Notes

Breaking down the shifts.

Short reads exploring specific aspects of post-quantum, autonomous AI, and on-chain security. New pieces roughly monthly per shift.

AI

The Many Layers of AI Manipulation

Do you really trust what your LLM or AI agent is telling you? Model weights, context, and outputs can be manipulated in many ways, introducing lies and biases.

WEB3

Web3 Isn’t Actually All That Decentralized

Decentralization is one of the core selling points of Bitcoin and other blockchains. However, the reality is that most layers of the Web3 infrastructure exhibit a surprising and unfortunate level of centralization.

PQC

Symmetric Algorithms Should Be Part of a Quantum Migration Strategy

Quantum migration plans often focus on Shor's threat to public key cryptography. However, symmetric encryption and hash algorithms face quantum threats as well.

AI

The Cascading Effects of Prompt Injection in Agentic Workflows

Often, prompt injection attack coverage and defenses focus on direct prompt injection attacks. In agentic workflows, indirect prompt injection is a major risk with the potential for cascading effects.

WEB3

Why Smart Contract Audits Aren’t Stopping Web3 Hacks

Smart contract audits have become commonplace in Web3, but large-scale attacks are still happening. There are many reasons for this, ranging from limited scoping to the growth of AI-driven analysis.

PQC

Harvest Now, Decrypt Later: Who's Actually Exposed Today

Harvest now, decrypt later attacks are the main driver for organizations to start their quantum migrations today. However, not all data is at risk, and understanding the threat is essential to prioritizing migration efforts.

AI

Memory Poisoning, Explained

Prompt injection is the most famous attack against AI systems, but it's not the only one. Memory poisoning introduces persistent changes to AI agent by targeting saved state.

WEB3

Why Blockchain "Immutability" Doesn't Mean What People Think

Blockchain immutability is a valuable on-chain security control, but it can easily be overstated. Counting on smart contract immutability can leave Web3 projects vulnerable.

PQC · WEB3

Why Quantum Computers Will Eventually Break Bitcoin and Ethereum Signatures

Quantum computing is described as a major threat to data encryption and confidentiality. However, the real threat in Web3 is quantum computing breaking ECDSA digital signatures.

AI

Why AI 'Guardrails' Aren't Enough

AI guardrails are often (over)sold as a defense against prompt injection and other AI threats. While useful, they're often ineffective and aren't enough for security.

WEB3

Flash Loan Attacks, Explained in Under Five Minutes

An introduction to flash loans and how they can be used to attack DeFi protocols.

PQC

Which NIST Post-Quantum Algorithm Actually Applies to You

A fast, practical guide to ML-KEM, ML-DSA, and SLH-DSA, and which one to choose.

PQC
Coming soon

Why Hybrid Cryptography is Best Practice for Quantum Migration

Quantum migration is increasingly critical as quantum computing grows closer to breaking classical cryptography. However, directly swapping in post-quantum algorithms for their classical counterparts isn't the best idea.