opsek (@opsek_io) 's Twitter Profile
opsek

@opsek_io

Operational security audits and training for web3 companies and hnwi. We train your team and harden your stack, so you don't get hacked.

ID: 1839062647872040963

linkhttps://opsek.io/ calendar_today25-09-2024 22:03:16

6 Tweet

190 Takipçi

29 Takip Edilen

opsek (@opsek_io) 's Twitter Profile Photo

Check out our founders presentation at DeFi Security Summit in Bangkok, about Operational Security in the Web3 ecosystem

pablito.eth 🦇🔊 ♢ (@pablosabbatella) 's Twitter Profile Photo

🔐 Not all 2FA are made equal: - SMS 2FA is vulnerable to many attacks such as: SS7 attacks, sim swaps, IMSI attacks, carrier compromise, compromised device, etc. - TOTP apps such as Google Authenticator, Authy and Microsoft authenticator are vulnerable to phishing attacks (as

🔐 Not all 2FA are made equal: 
- SMS 2FA is vulnerable to many attacks such as: SS7 attacks, sim swaps, IMSI attacks, carrier compromise, compromised device, etc.
- TOTP apps such as Google Authenticator, Authy and Microsoft authenticator are vulnerable to phishing attacks (as
Security Alliance (@_seal_org) 's Twitter Profile Photo

What would you do if you could spy on SMS messages? theredguild and opsek have identified SLOVENLY COMET, a threat actor which has been intercepting OTP codes and other credentials sent over SMS to certain regions since as early as February 7, 2025 More info below 🔗

What would you do if you could spy on SMS messages? <a href="/theredguild/">theredguild</a> and <a href="/opsek_io/">opsek</a> have identified SLOVENLY COMET, a threat actor which has been intercepting OTP codes and other credentials sent over SMS to certain regions since as early as February 7, 2025

More info below 🔗
pablito.eth 🦇🔊 ♢ (@pablosabbatella) 's Twitter Profile Photo

🔐 It's called two-factor for a reason: - You save passwords in Google chrome, which is synchronized with your Gmail. - And you save 2FA codes in Google authenticator, with cloud backup in your Gmail. - And you use passkeys in your Android and synchronize them with your Gmail. +

🔐 It's called two-factor for a reason:
- You save passwords in Google chrome, which is synchronized with your Gmail.
- And you save 2FA codes in Google authenticator, with cloud backup in your Gmail.
- And you use passkeys in your Android and synchronize them with your Gmail.
+
Defi Security Summit (@summit_defi) 's Twitter Profile Photo

Next DSS Webinar, on April 23 📆 We will deep dive into OpSec failures with: •Peter Kacherginsky (Blockchain Threat Intelligence) •pablito.eth 🦇🔊 ♢ & souilos (opsek) Moderated by Isaac Patka (Shield3) Covering Bybit, NickLFranklin, and other OpSec stories Register: us06web.zoom.us/webinar/regist…

Next DSS Webinar, on April 23 📆

We will deep dive into OpSec failures with:
•<a href="/_iphelix/">Peter Kacherginsky</a> (<a href="/blockthreat/">Blockchain Threat Intelligence</a>)
•<a href="/PabloSabbatella/">pablito.eth 🦇🔊 ♢</a> &amp; <a href="/theSouilos/">souilos</a> (<a href="/opsek_io/">opsek</a>)
Moderated by <a href="/isaacpatka/">Isaac Patka</a> (<a href="/0xshield3/">Shield3</a>)

Covering Bybit, NickLFranklin, and other OpSec stories

Register:  us06web.zoom.us/webinar/regist…
opsek (@opsek_io) 's Twitter Profile Photo

Kraken discovered a DPRK operative (North Korea agent) trying to infiltrate the company. Is your project safe from sophisticated threat actors? What are you waiting for?

dcbuilder.eth ⚪️ (@dcbuild3r) 's Twitter Profile Photo

I can't recommend opsek and Blockchain Security Series enough for those looking for personal/company security audits and educational materials. I'm sure there's several out there that you could use to improve your security all around

Devconnect ARG (@efdevcon) 's Twitter Profile Photo

Exploring security projects for the Ethereum World’s Fair 🔍 Starting with some that are shaping the space in Argentina 🔐 OpenZeppelin @CoinFabrik @TheRedGuild opsek Who else should we include for the Devconnect showcase?

opsek (@opsek_io) 's Twitter Profile Photo

Auditing your smart contracts is important, but in fact, 99% of stolen funds are NOT due to smart contract hacking, but operational security issues. Is your company prepared to stop sophisticated threat actors?

Blockchain Threat Intelligence (@blockthreat) 's Twitter Profile Photo

BlockThreat - Week 20, 2025 💙 Sponsored by opsek and Recon 🚿 Malicious insiders leak data at Coinbase 🛡️ 🎣 Curve hit with DNS Hijacking attack 🧑‍⚖️ Xinbi darkmarket OTC shut down 😡 Another crypto kidnapping attempt in France newsletter.blockthreat.io/p/blockthreat-…

pablito.eth 🦇🔊 ♢ (@pablosabbatella) 's Twitter Profile Photo

I'll be attending EthCC in Cannes 🇫🇷. If you are a founder and care about your company's Security, DM me and let's talk. Operational security is not an option any more. OpSec or be hunted. 🥷

I'll be attending EthCC in Cannes 🇫🇷. If you are a founder and care about your company's Security, DM me and let's talk. Operational security is not an option any more. OpSec or be hunted. 🥷
opsek (@opsek_io) 's Twitter Profile Photo

We audited and trained the Contango team regarding their Operational Security. They wrote a nice article about this experience. Check it out! 👇

Contango 💃🏾 (@contango_xyz) 's Twitter Profile Photo

Fact: Operational Security is the most boring shit ever. Until it hits the fan. Thats why, starting Dec 2024, we have undergone a lengthy audit by opsek. 🧵👇