<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Benjamin Samuels on The Trail of Bits Blog</title><link>https://miscreants.github.io/blog.trailofbits.com/authors/benjamin-samuels/</link><description>Recent content in Benjamin Samuels on The Trail of Bits Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 15 Nov 2025 00:00:00 -0500</lastBuildDate><atom:link href="https://miscreants.github.io/blog.trailofbits.com/authors/benjamin-samuels/index.xml" rel="self" type="application/rss+xml"/><item><title>Level up your Solidity LLM tooling with Slither-MCP</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/11/15/level-up-your-solidity-llm-tooling-with-slither-mcp/</link><pubDate>Sat, 15 Nov 2025 07:00:00 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/11/15/level-up-your-solidity-llm-tooling-with-slither-mcp/</guid><description>We’re releasing Slither-MCP, a new tool that augments LLMs with Slither’s unmatched static analysis engine.</description></item><item><title>Balancer hack analysis and guidance for the DeFi ecosystem</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/11/07/balancer-hack-analysis-and-guidance-for-the-defi-ecosystem/</link><pubDate>Fri, 07 Nov 2025 18:00:00 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/11/07/balancer-hack-analysis-and-guidance-for-the-defi-ecosystem/</guid><description>A retrospective on the $100M Balancer hack that occurred in November 2025, including long-term, strategic guidance on how to avoid similar bugs.</description></item><item><title>Maturing your smart contracts beyond private key risk</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/06/25/maturing-your-smart-contracts-beyond-private-key-risk/</link><pubDate>Tue, 24 Jun 2025 07:00:00 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/06/25/maturing-your-smart-contracts-beyond-private-key-risk/</guid><description>Private key compromise accounted for 43.8% of crypto hacks in 2024, yet traditional smart contract audits rarely address architectural access control weaknesses. This post introduces a four-level maturity framework for designing protocols that can tolerate key compromise, progressing from single EOA control to radical immutability, with practical examples demonstrating multisigs, timelocks, and the principle of least privilege.</description></item><item><title>The Custodial Stablecoin Rekt Test</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/05/29/the-custodial-stablecoin-rekt-test/</link><pubDate>Thu, 29 May 2025 00:00:00 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/05/29/the-custodial-stablecoin-rekt-test/</guid><description>Introducing the Custodial Stablecoin Rekt Test; a new spin on the classic Rekt Test for evaluating the security maturity of stablecoin issuers.</description></item><item><title>How Threat Modeling Could Have Prevented the $1.5B Bybit Hack</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/02/25/how-threat-modeling-could-have-prevented-the-1.5b-bybit-hack/</link><pubDate>Tue, 25 Feb 2025 00:00:00 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/02/25/how-threat-modeling-could-have-prevented-the-1.5b-bybit-hack/</guid><description>Learn how comprehensive threat modeling could have identified the operational security gaps that led to Bybit&amp;rsquo;s $1.5B hack and prevented similar breaches.</description></item><item><title>The $1.5B Bybit Hack: The Era of Operational Security Failures Has Arrived</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/02/21/the-1.5b-bybit-hack-the-era-of-operational-security-failures-has-arrived/</link><pubDate>Fri, 21 Feb 2025 00:00:00 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/02/21/the-1.5b-bybit-hack-the-era-of-operational-security-failures-has-arrived/</guid><description>The $1.5B Bybit Hack demonstrates how the Era of Operational Security Failures has arrived, and most cryptocurrency companies are not prepared for its implications.</description></item><item><title>Releasing the Attacknet: A new tool for finding bugs in blockchain nodes using chaos testing</title><link>https://miscreants.github.io/blog.trailofbits.com/2024/03/18/releasing-the-attacknet-a-new-tool-for-finding-bugs-in-blockchain-nodes-using-chaos-testing/</link><pubDate>Mon, 18 Mar 2024 09:00:59 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2024/03/18/releasing-the-attacknet-a-new-tool-for-finding-bugs-in-blockchain-nodes-using-chaos-testing/</guid><description>Today, Trail of Bits is publishing Attacknet, a new tool that addresses the limitations of traditional runtime verification tools, built in collaboration with the Ethereum Foundation. Attacknet is intended to augment the EF’s current test methods by subjecting their execution and consensus clients to some of the most challenging network conditions […]</description></item><item><title>The Engineer’s Guide to Blockchain Finality</title><link>https://miscreants.github.io/blog.trailofbits.com/2023/08/23/the-engineers-guide-to-blockchain-finality/</link><pubDate>Wed, 23 Aug 2023 07:00:53 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2023/08/23/the-engineers-guide-to-blockchain-finality/</guid><description>Many security-critical off-chain applications use a simple block delay to determine finality: the point at which a transaction becomes immutable in a blockchain’s ledger (and is impossible to “undo” without extreme economic cost). But this is inadequate for most networks, and can become a single point of failure for the centralized exchanges, […]</description></item></channel></rss>