Subscribe
Sign in
Home
Notes
Archive
About
Latest
Top
Discussions
The AI Bug-Report Flood Broke curl, Apple, and Linux in One Year
Three of the biggest security programmes hit the same wall. The model finds the vulnerability, but it cannot tell you whether the vulnerability is real.
Aug 10
•
Adrian ⛩️ Hetman
1
Gating AI models Solves the Wrong Problem
The AI labs' own filings say Chinese rivals are already rebuilding the capability of offensive models. The lock only slows the defenders who follow the…
Aug 7
•
Adrian ⛩️ Hetman
1
2
Coldcard’s $116M Entropy Flaw, AFX Trade’s $24M Validator-Key Compromise, and both Big AI Labs' Models Breaking Into Live Systems | Burn…
The largest self-custody failure in Bitcoin's history, a bridge drained through its own validator keys, and the two weeks with frontier AI now hacking…
Aug 6
•
Adrian ⛩️ Hetman
1
July 2026
A $13 Million Bridge Forgery, a Repeated Flash-Loan Exploit, and a Critical WordPress Vulnerability | Burn Notice #10
Wanchain's bridge had operated for more than eight years and Allbridge had already patched its attack class once, yet both were compromised through…
Jul 23
•
Adrian ⛩️ Hetman
1
Ostium Loses $18M, Bonzo Lend $9M, and BlueMove Drains Its Own Pools | Burn Notice #9
Two Oracle Failures and an Alleged Insider Backdoor, Plus a Security Vendor's npm Package Turned Infostealer.
Jul 22
•
Adrian ⛩️ Hetman
1
Bonk's $20M Governance Buyout, Summer.fi's $6M Vault Drain, and Aptos's $70B Move VM Bug | Burn Notice #8
Every loss that mattered this week came through machinery each team had stopped watching.
Jul 9
•
Adrian ⛩️ Hetman
1
Burn Notice #7 | SecondFi's Deterministic Nonce Flaw, Edel Finance's 78x Oracle Manipulation, and THORChain's 39-Day Reopening
One of the three entities that founded Cardano ships a wallet, and this week a flaw in its own signing software handed attackers the private keys to 374…
Jul 3
•
Adrian ⛩️ Hetman
1
1
June 2026
Jared’s $7.5M Approval Sweep, 144 Poisoned npm Packages, and Aztec Drained Twice in a Week | Burn Notice #6
A counter-MEV bot tricked into authorising its own drain, a North Korean crew republishing a million-download package scope, and a four-year-dead bridge…
Jun 24
•
Adrian ⛩️ Hetman
1
Will AI Take the Security Researcher's Job?
Your Security Career in the Age of AI
Jun 23
•
Adrian ⛩️ Hetman
2
2
A Bug Bounty Costs Less Than Getting Hacked
Don't Kill Your Bug Bounty Program Over AI Slop
Jun 21
•
Adrian ⛩️ Hetman
2
2
Burn Notice #5
Aztec Connect’s $2.19M Unpausable Drain, Verus’s $11.6M Replay of a 2022 Bridge Bug, and Two Bounty Programs Going Dark
Jun 17
•
Adrian ⛩️ Hetman
1
The Operational Security Gap Behind 2026's Web3 Losses
Roughly ~200 hack and exploit incidents in the first half of 2026, and about $900M stolen in total. Operational and infrastructure compromises took…
Jun 12
•
Adrian ⛩️ Hetman
1
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts