opsek (@opsek_io) 's Twitter Profile
opsek

@opsek_io

Operational security audits and training for web3 companies and hnwi. We train your team and harden your stack, so you don't get hacked.

ID: 1839062647872040963

linkhttps://opsek.io/ calendar_today25-09-2024 22:03:16

6 Tweet

190 Takipรงi

29 Takip Edilen

opsek (@opsek_io) 's Twitter Profile Photo

Check out our founders presentation at DeFi Security Summit in Bangkok, about Operational Security in the Web3 ecosystem

pablito.eth ๐Ÿฆ‡๐Ÿ”Š โ™ข (@pablosabbatella) 's Twitter Profile Photo

๐Ÿ” Not all 2FA are made equal: - SMS 2FA is vulnerable to many attacks such as: SS7 attacks, sim swaps, IMSI attacks, carrier compromise, compromised device, etc. - TOTP apps such as Google Authenticator, Authy and Microsoft authenticator are vulnerable to phishing attacks (as

๐Ÿ” Not all 2FA are made equal: 
- SMS 2FA is vulnerable to many attacks such as: SS7 attacks, sim swaps, IMSI attacks, carrier compromise, compromised device, etc.
- TOTP apps such as Google Authenticator, Authy and Microsoft authenticator are vulnerable to phishing attacks (as
Security Alliance (@_seal_org) 's Twitter Profile Photo

What would you do if you could spy on SMS messages? theredguild and opsek have identified SLOVENLY COMET, a threat actor which has been intercepting OTP codes and other credentials sent over SMS to certain regions since as early as February 7, 2025 More info below ๐Ÿ”—

What would you do if you could spy on SMS messages? <a href="/theredguild/">theredguild</a> and <a href="/opsek_io/">opsek</a> have identified SLOVENLY COMET, a threat actor which has been intercepting OTP codes and other credentials sent over SMS to certain regions since as early as February 7, 2025

More info below ๐Ÿ”—
pablito.eth ๐Ÿฆ‡๐Ÿ”Š โ™ข (@pablosabbatella) 's Twitter Profile Photo

๐Ÿ” It's called two-factor for a reason: - You save passwords in Google chrome, which is synchronized with your Gmail. - And you save 2FA codes in Google authenticator, with cloud backup in your Gmail. - And you use passkeys in your Android and synchronize them with your Gmail. +

๐Ÿ” It's called two-factor for a reason:
- You save passwords in Google chrome, which is synchronized with your Gmail.
- And you save 2FA codes in Google authenticator, with cloud backup in your Gmail.
- And you use passkeys in your Android and synchronize them with your Gmail.
+
Defi Security Summit (@summit_defi) 's Twitter Profile Photo

Next DSS Webinar, on April 23 ๐Ÿ“† We will deep dive into OpSec failures with: โ€ขPeter Kacherginsky (Blockchain Threat Intelligence) โ€ขpablito.eth ๐Ÿฆ‡๐Ÿ”Š โ™ข & souilos (opsek) Moderated by Isaac Patka (Shield3) Covering Bybit, NickLFranklin, and other OpSec stories Register: us06web.zoom.us/webinar/registโ€ฆ

Next DSS Webinar, on April 23 ๐Ÿ“†

We will deep dive into OpSec failures with:
โ€ข<a href="/_iphelix/">Peter Kacherginsky</a> (<a href="/blockthreat/">Blockchain Threat Intelligence</a>)
โ€ข<a href="/PabloSabbatella/">pablito.eth ๐Ÿฆ‡๐Ÿ”Š โ™ข</a> &amp; <a href="/theSouilos/">souilos</a> (<a href="/opsek_io/">opsek</a>)
Moderated by <a href="/isaacpatka/">Isaac Patka</a> (<a href="/0xshield3/">Shield3</a>)

Covering Bybit, NickLFranklin, and other OpSec stories

Register:  us06web.zoom.us/webinar/registโ€ฆ
opsek (@opsek_io) 's Twitter Profile Photo

Kraken discovered a DPRK operative (North Korea agent) trying to infiltrate the company. Is your project safe from sophisticated threat actors? What are you waiting for?

dcbuilder.eth โšช๏ธ (@dcbuild3r) 's Twitter Profile Photo

I can't recommend opsek and Blockchain Security Series enough for those looking for personal/company security audits and educational materials. I'm sure there's several out there that you could use to improve your security all around

Devconnect ARG (@efdevcon) 's Twitter Profile Photo

Exploring security projects for the Ethereum Worldโ€™s Fair ๐Ÿ” Starting with some that are shaping the space in Argentina ๐Ÿ” OpenZeppelin @CoinFabrik @TheRedGuild opsek Who else should we include for the Devconnect showcase?

opsek (@opsek_io) 's Twitter Profile Photo

Auditing your smart contracts is important, but in fact, 99% of stolen funds are NOT due to smart contract hacking, but operational security issues. Is your company prepared to stop sophisticated threat actors?

Blockchain Threat Intelligence (@blockthreat) 's Twitter Profile Photo

BlockThreat - Week 20, 2025 ๐Ÿ’™ Sponsored by opsek and Recon ๐Ÿšฟ Malicious insiders leak data at Coinbase ๐Ÿ›ก๏ธ ๐ŸŽฃ Curve hit with DNS Hijacking attack ๐Ÿง‘โ€โš–๏ธ Xinbi darkmarket OTC shut down ๐Ÿ˜ก Another crypto kidnapping attempt in France newsletter.blockthreat.io/p/blockthreat-โ€ฆ

pablito.eth ๐Ÿฆ‡๐Ÿ”Š โ™ข (@pablosabbatella) 's Twitter Profile Photo

I'll be attending EthCC in Cannes ๐Ÿ‡ซ๐Ÿ‡ท. If you are a founder and care about your company's Security, DM me and let's talk. Operational security is not an option any more. OpSec or be hunted. ๐Ÿฅท

I'll be attending EthCC in Cannes ๐Ÿ‡ซ๐Ÿ‡ท. If you are a founder and care about your company's Security, DM me and let's talk. Operational security is not an option any more. OpSec or be hunted. ๐Ÿฅท
opsek (@opsek_io) 's Twitter Profile Photo

We audited and trained the Contango team regarding their Operational Security. They wrote a nice article about this experience. Check it out! ๐Ÿ‘‡

Contango ๐Ÿ’ƒ๐Ÿพ (@contango_xyz) 's Twitter Profile Photo

Fact: Operational Security is the most boring shit ever. Until it hits the fan. Thats why, starting Dec 2024, we have undergone a lengthy audit by opsek. ๐Ÿงต๐Ÿ‘‡