Sitemap

SlowMist CISO 23pds Invited to Speak at “Web3 Leader Programme” Open Class

7 min readJan 5, 2026
Press enter or click to view image in full size

From January 2 to January 4, the Web3 Leader Programme (Cohort II), jointly launched by the Global Fintech Institute (GFI), HashKey Group, and the Frontier Technology Institute (FTI), was successfully held in Hong Kong. On January 3, 23pds, CISO of SlowMist, was invited to deliver a public lecture, engaging in in-depth discussions with guests and participants from traditional finance, blockchain, and frontier technology sectors on security challenges and risk governance in the development of Web3.

Press enter or click to view image in full size

At this public lecture, 23pds delivered a talk titled The Cost of Trust: The Past and Present of Cryptocurrency Security Drawing on years of blockchain security research and real-world incident response experience, he systematically reviewed the evolution of Web3 security issues and analyzed — from both attacker and user perspectives — why trust is so frequently abused in the crypto ecosystem, as well as how industry participants can build long-term, sustainable security awareness.

Why Has Web3 Become a “Dark Forest”?

At the beginning of the talk, 23pds traced the development of cryptocurrencies, revisiting landmark events such as the early “10,000 BTC for pizza” transaction to illustrate how crypto assets evolved from a niche technological experiment into high-value financial assets. He noted that as prices and market scale continued to grow, crypto assets increasingly became prime targets for attackers.

According to data from the SlowMist Hacked (https://hacked.slowmist.io/), as of December 30, 2025, a total of 1,990 blockchain hacking incidents have occurred globally, resulting in losses of approximately USD 36.927 billion. Among them, the Ethereum and BSC ecosystems were the hardest hit. Attacks caused by smart contract vulnerabilities were the most frequent, totaling 339 incidents, while phishing attacks ranked ninth but remained equally destructive. These figures vividly underscore the severe security challenges facing crypto assets today.

Press enter or click to view image in full size

Using the Mt. Gox incident as an example, 23pds warned:

“When trust is placed in technical systems without mature security governance mechanisms, a single mistake can often trigger a chain reaction that lasts for years.”

Press enter or click to view image in full size

In his view, the risks of Web3 do not stem from isolated incidents, but from a combination of inherent characteristics — high value, high liquidity, decentralization, and the irreversibility of transactions. In an environment where identities are difficult to verify and rules can be easily disguised, any misjudgment may be quickly exploited and amplified, which is the fundamental reason why Web3 is often described as a “dark forest.”

Breaking Down the Phishing Attack Chain

Focusing on phishing attacks — the most prevalent threat in the Web3 ecosystem — 23pds provided a systematic breakdown of their full attack chain during the talk. He pointed out that a mature phishing attack is rarely a single, isolated action; rather, it is a highly modular and reusable “industrialized process,” typically consisting of the following stages:

  • Selection and long-term monitoring of trending projects
  • High-fidelity imitation of identities, channels, and infrastructure
  • Design of bait with strong “high-return” appeal
  • Precise distribution via social media, search engines, and direct messages
  • Execution of the attack at critical moments such as authorization, signing, or software installation
  • Post-attack cleanup and obfuscation of fund flows
Press enter or click to view image in full size

23pds highlighted several classic phishing techniques:

  • Impersonation of official domains and social media accounts:

Attackers register highly similar domain names, replicate official website layouts, or masquerade as a project’s official X, Telegram, or Discord accounts to create an environment that looks “almost identical” to the real one. When users fail to perform secondary verification, they can easily be led to phishing pages during airdrop claims, wallet connections, or signing operations.

  • DM phishing and “official contact” pretexts:

Attackers often pose as “official administrators,” “project support staff,” or “community managers,” proactively reaching out to users via direct messages. Using excuses such as “account abnormalities,” “eligibility verification,” or “beta access invitations,” they lure users into clicking links or granting permissions. This type of attack exploits users’ trust in perceived authority and their anxiety about missing out on opportunities.

  • Fake airdrops, fake whitelists, and high-yield bait phishing:

Attackers design seemingly legitimate airdrop campaigns or whitelist tasks around trending projects, requiring users to complete a series of “normal” actions such as connecting wallets, signing messages, or approving contracts. The process often shows no obvious red flags, but ultimately embeds the risk of asset theft at the authorization stage.

  • Similar prefix-and-suffix address phishing:

Attackers generate wallet addresses whose beginning and ending characters closely resemble those of a target address, creating visual confusion during transfers and tricking users into sending assets to the attacker’s address. This type of attack typically does not rely on any technical vulnerabilities, but instead exploits users’ inattention to detail.

23pds emphasized that the essence of these techniques is “psychological warfare” — attackers exploit users’ desire for profits and their tendency to underestimate risk, rather than relying on sophisticated technical vulnerabilities. The core of defense lies not only in technical measures, but more importantly in improving awareness and cultivating habits of self-verification.

Web3 Security Defense Principles

Drawing on SlowMist’s years of research and hands-on experience, 23pds pointed out that a comprehensive set of technical tools forms an important foundation for Web3 security. In practice, SlowMist employs a security capability framework covering fund tracking, threat monitoring, and incident response to help reconstruct attack paths, identify high-risk behaviors, and provide warnings and support before and after security incidents, minimizing the impact of risk propagation. However, he also emphasized that relying solely on tools is not enough to build a truly robust security defense. Numerous security incidents show that the problem often does not lie in a “lack of tools,” but in underestimating risks and defaulting to trust at critical decision points.

Based on this, he introduced two mutually reinforcing core principles: zero trust and continuous verification. Zero trust does not mean rejecting everything, but rather refraining from establishing trust until verification is complete. Continuous verification is a long-term habit — before every authorization, signature, or program installation, actively asking, “Why do I trust this?” In his view, the real danger is not “lacking security knowledge,” but defaulting to thinking “this time should be fine” when faced with seemingly reasonable opportunities. The goal of security defense is not to achieve absolute safety, but to continually reduce the likelihood of making wrong decisions in critical operations. Additionally, he recommends that Web3 practitioners and users thoroughly study the Blockchain dark forest selfguard handbook, systematically learning from typical attack cases, cognitive traps, and defense strategies to further strengthen risk awareness and response capabilities.

Summary

At the end of the session, 23pds concluded: “The freedom, efficiency, and decentralization of Web3 inevitably come with greater personal responsibility. In a system where transactions are irreversible and accountability is highly individualized, misplaced trust often carries a personal cost.” He emphasized that Web3 security is not a one-time accumulation of knowledge, but a long-term cognitive training. Being aware of the limits of one’s judgment and restraining the impulse toward “too-good-to-miss” opportunities is the true skill for navigating this “dark forest.”

This session not only helped the participants of the Web3 Leader Programme (Cohort II) gain a comprehensive understanding of the offense-and-defense landscape in blockchain security, but also showcased SlowMist’s extensive experience and deep insights in the field. Participants generally reported significant takeaways, achieving a clearer and more holistic understanding of Web3 security risks, attack techniques, and defensive strategies.

About SlowMist

SlowMist is a threat intelligence firm focused on blockchain security, established in January 2018. The firm was started by a team with over ten years of network security experience to become a global force. Our goal is to make the blockchain ecosystem as secure as possible for everyone. We are now a renowned international blockchain security firm that has worked on various well-known projects such as HashKey Exchange, OSL, MEEX, BGE, BTCBOX, Bitget, BHEX.SG, OKX, Binance, HTX, Amber Group, Crypto.com, etc.

SlowMist offers a variety of services that include but are not limited to security audits, threat information, defense deployment, security consultants, and other security-related services. We also offer AML (Anti-money laundering) software, MistEye (Security Monitoring), SlowMist Hacked (Crypto hack archives), FireWall.x (Smart contract firewall) and other SaaS products. We have partnerships with domestic and international firms such as Akamai, BitDefender, RC², TianJi Partners, IPIP, etc. Our extensive work in cryptocurrency crime investigations has been cited by international organizations and government bodies, including the United Nations Security Council and the United Nations Office on Drugs and Crime.

By delivering a comprehensive security solution customized to individual projects, we can identify risks and prevent them from occurring. Our team was able to find and publish several high-risk blockchain security flaws. By doing so, we could spread awareness and raise the security standards in the blockchain ecosystem.

--

--

SlowMist
SlowMist

Written by SlowMist

SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.