Opsek founder warns of security risks from providers and code complexity

Summary

Pablo Sabbatella, founder of Opsek, highlighted two critical security risks in the cryptocurrency space: reliance on unchecked providers and the complexities of code. He pointed out that recent attacks exploited vulnerabilities in third-party security products used by exchanges, emphasizing that the effectiveness of an organization’s security is heavily dependent on its providers' operational security. Additionally, he noted that many crypto organizations fail to properly vet their domain registrars, which can lead to domain theft. This situation is aggravated by the prevalent issue of complexities in human-written code, which increases the likelihood of bugs and security vulnerabilities, creating further risks for the sector.

Analysis

Opsek: Opsek provides operational security audits and training for web3 organizations and high-net-worth individuals. Its founder recently appeared on Laura Shin's Uneasy Money podcast to discuss security risks tied to third-party providers and code complexity in the wake of incidents like the Bitget hack. Trezor: Trezor is a cryptocurrency hardware wallet provider. It was recently cited in security discussions as an example after attackers breached its email marketing provider Brevo, resulting in phishing emails sent to a large number of subscribers. GoDaddy: GoDaddy is a prominent domain registrar and web hosting provider. It addressed a CSRF vulnerability in September 2026 that could enable domain hijacking, consistent with warnings about crypto organizations' registrar security practices. Pablo Sabbatella: Pablo Sabbatella is a Web3 operational security researcher and founder of Opsek who also hosts SecuritySeries and is a member of SEAL_Org. He joined Laura Shin's Uneasy Money livestream on September 30, 2026, to analyze provider-related risks and code vulnerabilities highlighted by recent crypto security events. Provider Risk: Recent breaches of third-party services have enabled phishing campaigns targeting crypto users through legitimate-looking communications. Domain Security: Vulnerabilities identified in major registrars have raised concerns about domain takeover risks for crypto projects and organizations. Code Vulnerabilities: Security experts continue to note that human-written code in crypto systems leaves substantial unexploited attack surfaces.

Categories

cryptotech

Related sources

View Original Tweet