samczsun welcomes you to SEAL's first annual security conference, darkMode
Your smart contracts are audited, but is your contractor’s laptop? Most Web3 "hacks" aren't complex cryptographic exploits—they're basic Web2 security failures. From weak Discord credentials to unmanaged endpoints, many web3 companies have forgotten the web2 security fundamentals.
Join Andrew, a Mandiant/Google Cloud security expert with a decade of experience securing global financial giants, as he deconstructs the traditional attacks currently gutting the Web3 ecosystem. Learn why your "decentralized" future is failing at the basics, and how you can balance security and user privacy.
Wireless networks, a ubiquitous and often overlooked element of Web3 projects, pose a significant operational security (OPSEC) risk due to a phenomenon called "beaconing." As mobile devices move, they publicly disseminate personally identifiable information (PII) that malicious actors can combine with open-source intelligence (OSINT) to infer a user's travel plans, physical addresses, past conference attendance, associated crypto projects, and even the location of hardware wallets. This vulnerability contributes to the increasing threat of physical attacks (such as kidnapping and ransom, or "wrench attacks") and social engineering, as well as the risk of disclosing material nonpublic information.
This workshop will walk attendees through using readily available tools to collect and analyze everyday wireless signals. Hardware crypto wallets will be made available for analysis. Other secure tooling will be observed. Will there be enough information in the room to identify devices, individuals, crypto wealth? We will see.
I will present a summary of how 2FA works, the different methods (SMS, TOTP apps, Yubikeys, Passkeys, etc), the weaknesses each one of them have, how they are being exploited, and what we have to do in order to start using 2FA in a safe way.
Web2 is the Soft Underbelly of Web3
Web3 Security has a Web2 Security problem. As on-chain code gets better and better, attackers are going to go after the low-hanging fruit--and that means all the boring "legacy cybersecurity stuff" your grandpa used to tell you about. (See: the ByBit hack in Feb 2025, classic web2 compromise with web3 impact).
"Back in mah day, we cared about phishing and end point device security. Oh, and young whippersnapper, and did you know 'the cloud' just means 'someone's else's computer'? Sure seems like a terrible idea to run all yer validators in (checks notes) AWS, doncha think? Using CIA's preferred cloud vendor--that'll stick it to the man fer sure LOL!"
"and betcha never heard of this here dang thing called a SIEM before either, have yeah?"
I once met a security engineer at a conference who described themselves as a "web3 native security engineer". Couldn't explain TCP/IP, how Linux works, how a browser works, couldn't tell me the OSI model, but boy did they know a lot about Solidity security!
Yeah. Don't be that guy. Cuz you're going to get rekt if you do.
Come to grandpa's[*] curmudgeonly fireside chat to hear about all the old stuff that still matters today.
[*] not an actual grandpa. yet.
In 2025 alone, Immunefi paid out close to $11,000,000 in bug bounties for critical crypto vulnerabilities. preventing exploits that could have resulted in hundreds of millions of dollars in losses.
This talk breaks down a few of the highest-impact bounty payouts of 2025, focusing on what actually drove seven-figure and high six-figure rewards. We’ll examine specific vulnerabilities, system designs, and attacker mindsets behind the most severe findings, and explain why these specific bugs justified such large payouts.
This session is grounded in specific cases in 2025 across DeFi, bridges, L2s, and core infrastructure. Attendees will gain a practical understanding of where the highest paying security risks surfaced in 2025, and what both researchers and protocol teams should prioritize going forward.
AppleJeus, also known as Citrine Sleet, Gleaming Pisces, and Smooth Operator, is the North Korean hacker behind the Radiant Capital heist among others. This is the story of finding a previously undiscovered AppleJeus campaign targeting fintech. This talk will also give some background on North Korean hacking groups, show simple pivoting for analysts, and give recommendations to help protect your organization from North Korean threat actors.
Security Alliance (SEAL) is developing an open, collaborative certification program to help the crypto ecosystem define and demonstrate operational security maturity. Built on lessons learned from years of emergency incident response and threat intelligence sharing, SEAL Certifications distill collective knowledge into actionable standards developed openly with the community. For protocols, this means clear guidance to strengthen security posture and a credible way to signal trustworthiness to users, investors, and insurers. Currently in pilot with full rollout planned for 2026, this talk introduces the certification framework and how protocols and security firms can get involved. Presented by Isaac Patka, initiative lead.
We often analyze the "social engineering" behind cryptocurrency fraud, but we rarely discuss the coercion that powers it. Trust is manufactured at gunpoint in scam compounds around the world.
This talk exposes the reality of the industrialized criminality, where human trafficking fuels the global theft of digital assets.
We will trace the operation from the ground up: from the fake job ads that entrap the workforce to physical compounds like those in Myanmar where victims are forced to execute the fraud.
Drawing on active field intelligence and exclusive documentary footage, we will map the full cycle of the crime. This is a look at how criminal syndicates have weaponized human captivity to exploit the cryptocurrency ecosystem.
I want to introduce the fund to gather awareness!
There was some left over funding in TheDAO (Over 70k ETH) and we want to use it to fund ETH Security projects!
A deep dive into the CPIMP vulnerability—how a stealthy proxy-in-the-middle attack infected dozens of DeFi protocols across chains, embedded persistent backdoors, and how Dedaub and SEAL 911 raced to neutralize it before widespread exploitation.
Home invasions and physical attacks to get crypto transfers are all too common, and have led to grim situations. With all the factors, passphrase and biometrics in the world, people remain susceptible to the rubber hose. This panel will discuss theories and practices for defending against a rubber hose attack, through deterrence, defenses and mitigations. We will start with the assumption that the goal is to preserve life and limb, and preventing or reversing token transfer is secondary, but how to get there, and be reasonably confident that it will not backfire, is hard.
Wallet Drainers and other forms of phishing try to hide from security systems designed to catch them.
From Query param keys, to fake blog posts, and time limited attacks, there are many ways that scammers hide their sites from detection and blocklisting.
In this talk we will go over the latest cloaking techniques these sites use, approaches to bypassing cloaking, and some unsolved problems that will spark ideas.
In the security industry, we often take well-established development practices, such as the DevOps infinity loop, add a layer of security, and label it "DevSecOps." However, this approach frequently overlooks a critical issue: layering complex security processes onto efficient development processes can create inefficiency. In this talk, I argue that true innovation in security comes not from tooling or automation alone, but from mastering the underlying process first. By drawing an analogy to simple machines — where incremental improvements led to the evolution of tools like levers, wheels, and pulleys — I will illustrate how optimizing foundational processes leads to scalable, effective security practices. Attendees will leave with practical insights on reducing inefficiencies and fostering consistent improvement in their security workflows.
Security exploits in decentralised systems are rarely caused by technical failures alone. Instead, they emerge at the edges between code, incentives, and institutions - where authority is informal, coordination is improvised, and legitimacy is contested.
Drawing on multi-year ethnographic research embedded in decentralised security communities and real world experience in security practices, this talk reframes security as a socio-technical phenomenon: one sustained not only by protocols and tools, but by moral codes, information practices, incentive structures, and cross-institutional coordination. While the ecosystem is still (rightly) investing heavily in technical interventions (such as improved wallets and developer tooling), many high-impact dynamics remain under-acknowledged, including white-hat incentives, incident information formats, coordination with traditional authorities, and the physical and organisational realities of security work.
The presentation outlines key findings from a forthcoming book on blockchain security, followed by a practitioner response and Q&A with Matta from The Red Guild, who works daily on frontline interventions including phishing education, operational security guidance, and adversarial response. Together, the session bridges analytical diagnosis with operational reality, offering security professionals a clearer map of the system they already inhabit—and a basis for thinking differently about where leverage actually lies, and what needs to be done to improve the state of blockchain security.
Multisig wallets give holders a false sense of security. The real attack surface isn't key compromise, it's all of the human and non-deterministic elements. Spoofed simulations, poisoned addresses, compromised frontends, and coerced signers all exploit the same gap. Users don't know what they're signing, and by the time they find out something is wrong, it's already too late. This talk introduces a threat model for high-value custody and presents Kleidi, a wallet system built around reversibility, configurable policies, and guardian-based recovery.
Autonomous agents are moving from experiment to infrastructure. They're sharing tools, communicating with each other, and increasingly operating with real money. But the security conversation hasn't caught up. What happens when an agent gets compromised through shared tooling? How do you lock down something designed to act independently? And when agents need wallets to function, what does crypto security teach us about protecting them?
Everyone and their mother is trying to launch an AI auditing tool (usually meaning an LLM-based auditing tool). Do they perform any better than cats at auditing? Do they fill the same market purpose as auditing? This talk will take a praxeological approach to the question (as opposed to an empirical/scientific approach), so buckle up for some half-baked un-substantiated opinions! Mixed in will be some things I do think LLMs are good for in the auditing process, and some ideas of other approaches that may work better (some even being taken by some teams already).
Smart-contract security has reached a scale where purely manual review no longer keeps pace. However, fully automated AI auditors may miss context, intent, and threat models that experienced reviewers take for granted.
This talk showcases how one can integrate agent-style AI tools directly into their audit workflows to accelerate personal reasoning and amplify each auditor's individual expertise.
I am not a vuln researcher and that's kind of the point, LLMs have come a long way in the cyberz. I tried to find a real RCE with Codex, I failed so badly that I accidentally learned how to find bugs in common projects with LLMs. This talk is about using AI to turn bad vibes into real bugs. Drawing on multiple CVEs across React, Node, Ollama, Wordpress, etc and other projects, I'll show how anyone with a little debugging and security knowledge can go from vibes to vulnerabilities
In the Bybit incident response, a lot went right. The ecosystem showed up, teams moved fast, and we used the tools at our disposal to trace flows and push actionable intelligence.
But there was also a lot that went wrong. Some parts of the ecosystem were not responsive to investigators. Despite their best efforts, law enforcement around the world, they simply did not have enough workforce to dedicate to supporting the freezes and litigation. No matter how fast investigators could post new addresses to freeze the stolen money, it would take hours or even days to be published and actionable. On the other hand, North Korea and collaborators were moving at the rapid speed of blockchain settlement, measured in seconds. Investigators were moving at human coordination and off-chain corporate and government speeds, measured in hours and days. We were always chasing.
So how do we work together to do better the next time? We need to fix both the people & company coordination and the high speed intelligence infrastructure to support that coordination.
In this presentation we will highlight the Coalition for Freezing & Recovering (SEAL & zeroShadow project) and showcase the launch of zeroShadow’s new Threat Intelligence Platform (free critical infrastructure to all Web3 projects).
zeroShadow Threat Intelligence Platform (zS TIP): a high-speed intel network built so real-time coordination doesn’t depend on one-off channels. Trusted security teams can share vetted signals in real time, and VASPs receive those signals as they happen to make informed risk decisions quickly. From OFAC sanctioned addresses to the latest hacks and exploits, members will have access to this critical intelligence to stay safe, stay compliant, and be part of the solution to disrupt laundering and help return stolen assets to victims.
Most Web3 incidents aren’t “one bug, one drain” anymore. Attackers increasingly chain weaknesses across layers such as legacy contracts, subtle numerical edge cases, protocol/bridge exit paths, and off-chain vendor exposure, into an exploit path that ends in irreversible loss. In this talk we'll take a look at some high-signal incidents from 2025 and discuss how to break attack chains before they reach funds. Lessons learned will include practical strategies that projects may adopt to build defense-in-depth that breaks attack chains.
TraderTraitor, also known as Jade Sleet, Slow Pisces, UNC4899, Dark River is the North Korean threat actor behind major cryptocurrency heists from ByBit, DMM, WazirX, CoinsPaid, Alphapo, Atomic Wallet, Horizon Bridge, Ronin Bridge, and many others. This presentation is a deep dive into TraderTraitor and will cover how they compromise their victims, how defenders and security teams can track TraderTraitor, and measures that organizations can take to protect themselves from being the next Bybit. This presentation will have non-public details about TraderTraitor activity.
We keep seeing the same supply chain failures in crypto: compromised dependencies, leaked or abused publishing keys, and malicious or compromised contributors. These incidents are often framed as uniquely web3, leading teams to design bespoke trust models rather than adopt proven, well-understood security practices.
From an attacker’s perspective, none of this is new.
Open-source communities have spent years responding to these exact classes of supply chain attacks, resulting in concrete standards such as SLSA and ecosystem-level guidance and tooling from the OpenSSF. These approaches map directly to crypto development workflows, yet remain underutilized in practice. Instead, we repeatedly invent new frameworks, often increasing complexity without reducing risk.
In this talk, I’ll walk through how we approach release system design at Anza, looking at the full development lifecycle through an adversarial lens. We’ll identify where things commonly go wrong, how existing tools and frameworks already address these failure modes, and why reinventing the wheel in supply chain security frequently makes systems less secure, not more. I’ll also cover emerging tooling like gittuf, which takes a fundamentally different approach to Git security and policy enforcement.
Protocol security is shaped long before the first line of code is written. In this talk, Tomer Ganor, Tech Lead and Security Researcher at Certora, explores how Lido V3 combines security thinking with protocol design to reduce attack surfaces, prevent bugs, and strengthen the Ethereum infrastructure
Practical incidents + ops learning. Panel may also include “hot takes”.
Crypto incidents don’t behave like traditional breaches. They unfold in minutes, span chains, and can cause infinite cascading damage along the way. Most teams are still improvising without training or realistic strategies in place. This panel brings together leading DeFi security teams to share practical incident lessons, working incident pipelines, and response playbooks that actually hold up under live attack conditions.
The outcome: practical insights, candid stories, and debate on what the industry must fix next.
Most incident response and chain analysis tooling is built with an implicit assumption: account-based execution risk is the problem. That assumption holds, until it doesn’t.
Using Filecoin as a case study, this talk explores why many otherwise capable vendors struggle to support novel chains, and why gaps appear not because of neglect but because the mental model itself breaks down and product margins don't get in the way.
Filecoin isn’t a smart contract chain with storage bolted on. It’s a distributed system designed to verify long-lived behavior across independent operators. The primary asset isn’t just balance but it’s behavior over time. The dominant risks may not necessarily exploits, but they're based in incentive failures, coordinated degradation, and economic edge cases.
We’ll unpack what this means for incident response teams and why chain analysis and incident response platforms tend to miss the mark when stepping outside familiar ecosystems:
- Why transaction-centric alerts miss slow-burn incidents
- Why actor behavior matters more than bytecode inspection
- Why “the incident” often belongs to the network, not an app
- Why generic EVM heuristics actively create false confidence and false positives
To be crystal clear this talk is not a critique of vendors, it’s a lessons-learned hot take briefing from the field. Supporting novel chains requires different playbooks, different baselines, and a willingness to abandon security absolutism in favor of contextual risk analysis.
The key takeaway: if your incident response model can’t reason about incentives, time, and roles, it will fail quietly on novel chains right up until the ecosystem feels the impact.
This session aims to help security teams recognize those limits early, adapt deliberately, and build coverage that actually reflects how decentralized infrastructure fails in practice.
As Web3 moves from niche experiments to institutional-grade infrastructure, our security models are hitting a tipping point. This panel explores how the industry is maturing to meet the demands of mainstream adoption without abandoning decentralization. We’ll look at what’s fundamentally shifting—from the evolution of smart contract security and wallets to the critical rise of operational security (OpSec)—and what remains immutable.
Web3 security has cycled from custodial single points of failure to the "seed phrase anxiety" of self-custody. This session explores how Secure Enclaves (TEEs) can offer a unique solution to key management by enabling Verifiable Infrastructure for embedded wallets.
We’ll dive into Turnkey’s approach to TEE-based key management—using hardware-isolated environments like AWS Nitro to move beyond simple signing into a world where every policy is rooted in verifiable proofs. We'll also discuss Turnkey's new Verifiable Cloud: a new offering that extends these guarantees to general-purpose workloads, allowing developers to run sensitive code—from AI agents to DeFi logic—inside isolated enclaves that produce independently auditable proofs of execution.
Kyle Bligen - Decentralization Research Center,Michael Lewellen - Turnkey,Lindsay Fraser - Blockchain Association, Mike Orcutt - Project Glitch
Naomi Brockwell - Ludlow Institute, The modern digital era runs on surveillance, and it gets more invasive every day. In “State of Surveillance,” Naomi Brockwell shows how the machine actually works, how it’s embedded in ordinary daily life, and how it has enabled a monumental power shift in society. She'll also go over actionable steps you can take to fight back, protect yourself, and help make privacy normal again.
TJ Connolly - Fireblocks, A deep dive on the various approaches used by non-custodial & embedded wallets to generate & store private keys for their users, and despite their claims, the truth is most generate key material on software & hardware NOT controlled by the end user, therefore making them de facto custodial.
Keynote by Ameen Soleimani
Keynote: Alexander Wilke
Ying Tong Lai - (In stealth), Proofless consensus is a family of protocols moving transaction validation out of consensus, to client-side devices. This allows for lightweight private payments without placing additional burden on consensus. This talk compares shielded CSV, Intmax, and PlasmaFold, and explores private applications that can be built on top of these.
Zooko Wilcox - Shielded Labs for Zcash, Moderated by Ben Schiller - Miden
Zak Cole - Ethereum Community Foundation,
Zac Williamson - Aztec Network, Blockchain began as a rebellion against institutional power, but gradually retreated into safer terrain: speculation settlement, and regulatory-friendly finance. This talk argues that the field’s real failure wasn’t technical, it was canonical – splitting its founding myth into “number go up” finance and an underpowered vision of social coordination that never fully materialized. With privacy-preserving cryptography now real, crypto stands at a reckoning: becoming the institutional technology it promised to be or be remembered as a failed rebellion that optimized complacency and called it progress.
Howard Wu, Capital markets are moving onchain, but public stablecoin rails expose balances, flows, and counterparties. This session examines the ZK infrastructure behind private, compliant, programmable stablecoins like USDCx and what institutions require to deploy real capital safely.
Matthew Green, Ian Miers, ⏰ Howard Wu, Ben Lakoff - Bankless Ventures
Stablecoins need privacy to be usable for real payments. This session reveals how zero-knowledge stablecoins unlock global payroll, commerce, and remittances without exposing sensitive financial data. Learn from the pioneers making private money finally work at scale.