Digital Assets Security Posture Management for enterprises. The security function audits can't replace. Built by enterprise security veterans.

Madrid (Spain)
As institutions move onchain, the threat has shifted from code to operations. Over 75% of H1 losses (~$972M) came from operational and config gaps, not code. > Audits secure the code, at a point in time > Regulation secures reserves and custody > Defensive AI is catching up, but aimed at code Each is critical but together they leave one layer open, the operational state. State of Digital Asset Security, H1 2026 (link in comments)👇
4
1
7
418
We are at @token2049 Singapore🇸🇬 this week! As digital asset operations scale, security, risk and compliance teams need to know their controls aren't only defined but continuously effective, from code to chain. That's exactly what we focus on at Dedge. If you're around, we'd love to meet. Reach out to @0x0kyoshi directly to grab a coffee.
1
1
24
Bitget lost ~$351.6M in September and says no private keys were stolen. Per its CEO, a compromised backend spoofed the transfers and the wallets signed. Bybit lost about $1.5B in 2025 through a similar weakness. Both times the keys were safe. The risk sat in what wallets could sign 👇
1
2
3
47
Dedge has joined Japan's Digital Asset Co-Creation Consortium (DCC), led by @progmat_en The DCC is building production-grade infrastructure for onchain assets, from tokenized JGBs to repo and 24/7 settlement. As tokenization scales, so does what has to be secured. Japan is evolving, so are we.
1
2
3
124
Proud to join the @circle Alliance Program as a certified member! The digital dollar is scaling into institutional infrastructure and security posture has to scale with it. In 2026, much of what's lost onchain doesn't come from broken code, it comes from what changes after the audit. That's the gap we've signed up for 🫡
4
6
22
1,599
As institutions move onchain, the threat has shifted from code to operations. Over 75% of H1 losses (~$972M) came from operational and config gaps, not code. > Audits secure the code, at a point in time > Regulation secures reserves and custody > Defensive AI is catching up, but aimed at code Each is critical but together they leave one layer open, the operational state. State of Digital Asset Security, H1 2026 (link in comments)👇
4
1
7
418
Dedge Security is now ISO/IEC 27001 certified🙌 More than a badge. It's proof we operate with the governance and risk management institutions require from a security partner. Another step toward helping organizations adopt digital assets securely.
1
2
6
116
Dedge Security retweeted
Join @DedgeSecurity as we confront the dangerous gap between point-in-time audits and continuous real-world threats. Get practical insights on building true continuous security posture — real-time visibility and resilience before incidents hit. What you’ll take away: ✅ Where static audits fall short ✅ Common blind spots hitting APAC platforms ✅ A proven path to continuous monitoring from real deployments
1
1
2
136
AI makes code scanning cheaper and faster, but it does not replace security judgment, and in digital assets, the most expensive failures have never been code bugs in the first place. Ronin, Bybit, Drift: compromised keys, manipulated signers, governance issues. The smart contracts executed correctly. AI agents are only as useful as the threat model of the team behind them. Teams that deploy AI tooling without that expertise are not buying security, but rather the appearance of it, which is worse. During a full repository scan of Taiko, the Dedge platform surfaced an exposed private key in a public pull request. That finding did not come from a code vulnerability scanner, but rather a system built to understand operational exposure across the full development surface.
I heard recently that AI has already replaced Auditors. Someone said: "There's no need to hire a web3 firm for smart contract audits, I think it's overkill, and AI does just as good a job nowadays." My way of explaining why that's not the case was like this: "Look at it also as, we all always had Google and Stack Overflow to search and solve our coding issues, but it made a difference who used them and how. So, AI is powerful, yet it makes a difference how it’s used in what context and who is using it." From my experience, it makes a huge difference for both development and auditing whether the person using AI is proficient.
5
171
Dedge surfaces the preconditions of attacks like Taiko, before they become $1.7M incidents. W3SPM monitors the full attack surface, including repositories, secrets, on-chain contract logic, and runtime posture. The Taiko exploit required a failure mode that W3SPM would catch: A committed private key (DWE-SECRET-001). This didn't require the attacker to do anything sophisticated.
⚠️ Security Notice 1/2: We have confirmed a compromise of Taiko’s chain state verification mechanism. As a result, the security assumptions of all bridges deployed on Taiko can no longer be relied upon. We are actively coordinating with the Security Council and ecosystem partners to contain the incident, pause affected systems where possible, and take all necessary technical and legal actions. We strongly advise all users to withdraw their funds from all bridges deployed on Taiko immediately. Further updates will be provided as more information becomes available.
1
3
209
The blockchain recorded every loss. The industry never agreed on how to read the receipts. In 2025, four of the most-cited security firms published their annual loss figures: • @chainalysis: $3.4B • @CertiK: $3.35B • @peckshield: $4.04B • @SlowMist_Team: $2.78B Gap between highest and lowest: $1.26 billion. Each firm made defensible choices about what to include: • Scams vs. exploits. • Gross vs. net of recoveries. • Protocol-level vs. wallet-level incidents. Four legitimate answers to four slightly different questions, all published as the answer to one. The digital assets security industry built sophisticated threat detection infrastructure. It never built the risk accounting layer underneath it. DORA is in force. MiCA is live. The GENIUS Act is moving. Every one of these requires a consistent, auditable loss classification framework. The industry can build that standard, or inherit one written by regulators who don't understand on-chain mechanics. Full analysis 👇
1
1
4
170
The security model most Web3 projects run on is structurally wrong. Pre-deployment audit. Ship. Forget. But 2025 told a different story: the majority of losses by value came not from code vulnerabilities but from what happened after deployment, key compromise, governance manipulation, etc. You can pass every audit and still lose everything to a misconfigured signing authority or a zero-timelock governance change nobody caught in time. This is the gap @DedgeSecurity was built to close by continuous security posture across the full lifecycle, from code commit to on-chain state. On Canton Network, where institutional capital, tokenized assets, and interoperable settlement are operating at real scale, that gap isn't academic, but rather a systemic risk. The infrastructure carrying institutional-grade assets needs institutional-grade posture management. Not periodic reviews. Continuous coverage.
Did you know that @DedgeSecurity is the only Security Posture Management (SPM) platform built natively for digital asset infrastructure, continuous security from code commit to on-chain deployment. As a Member of Canton Foundation, Dedge secures the infrastructure layer that institutions and builders on the Global Synchronizer depend on. What they bring to Canton: → Autonomous smart contract security analysis with real-time findings mapped across the full deployment lifecycle → Continuous risk detection embedded directly into institutional build and deployment workflows → Full-stack posture coverage across tokenized asset infrastructure — contracts, nodes, wallets, and signing authority → Audit-ready evidence for regulated institutions operating on-chain Canton is where institutional tokenized assets, collateral mobility, and interoperable settlement come together. Dedge ensures the security posture behind that infrastructure meets the same standard.
4
93
Dedge Security retweeted
Did you know that @DedgeSecurity is the only Security Posture Management (SPM) platform built natively for digital asset infrastructure, continuous security from code commit to on-chain deployment. As a Member of Canton Foundation, Dedge secures the infrastructure layer that institutions and builders on the Global Synchronizer depend on. What they bring to Canton: → Autonomous smart contract security analysis with real-time findings mapped across the full deployment lifecycle → Continuous risk detection embedded directly into institutional build and deployment workflows → Full-stack posture coverage across tokenized asset infrastructure — contracts, nodes, wallets, and signing authority → Audit-ready evidence for regulated institutions operating on-chain Canton is where institutional tokenized assets, collateral mobility, and interoperable settlement come together. Dedge ensures the security posture behind that infrastructure meets the same standard.
4
8
36
1,307
Digital Assets security has matured beyond "secure at launch" thinking. A point-in-time audit is a hypothesis, not a guarantee. The real attack surface evolves daily with governance actions, upgrades, integrations, and human decisions. Security as a continuous, observable property of the entire system, from code, on-chain state, permissions, and external dependencies, rather than a one-time certification. Most of these incidents weren't novel zero-days in audited code. Happy to share how Dedge platform gives teams real-time visibility and automated risk detection.
Here’s a list of all crypto protocols hacked this year. It’s only May. Stake DAO WUSD fi/Glov Gnosis Users Fractal Protocol StablR Mure Polymarket MAP Protocol RetoSwap HermesVault Bankr Echo Bridge SEA Token Verus-Ethereum Bridge Adshares Thorchain DEX Transit Finance Aurellion SQ Protocol INK Finance Renegade TrustedVolumes Ekubo SmartCredit Sharwa Finance Bisq Wasabi Perps Aftermath Perps Sweat Foundation Syndicate Quant JUDAO Singularity Finance ZetaChain Scallop Lend Litecoin Purrlend Giddy Kipseli Volo Vault Thetanuts Finance Juicebox V3 Kelp Grinex Rhea Lend Zerion Wallet MONA Dango SubQuery Network Hyperbridge Aethir BSC TMM/USDT Drift Trade LML/USDT staking protocol GoonFi Cyrus Finance Resolv Neutrl dTRINITY dLEND Venus Core Pool Goose Finance Aave V3 Gondi V3 Molt EVM SolvBTC Curve LlamaLend FOOM Cash Wise Lending V2 Ploutos Money DGLD Blend Pools V2 IoTeX Veil Cash Moonwell Lending CrossCurve Step Finance Revert Lend Matcha Aperture LM Saga Makina Meteora DAMM V2 YO Protocol Truebit Polycule Fusion by IPOR TMX TRIBE PRXVT
1
5
292
Every major post-mortem since 2023 contains a version of this sentence: "The vulnerability was introduced after the audit was completed." The snapshot is necessary, but never sufficient. An audit tells you what the code looked like on one specific day. It tells you nothing about what your multisig configuration looks like today.
A clean audit report is a snapshot, not a shield. It describes the code on the day we looked at it. The code you deploy three commits later, with the "small fix" nobody re-reviewed, is the code that gets drained. Freeze scope before you ship.
3
166
and and and... with evm + svm contracts routing through canton natively, the attack surface just got crosschain, cross-app, and institutional-grade complex @DedgeSecurity sits at that intersection. web3-native security posture management (SPM) built for exactly this composability layer @ZenithFdn is building the bridge. we secure what crosses it. ; )
For developers coming from EVM or Solana, @ZenithFdn is the entry point to Canton. Deploy unmodified Solidity with Hardhat and MetaMask. Your contracts route natively through the Canton protocol and can atomically compose with Daml-native Canton apps. Canton’s EVM and SVM execution layer means you don’t need to learn a new language to get started. Bring your existing codebase and tooling. From there, your apps can tap into Canton’s privacy-preserving architecture, atomic cross-app settlement, and the full CIP-56 token ecosystem.
1
1
6
522
Matcha for Monday morning posture review. Some of us don't wait for the weekend.
The weekend is about to begin. Saturday morning cappuccino for Saturday morning bug hunting.
2
4
192
The PDF problem is real. But even a perfect audit only tells you what the code looked like on one specific day. Parameters drift. Keys change hands. Governance proposals queue silently. Dependencies get exploited upstream. None of that shows up in the report. All of it determines whether you get hit. H1 2026: smart contract flaws were the most common attack class and produced 11% of total losses. Key compromise and bridge exploits were less frequent and produced 85%. Audits address the 11%. They have no visibility into the 85%. The question after the audit isn't "was this thorough enough." It's "what's monitoring everything the audit couldn't see."
Imagine spending $20K on an audit, the auditor slaps a report on your desk and calls it a day. You’re left wondering if your code is safer or if you just bought a very expensive PDF. Teams deserve better than this.
2
1
4
266