Skip to content
Glossary

Insider threat

Misuse of access that was legitimately granted, by someone inside the organisation or project.

Why it matters

It defeats the perimeter, because nothing has to be broken into. In crypto the exposure is unusually direct: a single developer with deployment rights or key material can act irreversibly, and vetting is often informal in projects staffed by pseudonymous contributors.

What you can check

The observable mitigations are structural — whether privileged actions require more than one person, whether deployment keys sit behind a multisig, whether there is a timelock between decision and effect, and whether privileged addresses are published at all.

Where it showed up

Records in the Incident Tracker that turn on this: Munchables insider key compromise.

Not advice. Definitions are for understanding, not instruction. Nothing here is financial, legal, tax or security advice.