CEO @Fidesiumapp | Blockchain Security Partner Smart Contract Security • Manual Audits • Exploit Analysis • Onchain Security Building Autonomous Security Tools

London, England
Pinned Tweet
The audit model is broken and everyone knows it. You once paid $200k. You wait 8 weeks. You get a PDF. Then your protocol evolves and the audit is already stale. That's not security. That's a snapshot. We started @Fidesiumapp because security should be continuous, not ceremonial. Human auditors catch what machines miss. Automated and AI tools catch what humans can't scale to review. Neither alone is enough. The future isn't audit OR automation. It's both, working together.
4
13
621
OMG @Shanemgillis are you feeling attacked?
Japanese scientists removed the extra chromosome that causes Down syndrome for the first time using CRISPR.
1
62
When people hear audit, at least in web3, they think code review. This is a dangerously narrow take on security. An audit is defined as "an independent, official examination of an organization's financial records, systems, or quality standards to check if they are accurate and legal." As many of the latest security incidents illustrate, real losses are moving from code to process attacks. Protocols need to broaden the scope of their security thinking. It should be the customer demanding more depth, a more vigorous look at everywhere they are vulnerable.
1
1
5
70
Well this is just insane. Fortunately it looks like a whitehat has secured the assets.
No idea whats going on here but I just watched this wallet drain 3832 NFTs from 100s of different wallets May be a good idea to revoke all NFT permissions if you have any valuables in your wallet Seems to be funded from a wallet possibly linked to @0xQuit so maybe a whitehat?
2
33
The sophistication of these attacks are getting insane. Today's victim: BITGET. $351.6 million gone from hot and warm wallets this morning. Biggest crypto hack of 2026. Biggest exchange breach since Bybit. CEO Gracy Chen: the private keys were never stolen. Attackers hit a critical backend system in Bitget’s wallet stack, spoofed the transaction data, and walked it through the exchange’s own authorization process. The keys did their job. They signed what the system told them to sign. “Not a private key compromise” is technically true. It is also the least reassuring true sentence in this story. If fake transaction data can enter your authorization pipeline and leave it approved, the key is beside the point. The failure sat upstream: in the layer that decides what gets signed. This is a much more dificult problem than custody. Difficult to audit and build processes to protect against. $351.6M total, hot and warm wallets ~$192M across 15 transfers, 7 assets; ETH the largest slice at 44.4% $464M User Protection Fund covers the loss in full Withdrawals paused. Deposits and trading still live. Chen flagged IPs matching VPN patterns used by a DPRK group. On-chain analyst Specter traced bridged XRP back to AFX Trade exploit funds from July: attributed to TraderTraitor.
1
2
6
172
My London is Thames House, home of Mi5. Because of security, duh. What's yours?
CHOOSE YOUR LONDON Episode 1 'DOOMER'
Made with AI
1
7
153
5 questions to ask before hiring a smart contract auditor: 1. Named senior auditors, or whoever's free / contractor? 2. Findings reported live, or only at the end? 3. Policy if they find a live exploit? 4. Can you see a sample report? 5. What's explicitly NOT in scope? #5 matters most.
1
3
57
The 440% jump in on-chain malware commands isn’t a crypto story. It’s an AI + permanence story. Blockchains became uncensorable C2. Open-weight models remove much of the skill gate. State actors showed up. Defense that only looks at Solidity is now the same as having no security. Ask: Should wallets/RPC/infra vendors treat on-chain payload detection as table stakes?
2
54
I am also not speaking Solana Breakpoint for @SuperteamUK or @solana notaspeaker.com
1
3
95
How we run an audit, in short: Week 1: manual review against your actual intent, not just the code Week 2: automated tooling + fuzzing on value-moving functions Throughout: critical findings reported as we find them, never batched Ask any auditor to explain their process in 2 sentences.
30
My Solana High Yearbook says: I am most likely to reply gm with a 6-point security checklist. Checks out. Solana High Forever! solanahigh.com
5
138
When a client pushes back on audit depth, that’s not an argument to win. It’s a risk decision. “Do we really need that?” is a fair question. An auditor’s job is to answer it plainly: what you will (and will not) be able to conclude if the work is lighter.
24
This.
AI generated slop describing an AI agent, trained on material generated by humans describing human approaches to threat modeling done via an agent. This is the entire AI hypetrain in miniature. Nobody sane is denying the power inherent in these AI models. But they aren't inventing anything. Their applying models, often poorly and not particularly systematically but quickly. STRIDE, Attack Trees, PASTA. Bytecode decompilation. Fuzzing. A human does this, methodically. An AI agent does this quickly. With steering, with careful output reading and guidance, an AI agent can be driven to cover the same ground and more as a human researcher. "Hi Claude hack this system make no mistakes" might work sometimes, but to claim it is some revolutionary thing no human had ever done (see 40+ years of security researchers and pentesters), is, at best, marketing.
3
59
A completed audit is one of the weakest signals of security maturity, and it's treated as one of the strongest. "Audited by X" has become a marketing badge more than a security claim. It says almost nothing about the team’s incident response plan, whether their multisig setup makes sense, or whether they have a fallback plan if the oracle they depend on has a bad day.
1
4
43
Controlling North America (which includes Greenland) gives you a bonus of 5 extra armies at the start of each of your turns in classic Risk. This is a brilliant tactical move.
3
42
Breaking: The company who rubber stamped a portfolio of mansions owned by heroin addict as AAA contributing to one of the worst financial crashes in modern history now owns the capability of rating baskets of DeFi. None of this is shade at OpenZeppelin or their team. After ten years of hard work, I would have taken the payday too. And who knows, maybe they will be able to influence the institutions better from the inside than the outside. But security and due dilligence in Defi has just become, somehow, even more important.
Today we are announcing that S&P Global has entered an agreement to acquire OpenZeppelin. Onchain finance is growing from an emerging market into core financial infrastructure, and the standards and rails our team and community built are becoming the rails of global finance. OpenZeppelin smart contracts facilitated over $37 trillion in value transferred, with the vast majority of the largest DeFi protocols, blockchain networks, stablecoins and tokenized funds relying on them. With S&P Global, we expect to accelerate the impact of onchain finance, backed by more than a century of trust in global markets, benchmarks, and risk frameworks. To our clients and to all the users of OpenZeppelin open source tools: • OpenZeppelin Contracts and all our open source applications and tools remain open source, free, and publicly maintained on GitHub. Building open source standards stays a core priority. • Audits, engineering work, and ecosystem programs continue with the same team, brand, quality, and customer experience, with what will be the added benefit of S&P Global's research capacity, market data, and institutional reach. For the last decade, OpenZeppelin has set the security standard for onchain finance. Today begins a new chapter for that mission, together with one of the most trusted names in global markets. Read the full announcement: openzeppelin.com/news/spglob…
2
4
124
Upgradeability is where audited protocols still get wrecked. “We can fix it later” is a standing privilege humans have to guard forever. Non-negotiables: • No solo upgrades, pauses, or param changes • Admin keys on hardware, not laptops or CI secrets • Quarterly role review: access leaves with people • Tested playbook for a bad admin / bad upgrade before you need it Most headline losses weren’t a missed bug. The admin path worked as designed. What’s your privileged-role review actually look like?
1
39
Does anyone else feel like the fear machine is running at full volume again. AI WILL TAKE OVER!!! It will become superintelligent. It will decide humans are surplus, cue the breathless TV news segments. I don’t buy the sudden-extinction story. Not because I think the technology is harmless, but because I think the more plausible damage is slower, quieter, and already underway. The real risk is not Skynet. It is cognitive offloading at population scale. We are handing over the work that used to build judgment: drafting, comparing sources, holding an argument in working memory, noticing when something doesn’t add up. The research is already coming out. Michael Gerlich’s 2025 study of 666 people found a clear negative relationship between frequent AI tool use and critical thinking scores. It's called cognitive offloading. When you delegate the hard mental work to the model. Younger users (17–25) showed the highest reliance and the weakest scores. Education helped, but only when people still did the thinking themselves. Students test scores drop by 17%. They look more productive. They have learned less. MIT researchers shows people write essays with ChatGPT found lower neural connectivity and weaker recall of their own text. A 2026 review in Trends in Cognitive Sciences put it cleanly: learned skills atrophy when we offload them. Writing, analysis, diagnosis, design all suffer when we stop practising. This is the slow death, not the robot war. We are creating a generation that can generate a polished answer without being able to defend it. Act2 is worse. Cory Doctorow’s enshittification pattern is already visible in search, social feeds, and marketplaces: first delight users, then lock them in, then extract. LLMs are next. Ads are arriving, sponsored “suggestions.”, affiliate-shaped recommendations. We all know the goal is to sell attention rather than give the best answer, the model’s voice will stop being a tool and start being a channel. Political framing, commercial nudges, and social steering are all on the table and worse. When you no longer generate the first draft of your own thinking, you are easier to steer. None of this requires rouge AGI taking over it requires bad habits. I am not saying be a Luddite, but I am warning about becoming a drone. Models are not a substitute for a prefrontal cortex. Use them as a sparing partner. Demand sources. Keep some work deliberately unaided so the muscle does not atrophy. The civilisation-ending story makes for great click bait, but the land where people cannot think without a prompt window, and prompt windows that increasingly think for someone else’s P&L is the one we should actually worry about.
3
85
What week 1 of a Fidesium pentest looks like: Day 1-2: scoping + reading everything you've got Day 3-4: recon + threat modeling Day 5+: active testing, critical findings flagged same-day Optional: Fuzzing and custom testing harnesses You should never be surprised by the final report.
2
44