Register and share your invite link to earn from video plays and referrals.

Security Alliance
@_SEAL_Org
Securing the future of crypto | Cover art by @yueko__ | Emergencies:
103 Following    20.9K Followers
🔥 @1inch has joined the SEAL Safe Harbor! 1inch users are now getting an extra layer of protection, as white hats turn their good-faith interventions from a legal risk into protected action whenever needed. See all protected protocols →
Show more
🔥 Please welcome our newest Safe Harbor member: @AccountableData Notably, Accountable’s policy allows whitehats to respond anonymously, no named KYC required, lowering the barrier for good-faith experts to act fast & help rescue funds during an active exploit. More on Safe Harbor:
Show more
🚨PSA: For anyone whose funds were drained from an affected COLDCARD: Do not destroy, discard, reset, sell—or shoot—the original device. It is too soon to know what any recovery process might look like, but physical possession could become important evidence. Preserve it intact.
Show more
We're so grateful to everyone who contributed to the @TheDAOFund's recent Ethereum Security round! Your support helped fund critical updates for all of our programs: - SEAL Certifications (recently launched GA!🎉) - SEAL911 (incident resolution log: - SEAL Frameworks (launched several new domains!🎉) - SEAL White Hat Safe Harbor (launched several new adoptions! 🎉) - SEAL Intel (published our first quarterly threat report!🎉) We're a lean team, so all funding goes directly to sustaining these operations and extending our runway. <$5K: Covers a few days of operational costs - helps keep servers running and tools maintained. 5K-10K: Covers roughly one to two weeks of operations across all SEAL initiatives. 10K-25K: Covers 2-5 weeks of operations, helping us maintain continuity through 2026. 25K-50K: Covers 1-2 months of operations, giving us real breathing room. 50K+: Covers a month or more, and meaningfully extends our runway, letting us plan ahead instead of month-to-month. You can still support our initiatives at:
Show more
One of the best parts of running an open funding round is being able to learn in the open. The @thedaofund Ethereum Security QF Round retrospective is now live!! Inside you'll find what worked, what didn't, and the improvements we're already thinking about for future rounds. Thank you to everyone who joined our retrospective calls and shared thoughtful feedback along the way. 💜
Show more
He’s not exaggerating. We broke down those five things, what they are, why they keep working, & what actually stops them. Our 2Q 2026 Threat Intel Summary is available here:
Show more
I am working on a quarterly threat intel report for SEAL and goddamn blockchain projects are basically constantly getting rekt by the same things over and over again. And when I say 'the same things' it is literally the same things that somehow everybody claims to be 'well aware off' or 'not that stupid to fall for it'. And 90% of those things is actually easy to stop but that doesn't happen because nobody bothers with the actual recommendations made by security / threat / appsec / opsec people even if those are made for free or near-free if you include tooling. Like, it is honestly ridiculous when you finally get to creating the 'big picture' view. It even fooled me. I somehow thought - Omg, we deal with so many different things, tens of different things, 20 tickets and tips and signals a day, how am I supposed to cover it all! The answer - it is maybe like FIVE different things just over and over and over again. DPRK campaigns literally exists because of that massive discrepancy between signaling ("We are audited") and the reality ("... but we don't know what that means"). Yes, there is some adaptation/evolution on Norks part but only against nerds that chase them and not against geeks that get rekt by them. TTPs are EXACTLY the same, EDRs are DETECTING their malware, goddamn, I think in one or two instances we've seen their attack chain failing because of the firewall setting and they just gave up and moved to someone who just doesn't give a F at all? The bar is in hell and we only do not get another record hack front page news because the whole industry is in massive bear market.
Show more
We've just signed an accreditation agreement with @_SEAL_Org . This will help us provide operational security audits to protocols. Nowadays, approximately 70% of incidents come from operational issues. A compromised signer, a DNS takeover and many more. Our opsec audits cover multisig ops, treasury, incident response, DevOps, and identity controls. Shipping safely doesn't only mean securing the code, but also the operation behind it. Ship Safely. 🚀 Operate Securely🫡
Show more
Thank you, @UniswapFND for your generous support as a Silver Donor. Your commitment to a safer ecosystem makes our work possible. 🙏
🌷 @flyingtulip_ is now part of SEAL Safe Harbor, so authorized whitehats can help rescue funds during active exploits. That brings us to 31 protocols that have chosen to give whitehats a legal path to act when it matters most! 🎉
Show more
We’re proud to welcome @HyperFND as our newest Platinum Donor. With this support SEAL can do more emergency response, more threat intelligence, & more protection for the entire ecosystem.
Show more
“The DEF team is honored to play a role in amplifying the amazing cybersecurity expertise that already exists, and we look forward to introducing policymakers to OPSeC team members and resources.” — @amandatums on the OPSeC launch in @TheBlockCo @ForTheWynn_
Show more
Better-informed policy is good for everyone building in this space. OPSeC gives our industry a way to make that happen by curating free security resources, hosting educational events, and ensuring technical frameworks reach the policymakers who need them. Learn more:
Show more
Introducing OPSeC: a new industry-wide initiative we're convening in partnership with @_SEAL_Org & @asymmetric_re to improve cybersecurity resilience across blockchain ecosystems & onchain software. Join us to ensure security is at the heart of onchain technology development.
Show more
Want help with your operational security? We are approved by @_SEAL_Org to offer certifications that cover your operational security to make sure your systems are as safe as your code. Want to see the data Stefan refers to? We put together a 4-year report on web3 security:
Show more
Most multisig failures don't start with bad code. They start with "I thought someone else was handling that." @_SEAL_Org's Multisig Ops certification has 24 controls across 6 sections. Control "Named Multisig Operations Owner" is first for a reason. It asks one question: Is there a clearly named person or team accountable for multisig operations? Accountability scope according to SEAL: — Policy maintenance — Signer onboarding/offboarding — Documentation accuracy — Periodic reviews — Incident escalation Check your protocol. Open your internal docs. Search for whoever owns each of these five things. If you can't find a name in under 60 seconds, you don't have a named owner. You have an assumption. Assumptions are how a compromised signer stays on a multisig for 3 months after they leave the team. This is day 1 of a 30-day series on the SEAL Multisig Ops certification framework. One control per day. Self-assessment questions your protocol can answer today.
Show more
A huge thank you to @krakenfx for supporting SEAL’s mission to protect the crypto ecosystem. Your generosity directly funds the people and infrastructure keeping this space safer for everyone. We’re grateful to have you in our corner. 🙏
Show more
Long before supporting SEAL was the obvious move, @code4rena was already there. They helped us build the foundation that SEAL stands on, from the Whitehat Safe Harbor Agreement to a community of researchers who understood that coordination matters as much as competition. That legacy doesn’t wind down. Thank you for everything you’ve given this community. 💙
Show more
🌟 SEAL Frameworks Stewards Spotlight: Meet @n0guest & @hexnickk from @LidoFinance Stewards are experts who maintain individual SEAL Frameworks, review contributions, and help others implement security best practices. They help keep our frameworks current and useful! 🧵 (1/3)
Show more