Book. Secure. Relax. Oak Security offers audits, penetration testing, training, and advisory.

👀
ZisK v1.3.0-alpha release 🚀 ZisK is moving beyond arithmetic hashes with BLAKE3 strengthening security while outperforming our prior Poseidon1 version: ⚡ 7.43s p999 on 4×5090 ⚡ 5.14s p999 on 8×5090 🛡️ 128-bit provable security 🔐 Post-quantum secure This is a major step toward faster and safer proving. Release notes: github.com/0xPolygonHermez/z…
2
279
We have just published our audit report of @CoinList 's Ethereum smart contracts to support token sale and swap operations. Read all about our findings and recommendations in the report: github.com/oak-security/audi…
1
1
14
1,661
New @cyphertalkmedia episode: our co-founder @beyer_st sits down with @0xriptide of @therealgregoAI. Chaining vulnerabilities with AI, the $27.7M exploit it caught, and what's left for the human auditor.
🎙️ New episode: @0xriptide, bug bounty hunter turned co-founder and CEO of Grego AI. He built AI that chains vulnerabilities humans would almost never reach, found a high-severity bug in Lido, and prevented a $27.7M exploit. 🎧 podbean.com/ep/pb-e9u3w-1b5f…
1
11
1,905
Oak Security retweeted
One bug in Polygon's staking bridge meant a single compromised validator could forge consensus events on a bridge securing over $2 billion in staked assets.
1
1
1
143
A secret needs a lifecycle, not just a vault. Inventory. Ownership. Storage. Distribution. Rotation. Detection. Revocation. Use Oak’s Secrets Management Guide to review one production credential: academy.oaksecurity.io/resou…
Made with AI
150
We are encouraging our security researchers to pursue bug bounties, and they are doing just fine! Congrats @bernd_eth !
1
15
1,785
A production credential leaked five minutes ago. Who can revoke it—and what happens next? 🧵
1
1
373
Which workloads stop? Which replacement is issued? How is it distributed? What evidence is preserved? How do you prove the old credential is no longer accepted?
1
99
If the response depends on finding the right person and reconstructing the process during the incident, the capability is not ready. Rotation and revocation need owners, tests, and rehearsal.
1
57
New @cyphertalkmedia episode: our co-founder @beyer_st sits down with Lorenzo Sicilia (@aboutlo), Head of Technology from @ArbitrumDevs. The economics of the Audit Program, the cost-per-line benchmark, Stylus security trade-offs, and AI's red-team advantage.
🎙️ New episode: Lorenzo Sicilia (@aboutlo), Head of Technology at the @arbitrum and part of @ArbitrumDevs. He talks about: The Audit Program, Stylus and the "safe language is a mental trap," and the ZK-on-BoLD upgrade. 🎧 podbean.com/ep/pb-idsj6-1b47…
1
238
A secret is not managed merely because it is stored in a vault. Management also requires ownership, inventory, controlled distribution, rotation, exposure detection, revocation, replacement, and an understanding of what breaks when access changes.
4
540
The frontend is a delivery chain: registrar, DNS, source and dependencies, CI/CD, hosting and edge, monitoring and rollback. Assign an owner and recovery path to every control point. Oak’s complete guide: academy.oaksecurity.io/resou…
Made with AI
3
3
242
Assume an attacker controls one frontend build workflow. What can they change before anyone notices? 🧵
1
3
325
Could they replace an address, alter transaction parameters, inject a dependency, change what the wallet displays, or redirect users entirely?
1
142
Now ask: Which independent signal detects the change? Who can stop delivery? Who can restore a known-good build? How quickly can users be warned? Integrity without detection and recovery is incomplete.
58
The correct URL can still serve the wrong code. TLS protects a connection. It does not prove that the registrar, DNS, build workflow, dependencies, hosting, edge, and rollback path are under the right control. The frontend is part of protocol security.
348
Is DeFi dead? @syrupsid @maplefinance doesn't think so. We will see a paradigm shift.
Replying to @syrupsid
@syrupsid told me how he managed to grow @maplefinance after calling out “DeFi is Dead”. What is dead? According to Sid. It is the 2021 version of DeFi: wallet connections, token incentives, users manually combining protocols, and layers of smart-contract risk. Listen in!
1
1
271
Who can actually ship to production? Map the path through source control, workflows, runners, identities, environments, approvals, and deployment destinations. Oak’s practical CI/CD hardening guide: academy.oaksecurity.io/resou…
Made with AI
142