The attacker has been attributed. The money may never come back. LayerZero says North Korea's Lazarus Group, the same actors behind the $285M Drift exploit three weeks earlier. KelpDAO and LayerZero now blame each other for the configuration. The bigger truth: you can't sanction a smart contract or extradite a wallet.
Read the Article →One transaction. Forty-six minutes. $292M gone. The ensuing panic wiped $13B in the next 48 hours. DeFi has yet to demonstrate the control maturity of a regulated institution. The solution is not complicated. What is missing is the will to prioritise cybersecurity and governance over speed to market.
Read the Article →Credentials are still scattered across developer machines, build pipelines, configuration files, and AI agent directories. Unaudited, unrotated, and unprotected. This article reflects my first-hand experience. Root cause, real exposure, and a practical path forward, for both leadership and engineering teams. And it makes the case for a board-and-management mandate on credential security management even more urgent.
Read the Article →What Every Board Must Prioritise About Autonomous AI Agents Executive Summary TL;DR – Autonomous AI agents are operating within organisations today, and a landmark 2026 study shows they…
Read the Article →A fictional 2029, a real Q-Day. Not a single account hacked. Not one key cracked. Sinasia Financial Group was asked a question it could not answer. The suspension cost millions. The memo had warned them three years earlier. The board deferred. Q-Day is not a technical event. It is a trust event. With thanks to Marin Ivezic, whose framing reshaped how I see this threat.
Read the Article →Your AI is already hacked. You just haven't found the breach yet. Three real incidents from Perplexity, McKinsey, and an AI recruiter, and one fictional X thread that feels more like prophecy. Together they reveal the same uncomfortable truth: the industry's rush to deploy AI has outpaced its commitment to securing it. Six things boards and senior leaders must do differently.
Read the Article →DeepSeek V4 is expected to launch any time now, before China's Two Sessions in 2026. It is open source, a benefit none of its competitors can match. For regulated sectors where data sovereignty matters, this is the first frontier AI that enterprises can download and run on their own servers, with data never leaving their premises. An advisory brief for boards and management teams before it launches.
Read the Article →When Anthropic launched Claude Code Security last week, cyber stocks fell sharply. The narrative that followed was predictable. This analysis looks beyond the market noise — at what the shift means for CrowdStrike, Okta, SailPoint, Zscaler, Wiz, and others, and how technology and security leaders should think about their vendor landscape in 2026.
Read the Article →Seventeen years after the first Bitcoin block, the conversation is no longer centralised versus decentralised. It is how they converge. DeFi, stablecoins, tokenised real-world assets, CBDCs, instant payment rails, AI, and quantum are not separate stories. They are one architecture taking shape. A practitioner's view on how this evolved since 2009, and what it means for leaders today.
Read the Article →Earlier this month I passed the IAPP's AI Governance Professional (AIGP) certification exam. Preparation deepened both my understanding of AI governance and my commitment to its responsible use. This piece shares my top five go-to resources on AI — the people and institutions whose work has shaped how I think about the field.
Read the Article →The blockchain immortalises the hash and metadata. But the actual NFT lives on a centralised marketplace's servers. If the marketplace disappears, what remains is an orphan: a record on the chain pointing to an asset that no longer exists in the real world. After Axie, Terra Luna, Polygon, and Three Arrows, the possibility of marketplace failure is not far-fetched. So why is decentralised storage still not the norm?
Read the Article →The privacy coin Verge has just been hit by a 51% attack for the second time in a month, with $1.75M and $1.1M stolen on consecutive occasions. Look closely and it is not a 51% attack in the traditional sense. It is a time-warp exploit, made possible by the same recurring failure: coding shortcuts that traded resilience for speed.
Read the Article →Subscribers to the Grey Orbits Briefing receive each new article the day it publishes, direct to their inbox or LinkedIn feed.
Long-form analysis on artificial intelligence, cybersecurity, digital currencies, and post-quantum cryptography. Written for boards, investors, and senior leadership. No promotional material.
Prefer LinkedIn?
Subscribe to Briefing on LinkedInBoard engagements, advisory mandates, and education programmes.