This page documents how Conisec produces its records. It is deliberately specific, because a security publication that will not explain its sourcing is asking for the same blind trust it tells its readers to withhold.
What counts as a primary source
A primary source is a document published by a party with direct knowledge of the event:
- An official post-mortem or incident report from the affected project.
- An exchange status page, security notice or regulatory filing.
- A security firm’s technical advisory naming the vulnerability class.
- A regulator’s own notice, register entry, consultation or gazette publication.
- A court filing or charging document.
- An on-chain transaction or contract, cited by hash or address.
Secondary reporting may corroborate a fact, but it never stands alone for a loss figure, an attribution or a legal characterisation. If we cannot reach a primary document, the claim does not publish.
How an incident qualifies for the tracker
An incident is logged when it is (a) publicly disclosed by an affected or investigating party, and (b) supported by at least one primary document. We do not log rumours, unconfirmed on-chain speculation, or a claim that exists only as a social media post. An incident that is later shown not to have occurred is marked Disputed and kept, with the correction appended — we do not delete records.
What “reported loss” means
Every loss figure on Conisec is a reported figure, attributed to whoever reported it, with the date they reported it. It is not our estimate. Where two credible sources disagree, we show the figure with its source and note the disagreement in the timeline. Figures are rendered through a component that cannot display a number without a source name and a date attached — a figure with no provenance does not render at all.
Status definitions
- Active — the incident is ongoing, funds or data remain at risk, or the affected party has not contained it.
- Contained — the immediate vector is closed, but recovery, reimbursement or investigation continues.
- Resolved — the affected party has declared resolution, and no further user action is indicated.
- Disputed — credible parties disagree on whether the event occurred, its scale, or its cause.
Status changes are dated timeline entries, not silent edits.
Timelines and corrections
Incident timelines are append-only. A correction is added as its own dated entry marked CORRECTION; the original line stays visible. This is deliberate: a security record that can be quietly rewritten is not a record.
Attribution
Conisec does not name a perpetrator on its own analysis. We report an attribution only when an official body — a law-enforcement agency, a court, or the affected party — has made it, and we say who made it.
Jurisdiction pages
Each jurisdiction page carries an “as of” date and cites the regulator’s or tax authority’s own publication for every row. They are reviewed at least quarterly, and the review date is shown on the page. Rules change; the primary sources linked on each page are the authority, not our summary.
What The Ledger is not
The Ledger is a summary of published facts plus a verification path. It is never a recommendation, never an instruction to move funds or revoke an approval, and never a legal, tax or security opinion. The “How to verify” line points at official channels only. We do not host or link “recovery” or “revoke” tools we have not verified against the project’s own channel, because seeding exactly those links is a standard attack after a public incident.