Sitemap
Every page on Conisec. The machine-readable version is at /sitemap_index.xml.
Incidents (25)
- Atomic Wallet User Fund Theft, June 2023: What Happened & What to Check
- BadgerDAO Front-End Injection, December 2021: What Happened & What to Check
- Beanstalk Governance Flash Loan Attack, April 2022: What Happened & What to Check
- Bybit Cold Wallet Compromise, February 2025: What Happened & What to Check
- Coincheck NEM Theft, January 2018: What Happened & What to Check
- Cream Finance Oracle Manipulation, October 2021: What Happened & What to Check
- Curve Finance Vyper Compiler Reentrancy, July 2023: What Happened & What to Check
- DMM Bitcoin Unauthorised Outflow, May 2024: What Happened & What to Check
- Euler Finance Donation Attack, March 2023: What Happened & What to Check
- Harmony Horizon Bridge Key Compromise, June 2022: What Happened & What to Check
- KuCoin Hot Wallet Compromise, September 2020: What Happened & What to Check
- Ledger Connect Kit Supply Chain Attack, December 2023: What Happened & What to Check
- Mixin Network Database Compromise, September 2023: What Happened & What to Check
- Mt. Gox Collapse, February 2014: What Happened & What to Check
- Multichain Unauthorised Outflows, July 2023: What Happened & What to Check
- Munchables Insider Key Compromise, March 2024: What Happened & What to Check
- Nomad Bridge Replay Exploit, August 2022: What Happened & What to Check
- Orbit Chain Bridge Compromise, December 2023: What Happened & What to Check
- Poly Network Cross-Chain Exploit, August 2021: What Happened & What to Check
- Radiant Capital Signing Compromise, October 2024: What Happened & What to Check
- Ronin Bridge Validator Key Compromise, March 2022: What Happened & What to Check
- The DAO Recursive Call Exploit, June 2016: What Happened & What to Check
- WazirX Multisig Compromise, July 2024: What Happened & What to Check
- Wintermute Vanity Address Compromise, September 2022: What Happened & What to Check
- Wormhole Signature Verification Exploit, February 2022: What Happened & What to Check
Jurisdictions (32)
- Crypto Rules in Argentina
- Crypto Rules in Australia
- Crypto Rules in Brazil
- Crypto Rules in Canada
- Crypto Rules in China
- Crypto Rules in El Salvador
- Crypto Rules in France
- Crypto Rules in Germany
- Crypto Rules in Hong Kong
- Crypto Rules in India
- Crypto Rules in Indonesia
- Crypto Rules in Israel
- Crypto Rules in Japan
- Crypto Rules in Malaysia
- Crypto Rules in Mexico
- Crypto Rules in New Zealand
- Crypto Rules in Nigeria
- Crypto Rules in Saudi Arabia
- Crypto Rules in Singapore
- Crypto Rules in South Africa
- Crypto Rules in South Korea
- Crypto Rules in Switzerland
- Crypto Rules in Taiwan
- Crypto Rules in Thailand
- Crypto Rules in the European Union (MiCA)
- Crypto Rules in the Netherlands
- Crypto Rules in the Philippines
- Crypto Rules in the United Arab Emirates
- Crypto Rules in the United Kingdom
- Crypto Rules in the United States
- Crypto Rules in Turkey
- Crypto Rules in Ukraine
Guides (24)
- Analysis: Key Compromise Has Overtaken Contract Exploits as Crypto’s Main Loss Driver
- Analysis: What the Coldcard Flaw Means for What a Hardware Wallet Actually Guarantees
- BonkDAO Governance Bypass Reported at $21.2m
- Bridge Validation Failures at Wanchain and Verus Reported at $20.5m
- CLARITY Act Would Split SEC and CFTC Jurisdiction. It Has Not Passed.
- Coldcard RNG Flaw: Coinkite Discloses Five-Year Entropy Failure After Mass Bitcoin Theft
- DAC8 Brings Crypto Into the EU’s Automatic Tax Information Exchange
- How Crypto Bridges Work, and Why They Keep Getting Exploited
- How to Check What Your Wallet Has Approved
- How to Check Whether a Platform Is Regulated Where It Claims
- How to Check Who Controls a Smart Contract
- How to Read a Smart Contract Audit Report
- How to Read a Transaction Before You Sign It
- How to Verify a Security Incident Is Real
- July 2026 Crypto Losses Reach $210m Across 30 Incidents, Nearly Triple June
- MiCA Transitional Period Ends: Unauthorised Firms Must Now Wind Down
- Oracle Manipulation Hits AFX, Ostium and Bonzo in Clustered July Attacks
- SEC and CFTC Issue Joint Interpretation on How Securities Law Applies to Crypto-Assets
- Treasury Targets Final GENIUS Act Stablecoin Rules as Enforcement Phase Begins
- What “Regulated Exchange” Actually Means
- What Cold Storage Does and Does Not Protect
- What Happens to Your Crypto When an Exchange Fails
- What Self-Custody Actually Means (And What It Doesn’t Protect You From)
- Why Most Crypto Losses Come From a Few Failure Classes
Glossary (50)
- Address poisoning
- Air-gapped signing
- Allowlist
- AML (anti-money laundering)
- Blind signing
- Bridge
- Bug bounty
- Business logic flaw
- CASP (Crypto-Asset Service Provider)
- Circuit breaker
- Cold storage
- Custodial vs non-custodial
- Dusting attack
- FATF
- Flash loan
- Front-end compromise
- Governance attack
- Hardware wallet
- Hot wallet
- Insider threat
- KYT (Know Your Transaction)
- MEV (maximal extractable value)
- MiCA
- MPC (multi-party computation)
- Multisig
- Nonce
- Oracle manipulation
- Permit signature
- Private key
- Proof of reserves
- Proxy contract
- Qualified custodian
- Recovery phrase
- Reentrancy
- Replay attack
- Rug pull
- Sanctions screening
- Segregation of client assets
- Signature verification
- SIM swap
- Smart contract audit
- Supply chain attack
- Timelock
- Token approval
- Toolchain compromise
- Travel Rule
- Validator set
- Vanity address
- VASP (Virtual Asset Service Provider)
- Wallet drainer
Pages (22)
- About Conisec
- Affiliate Disclosure
- Contact Conisec
- Cookie Policy
- Corrections
- Disclaimer
- Do Not Sell My Personal Information
- Editorial Guidelines
- Ethics Policy
- Incident Lookup
- Methodology
- Privacy Policy
- Scam Report Directory
- Security Policy
- Self-Custody Security Checklist
- Sitemap
- Tax Deadline Tracker
- Team
- Terms of Service
- The Weekly Security Digest
- Tools
- Write for Conisec
Categories
- Beginner Guides (6)
- Guides & Education (12)
- News (12)
- Regulation (5)
- Security (7)
- Security Tips (6)