Plain answers about Digibastion: where incident data comes from, how severity and duplicates work, how to get alerts and what is free.
What is Digibastion? Digibastion is a free Web3 security site. It tracks crypto hacks, exploits and phishing from QuillMonitor and other public trackers, links every record to its source, and sends alerts by email and on Telegram. It also has security checklists, a two-minute OpSec self-check and practical guides. Teams that need more can hire Digibastion for OpSec consulting or a full-stack security review, or try Vantage (beta) to check their domain's security.
What is Digibastion Threat Intel? A free feed of crypto and Web3 security incidents (hacks, exploits, phishing, supply-chain attacks) and security news. Each incident has one record, even when several trackers report it, and every record names and links its source.
Where do the incidents come from? QuillMonitor, checked every 30 minutes; Web3 Is Going Just Great, every 6 hours; and security news sites such as The Hacker News, BleepingComputer and CISA, every hour. The methodology page lists every source.
Does Digibastion verify incidents? No. Digibastion shows the status the source gives. QuillMonitor marks incidents confirmed or unconfirmed; the other sources do not publish a status.
How do I get alerts? Join @digibastion on Telegram for new Web3 incidents from QuillMonitor, or subscribe by email for alerts on critical and high incidents, checked every 30 minutes. The daily brief and weekly deep-dive emails start soon; the weekly report is already published on the site every Monday.
How is severity set? Mostly by reported loss: $50M or more is critical and $10M or more is high. Private-key compromise, access-control flaws, oracle manipulation, reentrancy and flash-loan attacks are rated high even when no loss is disclosed. Any other disclosed loss is medium, and the rest are low. Security news uses the publisher's own rating.
What happens when two trackers report the same hack? Digibastion keeps one record and lists both sources. It merges only on a strong match: the same project name on the same day, or within two days plus one more matching fact such as the loss. It never merges records just because the names look alike, because a wrong merge would hide a real incident.
Is it free? Yes. The feed, alerts, checklists, self-check and guides are free and need no account. OpSec consulting and security reviews are paid.
What is the OpSec self-check? Eight questions drawn from 20 real scenarios. It takes about two minutes, shows where your habits are weak and what to fix first, and needs no wallet or account.
How do I report a mistake? Email support@digibastion.com with the record's link, or open an issue on GitHub. The methodology page explains how corrections work.