Suppose your DAO requires three of five signers to move treasury funds. Nobody gets to send the money somewhere new because they happened to be the first person awake. Now look at the domain. Can one contributor log-in to the registrar and change its nameservers? Can another edit DNS records with an API token? If so, you have approval rules for the treasury and ... View Post
Our latest blog posts
Auto-Renew Is a Setting. Domain Continuity Is a Plan.
“It’s on auto-renew.” That’s a good answer, sure. It means somebody checked a box. The thing is that domain renewals can fail. So, what happens if it does...? Here’s a likely scenario. Suppose the company card is replaced after a fraud alert. The old card remains on the registrar account. Then, when the renewal charge fails, the warning goes to whoever ... View Post
Your Domain Has MFA. What Happens When Someone Calls Support?
Your team uses hardware security keys and the registrar account has a strong, unique password. So, you’ve done the sensible things. Now somebody contacts support and says they’ve lost their key. What happens next? If you don’t know, there is a part of your domain security you haven’t checked. It’s multi-factor authentication (MFA). MFA governs the normal ... View Post
Your Domain Recovery Email Could Lock You Out When You Need It Most
Your domain goes down. So you open the registrar’s login page, discover you need a password reset, and click the link. “Check your email.” The reset went to admin@example.com, BUT the domain you’re trying to fix is example.com. You need working email to regain access. You need access to restore the domain that makes the email work. Meanwhile, customers are ... View Post
Trezor supply chain hack moves to postal mail attack
Background: Crypto hardware wallet-maker Trezor recently disclosed a customer data breach in one of their shipping partners. This is problematic for crypto users in particular, since having one's home address revealed opens you to so-called "wrench attacks" - which is why we recommend using PO boxes for receiving potentially sensitive items where disclosing your ... View Post
AI Hallucinates Domains for Your Brand. Criminals Register Them.
Ask ChatGPT where to log into your company's customer portal. Do it a few times, in a few different phrasings, and sooner or later it hands back a URL that looks plausible and does not exist. Criminals run the same exercise at scale and register the answers. What Unit 42 Found Palo Alto Networks' Unit 42 published the numbers in June. They ran 913 ... View Post






