OPN Intel · Intel / Beat
OpSec intelligence
16 articles
OpSec5 min read
Microsoft Identifies a USB Worm Swapping Crypto Addresses on Windows
On June 17, Microsoft's Security Response Center published a technical analysis of Trojan:Win32/CryptoBandits.A, a self-propagating malware worm that has targeted cryptocurrency holders on Windows PCs since February 2026. The worm spreads via infected USB drives, monitors the Windows clipboard every 500 milliseconds, silently swaps copied wallet addresses with attacker-controlled ones, and exfiltrates copied seed phrases and private keys over the Tor anonymity network. It also propagates itself to any clean USB drive inserted into an infected machine. The defensive answer is the same one it has always been for address verification: read the recipient address on your hardware wallet's display before approving the transaction.
June 19, 2026
OpSec5 min read
A 3-of-6 Multisig on One Laptop. $36M Gone.
On June 9, 2026, Humanity Protocol disclosed that an attacker compromised a single employee's laptop and used private keys from the device to drain approximately $36 million from the project's bridge contracts on Ethereum and BNB Chain. The multi-sig was configured as 3-of-6 on Ethereum and 3-of-5 on BNB Chain, but enough keys to meet both thresholds had been accidentally backed up to the same device during setup, collapsing what should have been a distributed security model into a single point of failure. The incident illustrates the key co-location anti-pattern cleanly: a multi-sig that stores its threshold-meeting keys on one device is not a multi-sig.
June 10, 2026
OpSecTrust Inversion5 min read
Four Years Undetected: Zcash Patches Orchard Counterfeit Bug
On June 5, Shielded Labs and Zcash Open Development Lab disclosed that a critical vulnerability in Zcash's Orchard shielded pool, present since May 2022, allowed unlimited undetectable ZEC counterfeiting for approximately four years before an emergency patch on June 2. Security engineer Taylor Hornby found the flaw using an AI-assisted audit powered by Anthropic's Opus 4.8: an under-constrained zero-knowledge circuit check that let forged proofs pass validation without triggering any on-chain signature. Because Orchard hides transaction amounts through zero-knowledge proofs, there is no cryptographic method to determine whether exploitation occurred before the fix, an uncertainty that sent ZEC down roughly 45% and prompted Arthur Hayes to exit his entire ZEC position.
June 5, 2026
OpSec5 min read
$4B Leaves LayerZero for Chainlink After Kelp DAO Exploit
In the five weeks since the April 18 Kelp DAO exploit drained $292 million through a single-verifier LayerZero bridge configuration, over $4 billion in wrapped assets have migrated away from LayerZero to Chainlink's Cross-Chain Interoperability Protocol. The latest and largest mover is Lombard Protocol, which announced on May 15 that it is migrating its $1 billion in wrapped Bitcoin (LBTC and BTC.b) to Chainlink CCIP after an internal security review. Kraken announced its own migration on May 14, replacing LayerZero for kBTC and all future wrapped assets. Solv Protocol moved $700 million earlier in May. The practical consequence: wrapped Bitcoin on cross-chain bridges is being reconfigured for security in real time, and the bridge selection now defines the security profile of every wrapped asset it carries. Self-custody native Bitcoin on the Bitcoin network depends on none of this.
May 17, 2026
OpSec3 min read
Judge to Tornado Cash Prosecutor: 'Doing Better Before You Started Talking'
On April 9, Judge Katherine Polk Failla heard oral arguments on Roman Storm's motion for acquittal. No ruling was issued. Failla is taking weeks to decide. But the hearing produced a specific courtroom exchange that drew attention across the DeFi legal community: when the judge asked the prosecutor whether merely maintaining Tornado Cash was a crime, the government's answer may have weakened its own case.
Apr 7, 2026
OpSec5 min read
Samourai Founders Jailed Against FinCEN's Own CoinJoin Guidance
During the Samourai Wallet prosecution, the DOJ asked FinCEN directly whether CoinJoin and non-custodial wallets qualified as money transmission. FinCEN said no. Prosecutors charged ahead anyway, under different statutes, and both founders are now in federal prison. With Roman Storm's Tornado Cash retrial pending and the April 9 acquittal hearing approaching, this is the clearest map available of where Bitcoin privacy tools actually stand under US law right now.
Mar 29, 2026
OpSec5 min read
DOJ Is Trying Roman Storm for Code the Treasury Cleared
On March 9, the US Treasury told Congress that lawful crypto users may use mixers for financial privacy. On March 10, the DOJ asked a federal judge to schedule an October retrial for Roman Storm, the developer who wrote Tornado Cash, a mixer. Storm faces up to 40 years in prison for writing open-source code for a protocol he no longer controls, for transactions he never touched. The contradiction is not accidental. It is the live test of whether financial privacy tools can legally exist in the United States.
Mar 25, 2026
OpSec8 min read
Where Monero's Privacy Holds and Where It Breaks
Monero is the strongest privacy cryptocurrency available. It is not perfectly anonymous. Understanding the difference matters if you are relying on it for anything serious. This is an honest technical assessment of what Monero's privacy protections actually do, where they can break down, and what the IRS, Chainalysis, and academic researchers have been able to accomplish against it.
Mar 17, 2026
OpSec5 min read
Treasury Tells Congress Mixers Are Legal. DOJ Still Prosecutes Samourai.
On March 9, the U.S. Treasury formally told Congress that lawful users may use coin mixers for financial privacy. It's the first time Treasury has put that in writing. The bigger question isn't what the policy says. It's whether the tools still work now that centralized mixers are shutting down and forensic analysis has caught up.
Mar 16, 2026
OpSec6 min read
How to Use Bitcoin Without the Internet
Your Bitcoin depends on the internet. The internet depends on centralized ISPs, undersea cables, and state-controlled infrastructure. Blockstream Satellite, Meshtastic, and mesh networking offer an alternative — and they’re more accessible than you think.
Feb 21, 2026
OpSec5 min read
The $5 Wrench Is Now the #1 Threat to Your Bitcoin
Physical attacks on crypto holders surged 75% in 2025. Technical security is meaningless without a physical security posture.
Feb 18, 2026
OpSec5 min read
BIP-39 Passphrases and the Art of the Duress Wallet
The $5 wrench attack is simple: someone threatens you until you hand over your Bitcoin. A duress wallet gives you something to hand over. BIP-39 passphrases, decoy balances, and the art of plausible deniability.
Feb 17, 2026
OpSec5 min read
Multi-Sig Should Be the Default Self-Custody Setup in 2026
Single-key wallets are a single point of failure. With over 60% of crypto losses from 2021–2024 traced to compromised individual keys, multi-signature setups have moved from advanced technique to baseline security requirement.
Feb 16, 2026
OpSec5 min read
The $6 Trillion Bitcoin Inheritance Problem Almost Nobody Has Solved
Bank of America projects $6 trillion in crypto will need to be inherited by 2045. Between 2.3 and 4 million BTC are already permanently lost. 90% of holders worry about succession — but almost none have a plan.
Feb 10, 2026
OpSec6 min read
A Complete Bitcoin Security Setup for Under $300
Hardware wallet, steel seed backup, personal node, VPN, and Faraday bag — a full self-sovereignty kit for under $300. No sponsors, no affiliate links, just a parts list and the knowledge to use it.
Feb 4, 2026
OpSec5 min read
70% of Crypto Theft Starts With a Compromised Seed Phrase
In 2024, approximately 70% of all stolen cryptocurrency came from private key or seed phrase compromise [1]. Not exchange hacks. Not protocol exploits. Human error with twelve words.
Feb 2, 2026