Security | 29 min read

The Coldcard Hack

How a five-year-old build error turned a trusted hardware wallet into predictable keys, and what it really teaches about generating, operating, and governing secrets.

Thibault de Lachèze-Murel Chief Information Security Officer
Security 9 min read

CGGMP21 Vulnerabilities Patched and Explained

CGGMP21 vulnerabilities have been disclosed and fixed. DFNS clients remain fully secure.

Denis Varlakov
Security 4 min read

A Month of Pentesting Completed

DFNS completes a month-long pentest with Borg Security, finding zero vulnerabilities.

Thibault de Lacheze-Murel
Security 8 min read

Certified ISO 27001, ISO 27017 and ISO 27018

DFNS achieves ISO 27001, 27017 and 27018 certifications, raising the bar on security, cloud assurance, and data privacy.

Thibault de Lacheze-Murel
Security 23 min read

The Bybit / Safe Hack

How one compromised laptop led to the largest crypto heist in history. This deep dive breaks down the attack, the systemic weaknesses it revealed, and why crypto must embrace real security beyond best practices.

Thibault de Lacheze-Murel, Christopher Grilhault des Fontaines
Security 7 min read

SOC 2 Renewed by KPMG

DFNS has successfully renewed its SOC 2 Type II certification for 2024 after a rigorous nine-month audit by KPMG, one of the Big Four firms.

Thibault de Lacheze-Murel
Security 7 min read

Cracks in Wallet Iframe Security

DFNS' security team has identified security risks in wallet iframes, based on vulnerabilities discovered in a major derivatives exchange. In this post, we'll explain how we uncovered and demonstrated the issue. We'll also explore how advanced methods like MPC and WebAuthn provide safer, non-custodial options to better protect user funds.

Thibault de Lacheze-Murel
Security 7 min read

The Magic Link Vulnerability

A year ago, our security team discovered a vulnerability in magic links that changed our industry's approach to wallet authentication.

Thibault de Lacheze-Murel
Contact us