‹ BackNewsMultisig

Multisig

EntropyLab releases candidate build of offline Bitcoin key and wallet calculator
Crypto Securi
2026-09-30 03:00:58

Crypto security’s center of gravity is shifting from code bugs to permissions and trust chains

A TechFlowPost article argues that the biggest security failures in crypto are no longer centered on undiscovered smart contract bugs. Instead, recent losses have clustered around permissions, signing flows, RPC dependencies, supply chains, backend approval systems, and the people trusted to operate them. The piece points to four major incidents — Bybit, Bitget, KelpDAO, and Drift — as evidence that attackers are increasingly bypassing code and going after the trust assumptions wrapped around it. In the article’s framing, the industry has spent years hardening contracts, adding multisigs, separating cold wallets, and expanding audits, yet funds still disappeared because the systems approving transactions were fed false data or because authorized signers were manipulated into approving malicious actions. It also argues that AI is changing the economics of attacks by making social engineering, malware delivery, identity fabrication, and large-scale contract scanning cheaper and easier to automate. The article does not say audits are useless. Its point is narrower: audits cover a shrinking share of the places where money is actually lost. As attack surfaces move outward, the proposed response shifts as well — toward permission governance, infrastructure diversity, runtime controls, continuous monitoring, and insurance structures that price security architecture directly.

180
Crypto security’s center of gravity is shifting from code bugs to permissions and trust chains
Web3 Security
2026-09-30 00:49:03

Web3 security is shifting from code exploits to trust and permission failures, Foresight says

A long-form analysis published by Foresight argues that the center of gravity in Web3 security has moved away from smart contract bugs and toward permissions, signing flows, RPC dependencies, supply chains, and operational trust. The piece points to four major incidents — Bybit, KelpDAO, Drift, and Bitget — to show that some of the largest recent losses did not come from undiscovered contract 0days. Instead, attackers targeted the systems and people around the code: compromised signing interfaces, poisoned backend approval flows, manipulated RPC responses, and social engineering aimed at privileged operators. The article says the pattern has become clearer over the past three years. In 2024, phishing overtook private key leaks as the biggest threat. In 2025, the Bybit theft pushed front-end supply chain risk and signing interfaces into focus. In 2026, the KelpDAO, Drift, and Bitget cases turned RPC trust, multisig design, and permission configuration into the main battleground. It also argues that AI is changing the economics of attacks by making phishing, fake identities, malware delivery, and old-contract scanning cheaper to run at scale, while forcing defenders to secure every entry point. Foresight’s conclusion is blunt: Web3 has not become safe or unsafe in a simple sense. The most valuable attack surface has moved outside the contract itself and into the broader trust chain that surrounds it.

190
Web3 security is shifting from code exploits to trust and permission failures, Foresight says
Cosmos Hub recovers 1.227 million ATOM from Neutron exploit, moves funds to 4-of-6 multisig
1.227 Million ATOM Moved to 4-of-6 Multisig After Neutron Governance Attack
How 4,000 BTC Left Liquid Network’s Vault Without a Stolen Key
CoinCorner rolls out Lloyd’s-insured multisig Bitcoin vault with AnchorWatch
Ai Yi says about 23 million LAPTOP tokens are allocated for market making, with GSR, G20 and Wintermute involved