. This also highlights that the project is focused on improving security and building trust. The current Probability of Loss reflects the current risk level. Its trajectory shows how that risk is changing over time, after launch, after the growth phase, and through periods of stress. Track counterparty risk dynamics on CORE3.io
2
4
18
226
Project’s transparency is becoming a fundraising asset. Funds are tired of underwriting risk from screenshots, claims, and scattered docs. If a project can’t show what controls exist, capital treats the missing evidence as risk ⬇️
9
3
21
251
The fundraising advantage is simple. A project that can prove its controls gives investors something to underwrite. A project that only says “trust us” forces investors to price uncertainty or just walk away.
2
1
4
64
As the next cycles emerge, transparency around risk will play a key role in how capital is allocated. Projects that disclose, verify, and improve their risk profile will be easier to assess. Track Probability of Loss scores on CORE3.io
1
3
60
Crypto wants your money but refuses to make risk easy to understand This will not work in the next adoption cycle, where users, funds, and partners expect clear, comparable risk before committing capital. A new approach is needed, one that makes loss exposure visible before any capital commitment. Probability of Loss (PoL) turns security, operations, finances, reputation, regulation, and dependencies into one readable risk score, with @Proof_Of_Voice as the human expert layer adding context behind the scores. Stop guessing and start measuring risk before you commit capital. Explore Probability of Loss on CORE3.io
12
5
27
474
"Audited" is one of the most misleading words in crypto CORE3 asks a better question: did the audit cover the contracts where funds, permissions, or user balances move? The results are not encouraging. 377 audited projects out of 1,427. 99.3% sit below 80% coverage.
4
5
22
395
What an audit covers determines whether the label reflects real risk or only a small part of the system. If the audit covered the token contract but funds move through an unaudited bridge, vault, admin module, or a legacy contract, the real loss path may lie outside the report.
1
2
11
128
Without this context, “audited” can create a false sense of security rather than real assurance. Check your favorite project’s audit coverage on CORE3 and tell us what you found: core3.io
2
7
103