<?xml version='1.0' encoding='utf-8' ?>
<!-- Made with love by pretalx v2026.3.0.dev0. -->
<schedule>
    <generator name="pretalx" system="darkmode.securityalliance.org" version="2026.3.0.dev0" />
    <version>0.12</version>
    <conference>
        <title>darkMode 2026</title>
        <acronym>darkmode-2026</acronym>
        <start>2026-02-16</start>
        <end>2026-02-18</end>
        <days>3</days>
        <timeslot_duration>00:05</timeslot_duration>
        <base_url>https://darkmode.securityalliance.org</base_url>
        <logo>https://darkmode.securityalliance.org/media/darkmode-2025/img/logo_OUhNnx6_3LLp8Fb.webp</logo>
        <time_zone_name>US/Mountain</time_zone_name>
        
        
        <track name="New Announcements" slug="6658-new-announcements"  color="#00ebff" />
        
        <track name="Privacy" slug="6661-privacy"  color="#000000" />
        
        <track name="Vulnerability Disclosure" slug="6656-vulnerability-disclosure"  color="#b5f79c" />
        
        <track name="Other" slug="6655-other"  color="#c655ec" />
        
        <track name="Lessons Learned" slug="6657-lessons-learned"  color="#ff003c" />
        
        <track name="Hot takes" slug="6659-hot-takes"  color="#8300ff" />
        
        <track name="SEAL" slug="6660-seal"  color="#4339db" />
        
    </conference>
    <day index='1' date='2026-02-16' start='2026-02-16T04:00:00-07:00' end='2026-02-17T03:59:00-07:00'>
        <room name='Auditorium' guid='8a28f735-ce62-54c3-8161-e4b61db80fbb'>
            <event guid='e1eea8c3-8944-58e0-8847-26bce0cbf39b' id='89203' code='WLMELT'>
                <room>Auditorium</room>
                <title>Welcome to darkMode</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-16T09:45:00-07:00</date>
                <start>09:45</start>
                <duration>00:05</duration>
                <abstract>samczsun welcomes you to SEAL&apos;s first annual security conference, darkMode</abstract>
                <slug>darkmode-2026-89203-welcome-to-darkmode</slug>
                <track>Other</track>
                
                <persons>
                    <person id='89690'>samczsun</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/WLMELT/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/WLMELT/feedback/</feedback_url>
            </event>
            <event guid='2a06c634-eeae-52de-9dcc-2cdd02d5a628' id='89303' code='CFCU37'>
                <room>Auditorium</room>
                <title>Old Hacks Targeting New Industries: How to Balance User Privacy and Security</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-16T09:50:00-07:00</date>
                <start>09:50</start>
                <duration>00:20</duration>
                <abstract>Your smart contracts are audited, but is your contractor&#8217;s laptop? Most Web3 &quot;hacks&quot; aren&apos;t complex cryptographic exploits&#8212;they&apos;re basic Web2 security failures. From weak Discord credentials to unmanaged endpoints, many web3 companies have forgotten the web2 security fundamentals.

Join Andrew, a Mandiant/Google Cloud security expert with a decade of experience securing global financial giants, as he deconstructs the traditional attacks currently gutting the Web3 ecosystem. Learn why your &quot;decentralized&quot; future is failing at the basics, and how you can balance security and user privacy.</abstract>
                <slug>darkmode-2026-89303-old-hacks-targeting-new-industries-how-to-balance-user-privacy-and-security</slug>
                <track>Lessons Learned</track>
                
                <persons>
                    <person id='89766'>Andrew Chang-Gu</person>
                </persons>
                <language>en</language>
                <description>In this talk, we will discuss common cyber threats facing web3 firms and the security controls that can stop them. Topics include:
Identity and access management: conditional access, device posture checking
Ways to deploy security controls on end-user machines while respecting user privacy
Conducting due-diligence checks on a multinational, contractor-led workforce, insider threat protections and social engineering awareness
Managing IT infrastructure such as servers, laptops and phones, including logging and monitoring</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/CFCU37/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/CFCU37/feedback/</feedback_url>
            </event>
            <event guid='c02de1cb-5ac7-5188-8f29-164c59400052' id='88227' code='UDCWH3'>
                <room>Auditorium</room>
                <title>Safeguarding Your Digital Footprint:  A Privacy-First Approach to Web3 OPsec</title>
                <subtitle></subtitle>
                <type>Closed Room Session</type>
                <date>2026-02-16T10:10:00-07:00</date>
                <start>10:10</start>
                <duration>00:20</duration>
                <abstract>Wireless networks, a ubiquitous and often overlooked element of Web3 projects, pose a significant operational security (OPSEC) risk due to a phenomenon called &quot;beaconing.&quot; As mobile devices move, they publicly disseminate personally identifiable information (PII) that malicious actors can combine with open-source intelligence (OSINT) to infer a user&apos;s travel plans, physical addresses, past conference attendance, associated crypto projects, and even the location of hardware wallets. This vulnerability contributes to the increasing threat of physical attacks (such as kidnapping and ransom, or &quot;wrench attacks&quot;) and social engineering, as well as the risk of disclosing material nonpublic information.

This workshop will walk attendees through using readily available tools to collect and analyze everyday wireless signals.  Hardware crypto wallets will be made available for analysis.  Other secure tooling will be observed. Will there be enough information in the room to identify devices, individuals, crypto wealth?  We will see.</abstract>
                <slug>darkmode-2026-88227-safeguarding-your-digital-footprint-a-privacy-first-approach-to-web3-opsec</slug>
                <track>Privacy</track>
                
                <persons>
                    <person id='88872'>Benjamin Speckien</person>
                </persons>
                <language>en</language>
                <description>As you move through the world, your devices connect to wireless networks and collect unique identifiers. Your mobile devices may be broadcasting these sensitive artifacts, possibly personally identifiable information (PII), through probes and beacons. These wireless signals can be combined with open-source intelligence (OSINT) to compromise your privacy, revealing your travel history, physical location, and even the existence and location of your hardware wallets.  This data is an asset to malicious actors: enabling pretexting for social engineers, exposing daily routines to physical attackers, or providing partnering information to data-hungry degens.

This workshop demonstrates a privacy-focused security paradigm for the Web3 space. It moves beyond on-chain contracts to detail the off-chain vulnerabilities in Wi-Fi and Bluetooth signals. Learn how to collect and analyze potentially sensitive wireless signals.  Examine your digital footprint in a way an attacker would.  

We will also discuss practical mitigation strategies and best practices necessary to secure your wireless devices, protect your personal safety, and ensure the operational integrity of your Web3 projects in a world where physical and digital security are inextricably linked.

To participate in this workshop, please bring a Macbook, Linux Laptop with a wireless card that supports monitor mode, or an Android device.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/UDCWH3/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/UDCWH3/feedback/</feedback_url>
            </event>
            <event guid='906c7785-fed3-5e1a-9d24-982dce98e1dd' id='89930' code='CYHTKN'>
                <room>Auditorium</room>
                <title>TOTP apps are dead and why you are doing 2FA wrong</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-16T10:30:00-07:00</date>
                <start>10:30</start>
                <duration>00:20</duration>
                <abstract>I will present a summary of how 2FA works, the different methods (SMS, TOTP apps, Yubikeys, Passkeys, etc), the weaknesses each one of them have, how they are being exploited, and what we have to do in order to start using 2FA in a safe way.</abstract>
                <slug>darkmode-2026-89930-totp-apps-are-dead-and-why-you-are-doing-2fa-wrong</slug>
                <track>Hot takes</track>
                
                <persons>
                    <person id='90324'>Pablo Sabbatella</person>
                </persons>
                <language>en</language>
                <description>I will present a summary of how 2FA works, the different methods (SMS, TOTP apps, Yubikeys, Passkeys, etc), the weaknesses each one of them have, how they are being exploited, and what we have to do in order to start using 2FA in a safe way.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/CYHTKN/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/CYHTKN/feedback/</feedback_url>
            </event>
            <event guid='7503e99c-4bff-54e6-bc47-21e3e6c741da' id='88221' code='7ZHSK9'>
                <room>Auditorium</room>
                <title>Get off my lawn: you&apos;re forgettin&apos; your web2 security risk, young whippersnapper</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-16T10:50:00-07:00</date>
                <start>10:50</start>
                <duration>00:20</duration>
                <abstract>Web2 is the Soft Underbelly of Web3

Web3 Security has a Web2 Security problem. As on-chain code gets better and better, attackers are going to go after the low-hanging fruit--and that means all the boring &quot;legacy cybersecurity stuff&quot; your grandpa used to tell you about. (See: the ByBit hack in Feb 2025, classic web2 compromise with web3 impact).

&quot;Back in mah day, we cared about phishing and end point device security. Oh, and young whippersnapper, and did you know &apos;the cloud&apos; just means &apos;someone&apos;s else&apos;s computer&apos;? Sure seems like a terrible idea to run all yer validators in (checks notes) AWS, doncha think? Using CIA&apos;s preferred cloud vendor--that&apos;ll stick it to the man fer sure LOL!&quot;

&quot;and betcha never heard of this here dang thing called a SIEM before either, have yeah?&quot;

I once met a security engineer at a conference who described themselves as a &quot;web3 native security engineer&quot;. Couldn&apos;t explain TCP/IP, how Linux works, how a browser works, couldn&apos;t tell me the OSI model, but boy did they know a lot about Solidity security!

Yeah. Don&apos;t be that guy. Cuz you&apos;re going to get rekt if you do.

Come to grandpa&apos;s[*] curmudgeonly fireside chat to hear about all the old stuff that still matters today.

[*] not an actual grandpa. yet.</abstract>
                <slug>darkmode-2026-88221-get-off-my-lawn-you-re-forgettin-your-web2-security-risk-young-whippersnapper</slug>
                <track>Hot takes</track>
                
                <persons>
                    <person id='88864'>J.M. Porup</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/7ZHSK9/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/7ZHSK9/feedback/</feedback_url>
            </event>
            <event guid='620d0953-242a-5b64-8754-1eb6f5caa074' id='88171' code='P8GGKC'>
                <room>Auditorium</room>
                <title>Inside Immunefi&#8217;s Highest-Paying Bug Bounties of 2025</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-16T11:10:00-07:00</date>
                <start>11:10</start>
                <duration>00:20</duration>
                <abstract>In 2025 alone, Immunefi paid out close to $11,000,000 in bug bounties for critical crypto vulnerabilities. preventing exploits that could have resulted in hundreds of millions of dollars in losses.

This talk breaks down a few of the highest-impact bounty payouts of 2025, focusing on what actually drove seven-figure and high six-figure rewards. We&#8217;ll examine specific vulnerabilities, system designs, and attacker mindsets behind the most severe findings, and explain why these specific bugs justified such large payouts.

This session is grounded in specific cases in 2025 across DeFi, bridges, L2s, and core infrastructure. Attendees will gain a practical understanding of where the highest paying security risks surfaced in 2025, and what both researchers and protocol teams should prioritize going forward.</abstract>
                <slug>darkmode-2026-88171-inside-immunefi-s-highest-paying-bug-bounties-of-2025</slug>
                <track>Lessons Learned</track>
                
                <persons>
                    <person id='88812'>Alejandro Munoz-McDonald</person>
                </persons>
                <language>en</language>
                <description>This talk is structured around a small number of high-impact 2025 case studies, including:
- The technical root cause of some of the largest bounty payouts of the year
- How these vulnerabilities could have been exploited in the wild
- What made these reports stand out and qualify for top-tier rewards

Each case is anonymized or based on information approved for public disclosure, and is used to extract concrete lessons for:
- Whitehats looking to focus on high-impact targets
- Protocol teams aiming to prevent catastrophic bugs
- The goal is to give attendees a realistic picture of what &#8220;critical&#8221; actually looks like in 2025 crypto systems.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/P8GGKC/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/P8GGKC/feedback/</feedback_url>
            </event>
            <event guid='0004c392-431a-5706-95a2-ce90607f960f' id='86974' code='ESCYXL'>
                <room>Auditorium</room>
                <title>When the AppleJeus GitHub is Worth The Squeeze</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-16T11:30:00-07:00</date>
                <start>11:30</start>
                <duration>00:20</duration>
                <abstract>AppleJeus, also known as Citrine Sleet, Gleaming Pisces, and Smooth Operator, is the North Korean hacker behind the Radiant Capital heist among others. This is the story of finding a previously undiscovered AppleJeus campaign targeting fintech. This talk will also give some background on North Korean hacking groups, show simple pivoting for analysts, and give recommendations to help protect your organization from North Korean threat actors.</abstract>
                <slug>darkmode-2026-86974-when-the-applejeus-github-is-worth-the-squeeze</slug>
                <track>Lessons Learned</track>
                
                <persons>
                    <person id='87698'>Daniel Gordon</person>
                </persons>
                <language>en</language>
                <description>This talk will have a little bit of everything!  Collaboration between different North Korean hacking groups! Involvement in hacking by North Korean IT workers! Activity across platforms including GitHub, NPM, PyPI, Twitter, and Discord!</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/ESCYXL/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/ESCYXL/feedback/</feedback_url>
            </event>
            <event guid='a364579d-ad38-5777-9300-65db1009a4a2' id='89204' code='JNGY3E'>
                <room>Auditorium</room>
                <title>SEAL Certifications: A Collaborative Framework for Maturity in Crypto Security</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-16T13:00:00-07:00</date>
                <start>13:00</start>
                <duration>00:20</duration>
                <abstract>Security Alliance (SEAL) is developing an open, collaborative certification program to help the crypto ecosystem define and demonstrate operational security maturity. Built on lessons learned from years of emergency incident response and threat intelligence sharing, SEAL Certifications distill collective knowledge into actionable standards developed openly with the community. For protocols, this means clear guidance to strengthen security posture and a credible way to signal trustworthiness to users, investors, and insurers. Currently in pilot with full rollout planned for 2026, this talk introduces the certification framework and how protocols and security firms can get involved. Presented by Isaac Patka, initiative lead.</abstract>
                <slug>darkmode-2026-89204-seal-certifications-a-collaborative-framework-for-maturity-in-crypto-security</slug>
                <track>New Announcements</track>
                
                <persons>
                    <person id='89691'>Isaac Patka</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/JNGY3E/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/JNGY3E/feedback/</feedback_url>
            </event>
            <event guid='86a6dccc-85d7-53ec-8053-b3e00cc0c862' id='89205' code='UVLUSC'>
                <room>Auditorium</room>
                <title>Trafficked Trust: The Human Cost of Crypto Scams</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-16T13:20:00-07:00</date>
                <start>13:20</start>
                <duration>00:20</duration>
                <abstract>We often analyze the &quot;social engineering&quot; behind cryptocurrency fraud, but we rarely discuss the coercion that powers it. Trust is manufactured at gunpoint in scam compounds around the world.

This talk exposes the reality of the industrialized criminality, where human trafficking fuels the global theft of digital assets.

We will trace the operation from the ground up: from the fake job ads that entrap the workforce to physical compounds like those in Myanmar where victims are forced to execute the fraud.

Drawing on active field intelligence and exclusive documentary footage, we will map the full cycle of the crime. This is a look at how criminal syndicates have weaponized human captivity to exploit the cryptocurrency ecosystem.</abstract>
                <slug>darkmode-2026-89205-trafficked-trust-the-human-cost-of-crypto-scams</slug>
                <track>Lessons Learned</track>
                
                <persons>
                    <person id='89692'>dobs</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/UVLUSC/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/UVLUSC/feedback/</feedback_url>
            </event>
            <event guid='7a5da98c-99ad-5103-b33f-3ea62bf5f839' id='86679' code='DTHPTP'>
                <room>Auditorium</room>
                <title>TheDAO Security Fund</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-16T13:40:00-07:00</date>
                <start>13:40</start>
                <duration>00:20</duration>
                <abstract>I want to introduce the fund to gather awareness!

There was some left over funding in TheDAO (Over 70k ETH) and we want to use it to fund ETH Security projects!</abstract>
                <slug>darkmode-2026-86679-thedao-security-fund</slug>
                <track>New Announcements</track>
                
                <persons>
                    <person id='87653'>Griff Green</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/DTHPTP/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/DTHPTP/feedback/</feedback_url>
            </event>
            <event guid='24256031-a232-5ed3-8bcc-fac0c135eda4' id='88140' code='AZ77PD'>
                <room>Auditorium</room>
                <title>The CPIMP Backdoor: Anatomy of a Multi-Chain Proxy Attack</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-16T14:10:00-07:00</date>
                <start>14:10</start>
                <duration>00:20</duration>
                <abstract>A deep dive into the CPIMP vulnerability&#8212;how a stealthy proxy-in-the-middle attack infected dozens of DeFi protocols across chains, embedded persistent backdoors, and how Dedaub and SEAL 911 raced to neutralize it before widespread exploitation.</abstract>
                <slug>darkmode-2026-88140-the-cpimp-backdoor-anatomy-of-a-multi-chain-proxy-attack</slug>
                <track>Vulnerability Disclosure</track>
                
                <persons>
                    <person id='88769'>Neville Grech</person>
                </persons>
                <language>en</language>
                <description>This talk unpacks the CPIMP (Clandestine Proxy In the Middle of Proxy) attack, a stealthy, highly sophisticated DeFi vulnerability that threatened millions of dollars across dozens of protocols and multiple EVM chains.

CPIMPs masqueraded as legitimate proxy contracts while embedding persistent backdoors, often lying dormant for months until optimal conditions arose. The attacker employed advanced evasion techniques, including spoofed events, dummy storage writes, and aggressive anti-recovery logic, successfully deceiving common analysis workflows and even public explorers.

We&#8217;ll walk through how Dedaub reverse-engineered the attack, identified affected deployments, and led a coordinated, multi-chain mitigation effort through SEAL 911. The session distills practical lessons on detecting deeply hidden threats, responding under time pressure, and maintaining continuous monitoring across chains.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/AZ77PD/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/AZ77PD/feedback/</feedback_url>
            </event>
            <event guid='b8fa0793-76db-5a06-bed0-cf29c9f5a745' id='88332' code='PBPFE3'>
                <room>Auditorium</room>
                <title>Stopping the Rubber Hose Attack: Hot Takes</title>
                <subtitle></subtitle>
                <type>Panel</type>
                <date>2026-02-16T14:30:00-07:00</date>
                <start>14:30</start>
                <duration>00:45</duration>
                <abstract>Home invasions and physical attacks to get crypto transfers are all too common, and have led to grim situations. With all the factors, passphrase and biometrics in the world, people remain susceptible to the rubber hose. This panel will discuss theories and practices for defending against a rubber hose attack, through deterrence, defenses and mitigations.  We will start with the assumption that the goal is to preserve life and limb, and preventing or reversing token transfer is secondary, but how to get there, and be reasonably confident that it will not backfire, is hard.</abstract>
                <slug>darkmode-2026-88332-stopping-the-rubber-hose-attack-hot-takes</slug>
                <track>Hot takes</track>
                
                <persons>
                    <person id='88959'>smagdali</person><person id='88952'>Kurt Opsahl</person><person id='88575'>Elliot</person>
                </persons>
                <language>en</language>
                <description>The panel will provide their hot takes and deep wisdom on these questions:
How do we increase the attackers costs and risks, and reduce the odds of profit?
What methods can prevent/slow/reduce fund transfer can be done safely, without undue risk? 
Would you rather a remote multisig that would never sign if your under duress, or would sign to pay the ransom?
What methods to bring help (police/private security) can help with safety, with undue risk
How can we establish norms and widely held understandings to create a disincentive for the attacker to try?
How can one hide their holdings from the public in a transparent blockchain world?
What can we learn from the history with fiat, where home invasion and the rubber hose is not as frequent
	Not common in CashApp/Venmo/Wires etc. 
	Kidnapping for fiat ransom is an analogy, usually target very wealthy
	Shorter term kidnapping for a ride to ATMs
Can you tech your way out of the problem by being super clever?
	Dummy accounts, honey pots, tainted transfers</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/PBPFE3/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/PBPFE3/feedback/</feedback_url>
            </event>
            <event guid='169ab5d7-2fb7-5932-ac8d-dcedbab9f799' id='88242' code='9YPLDE'>
                <room>Auditorium</room>
                <title>Bypassing Cloaking when Hunting Phishing Sites</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-16T15:15:00-07:00</date>
                <start>15:15</start>
                <duration>00:20</duration>
                <abstract>Wallet Drainers and other forms of phishing try to hide from security systems designed to catch them. 

From Query param keys, to fake blog posts, and time limited attacks, there are many ways that scammers hide their sites from detection and blocklisting.

In this talk we will go over the latest cloaking techniques these sites use, approaches to bypassing cloaking, and some unsolved problems that will spark ideas.</abstract>
                <slug>darkmode-2026-88242-bypassing-cloaking-when-hunting-phishing-sites</slug>
                <track>Lessons Learned</track>
                
                <persons>
                    <person id='88886'>Nikita Varabei</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/9YPLDE/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/9YPLDE/feedback/</feedback_url>
            </event>
            <event guid='27467282-9549-5ad9-b3e3-1829ac55c09d' id='85939' code='JQBPDF'>
                <room>Auditorium</room>
                <title>Mastering Security through Simple Machines: How Consistency, Not Complexity, Drives Innovation</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-16T15:35:00-07:00</date>
                <start>15:35</start>
                <duration>00:20</duration>
                <abstract>In the security industry, we often take well-established development practices, such as the DevOps infinity loop, add a layer of security, and label it &quot;DevSecOps.&quot; However, this approach frequently overlooks a critical issue: layering complex security processes onto efficient development processes can create inefficiency. In this talk, I argue that true innovation in security comes not from tooling or automation alone, but from mastering the underlying process first. By drawing an analogy to simple machines &#8212; where incremental improvements led to the evolution of tools like levers, wheels, and pulleys &#8212; I will illustrate how optimizing foundational processes leads to scalable, effective security practices. Attendees will leave with practical insights on reducing inefficiencies and fostering consistent improvement in their security workflows.</abstract>
                <slug>darkmode-2026-85939-mastering-security-through-simple-machines-how-consistency-not-complexity-drives-innovation</slug>
                <track>Hot takes</track>
                
                <persons>
                    <person id='87029'>Ken Toler</person>
                </persons>
                <language>en</language>
                <description>**1. Introduction: The Problem with Complexity in Security**

- The security industry often adopts development frameworks, such as DevOps, and layers security onto them, creating frameworks like DevSecOps.
- The issue: security processes are frequently complex and inefficient compared to streamlined development processes.
- Key point: You can&apos;t automate something that is inefficient. Applying generative AI or advanced tooling to broken processes won&#8217;t fix them.
- Outcome: This leads to frustration, bottlenecks, and unmet security goals.

**2. The Analogy: Security Processes as Simple Machines**

- Introduction to simple machines: lever, wheel, pulley, etc.
- Simple machines represent fundamental tools that evolve through mastery and incremental improvement.
- Just as a lever becomes more efficient when transformed into a wheel or pulley, security processes must evolve through optimization.
- Example: A long, inefficient SAST (Static Application Security Testing) scan taking two days doesn&#8217;t fit into a two-week sprint. Simply automating it doesn&#8217;t solve the problem; instead, the process itself must be optimized.

**3. Evolution of Security Processes through Consistency and Optimization**

- Consistency is key: innovation stems from mastery and consistent refinement, not from one-time application of advanced tools.
- Case study: Improving SAST scans
    - Initial state: A full SAST scan that takes two days to complete.
    - Optimization: Breaking the scan into targeted components, running incremental scans, or using real-time feedback tools.
    - Result: A faster, more efficient process that integrates seamlessly into the development lifecycle.
- Key takeaway: The goal is not to add complexity but to create efficiency through iteration.

**4. The Futility of Applying AI to Broken Processes**

- Generative AI and other advanced technologies can enhance efficient processes but cannot fix broken ones.
- Example: Applying AI to prioritize vulnerabilities from an inefficient scanning process will still result in a flood of low-value alerts.
- Solution: Fix the underlying process first, then enhance it with automation and AI.

**5. Practical Steps to Achieve Process Mastery**

- Identify inefficiencies: Audit current security processes to find bottlenecks and pain points.
- Apply incremental improvements: Start with small changes and measure their impact.
- Leverage automation only after optimization: Use tools to enhance an already efficient process.
- Foster a culture of continuous improvement: Encourage teams to regularly review and refine processes.

**6. The Path Forward: Consistency as a Driver of Innovation**

- Innovation doesn&#8217;t come from adding complexity; it comes from consistently improving simple, well-understood processes.
- Just as simple machines evolved over time into more complex but efficient systems, security processes must evolve through incremental mastery.
- Final analogy: A poorly applied lever remains inefficient regardless of how much force is applied; a well-crafted pulley system, however, can lift tremendous weight with minimal effort.

**7. Key Takeaways for the Audience**

- Stop trying to automate inefficiency: Focus on optimizing the underlying process first.
- Consistency drives innovation: Regular, incremental improvements lead to breakthroughs.
- Simplicity is powerful: Don&#8217;t overcomplicate security; instead, seek mastery of foundational processes.

**8. Closing Thoughts and Call to Action**

- Challenge to attendees: Audit one core security process in your organization and identify an inefficiency. Implement one small, consistent change and measure the impact.
- Final words: True security innovation comes not from flashy tools but from mastering the basics and improving them consistently over time.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/JQBPDF/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/JQBPDF/feedback/</feedback_url>
            </event>
            <event guid='101c0c01-6826-581e-8213-206be44d4b72' id='87763' code='NYFCXC'>
                <room>Auditorium</room>
                <title>Security Between the Code: Why Technical Excellence Can Fail</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-16T15:55:00-07:00</date>
                <start>15:55</start>
                <duration>00:20</duration>
                <abstract>Security exploits in decentralised systems are rarely caused by technical failures alone. Instead, they emerge at the edges between code, incentives, and institutions - where authority is informal, coordination is improvised, and legitimacy is contested.

Drawing on multi-year ethnographic research embedded in decentralised security communities and real world experience in security practices, this talk reframes security as a socio-technical phenomenon: one sustained not only by protocols and tools, but by moral codes, information practices, incentive structures, and cross-institutional coordination. While the ecosystem is still (rightly) investing heavily in technical interventions (such as improved wallets and developer tooling), many high-impact dynamics remain under-acknowledged, including white-hat incentives, incident information formats, coordination with traditional authorities, and the physical and organisational realities of security work.

The presentation outlines key findings from a forthcoming book on blockchain security, followed by a practitioner response and Q&amp;A with Matta from The Red Guild, who works daily on frontline interventions including phishing education, operational security guidance, and adversarial response. Together, the session bridges analytical diagnosis with operational reality, offering security professionals a clearer map of the system they already inhabit&#8212;and a basis for thinking differently about where leverage actually lies, and what needs to be done to improve the state of blockchain security.</abstract>
                <slug>darkmode-2026-87763-security-between-the-code-why-technical-excellence-can-fail</slug>
                <track>Lessons Learned</track>
                
                <persons>
                    <person id='88437'>Kelsie Nabben</person><person id='91310'>matta</person>
                </persons>
                <language>en</language>
                <description>Purpose and Value

This presentation is designed to respect the time and expertise of security professionals. It does not seek to explain technology to technologists, nor to moralise security practice. Instead, it aims to:

Reframe familiar problems with analytical clarity

Surface high-impact dynamics that are widely experienced but rarely formalised

Offer a shared language for discussing coordination, incentives, and legitimacy in decentralised security

The primary objective is practical: to provide conceptual tools that help practitioners better understand why certain security interventions succeed, stall, or repeatedly re-emerge in new forms.

Audience: Security engineers and incident responders

Security researchers and threat-intelligence professionals

Protocol teams and infrastructure operators

Policy and governance specialists engaging decentralised systems

Other presenter: Matta, The Red Guild</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/NYFCXC/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/NYFCXC/feedback/</feedback_url>
            </event>
            <event guid='856f73c4-0e71-5b0d-863b-2eda33b9efa7' id='87916' code='DQ3T8W'>
                <room>Auditorium</room>
                <title>Why Your Multisig Won&apos;t Save You: Attacks Against High-Value Holders</title>
                <subtitle></subtitle>
                <type>Long Talk</type>
                <date>2026-02-16T16:15:00-07:00</date>
                <start>16:15</start>
                <duration>00:45</duration>
                <abstract>Multisig wallets give holders a false sense of security. The real attack surface isn&apos;t key compromise, it&apos;s all of the human and non-deterministic elements. Spoofed simulations, poisoned addresses, compromised frontends, and coerced signers all exploit the same gap. Users don&apos;t know what they&apos;re signing, and by the time they find out something is wrong, it&apos;s already too late. This talk introduces a threat model for high-value custody and presents Kleidi, a wallet system built around reversibility, configurable policies, and guardian-based recovery.</abstract>
                <slug>darkmode-2026-87916-why-your-multisig-won-t-save-you-attacks-against-high-value-holders</slug>
                <track>New Announcements</track>
                
                <persons>
                    <person id='88575'>Elliot</person>
                </persons>
                <language>en</language>
                <description>Large crypto holders face well-resourced adversaries using attack vectors that multisig alone cannot address. This talk walks through six categories of threat: simulation spoofing, address poisoning, frontend compromises, supply chain attacks, insider threats, and kidnapping or duress scenarios.

Each attack exploits a common weakness: the finality of signed transactions and the opacity of what&apos;s actually being approved. We&apos;ll examine real incidents, break down why existing solutions fail, and introduce a defense framework centered on post-signature review windows and cancellation authority.

The session concludes with a demonstration of Kleidi, a wallet implementation that operationalizes this framework through timelocks, policy engines, and guardian services. Attendees will leave with a threat model they can apply to custody architecture reviews and a concrete reference for how reversibility changes the security calculus.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/DQ3T8W/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/DQ3T8W/feedback/</feedback_url>
            </event>
            
        </room>
        
    </day>
    <day index='2' date='2026-02-17' start='2026-02-17T04:00:00-07:00' end='2026-02-18T03:59:00-07:00'>
        <room name='Auditorium' guid='8a28f735-ce62-54c3-8161-e4b61db80fbb'>
            <event guid='17b8c46b-cb41-5999-b99b-bbe00ff3227f' id='90733' code='7FKKPQ'>
                <room>Auditorium</room>
                <title>When Agents Get Tools: Security for Autonomous Systems</title>
                <subtitle></subtitle>
                <type>Panel</type>
                <date>2026-02-17T09:30:00-07:00</date>
                <start>09:30</start>
                <duration>00:45</duration>
                <abstract>Autonomous agents are moving from experiment to infrastructure. They&apos;re sharing tools, communicating with each other, and increasingly operating with real money. But the security conversation hasn&apos;t caught up. What happens when an agent gets compromised through shared tooling? How do you lock down something designed to act independently? And when agents need wallets to function, what does crypto security teach us about protecting them?</abstract>
                <slug>darkmode-2026-90733-when-agents-get-tools-security-for-autonomous-systems</slug>
                <track>Hot takes</track>
                
                <persons>
                    <person id='91049'>Consensys Diligence</person><person id='89026'>Andrew MacPherson (AndrewMohawk) &apos;&lt;#&lt;h1&gt;</person><person id='91274'>Alex Stokes</person>
                </persons>
                <language>en</language>
                <description>Agents are everywhere now. They&apos;re in our workflows, they&apos;re talking to each other, and some of them have wallets. Most conversations about this are either hype or hand-wraving. This one won&apos;t be.
We&apos;ve assembled panelists who genuinely disagree on where the risks are and how to handle them. Some think crypto&apos;s hard-won security lessons translate directly. Others aren&apos;t convinced. Some see agent-to-agent communication as the real threat vector. Others worry more about what happens when an agent can spend money without asking.

We&apos;ll get into the uncomfortable questions. Can an agent be socially engineered? If one agent infects another through shared tooling, whose problem is that? When autonomy is the feature, how do you even define containment? And can we flip the script entirely, using adversarial agents as security tools rather than threats?

No consensus guaranteed. Come ready to think.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/7FKKPQ/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/7FKKPQ/feedback/</feedback_url>
            </event>
            <event guid='7ab7bc1f-43ac-5f3c-8f12-3f7539334a5e' id='88231' code='KL3EBP'>
                <room>Auditorium</room>
                <title>LLM Auditing, Better Than Cats?</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-17T10:15:00-07:00</date>
                <start>10:15</start>
                <duration>00:20</duration>
                <abstract>Everyone and their mother is trying to launch an AI auditing tool (usually meaning an LLM-based auditing tool). Do they perform any better than cats at auditing? Do they fill the same market purpose as auditing? This talk will take a praxeological approach to the question (as opposed to an empirical/scientific approach), so buckle up for some half-baked un-substantiated opinions! Mixed in will be some things I do think LLMs are good for in the auditing process, and some ideas of other approaches that may work better (some even being taken by some teams already).</abstract>
                <slug>darkmode-2026-88231-llm-auditing-better-than-cats</slug>
                <track>Hot takes</track>
                
                <persons>
                    <person id='88875'>Everett Hildenbrandt</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/KL3EBP/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/KL3EBP/feedback/</feedback_url>
            </event>
            <event guid='1ba2c10f-6512-5a1e-b8b2-41c46031dd5a' id='88288' code='JZASGB'>
                <room>Auditorium</room>
                <title>Co-Auditing With AI: Practical Techniques</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-17T10:35:00-07:00</date>
                <start>10:35</start>
                <duration>00:20</duration>
                <abstract>Smart-contract security has reached a scale where purely manual review no longer keeps pace.  However, fully automated AI auditors may miss context, intent, and threat models that experienced reviewers take for granted.
This talk showcases how one can integrate agent-style AI tools directly into their audit workflows to accelerate personal reasoning and amplify each auditor&apos;s individual expertise.</abstract>
                <slug>darkmode-2026-88288-co-auditing-with-ai-practical-techniques</slug>
                <track>Lessons Learned</track>
                
                <persons>
                    <person id='88932'>George Kobakhidze</person>
                </persons>
                <language>en</language>
                <description>This talk shares how we use AI agents as co-auditors to amplify individual reviewers, not replace them. We focus on a practical framework built inside our audit workflow:

- **Tool-aware agents** that can invoke hard technical tools - static analyzers, code mappers, and protocol helpers -  rather than rely on raw text prompting.

- **Primer-driven behavior**, where auditors define how the agent should think, interpret code, and execute repeatable methodology across domains like lending, staking, and accounting.

- **Artifact generation** that persists throughout the engagement - from initial scoping and code mapping to end-stage issue drafting - allowing humans and the agent to build on shared context as the audit progresses.

The core idea is that these systems let auditors bring their own expertise into the workflow. Teams can create private primers, encode their specialties, and optionally share them with the broader community to lift everyone&#8217;s capability. The goal is a future where every auditor can use AI to multiply the value of their own judgment - without ceding control to automation.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/JZASGB/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/JZASGB/feedback/</feedback_url>
            </event>
            <event guid='60154886-9342-500d-9fcf-c2dceeed2d5e' id='89735' code='G7B9P8'>
                <room>Auditorium</room>
                <title>From vibes to vulnerabilities</title>
                <subtitle></subtitle>
                <type>Long Talk</type>
                <date>2026-02-17T10:55:00-07:00</date>
                <start>10:55</start>
                <duration>00:45</duration>
                <abstract>I am not a vuln researcher and that&apos;s kind of the point, LLMs have come a long way in the cyberz. I tried to find a real RCE with Codex, I failed so badly that I accidentally learned how to find bugs in common projects with LLMs. This talk is about using AI to turn bad vibes into real bugs. Drawing on multiple CVEs across React, Node, Ollama, Wordpress, etc and other projects, I&apos;ll show how anyone with a little debugging and security knowledge can go from vibes to vulnerabilities</abstract>
                <slug>darkmode-2026-89735-from-vibes-to-vulnerabilities</slug>
                <track>Vulnerability Disclosure</track>
                
                <persons>
                    <person id='89026'>Andrew MacPherson (AndrewMohawk) &apos;&lt;#&lt;h1&gt;</person>
                </persons>
                <language>en</language>
                <description>This talk starts from a failure. As a long time blue team practitioner with no vulnerability research background, I tried to use OpenAI Codex to find a real-world RCE that had just dropped&#8212;and got absolutely nowhere. What followed was confusion, false positives, and confidently wrong model output. But once I stopped treating Codex like a one-shot bug oracle and started using it as a deeply opinionated debugging assistant, things began to click.

The session walks through how I used &#8220;vibes&#8221; to find vulnerabilities: from being the annoying kid in the back seat asking &#8220;why?&#8221; a hundred times, to forcing the model to reason more deeply about code paths, assumptions, and edge cases until something real fell out. I&apos;ll walk through the pain and the pleasure of using LLMs for vulnerability discovery, including how this approach led to real findings across projects like React, Node, Ollama, Tethers Password manager, wordpress, supabase, etc.

We&apos;ll talk candidly about where models get stuck, how to work around refusals, why the dumbest ideas sometimes work best, and just how creative&#8212;and unhinged&#8212;you can get when you stop trusting the model and start interrogating it. I&apos;ll also show how this fundamentally changes offensive capability and why it feels like red teams are about to get a serious advantage.

The talk closes with a sober look at the current limitations, the risks, and the broader impact on the security community. The goal isn&apos;t to teach exploit development, but to show that with basic debugging skills and the right guardrails, AI can meaningfully assist in finding real vulnerabilities&#8212;and dramatically lower the barrier to entry for vulnerability research.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/G7B9P8/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/G7B9P8/feedback/</feedback_url>
            </event>
            <event guid='96507c17-5b59-526c-abae-b4fabc423c88' id='90865' code='ETHYXP'>
                <room>Auditorium</room>
                <title>How we stop North Korea getting away with the next Billion: Next generation of security professional coordination and new high speed threat intel network.</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-17T12:40:00-07:00</date>
                <start>12:40</start>
                <duration>00:20</duration>
                <abstract>In the Bybit incident response, a lot went right. The ecosystem showed up, teams moved fast, and we used the tools at our disposal to trace flows and push actionable intelligence.

But there was also a lot that went wrong. Some parts of the ecosystem were not responsive to investigators. Despite their best efforts, law enforcement around the world, they simply did not have enough workforce to dedicate to supporting the freezes and litigation. No matter how fast investigators could post new addresses to freeze the stolen money, it would take hours or even days to be published and actionable. On the other hand, North Korea and collaborators were moving at the rapid speed of blockchain settlement, measured in seconds. Investigators were moving at human coordination and off-chain corporate and government speeds, measured in hours and days. We were always chasing.

So how do we work together to do better the next time? We need to fix both the people &amp; company coordination and the high speed intelligence infrastructure to support that coordination.

In this presentation we will highlight the Coalition for Freezing &amp; Recovering (SEAL &amp; zeroShadow project) and showcase the launch of zeroShadow&#8217;s new Threat Intelligence Platform (free critical infrastructure to all Web3 projects).

zeroShadow Threat Intelligence Platform (zS TIP): a high-speed intel network built so real-time coordination doesn&#8217;t depend on one-off channels. Trusted security teams can share vetted signals in real time, and VASPs receive those signals as they happen to make informed risk decisions quickly. From OFAC sanctioned addresses to the latest hacks and exploits, members will have access to this critical intelligence to stay safe, stay compliant, and be part of the solution to disrupt laundering and help return stolen assets to victims.</abstract>
                <slug>darkmode-2026-90865-how-we-stop-north-korea-getting-away-with-the-next-billion-next-generation-of-security-professional-coordination-and-new-high-speed-threat-intel-network</slug>
                <track>New Announcements</track>
                
                <persons>
                    <person id='91164'>Casey G</person><person id='91171'>Col G</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/ETHYXP/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/ETHYXP/feedback/</feedback_url>
            </event>
            <event guid='d842ac91-930a-55c1-aed6-23ec3bd841bf' id='88182' code='MLLQAQ'>
                <room>Auditorium</room>
                <title>Attack Chains in Web3: Lessons from Multi&#8209;Stage Web3 Exploits</title>
                <subtitle></subtitle>
                <type>Long Talk</type>
                <date>2026-02-17T13:00:00-07:00</date>
                <start>13:00</start>
                <duration>00:45</duration>
                <abstract>Most Web3 incidents aren&#8217;t &#8220;one bug, one drain&#8221; anymore. Attackers increasingly chain weaknesses across layers such as legacy contracts, subtle numerical edge cases, protocol/bridge exit paths, and off-chain vendor exposure, into an exploit path that ends in irreversible loss. In this talk we&apos;ll take a look at some high-signal incidents from 2025 and discuss how to break attack chains before they reach funds. Lessons learned will include practical strategies that projects may adopt to build defense-in-depth that breaks attack chains.</abstract>
                <slug>darkmode-2026-88182-attack-chains-in-web3-lessons-from-multi-stage-web3-exploits</slug>
                <track>Lessons Learned</track>
                
                <persons>
                    <person id='88826'>Sebastian Banescu</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/MLLQAQ/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/MLLQAQ/feedback/</feedback_url>
            </event>
            <event guid='2e49324d-f394-5277-84bb-aec21b20270a' id='86785' code='BJJM8V'>
                <room>Auditorium</room>
                <title>TraderTraitor: A Real Bad MATA</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-17T13:45:00-07:00</date>
                <start>13:45</start>
                <duration>00:20</duration>
                <abstract>TraderTraitor, also known as Jade Sleet, Slow Pisces, UNC4899, Dark River is the North Korean threat actor behind major cryptocurrency heists from ByBit, DMM, WazirX, CoinsPaid, Alphapo, Atomic Wallet, Horizon Bridge, Ronin Bridge, and many others. This presentation is a deep dive into TraderTraitor and will cover how they compromise their victims, how defenders and security teams can track TraderTraitor, and measures that organizations can take to protect themselves from being the next Bybit. This presentation will have non-public details about TraderTraitor activity.</abstract>
                <slug>darkmode-2026-86785-tradertraitor-a-real-bad-mata</slug>
                <track>Lessons Learned</track>
                
                <persons>
                    <person id='87698'>Daniel Gordon</person>
                </persons>
                <language>en</language>
                <description>North Korea loves stealing crypto. This presentation is a deep dive into TraderTraitor, North Korea&apos;s most effective hacking group. This presentation will explore how TraderTraitor compromises cryptocurrency exchanges, wallet service providers, and cloud companies in order to steal massive amounts of cryptocurrency including the ByBit heist where they walked away with $1.5 Billion worth of Ethereum. While TraderTraitor is incredibly effective at stealing cryptocurrency for North Korea, a few security measures can help protect your organization, and your service providers, from this threat actor.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/BJJM8V/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/BJJM8V/feedback/</feedback_url>
            </event>
            <event guid='3e164d41-16ad-56cd-94cf-0e68c434523d' id='88136' code='QUX7KW'>
                <room>Auditorium</room>
                <title>When the Supply Chain Isn&#8217;t Chaining: Stop Reinventing the Wheel</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-17T14:15:00-07:00</date>
                <start>14:15</start>
                <duration>00:20</duration>
                <abstract>We keep seeing the same supply chain failures in crypto: compromised dependencies, leaked or abused publishing keys, and malicious or compromised contributors. These incidents are often framed as uniquely web3, leading teams to design bespoke trust models rather than adopt proven, well-understood security practices.

From an attacker&#8217;s perspective, none of this is new.

Open-source communities have spent years responding to these exact classes of supply chain attacks, resulting in concrete standards such as SLSA and ecosystem-level guidance and tooling from the OpenSSF. These approaches map directly to crypto development workflows, yet remain underutilized in practice. Instead, we repeatedly invent new frameworks, often increasing complexity without reducing risk.

In this talk, I&#8217;ll walk through how we approach release system design at Anza, looking at the full development lifecycle through an adversarial lens. We&#8217;ll identify where things commonly go wrong, how existing tools and frameworks already address these failure modes, and why reinventing the wheel in supply chain security frequently makes systems less secure, not more. I&#8217;ll also cover emerging tooling like gittuf, which takes a fundamentally different approach to Git security and policy enforcement.</abstract>
                <slug>darkmode-2026-88136-when-the-supply-chain-isn-t-chaining-stop-reinventing-the-wheel</slug>
                <track>Lessons Learned</track>
                
                <persons>
                    <person id='88783'>Nikita Belenkov</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/QUX7KW/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/QUX7KW/feedback/</feedback_url>
            </event>
            <event guid='8d26c633-7d45-5aeb-b727-1834d2907ed0' id='87925' code='URDMBC'>
                <room>Auditorium</room>
                <title>Lido V3: Security by Design</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-17T14:35:00-07:00</date>
                <start>14:35</start>
                <duration>00:20</duration>
                <abstract>Protocol security is shaped long before the first line of code is written. In this talk, Tomer Ganor, Tech Lead and Security Researcher at Certora, explores how Lido V3 combines security thinking with protocol design to reduce attack surfaces, prevent bugs, and strengthen the Ethereum infrastructure</abstract>
                <slug>darkmode-2026-87925-lido-v3-security-by-design</slug>
                <track>Other</track>
                
                <persons>
                    <person id='88583'>Tomer Ganor</person>
                </persons>
                <language>en</language>
                <description>Attendees will learn how protocol design decisions shape security outcomes and how security first architecture prevents entire classes of DeFi bugs</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/URDMBC/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/URDMBC/feedback/</feedback_url>
            </event>
            <event guid='a5a17daf-fcef-5c91-a501-3ea6b023f30d' id='88116' code='TT3GRQ'>
                <room>Auditorium</room>
                <title>From Chaos to Containment: Making Incident Response Actually Work in the Digital Asset Economy</title>
                <subtitle></subtitle>
                <type>Panel</type>
                <date>2026-02-17T14:55:00-07:00</date>
                <start>14:55</start>
                <duration>00:45</duration>
                <abstract>Practical incidents + ops learning. Panel may also include &#8220;hot takes&#8221;.

Crypto incidents don&#8217;t behave like traditional breaches. They unfold in minutes, span chains, and can cause infinite cascading damage along the way. Most teams are still improvising without training or realistic strategies in place. This panel brings together leading DeFi security teams to share practical incident lessons, working incident pipelines, and response playbooks that actually hold up under live attack conditions. 

The outcome: practical insights, candid stories, and debate on what the industry must fix next.</abstract>
                <slug>darkmode-2026-88116-from-chaos-to-containment-making-incident-response-actually-work-in-the-digital-asset-economy</slug>
                <track>Lessons Learned</track>
                
                <persons>
                    <person id='88746'>Cantina</person><person id='88887'>Sharon Ideguchi</person>
                </persons>
                <language>en</language>
                <description>Incident Response is where the digital economy defensive layer succeeds or fails, but it is still underdeveloped across the industry. This panel focuses on turning MDR/IR from a reactive approach into reliable operational capability.

We&#8217;ll dig into:
What the first 60 minutes of real incidents actually look like and why they matter
How teams are building MDR workflows that merge on-chain + off-chain telemetry
How playbooks and containment strategies can change the outcome
What the industry consistently gets wrong about response today
How collaboration and threat intelligence meaningfully reduce impact

Attendees will leave with actionable frameworks, hard-earned lessons, and new thinking on how we can collectively raise the baseline of defense in crypto.

Panelists (proposed): representatives from Cantina, Hypernative, and ChainPatrol
Moderator: Mike Leffer, President of Cantina/Spearbit</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/TT3GRQ/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/TT3GRQ/feedback/</feedback_url>
            </event>
            <event guid='6af00cd7-3f9e-5ab6-bf9f-105cf5281f8a' id='88699' code='THSJYH'>
                <room>Auditorium</room>
                <title>Crazy Chains: Why Incident Response Breaks Outside the EVM</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-17T15:40:00-07:00</date>
                <start>15:40</start>
                <duration>00:20</duration>
                <abstract>Most incident response and chain analysis tooling is built with an implicit assumption: account-based execution risk is the problem. That assumption holds, until it doesn&#8217;t.

Using Filecoin as a case study, this talk explores why many otherwise capable vendors struggle to support novel chains, and why gaps appear not because of neglect but because the mental model itself breaks down and product margins don&apos;t get in the way.

Filecoin isn&#8217;t a smart contract chain with storage bolted on. It&#8217;s a distributed system designed to verify long-lived behavior across independent operators. The primary asset isn&#8217;t just balance but it&#8217;s behavior over time. The dominant risks may not necessarily exploits, but they&apos;re based in incentive failures, coordinated degradation, and economic edge cases.

We&#8217;ll unpack what this means for incident response teams and why chain analysis and incident response platforms tend to miss the mark when stepping outside familiar ecosystems:

- Why transaction-centric alerts miss slow-burn incidents
- Why actor behavior matters more than bytecode inspection
- Why &#8220;the incident&#8221; often belongs to the network, not an app
- Why generic EVM heuristics actively create false confidence and false positives

To be crystal clear this talk is not a critique of vendors, it&#8217;s a lessons-learned hot take briefing from the field. Supporting novel chains requires different playbooks, different baselines, and a willingness to abandon security absolutism in favor of contextual risk analysis.

The key takeaway: if your incident response model can&#8217;t reason about incentives, time, and roles, it will fail quietly on novel chains right up until the ecosystem feels the impact.

This session aims to help security teams recognize those limits early, adapt deliberately, and build coverage that actually reflects how decentralized infrastructure fails in practice.</abstract>
                <slug>darkmode-2026-88699-crazy-chains-why-incident-response-breaks-outside-the-evm</slug>
                <track>Hot takes</track>
                
                <persons>
                    <person id='87029'>Ken Toler</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/THSJYH/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/THSJYH/feedback/</feedback_url>
            </event>
            <event guid='b2d89c5a-8584-5e61-992e-5374c950e18c' id='88422' code='UX3RPF'>
                <room>Auditorium</room>
                <title>Web3 Security&apos;s Evolution for Mainstream Adoption</title>
                <subtitle></subtitle>
                <type>Panel</type>
                <date>2026-02-17T16:00:00-07:00</date>
                <start>16:00</start>
                <duration>00:45</duration>
                <abstract>As Web3 moves from niche experiments to institutional-grade infrastructure, our security models are hitting a tipping point. This panel explores how the industry is maturing to meet the demands of mainstream adoption without abandoning decentralization. We&#8217;ll look at what&#8217;s fundamentally shifting&#8212;from the evolution of smart contract security and wallets to the critical rise of operational security (OpSec)&#8212;and what remains immutable.</abstract>
                <slug>darkmode-2026-88422-web3-security-s-evolution-for-mainstream-adoption</slug>
                <track>Hot takes</track>
                
                <persons>
                    <person id='88973'>Michael Lewellen</person><person id='89019'>Anto</person><person id='89026'>Andrew MacPherson (AndrewMohawk) &apos;&lt;#&lt;h1&gt;</person><person id='89043'>Mooly Sagiv</person>
                </persons>
                <language>en</language>
                <description>Mainstream adoption isn&apos;t just about better UI; it&#8217;s about a fundamental shift in how we manage risk. This session brings together security architects from both the &quot;move fast&quot; world of DeFi and the &quot;zero-fail&quot; world of institutions to discuss the practical realities of securing a global ecosystem.

The Evolution of the Stack:

Scaling Security: How do we transition from one-off smart contract audits to continuous, real-time security monitoring and automated response?

The User Experience Paradox: Discussing the shift from the burden of seed phrases to invisible security like MPC, TEEs and Account Abstraction&#8212;and whether we&#8217;re introducing new risks in the process.

Operational Maturity: Why OpSec (key management, governance, and internal controls) is becoming the most critical failure point as organizations move on-chain.

What Stays the Same: Identifying the &quot;load-bearing&quot; pillars of Web3&#8212;like zero-trust and cryptographic proofs&#8212;that must survive the leap to the mainstream.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/UX3RPF/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/UX3RPF/feedback/</feedback_url>
            </event>
            <event guid='f1cd353d-2247-5f03-8ce8-85c7704cedbb' id='88361' code='VDPMHS'>
                <room>Auditorium</room>
                <title>Protecting Keys and Compute with Secure Enclaves</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-17T16:45:00-07:00</date>
                <start>16:45</start>
                <duration>00:20</duration>
                <abstract>Web3 security has cycled from custodial single points of failure to the &quot;seed phrase anxiety&quot; of self-custody. This session explores how Secure Enclaves (TEEs) can offer a unique solution to key management by enabling Verifiable Infrastructure for embedded wallets.

We&#8217;ll dive into Turnkey&#8217;s approach to TEE-based key management&#8212;using hardware-isolated environments like AWS Nitro to move beyond simple signing into a world where every policy is rooted in verifiable proofs. We&apos;ll also discuss Turnkey&apos;s new Verifiable Cloud: a new offering that extends these guarantees to general-purpose workloads, allowing developers to run sensitive code&#8212;from AI agents to DeFi logic&#8212;inside isolated enclaves that produce independently auditable proofs of execution.</abstract>
                <slug>darkmode-2026-88361-protecting-keys-and-compute-with-secure-enclaves</slug>
                <track>New Announcements</track>
                
                <persons>
                    <person id='88973'>Michael Lewellen</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/VDPMHS/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/VDPMHS/feedback/</feedback_url>
            </event>
            
        </room>
        
    </day>
    <day index='3' date='2026-02-18' start='2026-02-18T04:00:00-07:00' end='2026-02-19T03:59:00-07:00'>
        <room name='Auditorium' guid='8a28f735-ce62-54c3-8161-e4b61db80fbb'>
            <event guid='cc59e09f-fc64-571c-85ed-c43d9b79c99c' id='91481' code='NEHCVJ'>
                <room>Auditorium</room>
                <title>Decoding the DC Politics of Crypto Privacy</title>
                <subtitle></subtitle>
                <type>Panel</type>
                <date>2026-02-18T12:00:00-07:00</date>
                <start>12:00</start>
                <duration>00:25</duration>
                <abstract>Kyle Bligen - Decentralization Research Center,Michael Lewellen - Turnkey,Lindsay Fraser - Blockchain Association, Mike Orcutt - Project Glitch</abstract>
                <slug>darkmode-2026-91481-decoding-the-dc-politics-of-crypto-privacy</slug>
                <track>Privacy</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/NEHCVJ/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/NEHCVJ/feedback/</feedback_url>
            </event>
            <event guid='bd136582-744c-58fd-8077-df59b7b46470' id='91482' code='FUUDPW'>
                <room>Auditorium</room>
                <title>State of Surveillance</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-18T12:25:00-07:00</date>
                <start>12:25</start>
                <duration>00:15</duration>
                <abstract>Naomi Brockwell - Ludlow Institute, The modern digital era runs on surveillance, and it gets more invasive every day. In &#8220;State of Surveillance,&#8221; Naomi Brockwell shows how the machine actually works, how it&#8217;s embedded in ordinary daily life, and how it has enabled a monumental power shift in society. She&apos;ll also go over actionable steps you can take to fight back, protect yourself, and help make privacy normal again.</abstract>
                <slug>darkmode-2026-91482-state-of-surveillance</slug>
                <track>Privacy</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/FUUDPW/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/FUUDPW/feedback/</feedback_url>
            </event>
            <event guid='9917726e-c8b7-5850-a89b-57f2f4bb11ed' id='91483' code='8LQSUJ'>
                <room>Auditorium</room>
                <title>Non-Custodial? Not Really! Misconceptions in Key Management</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-18T12:40:00-07:00</date>
                <start>12:40</start>
                <duration>00:15</duration>
                <abstract>TJ Connolly - Fireblocks, A deep dive on the various approaches used by non-custodial &amp; embedded wallets to generate &amp; store private keys for their users, and despite their claims, the truth is most generate key material on software &amp; hardware NOT controlled by the end user, therefore making them de facto custodial.</abstract>
                <slug>darkmode-2026-91483-non-custodial-not-really-misconceptions-in-key-management</slug>
                <track>Privacy</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/8LQSUJ/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/8LQSUJ/feedback/</feedback_url>
            </event>
            <event guid='a7871e65-dd54-5fc3-8034-e9245f45740a' id='91485' code='L7P9WS'>
                <room>Auditorium</room>
                <title>Keynote: Ameen Soleimani</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-18T12:55:00-07:00</date>
                <start>12:55</start>
                <duration>00:15</duration>
                <abstract>Keynote by Ameen Soleimani</abstract>
                <slug>darkmode-2026-91485-keynote-ameen-soleimani</slug>
                <track>Privacy</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/L7P9WS/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/L7P9WS/feedback/</feedback_url>
            </event>
            <event guid='c74c51dd-b593-5ae7-8c65-5d64b66b5ef5' id='91486' code='DAHPWV'>
                <room>Auditorium</room>
                <title>Keynote: Alexander Wilke</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-18T13:10:00-07:00</date>
                <start>13:10</start>
                <duration>00:15</duration>
                <abstract>Keynote: Alexander Wilke</abstract>
                <slug>darkmode-2026-91486-keynote-alexander-wilke</slug>
                <track>Privacy</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/DAHPWV/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/DAHPWV/feedback/</feedback_url>
            </event>
            <event guid='9f758aa1-fcc1-579c-9521-0a6dbc89dbf9' id='91487' code='HSMC3Y'>
                <room>Auditorium</room>
                <title>Proofless Consensus and Client-Side Validation</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-18T13:25:00-07:00</date>
                <start>13:25</start>
                <duration>00:15</duration>
                <abstract>Ying Tong Lai - (In stealth), Proofless consensus is a family of protocols moving transaction validation out of consensus, to client-side devices. This allows for lightweight private payments without placing additional burden on consensus. This talk compares shielded CSV, Intmax, and PlasmaFold, and explores private applications that can be built on top of these.</abstract>
                <slug>darkmode-2026-91487-proofless-consensus-and-client-side-validation</slug>
                <track>Privacy</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/HSMC3Y/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/HSMC3Y/feedback/</feedback_url>
            </event>
            <event guid='2a4b9218-95ac-5582-a8dd-e121039f8dba' id='91490' code='8H88ZS'>
                <room>Auditorium</room>
                <title>Fireside: Zcash&apos;s Zooko Wilcox</title>
                <subtitle></subtitle>
                <type>Panel</type>
                <date>2026-02-18T13:40:00-07:00</date>
                <start>13:40</start>
                <duration>00:20</duration>
                <abstract>Zooko Wilcox - Shielded Labs for Zcash, Moderated by Ben Schiller - Miden</abstract>
                <slug>darkmode-2026-91490-fireside-zcash-s-zooko-wilcox</slug>
                <track>Privacy</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/8H88ZS/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/8H88ZS/feedback/</feedback_url>
            </event>
            <event guid='d8bd331c-7972-50f4-aa1f-2523a4f4ea0d' id='91491' code='ALEX7U'>
                <room>Auditorium</room>
                <title>Keynote: Zak Cole</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-18T14:00:00-07:00</date>
                <start>14:00</start>
                <duration>00:15</duration>
                <abstract>Zak Cole - Ethereum Community Foundation,</abstract>
                <slug>darkmode-2026-91491-keynote-zak-cole</slug>
                <track>Privacy</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/ALEX7U/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/ALEX7U/feedback/</feedback_url>
            </event>
            <event guid='08a98484-d8b5-58d4-8ac9-350eac5f5c8d' id='91492' code='FL8VYA'>
                <room>Auditorium</room>
                <title>Crypto Lost the Plot: How Blockchain Forgot Its Own Canon</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-18T14:15:00-07:00</date>
                <start>14:15</start>
                <duration>00:20</duration>
                <abstract>Zac Williamson - Aztec Network, Blockchain began as a rebellion against institutional power, but gradually retreated into safer terrain: speculation settlement, and regulatory-friendly finance. This talk argues that the field&#8217;s real failure wasn&#8217;t technical, it was canonical &#8211; splitting its founding myth into &#8220;number go up&#8221; finance and an underpowered vision of social coordination that never fully materialized. With privacy-preserving cryptography now real, crypto stands at a reckoning: becoming the institutional technology it promised to be or be remembered as a failed rebellion that optimized complacency and called it progress.</abstract>
                <slug>darkmode-2026-91492-crypto-lost-the-plot-how-blockchain-forgot-its-own-canon</slug>
                <track>Privacy</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/FL8VYA/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/FL8VYA/feedback/</feedback_url>
            </event>
            <event guid='9a6ef293-f86a-52a4-b7ee-c2cf60d5ed20' id='91493' code='ZSTD3M'>
                <room>Auditorium</room>
                <title>The Infrastructure Capital Markets Need to Go Onchain</title>
                <subtitle></subtitle>
                <type>Short Talk</type>
                <date>2026-02-18T14:35:00-07:00</date>
                <start>14:35</start>
                <duration>00:15</duration>
                <abstract>Howard Wu, Capital markets are moving onchain, but public stablecoin rails expose balances, flows, and counterparties. This session examines the ZK infrastructure behind private, compliant, programmable stablecoins like USDCx and what institutions require to deploy real capital safely.</abstract>
                <slug>darkmode-2026-91493-the-infrastructure-capital-markets-need-to-go-onchain</slug>
                <track>Privacy</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/ZSTD3M/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/ZSTD3M/feedback/</feedback_url>
            </event>
            <event guid='a5150ad3-6046-5e11-8a18-47344b17f945' id='91501' code='MSKFFY'>
                <room>Auditorium</room>
                <title>Stablecoin Endgame: Programmable Privacy</title>
                <subtitle></subtitle>
                <type>Long Talk</type>
                <date>2026-02-18T14:50:00-07:00</date>
                <start>14:50</start>
                <duration>00:30</duration>
                <abstract>Matthew Green, Ian Miers, &#9200; Howard Wu, Ben Lakoff - Bankless Ventures

Stablecoins need privacy to be usable for real payments. This session reveals how zero-knowledge stablecoins unlock global payroll, commerce, and remittances without exposing sensitive financial data. Learn from the pioneers making private money finally work at scale.</abstract>
                <slug>darkmode-2026-91501-stablecoin-endgame-programmable-privacy</slug>
                <track>Privacy</track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://darkmode.securityalliance.org/darkmode-2026/talk/MSKFFY/</url>
                <feedback_url>https://darkmode.securityalliance.org/darkmode-2026/talk/MSKFFY/feedback/</feedback_url>
            </event>
            
        </room>
        
    </day>
    
</schedule>
