A few quick notes
(1) Supernova is live, running with remarkable speed and precision.
(2) Over the next 5–10 days, glo | Hanami
A few quick notes
(1) Supernova is live, running with remarkable speed and precision.
(2) Over the next 5–10 days, global exchanges and other independent partners will begin reopening deposits and withdrawals. The rollout is gradual by design. Each exchange follows its own rigorous internal process, built to protect users and keep the recovery smooth.
(3) An in-depth security analysis is still underway. Several critical elements are already mapped and understood, from the bugs and their fixes to the technical implications and the path to recovery. A few discussions with independent parties remain open. The findings are preliminary, but one stands out above the rest. The tools, methods, preparation, and coordination behind this attack appear to go well beyond those typically associated with amateur attackers. The observed sophistication bears the hallmarks of advanced, experienced, repeated threat actors, including groups operating at the level historically associated with hacker organizations such as Lazarus. Attribution is not yet confirmed, but it is worth stating this out loud: to have successfully defended our users against Lazarus, or another group of that caliber, is a milestone we are proud of! Huge respect to all independent partners, including global exchanges, who have mobilized with extraordinary speed for the greater good of protecting users and the network!
(4) More importantly, the larger lesson goes beyond this incident. As an industry, we have entered an era of permanent, constant, unending war. Open-source financial infrastructure operates on a global battlefield, continuously exposed to increasingly sophisticated attackers, tools, and methods. Under these conditions, the traditional definition of security is no longer sufficient.
Three capabilities are becoming non-negotiable:
(a) a relentless defensive and offensive security tooling arms race;
(b) continuous, 24/7 red-teaming and penetration testing;
(c) blitz-speed detection, coordination, and response.
We have been intensifying precisely these capabilities over the past 3–6 months. What happened over the last few days is one visible incident among several potential threats that have been identified, contained, or neutralized through increasingly proactive security work.
This reality is not unique to MultiversX. Every major open-source stack, every blockchain (bitcoin and ethereum not excluded), and soon, every closed source software stack, will increasingly have to adapt to an environment where infrastructure is continuously and deeply probed, attacked, and tested. That requires a much more rugged approach to code. A more adversarial approach to architecture design. And ultimately, a fundamental rethinking of how safety-critical software is built and defended.
The three measures above are critical today. But over time, we will need to go much further and rethink security from the ground up for the new world we are actually operating in. Verifiably correct-by-construction software is about to have its moment and become fashionable very quickly. Reality has a way of accelerating standards. Not so much by preference, but by necessity.