Notes

Breaking down the shifts.

Short reads exploring specific aspects of post-quantum, autonomous AI, and on-chain security. New pieces roughly monthly per shift.

AI
Coming soon

Tool-Output Injection: The Attack Vector Nobody's Testing For

A narrower, more concrete injection vector than the usual prompt-injection framing — and one most red-team methodology misses.

AI
Coming soon

Memory Poisoning, Explained

A distinct failure mode from prompt injection, and one most agentic security coverage skips entirely.

AI
Coming soon

Why "Guardrails" Aren't Enough

The real limits of prompt-level defenses, and what actually has to change instead.

PQC
Coming soon

Why Quantum Computers Will Eventually Break Bitcoin and Ethereum Signatures

Why classical signature schemes break under quantum attack, and what that means for on-chain systems specifically.

PQC
Coming soon

Which NIST Post-Quantum Algorithm Actually Applies to You

A fast, practical guide to ML-KEM, ML-DSA, and SLH-DSA — and which one actually matters for your situation.

PQC
Coming soon

"Harvest Now, Decrypt Later" — Who's Actually Exposed Today

Real exposure isn't hypothetical — a concrete look at who's actually at risk today, and why waiting has a cost.

WEB3
Coming soon

Access Control Bugs: The Most Boring, Most Common Web3 Vulnerability

Not the flashy exploit — the dumb one that keeps happening, and why it's still so common.

WEB3
Coming soon

Why "Immutable" Doesn't Mean What People Think

What blockchain immutability actually guarantees — and the gap between that and what people assume.

WEB3
Coming soon

Flash Loan Attacks, Explained in Under Five Minutes

A fast, concrete walkthrough of how flash loan attacks actually work.