We analyzed the 100 largest digital asset security incidents from 2014 to H1 2026. ๐
The attack surface moved. 96% of H1 2026 losses now come from compromised keys, signing workflows, and vendor infrastructure.
๐ Get your copy: halborn.com/reports/top-100-โฆ
Custody decisions carry more than operational weight. They define an institution's compliance posture and risk exposure for years. โ๏ธ
Our CEO Jacques Boschung joins experts from @ArchaxEx, @taurus_hq, @Bitpanda, and @StateStreet at DAW London to break down each option.
DPRK-linked incidents were 0% of annual crypto losses in 2021. By H1 2026, they hit 81.9%. ๐จ
Fake recruiters, deepfake approval calls, compromised signing vendors. This is patient APT tradecraft, not smash-and-grab crime.
๐ฐ More in our report: halborn.com/reports/top-100-โฆ
$12B+ lost across the 100 largest digital asset hacks. ๐ธ
Our CEO Jacques Boschung made the case at @CV_Labs Summit yesterday: traditional finance cannot secure digital assets like a perimeter.
Atomic settlement means no recovery window. Only prevention.
The Avalanche Audit Marketplace is live on the Builder Hub ๐บ
One request reaches all Ava Labs vetted firms. Quotes stay private, you pick one, and the program can cover up to 75% of the cost.
$0 fees for builders and auditors.
Request quotes ๐
Most vault reviews stop at one question: is the code correct? ๐ก๏ธ
That misses where losses may actually happen.
This breakdown covers where those boundaries sit, how Morpho's architecture changes exposure at each one, and the controls to match.
๐ฐ Read: halborn.com/blog/post/morphoโฆ
$387.5M stolen. Not one private key touched. ๐ฑ
The Bitget hack, the largest crypto hack of 2026 so far, was pulled off by forging transactions through compromised backend infrastructure, not stolen keys.
๐ฐ Learn more: halborn.com/blog/post/explaiโฆ
The industry hardened smart contracts for years. Attackers adapted. ๐จ
Compromised keys, signing infrastructure, social engineering, and supply chain failures drove 96% of H1 2026 hack losses, up from 36% in 2021.
๐ฐ Get our Top 100 Hacks report: halborn.com/reports/top-100-โฆ
Custodian, self-custody, in-house build, or acquisition: which fits you? ๐ฆ
Each trades cost, control and compliance differently.
Halborn CEO Jacques Boschung joins a panel of experts at Digital Assets Week London to help institutions decide.
Nostra Finance, a Starknet-based lending protocol, was the victim of a price manipulation attack. ๐ธ
The attacker built a fake NSTR pool, wash traded for 20 minutes, and pumped the token 8,000x.
Full breakdown: halborn.com/blog/post/explaiโฆ
First audit just PASSED
We have successfully passed its security audit by @HalbornSecurity
Summary:
100% of all REPORTED Findings have been addressed
Details โ halborn.com/audits/1win/smarโฆ
$12 billion in digital asset hacks. And counting. ๐ธ
At @CV_Labs Summit, our CEO Jacques Boschung unpacks what the industry has learned from the largest hacks, and what institutions still need to fix before the next one.
๐ Save your spot: cvsummit.ch/
Security check: passed. ๐
AstralBeamโs security audit by @HalbornSecurity is complete.
0 critical findings
100% of reported findings addressed
The beam is clear. โจ
Read the full audit report: halborn.com/audits/casper-asโฆ
๐ง๐ต๐ฒ ๐ฉ๐ฎ๐๐น๐ ๐น๐ฎ๐๐ป๐ฐ๐ต๐ฒ๐ ๐ถ๐๐ ๐ผ๐๐ป ๐ ๐ฃ๐ ๐น๐ถ๐ฏ๐ฟ๐ฎ๐ฟ๐ ๐ณ๐ผ๐ฟ ๐ถ๐ป๐๐๐ถ๐๐๐๐ถ๐ผ๐ป๐ฎ๐น ๐ฐ๐๐๐๐ผ๐ฑ๐
We have launched our own multi-party computation (MPC) library for institutional custody, following an independent security audit by @HalbornSecurity.
The library is built in-house and supports our co-signing model, where no single party, including The Vault itself, can authorise a transfer on its own.
Building the cryptographic layer in-house gives us direct control over the code, signing protocols and release schedule. It also means auditors can examine the complete implementation without an external vendor boundary.
Halborn reviewed 91 files across the cryptographic core, test suite, and iOS and Android signer applications. All findings raised during the engagement were remediated and verified.
๐ Read more about this update and the work behind our MPC library in the full article: thevault.inc/company/newsrooโฆ
Most security budgets still go straight to smart contract audits. ๐
A backend that skips one validation check can drain funds just as fast. No exploit, no stolen key. In this article we break down the 3 most common offchain attack vectors.
๐ฐ Read: halborn.com/blog/post/top-3-โฆ
๐ก๏ธ @HalbornSecurity joins #CVSummit 2026 as a partner
Halborn is the security partner trusted by the world's largest banks and financial institutions to protect enterprise-grade digital assets. Their services span blockchain architecture assessment, custody and key management assessment, compliance readiness, as well as assurance work, giving institutions the coverage they need to innovate securely. With 4,000+ engagements completed and multiple zero-day discoveries, Halborn has protected over $1 trillion in value.
Meet Halborn at CV Summit 2026 to see how your organization can adopt digital assets while staying ahead of security, risk, and compliance requirements.
๐๏ธ Join the room on 29-30 September at Kongresshaus Zรผrich: cvsummit.ch/tickets
Together with @fuzefinance we built a blueprint for banks and custodians launching digital asset services. ๐ฆ
Custody architecture, regulatory mapping, and the exact controls the biggest exploits needed but didn't have.
๐ Get your copy: fuze.finance/report/securityโฆ
As a founding member of the @CantonFdn running validator infrastructure for regulated institutions, @IntellectEU needed proof its Azure KMS driver could hold up under scrutiny. ๐
Our work together provided that assurance.
๐ฐ Full case study: halborn.com/case-studies/posโฆ
.@HalbornSecurity has completed a security assessment of @AlpendHQ, a privacy-aware institutional money market built on the Canton Network.
The assessment covered Alpend's multi-party authorization, accounting, risk recomputation, and onchain verification.
โ Read the study.
We are pleased to release our case study with @AlpendHQ, a privacy-aware institutional money market built on the @CantonNetwork. ๐ธ
No audit corpus meant no shortcuts. Together, we built proof Alpend brings into institutional talks.
๐ฐ Read: halborn.com/case-studies/posโฆ
We are proud to share that we have completed our re-audit of the full Batch transaction implementation within the XRP Ledger codebase. ๐
The objective of the security engagement was to ensure batch security for the XRP Ledger.