{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2026.3.0.dev0", "url": "https://darkmode.securityalliance.org"}, "schedule": {"url": "https://darkmode.securityalliance.org/darkmode-2026/schedule/", "version": "0.12", "base_url": "https://darkmode.securityalliance.org", "conference": {"acronym": "darkmode-2026", "title": "darkMode 2026", "start": "2026-02-16", "end": "2026-02-18", "daysCount": 3, "timeslot_duration": "00:05", "time_zone_name": "US/Mountain", "colors": {"primary": "#1d262f"}, "rooms": [{"name": "Workshop", "slug": "5154-workshop", "guid": "97da1034-d0f7-5cf4-8beb-f671d0a8eaf3", "description": "Private room near auditorium", "capacity": 20}, {"name": "Auditorium", "slug": "5155-auditorium", "guid": "8a28f735-ce62-54c3-8161-e4b61db80fbb", "description": "Main stage", "capacity": 200}], "tracks": [{"name": "New Announcements", "slug": "6658-new-announcements", "color": "#00ebff"}, {"name": "Privacy", "slug": "6661-privacy", "color": "#000000"}, {"name": "Vulnerability Disclosure", "slug": "6656-vulnerability-disclosure", "color": "#b5f79c"}, {"name": "Other", "slug": "6655-other", "color": "#c655ec"}, {"name": "Lessons Learned", "slug": "6657-lessons-learned", "color": "#ff003c"}, {"name": "Hot takes", "slug": "6659-hot-takes", "color": "#8300ff"}, {"name": "SEAL", "slug": "6660-seal", "color": "#4339db"}], "days": [{"index": 1, "date": "2026-02-16", "day_start": "2026-02-16T04:00:00-07:00", "day_end": "2026-02-17T03:59:00-07:00", "rooms": {"Auditorium": [{"guid": "e1eea8c3-8944-58e0-8847-26bce0cbf39b", "code": "WLMELT", "id": 89203, "logo": null, "date": "2026-02-16T09:45:00-07:00", "start": "09:45", "end": "2026-02-16T09:50:00-07:00", "duration": "00:05", "room": "Auditorium", "slug": "darkmode-2026-89203-welcome-to-darkmode", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/WLMELT/", "title": "Welcome to darkMode", "subtitle": "", "track": "Other", "type": "Short Talk", "language": "en", "abstract": "samczsun welcomes you to SEAL's first annual security conference, darkMode", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "SHNEJ7", "name": "samczsun", "avatar": null, "biography": null, "public_name": "samczsun", "guid": "8078c7f1-b9ff-5095-832d-8ccf271d53a4", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/SHNEJ7/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/WLMELT/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/WLMELT/", "attachments": []}, {"guid": "2a06c634-eeae-52de-9dcc-2cdd02d5a628", "code": "CFCU37", "id": 89303, "logo": null, "date": "2026-02-16T09:50:00-07:00", "start": "09:50", "end": "2026-02-16T10:10:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-89303-old-hacks-targeting-new-industries-how-to-balance-user-privacy-and-security", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/CFCU37/", "title": "Old Hacks Targeting New Industries: How to Balance User Privacy and Security", "subtitle": "", "track": "Lessons Learned", "type": "Short Talk", "language": "en", "abstract": "Your smart contracts are audited, but is your contractor\u2019s laptop? Most Web3 \"hacks\" aren't complex cryptographic exploits\u2014they're basic Web2 security failures. From weak Discord credentials to unmanaged endpoints, many web3 companies have forgotten the web2 security fundamentals.\n\nJoin Andrew, a Mandiant/Google Cloud security expert with a decade of experience securing global financial giants, as he deconstructs the traditional attacks currently gutting the Web3 ecosystem. Learn why your \"decentralized\" future is failing at the basics, and how you can balance security and user privacy.", "description": "In this talk, we will discuss common cyber threats facing web3 firms and the security controls that can stop them. Topics include:\nIdentity and access management: conditional access, device posture checking\nWays to deploy security controls on end-user machines while respecting user privacy\nConducting due-diligence checks on a multinational, contractor-led workforce, insider threat protections and social engineering awareness\nManaging IT infrastructure such as servers, laptops and phones, including logging and monitoring", "recording_license": "", "do_not_record": false, "persons": [{"code": "YBFRFP", "name": "Andrew Chang-Gu", "avatar": "https://darkmode.securityalliance.org/media/avatars/YBFRFP_S6J1Z43.webp", "biography": "Andrew has been living on-chain since the \"early days\"\u2014a journey that began with mining a million Dogecoin on his laptop. After founding a college crypto-investing group in 2013, he spent the next decade navigating the ecosystem as a smart contract developer and strategic investor.\n\nProfessionally, Andrew is a veteran of the traditional security world, having spent ten years as a global consultant securing multinational financial institutions across four continents. Now a Web3 security expert at Google Mandiant, he blends his \"OG\" intuition with enterprise-grade logic to protect the next generation of decentralized protocols from the hackers of today.", "public_name": "Andrew Chang-Gu", "guid": "029bd916-e393-527a-b0cd-c8393ca98d89", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/YBFRFP/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/CFCU37/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/CFCU37/", "attachments": []}, {"guid": "c02de1cb-5ac7-5188-8f29-164c59400052", "code": "UDCWH3", "id": 88227, "logo": null, "date": "2026-02-16T10:10:00-07:00", "start": "10:10", "end": "2026-02-16T10:30:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-88227-safeguarding-your-digital-footprint-a-privacy-first-approach-to-web3-opsec", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/UDCWH3/", "title": "Safeguarding Your Digital Footprint:  A Privacy-First Approach to Web3 OPsec", "subtitle": "", "track": "Privacy", "type": "Closed Room Session", "language": "en", "abstract": "Wireless networks, a ubiquitous and often overlooked element of Web3 projects, pose a significant operational security (OPSEC) risk due to a phenomenon called \"beaconing.\" As mobile devices move, they publicly disseminate personally identifiable information (PII) that malicious actors can combine with open-source intelligence (OSINT) to infer a user's travel plans, physical addresses, past conference attendance, associated crypto projects, and even the location of hardware wallets. This vulnerability contributes to the increasing threat of physical attacks (such as kidnapping and ransom, or \"wrench attacks\") and social engineering, as well as the risk of disclosing material nonpublic information.\n\nThis workshop will walk attendees through using readily available tools to collect and analyze everyday wireless signals.  Hardware crypto wallets will be made available for analysis.  Other secure tooling will be observed. Will there be enough information in the room to identify devices, individuals, crypto wealth?  We will see.", "description": "As you move through the world, your devices connect to wireless networks and collect unique identifiers. Your mobile devices may be broadcasting these sensitive artifacts, possibly personally identifiable information (PII), through probes and beacons. These wireless signals can be combined with open-source intelligence (OSINT) to compromise your privacy, revealing your travel history, physical location, and even the existence and location of your hardware wallets.  This data is an asset to malicious actors: enabling pretexting for social engineers, exposing daily routines to physical attackers, or providing partnering information to data-hungry degens.\n\nThis workshop demonstrates a privacy-focused security paradigm for the Web3 space. It moves beyond on-chain contracts to detail the off-chain vulnerabilities in Wi-Fi and Bluetooth signals. Learn how to collect and analyze potentially sensitive wireless signals.  Examine your digital footprint in a way an attacker would.  \n\nWe will also discuss practical mitigation strategies and best practices necessary to secure your wireless devices, protect your personal safety, and ensure the operational integrity of your Web3 projects in a world where physical and digital security are inextricably linked.\n\nTo participate in this workshop, please bring a Macbook, Linux Laptop with a wireless card that supports monitor mode, or an Android device.", "recording_license": "", "do_not_record": false, "persons": [{"code": "GD7EEJ", "name": "Benjamin Speckien", "avatar": "https://darkmode.securityalliance.org/media/avatars/GD7EEJ_Fmrynhv.webp", "biography": "Benjamin Speckien is a veteran of the digital trenches, a cybersecurity professional who's successfully managed to keep the $200M+ cloud assets at cLabs from becoming a thrilling news headline. As their former Head of Security, he didn't just \"lead\" incident response; he personally ensured over 500 potential dumpster fires were quickly extinguished, achieving a mean time to detect (MTTD) in mere seconds thanks to some clever cloud security posture management. He's a certified, degree-holding hacker (CISSP, M.S. in Cybersecurity) with expertise spanning the Financial, Defense, and Blockchain sectors. When he's not busy making software supply chains less of a liability, you can probably find him contemplating the simple, secure life back in the peaceful Northwoods of Wisconsin.", "public_name": "Benjamin Speckien", "guid": "1a4926c3-3fea-5445-8476-056cc86dfea5", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/GD7EEJ/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/UDCWH3/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/UDCWH3/", "attachments": []}, {"guid": "906c7785-fed3-5e1a-9d24-982dce98e1dd", "code": "CYHTKN", "id": 89930, "logo": null, "date": "2026-02-16T10:30:00-07:00", "start": "10:30", "end": "2026-02-16T10:50:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-89930-totp-apps-are-dead-and-why-you-are-doing-2fa-wrong", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/CYHTKN/", "title": "TOTP apps are dead and why you are doing 2FA wrong", "subtitle": "", "track": "Hot takes", "type": "Short Talk", "language": "en", "abstract": "I will present a summary of how 2FA works, the different methods (SMS, TOTP apps, Yubikeys, Passkeys, etc), the weaknesses each one of them have, how they are being exploited, and what we have to do in order to start using 2FA in a safe way.", "description": "I will present a summary of how 2FA works, the different methods (SMS, TOTP apps, Yubikeys, Passkeys, etc), the weaknesses each one of them have, how they are being exploited, and what we have to do in order to start using 2FA in a safe way.", "recording_license": "", "do_not_record": false, "persons": [{"code": "XPVTU3", "name": "Pablo Sabbatella", "avatar": "https://darkmode.securityalliance.org/media/avatars/XPVTU3_7seITOc.webp", "biography": "Pablo Sabbatella, a.k.a pablito.eth is a Web3 Operational security researcher. He founded Opsek, a company dedicated to Operational security audits and trainings for web3 organizations and HNWI. He is also a SEAL contributor and the host of the Blockchain Security Series podcast.", "public_name": "Pablo Sabbatella", "guid": "64df9f5e-7559-5641-9e78-0cc23795371d", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/XPVTU3/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/CYHTKN/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/CYHTKN/", "attachments": []}, {"guid": "7503e99c-4bff-54e6-bc47-21e3e6c741da", "code": "7ZHSK9", "id": 88221, "logo": null, "date": "2026-02-16T10:50:00-07:00", "start": "10:50", "end": "2026-02-16T11:10:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-88221-get-off-my-lawn-you-re-forgettin-your-web2-security-risk-young-whippersnapper", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/7ZHSK9/", "title": "Get off my lawn: you're forgettin' your web2 security risk, young whippersnapper", "subtitle": "", "track": "Hot takes", "type": "Short Talk", "language": "en", "abstract": "Web2 is the Soft Underbelly of Web3\n\nWeb3 Security has a Web2 Security problem. As on-chain code gets better and better, attackers are going to go after the low-hanging fruit--and that means all the boring \"legacy cybersecurity stuff\" your grandpa used to tell you about. (See: the ByBit hack in Feb 2025, classic web2 compromise with web3 impact).\n\n\"Back in mah day, we cared about phishing and end point device security. Oh, and young whippersnapper, and did you know 'the cloud' just means 'someone's else's computer'? Sure seems like a terrible idea to run all yer validators in (checks notes) AWS, doncha think? Using CIA's preferred cloud vendor--that'll stick it to the man fer sure LOL!\"\n\n\"and betcha never heard of this here dang thing called a SIEM before either, have yeah?\"\n\nI once met a security engineer at a conference who described themselves as a \"web3 native security engineer\". Couldn't explain TCP/IP, how Linux works, how a browser works, couldn't tell me the OSI model, but boy did they know a lot about Solidity security!\n\nYeah. Don't be that guy. Cuz you're going to get rekt if you do.\n\nCome to grandpa's[*] curmudgeonly fireside chat to hear about all the old stuff that still matters today.\n\n[*] not an actual grandpa. yet.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "EXANXQ", "name": "J.M. Porup", "avatar": null, "biography": "J.M. has twenty-five years of experience in cybersecurity, including five in crypto. He is currently on his third CISO role, this time at Berachain.", "public_name": "J.M. Porup", "guid": "0cd7f600-6d76-5703-8b27-1ae44f781504", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/EXANXQ/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/7ZHSK9/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/7ZHSK9/", "attachments": []}, {"guid": "620d0953-242a-5b64-8754-1eb6f5caa074", "code": "P8GGKC", "id": 88171, "logo": null, "date": "2026-02-16T11:10:00-07:00", "start": "11:10", "end": "2026-02-16T11:30:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-88171-inside-immunefi-s-highest-paying-bug-bounties-of-2025", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/P8GGKC/", "title": "Inside Immunefi\u2019s Highest-Paying Bug Bounties of 2025", "subtitle": "", "track": "Lessons Learned", "type": "Short Talk", "language": "en", "abstract": "In 2025 alone, Immunefi paid out close to $11,000,000 in bug bounties for critical crypto vulnerabilities. preventing exploits that could have resulted in hundreds of millions of dollars in losses.\n\nThis talk breaks down a few of the highest-impact bounty payouts of 2025, focusing on what actually drove seven-figure and high six-figure rewards. We\u2019ll examine specific vulnerabilities, system designs, and attacker mindsets behind the most severe findings, and explain why these specific bugs justified such large payouts.\n\nThis session is grounded in specific cases in 2025 across DeFi, bridges, L2s, and core infrastructure. Attendees will gain a practical understanding of where the highest paying security risks surfaced in 2025, and what both researchers and protocol teams should prioritize going forward.", "description": "This talk is structured around a small number of high-impact 2025 case studies, including:\n- The technical root cause of some of the largest bounty payouts of the year\n- How these vulnerabilities could have been exploited in the wild\n- What made these reports stand out and qualify for top-tier rewards\n\nEach case is anonymized or based on information approved for public disclosure, and is used to extract concrete lessons for:\n- Whitehats looking to focus on high-impact targets\n- Protocol teams aiming to prevent catastrophic bugs\n- The goal is to give attendees a realistic picture of what \u201ccritical\u201d actually looks like in 2025 crypto systems.", "recording_license": "", "do_not_record": false, "persons": [{"code": "BQTDJJ", "name": "Alejandro Munoz-McDonald", "avatar": "https://darkmode.securityalliance.org/media/avatars/BQTDJJ_6RcDTPq.webp", "biography": "Alejandro Mu\u00f1oz-McDonald is a Senior Security Researcher and Smart Contract Lead Triager at Immunefi, with over eight years of experience in Web3 security. He joined Immunefi in January 2022 as one of the earliest members of the company\u2019s 24/7 triage team.\n\nImmunefi has facilitated more responsible disclosures than any other organization in the crypto ecosystem. In his role, Alejandro has personally handled thousands of vulnerability reports and has been directly involved in hundreds of critical incident response events across DeFi, bridges, and core blockchain infrastructure. This hands-on exposure to real-world exploits, near-misses, and complex attack paths has given him a rare, practical perspective on where crypto systems fail in practice.", "public_name": "Alejandro Munoz-McDonald", "guid": "aad6a979-39c5-5691-ad4d-75b1f1a1ccaa", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/BQTDJJ/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/P8GGKC/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/P8GGKC/", "attachments": []}, {"guid": "0004c392-431a-5706-95a2-ce90607f960f", "code": "ESCYXL", "id": 86974, "logo": null, "date": "2026-02-16T11:30:00-07:00", "start": "11:30", "end": "2026-02-16T11:50:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-86974-when-the-applejeus-github-is-worth-the-squeeze", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/ESCYXL/", "title": "When the AppleJeus GitHub is Worth The Squeeze", "subtitle": "", "track": "Lessons Learned", "type": "Short Talk", "language": "en", "abstract": "AppleJeus, also known as Citrine Sleet, Gleaming Pisces, and Smooth Operator, is the North Korean hacker behind the Radiant Capital heist among others. This is the story of finding a previously undiscovered AppleJeus campaign targeting fintech. This talk will also give some background on North Korean hacking groups, show simple pivoting for analysts, and give recommendations to help protect your organization from North Korean threat actors.", "description": "This talk will have a little bit of everything!  Collaboration between different North Korean hacking groups! Involvement in hacking by North Korean IT workers! Activity across platforms including GitHub, NPM, PyPI, Twitter, and Discord!", "recording_license": "", "do_not_record": false, "persons": [{"code": "UJTGCS", "name": "Daniel Gordon", "avatar": "https://darkmode.securityalliance.org/media/avatars/UJTGCS_jDAt7cL.webp", "biography": "Daniel Gordon has over a decade of experience hunting, researching, tracking, and stopping North Korean hacking groups across both public and private sector. He has a bunch of degrees and certifications, and has published blogs for DarkReading, War on the Rocks, and Risky.biz and given talks on North Korean hacking at SleuthCon and FTSCon.", "public_name": "Daniel Gordon", "guid": "c19dbd84-7050-5617-b1bc-6bf8214ddb6d", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/UJTGCS/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/ESCYXL/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/ESCYXL/", "attachments": []}, {"guid": "a364579d-ad38-5777-9300-65db1009a4a2", "code": "JNGY3E", "id": 89204, "logo": null, "date": "2026-02-16T13:00:00-07:00", "start": "13:00", "end": "2026-02-16T13:20:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-89204-seal-certifications-a-collaborative-framework-for-maturity-in-crypto-security", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/JNGY3E/", "title": "SEAL Certifications: A Collaborative Framework for Maturity in Crypto Security", "subtitle": "", "track": "New Announcements", "type": "Short Talk", "language": "en", "abstract": "Security Alliance (SEAL) is developing an open, collaborative certification program to help the crypto ecosystem define and demonstrate operational security maturity. Built on lessons learned from years of emergency incident response and threat intelligence sharing, SEAL Certifications distill collective knowledge into actionable standards developed openly with the community. For protocols, this means clear guidance to strengthen security posture and a credible way to signal trustworthiness to users, investors, and insurers. Currently in pilot with full rollout planned for 2026, this talk introduces the certification framework and how protocols and security firms can get involved. Presented by Isaac Patka, initiative lead.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "7PJGJV", "name": "Isaac Patka", "avatar": null, "biography": null, "public_name": "Isaac Patka", "guid": "ed057462-c267-53af-ab62-ea883dc098f1", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/7PJGJV/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/JNGY3E/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/JNGY3E/", "attachments": []}, {"guid": "86a6dccc-85d7-53ec-8053-b3e00cc0c862", "code": "UVLUSC", "id": 89205, "logo": null, "date": "2026-02-16T13:20:00-07:00", "start": "13:20", "end": "2026-02-16T13:40:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-89205-trafficked-trust-the-human-cost-of-crypto-scams", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/UVLUSC/", "title": "Trafficked Trust: The Human Cost of Crypto Scams", "subtitle": "", "track": "Lessons Learned", "type": "Short Talk", "language": "en", "abstract": "We often analyze the \"social engineering\" behind cryptocurrency fraud, but we rarely discuss the coercion that powers it. Trust is manufactured at gunpoint in scam compounds around the world.\n\nThis talk exposes the reality of the industrialized criminality, where human trafficking fuels the global theft of digital assets.\n\nWe will trace the operation from the ground up: from the fake job ads that entrap the workforce to physical compounds like those in Myanmar where victims are forced to execute the fraud.\n\nDrawing on active field intelligence and exclusive documentary footage, we will map the full cycle of the crime. This is a look at how criminal syndicates have weaponized human captivity to exploit the cryptocurrency ecosystem.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "SVQP3F", "name": "dobs", "avatar": null, "biography": null, "public_name": "dobs", "guid": "2a3c3c36-24a4-551c-8322-60ef4c415445", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/SVQP3F/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/UVLUSC/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/UVLUSC/", "attachments": []}, {"guid": "7a5da98c-99ad-5103-b33f-3ea62bf5f839", "code": "DTHPTP", "id": 86679, "logo": null, "date": "2026-02-16T13:40:00-07:00", "start": "13:40", "end": "2026-02-16T14:00:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-86679-thedao-security-fund", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/DTHPTP/", "title": "TheDAO Security Fund", "subtitle": "", "track": "New Announcements", "type": "Short Talk", "language": "en", "abstract": "I want to introduce the fund to gather awareness!\n\nThere was some left over funding in TheDAO (Over 70k ETH) and we want to use it to fund ETH Security projects!", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "99SWMF", "name": "Griff Green", "avatar": "https://darkmode.securityalliance.org/media/avatars/99SWMF_Y7wRlQo.webp", "biography": "I\u2019ve been a well known member of the Ethereum community since 2015 & received the first degree ever given in digital currency, a Masters degree in 2016. \n\nAs community manager for Slock.it and TheDAO, I helped form the community around TheDAO and led every angle of the crisis response effort following TheDAO Hack. I co-founded the White Hat Group, which secured the at-risk funds (10% of the total supply of ETH) during TheDAO hack and one year later rescued $210 million dollars worth of crypto assets following the Parity Multisig Hack among other exploits. I also audited Aragon and MakerDAO systems with the WHG.\n\nIn 2016 I co-founded Giveth, a crypto donation platform that radically empowers individuals and communities to affect real change in a transparent, decentralized way. I co-founded DAppNode in early 2018 and co-founded the Commons Stack in 2019. The Commons Stack launched the Token Engineering Commons in 2022. I co-founded General Magic in 2021, a web3 design and dev studio focused on web3 impact projects. Via GM I led the creation of Praise (reputation tool), and Pairwise (voting tool), Unicorn.eth (simple and safe wallet infra); and q/acc (token launchpad). I am currently spearheading an effort to create a $300M Ethereum security fund.\n\nI have contributed to dozens of other projects as well, most notably, BrightID, Treegens, and Thrive and support these and many other projects in an advisory capacity. \n\nI am a top delegate for ENS, Arbitrum, Gitcoin and Optimism, and sit on the Security Council for ENS and Arbitrum and on the bridge multisig for Gnosis.\n\nI also have led/co-led 3 crypto focused burning man camps Decentral, Dogecentral and BlockHaus ;-)", "public_name": "Griff Green", "guid": "d8db4c57-db70-5dba-9003-7d76e8f10b60", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/99SWMF/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/DTHPTP/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/DTHPTP/", "attachments": []}, {"guid": "24256031-a232-5ed3-8bcc-fac0c135eda4", "code": "AZ77PD", "id": 88140, "logo": null, "date": "2026-02-16T14:10:00-07:00", "start": "14:10", "end": "2026-02-16T14:30:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-88140-the-cpimp-backdoor-anatomy-of-a-multi-chain-proxy-attack", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/AZ77PD/", "title": "The CPIMP Backdoor: Anatomy of a Multi-Chain Proxy Attack", "subtitle": "", "track": "Vulnerability Disclosure", "type": "Short Talk", "language": "en", "abstract": "A deep dive into the CPIMP vulnerability\u2014how a stealthy proxy-in-the-middle attack infected dozens of DeFi protocols across chains, embedded persistent backdoors, and how Dedaub and SEAL 911 raced to neutralize it before widespread exploitation.", "description": "This talk unpacks the CPIMP (Clandestine Proxy In the Middle of Proxy) attack, a stealthy, highly sophisticated DeFi vulnerability that threatened millions of dollars across dozens of protocols and multiple EVM chains.\n\nCPIMPs masqueraded as legitimate proxy contracts while embedding persistent backdoors, often lying dormant for months until optimal conditions arose. The attacker employed advanced evasion techniques, including spoofed events, dummy storage writes, and aggressive anti-recovery logic, successfully deceiving common analysis workflows and even public explorers.\n\nWe\u2019ll walk through how Dedaub reverse-engineered the attack, identified affected deployments, and led a coordinated, multi-chain mitigation effort through SEAL 911. The session distills practical lessons on detecting deeply hidden threats, responding under time pressure, and maintaining continuous monitoring across chains.", "recording_license": "", "do_not_record": false, "persons": [{"code": "U9HBS7", "name": "Neville Grech", "avatar": "https://darkmode.securityalliance.org/media/avatars/U9HBS7_ilza0nc.webp", "biography": "Dr. Neville Grech is a white-hat hacker with 15 years of experience in software engineering, security, and program analysis, and the lead author of MadMax. He is a co-founder of Dedaub and has spoken at events such as Web3 Summit and ETHTaipei, presenting how decompilation and static analysis uncover hidden smart contract vulnerabilities across EVM chains.", "public_name": "Neville Grech", "guid": "d4fb212d-6e6f-59ab-99d9-66cbefcf08e5", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/U9HBS7/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/AZ77PD/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/AZ77PD/", "attachments": []}, {"guid": "b8fa0793-76db-5a06-bed0-cf29c9f5a745", "code": "PBPFE3", "id": 88332, "logo": null, "date": "2026-02-16T14:30:00-07:00", "start": "14:30", "end": "2026-02-16T15:15:00-07:00", "duration": "00:45", "room": "Auditorium", "slug": "darkmode-2026-88332-stopping-the-rubber-hose-attack-hot-takes", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/PBPFE3/", "title": "Stopping the Rubber Hose Attack: Hot Takes", "subtitle": "", "track": "Hot takes", "type": "Panel", "language": "en", "abstract": "Home invasions and physical attacks to get crypto transfers are all too common, and have led to grim situations. With all the factors, passphrase and biometrics in the world, people remain susceptible to the rubber hose. This panel will discuss theories and practices for defending against a rubber hose attack, through deterrence, defenses and mitigations.  We will start with the assumption that the goal is to preserve life and limb, and preventing or reversing token transfer is secondary, but how to get there, and be reasonably confident that it will not backfire, is hard.", "description": "The panel will provide their hot takes and deep wisdom on these questions:\nHow do we increase the attackers costs and risks, and reduce the odds of profit?\nWhat methods can prevent/slow/reduce fund transfer can be done safely, without undue risk? \nWould you rather a remote multisig that would never sign if your under duress, or would sign to pay the ransom?\nWhat methods to bring help (police/private security) can help with safety, with undue risk\nHow can we establish norms and widely held understandings to create a disincentive for the attacker to try?\nHow can one hide their holdings from the public in a transparent blockchain world?\nWhat can we learn from the history with fiat, where home invasion and the rubber hose is not as frequent\n\tNot common in CashApp/Venmo/Wires etc. \n\tKidnapping for fiat ransom is an analogy, usually target very wealthy\n\tShorter term kidnapping for a ride to ATMs\nCan you tech your way out of the problem by being super clever?\n\tDummy accounts, honey pots, tainted transfers", "recording_license": "", "do_not_record": false, "persons": [{"code": "JNEGCA", "name": "smagdali", "avatar": "https://darkmode.securityalliance.org/media/avatars/JNEGCA_USiCyMR.webp", "biography": "Most recently, Stef spent 3.5 years as Head of Technical Programs at the Filecoin Foundation, with responsibility for security, UX, and funding initiatives across the Filecoin ecosystem, including supporting SEAL.\n\nPrior to joining Filecoin Foundation, Stefan Magdalinski spent 30 years building internet companies and non-profits, as a CEO, COO and CTO, across multiple sectors in the UK, USA, Africa and Asia.\n\nHe is a founder of the Open Rights Group (https://openrightsgroup.org), and a veteran of the OG Crypto Wars in the UK. He is passionate about making the web work for the benefit of everybody, and worries about harms to consumers, above all.", "public_name": "smagdali", "guid": "4b3ffdd4-182e-5dcb-8bc9-86670fd98223", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/JNEGCA/"}, {"code": "8SBCGH", "name": "Kurt Opsahl", "avatar": "https://darkmode.securityalliance.org/media/avatars/8SBCGH_Q2RizUZ.webp", "biography": "Kurt Opsahl is the Associate General Counsel for Cybersecurity and Civil Liberties Policy for the Filecoin Foundation. Opsahl has been working for close to 30 years on technology law and policy, representing Internet startups in the dot-com boom, protecting digital rights at the Electronic Frontier Foundation, and now focusing on protecting the decentralized web. Opsahl volunteers as the President of the Security Research Legal Defense Fund, Special Counsel for EFF, and on the board of the Financial Privacy Foundation.  Formerly, Opsahl was the Deputy Executive Director and General Counsel of the EFF, and litigated key cases, protecting civil liberties online. Opsahl was also the lead attorney defending security researchers at EFF;s Coders' Rights Project, and continues to assist EFF with that work as Special Counsel.  From 2014 -22, Opsahl served on the USENIX Board of Directors, and a member of the CISA Cybersecurity Advisory Committee\u2019s Technical Advisory Council from 2023-24.", "public_name": "Kurt Opsahl", "guid": "053edfae-b35b-5930-a3b3-6a52f8ea74f0", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/8SBCGH/"}, {"code": "KQEMNR", "name": "Elliot", "avatar": "https://darkmode.securityalliance.org/media/avatars/KQEMNR_Ff5Jpon.webp", "biography": "Elliot is a smart contract security engineer and the principal at Solidity Labs. Over seven years he has deployed 67+ production contracts securing more than $2 billion in TVL, with zero losses. He built Forge Proposal Simulator, a governance security tool widely adopted across DeFi, and Kleidi, a timelock-based self-custody system built to defend against attacks that multisigs can't stop. He contributes to SEAL Frameworks and speaks about software and operational security at industry conferences.", "public_name": "Elliot", "guid": "9b5e7448-9196-5408-84af-143c704bd0e6", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/KQEMNR/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/PBPFE3/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/PBPFE3/", "attachments": []}, {"guid": "169ab5d7-2fb7-5932-ac8d-dcedbab9f799", "code": "9YPLDE", "id": 88242, "logo": null, "date": "2026-02-16T15:15:00-07:00", "start": "15:15", "end": "2026-02-16T15:35:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-88242-bypassing-cloaking-when-hunting-phishing-sites", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/9YPLDE/", "title": "Bypassing Cloaking when Hunting Phishing Sites", "subtitle": "", "track": "Lessons Learned", "type": "Short Talk", "language": "en", "abstract": "Wallet Drainers and other forms of phishing try to hide from security systems designed to catch them. \n\nFrom Query param keys, to fake blog posts, and time limited attacks, there are many ways that scammers hide their sites from detection and blocklisting.\n\nIn this talk we will go over the latest cloaking techniques these sites use, approaches to bypassing cloaking, and some unsolved problems that will spark ideas.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "MWTGWN", "name": "Nikita Varabei", "avatar": "https://darkmode.securityalliance.org/media/avatars/MWTGWN_fq0vgBp.webp", "biography": "Nikita is the CEO and co-founder of ChainPatrol. After working at Coinbase, Nikita started ChainPatrol to protect users from phishing attacks. Today ChainPatrol protects leading Web3 communities including Consensys, Arbitrum, ZkSync, Polymarket, and many more. ChainPatrol develop systems to crawl domains and social media to identify and takedown phishing.\n\nNikita has given numerous Security presentations in the past 4 years to the wider crypto ecosystem. \n\n- DSS 2025 Security Talk\n- Security Panel at DevConnect 2023 User Security Summit\n- Multiple Metamask Event Security Talks\n- Speaker at Eth Denver 2023\n- ETH NYC Finalist and Presenter 2022", "public_name": "Nikita Varabei", "guid": "b4de42dc-6b3a-55a9-ab64-9605fb9d36b9", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/MWTGWN/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/9YPLDE/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/9YPLDE/", "attachments": []}, {"guid": "27467282-9549-5ad9-b3e3-1829ac55c09d", "code": "JQBPDF", "id": 85939, "logo": null, "date": "2026-02-16T15:35:00-07:00", "start": "15:35", "end": "2026-02-16T15:55:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-85939-mastering-security-through-simple-machines-how-consistency-not-complexity-drives-innovation", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/JQBPDF/", "title": "Mastering Security through Simple Machines: How Consistency, Not Complexity, Drives Innovation", "subtitle": "", "track": "Hot takes", "type": "Short Talk", "language": "en", "abstract": "In the security industry, we often take well-established development practices, such as the DevOps infinity loop, add a layer of security, and label it \"DevSecOps.\" However, this approach frequently overlooks a critical issue: layering complex security processes onto efficient development processes can create inefficiency. In this talk, I argue that true innovation in security comes not from tooling or automation alone, but from mastering the underlying process first. By drawing an analogy to simple machines \u2014 where incremental improvements led to the evolution of tools like levers, wheels, and pulleys \u2014 I will illustrate how optimizing foundational processes leads to scalable, effective security practices. Attendees will leave with practical insights on reducing inefficiencies and fostering consistent improvement in their security workflows.", "description": "**1. Introduction: The Problem with Complexity in Security**\n\n- The security industry often adopts development frameworks, such as DevOps, and layers security onto them, creating frameworks like DevSecOps.\n- The issue: security processes are frequently complex and inefficient compared to streamlined development processes.\n- Key point: You can't automate something that is inefficient. Applying generative AI or advanced tooling to broken processes won\u2019t fix them.\n- Outcome: This leads to frustration, bottlenecks, and unmet security goals.\n\n**2. The Analogy: Security Processes as Simple Machines**\n\n- Introduction to simple machines: lever, wheel, pulley, etc.\n- Simple machines represent fundamental tools that evolve through mastery and incremental improvement.\n- Just as a lever becomes more efficient when transformed into a wheel or pulley, security processes must evolve through optimization.\n- Example: A long, inefficient SAST (Static Application Security Testing) scan taking two days doesn\u2019t fit into a two-week sprint. Simply automating it doesn\u2019t solve the problem; instead, the process itself must be optimized.\n\n**3. Evolution of Security Processes through Consistency and Optimization**\n\n- Consistency is key: innovation stems from mastery and consistent refinement, not from one-time application of advanced tools.\n- Case study: Improving SAST scans\n    - Initial state: A full SAST scan that takes two days to complete.\n    - Optimization: Breaking the scan into targeted components, running incremental scans, or using real-time feedback tools.\n    - Result: A faster, more efficient process that integrates seamlessly into the development lifecycle.\n- Key takeaway: The goal is not to add complexity but to create efficiency through iteration.\n\n**4. The Futility of Applying AI to Broken Processes**\n\n- Generative AI and other advanced technologies can enhance efficient processes but cannot fix broken ones.\n- Example: Applying AI to prioritize vulnerabilities from an inefficient scanning process will still result in a flood of low-value alerts.\n- Solution: Fix the underlying process first, then enhance it with automation and AI.\n\n**5. Practical Steps to Achieve Process Mastery**\n\n- Identify inefficiencies: Audit current security processes to find bottlenecks and pain points.\n- Apply incremental improvements: Start with small changes and measure their impact.\n- Leverage automation only after optimization: Use tools to enhance an already efficient process.\n- Foster a culture of continuous improvement: Encourage teams to regularly review and refine processes.\n\n**6. The Path Forward: Consistency as a Driver of Innovation**\n\n- Innovation doesn\u2019t come from adding complexity; it comes from consistently improving simple, well-understood processes.\n- Just as simple machines evolved over time into more complex but efficient systems, security processes must evolve through incremental mastery.\n- Final analogy: A poorly applied lever remains inefficient regardless of how much force is applied; a well-crafted pulley system, however, can lift tremendous weight with minimal effort.\n\n**7. Key Takeaways for the Audience**\n\n- Stop trying to automate inefficiency: Focus on optimizing the underlying process first.\n- Consistency drives innovation: Regular, incremental improvements lead to breakthroughs.\n- Simplicity is powerful: Don\u2019t overcomplicate security; instead, seek mastery of foundational processes.\n\n**8. Closing Thoughts and Call to Action**\n\n- Challenge to attendees: Audit one core security process in your organization and identify an inefficiency. Implement one small, consistent change and measure the impact.\n- Final words: True security innovation comes not from flashy tools but from mastering the basics and improving them consistently over time.", "recording_license": "", "do_not_record": false, "persons": [{"code": "87TMW7", "name": "Ken Toler", "avatar": "https://darkmode.securityalliance.org/media/avatars/87TMW7_ZS4jiAg.webp", "biography": "Ken is the Head of Security at Filecoin Foundation and a security practitioner that focuses on software security from applications, to cloud and web3 technologies. He is also the host and producer of Relating to DevSecOps, a podcast focused on cultivating security relationships in organizations. With 15+ years of experience in the security industry, he has had the opportunity to serve in many roles from hacking on governments to building robust security programs from the ground up. In his spare time, he builds drones, sings karaoke, and makes things out of wood.", "public_name": "Ken Toler", "guid": "6952c397-12d4-570b-a419-4dc3b3af403e", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/87TMW7/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/JQBPDF/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/JQBPDF/", "attachments": []}, {"guid": "101c0c01-6826-581e-8213-206be44d4b72", "code": "NYFCXC", "id": 87763, "logo": null, "date": "2026-02-16T15:55:00-07:00", "start": "15:55", "end": "2026-02-16T16:15:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-87763-security-between-the-code-why-technical-excellence-can-fail", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/NYFCXC/", "title": "Security Between the Code: Why Technical Excellence Can Fail", "subtitle": "", "track": "Lessons Learned", "type": "Short Talk", "language": "en", "abstract": "Security exploits in decentralised systems are rarely caused by technical failures alone. Instead, they emerge at the edges between code, incentives, and institutions - where authority is informal, coordination is improvised, and legitimacy is contested.\n\nDrawing on multi-year ethnographic research embedded in decentralised security communities and real world experience in security practices, this talk reframes security as a socio-technical phenomenon: one sustained not only by protocols and tools, but by moral codes, information practices, incentive structures, and cross-institutional coordination. While the ecosystem is still (rightly) investing heavily in technical interventions (such as improved wallets and developer tooling), many high-impact dynamics remain under-acknowledged, including white-hat incentives, incident information formats, coordination with traditional authorities, and the physical and organisational realities of security work.\n\nThe presentation outlines key findings from a forthcoming book on blockchain security, followed by a practitioner response and Q&A with Matta from The Red Guild, who works daily on frontline interventions including phishing education, operational security guidance, and adversarial response. Together, the session bridges analytical diagnosis with operational reality, offering security professionals a clearer map of the system they already inhabit\u2014and a basis for thinking differently about where leverage actually lies, and what needs to be done to improve the state of blockchain security.", "description": "Purpose and Value\n\nThis presentation is designed to respect the time and expertise of security professionals. It does not seek to explain technology to technologists, nor to moralise security practice. Instead, it aims to:\n\nReframe familiar problems with analytical clarity\n\nSurface high-impact dynamics that are widely experienced but rarely formalised\n\nOffer a shared language for discussing coordination, incentives, and legitimacy in decentralised security\n\nThe primary objective is practical: to provide conceptual tools that help practitioners better understand why certain security interventions succeed, stall, or repeatedly re-emerge in new forms.\n\nAudience: Security engineers and incident responders\n\nSecurity researchers and threat-intelligence professionals\n\nProtocol teams and infrastructure operators\n\nPolicy and governance specialists engaging decentralised systems\n\nOther presenter: Matta, The Red Guild", "recording_license": "", "do_not_record": false, "persons": [{"code": "FWSLVP", "name": "Kelsie Nabben", "avatar": "https://darkmode.securityalliance.org/media/avatars/FWSLVP_79KNPkS.webp", "biography": "Dr Kelsie Nabben is an ethnographic researcher specialising in the social outcomes of emerging technologies, particularly decentralised digital infrastructure. Her Open Access book on blockchain security, titled 'Decentralised Security: Code, crisis, community', comes out in 2026", "public_name": "Kelsie Nabben", "guid": "b4c4ceda-5cc2-5457-a659-228183c5e2cf", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/FWSLVP/"}, {"code": "RB7LHX", "name": "matta", "avatar": "https://darkmode.securityalliance.org/media/avatars/RB7LHX_eNoU53i.webp", "biography": "founder @theredguild\ninitiative lead @seal\nsecurity knowma", "public_name": "matta", "guid": "a9c02146-95d3-5053-88e8-a7e93d940b90", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/RB7LHX/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/NYFCXC/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/NYFCXC/", "attachments": []}, {"guid": "856f73c4-0e71-5b0d-863b-2eda33b9efa7", "code": "DQ3T8W", "id": 87916, "logo": null, "date": "2026-02-16T16:15:00-07:00", "start": "16:15", "end": "2026-02-16T17:00:00-07:00", "duration": "00:45", "room": "Auditorium", "slug": "darkmode-2026-87916-why-your-multisig-won-t-save-you-attacks-against-high-value-holders", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/DQ3T8W/", "title": "Why Your Multisig Won't Save You: Attacks Against High-Value Holders", "subtitle": "", "track": "New Announcements", "type": "Long Talk", "language": "en", "abstract": "Multisig wallets give holders a false sense of security. The real attack surface isn't key compromise, it's all of the human and non-deterministic elements. Spoofed simulations, poisoned addresses, compromised frontends, and coerced signers all exploit the same gap. Users don't know what they're signing, and by the time they find out something is wrong, it's already too late. This talk introduces a threat model for high-value custody and presents Kleidi, a wallet system built around reversibility, configurable policies, and guardian-based recovery.", "description": "Large crypto holders face well-resourced adversaries using attack vectors that multisig alone cannot address. This talk walks through six categories of threat: simulation spoofing, address poisoning, frontend compromises, supply chain attacks, insider threats, and kidnapping or duress scenarios.\n\nEach attack exploits a common weakness: the finality of signed transactions and the opacity of what's actually being approved. We'll examine real incidents, break down why existing solutions fail, and introduce a defense framework centered on post-signature review windows and cancellation authority.\n\nThe session concludes with a demonstration of Kleidi, a wallet implementation that operationalizes this framework through timelocks, policy engines, and guardian services. Attendees will leave with a threat model they can apply to custody architecture reviews and a concrete reference for how reversibility changes the security calculus.", "recording_license": "", "do_not_record": false, "persons": [{"code": "KQEMNR", "name": "Elliot", "avatar": "https://darkmode.securityalliance.org/media/avatars/KQEMNR_Ff5Jpon.webp", "biography": "Elliot is a smart contract security engineer and the principal at Solidity Labs. Over seven years he has deployed 67+ production contracts securing more than $2 billion in TVL, with zero losses. He built Forge Proposal Simulator, a governance security tool widely adopted across DeFi, and Kleidi, a timelock-based self-custody system built to defend against attacks that multisigs can't stop. He contributes to SEAL Frameworks and speaks about software and operational security at industry conferences.", "public_name": "Elliot", "guid": "9b5e7448-9196-5408-84af-143c704bd0e6", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/KQEMNR/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/DQ3T8W/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/DQ3T8W/", "attachments": []}]}}, {"index": 2, "date": "2026-02-17", "day_start": "2026-02-17T04:00:00-07:00", "day_end": "2026-02-18T03:59:00-07:00", "rooms": {"Auditorium": [{"guid": "17b8c46b-cb41-5999-b99b-bbe00ff3227f", "code": "7FKKPQ", "id": 90733, "logo": null, "date": "2026-02-17T09:30:00-07:00", "start": "09:30", "end": "2026-02-17T10:15:00-07:00", "duration": "00:45", "room": "Auditorium", "slug": "darkmode-2026-90733-when-agents-get-tools-security-for-autonomous-systems", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/7FKKPQ/", "title": "When Agents Get Tools: Security for Autonomous Systems", "subtitle": "", "track": "Hot takes", "type": "Panel", "language": "en", "abstract": "Autonomous agents are moving from experiment to infrastructure. They're sharing tools, communicating with each other, and increasingly operating with real money. But the security conversation hasn't caught up. What happens when an agent gets compromised through shared tooling? How do you lock down something designed to act independently? And when agents need wallets to function, what does crypto security teach us about protecting them?", "description": "Agents are everywhere now. They're in our workflows, they're talking to each other, and some of them have wallets. Most conversations about this are either hype or hand-wraving. This one won't be.\nWe've assembled panelists who genuinely disagree on where the risks are and how to handle them. Some think crypto's hard-won security lessons translate directly. Others aren't convinced. Some see agent-to-agent communication as the real threat vector. Others worry more about what happens when an agent can spend money without asking.\n\nWe'll get into the uncomfortable questions. Can an agent be socially engineered? If one agent infects another through shared tooling, whose problem is that? When autonomy is the feature, how do you even define containment? And can we flip the script entirely, using adversarial agents as security tools rather than threats?\n\nNo consensus guaranteed. Come ready to think.", "recording_license": "", "do_not_record": false, "persons": [{"code": "SBTKVC", "name": "Consensys Diligence", "avatar": "https://darkmode.securityalliance.org/media/avatars/SBTKVC_0Yi5vsD.webp", "biography": "Consensys Diligence is a security research team that's been auditing smart contracts since Ethereum's earliest days. Eight years of institutional memory, hundreds of audits, and a front-row seat to every major evolution in Web3 security. Our aim isn't to be the biggest shop, but the most thorough one. Our work spans protocol auditing, tool development, and ongoing research into emerging threat patterns. We believe security is a continuous process, not a checkbox, and we're committed to sharing what we learn with the broader community.", "public_name": "Consensys Diligence", "guid": "e88a213e-51e4-5ee2-87f5-74990b58ae23", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/SBTKVC/"}, {"code": "BYYCY7", "name": "Andrew MacPherson (AndrewMohawk) '<#<h1>", "avatar": "https://darkmode.securityalliance.org/media/avatars/BYYCY7_Ekzxml4.webp", "biography": "Andrew has been breaking, building, and defending things in infosec for over two decades (wow old). Starting at Paterva he spent 10+ years creating Maltego before moving to the US for security roles at BitMEX (IR), Robinhood (IR/D&R), Uniswap (Head of Security), and now Privy (Principal Security Engineer). He\u2019s spoken at Black Hat, DEF CON, DSS, EthCC and countless others, teaching courses and drinking malibu on the way. When not thinking about security, he\u2019s into cat memes, punk rock, and getting involved in just the right amount of unhinged shit to keep security interesting.", "public_name": "Andrew MacPherson (AndrewMohawk) '<#<h1>", "guid": "c219c69f-7dc5-5505-9f32-129d06b9dfe9", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/BYYCY7/"}, {"code": "NKP9PY", "name": "Alex Stokes", "avatar": null, "biography": null, "public_name": "Alex Stokes", "guid": "ec118d18-f9be-573b-be78-9a0309dbfa07", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/NKP9PY/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/7FKKPQ/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/7FKKPQ/", "attachments": []}, {"guid": "7ab7bc1f-43ac-5f3c-8f12-3f7539334a5e", "code": "KL3EBP", "id": 88231, "logo": null, "date": "2026-02-17T10:15:00-07:00", "start": "10:15", "end": "2026-02-17T10:35:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-88231-llm-auditing-better-than-cats", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/KL3EBP/", "title": "LLM Auditing, Better Than Cats?", "subtitle": "", "track": "Hot takes", "type": "Short Talk", "language": "en", "abstract": "Everyone and their mother is trying to launch an AI auditing tool (usually meaning an LLM-based auditing tool). Do they perform any better than cats at auditing? Do they fill the same market purpose as auditing? This talk will take a praxeological approach to the question (as opposed to an empirical/scientific approach), so buckle up for some half-baked un-substantiated opinions! Mixed in will be some things I do think LLMs are good for in the auditing process, and some ideas of other approaches that may work better (some even being taken by some teams already).", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "8AQGSU", "name": "Everett Hildenbrandt", "avatar": null, "biography": "Everett Hildenbrandt has spent over 6 years leading the technical direction for RV's software tooling. He is passionate about providing high-quality and consistent developer tooling for all programming languages that emphasizes usability and power. In his journey from studying physics to working on validating the safety of distributed Web3 applications, he's seen that formal methods can play a crucial role in improving the quality of software for everyone. During his time at RV, he's driven broader adoption of formal verification through both education and bringing the verification tooling to the developers via improved UX.", "public_name": "Everett Hildenbrandt", "guid": "af986815-3ff3-578d-bb2f-91160dfb00da", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/8AQGSU/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/KL3EBP/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/KL3EBP/", "attachments": []}, {"guid": "1ba2c10f-6512-5a1e-b8b2-41c46031dd5a", "code": "JZASGB", "id": 88288, "logo": null, "date": "2026-02-17T10:35:00-07:00", "start": "10:35", "end": "2026-02-17T10:55:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-88288-co-auditing-with-ai-practical-techniques", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/JZASGB/", "title": "Co-Auditing With AI: Practical Techniques", "subtitle": "", "track": "Lessons Learned", "type": "Short Talk", "language": "en", "abstract": "Smart-contract security has reached a scale where purely manual review no longer keeps pace.  However, fully automated AI auditors may miss context, intent, and threat models that experienced reviewers take for granted.\nThis talk showcases how one can integrate agent-style AI tools directly into their audit workflows to accelerate personal reasoning and amplify each auditor's individual expertise.", "description": "This talk shares how we use AI agents as co-auditors to amplify individual reviewers, not replace them. We focus on a practical framework built inside our audit workflow:\n\n- **Tool-aware agents** that can invoke hard technical tools - static analyzers, code mappers, and protocol helpers -  rather than rely on raw text prompting.\n\n- **Primer-driven behavior**, where auditors define how the agent should think, interpret code, and execute repeatable methodology across domains like lending, staking, and accounting.\n\n- **Artifact generation** that persists throughout the engagement - from initial scoping and code mapping to end-stage issue drafting - allowing humans and the agent to build on shared context as the audit progresses.\n\nThe core idea is that these systems let auditors bring their own expertise into the workflow. Teams can create private primers, encode their specialties, and optionally share them with the broader community to lift everyone\u2019s capability. The goal is a future where every auditor can use AI to multiply the value of their own judgment - without ceding control to automation.", "recording_license": "", "do_not_record": false, "persons": [{"code": "N3SU8V", "name": "George Kobakhidze", "avatar": "https://darkmode.securityalliance.org/media/avatars/N3SU8V_5RoJyI0.webp", "biography": "A security researcher at Consensys Diligence, George is fascinated by Math, Technology, and their human aspects - privacy, game theory, digital identity, and so on. Eventually he found Ethereum, a promising world that fit his interests, where he focuses on audits to safeguard the future of finance.", "public_name": "George Kobakhidze", "guid": "ac090978-fb07-50e1-bd0e-87d337347685", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/N3SU8V/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/JZASGB/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/JZASGB/", "attachments": []}, {"guid": "60154886-9342-500d-9fcf-c2dceeed2d5e", "code": "G7B9P8", "id": 89735, "logo": null, "date": "2026-02-17T10:55:00-07:00", "start": "10:55", "end": "2026-02-17T11:40:00-07:00", "duration": "00:45", "room": "Auditorium", "slug": "darkmode-2026-89735-from-vibes-to-vulnerabilities", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/G7B9P8/", "title": "From vibes to vulnerabilities", "subtitle": "", "track": "Vulnerability Disclosure", "type": "Long Talk", "language": "en", "abstract": "I am not a vuln researcher and that's kind of the point, LLMs have come a long way in the cyberz. I tried to find a real RCE with Codex, I failed so badly that I accidentally learned how to find bugs in common projects with LLMs. This talk is about using AI to turn bad vibes into real bugs. Drawing on multiple CVEs across React, Node, Ollama, Wordpress, etc and other projects, I'll show how anyone with a little debugging and security knowledge can go from vibes to vulnerabilities", "description": "This talk starts from a failure. As a long time blue team practitioner with no vulnerability research background, I tried to use OpenAI Codex to find a real-world RCE that had just dropped\u2014and got absolutely nowhere. What followed was confusion, false positives, and confidently wrong model output. But once I stopped treating Codex like a one-shot bug oracle and started using it as a deeply opinionated debugging assistant, things began to click.\n\nThe session walks through how I used \u201cvibes\u201d to find vulnerabilities: from being the annoying kid in the back seat asking \u201cwhy?\u201d a hundred times, to forcing the model to reason more deeply about code paths, assumptions, and edge cases until something real fell out. I'll walk through the pain and the pleasure of using LLMs for vulnerability discovery, including how this approach led to real findings across projects like React, Node, Ollama, Tethers Password manager, wordpress, supabase, etc.\n\nWe'll talk candidly about where models get stuck, how to work around refusals, why the dumbest ideas sometimes work best, and just how creative\u2014and unhinged\u2014you can get when you stop trusting the model and start interrogating it. I'll also show how this fundamentally changes offensive capability and why it feels like red teams are about to get a serious advantage.\n\nThe talk closes with a sober look at the current limitations, the risks, and the broader impact on the security community. The goal isn't to teach exploit development, but to show that with basic debugging skills and the right guardrails, AI can meaningfully assist in finding real vulnerabilities\u2014and dramatically lower the barrier to entry for vulnerability research.", "recording_license": "", "do_not_record": false, "persons": [{"code": "BYYCY7", "name": "Andrew MacPherson (AndrewMohawk) '<#<h1>", "avatar": "https://darkmode.securityalliance.org/media/avatars/BYYCY7_Ekzxml4.webp", "biography": "Andrew has been breaking, building, and defending things in infosec for over two decades (wow old). Starting at Paterva he spent 10+ years creating Maltego before moving to the US for security roles at BitMEX (IR), Robinhood (IR/D&R), Uniswap (Head of Security), and now Privy (Principal Security Engineer). He\u2019s spoken at Black Hat, DEF CON, DSS, EthCC and countless others, teaching courses and drinking malibu on the way. When not thinking about security, he\u2019s into cat memes, punk rock, and getting involved in just the right amount of unhinged shit to keep security interesting.", "public_name": "Andrew MacPherson (AndrewMohawk) '<#<h1>", "guid": "c219c69f-7dc5-5505-9f32-129d06b9dfe9", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/BYYCY7/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/G7B9P8/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/G7B9P8/", "attachments": []}, {"guid": "96507c17-5b59-526c-abae-b4fabc423c88", "code": "ETHYXP", "id": 90865, "logo": null, "date": "2026-02-17T12:40:00-07:00", "start": "12:40", "end": "2026-02-17T13:00:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-90865-how-we-stop-north-korea-getting-away-with-the-next-billion-next-generation-of-security-professional-coordination-and-new-high-speed-threat-intel-network", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/ETHYXP/", "title": "How we stop North Korea getting away with the next Billion: Next generation of security professional coordination and new high speed threat intel network.", "subtitle": "", "track": "New Announcements", "type": "Short Talk", "language": "en", "abstract": "In the Bybit incident response, a lot went right. The ecosystem showed up, teams moved fast, and we used the tools at our disposal to trace flows and push actionable intelligence.\n\nBut there was also a lot that went wrong. Some parts of the ecosystem were not responsive to investigators. Despite their best efforts, law enforcement around the world, they simply did not have enough workforce to dedicate to supporting the freezes and litigation. No matter how fast investigators could post new addresses to freeze the stolen money, it would take hours or even days to be published and actionable. On the other hand, North Korea and collaborators were moving at the rapid speed of blockchain settlement, measured in seconds. Investigators were moving at human coordination and off-chain corporate and government speeds, measured in hours and days. We were always chasing.\n\nSo how do we work together to do better the next time? We need to fix both the people & company coordination and the high speed intelligence infrastructure to support that coordination.\n\nIn this presentation we will highlight the Coalition for Freezing & Recovering (SEAL & zeroShadow project) and showcase the launch of zeroShadow\u2019s new Threat Intelligence Platform (free critical infrastructure to all Web3 projects).\n\nzeroShadow Threat Intelligence Platform (zS TIP): a high-speed intel network built so real-time coordination doesn\u2019t depend on one-off channels. Trusted security teams can share vetted signals in real time, and VASPs receive those signals as they happen to make informed risk decisions quickly. From OFAC sanctioned addresses to the latest hacks and exploits, members will have access to this critical intelligence to stay safe, stay compliant, and be part of the solution to disrupt laundering and help return stolen assets to victims.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "WDERXJ", "name": "Casey G", "avatar": null, "biography": "CEO of zeroShadow", "public_name": "Casey G", "guid": "6a225d82-a419-5e31-80e9-a4e85eca220b", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/WDERXJ/"}, {"code": "3KP9BZ", "name": "Col G", "avatar": "https://darkmode.securityalliance.org/media/avatars/3KP9BZ_IrNs7qG.webp", "biography": "zeroShadow Co-founder | Head of Threat Intel", "public_name": "Col G", "guid": "0c9929cc-4192-5a6a-a76b-4c585be297d8", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/3KP9BZ/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/ETHYXP/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/ETHYXP/", "attachments": []}, {"guid": "d842ac91-930a-55c1-aed6-23ec3bd841bf", "code": "MLLQAQ", "id": 88182, "logo": null, "date": "2026-02-17T13:00:00-07:00", "start": "13:00", "end": "2026-02-17T13:45:00-07:00", "duration": "00:45", "room": "Auditorium", "slug": "darkmode-2026-88182-attack-chains-in-web3-lessons-from-multi-stage-web3-exploits", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/MLLQAQ/", "title": "Attack Chains in Web3: Lessons from Multi\u2011Stage Web3 Exploits", "subtitle": "", "track": "Lessons Learned", "type": "Long Talk", "language": "en", "abstract": "Most Web3 incidents aren\u2019t \u201cone bug, one drain\u201d anymore. Attackers increasingly chain weaknesses across layers such as legacy contracts, subtle numerical edge cases, protocol/bridge exit paths, and off-chain vendor exposure, into an exploit path that ends in irreversible loss. In this talk we'll take a look at some high-signal incidents from 2025 and discuss how to break attack chains before they reach funds. Lessons learned will include practical strategies that projects may adopt to build defense-in-depth that breaks attack chains.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "KRJRVE", "name": "Sebastian Banescu", "avatar": "https://darkmode.securityalliance.org/media/avatars/KRJRVE_FycsIWW.webp", "biography": "Dr. Sebastian Banescu is the founder of Adevar Labs, a security firm dedicated to hardening the Web3 ecosystem. With over 15 years in digital security and 7 years specifically in blockchain, his experience spans from securing industrial systems at BMW, Philips, and Deloitte to conducting over 100 smart contract audits since 2018. A former researcher with a PhD from TU Munich and over 1,200 citations on Google Scholar, Sebastian Banescu specializes in the intersection of formal verification and real-world exploit analysis. He notably founded the first regulated insurance company for smart contract risks, pioneering the use of actuarial standards in DeFi.", "public_name": "Sebastian Banescu", "guid": "6e9021de-24ef-59a9-b341-450a65b7c5da", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/KRJRVE/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/MLLQAQ/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/MLLQAQ/", "attachments": []}, {"guid": "2e49324d-f394-5277-84bb-aec21b20270a", "code": "BJJM8V", "id": 86785, "logo": null, "date": "2026-02-17T13:45:00-07:00", "start": "13:45", "end": "2026-02-17T14:05:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-86785-tradertraitor-a-real-bad-mata", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/BJJM8V/", "title": "TraderTraitor: A Real Bad MATA", "subtitle": "", "track": "Lessons Learned", "type": "Short Talk", "language": "en", "abstract": "TraderTraitor, also known as Jade Sleet, Slow Pisces, UNC4899, Dark River is the North Korean threat actor behind major cryptocurrency heists from ByBit, DMM, WazirX, CoinsPaid, Alphapo, Atomic Wallet, Horizon Bridge, Ronin Bridge, and many others. This presentation is a deep dive into TraderTraitor and will cover how they compromise their victims, how defenders and security teams can track TraderTraitor, and measures that organizations can take to protect themselves from being the next Bybit. This presentation will have non-public details about TraderTraitor activity.", "description": "North Korea loves stealing crypto. This presentation is a deep dive into TraderTraitor, North Korea's most effective hacking group. This presentation will explore how TraderTraitor compromises cryptocurrency exchanges, wallet service providers, and cloud companies in order to steal massive amounts of cryptocurrency including the ByBit heist where they walked away with $1.5 Billion worth of Ethereum. While TraderTraitor is incredibly effective at stealing cryptocurrency for North Korea, a few security measures can help protect your organization, and your service providers, from this threat actor.", "recording_license": "", "do_not_record": false, "persons": [{"code": "UJTGCS", "name": "Daniel Gordon", "avatar": "https://darkmode.securityalliance.org/media/avatars/UJTGCS_jDAt7cL.webp", "biography": "Daniel Gordon has over a decade of experience hunting, researching, tracking, and stopping North Korean hacking groups across both public and private sector. He has a bunch of degrees and certifications, and has published blogs for DarkReading, War on the Rocks, and Risky.biz and given talks on North Korean hacking at SleuthCon and FTSCon.", "public_name": "Daniel Gordon", "guid": "c19dbd84-7050-5617-b1bc-6bf8214ddb6d", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/UJTGCS/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/BJJM8V/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/BJJM8V/", "attachments": []}, {"guid": "3e164d41-16ad-56cd-94cf-0e68c434523d", "code": "QUX7KW", "id": 88136, "logo": null, "date": "2026-02-17T14:15:00-07:00", "start": "14:15", "end": "2026-02-17T14:35:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-88136-when-the-supply-chain-isn-t-chaining-stop-reinventing-the-wheel", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/QUX7KW/", "title": "When the Supply Chain Isn\u2019t Chaining: Stop Reinventing the Wheel", "subtitle": "", "track": "Lessons Learned", "type": "Short Talk", "language": "en", "abstract": "We keep seeing the same supply chain failures in crypto: compromised dependencies, leaked or abused publishing keys, and malicious or compromised contributors. These incidents are often framed as uniquely web3, leading teams to design bespoke trust models rather than adopt proven, well-understood security practices.\n\nFrom an attacker\u2019s perspective, none of this is new.\n\nOpen-source communities have spent years responding to these exact classes of supply chain attacks, resulting in concrete standards such as SLSA and ecosystem-level guidance and tooling from the OpenSSF. These approaches map directly to crypto development workflows, yet remain underutilized in practice. Instead, we repeatedly invent new frameworks, often increasing complexity without reducing risk.\n\nIn this talk, I\u2019ll walk through how we approach release system design at Anza, looking at the full development lifecycle through an adversarial lens. We\u2019ll identify where things commonly go wrong, how existing tools and frameworks already address these failure modes, and why reinventing the wheel in supply chain security frequently makes systems less secure, not more. I\u2019ll also cover emerging tooling like gittuf, which takes a fundamentally different approach to Git security and policy enforcement.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "VRQPTP", "name": "Nikita Belenkov", "avatar": null, "biography": "Nikita is a security engineer at Anza, a Solana-focused research and development firm behind the Agave validator client and core developer tooling, where he works on security across development, upgrades, and releases.\n\nBefore Anza, Nikita was a Senior Security Engineer at Quantstamp, where he contributed to and led protocol and infrastructure security reviews for major blockchain projects securing over $10B in assets, including TON, Alchemy, and Trust Wallet. He is a co-author of the ERC-6900 modular smart contract account standard and has published research on cross-chain bridge security. Nikita holds an MEng from Imperial College London and co-founded the Imperial Blockchain Group.", "public_name": "Nikita Belenkov", "guid": "fe6f1909-6104-5cef-abf5-b8196980f4d5", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/VRQPTP/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/QUX7KW/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/QUX7KW/", "attachments": []}, {"guid": "8d26c633-7d45-5aeb-b727-1834d2907ed0", "code": "URDMBC", "id": 87925, "logo": null, "date": "2026-02-17T14:35:00-07:00", "start": "14:35", "end": "2026-02-17T14:55:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-87925-lido-v3-security-by-design", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/URDMBC/", "title": "Lido V3: Security by Design", "subtitle": "", "track": "Other", "type": "Short Talk", "language": "en", "abstract": "Protocol security is shaped long before the first line of code is written. In this talk, Tomer Ganor, Tech Lead and Security Researcher at Certora, explores how Lido V3 combines security thinking with protocol design to reduce attack surfaces, prevent bugs, and strengthen the Ethereum infrastructure", "description": "Attendees will learn how protocol design decisions shape security outcomes and how security first architecture prevents entire classes of DeFi bugs", "recording_license": "", "do_not_record": false, "persons": [{"code": "JDSYA9", "name": "Tomer Ganor", "avatar": "https://darkmode.securityalliance.org/media/avatars/JDSYA9_SFhPFVS.webp", "biography": "I am a Tech Lead and Security Researcher at Certora with over three and a half years of experience securing DeFi protocols. I work closely with core protocol teams on security driven design and have contributed to the architecture of major Ethereum protocols including Aave and Lido and many more.", "public_name": "Tomer Ganor", "guid": "2241e812-e16b-56fe-9e62-4b6e2f538800", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/JDSYA9/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/URDMBC/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/URDMBC/", "attachments": []}, {"guid": "a5a17daf-fcef-5c91-a501-3ea6b023f30d", "code": "TT3GRQ", "id": 88116, "logo": null, "date": "2026-02-17T14:55:00-07:00", "start": "14:55", "end": "2026-02-17T15:40:00-07:00", "duration": "00:45", "room": "Auditorium", "slug": "darkmode-2026-88116-from-chaos-to-containment-making-incident-response-actually-work-in-the-digital-asset-economy", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/TT3GRQ/", "title": "From Chaos to Containment: Making Incident Response Actually Work in the Digital Asset Economy", "subtitle": "", "track": "Lessons Learned", "type": "Panel", "language": "en", "abstract": "Practical incidents + ops learning. Panel may also include \u201chot takes\u201d.\n\nCrypto incidents don\u2019t behave like traditional breaches. They unfold in minutes, span chains, and can cause infinite cascading damage along the way. Most teams are still improvising without training or realistic strategies in place. This panel brings together leading DeFi security teams to share practical incident lessons, working incident pipelines, and response playbooks that actually hold up under live attack conditions. \n\nThe outcome: practical insights, candid stories, and debate on what the industry must fix next.", "description": "Incident Response is where the digital economy defensive layer succeeds or fails, but it is still underdeveloped across the industry. This panel focuses on turning MDR/IR from a reactive approach into reliable operational capability.\n\nWe\u2019ll dig into:\nWhat the first 60 minutes of real incidents actually look like and why they matter\nHow teams are building MDR workflows that merge on-chain + off-chain telemetry\nHow playbooks and containment strategies can change the outcome\nWhat the industry consistently gets wrong about response today\nHow collaboration and threat intelligence meaningfully reduce impact\n\nAttendees will leave with actionable frameworks, hard-earned lessons, and new thinking on how we can collectively raise the baseline of defense in crypto.\n\nPanelists (proposed): representatives from Cantina, Hypernative, and ChainPatrol\nModerator: Mike Leffer, President of Cantina/Spearbit", "recording_license": "", "do_not_record": false, "persons": [{"code": "S7PWVL", "name": "Cantina", "avatar": "https://darkmode.securityalliance.org/media/avatars/S7PWVL_llaJsXl.webp", "biography": "Cantina and Spearbit work with financial services and blockchain organizations to protect the world's most critical and complex code by combining a world-class security researcher network with purpose-built tools, delivering scalable and effective solutions pre-deployment through runtime all in one platform.", "public_name": "Cantina", "guid": "98dfeff2-1770-5b7a-a216-6f50b430821e", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/S7PWVL/"}, {"code": "YK9ANL", "name": "Sharon Ideguchi", "avatar": "https://darkmode.securityalliance.org/media/avatars/YK9ANL_TmlRAtj.webp", "biography": "Sharon leads strategic product development and programming at Cantina, bringing bespoke security programs to teams across web3 and web2.", "public_name": "Sharon Ideguchi", "guid": "b118a4a3-ca6d-5b40-bebd-79181e572045", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/YK9ANL/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/TT3GRQ/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/TT3GRQ/", "attachments": []}, {"guid": "6af00cd7-3f9e-5ab6-bf9f-105cf5281f8a", "code": "THSJYH", "id": 88699, "logo": null, "date": "2026-02-17T15:40:00-07:00", "start": "15:40", "end": "2026-02-17T16:00:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-88699-crazy-chains-why-incident-response-breaks-outside-the-evm", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/THSJYH/", "title": "Crazy Chains: Why Incident Response Breaks Outside the EVM", "subtitle": "", "track": "Hot takes", "type": "Short Talk", "language": "en", "abstract": "Most incident response and chain analysis tooling is built with an implicit assumption: account-based execution risk is the problem. That assumption holds, until it doesn\u2019t.\n\nUsing Filecoin as a case study, this talk explores why many otherwise capable vendors struggle to support novel chains, and why gaps appear not because of neglect but because the mental model itself breaks down and product margins don't get in the way.\n\nFilecoin isn\u2019t a smart contract chain with storage bolted on. It\u2019s a distributed system designed to verify long-lived behavior across independent operators. The primary asset isn\u2019t just balance but it\u2019s behavior over time. The dominant risks may not necessarily exploits, but they're based in incentive failures, coordinated degradation, and economic edge cases.\n\nWe\u2019ll unpack what this means for incident response teams and why chain analysis and incident response platforms tend to miss the mark when stepping outside familiar ecosystems:\n\n- Why transaction-centric alerts miss slow-burn incidents\n- Why actor behavior matters more than bytecode inspection\n- Why \u201cthe incident\u201d often belongs to the network, not an app\n- Why generic EVM heuristics actively create false confidence and false positives\n\nTo be crystal clear this talk is not a critique of vendors, it\u2019s a lessons-learned hot take briefing from the field. Supporting novel chains requires different playbooks, different baselines, and a willingness to abandon security absolutism in favor of contextual risk analysis.\n\nThe key takeaway: if your incident response model can\u2019t reason about incentives, time, and roles, it will fail quietly on novel chains right up until the ecosystem feels the impact.\n\nThis session aims to help security teams recognize those limits early, adapt deliberately, and build coverage that actually reflects how decentralized infrastructure fails in practice.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "87TMW7", "name": "Ken Toler", "avatar": "https://darkmode.securityalliance.org/media/avatars/87TMW7_ZS4jiAg.webp", "biography": "Ken is the Head of Security at Filecoin Foundation and a security practitioner that focuses on software security from applications, to cloud and web3 technologies. He is also the host and producer of Relating to DevSecOps, a podcast focused on cultivating security relationships in organizations. With 15+ years of experience in the security industry, he has had the opportunity to serve in many roles from hacking on governments to building robust security programs from the ground up. In his spare time, he builds drones, sings karaoke, and makes things out of wood.", "public_name": "Ken Toler", "guid": "6952c397-12d4-570b-a419-4dc3b3af403e", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/87TMW7/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/THSJYH/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/THSJYH/", "attachments": []}, {"guid": "b2d89c5a-8584-5e61-992e-5374c950e18c", "code": "UX3RPF", "id": 88422, "logo": null, "date": "2026-02-17T16:00:00-07:00", "start": "16:00", "end": "2026-02-17T16:45:00-07:00", "duration": "00:45", "room": "Auditorium", "slug": "darkmode-2026-88422-web3-security-s-evolution-for-mainstream-adoption", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/UX3RPF/", "title": "Web3 Security's Evolution for Mainstream Adoption", "subtitle": "", "track": "Hot takes", "type": "Panel", "language": "en", "abstract": "As Web3 moves from niche experiments to institutional-grade infrastructure, our security models are hitting a tipping point. This panel explores how the industry is maturing to meet the demands of mainstream adoption without abandoning decentralization. We\u2019ll look at what\u2019s fundamentally shifting\u2014from the evolution of smart contract security and wallets to the critical rise of operational security (OpSec)\u2014and what remains immutable.", "description": "Mainstream adoption isn't just about better UI; it\u2019s about a fundamental shift in how we manage risk. This session brings together security architects from both the \"move fast\" world of DeFi and the \"zero-fail\" world of institutions to discuss the practical realities of securing a global ecosystem.\n\nThe Evolution of the Stack:\n\nScaling Security: How do we transition from one-off smart contract audits to continuous, real-time security monitoring and automated response?\n\nThe User Experience Paradox: Discussing the shift from the burden of seed phrases to invisible security like MPC, TEEs and Account Abstraction\u2014and whether we\u2019re introducing new risks in the process.\n\nOperational Maturity: Why OpSec (key management, governance, and internal controls) is becoming the most critical failure point as organizations move on-chain.\n\nWhat Stays the Same: Identifying the \"load-bearing\" pillars of Web3\u2014like zero-trust and cryptographic proofs\u2014that must survive the leap to the mainstream.", "recording_license": "", "do_not_record": false, "persons": [{"code": "8UGERQ", "name": "Michael Lewellen", "avatar": "https://darkmode.securityalliance.org/media/avatars/8UGERQ_YbBUZGT.webp", "biography": "Michael Lewellen is a blockchain security and software architect with over 14 years of experience in web3 systems. As Head of Solutions Engineering at Turnkey, he advises leading financial institutions and protocols on secure key management and infrastructure design. He has worked with major protocols including Arbitrum, Compound, and the EF during his time at OpenZeppelin. He currently teaches blockchain technology at UT Dallas and is a long-time contributor to the Security Alliance.", "public_name": "Michael Lewellen", "guid": "a534fa8f-4e60-5aee-98a4-2551f65be006", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/8UGERQ/"}, {"code": "AGR8MF", "name": "Anto", "avatar": null, "biography": null, "public_name": "Anto", "guid": "6b8f2230-3159-5ded-a0da-03d9b1e6ff7d", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/AGR8MF/"}, {"code": "BYYCY7", "name": "Andrew MacPherson (AndrewMohawk) '<#<h1>", "avatar": "https://darkmode.securityalliance.org/media/avatars/BYYCY7_Ekzxml4.webp", "biography": "Andrew has been breaking, building, and defending things in infosec for over two decades (wow old). Starting at Paterva he spent 10+ years creating Maltego before moving to the US for security roles at BitMEX (IR), Robinhood (IR/D&R), Uniswap (Head of Security), and now Privy (Principal Security Engineer). He\u2019s spoken at Black Hat, DEF CON, DSS, EthCC and countless others, teaching courses and drinking malibu on the way. When not thinking about security, he\u2019s into cat memes, punk rock, and getting involved in just the right amount of unhinged shit to keep security interesting.", "public_name": "Andrew MacPherson (AndrewMohawk) '<#<h1>", "guid": "c219c69f-7dc5-5505-9f32-129d06b9dfe9", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/BYYCY7/"}, {"code": "GTJLKH", "name": "Mooly Sagiv", "avatar": null, "biography": null, "public_name": "Mooly Sagiv", "guid": "bfdaed59-6fa9-5356-9afb-a0e03daa459c", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/GTJLKH/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/UX3RPF/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/UX3RPF/", "attachments": []}, {"guid": "f1cd353d-2247-5f03-8ce8-85c7704cedbb", "code": "VDPMHS", "id": 88361, "logo": null, "date": "2026-02-17T16:45:00-07:00", "start": "16:45", "end": "2026-02-17T17:05:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-88361-protecting-keys-and-compute-with-secure-enclaves", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/VDPMHS/", "title": "Protecting Keys and Compute with Secure Enclaves", "subtitle": "", "track": "New Announcements", "type": "Short Talk", "language": "en", "abstract": "Web3 security has cycled from custodial single points of failure to the \"seed phrase anxiety\" of self-custody. This session explores how Secure Enclaves (TEEs) can offer a unique solution to key management by enabling Verifiable Infrastructure for embedded wallets.\n\nWe\u2019ll dive into Turnkey\u2019s approach to TEE-based key management\u2014using hardware-isolated environments like AWS Nitro to move beyond simple signing into a world where every policy is rooted in verifiable proofs. We'll also discuss Turnkey's new Verifiable Cloud: a new offering that extends these guarantees to general-purpose workloads, allowing developers to run sensitive code\u2014from AI agents to DeFi logic\u2014inside isolated enclaves that produce independently auditable proofs of execution.", "description": "", "recording_license": "", "do_not_record": false, "persons": [{"code": "8UGERQ", "name": "Michael Lewellen", "avatar": "https://darkmode.securityalliance.org/media/avatars/8UGERQ_YbBUZGT.webp", "biography": "Michael Lewellen is a blockchain security and software architect with over 14 years of experience in web3 systems. As Head of Solutions Engineering at Turnkey, he advises leading financial institutions and protocols on secure key management and infrastructure design. He has worked with major protocols including Arbitrum, Compound, and the EF during his time at OpenZeppelin. He currently teaches blockchain technology at UT Dallas and is a long-time contributor to the Security Alliance.", "public_name": "Michael Lewellen", "guid": "a534fa8f-4e60-5aee-98a4-2551f65be006", "url": "https://darkmode.securityalliance.org/darkmode-2026/speaker/8UGERQ/"}], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/VDPMHS/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/VDPMHS/", "attachments": []}]}}, {"index": 3, "date": "2026-02-18", "day_start": "2026-02-18T04:00:00-07:00", "day_end": "2026-02-19T03:59:00-07:00", "rooms": {"Auditorium": [{"guid": "cc59e09f-fc64-571c-85ed-c43d9b79c99c", "code": "NEHCVJ", "id": 91481, "logo": null, "date": "2026-02-18T12:00:00-07:00", "start": "12:00", "end": "2026-02-18T12:25:00-07:00", "duration": "00:25", "room": "Auditorium", "slug": "darkmode-2026-91481-decoding-the-dc-politics-of-crypto-privacy", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/NEHCVJ/", "title": "Decoding the DC Politics of Crypto Privacy", "subtitle": "", "track": "Privacy", "type": "Panel", "language": "en", "abstract": "Kyle Bligen - Decentralization Research Center,Michael Lewellen - Turnkey,Lindsay Fraser - Blockchain Association, Mike Orcutt - Project Glitch", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/NEHCVJ/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/NEHCVJ/", "attachments": []}, {"guid": "bd136582-744c-58fd-8077-df59b7b46470", "code": "FUUDPW", "id": 91482, "logo": null, "date": "2026-02-18T12:25:00-07:00", "start": "12:25", "end": "2026-02-18T12:40:00-07:00", "duration": "00:15", "room": "Auditorium", "slug": "darkmode-2026-91482-state-of-surveillance", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/FUUDPW/", "title": "State of Surveillance", "subtitle": "", "track": "Privacy", "type": "Short Talk", "language": "en", "abstract": "Naomi Brockwell - Ludlow Institute, The modern digital era runs on surveillance, and it gets more invasive every day. In \u201cState of Surveillance,\u201d Naomi Brockwell shows how the machine actually works, how it\u2019s embedded in ordinary daily life, and how it has enabled a monumental power shift in society. She'll also go over actionable steps you can take to fight back, protect yourself, and help make privacy normal again.", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/FUUDPW/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/FUUDPW/", "attachments": []}, {"guid": "9917726e-c8b7-5850-a89b-57f2f4bb11ed", "code": "8LQSUJ", "id": 91483, "logo": null, "date": "2026-02-18T12:40:00-07:00", "start": "12:40", "end": "2026-02-18T12:55:00-07:00", "duration": "00:15", "room": "Auditorium", "slug": "darkmode-2026-91483-non-custodial-not-really-misconceptions-in-key-management", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/8LQSUJ/", "title": "Non-Custodial? Not Really! Misconceptions in Key Management", "subtitle": "", "track": "Privacy", "type": "Short Talk", "language": "en", "abstract": "TJ Connolly - Fireblocks, A deep dive on the various approaches used by non-custodial & embedded wallets to generate & store private keys for their users, and despite their claims, the truth is most generate key material on software & hardware NOT controlled by the end user, therefore making them de facto custodial.", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/8LQSUJ/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/8LQSUJ/", "attachments": []}, {"guid": "a7871e65-dd54-5fc3-8034-e9245f45740a", "code": "L7P9WS", "id": 91485, "logo": null, "date": "2026-02-18T12:55:00-07:00", "start": "12:55", "end": "2026-02-18T13:10:00-07:00", "duration": "00:15", "room": "Auditorium", "slug": "darkmode-2026-91485-keynote-ameen-soleimani", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/L7P9WS/", "title": "Keynote: Ameen Soleimani", "subtitle": "", "track": "Privacy", "type": "Short Talk", "language": "en", "abstract": "Keynote by Ameen Soleimani", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/L7P9WS/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/L7P9WS/", "attachments": []}, {"guid": "c74c51dd-b593-5ae7-8c65-5d64b66b5ef5", "code": "DAHPWV", "id": 91486, "logo": null, "date": "2026-02-18T13:10:00-07:00", "start": "13:10", "end": "2026-02-18T13:25:00-07:00", "duration": "00:15", "room": "Auditorium", "slug": "darkmode-2026-91486-keynote-alexander-wilke", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/DAHPWV/", "title": "Keynote: Alexander Wilke", "subtitle": "", "track": "Privacy", "type": "Short Talk", "language": "en", "abstract": "Keynote: Alexander Wilke", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/DAHPWV/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/DAHPWV/", "attachments": []}, {"guid": "9f758aa1-fcc1-579c-9521-0a6dbc89dbf9", "code": "HSMC3Y", "id": 91487, "logo": null, "date": "2026-02-18T13:25:00-07:00", "start": "13:25", "end": "2026-02-18T13:40:00-07:00", "duration": "00:15", "room": "Auditorium", "slug": "darkmode-2026-91487-proofless-consensus-and-client-side-validation", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/HSMC3Y/", "title": "Proofless Consensus and Client-Side Validation", "subtitle": "", "track": "Privacy", "type": "Short Talk", "language": "en", "abstract": "Ying Tong Lai - (In stealth), Proofless consensus is a family of protocols moving transaction validation out of consensus, to client-side devices. This allows for lightweight private payments without placing additional burden on consensus. This talk compares shielded CSV, Intmax, and PlasmaFold, and explores private applications that can be built on top of these.", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/HSMC3Y/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/HSMC3Y/", "attachments": []}, {"guid": "2a4b9218-95ac-5582-a8dd-e121039f8dba", "code": "8H88ZS", "id": 91490, "logo": null, "date": "2026-02-18T13:40:00-07:00", "start": "13:40", "end": "2026-02-18T14:00:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-91490-fireside-zcash-s-zooko-wilcox", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/8H88ZS/", "title": "Fireside: Zcash's Zooko Wilcox", "subtitle": "", "track": "Privacy", "type": "Panel", "language": "en", "abstract": "Zooko Wilcox - Shielded Labs for Zcash, Moderated by Ben Schiller - Miden", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/8H88ZS/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/8H88ZS/", "attachments": []}, {"guid": "d8bd331c-7972-50f4-aa1f-2523a4f4ea0d", "code": "ALEX7U", "id": 91491, "logo": null, "date": "2026-02-18T14:00:00-07:00", "start": "14:00", "end": "2026-02-18T14:15:00-07:00", "duration": "00:15", "room": "Auditorium", "slug": "darkmode-2026-91491-keynote-zak-cole", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/ALEX7U/", "title": "Keynote: Zak Cole", "subtitle": "", "track": "Privacy", "type": "Short Talk", "language": "en", "abstract": "Zak Cole - Ethereum Community Foundation,", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/ALEX7U/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/ALEX7U/", "attachments": []}, {"guid": "08a98484-d8b5-58d4-8ac9-350eac5f5c8d", "code": "FL8VYA", "id": 91492, "logo": null, "date": "2026-02-18T14:15:00-07:00", "start": "14:15", "end": "2026-02-18T14:35:00-07:00", "duration": "00:20", "room": "Auditorium", "slug": "darkmode-2026-91492-crypto-lost-the-plot-how-blockchain-forgot-its-own-canon", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/FL8VYA/", "title": "Crypto Lost the Plot: How Blockchain Forgot Its Own Canon", "subtitle": "", "track": "Privacy", "type": "Short Talk", "language": "en", "abstract": "Zac Williamson - Aztec Network, Blockchain began as a rebellion against institutional power, but gradually retreated into safer terrain: speculation settlement, and regulatory-friendly finance. This talk argues that the field\u2019s real failure wasn\u2019t technical, it was canonical \u2013 splitting its founding myth into \u201cnumber go up\u201d finance and an underpowered vision of social coordination that never fully materialized. With privacy-preserving cryptography now real, crypto stands at a reckoning: becoming the institutional technology it promised to be or be remembered as a failed rebellion that optimized complacency and called it progress.", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/FL8VYA/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/FL8VYA/", "attachments": []}, {"guid": "9a6ef293-f86a-52a4-b7ee-c2cf60d5ed20", "code": "ZSTD3M", "id": 91493, "logo": null, "date": "2026-02-18T14:35:00-07:00", "start": "14:35", "end": "2026-02-18T14:50:00-07:00", "duration": "00:15", "room": "Auditorium", "slug": "darkmode-2026-91493-the-infrastructure-capital-markets-need-to-go-onchain", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/ZSTD3M/", "title": "The Infrastructure Capital Markets Need to Go Onchain", "subtitle": "", "track": "Privacy", "type": "Short Talk", "language": "en", "abstract": "Howard Wu, Capital markets are moving onchain, but public stablecoin rails expose balances, flows, and counterparties. This session examines the ZK infrastructure behind private, compliant, programmable stablecoins like USDCx and what institutions require to deploy real capital safely.", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/ZSTD3M/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/ZSTD3M/", "attachments": []}, {"guid": "a5150ad3-6046-5e11-8a18-47344b17f945", "code": "MSKFFY", "id": 91501, "logo": null, "date": "2026-02-18T14:50:00-07:00", "start": "14:50", "end": "2026-02-18T15:20:00-07:00", "duration": "00:30", "room": "Auditorium", "slug": "darkmode-2026-91501-stablecoin-endgame-programmable-privacy", "url": "https://darkmode.securityalliance.org/darkmode-2026/talk/MSKFFY/", "title": "Stablecoin Endgame: Programmable Privacy", "subtitle": "", "track": "Privacy", "type": "Long Talk", "language": "en", "abstract": "Matthew Green, Ian Miers, \u23f0 Howard Wu, Ben Lakoff - Bankless Ventures\n\nStablecoins need privacy to be usable for real payments. This session reveals how zero-knowledge stablecoins unlock global payroll, commerce, and remittances without exposing sensitive financial data. Learn from the pioneers making private money finally work at scale.", "description": "", "recording_license": "", "do_not_record": false, "persons": [], "links": [], "feedback_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/MSKFFY/feedback/", "origin_url": "https://darkmode.securityalliance.org/darkmode-2026/talk/MSKFFY/", "attachments": []}]}}]}}}