To see our schedule with full functionality, like timezone conversion and personal scheduling, please enable JavaScript and go here.
09:00
09:00
45min
SEAL darkMode - Doors Open
Auditorium
09:45
09:45
5min
Welcome to darkMode
samczsun

samczsun welcomes you to SEAL's first annual security conference, darkMode

Other
Auditorium
09:50
09:50
20min
Old Hacks Targeting New Industries: How to Balance User Privacy and Security
Andrew Chang-Gu

Your smart contracts are audited, but is your contractor’s laptop? Most Web3 "hacks" aren't complex cryptographic exploits—they're basic Web2 security failures. From weak Discord credentials to unmanaged endpoints, many web3 companies have forgotten the web2 security fundamentals.

Join Andrew, a Mandiant/Google Cloud security expert with a decade of experience securing global financial giants, as he deconstructs the traditional attacks currently gutting the Web3 ecosystem. Learn why your "decentralized" future is failing at the basics, and how you can balance security and user privacy.

Lessons Learned
Auditorium
10:10
10:10
20min
Safeguarding Your Digital Footprint: A Privacy-First Approach to Web3 OPsec
Benjamin Speckien

Wireless networks, a ubiquitous and often overlooked element of Web3 projects, pose a significant operational security (OPSEC) risk due to a phenomenon called "beaconing." As mobile devices move, they publicly disseminate personally identifiable information (PII) that malicious actors can combine with open-source intelligence (OSINT) to infer a user's travel plans, physical addresses, past conference attendance, associated crypto projects, and even the location of hardware wallets. This vulnerability contributes to the increasing threat of physical attacks (such as kidnapping and ransom, or "wrench attacks") and social engineering, as well as the risk of disclosing material nonpublic information.

This workshop will walk attendees through using readily available tools to collect and analyze everyday wireless signals. Hardware crypto wallets will be made available for analysis. Other secure tooling will be observed. Will there be enough information in the room to identify devices, individuals, crypto wealth? We will see.

Privacy
Auditorium
10:30
10:30
20min
TOTP apps are dead and why you are doing 2FA wrong
Pablo Sabbatella

I will present a summary of how 2FA works, the different methods (SMS, TOTP apps, Yubikeys, Passkeys, etc), the weaknesses each one of them have, how they are being exploited, and what we have to do in order to start using 2FA in a safe way.

Hot takes
Auditorium
10:50
10:50
20min
Get off my lawn: you're forgettin' your web2 security risk, young whippersnapper
J.M. Porup

Web2 is the Soft Underbelly of Web3

Web3 Security has a Web2 Security problem. As on-chain code gets better and better, attackers are going to go after the low-hanging fruit--and that means all the boring "legacy cybersecurity stuff" your grandpa used to tell you about. (See: the ByBit hack in Feb 2025, classic web2 compromise with web3 impact).

"Back in mah day, we cared about phishing and end point device security. Oh, and young whippersnapper, and did you know 'the cloud' just means 'someone's else's computer'? Sure seems like a terrible idea to run all yer validators in (checks notes) AWS, doncha think? Using CIA's preferred cloud vendor--that'll stick it to the man fer sure LOL!"

"and betcha never heard of this here dang thing called a SIEM before either, have yeah?"

I once met a security engineer at a conference who described themselves as a "web3 native security engineer". Couldn't explain TCP/IP, how Linux works, how a browser works, couldn't tell me the OSI model, but boy did they know a lot about Solidity security!

Yeah. Don't be that guy. Cuz you're going to get rekt if you do.

Come to grandpa's[*] curmudgeonly fireside chat to hear about all the old stuff that still matters today.

[*] not an actual grandpa. yet.

Hot takes
Auditorium
11:10
11:10
20min
Inside Immunefi’s Highest-Paying Bug Bounties of 2025
Alejandro Munoz-McDonald

In 2025 alone, Immunefi paid out close to $11,000,000 in bug bounties for critical crypto vulnerabilities. preventing exploits that could have resulted in hundreds of millions of dollars in losses.

This talk breaks down a few of the highest-impact bounty payouts of 2025, focusing on what actually drove seven-figure and high six-figure rewards. We’ll examine specific vulnerabilities, system designs, and attacker mindsets behind the most severe findings, and explain why these specific bugs justified such large payouts.

This session is grounded in specific cases in 2025 across DeFi, bridges, L2s, and core infrastructure. Attendees will gain a practical understanding of where the highest paying security risks surfaced in 2025, and what both researchers and protocol teams should prioritize going forward.

Lessons Learned
Auditorium
11:30
11:30
20min
When the AppleJeus GitHub is Worth The Squeeze
Daniel Gordon

AppleJeus, also known as Citrine Sleet, Gleaming Pisces, and Smooth Operator, is the North Korean hacker behind the Radiant Capital heist among others. This is the story of finding a previously undiscovered AppleJeus campaign targeting fintech. This talk will also give some background on North Korean hacking groups, show simple pivoting for analysts, and give recommendations to help protect your organization from North Korean threat actors.

Lessons Learned
Auditorium
11:50
11:50
60min
Lunch
Auditorium
13:00
13:00
20min
SEAL Certifications: A Collaborative Framework for Maturity in Crypto Security
Isaac Patka

Security Alliance (SEAL) is developing an open, collaborative certification program to help the crypto ecosystem define and demonstrate operational security maturity. Built on lessons learned from years of emergency incident response and threat intelligence sharing, SEAL Certifications distill collective knowledge into actionable standards developed openly with the community. For protocols, this means clear guidance to strengthen security posture and a credible way to signal trustworthiness to users, investors, and insurers. Currently in pilot with full rollout planned for 2026, this talk introduces the certification framework and how protocols and security firms can get involved. Presented by Isaac Patka, initiative lead.

New Announcements
Auditorium
13:20
13:20
20min
Trafficked Trust: The Human Cost of Crypto Scams
dobs

We often analyze the "social engineering" behind cryptocurrency fraud, but we rarely discuss the coercion that powers it. Trust is manufactured at gunpoint in scam compounds around the world.

This talk exposes the reality of the industrialized criminality, where human trafficking fuels the global theft of digital assets.

We will trace the operation from the ground up: from the fake job ads that entrap the workforce to physical compounds like those in Myanmar where victims are forced to execute the fraud.

Drawing on active field intelligence and exclusive documentary footage, we will map the full cycle of the crime. This is a look at how criminal syndicates have weaponized human captivity to exploit the cryptocurrency ecosystem.

Lessons Learned
Auditorium
13:40
13:40
20min
TheDAO Security Fund
Griff Green

I want to introduce the fund to gather awareness!

There was some left over funding in TheDAO (Over 70k ETH) and we want to use it to fund ETH Security projects!

New Announcements
Auditorium
14:00
14:00
10min
Break
Auditorium
14:10
14:10
20min
The CPIMP Backdoor: Anatomy of a Multi-Chain Proxy Attack
Neville Grech

A deep dive into the CPIMP vulnerability—how a stealthy proxy-in-the-middle attack infected dozens of DeFi protocols across chains, embedded persistent backdoors, and how Dedaub and SEAL 911 raced to neutralize it before widespread exploitation.

Vulnerability Disclosure
Auditorium
14:30
14:30
45min
Stopping the Rubber Hose Attack: Hot Takes
smagdali, Kurt Opsahl, Elliot

Home invasions and physical attacks to get crypto transfers are all too common, and have led to grim situations. With all the factors, passphrase and biometrics in the world, people remain susceptible to the rubber hose. This panel will discuss theories and practices for defending against a rubber hose attack, through deterrence, defenses and mitigations. We will start with the assumption that the goal is to preserve life and limb, and preventing or reversing token transfer is secondary, but how to get there, and be reasonably confident that it will not backfire, is hard.

Hot takes
Auditorium
15:15
15:15
20min
Bypassing Cloaking when Hunting Phishing Sites
Nikita Varabei

Wallet Drainers and other forms of phishing try to hide from security systems designed to catch them.

From Query param keys, to fake blog posts, and time limited attacks, there are many ways that scammers hide their sites from detection and blocklisting.

In this talk we will go over the latest cloaking techniques these sites use, approaches to bypassing cloaking, and some unsolved problems that will spark ideas.

Lessons Learned
Auditorium
15:35
15:35
20min
Mastering Security through Simple Machines: How Consistency, Not Complexity, Drives Innovation
Ken Toler

In the security industry, we often take well-established development practices, such as the DevOps infinity loop, add a layer of security, and label it "DevSecOps." However, this approach frequently overlooks a critical issue: layering complex security processes onto efficient development processes can create inefficiency. In this talk, I argue that true innovation in security comes not from tooling or automation alone, but from mastering the underlying process first. By drawing an analogy to simple machines — where incremental improvements led to the evolution of tools like levers, wheels, and pulleys — I will illustrate how optimizing foundational processes leads to scalable, effective security practices. Attendees will leave with practical insights on reducing inefficiencies and fostering consistent improvement in their security workflows.

Hot takes
Auditorium
15:55
15:55
20min
Security Between the Code: Why Technical Excellence Can Fail
Kelsie Nabben, matta

Security exploits in decentralised systems are rarely caused by technical failures alone. Instead, they emerge at the edges between code, incentives, and institutions - where authority is informal, coordination is improvised, and legitimacy is contested.

Drawing on multi-year ethnographic research embedded in decentralised security communities and real world experience in security practices, this talk reframes security as a socio-technical phenomenon: one sustained not only by protocols and tools, but by moral codes, information practices, incentive structures, and cross-institutional coordination. While the ecosystem is still (rightly) investing heavily in technical interventions (such as improved wallets and developer tooling), many high-impact dynamics remain under-acknowledged, including white-hat incentives, incident information formats, coordination with traditional authorities, and the physical and organisational realities of security work.

The presentation outlines key findings from a forthcoming book on blockchain security, followed by a practitioner response and Q&A with Matta from The Red Guild, who works daily on frontline interventions including phishing education, operational security guidance, and adversarial response. Together, the session bridges analytical diagnosis with operational reality, offering security professionals a clearer map of the system they already inhabit—and a basis for thinking differently about where leverage actually lies, and what needs to be done to improve the state of blockchain security.

Lessons Learned
Auditorium
16:15
16:15
45min
Why Your Multisig Won't Save You: Attacks Against High-Value Holders
Elliot

Multisig wallets give holders a false sense of security. The real attack surface isn't key compromise, it's all of the human and non-deterministic elements. Spoofed simulations, poisoned addresses, compromised frontends, and coerced signers all exploit the same gap. Users don't know what they're signing, and by the time they find out something is wrong, it's already too late. This talk introduces a threat model for high-value custody and presents Kleidi, a wallet system built around reversibility, configurable policies, and guardian-based recovery.

New Announcements
Auditorium
09:00
09:00
30min
SEAL darkMode - Doors Open
Auditorium
09:30
09:30
45min
When Agents Get Tools: Security for Autonomous Systems
Consensys Diligence, Andrew MacPherson (AndrewMohawk) '<#<h1>, Alex Stokes

Autonomous agents are moving from experiment to infrastructure. They're sharing tools, communicating with each other, and increasingly operating with real money. But the security conversation hasn't caught up. What happens when an agent gets compromised through shared tooling? How do you lock down something designed to act independently? And when agents need wallets to function, what does crypto security teach us about protecting them?

Hot takes
Auditorium
10:15
10:15
20min
LLM Auditing, Better Than Cats?
Everett Hildenbrandt

Everyone and their mother is trying to launch an AI auditing tool (usually meaning an LLM-based auditing tool). Do they perform any better than cats at auditing? Do they fill the same market purpose as auditing? This talk will take a praxeological approach to the question (as opposed to an empirical/scientific approach), so buckle up for some half-baked un-substantiated opinions! Mixed in will be some things I do think LLMs are good for in the auditing process, and some ideas of other approaches that may work better (some even being taken by some teams already).

Hot takes
Auditorium
10:35
10:35
20min
Co-Auditing With AI: Practical Techniques
George Kobakhidze

Smart-contract security has reached a scale where purely manual review no longer keeps pace. However, fully automated AI auditors may miss context, intent, and threat models that experienced reviewers take for granted.
This talk showcases how one can integrate agent-style AI tools directly into their audit workflows to accelerate personal reasoning and amplify each auditor's individual expertise.

Lessons Learned
Auditorium
10:55
10:55
45min
From vibes to vulnerabilities
Andrew MacPherson (AndrewMohawk) '<#<h1>

I am not a vuln researcher and that's kind of the point, LLMs have come a long way in the cyberz. I tried to find a real RCE with Codex, I failed so badly that I accidentally learned how to find bugs in common projects with LLMs. This talk is about using AI to turn bad vibes into real bugs. Drawing on multiple CVEs across React, Node, Ollama, Wordpress, etc and other projects, I'll show how anyone with a little debugging and security knowledge can go from vibes to vulnerabilities

Vulnerability Disclosure
Auditorium
11:40
11:40
60min
Lunch
Auditorium
12:40
12:40
20min
How we stop North Korea getting away with the next Billion: Next generation of security professional coordination and new high speed threat intel network.
Casey G, Col G

In the Bybit incident response, a lot went right. The ecosystem showed up, teams moved fast, and we used the tools at our disposal to trace flows and push actionable intelligence.

But there was also a lot that went wrong. Some parts of the ecosystem were not responsive to investigators. Despite their best efforts, law enforcement around the world, they simply did not have enough workforce to dedicate to supporting the freezes and litigation. No matter how fast investigators could post new addresses to freeze the stolen money, it would take hours or even days to be published and actionable. On the other hand, North Korea and collaborators were moving at the rapid speed of blockchain settlement, measured in seconds. Investigators were moving at human coordination and off-chain corporate and government speeds, measured in hours and days. We were always chasing.

So how do we work together to do better the next time? We need to fix both the people & company coordination and the high speed intelligence infrastructure to support that coordination.

In this presentation we will highlight the Coalition for Freezing & Recovering (SEAL & zeroShadow project) and showcase the launch of zeroShadow’s new Threat Intelligence Platform (free critical infrastructure to all Web3 projects).

zeroShadow Threat Intelligence Platform (zS TIP): a high-speed intel network built so real-time coordination doesn’t depend on one-off channels. Trusted security teams can share vetted signals in real time, and VASPs receive those signals as they happen to make informed risk decisions quickly. From OFAC sanctioned addresses to the latest hacks and exploits, members will have access to this critical intelligence to stay safe, stay compliant, and be part of the solution to disrupt laundering and help return stolen assets to victims.

New Announcements
Auditorium
13:00
13:00
45min
Attack Chains in Web3: Lessons from Multi‑Stage Web3 Exploits
Sebastian Banescu

Most Web3 incidents aren’t “one bug, one drain” anymore. Attackers increasingly chain weaknesses across layers such as legacy contracts, subtle numerical edge cases, protocol/bridge exit paths, and off-chain vendor exposure, into an exploit path that ends in irreversible loss. In this talk we'll take a look at some high-signal incidents from 2025 and discuss how to break attack chains before they reach funds. Lessons learned will include practical strategies that projects may adopt to build defense-in-depth that breaks attack chains.

Lessons Learned
Auditorium
13:45
13:45
20min
TraderTraitor: A Real Bad MATA
Daniel Gordon

TraderTraitor, also known as Jade Sleet, Slow Pisces, UNC4899, Dark River is the North Korean threat actor behind major cryptocurrency heists from ByBit, DMM, WazirX, CoinsPaid, Alphapo, Atomic Wallet, Horizon Bridge, Ronin Bridge, and many others. This presentation is a deep dive into TraderTraitor and will cover how they compromise their victims, how defenders and security teams can track TraderTraitor, and measures that organizations can take to protect themselves from being the next Bybit. This presentation will have non-public details about TraderTraitor activity.

Lessons Learned
Auditorium
14:05
14:05
10min
Break
Auditorium
14:15
14:15
20min
When the Supply Chain Isn’t Chaining: Stop Reinventing the Wheel
Nikita Belenkov

We keep seeing the same supply chain failures in crypto: compromised dependencies, leaked or abused publishing keys, and malicious or compromised contributors. These incidents are often framed as uniquely web3, leading teams to design bespoke trust models rather than adopt proven, well-understood security practices.

From an attacker’s perspective, none of this is new.

Open-source communities have spent years responding to these exact classes of supply chain attacks, resulting in concrete standards such as SLSA and ecosystem-level guidance and tooling from the OpenSSF. These approaches map directly to crypto development workflows, yet remain underutilized in practice. Instead, we repeatedly invent new frameworks, often increasing complexity without reducing risk.

In this talk, I’ll walk through how we approach release system design at Anza, looking at the full development lifecycle through an adversarial lens. We’ll identify where things commonly go wrong, how existing tools and frameworks already address these failure modes, and why reinventing the wheel in supply chain security frequently makes systems less secure, not more. I’ll also cover emerging tooling like gittuf, which takes a fundamentally different approach to Git security and policy enforcement.

Lessons Learned
Auditorium
14:35
14:35
20min
Lido V3: Security by Design
Tomer Ganor

Protocol security is shaped long before the first line of code is written. In this talk, Tomer Ganor, Tech Lead and Security Researcher at Certora, explores how Lido V3 combines security thinking with protocol design to reduce attack surfaces, prevent bugs, and strengthen the Ethereum infrastructure

Other
Auditorium
14:55
14:55
45min
From Chaos to Containment: Making Incident Response Actually Work in the Digital Asset Economy
Cantina, Sharon Ideguchi

Practical incidents + ops learning. Panel may also include “hot takes”.

Crypto incidents don’t behave like traditional breaches. They unfold in minutes, span chains, and can cause infinite cascading damage along the way. Most teams are still improvising without training or realistic strategies in place. This panel brings together leading DeFi security teams to share practical incident lessons, working incident pipelines, and response playbooks that actually hold up under live attack conditions.

The outcome: practical insights, candid stories, and debate on what the industry must fix next.

Lessons Learned
Auditorium
15:40
15:40
20min
Crazy Chains: Why Incident Response Breaks Outside the EVM
Ken Toler

Most incident response and chain analysis tooling is built with an implicit assumption: account-based execution risk is the problem. That assumption holds, until it doesn’t.

Using Filecoin as a case study, this talk explores why many otherwise capable vendors struggle to support novel chains, and why gaps appear not because of neglect but because the mental model itself breaks down and product margins don't get in the way.

Filecoin isn’t a smart contract chain with storage bolted on. It’s a distributed system designed to verify long-lived behavior across independent operators. The primary asset isn’t just balance but it’s behavior over time. The dominant risks may not necessarily exploits, but they're based in incentive failures, coordinated degradation, and economic edge cases.

We’ll unpack what this means for incident response teams and why chain analysis and incident response platforms tend to miss the mark when stepping outside familiar ecosystems:

  • Why transaction-centric alerts miss slow-burn incidents
  • Why actor behavior matters more than bytecode inspection
  • Why “the incident” often belongs to the network, not an app
  • Why generic EVM heuristics actively create false confidence and false positives

To be crystal clear this talk is not a critique of vendors, it’s a lessons-learned hot take briefing from the field. Supporting novel chains requires different playbooks, different baselines, and a willingness to abandon security absolutism in favor of contextual risk analysis.

The key takeaway: if your incident response model can’t reason about incentives, time, and roles, it will fail quietly on novel chains right up until the ecosystem feels the impact.

This session aims to help security teams recognize those limits early, adapt deliberately, and build coverage that actually reflects how decentralized infrastructure fails in practice.

Hot takes
Auditorium
16:00
16:00
45min
Web3 Security's Evolution for Mainstream Adoption
Michael Lewellen, Anto, Andrew MacPherson (AndrewMohawk) '<#<h1>, Mooly Sagiv

As Web3 moves from niche experiments to institutional-grade infrastructure, our security models are hitting a tipping point. This panel explores how the industry is maturing to meet the demands of mainstream adoption without abandoning decentralization. We’ll look at what’s fundamentally shifting—from the evolution of smart contract security and wallets to the critical rise of operational security (OpSec)—and what remains immutable.

Hot takes
Auditorium
16:45
16:45
20min
Protecting Keys and Compute with Secure Enclaves
Michael Lewellen

Web3 security has cycled from custodial single points of failure to the "seed phrase anxiety" of self-custody. This session explores how Secure Enclaves (TEEs) can offer a unique solution to key management by enabling Verifiable Infrastructure for embedded wallets.

We’ll dive into Turnkey’s approach to TEE-based key management—using hardware-isolated environments like AWS Nitro to move beyond simple signing into a world where every policy is rooted in verifiable proofs. We'll also discuss Turnkey's new Verifiable Cloud: a new offering that extends these guarantees to general-purpose workloads, allowing developers to run sensitive code—from AI agents to DeFi logic—inside isolated enclaves that produce independently auditable proofs of execution.

New Announcements
Auditorium
11:00
11:00
60min
SEAL darkMode - Doors Open
Auditorium
12:00
12:00
25min
Decoding the DC Politics of Crypto Privacy

Kyle Bligen - Decentralization Research Center,Michael Lewellen - Turnkey,Lindsay Fraser - Blockchain Association, Mike Orcutt - Project Glitch

Privacy
Auditorium
12:25
12:25
15min
State of Surveillance

Naomi Brockwell - Ludlow Institute, The modern digital era runs on surveillance, and it gets more invasive every day. In “State of Surveillance,” Naomi Brockwell shows how the machine actually works, how it’s embedded in ordinary daily life, and how it has enabled a monumental power shift in society. She'll also go over actionable steps you can take to fight back, protect yourself, and help make privacy normal again.

Privacy
Auditorium
12:40
12:40
15min
Non-Custodial? Not Really! Misconceptions in Key Management

TJ Connolly - Fireblocks, A deep dive on the various approaches used by non-custodial & embedded wallets to generate & store private keys for their users, and despite their claims, the truth is most generate key material on software & hardware NOT controlled by the end user, therefore making them de facto custodial.

Privacy
Auditorium
12:55
12:55
15min
Keynote: Ameen Soleimani

Keynote by Ameen Soleimani

Privacy
Auditorium
13:10
13:10
15min
Keynote: Alexander Wilke

Keynote: Alexander Wilke

Privacy
Auditorium
13:25
13:25
15min
Proofless Consensus and Client-Side Validation

Ying Tong Lai - (In stealth), Proofless consensus is a family of protocols moving transaction validation out of consensus, to client-side devices. This allows for lightweight private payments without placing additional burden on consensus. This talk compares shielded CSV, Intmax, and PlasmaFold, and explores private applications that can be built on top of these.

Privacy
Auditorium
13:40
13:40
20min
Fireside: Zcash's Zooko Wilcox

Zooko Wilcox - Shielded Labs for Zcash, Moderated by Ben Schiller - Miden

Privacy
Auditorium
14:00
14:00
15min
Keynote: Zak Cole

Zak Cole - Ethereum Community Foundation,

Privacy
Auditorium
14:15
14:15
20min
Crypto Lost the Plot: How Blockchain Forgot Its Own Canon

Zac Williamson - Aztec Network, Blockchain began as a rebellion against institutional power, but gradually retreated into safer terrain: speculation settlement, and regulatory-friendly finance. This talk argues that the field’s real failure wasn’t technical, it was canonical – splitting its founding myth into “number go up” finance and an underpowered vision of social coordination that never fully materialized. With privacy-preserving cryptography now real, crypto stands at a reckoning: becoming the institutional technology it promised to be or be remembered as a failed rebellion that optimized complacency and called it progress.

Privacy
Auditorium
14:35
14:35
15min
The Infrastructure Capital Markets Need to Go Onchain

Howard Wu, Capital markets are moving onchain, but public stablecoin rails expose balances, flows, and counterparties. This session examines the ZK infrastructure behind private, compliant, programmable stablecoins like USDCx and what institutions require to deploy real capital safely.

Privacy
Auditorium
14:50
14:50
30min
Stablecoin Endgame: Programmable Privacy

Matthew Green, Ian Miers, ⏰ Howard Wu, Ben Lakoff - Bankless Ventures

Stablecoins need privacy to be usable for real payments. This session reveals how zero-knowledge stablecoins unlock global payroll, commerce, and remittances without exposing sensitive financial data. Learn from the pioneers making private money finally work at scale.

Privacy
Auditorium
15:20
15:20
60min
darkMode Wraps - Hangout and Social
Auditorium