opsek (@opsek_io) 's Twitter Profile
opsek

@opsek_io

Operational security audits and training for web3 companies and hnwi. We train your team and harden your stack, so you don't get hacked.

ID: 1839062647872040963

linkhttps://opsek.io/ calendar_today25-09-2024 22:03:16

6 Tweet

190 Followers

29 Following

opsek (@opsek_io) 's Twitter Profile Photo

Check out our founders presentation at DeFi Security Summit in Bangkok, about Operational Security in the Web3 ecosystem

pablito.eth πŸ¦‡πŸ”Š β™’ (@pablosabbatella) 's Twitter Profile Photo

πŸ” Not all 2FA are made equal: - SMS 2FA is vulnerable to many attacks such as: SS7 attacks, sim swaps, IMSI attacks, carrier compromise, compromised device, etc. - TOTP apps such as Google Authenticator, Authy and Microsoft authenticator are vulnerable to phishing attacks (as

πŸ” Not all 2FA are made equal: 
- SMS 2FA is vulnerable to many attacks such as: SS7 attacks, sim swaps, IMSI attacks, carrier compromise, compromised device, etc.
- TOTP apps such as Google Authenticator, Authy and Microsoft authenticator are vulnerable to phishing attacks (as
Security Alliance (@_seal_org) 's Twitter Profile Photo

What would you do if you could spy on SMS messages? theredguild and opsek have identified SLOVENLY COMET, a threat actor which has been intercepting OTP codes and other credentials sent over SMS to certain regions since as early as February 7, 2025 More info below πŸ”—

What would you do if you could spy on SMS messages? <a href="/theredguild/">theredguild</a> and <a href="/opsek_io/">opsek</a> have identified SLOVENLY COMET, a threat actor which has been intercepting OTP codes and other credentials sent over SMS to certain regions since as early as February 7, 2025

More info below πŸ”—
pablito.eth πŸ¦‡πŸ”Š β™’ (@pablosabbatella) 's Twitter Profile Photo

πŸ” It's called two-factor for a reason: - You save passwords in Google chrome, which is synchronized with your Gmail. - And you save 2FA codes in Google authenticator, with cloud backup in your Gmail. - And you use passkeys in your Android and synchronize them with your Gmail. +

πŸ” It's called two-factor for a reason:
- You save passwords in Google chrome, which is synchronized with your Gmail.
- And you save 2FA codes in Google authenticator, with cloud backup in your Gmail.
- And you use passkeys in your Android and synchronize them with your Gmail.
+
Defi Security Summit (@summit_defi) 's Twitter Profile Photo

Next DSS Webinar, on April 23 πŸ“† We will deep dive into OpSec failures with: β€’Peter Kacherginsky (Blockchain Threat Intelligence) β€’pablito.eth πŸ¦‡πŸ”Š β™’ & souilos (opsek) Moderated by Isaac Patka (Shield3) Covering Bybit, NickLFranklin, and other OpSec stories Register: us06web.zoom.us/webinar/regist…

Next DSS Webinar, on April 23 πŸ“†

We will deep dive into OpSec failures with:
β€’<a href="/_iphelix/">Peter Kacherginsky</a> (<a href="/blockthreat/">Blockchain Threat Intelligence</a>)
β€’<a href="/PabloSabbatella/">pablito.eth πŸ¦‡πŸ”Š β™’</a> &amp; <a href="/theSouilos/">souilos</a> (<a href="/opsek_io/">opsek</a>)
Moderated by <a href="/isaacpatka/">Isaac Patka</a> (<a href="/0xshield3/">Shield3</a>)

Covering Bybit, NickLFranklin, and other OpSec stories

Register:  us06web.zoom.us/webinar/regist…
opsek (@opsek_io) 's Twitter Profile Photo

Kraken discovered a DPRK operative (North Korea agent) trying to infiltrate the company. Is your project safe from sophisticated threat actors? What are you waiting for?

dcbuilder.eth βšͺ️ (@dcbuild3r) 's Twitter Profile Photo

I can't recommend opsek and Blockchain Security Series enough for those looking for personal/company security audits and educational materials. I'm sure there's several out there that you could use to improve your security all around

Devconnect ARG (@efdevcon) 's Twitter Profile Photo

Exploring security projects for the Ethereum World’s Fair πŸ” Starting with some that are shaping the space in Argentina πŸ” OpenZeppelin @CoinFabrik @TheRedGuild opsek Who else should we include for the Devconnect showcase?

opsek (@opsek_io) 's Twitter Profile Photo

Auditing your smart contracts is important, but in fact, 99% of stolen funds are NOT due to smart contract hacking, but operational security issues. Is your company prepared to stop sophisticated threat actors?

Blockchain Threat Intelligence (@blockthreat) 's Twitter Profile Photo

BlockThreat - Week 20, 2025 πŸ’™ Sponsored by opsek and Recon 🚿 Malicious insiders leak data at Coinbase πŸ›‘οΈ 🎣 Curve hit with DNS Hijacking attack πŸ§‘β€βš–οΈ Xinbi darkmarket OTC shut down 😑 Another crypto kidnapping attempt in France newsletter.blockthreat.io/p/blockthreat-…

pablito.eth πŸ¦‡πŸ”Š β™’ (@pablosabbatella) 's Twitter Profile Photo

I'll be attending EthCC in Cannes πŸ‡«πŸ‡·. If you are a founder and care about your company's Security, DM me and let's talk. Operational security is not an option any more. OpSec or be hunted. πŸ₯·

I'll be attending EthCC in Cannes πŸ‡«πŸ‡·. If you are a founder and care about your company's Security, DM me and let's talk. Operational security is not an option any more. OpSec or be hunted. πŸ₯·
opsek (@opsek_io) 's Twitter Profile Photo

We audited and trained the Contango team regarding their Operational Security. They wrote a nice article about this experience. Check it out! πŸ‘‡

Contango πŸ’ƒπŸΎ (@contango_xyz) 's Twitter Profile Photo

Fact: Operational Security is the most boring shit ever. Until it hits the fan. Thats why, starting Dec 2024, we have undergone a lengthy audit by opsek. πŸ§΅πŸ‘‡