Should GnosisDAO fund Rekt News for independent Safe security coverage?
Summary
Rekt News proposes a $40,000 USDC partnership with Gnosis DAO to produce a definitive retrospective and forward-looking reference on the post-Bybit Safe security era, plus structured ongoing editorial coverage of the Safe stack for 12 months. Output: the “Safe After Bybit” anchor piece, 3 follow-up long-form investigations, 6 distribution features across newsletter (~30K subscribers) and X (~280K followers @RektHQ), 1 video documentary, 1 podcast panel and a dedicated Safe security tag on hub.rekt.news. Topic selection collaborative with Gnosis contributors; framing, conclusions and incident coverage stay editorially independent. Ask: 40,000 USDC, 4 quarterly tranches against shipped deliverables.
About Rekt News
Rekt News (rekt.news) was founded by Julien Bouteloup and has operated since 2020 as an independent investigative publication covering DeFi security. No paywall, no token, no VC funding. Approximately 280K X followers (@RektHQ), 30K+ newsletter subscribers, 42K monthly readers. Routinely cited by audit firms, governance forums and security researchers. Operating entity located in Switzerland.
We hosted the inaugural Rekt Security Summit in Cannes, March 2026 (https://summit.rekt.news), with 40+ speakers including Gnosis VC, Ethereum Foundation, Certora, Nethermind, Trail of Bits, Immunefi, Cyfrin, Hypernative, Aragon and Curve. Full session recordings: https://www.youtube.com/playlist?list=PL8GXJfkZ1Eyhnmg46D7HeblLlHzBiZTMs
Why this proposal
Safe is the de facto standard for multisig infrastructure in crypto. Since the Bybit Lazarus heist of February 2025 — which targeted Safe{Wallet}'s frontend infrastructure rather than the Safe smart contracts themselves — it is also the case study every protocol team examines for frontend supply chain risk, transaction verification practice and operational multisig security. The forensic record of that period and the broader story of how Safe and its integrations hardened in response exists only as scattered post-incident threads, audit notes and protocol-controlled disclosures.
Forensic analyses of the incident exist (Mandiant, BlockSec, Sygnia). What does not exist is an independent editorial synthesis — drawing on interviews with Safe contributors, accessible to the broader DeFi community, forward-looking in scope — that tells the story of what Safe became in response. The Bybit incident is the context, not the subject. Rekt covered the original incident in real time (Rekt - <!-- -->ByBit - Rekt), has ongoing relationships with several of the audit firms involved and has the editorial format to produce that synthesis. Beyond the anchor, the Safe stack (modules, deployment practices, social engineering threat surface, signing infrastructure) continues to evolve and Gnosis DAO would benefit from sustained independent editorial coverage of it.
Why Gnosis specifically should fund this
The “Safe After Bybit” retrospective is a community asset that benefits Gnosis directly. Every protocol team thinking about frontend supply chain risk, transaction verification practice and the operational side of multisig security examines the Bybit story — and specifically how Safe rebuilt, hardened its entire infrastructure and came out as demonstrably stronger tooling. That antifragile case study does not yet exist in an accessible, independent format. The choice is whether it is told by a publication that already covered the incident in depth, or remains fragmented and protocol-controlled.
GNO holders and Gnosis contributors benefit from independent reference material on the topics they vote on: Safe ecosystem grants and integrations, contributor proposals related to the multisig stack, treasury allocations to Safe-related work. Independent editorial coverage of how the multisig category has been tested in the wild gives voters substantive context.
Safe is core infrastructure used by thousands of protocols. Multisig compromises and admin-key incidents have caused billions in losses across the ecosystem. Independent editorial coverage of these creates a public record with positive externalities far beyond Gnosis itself.
Defensive narrative matters too. Having a publication that already understands the architecture writing the post-mortem of any future incident is materially better for the Safe brand than the alternative.
Editorial scope and independence
This grant funds Rekt News to produce educational content covering Safe-stack security. Topic selection and editorial planning for the deliverables happen in collaboration with Gnosis DAO contributors. Gnosis may suggest topics, propose angles and review draft content for factual accuracy and clarity. Rekt retains final editorial decision on framing, conclusions and headlines.
Coverage of security incidents is treated separately. If Safe or any protocol in the Safe ecosystem experiences a security incident during this partnership, that coverage is not part of the educational scope above and is not subject to collaborative input. Incidents are covered with the same depth applied to our original “ByBit” investigation.
Disbursement is contingent on the listed deliverables being publicly published. It is not contingent on coverage tone or the specific framing of any individual piece. A Gnosis-designated multisig signer verifies that each deliverable exists at each tranche.
This commitment is documented in this proposal so it is enforceable as a community expectation, not just a promise.
Deliverables (12 months)
All deliverables published openly on rekt.news under standard editorial terms. Public URLs reported at each milestone.
-
“Safe After Bybit” definitive retrospective and forward-looking reference. Anchor piece (4,000-6,000 words). Timeline of the Bybit Lazarus heist (Safe{Wallet} developer machine compromised via social engineering, target-specific JavaScript injected into the AWS S3 bucket serving the frontend, the proxy upgrade signers approved while the UI displayed legitimate transaction data), what was NOT compromised (Safe smart contracts, source code), the response and recovery, the Safe hardening that followed and forward-looking lessons on frontend supply chain risk, transaction verification practice and operational multisig security for protocol teams. Published as the centerpiece of the engagement.
-
3 follow-up long-form investigations on Safe-stack security. Topics determined collaboratively at scope-planning sessions with Gnosis contributors. Suggested areas include:
-
Safe module security and module exploit patterns
-
Social engineering vectors targeting multisig signers (the Lazarus playbook and its variants)
-
Signing infrastructure as attack surface (TSS, hardware wallets, signer device security)
-
The operational-security gap between Safe-the-protocol and Safe-the-deployment-practice
-
-
6 distribution features across Rekt’s owned channels (newsletter ~30K subscribers + @RektHQ on X ~280K followers). Format at editorial discretion (newsletter feature, X thread or X mention with substantive context).
-
1 video documentary on multisig operational security. Published on YouTube and embedded on rekt.news.
-
1 podcast panel on a Safe-stack security topic, with relevant guests (white-hats, auditors, Safe contributors). Distributed via Spotify and YouTube. Recording archived on rekt.news.
-
Dedicated Safe security tag on hub.rekt.news with all relevant coverage organised and discoverable. Maintained through the 12 months.
Strategic partnership with TheDefiant (optional extension)
Rekt holds a strategic content partnership with TheDefiant (~327K followers on X, ~130K subscribers on YouTube), under which co-productions are distributed across both communities (example: Rekt News on X: "Can privacy and transparency coexist on a public blockchain? We investigated. With @DefiantNews, in partnership with @StellarOrg. Full documentary out now. https://t.co/RqlfzTQ2Fa https://t.co/NME08fEaZ4" / X). If Gnosis DAO sees value, we are open to reframing this proposal to include co-production of the video or podcast with TheDefiant for cross-community distribution materially beyond Rekt’s owned channels. Specifics negotiated based on community appetite.
Past work / Track record
Selected Rekt coverage of Safe, multisig and adjacent infrastructure, grouped by relevance.
Direct Safe and multisig coverage:
- “ByBit” (February 2025): Rekt - <!-- -->ByBit - Rekt — investigation of the $1.43B Lazarus heist via Safe{Wallet} frontend infrastructure compromise. Covers the malicious proxy upgrade signers approved while the UI displayed legitimate transaction data and the bounty program Bybit launched (10% of recovered funds, $140M cap). Foundation the “Safe After Bybit” retrospective builds on.
Admin key, signer compromise patterns and signing infrastructure (multisig threat modeling):
-
“Drift Protocol - Rekt” (April 2026): Rekt - <!-- -->Drift Protocol - Rekt — $285M DPRK social engineering compromise on the Solana perpetuals platform; six-month operation where attackers built trust through conferences and proxies before reaching the signers. Precedent for social-engineering threats to multisig signing groups.
-
“Wasabi Protocol - Rekt” (April 2026): Rekt - <!-- -->Wasabi Protocol - Rekt — $4.55M admin key compromise across four chains on the Wasabi perpetuals platform. The deployer EOA held the sole ADMIN_ROLE; the attacker used grantRole with zero delay, then UUPS-upgraded the perp vaults to malicious implementations. Cautionary case for protocols bypassing multisig governance and timelocks.
-
“Resolv Labs - Rekt” (March 2026): Rekt - <!-- -->Resolv Labs - Rekt — $25M loss after a compromised private key handed an attacker unlimited USR minting power. No oracle check, no mint cap. Supply chain compromise plus single-key admin design.
-
“THORChain - Rekt III” (May 2026): Rekt - <!-- -->THORChain - Rekt III — $10.7M GG20 TSS signing stack compromise. A malicious node operator exploited an implementation flaw to leak partial key material across signing ceremonies and reconstruct the full vault private key offline. Signing infrastructure as attack surface.
-
“Volo - Rekt” (April 2026): Rekt - <!-- -->Volo - Rekt — $3.5M Sui admin key compromise across three vaults (WBTC, XAUm, USDC), likely via social engineering. Volo self-disclosed first and recovered nearly all of it for a net loss of ~$60K. Reference for a positive response playbook.
Pre-mortem capability (broader DeFi infrastructure):
- “House of Cards” (October 2025): Rekt - <!-- -->House Of Cards — pre-mortem on Stream Finance / Elixir recursive minting, published weeks before the $93M xUSD collapse and the resulting $285M contagion across DeFi lending and DEX infrastructure.
Broader track record: 280K X followers, 30K+ newsletter, 42K monthly readers. Routinely cited by audit firms, governance forums and security researchers. Over 100 long-form post-mortems published in the last 12 months covering incidents totalling billions in user losses.
Rekt Security Summit Cannes 2026: https://summit.rekt.news/
Budget
40,000 USDC total, disbursed in four equal quarterly tranches of 10,000 USDC against verified delivery of milestones.
-
T0 (signing) — 10,000 USDC. Triggered by Snapshot pass and signed agreement.
-
T1 (month 3) — 10,000 USDC. Triggered by: Safe security tag live on hub.rekt.news with at least 3 indexed pieces; first follow-up long-form published; 2 distribution features published.
-
T2 (month 6) — 10,000 USDC. Triggered by: “Safe After Bybit” retrospective published; 2 follow-up long-forms total; podcast panel published; 4 distribution features total.
-
T3 (month 12) — 10,000 USDC. Triggered by: 3 follow-up long-forms total complete; video documentary published; 6 distribution features total.
Disbursement contingent on listed deliverables being publicly published. A Gnosis-designated multisig signer verifies existence at each tranche. No editorial review.
Audience math: Rekt’s 280K X followers, 30K newsletter subscribers and 42K monthly readers are mostly DeFi-native traders, allocators, governance participants and protocol contributors. Conservative reach over 12 months: 1M+ qualified impressions across X, newsletter, long-form, video and podcast. Sub-$40 CPM on a crypto-native qualified audience, for native editorial from an independent source. Paid newsletter and X placements in the same tier typically clear $30-100 CPM for ad-only, without the editorial production or credibility lift of independent coverage.
Funds transferred to a wallet controlled by Stake Capital Group, Switzerland.
Why USDC
USDC keeps the funding politically neutral. No price exposure to GNO during the work period, no perceived conflict in coverage of GNO-related events.
Reporting and accountability
-
Quarterly public reports on rekt.news listing all deliverables shipped against the milestones, with public URLs.
-
On-chain transparency: every tranche reported with receiving address and tx id.
-
Community accountability: if a substantive objection to a tranche is raised in the Gnosis governance forum or directly to the multisig signers, release is paused pending review.
-
End-of-partnership retrospective at month 12: public write-up of what worked, what didn’t and what we recommend Gnosis (and other DAOs) do differently in similar future partnerships.
What this is not
This proposal funds educational content, not promotion. This is not paid for favorable coverage. This is not a content partnership where Gnosis or Safe has approval rights over framing, conclusions or coverage of security incidents. This is not a retainer.
Discussion
We are posting this as pre-GIP discussion. Two weeks of community feedback. Welcome input on:
-
Scope of the “Safe After Bybit” anchor retrospective: are there specific angles, individuals to interview or aspects the community wants prioritised?
-
Follow-up long-form topics: would the community weight any of the suggested areas (modules, social engineering, signing infrastructure, deployment practice) over others?
-
Anchor topic flexibility: if the community prefers to lead with Safe’s post-Bybit architecture and security improvements rather than the Bybit reference point, we are open to that pivot — scope and budget unchanged.
-
Topics Gnosis/Safe consider leadership: are there areas where Gnosis DAO or Safe contributors believe they have built something the ecosystem should understand better — module security, multi-chain deployment practices, account abstraction security — where independent coverage and distribution would add value? We will go where the community sees the most value.
-
Vehicle: is Gnosis DAO via GIP the right route, or would Gnosis Ltd. be more appropriate?
-
Podcast panel guest invitation list (white-hats, auditors, Safe contributors)
-
TheDefiant integration: would the community see value in extending the proposal to include co-production with TheDefiant for the video, the podcast or additional formats, with cross-community distribution? If so, we will return with a revised scope.
We will iterate based on substantive feedback and move to formal GIP and Snapshot vote if there is community support.
Submitted by: Stake Capital Group. Julien Bouteloup, Founder of Rekt News and CEO of Stake Capital Group. Working contact for clarifications: Diogo Patão, Operations, diogo@rekt.news. Institutional contact: governance@stake.capital.