官方的 MASTR 标志 MASTR
菜单
阅读文章

研究方法

Six security reports: the work behind responsible disclosure

No names but: -A wallet-connected launch platform, -a Solana gaming/trading app, -2 perpetuals DEX, -a crypto exchange -....and an on-chain order-book protocol.

Original publication · 27 Aug 2026. Figures, claims and opinions reflect the original publication date.

原文为英语,导航提供七种语言。

01

查看 X 原帖 ↗

I submitted 6 professional security reports across 5 crypto products.

Approximately 240 pages and 2 weeks of non-stop work.

No names but:
-A wallet-connected launch platform,
-a Solana gaming/trading app,
-2 perpetuals DEX,
-a crypto exchange
-....and an on-chain order-book protocol.

43 proven and fully documented findings.

2 Critical
14 High
15 Medium
13 Low / Informational
Plus 5 additional assurance observations.

An average of seven days has passed since submission.

Only one team has replied, with a one-line acknowledgement saying the report was accepted, but I wasn’t eligible. No explanation.

I decided to put my skills back to work where they could have a direct impact: protecting users inside the apps and platforms they actually use, while expecting fair compensation for the work and to feed my family beside irl job.

Posting warnings and helping individuals may protect people, but the industry rarely rewards the research, evidence and technical effort behind it.

So far, however, it has been a complete disaster, and I genuinely regret the amount of time I have invested.

Ok, lmao, well.

To be fair: I know proper security triage takes time. I’m still giving several teams the benefit of the doubt, and I genuinely hope they are reviewing the material and will respond.

This is not aimed at teams that are quietly doing the work and intend to communicate professionally!

But these are live production products handling wallets, accounts, identities, trades and real money.

When a weakness could allow me or someone with far worse intentions, to harm users without extraordinary resources, I expect more than silence.

The findings are not theoretical entertainment.

Depending on the documented preconditions, the reported attack paths could expose users to account compromise, leaked password-reset or delegated-access secrets, unauthorized wallet or signing actions, impersonation and phishing, manipulated trading behaviour, financial loss, sensitive-data exposure or abuse of production infrastructure.

The potential victims are real: wallet owners, traders, account holders, liquidity providers, project teams and every user who trusted these products to take security seriously.

I disclosed everything privately, responsibly and with detailed evidence. No exploitation and no fund movement.

No public naming.

Too much of this industry is shaped by liars and opportunists selling “security,” “community” and “decentralization” while rewarding hype, connections, silence and plausible deniability.

Then another hack, breach or drain happens and everyone performs the same theatre of shock.

I’ve done the same kind of responsible security research on Web2 applications, products without connected wallets or direct access to users’ funds.

Their responses were fair, timely and professional.

Now compare that with an industry handling wallets, signatures, trades and real money.

Crazy.

Sad.

The problem should be obvious.

Crypto has an integrity problem.

Attachment to the original X post
Attachment to the original X post 查看完整尺寸图片 ↗
Attachment to the original X post
Attachment to the original X post 查看完整尺寸图片 ↗
Attachment to the original X post
Attachment to the original X post 查看完整尺寸图片 ↗
Attachment to the original X post
Attachment to the original X post 查看完整尺寸图片 ↗

02

查看 X 原帖 ↗

I’m simply disappointed, and I’m losing more and more faith in this industry and the people behind it.

03

查看 X 原帖 ↗

On the other hand, I closely examined 10 other projects using the same methods and expertise and found nothing.

来源与原帖

MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包