How smart contract, dependency, human, integration, and configuration risk have produced real losses — and what a defensible pre-deployment program looks like.
A practical look at AI-assisted formal verification for onchain systems: what it can rule out, what sits outside the model, and when a proof no longer applies.
A high-level article going over penetration testing in the Web3 space, and what protocol teams need to be aware of when securing their infrastructure.
Sherlock’s State of Web3 Security: Q1 2026 breaks down the biggest crypto security incidents, attack trends, and over $450M in losses across Web3 from January 1 to April 1, 2026.
Where Rust security actually breaks in 2026: unsafe contracts, FFI boundaries, async deadlocks, and supply chain gaps. Technical audit patterns with Miri, sanitizers, and fuzzing.
Practical guide to Web3 cross-chain security: threat models, trust assumptions, and failure modes for builders and auditors working with bridges and messaging systems.