We have just published our audit report of
@quipnetwork 's smart contracts and Ethereum SDK. Read all about our findings and recommendations in the report:
github.com/oak-security/audi…
We have just published our audit report of
@Valdora_finance 's @CosmWasm StZIG smart contract updates for the ZIGChain v5 migration. Read all about our findings and recommendations in the report:
github.com/oak-security/audi…
ZisK v1.3.0-alpha release 🚀
ZisK is moving beyond arithmetic hashes with BLAKE3 strengthening security while outperforming our prior Poseidon1 version:
⚡ 7.43s p999 on 4×5090
⚡ 5.14s p999 on 8×5090
🛡️ 128-bit provable security
🔐 Post-quantum secure
This is a major step toward faster and safer proving.
Release notes: github.com/0xPolygonHermez/z…
We have just published our audit report of
@CoinList 's Ethereum smart contracts to support token sale and swap operations. Read all about our findings and recommendations in the report:
github.com/oak-security/audi…
New @cyphertalkmedia episode: our co-founder @beyer_st sits down with @0xriptide of @therealgregoAI.
Chaining vulnerabilities with AI, the $27.7M exploit it caught, and what's left for the human auditor.
🎙️ New episode: @0xriptide, bug bounty hunter turned co-founder and CEO of Grego AI.
He built AI that chains vulnerabilities humans would almost never reach, found a high-severity bug in Lido, and prevented a $27.7M exploit.
🎧 podbean.com/ep/pb-e9u3w-1b5f…
One bug in Polygon's staking bridge meant a single compromised validator could forge consensus events on a bridge securing over $2 billion in staked assets.
A secret needs a lifecycle, not just a vault.
Inventory. Ownership. Storage. Distribution. Rotation. Detection. Revocation.
Use Oak’s Secrets Management Guide to review one production credential:
academy.oaksecurity.io/resou…
ALT Oak Security landscape graphic showing one production credential moving through ownership, storage, distribution, rotation, detection, revocation, and replacement.
Which workloads stop? Which replacement is issued? How is it distributed? What evidence is preserved? How do you prove the old credential is no longer accepted?
If the response depends on finding the right person and reconstructing the process during the incident, the capability is not ready.
Rotation and revocation need owners, tests, and rehearsal.
New @cyphertalkmedia episode: our co-founder @beyer_st sits down with Lorenzo Sicilia (@aboutlo), Head of Technology from @ArbitrumDevs.
The economics of the Audit Program, the cost-per-line benchmark, Stylus security trade-offs, and AI's red-team advantage.
🎙️ New episode: Lorenzo Sicilia (@aboutlo), Head of Technology at the @arbitrum and part of @ArbitrumDevs.
He talks about: The Audit Program, Stylus and the "safe language is a mental trap," and the ZK-on-BoLD upgrade.
🎧 podbean.com/ep/pb-idsj6-1b47…
A secret is not managed merely because it is stored in a vault.
Management also requires ownership, inventory, controlled distribution, rotation, exposure detection, revocation, replacement, and an understanding of what breaks when access changes.
The frontend is a delivery chain: registrar, DNS, source and dependencies, CI/CD, hosting and edge, monitoring and rollback.
Assign an owner and recovery path to every control point.
Oak’s complete guide:
academy.oaksecurity.io/resou…
ALT Oak Security landscape graphic showing six connected frontend delivery control points and a separate monitoring and rollback loop.
Now ask:
Which independent signal detects the change?
Who can stop delivery?
Who can restore a known-good build?
How quickly can users be warned?
Integrity without detection and recovery is incomplete.
The correct URL can still serve the wrong code.
TLS protects a connection. It does not prove that the registrar, DNS, build workflow, dependencies, hosting, edge, and rollback path are under the right control.
The frontend is part of protocol security.
@syrupsid told me how he managed to grow @maplefinance after calling out “DeFi is Dead”.
What is dead?
According to Sid. It is the 2021 version of DeFi: wallet connections, token incentives, users manually combining protocols, and layers of smart-contract risk.
Listen in!
Who can actually ship to production?
Map the path through source control, workflows, runners, identities, environments, approvals, and deployment destinations.
Oak’s practical CI/CD hardening guide:
academy.oaksecurity.io/resou…
ALT Oak Security landscape graphic mapping a privileged delivery path from source control through workflows, runners, identity, approval, and production.