It’s time for blockchain security firms to join forces

Working alongside security experts from rival firms, not only with colleagues, will minimize risk for all of crypto

OPINION
article-image

FLY:D/Unsplash modified by Blockworks

share

The lack of open communication between blockchain security firms requires urgent action. 

Following a spate of high-profile hacks, the time to address the prevalence of multi-million-dollar hacks is severely overdue. Not even respected figureheads like Vitalik Buterin and Mark Cuban are immune, with over $1 million lost following a hacked Twitter account and wallet, respectively. 

Without a doubt, technical capabilities matter in securing funds against bad actors. However, there is a critical component that is being overlooked in the present: teamwork. If we are to successfully neutralize the risks of financial and reputational loss to the industry, communication and collaboration between blockchain security firms is necessary. 

As one prominent example, the lack of effective communication exacerbated the Curve hack this summer and should serve as an important wake-up call for the industry. 

Read more: Mixin halts withdrawals as network suffers $200M loss in hack

Security experts faced challenges in rapidly coordinating their actions, resulting in missed opportunities for effective execution. Multiple security teams operated independently to recover and protect user funds, causing redundant efforts and a delayed response time. Due to the ambiguous nature of white hat hacking, certain security teams sought explicit permission from Curve before initiating any recovery efforts. Consequently, the attacker managed to steal funds before the coordinated white hat team could secure them. 

Openly discussing exploits, vulnerabilities and root causes is already the norm in traditional cybersecurity, as firms follow established protocols for the responsible disclosure of vulnerabilities. 

Blockchain security firms can and should adopt similar practices, ensuring that they are able to communicate vulnerabilities responsibly to relevant projects and communities to minimize risk in the most efficient way possible. 

Solid examples of streamlined communication seen in more traditional cybersecurity include Europol, a criminal information and intelligence database that collates information on cybercrime, making this information available to the wider public. Another example is the Common Vulnerabilities and Exposures (CVE), a publicly available database listing known cybersecurity vulnerabilities. 

Working alongside security experts from rival firms, not only with colleagues, is a valuable approach driven by an ethos of collaboration for the greater good. One such example already in action in crypto is the Seal 911 initiative, a collective of blockchain security experts working together to offer support from within a Telegram group. So far, Seal 911’s coordinated response has helped prevent a $200,000 theft.

Resources that pool information empower the community to more effectively monitor vulnerabilities and respond accordingly. However, there is no one such standardized process in Web3.

Read more: Mark Cuban loses nearly $900k on MetaMask fake

As the industry is still relatively nascent, this is not surprising. However, blockchain security firms should join together to create standardized protocols for common vulnerabilities for all Web3 projects — using the traditional cybersecurity resources as templates.

Crypto cybersecurity practices now are simply lacking

Relying on white hat hackers in crypto has proven extremely valuable up until now, saving individual projects millions in financial losses with each hack averted. However, relying on white hat hackers alone is not an efficient catch-all strategy. 

The execution of a white hat strategy necessitates a costly on-chain procedure to transfer funds to a trusted third party, followed by the need for that trusted third party to return the funds to the protocol or individual users. 

While advertising a white hat bounty can entice the most skilled white hat hackers to solve security issues quickly, it can also inadvertently provide attackers with hints that important or sensitive work is underway. This can propagate misinformation, potentially causing confusion about whether the event is an external attack or an asset protection operation (done by internal teams). Solving security issues publicly is not always the most effective solution. 

Web3’s penchant for anonymity, often due to legal and regulatory pressure, can also create uncertainty, as it can be unclear how to contact a trustworthy person within a protocol. Vulnerabilities should ideally be communicated to relevant parties first, in order to allow projects a fair opportunity to correct them before disclosing vulnerabilities to a wider audience. Yet the reality is that bad actors are often tipped off inadvertently at the same time, making the situation worse.

Collaboration must be embraced by blockchain security firms and experts. Only by working together cohesively can blockchain security firms establish best practices and standards for securing blockchain networks and decentralized applications.



Get the news in your inbox. Explore Blockworks newsletters:

  • Blockworks Daily: The newsletter that helps thousands of investors understand crypto and the markets, by Byron Gilliam.
  • Empire: Start your morning with the top news and analysis to inform your day in crypto.
  • Forward Guidance: Reporting and analysis on the growing intersection of crypto and macroeconomics, policy and finance.
  • 0xResearch: Alpha directly in your inbox. Market highlights, data, degen trade ideas, governance updates, token performance and more.
  • Lightspeed: Built for Solana investors, developers and community members. The latest from one of crypto’s hottest networks.
  • The Drop: For crypto collectors and traders, covering apps, games, memes and more.
  • Supply Shock: Tracking Bitcoin’s rise from internet plaything worth less than a penny to global phenomenon disrupting money as we know it.
Tags

Upcoming Events

Industry City | Brooklyn, NY

TUES - THURS, JUNE 24 - 26, 2025

Permissionless IV serves as the definitive gathering for crypto’s technical founders, developers, and builders to come together and create the future.If you’re ready to shape the future of crypto, Permissionless IV is where it happens.

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

morpho 2 graphic.png

Research

Utilizing a ‘DeFi Mullet’ approach, Coinbase’s Bitcoin-backed loans integration with Morpho demonstrates a powerful blueprint for CEXs to monetize dormant assets by expanding adoption of wrapped products (cbBTC, USDC) while also supporting native and/or preferred DeFi ecosystems (Base) which can further lead to downstream growth in onchain liquidity and increased utilization of the related assets.

article-image

The network is at a “pivotal juncture,” Blockworks Research’s Marc-Thomas Arjoon said

article-image

Altcoin trade volume has returned to pre-FTX levels, but with a shrinking pool of market leaders

article-image

Solana Foundation’s former head of strategy proposes increasing the disinflation rate

article-image

With much of the bitcoin mining supply chain based in Asia, US-based operations now face higher equipment prices

article-image

Anticipating an economic downturn, venture firms may be less likely to invest

article-image

Trump’s tariffs may have potentially significant impacts on GDP, household spending and food prices — if they hold