Category
Sort by
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
CrossCurve lost about $3M after a bridge integration exposed expressExecute, letting spoofed messages pass with no Axelar approval.

CrossCurve Bridge Hack : An integration blunder that cost multi-million dollars

The CrossCurve bridge exploit abused Axelar expressExecute and a low consensus threshold to drain about $3M across Ethereum and Arbitrum.
Read blog article
March 10, 2026
ERC-4337 expands the security boundary. Learn the key risks in bundlers, paymasters, signatures, replay protection, and liveness.

ERC-4337 Security: Bundlers, Paymasters, Signatures

ERC-4337 expands the security boundary. Learn the key risks in bundlers, paymasters, signatures, replay protection, and liveness.
Read blog article
March 10, 2026
Why banks adopt MDR to validate alerts fast, contain incidents, and reduce business impact from long dwell times and ransomware.

Managed Detection & Response in Banking: Reducing Breach Costs

Managed detection and response helps banks cut dwell time, reduce breach costs, and meet resilience and audit expectations with 24 7 triage.
Read blog article
March 4, 2026
Evidence-first LLM analysis for smart contract vulnerabilities.

LLMs in Smart Contract Audits Need Evidence

LLMs can speed smart contract audits, but only evidence-backed workflows are trustworthy. How Cantina AI Code Analyzer validates findings.
Read blog article
March 4, 2026
What changes in 2026 security, AI driven social engineering

Financial Security in 2026: AI, DORA, Web2, Web3

How AI enabled fraud, DORA obligations, and Web2 Web3 convergence reshape bank security in 2026, plus what to monitor and rehearse.
Read blog article
February 27, 2026
AI coding risks, prompt injection, and AppSec controls.

The End of the AppSec Black Box

AI coding assistants add new risk: prompt injection, NHIs, and subtle auth bugs. Controls and why Cantina AI Code Analyzer matters.
Read blog article
February 25, 2026
Account abstraction shifts security to infrastructure. Hardening ERC 4337 bundlers and paymasters, plus signature validation and replay defenses.

Top 5 Cyber Threats for Banks in 2026

Account abstraction expands risk beyond smart accounts. Secure ERC 4337 bundlers, paymasters, and signatures against replay and policy drift.
Read blog article
February 24, 2026
Zero Trust plus cloud governance for banks, with practical controls for credentials, insider risk, segmentation, monitoring, and incident response.

Zero Trust & Cloud Security for Financial Institutions

How institutions can apply Zero Trust and cloud security controls, including IAM, segmentation, monitoring, and governance, to reduce risk.
Read blog article
February 23, 2026
Lazarus Group uses Zoom deepfakes and audio fix files to steal keys. Verification steps for teams before installs or approvals.

Deepfakes & Billion-Dollar Heists: The Lazarus Group Act

Deepfake Zoom calls and fake plugins are Lazarus’s 2025 to 2026 playbook. Controls to prevent key theft, wallet drains, and downtime.
Read blog article
February 20, 2026
Solana upgrades can change overnight. 2026 security checklist for upgrade keys, state migrations, and monitoring program diffs.

Solana Upgrade Patterns: Security Guide for 2026

Solana programs upgrade by default. Learn 2026 risks, ghost state, uninitialized accounts, key compromise, and safer authority controls.
Read blog article
February 19, 2026
Delta neutral stablecoins stay stable only if hedges execute. Key checks for funding rate stress, keeper ops, liquidation risk, and NAV accuracy.

Auditing Delta Neutral Stablecoins for Peg Safety

Audit delta neutral stablecoins with funding rate stress tests, hedge execution checks, keeper security, and NAV accounting for fair redemptions.
Read blog article
February 17, 2026
Lookalike domains, typosquats, and brand phishing risk.

Lookalike Domains: Stop Brand Impersonation

Lookalike domains power phishing and invoice fraud. Learn how to detect typosquats with DNS monitoring, CT alerts, and fast takedowns.
Read blog article
February 17, 2026
The vibe died, AI shipped the feature, and security broke. ClawdStrike adds checks for secrets, auth, and runtime behavior.

Why Your "Vibe Coded" App is a Ticking Time Bomb

Vibe coding ships fast, but AI can break auth, leak secrets, and ship unsafe defaults. Learn the risks and how ClawdStrike.ai helps.
Read blog article
February 16, 2026
Provenance EndBlocker panic bug found by Cantina AI Code Analyzer.

Cantina AI Code Analyzer Found a Provenance Bug

Cantina AI Code Analyzer found a consensus liveness bug in Provenance v1.27.0. Fix shipped in v1.27.1.
Read blog article
February 16, 2026
How DNS hijacks happen, and what to monitor first.

DNS Hijacks Hit Big Brands: What Your Team Misses

Recent DNS hijacks show how dangling records enable phishing. Build a DNS baseline, monitor changes, and respond before users are hit.
Read blog article
February 13, 2026
FTC reasonable security, why Web3SOC and MDR matter for DeFi.

Meeting the FTC’s "Reasonable Security" Bar

FTC guidance on reasonable security for DeFi, plus how Web3SOC and MDR create evidence, monitoring, and incident response readiness.
Read blog article
February 12, 2026
Pendle x Cantina security: audits and bounties for yield trading and Boros funding rates.

Scaling Security for Billions: The Pendle and Cantina Collaboration

Pendle and Cantina pair audits and $2.5M bounties to secure Pendle V2 and Boros, supporting onchain yield and funding rate markets.
Read blog article
February 12, 2026
What to lock before mainnet: scope, audits, privilege paths, timelocks, caps, alerts, and drills to contain issues fast.

Before You Launch, DeFi Mainnet Security Checklist

A pre launch checklist for DeFi mainnet: audit deploy parity, privilege graphs, timelocks, caps, monitoring, incident response, and bounties.
Read blog article
February 11, 2026
Stablecoin peg mechanics, key risks, and what audits must test.

Auditing New Stablecoin Peg Designs, Risks and Tests

A security guide to modern stablecoin peg designs, LSD, RWA, algorithmic, and delta neutral models, plus oracle, governance, and cross chain risks.
Read blog article
February 10, 2026
ZK proof soundness risks and audit checks, Cantina x ZKsync.

Cantina x ZKsync: The 2026 Guide to Securing ZKPs

Cantina x ZKsync guide to ZKP soundness in 2026, covering transcript omissions, missing constraints, and range check failures.
Read blog article
February 10, 2026
Why Concrete paired institutional yield vaults with continuous security: a $250K Cantina bounty and structured triage.

Cantina x Concrete: Securing Institutional Yield Infrastructure

Concrete’s ERC 4626 vaults near $1B TVL and a $250K Cantina bug bounty secure strategy modules, NAV updates, and withdrawals.
Read blog article
February 5, 2026
Euler SEAL Safe Harbor, Cantina verified whitehat rescues.

Euler Adopts SEAL Safe Harbor, Verified by Cantina

Euler adopts SEAL Safe Harbor for live exploits. Cantina verifies eligible whitehats via KYC, and the program sets return and payout rules.
Read blog article
February 4, 2026
Cantina x Guardrail, runtime detection integrated into MDR.

Cantina x Guardrail: Runtime Detection Meets Managed Detection & Response

Cantina and Guardrail connect protocol aware runtime detection to MDR, pairing sub second monitoring with 24 7 triage, playbooks, and containment.
Read blog article
February 4, 2026
LSD security guide: peg, minting, oracles, slashing, governance, integrations.

Liquid Staking Derivative Security, Risks and Safeguards

Key LSD security risks, peg breaks, mint and redeem bugs, oracle manipulation, slashing, governance, and integration cascades, plus defenses teams should ship.
Read blog article
February 3, 2026
Kinetiq x Cantina on securing kHYPE liquid staking, StakeHub validator routing, and a $5M bug bounty on Hyperliquid.

Kinetiq x Cantina: Securing the Future of Liquid Staking on Hyperliquid

Kinetiq scaled kHYPE liquid staking on Hyperliquid, then opened a $5M Cantina bug bounty to harden validator routing, oracles, and accounting.
Read blog article
February 3, 2026
Why DeFi gets hacked through Web2: SSRF, IDOR, XSS, RCE, and misconfigurations, and what to harden first.

Top 5 Web2 Vulnerabilities Threatening Your DeFi Organization

DeFi exploits often start off chain. Learn five Web2 weaknesses, SSRF, IDOR, RCE, XSS, and misconfigurations, and how to fix them.
Read blog article
February 2, 2026
Symbiotic bug bounty launch on Cantina, $500K top tier.

Symbiotic Arrives on Cantina: A $500k Bounty for Shared Security

Cantina and Symbiotic launch a bug bounty with a $500K top reward to stress test shared security and protect networks that rely on Symbiotic.
Read blog article
February 2, 2026
A $1M OKX DEX onchain bug bounty on Cantina, securing production routing contracts with clear scope, severity tiers, and high signal review.

OKX Labs, OKX Wallet and Cantina Launch the OKX DEX Onchain Bug Bounty Program

OKX Labs and OKX Wallet launch a $1M onchain bug bounty on Cantina, focused on production mainnet smart contracts in the DEX routing stack.
Read blog article
January 30, 2026
PancakeSwap Infinity security on BNB Chain, plus the $1M Cantina bug bounty.

PancakeSwap: Redefining Dominance and Security on BNB Chain

PancakeSwap reached about $2.3B TVL on BNB Chain in 2025, shipped Infinity, and launched a $1M Cantina bug bounty to secure it.
Read blog article
January 29, 2026
How to secure provenance based systems on Cosmos: prevent nondeterminism, validate oracle and IBC inputs, harden validators, and keep records auditable.

Provenance Security Best Practices for Cosmos Ecosystems

Best practices for provenance based blockchains: deterministic execution, oracle and IBC validation, metadata integrity, validator hardening, and auditability.
Read blog article
January 29, 2026
Neobank security guide, cloud to custody to smart contracts.

Neobank Security Best Practices: Safeguarding Digital Banks in Fintech and DeFi

A practical neobank security guide: cloud, APIs, mobile apps, custody, smart contracts, insider risk, monitoring, and incident response.
Read blog article
January 28, 2026
How Web3SOC helps institutions evaluate DeFi and tokenization partners faster with consistent scoring across security operations financial and regulatory readiness

Web3SOC for TradFi: De-Risking Digital Asset Adoption

Web3SOC helps banks asset managers and fintechs compare digital asset partners with evidence across security, operations, financial, and regulatory aspects.
Read blog article
January 28, 2026
Cartoon-style illustration of a smiling Cantina tardigrade mascot with chubby features.
No results found
Please clear your search terms and try again