官方的 MASTR 标志 MASTR
菜单
阅读文章

MASTR · 2024–2026

钓鱼攻击、漏洞与隐私

From the first contact to the permission, key or device an attacker wants.

Many attacks begin outside the blockchain. A convincing interview invitation, a password-reset email or a compromised public account can move a person from a familiar service to an attacker-controlled workflow. The BlockLayerPod and BeaconLayerPod article follows that progression through the accounts, invitations and installation requests reported to MASTR. Read it alongside the account-compromise and reply-bot records to see how reputation is reused as bait.

Other failures occur in software people already trust. Browser extensions, dependencies, release pipelines and embedded signing systems can change the risk without changing the logo on screen. The Trust Wallet, Coldcard and agentic-finance publications examine different parts of that problem. A wallet connection, token approval, leaked session and exposed seed are different events; their consequences and the response they require should not be conflated.

The privacy series adds the information layer. Public transfers, exchange records, infrastructure logs and reused identities can connect activities that a user believed were separate. Its three original posts are presented together. Historical warnings describe the situation then; check the relevant product’s current guidance before acting on an old software version or incident report.

53 · 精选文章 · 1/3

Password-reset emails: what they do and do not reveal — original source image
钓鱼攻击、漏洞与隐私

Password-reset emails: what they do and do not reveal

What’s happening is simple: someone, (in this case most likely bots), triggers a password reset request through X’s public reset form. For that, the public username is enough. X then sends the reset email itself to the address linked to the…

研究与分析3 min
钓鱼攻击、漏洞与隐私

Exchange accountability · 28 Aug 2026

If onchain evidence clearly documents a scam, theft or other crime, CEXs should be legally required to hand over the relevant KYC and transaction data to law enforcement when a valid legal request exists.

评论与直言2 min
钓鱼攻击、漏洞与隐私

Paid promotion · 23 Aug 2026

I’ll focus more heavily on bug bounties again. Unless this space decides that this public work, which depends entirely on support, matters enough to keep alive.

评论与直言1 min
钓鱼攻击、漏洞与隐私

Security and verification · 19 Aug 2026

I’m being paid to perform full security assessments on 2 of them, while I gave another 5 only a rough 30-minute pass. Even at that depth, some of the vulnerabilities and basic security failures I found are frankly alarming.

评论与直言1 min
North Korea-linked theft and the first-half 2026 record — original source image
钓鱼攻击、漏洞与隐私

North Korea-linked theft and the first-half 2026 record

They are organised, patient, funded, technically serious and fully aware that crypto still runs on weak humans, lazy security, rushed integrations and teams that spend more on marketing than on infrastructure hardening.

研究与分析2 min
钓鱼攻击、漏洞与隐私

Frontier AI oversight: a proposed institutional model

These systems are moving into the layers where modern society actually runs: code, cloud, identity, payment rails, financial markets, logistics, media, operating systems, cyber operations, hardware design and the information feeds through…

评论与直言3 min
How AI changes the scale and speed of attacks — original source image
钓鱼攻击、漏洞与隐私

How AI changes the scale and speed of attacks

AI will multiply the scale, speed and precision of attacks, but the ugly truth is that many of these incidents are not some mysterious act of cyber warfare.

研究与分析3 min
钓鱼攻击、漏洞与隐私

Private data and AI: where MASTR draws the boundary

Private/ personal thoughts I would not want stored, processed, analysed, profiled, misunderstood, leaked, subpoenaed, monetised or used to build a better psychological map of me.

评论与直言1 min
Grok and DRB: the trust problem in agentic finance — original source image
钓鱼攻击、漏洞与隐私

Grok and DRB: the trust problem in agentic finance

A "short" scientific breakdown of AI finance, agentic wallets and the problems nobody wants to think about yet, for those who occasionally still enjoy reading something longer: 👇

研究与分析8 min
Paradex: a zero-price display, liquidations and rollback — original source image
钓鱼攻击、漏洞与隐私

Paradex: a zero-price display, liquidations and rollback

A severe technical malfunction on the derivatives exchange Paradex caused the Bitcoin price to briefly display at 0 US dollars, triggering mass liquidations across the platform.

研究与分析2 min
MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包