When the chain is on fire, someone answers.
0xCERT is an independent, non-commercial CERT. We coordinate incident response, advisories, and stolen-fund recovery across smart contracts, bridges, wallets, and Web3 infrastructure — on every chain that matters.
● On-call now · 24/7 intake · initial triage within 24 hours
- 14:23:07
Report received
Bridge outflows · Ethereum → Base
- 14:23:41
On-call paged
Analyst acknowledged
- 14:31:12
War room opened
Protocol, bridge, 3 exchanges
- 14:52:30
Attacker EOAs flagged
IOCs pushed to wallet vendors
- 15:06:04
Funds frozen at off-ramp
Partial recovery in progress
Built on CERT standards
- Stolen in 2025
- $2.1B+
- across tracked exploits
- Initial triage
- < 24 h
- from report to analyst
- Chains monitored
- 40+
- live health checks every 5 min
- Coverage
- 24/7/365
- on-call rotation
How response works
From first message to public advisory.
A repeatable playbook adapted from forty years of CERT practice to a world where the ledger is the crime scene.
- T+001
You reach out
Form, email, or a peer CERT. Partial information is fine — speed beats completeness.
- T+60s02
On-call is paged
A human analyst acknowledges and assigns a case ID (CASE-YYYY-NNNN).
- T+24h03
Triage & containment
War room with your team, exchanges, bridges, and wallet vendors to stop the bleeding.
- T+disclosure04
Public advisory
Post-mortem, IOCs, and remediation published — signed, numbered, and syndicated.
Mission
Nobody owns the incident. So we coordinate it.
Traditional CERTs were designed for IP networks, TLS certificates, and a small set of vendors. Blockchains have none of those assumptions. Code is the bank, the ledger is public, and the attacker keeps the funds the moment a transaction lands.
Protocols, bridges, wallets, validators, and exchanges all touch the blast radius of a single exploit, but none of them have the standing to coordinate the others. We do.
We are non-commercial, vendor-neutral, and chain-agnostic. We don't sell a product. We answer the phone, run the war room, publish the advisory, and feed the IOC list to everyone who needs it — for free.
Services
What we do, around the clock.
Incident Response
24/7 triage and containment for active blockchain incidents.
Advisories & Vulnerability Disclosure
CVE-style advisories for smart contracts and Web3 infrastructure.
Threat Intelligence & IOC Feeds
Curated indicators of compromise for the Web3 attack surface.
Phishing & Drainer Takedowns
Coordinated takedown of malicious sites and front-end takeovers.
Stolen-Fund Tracing & Recovery Support
On-chain forensics to follow stolen assets across chains and mixers.
Awareness & Training
Tabletop exercises and IR training for protocol and infra teams.
Recent advisories
Coordinated disclosure, made public.
go-ethereum v1.17.8 security release fixes p2p DoS issues and a STUN-response node crash
go-ethereum (Geth) v1.17.8 is a security-focused release fixing several denial-of-service risks in the eth/snap p2p handlers, JUMPDEST analysis caching, BAL account handling, and a crash triggered by a rogue STUN server. Most fixes concern post-Amsterdam behaviour. Node operators should upgrade to v1.17.8.
CVE-2026-106511: MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference i
MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with the Proposer role to perform explicitly barred actions. This vulnerability allows the Proposer role to move funds alone, draining 100% of a contract's EGLD/ESDT balance in two transactions with zero signatures.
Vyper: Memory corruption using function calls within tuples / nested calls
Vyper: Memory corruption using function calls within tuples / nested calls. When performing a function call inside a tuple or as an argument inside another function call, there is a memory corruption issue that occurs because of an incorrect pointer to the the tip of the stack.
Active incident?
Don't wait. Triage starts the moment you reach out.
Funds moving, a key exposed, or a front-end serving malicious code — open a report and our on-call engineer is paged immediately. No contract, no retainer.