Crypto reading list
Crypto security & investigations
Crypto security starts with several different questions. How did stolen funds move? Which rule in a contract failed? How did someone gain access to an account or device? Choose a question below and read a worked example from the person investigating it.
- Selected sources
- 10
People to read
Open the first material, then continue with the author on X. People appear once, grouped by their main reading use and ordered by handle within each group.
10 people
Onchain investigations
Follow transaction trails and see how investigators connect them to records, communications and other evidence.
-
Nick Bax combines transaction analysis with historical data and case documents. His work in commercial crypto forensics is useful when an explorer alone cannot explain a theft or identify the evidence behind an allegation.
Start with this Web material · medium.com
Anatomy of a Bitcoin Heist: The Electrum Atom Malware Saga
A historical case study of clipboard malware, transaction tracing and a civil complaint. Follow the distinction between the observed transfer, the researcher’s attribution and the allegations contested by the defendants.
Published . Material checked .
-
ZachXBT connects transaction trails with communications and other records in investigations of crypto theft and fraud. Read him to see which links come from the blockchain and which conclusions need additional evidence.
Start with this X post · x.com
Investigation of the Genesis creditor theft
Start with the reused deposit address in this 2024 investigation: it shows how two flows can become connected. Read the author’s allegations alongside the evidence and subsequent case updates.
Published . Material checked . Authorship source.
Audits & incident response
Understand why code fails, how researchers look for bugs and what teams do when a vulnerability puts funds at risk.
-
Luna Tong explains how researchers approach contract audits and which kinds of findings deserve attention. As cofounder and CEO of Zellic, she writes from inside the audit industry; her technical guides are most useful to readers who already understand code.
Start with this Web material · zellic.io
A technical introduction aimed at experienced vulnerability researchers. Start with the categories of contract problems and the discussion of reports; the career and market claims belong to the article’s 2022 context.
Published . Material checked .
-
Mudit shows how a vulnerability emerges from a particular combination of contract calls and how an incident response unfolds. Read him when you want the mechanism behind a failure, with code and the people’s decisions kept in the same story.
Start with this Web material · mudit.blog
A peek inside the MISO war room
The 2021 MISO story explains why batching and an otherwise reasonable payment function became dangerous together. The later sections show the coordination needed to address the bug; this is a historical incident account.
Published . Material checked .
-
@pcaversaccio Auditor
pcaversaccio organizes examples of EVM failures and builds tools for examining what people sign. His collections help a developer move from the name of a bug class to concrete incidents and the code behind them.
Start with this Code · github.com
A maintained collection of reentrancy incidents and references. Choose one familiar protocol and follow its linked explanation; the collection brings together others’ findings as well as the maintainer’s work.
Material checked .
-
samczsun explains serious contract vulnerabilities and the response when funds are already at risk. His writing connects individual bugs to the incentives and continuing work needed to protect a protocol after launch.
Start with this Web material · samczsun.com
Higher Bug Bounties Won’t Stop Hacks
A readable argument about the limits of tests, audits and bug bounties. Use it to ask how a team continues finding and addressing risk after its initial security checks.
Published . Material checked .
Personal security
Learn to recognize the risks in messages, calls, permissions, devices and backups before going deeper into technical research.
-
Dan Guido connects crypto theft to the security of devices, workflows and professional relationships. As cofounder and CEO of the security firm Trail of Bits, he offers a practitioner’s view of organizational defenses and their tradeoffs.
Start with this Web material · blog.trailofbits.com
Mitigating ELUSIVE COMET Zoom remote control attacks
A concrete example of a fake media invitation leading to a remote-control request. Read the account of the approach first, then the discussion of permissions and organizational controls.
Published . Material checked .
-
Lopp explains Bitcoin self-custody through threat models and experiments with backups and physical storage. He is a cofounder and Chief Security Officer at Casa; read him to understand the choices a storage design makes and the risks it leaves open.
Start with this Web material · blog.lopp.net
The article maps the decisions behind a seed backup: loss, damage, theft and the people who may need access. Use the decision process to understand tradeoffs before comparing particular storage products.
Published . Material checked .
-
Pablo teaches the everyday security of accounts, messages and work devices used in crypto. His perspective includes his security and training venture Opsek; start with the kinds of access a message or call asks you to grant.
Start with this Video · archive.devcon.org
OpSec for the Dark Forest (or how to avoid getting rekt)
The official Devcon archive hosts this nine-minute talk. Its scope includes devices, email, social accounts, passwords, 2FA and social engineering—a compact route into the questions to ask about everyday access.
Material checked .
-
Taylor explains phishing, malicious software and the ways people are persuaded to grant access themselves. Her MetaMask writing helps you look beyond a wallet interface to the device, message and permissions around it.
Start with this Web material · metamask.io
Blockchain malware’s neverending novelty
The article asks what a blockchain actually does for a malware campaign. Start with the delivery chain and compare the headline about a novel technique with the practical route onto a victim’s device.
Published . Material checked .
No people match that search. Try another name, subject or reading task.
A few bearings for your reading
These field notes explain the people, language and questions you may meet along the way.
Meet ZachXBT through an investigation
See what a transaction link establishes and where an investigator needs additional evidence.
Follow a claim back to its source
A practical way to read the conversation around an incident on X.
How this list is selected
We selected people through their own investigations, articles, code and talks. Linked public sources connect names or pseudonyms to X accounts. Material dates describe the linked work; check dates describe checking the material and its authorship through the cited sources. Recent X activity is recorded separately and remains unknown where it was not checked. Read case-specific conclusions alongside the evidence and any later updates.