Blog
Field notes
Writing on secure self-custody, efficient onchain operations and opsec, agentic DeFi, and open, modular, extensible architectures.
- Threat landscape12 min read
April 2026 was the worst month on record for DeFi exploits
A taxonomy of the incidents — compromised admin keys, overbroad keepers, unsafe configs — and an honest accounting of which classes onchain policy bounds and which it doesn’t.
Read post → - Architecture10 min read
Beyond TEE and MPC: the limits of key-centric custody
Both architectures protect the key. Neither protects the intent. A look at the empirical track record — Foreshadow, Plundervolt, Battering RAM — and why the right answer moves the check to the chain.
Read post → - Incident analysis9 min read
Anatomy of the Bybit hack: why protecting the key wasn’t enough
$1.5B left a cold Safe wallet that did exactly what it was designed to do. The signers signed. The keys were never compromised. The intent verification was missing. A close read of the forensic record and the architectural lesson.
Read post →