WRITING · DATED, SIGNED

On detection, methodology, and the gaps that remain.

Post-mortems, threat-model breakdowns, and gate-by-gate honesty about what we do not detect.

THESIS May 4, 2026 · 6 min read

The front door and the vault

Ripple opened its internal DPRK threat intelligence to the industry through Crypto ISAC. The perimeter just got sharper. The action moment is still naked.

THESIS April 29, 2026 · 11 min read

Yes. Weeks ago.

Six months across the table. Twelve minutes to drain. The signatures were valid. The gap between when a human says yes and when the action executes.

THESIS April 28, 2026 · 14 min read

The cert tests yesterday's threat.

iBeta Level 2 certification does not test digital injection. NIST said so in 2023. iProov measured 2,665 percent native-virtual-camera growth in 2024.

THESIS April 27, 2026 · 15 min read

The action layer just stopped being optional.

In nineteen days, three institutional voices independently named the action layer as mandatory. Treasury, Tether, and the SEC Chair all converged.

THESIS April 26, 2026 · 8 min read

One signer.

Aave is mid-raise on a $230M bad-debt cover. The architectural choice was a 1-of-1 DVN — a cross-chain bridge whose authority reduced to one off-chain signer.

THESIS April 25, 2026 · 7 min read

49 days to undo 46 minutes.

Five DeFi protocols filed a coordinated proposal to recover funds an attacker took in 46 minutes. The proposal will take 49 days. That ratio is the design.

THESIS April 24, 2026 · 9 min read

The bank wasn't breached. The printer was.

3.4M Citizens Bank records and 250K Frost Bank records walked out of a print vendor on April 20. Neither bank was breached. The next $300M loss is downstream.

THESIS April 23, 2026 · 10 min read

Three audits. One admin. $3.5M.

Volo Protocol paid three auditors. Ran a bug bounty. Shipped reviewed production code. On April 21, none of that mattered. The attacker never touched the code.

THESIS April 20, 2026 · 10 min read

Meta paid for agent identity verification

Meta acquired Moltbook to bet on a registry where agents are tethered to human owners. Juniper projects $1.5T in agentic commerce by 2030.

HACK AUTOPSY April 16, 2026 · 7 min read

Grinex lost $13M. Same chain that broke at Bybit.

On April 16, the Grinex exchange disclosed approximately $13M in stolen user funds. The post-mortem reads identically to four other 2025 incidents. Authentication held at signup. Authorization held at withdrawal. The gap between them held nothing.

THESIS April 15, 2026 · 10 min read

Deepfake injection attacks grew 2,665% in 2025

iProov 2025: virtual-camera injection attacks up 2,665% YoY. Four regulatory deadlines in 120 days. The gap between KYC and the withdrawal button.

HACK AUTOPSY April 14, 2026 · 4 min read

The funniest hack of 2026 almost wasn't funny.

Hyperbridge joked about being hacked on April 1. Twelve days later, an attacker minted $1B in fake tokens. The only thing that saved them was no buyers.

THESIS April 11, 2026 · 5 min read

20,000 people signed away their crypto

Operation Atlantic found 20,000 approval phishing victims in 30 countries. A Kraken user lost $18.2M to social engineering. The same gap fed both attacks.

THESIS April 9, 2026 · 11 min read

The JWT your auditor actually wants to see

Treasury now treats crypto like banks. Bitcoin Depot lost $3.7M with no proof of who authorized the transfers. What a real audit trail looks like.

PRODUCT April 3, 2026 · 3 min read

Integration guide: 3 endpoints, 15 minutes

Install the SDK, enroll a user, verify a transaction. Full integration in 15 minutes with code examples in Python, Node, and cURL.

HACK AUTOPSY March 29, 2026 · 5 min read

You Don't Get to Add Trust After the Breach

Every financial platform builds security after the first incident. The ones that survive build it before. The architecture of trust infrastructure.