
Featured Post
USDT Freeze 2026: Who's Frozen, How to Check, Live Data
As of 2026-07-26, Tether has blacklisted 9,597 USDT addresses and frozen $5.69 billion via the USDT smart contract's freeze mechanic. This 2026 pillar guide covers how freezes work on-chain, why Tether freezes addresses (with 2026 case data from the $344M April Iran seizure to the $131M July Operation Economic Fury freeze, and roughly $1B cumulative Iran-linked seizures since the campaign began), how the multisig-delay window opens a documented escape channel (BlockSec's analysis of 8,310 executed freeze proposals recorded $215.5M moved out during the delay), what 'destroyed' USDT really means for victims (burn-and-reissue mechanism), whether frozen addresses can be unfrozen (3.6% do get removed), and how to build compliance around freeze risk.

Beyond the Smart Contract: Domain and DNS Operational Security in Web3
Contract audits stop at the contract. We ran eight SEAL-based DNS and registrar checks across the 100 domains behind DefiLlama's TVL Top 100 — 800 checks, and only one domain passed them all. Here's which four controls most projects are missing, and why it matters at the user's entry point.

Politically Exposed Person Meaning: The Role, Not the Registry
Politically exposed person meaning: status attaches to the public function itself, extends to family and close associates, and decays after office ends.

PEP Definition: The Three Types of Politically Exposed Persons Explained
PEP definition: anyone holding a prominent public function. The three FATF types, foreign, domestic, and international organization, set different EDD duties.

Politically Exposed Person Definition Compared: FATF, FinCEN, and EU AMLD
Politically exposed person definition compared: FATF, FinCEN, and EU AMLD agree on foreign PEPs, split on domestic EDD. Which one governs your platform?

What Does PEP Mean at Work? Plain Answers for New Compliance Team Members
What does PEP mean? A risk category, not an accusation: public office raises money-laundering risk. Plain-language answers for new compliance team members.

VASP Crypto Compliance Obligations: A Practical Checklist for Virtual Asset Service Providers
VASP crypto compliance checklist: five obligations every virtual asset service provider owes, mapped to tooling, in a quarter-one build order for lean teams.

Web3 Attack Surfaces: A Penetration Testing Overview
Crypto institutions keep every traditional attack surface and add the money-handling chain on top of it. This article gives testers a practical abstraction of the running system: a four-component model—Application, Authorization and Signing, Blockchain Interaction, and Infrastructure—with each component's responsibility, representative implementations, and inherited attack surfaces. It then structures web3-specific coverage into five attack-surface areas, from production and automation operations through signing intent, approval and withdrawal chains, and fund logic to on-chain transactions and deployed contracts.

~$23M Lost: Cosmos EVM, Moonwell Exploits | BlockSec Weekly
During the reporting period (2026/08/22 - 2026/08/30), we cover 5 blockchain security incidents totaling approximately $22.7M in losses; an estimated $74M-$119.5M was drained from Tectonic, most of it erased when Cronos was rolled back to its pre-exploit state. The highlight is a six-chain Cosmos EVM exploit series (~$5.7M realized), traced on TAC Chain, where a shared balance-synchronization bug chained an underflow and an overflow to drain a staking pool. The report also analyzes Moonwell's combined collateral-accounting and oracle price manipulation, Tectonic's combined oracle-price and receipt-token exchange-rate manipulation of low-liquidity collateral, an Ajna liquidation business-logic flaw, and a Rain Card Contract Exploit Series with an Ed25519 signature-verification bypass (Avici, Tria, and others) on Solana.

Rules of Engagement and Production Safety for Institutional Blockchain Penetration Testing
A penetration test that touches signing, withdrawal, and ledger systems is prepared before it runs. This article follows the engagement lifecycle: turning a business decision into objective, scope, named owners, and authorized access; recording authority, permitted techniques, operating limits, prohibited activity, communications, and evidence handling in a Rules of Engagement document; and protecting live service with measurable stop criteria, monitoring, change coordination, and named pause authority. It closes with the remediation and retest that turn findings into validated controls.

What Is Blockchain Penetration Testing? Definitions and Boundaries
No widely accepted definition of blockchain penetration testing exists, and many proposed ones tangle it with audit, scanning, and bug bounty. This article sets out a working definition—an adversarial, hands-on assessment of a running system, under agreed scope and rules of engagement, that validates exploitable paths and control chains—and what web3 adds: a money-handling threat model whose defining composition gap is the off-chain-to-on-chain handoff. It then maps the five testable capabilities of that chain and routes nearby objectives to code audit, wallet security audit, web3 security testing, scanning, and bug bounty.

From Incidents to Regulation: Why Crypto Institutions Need Blockchain Penetration Testing
Exchanges, payment firms, custodians, and wallet providers now lose the most money beyond the smart contract—in signing, custody, keys, people, and supply chains. Code-level audit and transaction-level monitoring each leave a gap, and traditional penetration tests may miss crypto's signing and fund semantics. This article opens our blockchain penetration testing series with the two legs of the case for institutions in scope: where the risk actually comes from, and how NYDFS, DORA, VARA, SFC, and MAS treat adversarial testing across five jurisdictions.

Newsletter - August 2026
During August 2026, three major DeFi security incidents caused significant losses. A balance-synchronization vulnerability in the Cosmos EVM module was exploited across six chains (~$14.8M). Moonwell on Base lost ~$9.1M to oracle price manipulation targeting the low-liquidity MAMO token. Term Finance on Ethereum suffered a ~$8.47M governance takeover enabled by near-zero voter participation.