North Korean IT workers: How DPRK infiltrates remote hiring
North Korea's fake IT workers have infiltrated hundreds of companies. How the DPRK scheme works, how big it is and how they are using American facilitators to grow even bigger
North Korea's fake IT workers have infiltrated hundreds of companies. How the DPRK scheme works, how big it is and how they are using American facilitators to grow even bigger
Behind every great security conference is a group of people reading through hundreds of submissions, looking for the talks that will teach the audience something real. At the DeFi Security Summit, that work runs through the Review Committee, which reads every talk and workshop proposal and helps the strongest, most useful research find its way to the stage. It's quiet, detailed work, and it's a big
You think you're smart enough to spot any scam? Good. We built something to check. 99% of stolen funds in Web3 today are not smart contract hacks anymore, they're Operational Security issues: social engineering, fake job interviews, malicious Zoom calls. Most Web3 hacks don't start onchain, they start on someone's laptop. The Bybit hack ($1.4bn) started with a developer getting social
When you set up a YubiKey, you get two main options: register it as a security key, or save a passkey on it. Both are phishing-resistant, both use the same crypto under the hood. So what's the actual difference, and which one should you use? This article breaks down what each mode is, what it does inside your authentication flow, and which setup is the strongest. If
The crypto industry has gotten better at auditing code. But the devices the code runs on are still underprotected. A compromised device is the cleanest path to a compromised key. If the device signing transactions or holding seeds hasn't installed its security updates, is sending out data it doesn't need to, has more services running than it actually uses, or was never properly cleaned, none of
We're proud to share that Opsek's founder, Pablo Sabbatella, has been elected to the Arbitrum Security Council. Pablo is one of the six members chosen by the Arbitrum DAO community in the March 2026 election. The Security Council is a 12-member body elected by the Arbitrum DAO, responsible for managing risk across the Arbitrum ecosystem. In practice, that means making time-sensitive decisions to protect
On May 5 in Miami, our founder Pablo Sabbatella will be at Solana Accelerate alongside Isaac Patka (Shield3) for 1:1 security office hours, hosted by SEAL, the Security Alliance.
TheDAO Fund finished announcing the 200 holders of the ETHSecurity Badge today. Pablo Sabbatella, founder of Opsek, is one of them. The badges are TheDAO Fund's mechanism for deciding how its security endowment gets allocated. Two hundred practitioners, selected over several batches against a public rubric, vote on which projects, teams, and tools receive funding. It's the closest thing Ethereum has produced to a credentialed electorate
Subscribe to get the latest updates, straight to your inbox.