Field notes
Writing on secure self-custody, efficient onchain operations and opsec, agentic DeFi, and open, modular, extensible architectures.
- Onchain operations · Part 16 min read · plus one treasury to defend
Can you keep $45,000,000?
A simulated treasury, the structure to protect it, and eight threats to run against what you build. Protocol multisigs fail operationally more often than cryptographically; here is what holds up.
Read post → - Threat landscape12 min read
April 2026 was the worst month on record for DeFi exploits
A taxonomy of the incidents — compromised admin keys, overbroad keepers, unsafe configs — and an honest accounting of which classes onchain policy bounds and which it doesn’t.
Read post → - Architecture10 min read
Beyond TEE and MPC: the limits of key-centric custody
Both architectures protect the key. Neither protects the intent. A look at the empirical track record — Foreshadow, Plundervolt, Battering RAM — and why the right answer moves the check to the chain.
Read post → - Incident analysis9 min read
Anatomy of the Bybit hack: why protecting the key wasn’t enough
$1.5B left a cold Safe wallet that did exactly what it was designed to do. The signers signed. The keys were never compromised. The intent verification was missing. A close read of the forensic record and the architectural lesson.
Read post →