Skip to content

Write for Conisec

We commission sourced security and regulatory reporting. Real names, real credentials, primary sources.

Last reviewed

Conisec commissions reporting and analysis on crypto security incidents, vulnerability classes, enforcement actions and jurisdictional rules. If you work in security research, incident response, compliance or regulatory practice, we would like to hear from you.

What we publish

  • Exploit post-mortems that explain the vulnerability class, not just the loss figure.
  • Jurisdictional analysis grounded in the regulator’s own publications.
  • Practical security guidance that is honest about what it does not protect against.
  • Enforcement and licensing coverage sourced to filings and notices.

What we require

  • A real name and a real biography. We do not publish pseudonymous bylines, and we verify credentials before they appear on a profile.
  • Primary sources for every factual claim, linked.
  • Disclosure of any holding or relationship relevant to the subject.
  • No price calls, no predictions, no vendor pitches.

What we will not accept

Guest posts written to place a link. Vendor marketing framed as a security warning. Anything containing a “recovery” or “revoke” URL. Anything that instructs readers to move funds or sign a transaction.

Pitching

Send a short pitch — the claim, the primary sources, and why it matters now — via our contact page. Please include a link to previous work and a note on your background.

The sourcing bar

This is the part that most submissions fail, so it is worth being explicit. Every factual claim needs a primary source: the affected project’s own post-mortem, an on-chain transaction, a regulator’s published notice, a court filing, a signed statement. Secondary coverage is a lead, not a citation — if the only support for a figure is another publication reporting it, the figure does not run.

Where credible sources disagree — and on loss figures they routinely do — the piece reports the disagreement with attribution rather than picking the largest number.

What we publish

  • Post-mortems that explain a failure class, not just a timeline of events.
  • Regulatory analysis that reads the instrument itself and says what changed for whom.
  • Verification method — how a reader can check a claim about a platform, a contract or a jurisdiction for themselves.

What we decline

  • Anything paid for, placed, or written to support a link. We do not accept sponsored posts or guest posts with commercial links, at any price.
  • Price prediction and market commentary of any kind.
  • Pieces that instruct readers to move funds, revoke specific approvals, or interact with contract addresses.
  • Vendor content about a product, written by that vendor.

How it works

Send a pitch rather than a finished draft — a paragraph on the claim, and the primary sources you would build it on. We will tell you quickly whether it is a fit. Accepted pieces are edited, fact-checked against your sources, and published under your real name with a genuine biography; we do not publish pseudonymous bylines or invented personas. You keep the right to be identified as the author.