Kerberus’ Alex Katz: Why Psychological Attacks Are WEB3’s Biggest Risk – And How To Stop Them

ccn.comОпубликовано 2025-12-13Обновлено 2025-12-13

Введение

In an exclusive interview, Alex Katz, CEO of Web3 security firm Kerberus, highlights that the biggest risk in crypto is not technical flaws but psychological attacks. Despite evolving methods like NFT approval exploits and airdrop scams, over $594 million was lost to phishing in the first half of 2025 alone, with Solana users accounting for $90 million. Katz emphasizes that attackers exploit human behavior—greed, distraction, and haste—to gain control of wallets. Kerberus addresses these threats through its Sentinel3 browser extension, which uses a closed-source detection engine to evaluate and block malicious transactions in real time before they are signed. The firm has expanded to cover both EVM chains and Solana, and offers up to $30,000 in coverage if protection fails. Looking ahead, Katz warns that malware is the next major frontier, prompting Kerberus to develop a crypto-specific antivirus to protect private keys and seed phrases. The ultimate goal is to create a "secure by default" experience where security is automatic and invisible, enabling broader adoption by making it safer for all users.

In an exclusive interview with CCN, Alex Katz, CEO and founder of Kerberus, shared insights into the evolving security threats facing crypto users—and why most losses still come down to human behavior.

Kerberus, a Web3 security firm best known for its Sentinel3 browser extension, has protected over 250,000 users without a single reported loss since its launch nearly three years ago.

The Growing Threat Landscape in Web3

Phishing remains the dominant threat in crypto.

Katz pointed to industry data showing that more than $594 million was lost across blockchains in the first half of 2025 alone.

Solana users accounted for roughly $90 million—about 15% of those losses.

Katz emphasized that this reflects adoption and growth, rather than weaknesses in Solana’s design.

“Solana is growing a lot... Attackers do not discriminate based on asset or blockchain. They want your long-earned crypto.”

While attack methods evolve, ranging from NFT approval exploits to airdrop scams, the objective stays the same: gaining control of wallets.

Increasingly, Katz said, the real vulnerability is psychological.

“It’s purely psychological. The reason why people get drained is that they’re in a rush or distracted... You’re greedy. In the heat of the moment, you just want to go as fast as possible.”

Solana-Specific Risks—and Kerberus’ Approach

Solana introduces unique risks that differ from EVM-based chains. One example is token account ownership.

“What they can do in Solana is transfer the ownership of the token account... Instead of you seeing a transfer out of the token, the ownership is being transferred,” Katz explained.

Kerberus addresses these threats through a closed-source detection engine that evaluates transactions before they’re signed, allowing it to block malicious activity regardless of network speed.

After expanding into Solana in February 2025 and acquiring Pocket Universe in August, Kerberus now offers coverage across both EVM chains and Solana through Sentinel3 and its integrated Pocket Universe tooling.

Beyond Phishing: The Next Security Frontier

Katz warned that malware represents the next major threat.

Once a device is compromised, attackers can gain full control over wallets—something traditional antivirus tools are not designed to stop.

To address this, Kerberus is developing a crypto-specific antivirus focused on protecting private keys and seed phrases.

“Whenever some file is trying to access your private key or seed phrases, it would be stopped... This is specifically to protect you from crypto attacks and nothing else.”

Toward a “Secure by Default” Crypto Experience

For Katz, long-term adoption depends on making security invisible and automatic.

“Imagine that your mom or your grandma wants to come into crypto. It’s literally impossible for them to do right now... All the security rails and insurance have to be baked in.”

He emphasized that browser-level protections should work alongside hardware wallets, not replace them.

“You make the profits, we keep them yours.”

Kerberus positions itself as a proactive defense layer between users’ wallets and the web. As Katz explained:

“Kerberus is the only security solution for users that is designed to detect phishing sites in real time... If they install our browser extension, which is in the middle between their wallet and whatever the website wants to do, they just don’t get drained.”

Rather than reacting after funds are gone, Sentinel3 intercepts transactions before they’re signed, analyzing them in real time and blocking malicious requests with a clear warning.

Kerberus also offers up to $30,000 in coverage if its protection fails.

As crypto continues to scale, Kerberus is betting that reducing human error—not just patching technical flaws—will define the next phase of security.

Похожее

Four Questions on the Zcash Orchard Vulnerability: Was It Exploited? Can Funds Be Recovered? Is the Supply Verifiable? And Are There Others?

Zcash Orchard Bug: Four Key Questions Answered A critical forgery vulnerability was discovered in Zcash's Orchard privacy pool, raising four major concerns for users. 1. **Was the Orchard bug exploited?** The likelihood is considered low. The bug was found proactively using advanced AI-assisted tools and was promptly patched, limiting any potential attack window. If exploitation had occurred, evidence would likely have surfaced by now. 2. **Can legitimate Orchard funds be recovered?** It is believed so, based on the assessment that the bug was not exploited. If forgery did happen, existing "turnstile" mechanisms could prevent full recovery of legitimate funds if forged coins were moved out first, though this scenario is deemed unlikely. Users can choose to move funds, but this carries risks like loss of privacy or new wallet/software issues. 3. **Can users verify Zcash's total supply?** Currently, no. The vulnerability's prior existence prevented independent verification of the shielded supply. The proposed "Ironwood" network upgrade will restore this ability by sealing the Orchard pool, allowing anyone running a node to verify that the circulating ZEC does not exceed the correct amount. 4. **Are there other forgery bugs?** Ongoing intensive audits by multiple teams, including AI-assisted analysis, have not found additional forgery vulnerabilities, increasing confidence that none remain. Further work and collaborations are planned to provide additional guarantees. In conclusion, while the team assesses that exploitation was unlikely and the supply is safe, the upcoming upgrade is critical to restore users' ability to independently verify Zcash's supply integrity, moving away from reliance on trust.

marsbit28 мин. назад

Four Questions on the Zcash Orchard Vulnerability: Was It Exploited? Can Funds Be Recovered? Is the Supply Verifiable? And Are There Others?

marsbit28 мин. назад

Four Questions on the Zcash Orchard Vulnerability: Was it Exploited? Can Funds Be Recovered? Is the Supply Verifiable? Are There Others?

**Summary: Zcash Orchard Vulnerability Analysis** A critical forgery vulnerability was recently discovered in Zcash's Orchard shielded pool, raising concerns about the coin's supply and user funds. The developers, led by Zcash Open Development Labs, acted swiftly to temporarily freeze the pool and deploy a fix. The article addresses four key questions: 1. **Was the vulnerability exploited?** While unknown, the developers believe it is unlikely for several reasons: the bug was difficult to find, using advanced AI tools; the fix was deployed quickly; and typical crypto exploits are fast, with no evidence of abnormal outflows. 2. **Can legitimate Orchard funds be recovered?** If the bug was not exploited, all funds are safe. If exploited, a mechanism limits total withdrawals from the pool to the amount legitimately entered, potentially blocking some legitimate funds. The developers deem this unlikely but advise cautious users to consider moving funds, noting the privacy and risk trade-offs of moving to transparent or Sapling pools. 3. **Can users verify Zcash's total supply?** Not currently. The vulnerability temporarily broke the ability for users to independently verify that no extra ZEC was created. 4. **Are there other forgery bugs?** Ongoing audits by multiple teams, including using advanced AI analysis, have so far found no others, increasing confidence. The proposed "Ironwood" network upgrade is the core solution. It will **seal** the Orchard pool, preventing new entries or internal circulation. This action, combined with the existing withdrawal mechanism, will restore the ability for any node operator to verify that Zcash's supply limit has not been violated, regardless of whether exploitation occurred in the past. The upgrade aims to restore the system's long-term credibility through user-verifiable supply integrity.

Odaily星球日报29 мин. назад

Four Questions on the Zcash Orchard Vulnerability: Was it Exploited? Can Funds Be Recovered? Is the Supply Verifiable? Are There Others?

Odaily星球日报29 мин. назад

An AI Version of the 'Subprime Crisis'? A Hidden Debt of $1.8 Trillion is Accumulating in the Shadows Amid the Frenzy

Amidst the AI infrastructure construction boom, a massive debt expansion is forming, with the most dangerous portion remaining off-balance sheets. Morgan Stanley research reveals approximately $1.8 trillion in off-balance-sheet exposures, including nearly $1 trillion in purchase commitments and over $800 billion in non-active lease contracts. These future cash outflows are not recorded as liabilities. The leverage of hyperscale cloud companies has surged from 0.9x to 1.8x in just two quarters. Private credit firms like Apollo and Blackstone are shifting leverage into the supply chain through complex, opaque SPV (Special Purpose Vehicle) financing structures. Global AI-related bond issuance has skyrocketed, with annual volume projected to exceed $570 billion. However, capital expenditure growth is outpacing revenue and free cash flow. Major cloud providers may see free cash flow approach zero or turn negative in 2026. A significant 'depreciation cliff' looms as vast amounts of current capital spending, recorded as 'construction in progress,' have yet to begin depreciating, artificially inflating current profit margins. Future depreciation could severely pressure earnings. The core risk is identified as a series of timing mismatches, not an immediate solvency crisis. Investment is racing ahead of monetization, leverage is being obscured, and accounting classifications hinder comparability. The entire financing structure faces a fundamental stress test if AI commercialization lags or enterprise clients shift to cheaper alternatives, potentially triggering chain reactions within the highly interconnected funding ecosystem.

marsbit40 мин. назад

An AI Version of the 'Subprime Crisis'? A Hidden Debt of $1.8 Trillion is Accumulating in the Shadows Amid the Frenzy

marsbit40 мин. назад

Торговля

Спот
Фьючерсы

Популярные статьи

Как купить S

Добро пожаловать на HTX.com! Мы сделали приобретение Sonic (S) простым и удобным. Следуйте нашему пошаговому руководству и отправляйтесь в свое крипто-путешествие.Шаг 1: Создайте аккаунт на HTXИспользуйте свой адрес электронной почты или номер телефона, чтобы зарегистрироваться и бесплатно создать аккаунт на HTX. Пройдите удобную регистрацию и откройте для себя весь функционал.Создать аккаунтШаг 2: Перейдите в Купить криптовалюту и выберите свой способ оплатыКредитная/Дебетовая Карта: Используйте свою карту Visa или Mastercard для мгновенной покупки Sonic (S).Баланс: Используйте средства с баланса вашего аккаунта HTX для простой торговли.Третьи Лица: Мы добавили популярные способы оплаты, такие как Google Pay и Apple Pay, для повышения удобства.P2P: Торгуйте напрямую с другими пользователями на HTX.Внебиржевая Торговля (OTC): Мы предлагаем индивидуальные услуги и конкурентоспособные обменные курсы для трейдеров.Шаг 3: Хранение Sonic (S)После приобретения вами Sonic (S) храните их в своем аккаунте на HTX. В качестве альтернативы вы можете отправить их куда-либо с помощью перевода в блокчейне или использовать для торговли с другими криптовалютами.Шаг 4: Торговля Sonic (S)С легкостью торгуйте Sonic (S) на спотовом рынке HTX. Просто зайдите в свой аккаунт, выберите торговую пару, совершайте сделки и следите за ними в режиме реального времени. Мы предлагаем удобный интерфейс как для начинающих, так и для опытных трейдеров.

1.5k просмотров всегоОпубликовано 2025.01.15Обновлено 2026.06.02

Как купить S

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

Он решает проблемы масштабируемости, совместимости между блокчейнами и стимулов для разработчиков с помощью технологических инноваций.

2.3k просмотров всегоОпубликовано 2025.04.09Обновлено 2025.04.09

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

HTX Learn — ваш проводник в мир перспективных проектов, и мы запускаем специальное мероприятие "Учитесь и Зарабатывайте", посвящённое этим проектам. Наше новое направление .

1.8k просмотров всегоОпубликовано 2025.04.10Обновлено 2025.04.10

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на S (S) представлены ниже.

活动图片