web3radar · a cybersecurity offering by Stakecito
About web3radar
web3radar is a security-incident intelligence dashboard built and maintained by Stakecito, the validator infrastructure operator. It is currently in beta: coverage is expanding and data is best-effort. A public, free, machine-readable record of on-chain security incidents across the chains Stakecito monitors.
What this is
web3radar is an editorial-driven incident database for major blockchain ecosystems. We ingest public reports, normalise them into a stable schema, and a human reviewer verifies and publishes each record. The dataset is queryable through this site and the public API.
Methodology
- Automated ingestion runs every 15 minutes and pulls structured records from public sources. Records land in the editorial review queue, never directly on the public site.
- A reviewer reads the source material, fills in fields the upstream feed lacks, authors a plain-English summary, and only then promotes the incident to PUBLISHED.
- Every published incident shows the reviewer's name and the date of verification.
- Attribution language is intentional. We say alleged, attributed to, or according to [source] when attribution is uncertain. Incidents may be updated as investigations progress.
- If sources conflict, we surface the disagreement rather than collapse it.
Sources
Primary sources include public hack feeds (DefiLlama), post-mortems published by affected protocols, security firm research (e.g. SlowMist, PeckShield, OpenZeppelin), and reputable industry reporting. Every published incident lists its sources on the incident page. If a source is not cited, the incident is not published.
Coverage limitations
Coverage is uneven across chains. Ethereum and large L2s have years of public reporting; newer Cosmos appchains, Bitcoin smart-contract layers, and emerging L1s often have thinner public records. We surface this honestly on chain pages with a Monitored — Limited Data indicator and a date for when monitoring began.
Coverage is not — and cannot be — exhaustive. Many private exploits go unreported, and attribution is sometimes contested. Use this dataset as a starting point, not a final word.
Report an inaccuracy
If you spot incorrect attribution, a missing source, or an incident we have wrong, email contact@web3radar.invalid with the incident URL and what should change. We will respond and update or retract the record. Retraction reasons are stored and visible.
Disclaimer
Incident details are sourced from public reports and may be updated as investigations progress. Nothing on this site is legal, financial, or investment advice. We make no guarantee of completeness or accuracy.