Our Blog

Research, analysis, and practical guidance on cybersecurity and AI security from our London team.

Web3 & Smart-Contract Security15 August 2026

BonkDAO's $20M Governance Attack: The Contracts Worked Exactly as Coded

An attacker spent roughly $4.4M buying BONK to clear a 1% quorum, then pushed a malicious treasury proposal through a near-empty vote — no exploit, no bug, just governance math.

dao-securitygovernance-attackdefi
4 min readRead
AI Governance15 August 2026

Study: Soldiers Trust AI Targeting Less Than Humans — Until You Explain It

A 2,015-participant experiment with a replica Israeli military AI targeting system found algorithmic aversion, not automation bias — but adding explainability features erased that skepticism entirely.

ai governancehuman oversightexplainable ai
4 min readRead
Web3 & DeFi Security14 August 2026

Step App Shuts Down: What a Silent Move-to-Earn Exit Teaches About Crypto Risk

One of the last surviving move-to-earn projects is closing on 21 August with no explanation for users — a pattern worth understanding if you hold tokens in any similarly structured app.

web3move-to-earntokenomics
4 min readRead
API & Supply-Chain Security14 August 2026

Datasette's New Upload API Turns a Bearer Token Into a Production Database Swap

The datasette-upload-dbs 0.5a0 release formalises a POST API for hot-swapping a live SQLite database — a convenient CD primitive that is only as safe as the bearer token and permission scope guarding it.

api-securitydevsecopssecrets-management
4 min readRead
AI Governance13 August 2026

Sycophancy, Overconfidence, and the AI Risk You Can't Fix With a Patch

Bruce Schneier and Nathan Sanders argue that many of AI's harms are business-model failures, not engineering ones — but the essay also flags two technical failure modes vendors keep ignoring, and those belong on every AI governance register.

ai governancellm securityiso 42001
4 min readRead
AI Governance13 August 2026

DeepSeek Ships V4 Pro 0813 With No Announcement — What That Means for AI Governance

DeepSeek's newest reasoning model surfaced on OpenRouter with no model card, no vendor announcement, and benchmarks first seen in a leaked WeChat screenshot. For teams with an AI governance program, that's the real story.

ai-governancellm-securityiso-42001
4 min readRead
Web3 Security12 August 2026

Fake Flare Network Staking Site Drains $8.5M in XRP, Two Arrested

A cloned staking site, a fabricated Wikipedia entry, and a paid actor were enough to convince 71 investors to hand over 3.4 million XRP — a reminder that brand impersonation, not smart-contract exploits, remains crypto's most reliable attack surface.

web3-securitycrypto-scamsbrand-impersonation
4 min readRead
AI Security12 August 2026

Context Bombs: Using Prompt Injection to Stop AI Hacking Agents

Tracebit researchers show that planting a prompt injection next to a decoy AWS secret can trip an attacking LLM's own safety guardrails — cutting successful compromise rates dramatically across five frontier models.

ai-securityprompt-injectioncloud-security
4 min readRead
AI & LLM Security11 August 2026

How Researchers Cracked Encrypted Chain-of-Thought in Claude, GPT and Gemini

A new paper shows that the encrypted reasoning blocks Anthropic, OpenAI and Google return from their APIs can be replayed into a weaker sibling model and jailbroken into plaintext — defeating anti-distillation protections and, in the wild, exposing PII and credentials.

llm securitychain-of-thoughtai security research
4 min readRead
Vulnerability Management11 August 2026

CISA KEV Alert: Langflow RCE Exploited at Scale, AI Agents in the Loop

CISA added an unauthenticated Langflow RCE, an Apache Tomcat cluster-encryption bypass, and two N-able N-central auth-bypass bugs to its KEV catalog on August 5 — one of them already chained by an actor using agentic AI tooling.

kev-cataloglangflowai-agent-security
4 min readRead
Web3 & Exchange Security10 August 2026

Coinsbuy's $8M Cross-Chain Drain: When Wallets Refill, the Keys Weren't the Problem

An attacker emptied eleven Coinsbuy wallets across Tron and Ethereum in under an hour, then laundered the proceeds through an instant-swap service before the exchange quietly topped the wallets back up — a strong signal the breach sat in withdrawal logic, not key custody.

web3-securityexchange-securitycross-chain
4 min readRead
AI & Cryptography Governance10 August 2026

Python's Crypto Library Now Ships Post-Quantum Algorithms by Default

pyca/cryptography 48 adds NIST-standard ML-KEM and ML-DSA support, putting quantum-resistant primitives one pip install away for one of PyPI's most-downloaded packages — with no emergency forcing the move.

post-quantum-cryptographyml-kemml-dsa
4 min readRead
Software Supply Chain & DevSecOps9 August 2026

GitHub Models Retirement: The CI/CD Secrets Lesson Nobody Flagged

GitHub quietly retired its Models API on 30 July 2026, cutting off a feature that let Actions workflows call LLMs using the same GITHUB_TOKEN already sitting in the pipeline. That convenience is worth a second look.

github-actionsci-cd-securitysupply-chain
4 min readRead
Web3 & Crypto Security9 August 2026

How a 2021 RNG Bug Turned Coldcard's 'Offline' Wallets Into a $130M Heist

A firmware error from March 2021 quietly swapped Coldcard's hardware random number generator for a predictable software fallback, letting at least a dozen threat actors brute-force seed phrases and drain over $130M in Bitcoin.

hardware-walletsbitcoinentropy
5 min readRead
Software Supply-Chain Security8 August 2026

npm's Keyv and Cacheable Hijacked in 'Mini Shai-Hulud' Supply-Chain Worm

A hijacked maintainer account let attackers trojan keyv, cacheable-request and flat-cache — reusing the same Shai-Hulud toolkit seen on PyPI and npm earlier in 2026.

supply-chain-securitynpmshai-hulud
4 min readRead

Archive

Browse all 105 posts by month

Topics

Llm Security28Ai Governance23Ai Security20Prompt Injection17Ai Red Teaming17Iso 4200112Agentic Ai11Supply Chain10Web39Incident Response7Ai Agents7Devsecops6Supply Chain Security6Defi5Ai Agent Security5Defi Security5Web3 Security4Vulnerability Management4Agentic Coding4Cryptography4Project Zero4Android4Secrets Management3Cloud Security3Npm3Rce3Sandbox Escape3Patch Management3Owasp3Vibe Coding3Claude3Llm Agents3Smart Contracts3Smart Contract Security3Mobile Security3Solana2Human Oversight2Datasette2Deepseek2Social Engineering2Anthropic2Post Quantum Cryptography2Github Actions2Ci Cd Security2Hardware Wallets2Bitcoin2Facial Recognition2Computer Vision2Privacy2Llm Tooling2Cryptanalysis2Threat Intelligence2Phishing2Account Takeover2Privilege Escalation2Ai Supply Chain2Physical Security2Openai2Bridge Security2Claude Code2Flash Loan Attack2Tls2Compliance2Open Weights2Data Exfiltration2Vulnerability Disclosure2Secure Code Review2Ai Generated Code2Malware Analysis2Pypi2Pki2Vulnerability Research20 Click2Agent Security2Bridge Exploit2Dao Security1Governance Attack1Explainable Ai1Military Ai1Move To Earn1Tokenomics1Crypto Risk1Due Diligence1Api Security1Ai Policy1Ai Risk Management1Model Vetting1Crypto Scams1Brand Impersonation1Xrp1Aws1Chain Of Thought1Ai Security Research1Jailbreak1Kev Catalog1Langflow1Apache Tomcat1Exchange Security1Cross Chain1Ml Kem1Ml Dsa1Python Security1Crypto Agility1Entropy1Crypto Security1Shai Hulud1Credential Theft1Servicenow1Cve 2026 68751Adversarial Ml1Privacy Tech1Mcp1Llm Cli1Ai Misuse1Secure Coding1Data Exposure1Kubernetes Security1Rng1Key Management1Sandboxing1Sandbox Isolation1Grapheneos1Border Search1Mobile Forensics1Duress Pin1Digital Rights1Zero Day1Uefi1Secure Boot1Eset1Nist1Post Quantum1Llm Research1Teamcity1Cicd Security1Iot Security1Botnet1Blockchain C21Ddos1Sharepoint1Cve 2026 505221On Prem Security1Api Abuse1Denial Of Wallet1Token Theft1Otp Interception1Insurance1Fastjson1Java1Spring Boot1Cve 2026 167231Active Directory1Ad Cs1Cve 2026 541211Kerberos1Open Weight Models1Distillation1Biometric Surveillance1Data Retention1Hugging Face1Mfa1Identity Theft1Cardano1Local Llms1Mlx1Data Sovereignty1Macos1Flash Loan1Smart Contract Audit1Allbridge17 Zip1Cve 2026 142661Xz1Heap Overflow1Vault Exploit1Shadow Ai1Ai Risk1Developer Tools1Openssl1Denial Of Service1Data Protection1Browser Security1Webassembly1Network Security1Cli Tools1Broken Access Control1Penetration Testing1Web Application Security1Attack Surface1Architecture1Database Security1Software Supply Chain1Accountability1Vendor Risk1Ai Browsers1Typosquatting1Smart Contract Exploit1Vault Accounting1Tls Certificates1Domain Validation1Ca Browser Forum1Web Security1Sycophancy1Windows Exploitation1Google1Offensive Security1Pixel1Kernel Exploit1Mediacodec1Llm Generated Code1Dom Xss1Web Components1Secure Development1Google Project Zero1Google Play1Malware1App Security1Anssi1Critical Infrastructure1Windows Security1Uac Bypass1Win32k1Tool Calling1Export Controls1National Security1Open Source Ai1Model Provenance1Current Ai1Cognitive Debt1Prompt Engineering1Dspy1Evals1Google Workspace1Gemini1Aztec Connect1Zero Knowledge1Ai Surveillance1Mass Surveillance1Browser Automation1Rsa1Ssh Security1Code Generation1Drone Security1Autonomous Systems1Law Enforcement Technology1Cyber Physical Security1Ethereum L21Sgx1Secret Network1Axelar1Infinite Mint1Mev1Ethereum1Ai Evasion1Ci Cd1Role Confusion1Python1Dependency Management1Packaging1Surveillance1Smart Glasses1Meta1Law Enforcement1Multi Agent Security1Llm1Appsec1