Sitemap

Hacking Time Recap: SlowMist Joins Industry Experts to Explore New Security Paradigms in AI & Web3

9 min readApr 23, 2026

--

Press enter or click to view image in full size

On the afternoon of April 21, Hacking Time, hosted by SlowMist, was successfully held at the CAI Building in Hong Kong. Riding the momentum of the Hong Kong Web3 Festival, the event was themed “Security for AI & Crypto, AI for Security,” bringing together security researchers, developers, industry experts, and Web3 practitioners from around the world. The venue was fully packed with a vibrant atmosphere, and attendees continuously rotated between listening and networking sessions, reflecting the industry’s strong interest in the convergence of AI and Web3 security.

Press enter or click to view image in full size

Hacking Time Event Recap

The event officially kicked off under the moderation of 23pds, Partner & CISO of SlowMist. He began by welcoming all guests and attendees, and provided a brief overview of the theme and agenda of this Hacking Time, setting the tone for the event as “technology-driven + practice-oriented.”

Press enter or click to view image in full size

Next, Cos, the founder of SlowMist, delivered the opening keynote speech focusing on “SlowMist AI Security Practices.” He pointed out that AI security threats have evolved from a “future risk” into a “present reality.” On one hand, attackers are leveraging AI to significantly enhance malicious capabilities — for example, lowering the barrier for audio and video deepfake generation and improving the efficiency of vulnerability discovery. On the other hand, when projects integrate AI, they may also introduce new security risks due to issues such as model hallucinations and reliance on third-party model services.

On this basis, Cos further emphasized that with the rise of AI Agents, “text becomes instruction” is emerging as a new security boundary. Prompts themselves may become attack vectors, introducing entirely new attack surfaces and defense challenges.

From a practical perspective, he outlined SlowMist’s journey from a community-driven approach to productized implementation. He also introduced an AI security framework centered on MistAgent, combined with capabilities such as MistEye and MistTrack, to build a comprehensive AI security system.

He concluded by noting that as AI and Web3 continue to converge deeply, the essence of security competition still comes down to humans — either mastering the machine, or being shaped by it.

Press enter or click to view image in full size

In the following thematic sharing session, several technical experts from SlowMist and the broader industry conducted in-depth analyses of key security challenges across AI and Web3 from multiple perspectives:

Thinking, Head of Business Security at SlowMist, delivered a talk titled “From the Frontline to Infrastructure: Building an AI-Driven Threat Intelligence Security Loop.” He provided a deep analysis of the “asymmetry in offense and defense” in the AI era, driven by attackers leveraging automation tools and social engineering techniques. He combined real-world cases such as supply chain poisoning, malicious plugins in AI Agent Skills marketplaces, and the Bybit hack incident to illustrate how SlowMist has progressively transformed eight years of frontline offensive and defensive experience into scalable security infrastructure. The presentation highlighted a five-layer defense-in-depth system, including MistEye (threat perception), MistAgent (deep analysis engine), and MistTrack (on-chain risk control). He emphasized a productization strategy that combines “expert human capabilities × AI” to build a self-adaptive digital immune system for the Web3 and AI ecosystem.

Press enter or click to view image in full size

Kong, Head of Security Audit Team at SlowMist, focused on “AI-Powered Web3 Security : The Offense and Defense Practices,” exploring the applications and boundaries of AI in smart contract auditing and on-chain attack analysis. He pointed out that current AI-powered auditing faces challenges such as context limitations and insufficient reliability of conclusions. To address this, he introduced a four-layer architecture based on AST parsing, RAG-based historical case retrieval, multi-model parallel auditing, and LLM-as-Judge, aimed at improving the trustworthiness of audit results.

At the same time, he proposed optimizing on-chain attack analysis workflows through a “cognitive state architecture” to mitigate attention dilution issues, enabling more precise reconstruction of attack paths and root cause identification.

Press enter or click to view image in full size

Keywolf, Partner & CPO at SlowMist, delivered a talk titled “AML Challenges and Countermeasures in the Age of AI for Cryptocurrency.” He provided an in-depth analysis of the increasingly severe anti-money laundering landscape for crypto assets amid rapid AI advancements and geopolitical dynamics.

On the technical side, Keywolf highlighted two core capabilities of SlowMist’s AML system. First, for on-chain entities (such as exchanges and smart contracts), he introduced a four-step methodology — “account opening KYC → deposit interaction → withdrawal detection → automated monitoring” — combined with techniques such as Nonce derivation and CREATE2 precomputation to enable precise identification and dynamic updates.

Second, he discussed the construction of a global black address intelligence network, which leverages both public data and high-barrier non-public intelligence (such as judicial collaboration and industry alliances) to continuously track and label malicious addresses.

Press enter or click to view image in full size

In the industry insight session, guest speakers also brought a diverse range of perspectives:

Security speaker SEEM delivered a talk titled “The Engineering Reality and Security Applications Behind Claude Code’s Source Code,” offering an in-depth breakdown of the underlying architecture of AI agents. He introduced the concept of “context engineering,” advocating for empowering agents with autonomous exploration capabilities through tool integration, while leveraging a Harness mechanism to address context contamination in long-running tasks.

He also analyzed a “boundary-centric” security defense model, emphasizing the use of sandbox isolation and permission gating to limit the blast radius. He highlighted that the capabilities of AI agents are, in essence, the result of deep synergy between model capabilities and engineering constraints.

Press enter or click to view image in full size

Chris Yang, founder at RC² TSCM LAB, delivered a talk titled “Privacy Protection for Web3 Practitioners: A Brief Overview.” Drawing on his professional experience in RC²’s commercial secret and privacy protection services, he exposed the physical coercion risks — such as “wrench attacks” — faced by Web3 professionals worldwide.

Referencing a series of serious incidents between 2024 and 2025, he pointed out that intelligence leakage remains the core threat, and emphasized that traditional security measures are insufficient to meet the needs of concealing digital wealth.

Press enter or click to view image in full size

In the latter half of the event, a high-quality panel discussion brought the atmosphere to its peak. Centered on the theme “The Future of Web3 in Hong Kong : Will AI or Stablecoins Be the Key Driver”, the panel was moderated by Tony Tan, SlowMist Hong Kong Community Lead.

Guests from diverse fields — including Neilson Lei, CTO of RigSec; Calix, Founder & CEO of FinTax; Jacqueline Qiao, Partner at JunHe Law Offices ; and Keywolf, Partner & CPO of SlowMist — engaged in discussions from multiple perspectives, including technology, compliance, industry, and finance.

Focusing on the roles of AI and stablecoins in the future Web3 ecosystem, the panelists generally agreed that the two are not in a zero-sum relationship, but rather serve as mutually reinforcing core infrastructures. AI can provide risk control and operational support for stablecoins, while stablecoins offer value anchoring and payment rails for the AI-driven economy.

Building on this, the panel further explored Hong Kong’s development path within the global Web3 landscape. The consensus was that if Hong Kong can seize the opportunity at the intersection of AI and stablecoins, it is well-positioned to gain a competitive edge in the next phase of Web3 industry development.

Press enter or click to view image in full size

The event maintained a highly focused and engaging atmosphere throughout. During breaks between presentations and discussions, speakers and attendees engaged in continuous exchanges around AI security, on-chain offense and defense, and compliance practices, with frequent interactions.

Both the in-depth technical breakdowns on stage and the spontaneous discussions off stage reflected the industry’s strong attention to the topic of “AI × Web3 Security.” This also made Hacking Time one of the most technically in-depth security-focused events during this year’s Hong Kong Web3 Festival.

Press enter or click to view image in full size

In addition, following the conclusion of Hacking Time, a networking session titled “SlowMist Night Talk” brought together more than 30 professionals from fields including security research, on-chain analytics, compliance, and infrastructure to engage in in-depth discussions on AI × Web3 security.

In a relaxed and open atmosphere, participants strengthened mutual understanding and connections through self-introductions and experience sharing. They also exchanged insights on topics such as threat intelligence sharing, collaborative attack detection, and complementary security capabilities.

These discussions further enhanced cross-team and cross-organizational understanding and collaboration, laying a foundation for closer cooperation in on-chain security defense and ecosystem security development in the future.

Closing Remarks

This Hacking Time not only maintained its consistent level of technical depth and professional standards, but also clearly illustrated, in the context of AI and Web3 convergence, the evolution of security systems from “offensive and defensive practices” toward “infrastructure-level capabilities.” From smart contract auditing to on-chain attack analysis, from threat intelligence to compliance governance, the diverse set of presentations collectively pointed to a central trend: security is becoming one of the most critical foundational capabilities in the AI × Web3 era.

As the industry continues to evolve, security is no longer merely a defensive measure, but a foundational layer that supports system stability and value flow. The ongoing Hacking Time series aims to foster a more resilient and sustainable security ecosystem through open exchange and practical insights. Looking ahead, SlowMist will continue to be technology-driven and work alongside global practitioners to advance a safer and more trustworthy Web3 ecosystem.

We sincerely thank all speakers and attendees who joined and contributed to Hacking Time. We look forward to seeing you again at the next session.

P.S. For further discussion and learning, selected presentation slides from this event are now available for download via GitHub: https://github.com/slowmist/HackingTime_Public/tree/master#hacking-time-%E7%AC%AC%E4%BA%94%E6%9C%9F-20260421

About SlowMist

SlowMist is a threat intelligence firm focused on blockchain security, established in January 2018. The firm was started by a team with over ten years of network security experience to become a global force. Our goal is to make the blockchain ecosystem as secure as possible for everyone. We are now a renowned international blockchain security firm that has worked on various well-known projects such as HashKey Exchange, OSL, MEEX, BGE, BTCBOX, Bitget, BHEX.SG, OKX, Binance, HTX, Amber Group, Crypto.com, etc.

SlowMist offers a variety of services that include but are not limited to security audits, threat information, defense deployment, security consultants, and other security-related services. We also offer AML (Anti-money laundering) software, MistEye (Security Monitoring), SlowMist Hacked (Crypto hack archives), FireWall.x (Smart contract firewall) and other SaaS products. We have partnerships with domestic and international firms such as Akamai, BitDefender, RC², TianJi Partners, IPIP, etc. Our extensive work in cryptocurrency crime investigations has been cited by international organizations and government bodies, including the United Nations Security Council and the United Nations Office on Drugs and Crime.

By delivering a comprehensive security solution customized to individual projects, we can identify risks and prevent them from occurring. Our team was able to find and publish several high-risk blockchain security flaws. By doing so, we could spread awareness and raise the security standards in the blockchain ecosystem.

--

--

SlowMist
SlowMist

Written by SlowMist

SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.