{
  "schema_version": "2",
  "oak_version": "0.7.0",
  "generated_at": "2026-08-28T09:21:17+00:00",
  "tactics": [
    {
      "id": "OAK-T1",
      "name": "Token Genesis",
      "phase": "Pre-launch / Launch",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T1.001",
        "OAK-T1.002",
        "OAK-T1.003",
        "OAK-T1.004",
        "OAK-T1.005",
        "OAK-T1.006",
        "OAK-T1.007"
      ],
      "source_file": "tactics/T1-token-genesis.md"
    },
    {
      "id": "OAK-T10",
      "name": "Bridge and Cross-Chain",
      "phase": "Targeted compromise",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T10.001",
        "OAK-T10.002",
        "OAK-T10.002.001",
        "OAK-T10.003",
        "OAK-T10.004",
        "OAK-T10.005",
        "OAK-T10.006",
        "OAK-T10.007",
        "OAK-T10.008",
        "OAK-T10.009"
      ],
      "source_file": "tactics/T10-bridge-and-cross-chain.md"
    },
    {
      "id": "OAK-T11",
      "name": "Custody and Signing Infrastructure",
      "phase": "Targeted compromise",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T11.003",
        "OAK-T11.004",
        "OAK-T11.005",
        "OAK-T11.005.001",
        "OAK-T11.005.002",
        "OAK-T11.005.003",
        "OAK-T11.006",
        "OAK-T11.006.001",
        "OAK-T11.006.002",
        "OAK-T11.007",
        "OAK-T11.007.001",
        "OAK-T11.007.002",
        "OAK-T11.007.003",
        "OAK-T11.008",
        "OAK-T11.009",
        "OAK-T11.010",
        "OAK-T11.011",
        "OAK-T11.012",
        "OAK-T11.013"
      ],
      "source_file": "tactics/T11-custody-and-signing-infrastructure.md"
    },
    {
      "id": "OAK-T12",
      "name": "NFT-Specific Patterns",
      "phase": "Realization",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T12.001",
        "OAK-T12.002",
        "OAK-T12.003",
        "OAK-T12.004",
        "OAK-T12.005",
        "OAK-T12.006",
        "OAK-T12.007",
        "OAK-T12.008"
      ],
      "source_file": "tactics/T12-nft-specific-patterns.md"
    },
    {
      "id": "OAK-T13",
      "name": "Account Abstraction Attacks",
      "phase": "Targeted compromise",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T13.001",
        "OAK-T13.001.001",
        "OAK-T13.001.002",
        "OAK-T13.001.003",
        "OAK-T13.001.004",
        "OAK-T13.002",
        "OAK-T13.003",
        "OAK-T13.004"
      ],
      "source_file": "tactics/T13-account-abstraction-attacks.md"
    },
    {
      "id": "OAK-T14",
      "name": "Validator / Staking / Restaking Attacks",
      "phase": "Targeted compromise",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T14.001",
        "OAK-T14.002",
        "OAK-T14.003",
        "OAK-T14.003.001",
        "OAK-T14.004",
        "OAK-T14.005",
        "OAK-T14.006"
      ],
      "source_file": "tactics/T14-validator-staking-restaking-attacks.md"
    },
    {
      "id": "OAK-T15",
      "name": "Off-chain Entry-Vector / Pre-Positioning",
      "phase": "Pre-positioning",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T15.001",
        "OAK-T15.002",
        "OAK-T15.003",
        "OAK-T15.004",
        "OAK-T15.005",
        "OAK-T15.006"
      ],
      "source_file": "tactics/T15-off-chain-entry-vector.md"
    },
    {
      "id": "OAK-T16",
      "name": "Governance / Voting Manipulation",
      "phase": "Realization",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T16.001",
        "OAK-T16.002",
        "OAK-T16.003",
        "OAK-T16.004",
        "OAK-T16.005",
        "OAK-T16.006"
      ],
      "source_file": "tactics/T16-governance-voting-manipulation.md"
    },
    {
      "id": "OAK-T17",
      "name": "Market Manipulation",
      "phase": "Realization",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T17.001",
        "OAK-T17.002",
        "OAK-T17.003",
        "OAK-T17.004",
        "OAK-T17.005"
      ],
      "source_file": "tactics/T17-market-manipulation.md"
    },
    {
      "id": "OAK-T2",
      "name": "Liquidity Establishment",
      "phase": "Pre-launch / Launch",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T2.001",
        "OAK-T2.002",
        "OAK-T2.003",
        "OAK-T2.004",
        "OAK-T2.005"
      ],
      "source_file": "tactics/T2-liquidity-establishment.md"
    },
    {
      "id": "OAK-T3",
      "name": "Holder Capture",
      "phase": "Pre-launch / Launch",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T3.001",
        "OAK-T3.002",
        "OAK-T3.003",
        "OAK-T3.004",
        "OAK-T3.005",
        "OAK-T3.006"
      ],
      "source_file": "tactics/T3-holder-capture.md"
    },
    {
      "id": "OAK-T4",
      "name": "Access Acquisition",
      "phase": "Targeted compromise",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T4.001",
        "OAK-T4.002",
        "OAK-T4.003",
        "OAK-T4.004",
        "OAK-T4.005",
        "OAK-T4.006",
        "OAK-T4.007",
        "OAK-T4.008",
        "OAK-T4.009",
        "OAK-T4.010",
        "OAK-T4.011",
        "OAK-T4.012",
        "OAK-T4.013"
      ],
      "source_file": "tactics/T4-access-acquisition.md"
    },
    {
      "id": "OAK-T5",
      "name": "Value Extraction",
      "phase": "Realization",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T5.001",
        "OAK-T5.002",
        "OAK-T5.003",
        "OAK-T5.004",
        "OAK-T5.005",
        "OAK-T5.006",
        "OAK-T5.007",
        "OAK-T5.008",
        "OAK-T5.009"
      ],
      "source_file": "tactics/T5-value-extraction.md"
    },
    {
      "id": "OAK-T6",
      "name": "Defense Evasion",
      "phase": "Cross-cutting",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T6.001",
        "OAK-T6.002",
        "OAK-T6.003",
        "OAK-T6.004",
        "OAK-T6.005",
        "OAK-T6.006",
        "OAK-T6.007",
        "OAK-T6.008"
      ],
      "source_file": "tactics/T6-defense-evasion.md"
    },
    {
      "id": "OAK-T7",
      "name": "Laundering",
      "phase": "Post-extraction",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T7.003",
        "OAK-T7.004",
        "OAK-T7.005",
        "OAK-T7.006",
        "OAK-T7.007",
        "OAK-T7.008",
        "OAK-T7.009",
        "OAK-T7.010"
      ],
      "source_file": "tactics/T7-laundering.md"
    },
    {
      "id": "OAK-T8",
      "name": "Operator Continuity / Attribution Signals",
      "phase": "Post-extraction",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T8.001",
        "OAK-T8.002",
        "OAK-T8.003",
        "OAK-T8.004",
        "OAK-T8.005"
      ],
      "source_file": "tactics/T8-operational-reuse.md"
    },
    {
      "id": "OAK-T9",
      "name": "Smart-Contract Exploit",
      "phase": "Realization",
      "adjacent_tactics": [],
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.002",
        "OAK-T9.003",
        "OAK-T9.004",
        "OAK-T9.005",
        "OAK-T9.006",
        "OAK-T9.006.001",
        "OAK-T9.006.002",
        "OAK-T9.006.003",
        "OAK-T9.006.004",
        "OAK-T9.006.005",
        "OAK-T9.007",
        "OAK-T9.008",
        "OAK-T9.009",
        "OAK-T9.010",
        "OAK-T9.011",
        "OAK-T9.012",
        "OAK-T9.013",
        "OAK-T9.014",
        "OAK-T9.015"
      ],
      "source_file": "tactics/T9-smart-contract-exploit.md"
    }
  ],
  "techniques": [
    {
      "id": "OAK-T1.001",
      "name": "Modifiable Tax Function",
      "parent_tactics": [
        "OAK-T1",
        "OAK-T6"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana"
      ],
      "first_documented": "2018 (academic), widespread by 2020",
      "aliases": [
        "honeypot tax",
        "trap tax",
        "anti-sell tax",
        "tax trap"
      ],
      "citations": [
        "chainalysis2025rug",
        "cointelegraphanubismixer2022",
        "decryptanubis2021",
        "quillauditsbackdoor",
        "slowmist2024report",
        "torres2019",
        "trmsquid2021"
      ],
      "source_file": "techniques/T1.001-modifiable-tax-function.md"
    },
    {
      "id": "OAK-T1.002",
      "name": "Token-2022 Permanent Delegate Authority",
      "parent_tactics": [
        "OAK-T1",
        "OAK-T6"
      ],
      "maturity": "observed",
      "chains": [
        "Solana"
      ],
      "first_documented": "2024 (industry advisories); industrial-scale abuse from late 2024 onward",
      "aliases": [
        "permanent delegate token",
        "PD authority",
        "burn-on-buy scam"
      ],
      "citations": [
        "neodyme2024token2022",
        "solana2024permdelegate"
      ],
      "source_file": "techniques/T1.002-token-2022-permanent-delegate.md"
    },
    {
      "id": "OAK-T1.003",
      "name": "Renounced-But-Not-Really (Proxy-Upgrade Backdoor)",
      "parent_tactics": [
        "OAK-T1",
        "OAK-T6"
      ],
      "maturity": "stable",
      "chains": [
        "EVM (primary)"
      ],
      "first_documented": "systematic 2022 onward; Shido 2024 as a canonical large-scale named case",
      "aliases": [
        "fake renounce",
        "proxy backdoor",
        "ghost owner",
        "transferOwnership-not-really"
      ],
      "citations": [
        "chainalysis2025rug",
        "nomicproxybackdoor",
        "quillauditsbackdoor",
        "slowmist2024report"
      ],
      "source_file": "techniques/T1.003-renounced-but-not-really.md"
    },
    {
      "id": "OAK-T1.004",
      "name": "Blacklist / Pausable Transfer Weaponization",
      "parent_tactics": [
        "OAK-T1",
        "OAK-T6"
      ],
      "maturity": "stable",
      "chains": [
        "EVM (primary)"
      ],
      "first_documented": "widespread from approximately 2020 onward",
      "aliases": [
        "blacklist scam",
        "pausable token",
        "anti-sell pausable",
        "selective-block transfer",
        "freeze-on-buy"
      ],
      "citations": [
        "chainalysis2025rug",
        "ofac2022tornado",
        "quillauditsbackdoor",
        "slowmist2024report"
      ],
      "source_file": "techniques/T1.004-blacklist-pausable-weaponization.md"
    },
    {
      "id": "OAK-T1.005",
      "name": "Hidden Fee-on-Transfer",
      "parent_tactics": [
        "OAK-T1",
        "OAK-T6"
      ],
      "maturity": "stable",
      "chains": [
        "EVM (primary)",
        "Solana (SPL via Token-2022 transfer-fee extension; secondary)"
      ],
      "first_documented": "widespread from approximately 2020 onward",
      "aliases": [
        "sell tax",
        "anti-bot tax",
        "asymmetric fee",
        "router-only fee",
        "honeypot-lite",
        "conditional fee-on-transfer"
      ],
      "citations": [
        "chainalysis2025rug",
        "quillauditsbackdoor",
        "slowmist2024report"
      ],
      "source_file": "techniques/T1.005-hidden-fee-on-transfer.md"
    },
    {
      "id": "OAK-T1.006",
      "name": "Honeypot-by-Design",
      "parent_tactics": [
        "OAK-T1"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (BNB Chain dominant by deployment count; Base, Ethereum); cross-chain"
      ],
      "first_documented": "academic foundational reference 2019 (`[torres2019]`); industrial-scale cohort observable from 2023 onward; canonical 2024-Q4 cross-chain prevalence",
      "aliases": [
        "honeypot token",
        "buy-only token",
        "cannot-sell token",
        "sell-blocking smart contract",
        "asymmetric-fee honeypot"
      ],
      "citations": [
        "certikhoneypotproliferation",
        "chainalysis2025rug",
        "cryptorankhoneypotbase2025",
        "dipprofithoneypot2024",
        "goplusq42024honeypot",
        "hackenhoneypotscam",
        "mediumsnibbb2023",
        "slowmist2024report",
        "torres2019"
      ],
      "source_file": "techniques/T1.006-honeypot-by-design.md"
    },
    {
      "id": "OAK-T1.007",
      "name": "Token-2022 Transfer-Hook Abuse",
      "parent_tactics": [
        "OAK-T1",
        "OAK-T6"
      ],
      "maturity": "emerging",
      "chains": [
        "Solana (SPL Token-2022); cross-standard analogues on EVM (ERC-777 `tokensReceived`, ERC-1363 transfer-and-call, ERC-4626 vault hooks) covered separately at OAK-T9.005"
      ],
      "first_documented": "Halborn pre-production audit of Token-2022 (November 2022); class-level developer-side documentation 2023–2025; April 2025 ZK-ElGamal proof zero-day disclosure-and-patch cycle. Per-incident externally-attributed-exploit anchor remains empty at v0.1 freeze.",
      "aliases": [
        "transfer-hook callback abuse",
        "Token-2022 hook reentrancy",
        "SPL transfer-hook attack"
      ],
      "citations": [
        "ackeesolanahandbook",
        "chainstacktransferhook",
        "coindesksolanatoken2022zk2025",
        "cryptonomistsolanatoken2022zk2025",
        "cryptoslatesolanatoken2022zk2025",
        "dailycoinsolanatoken2022zk2025",
        "devtosolanahooks2025",
        "halbornsolanatokenception2022",
        "neodyme2024token2022",
        "quicknodetransferhook",
        "rareskillstoken2022",
        "solanatransferhookguide"
      ],
      "source_file": "techniques/T1.007-token-2022-transfer-hook-abuse.md"
    },
    {
      "id": "OAK-T10.001",
      "name": "Validator / Signer Key Compromise",
      "parent_tactics": [
        "OAK-T10"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "cross-chain"
      ],
      "first_documented": "2022 (Ronin canonical case)",
      "aliases": [
        "validator key theft",
        "multisig compromise",
        "MPC key loss"
      ],
      "citations": [
        "chainalysis2024dprk",
        "ellipticronin2022"
      ],
      "source_file": "techniques/T10.001-validator-signer-key-compromise.md"
    },
    {
      "id": "OAK-T10.002",
      "name": "Message-Verification Bypass",
      "parent_tactics": [
        "OAK-T10"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana",
        "cross-chain"
      ],
      "first_documented": "2022 (Wormhole, Nomad canonical cases)",
      "aliases": [
        "bridge proof bypass",
        "message-validation flaw",
        "VAA forgery\" (Wormhole-specific)"
      ],
      "citations": [
        "mandiantnomad2022"
      ],
      "source_file": "techniques/T10.002-message-verification-bypass.md"
    },
    {
      "id": "OAK-T10.002.001",
      "name": "Off-chain Observer Source-Event Forgery",
      "parent_tactics": [
        "OAK-T10",
        "OAK-T1"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (anchors on Solana → 18 destination chains, and XRP Ledger → Coreum)"
      ],
      "first_documented": "2026-07-17 (Across / Risk Labs on Solana); promoted on the second independent anchor, 2026-08-09 (Coreum–XRPL bridge)",
      "aliases": [
        "relayer event forgery",
        "fake deposit signal",
        "off-chain deposit-event forgery",
        "filler/solver event-parse bug",
        "indexer-grade code with contract-grade authority"
      ],
      "citations": [],
      "source_file": "techniques/T10.002.001-off-chain-observer-source-event-forgery.md"
    },
    {
      "id": "OAK-T10.003",
      "name": "Cross-Chain Replay",
      "parent_tactics": [
        "OAK-T10"
      ],
      "maturity": "observed",
      "chains": [
        "EVM",
        "cross-chain"
      ],
      "first_documented": "2022 (concept characterised in academic literature; recurring across smaller incidents)",
      "aliases": [
        "bridge replay attack",
        "chain-ID replay",
        "message-replay across chains"
      ],
      "citations": [
        "zhou2023sok"
      ],
      "source_file": "techniques/T10.003-cross-chain-replay.md"
    },
    {
      "id": "OAK-T10.004",
      "name": "Optimistic-Bridge Fraud-Proof Gap",
      "parent_tactics": [
        "OAK-T10"
      ],
      "maturity": "observed",
      "chains": [
        "EVM",
        "cross-chain (any optimistic-message-verification or optimistic-rollup-bridged architecture)"
      ],
      "first_documented": "2022 (concept characterised in Connext / Nomad architecture write-ups; recurring as architecture-review finding)",
      "aliases": [
        "watcher-liveness failure",
        "challenge-window inadequacy",
        "fraud-proof system gap",
        "1-of-N honest-verifier assumption failure"
      ],
      "citations": [
        "bhuptanioptbridges2022",
        "halbornnomadoptimistic2022",
        "hollowvictory2025",
        "owaspscstop10",
        "zhou2023sok"
      ],
      "source_file": "techniques/T10.004-optimistic-bridge-fraud-proof-gap.md"
    },
    {
      "id": "OAK-T10.005",
      "name": "Light-Client Verification Bypass",
      "parent_tactics": [
        "OAK-T10"
      ],
      "maturity": "observed",
      "chains": [
        "EVM",
        "Cosmos / IBC",
        "Bitcoin SPV consumers",
        "cross-chain (any bridge whose security reduces to a cryptographic light-client or proof-verification primitive)"
      ],
      "first_documented": "2022 (Verichains \"Dragonberry\" disclosure of an ICS-23 Merkle-proof soundness bug affecting IBC light-client verification across Cosmos-SDK chains; class characterised earlier in zk-bridge academic literature)",
      "aliases": [
        "circuit soundness bug",
        "trusted-setup compromise",
        "proof-system bypass",
        "light-client verifier bug",
        "zk-bridge soundness failure"
      ],
      "citations": [
        "owaspscstop10",
        "soksnarkvulns2024",
        "verichainsdragonberry2022",
        "xie2022zkbridge",
        "zhou2023sok",
        "zkbugtracker"
      ],
      "source_file": "techniques/T10.005-light-client-verification-bypass.md"
    },
    {
      "id": "OAK-T10.006",
      "name": "Cross-Chain Governance Relay Attack",
      "parent_tactics": [
        "OAK-T10"
      ],
      "maturity": "emerging",
      "chains": [
        "Cross-chain (any protocol stack where governance actions are relayed across chains via a message bridge — LayerZero, Wormhole, Chainlink CCIP, Hyperlane, Axelar); target chains typically EVM or EVM-compatible"
      ],
      "first_documented": "2023–2024 (class characterised in bridge-security literature; specific governance-bridge bypass incidents from 2024 onward)",
      "aliases": [
        "governance-bridge attack",
        "cross-chain governance hijack",
        "message-relay governance bypass",
        "governance-message forgery",
        "cross-chain proposal injection"
      ],
      "citations": [
        "owaspscstop10",
        "zhou2023sok"
      ],
      "source_file": "techniques/T10.006-cross-chain-governance-relay-attack.md"
    },
    {
      "id": "OAK-T10.007",
      "name": "Bridge Validator Economic-Incentive Misalignment",
      "parent_tactics": [
        "OAK-T10"
      ],
      "maturity": "emerging",
      "chains": [
        "Cross-chain (any bridge whose security model relies on a validator set bonded by economic stake — Ronin/Sky Mavis, Wormhole (pre-Guardian-set expansion), Axie Infinity bridge, Polygon PoS bridge, Ronin DPoS, any PoS-style validator bridge where the validator's stake is independent of the bridge's TVL)"
      ],
      "first_documented": "2022 (the Ronin bridge incident crystallised the class at operational scale, though the economic-misalignment framing predates it); the academic characterisation of validator-stake-vs-TVL misalignment as a structural bridge vulnerability class matured 2022–2024",
      "aliases": [
        "validator-stake TVL gap",
        "bridge validator bribe attack",
        "economic-security deficit",
        "stake-to-TVL ratio attack",
        "validator-profitability attack"
      ],
      "citations": [
        "ronin2022postmortem",
        "wormhole2022postmortem",
        "zhou2023sok"
      ],
      "source_file": "techniques/T10.007-bridge-validator-economic-incentive-misalignment.md"
    },
    {
      "id": "OAK-T10.008",
      "name": "Bridge Observer Signature Scope Truncation",
      "parent_tactics": [
        "OAK-T10"
      ],
      "maturity": "emerging",
      "chains": [
        "Cross-chain (any bridge or cross-chain protocol where a relayer/observer network signs observations of external chain events and the signed payload does not cover all semantically-meaningful wrapper fields — THORChain Bifrost, Chainlink CCIP, LayerZero, Wormhole, Axelar, any MPC-based bridge with observer-consensus architecture)"
      ],
      "first_documented": "2026-05-15 (THORChain Router exploit — Bifrost `GetSignablePayload()` truncation: inner `Tx` signed, `ObservedTx` wrapper direction flag unsigned, proposer flipped inbound→outbound to forge migration observation)",
      "aliases": [
        "observer signature scope attack",
        "unsigned wrapper field forgery",
        "Bifrost direction-bit attack",
        "relayer payload truncation",
        "incomplete payload signing"
      ],
      "citations": [
        "thorchain2026postmortem"
      ],
      "source_file": "techniques/T10.008-bridge-observer-signature-scope-truncation.md"
    },
    {
      "id": "OAK-T10.009",
      "name": "Cross-Chain Token Configuration-Role Capture",
      "parent_tactics": [
        "OAK-T10"
      ],
      "maturity": "emerging",
      "chains": [
        "Cross-chain (any omnichain-token standard that carries per-deployment configuration roles — LayerZero OFT `delegate` / `peer`, Wormhole NTT manager and transceiver roles, Chainlink CCIP token-pool administration, Hyperlane warp-route ownership); remote deployments are typically EVM"
      ],
      "first_documented": "2026-05 (Stake DAO vsdCRV OFT peer redirect); second independent anchor 2026-08 (The Sandbox SAND OFT delegate hijack)",
      "aliases": [
        "OFT delegate hijack",
        "OFT peer redirect",
        "omnichain token config takeover",
        "cross-chain token role capture",
        "bridge wiring compromise"
      ],
      "citations": [],
      "source_file": "techniques/T10.009-cross-chain-token-configuration-role-capture.md"
    },
    {
      "id": "OAK-T11.001",
      "name": "Third-Party Signing-Vendor UI / Signing-Flow Compromise",
      "parent_tactics": [
        "OAK-T11"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana",
        "cross-chain"
      ],
      "first_documented": "systematic 2022 onward; canonical large-scale case Bybit / Safe{Wallet} 2025-02",
      "aliases": [
        "signing-vendor UI compromise",
        "Safe{Wallet}-class supply-chain compromise",
        "UI-payload substitution at sign time"
      ],
      "citations": [
        "chainalysis2024dprk",
        "crystalwazirx2024",
        "wazirxwiki2024"
      ],
      "source_file": "techniques/T11.001-third-party-signing-vendor-compromise.md"
    },
    {
      "id": "OAK-T11.002",
      "name": "Wallet-Software Distribution Compromise",
      "parent_tactics": [
        "OAK-T11"
      ],
      "maturity": "stable",
      "chains": [
        "multi-chain (any chain the affected wallet supports)"
      ],
      "first_documented": "systematic 2023 onward; canonical case Atomic Wallet June 2023",
      "aliases": [
        "wallet supply-chain attack",
        "trojanised wallet update",
        "self-custodial wallet compromise"
      ],
      "citations": [
        "chainalysis2024dprk",
        "ellipticatomic2023"
      ],
      "source_file": "techniques/T11.002-wallet-software-distribution-compromise.md"
    },
    {
      "id": "OAK-T11.003",
      "name": "In-Use Multisig Smart-Contract Manipulation",
      "parent_tactics": [
        "OAK-T11",
        "OAK-T9"
      ],
      "maturity": "observed",
      "chains": [
        "EVM"
      ],
      "first_documented": "2024 (WazirX canonical case)",
      "aliases": [
        "multisig hijack",
        "in-flight multisig modification"
      ],
      "citations": [
        "chainalysis2024dprk",
        "crystalwazirx2024",
        "wazirxwiki2024"
      ],
      "source_file": "techniques/T11.003-multisig-contract-manipulation.md"
    },
    {
      "id": "OAK-T11.004",
      "name": "Insufficient-Entropy Key Generation",
      "parent_tactics": [
        "OAK-T11"
      ],
      "maturity": "stable",
      "chains": [
        "chain-agnostic (any ECDSA / EdDSA-curve chain whose end-user keys are produced by an off-chain generator); canonical anchors on Ethereum"
      ],
      "first_documented": "2022-09 (Profanity vanity-address generator public disclosure by 1inch); the structural class is older (Bitcoin \"RNG bug\" cohorts predate the canonical Ethereum case but are not the v0.1 anchor)",
      "aliases": [
        "weak-RNG key generation",
        "vanity-address entropy collapse",
        "Profanity-class private-key recovery",
        "32-bit-seed key recovery"
      ],
      "citations": [
        "cointelegraphprofanitycohort2022",
        "halbornprofanitytool2022",
        "halbornwintermute2022"
      ],
      "source_file": "techniques/T11.004-insufficient-entropy-key-generation.md"
    },
    {
      "id": "OAK-T11.005",
      "name": "Operator-side Fake-Platform Fraud",
      "parent_tactics": [
        "OAK-T11"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (deposit substrate is BTC / ETH / stablecoins on-chain; the fraud \"platform\" is off-chain operator-controlled UI/database)"
      ],
      "first_documented": "2014 (OneCoin) at the modern threshold; pre-pig-butchering-era (2014–2018) MLM-Ponzi cohort plus 2018-onward multi-asset-wallet Ponzi plus 2020-onward fake-CEX / pig-butchering cohort",
      "aliases": [
        "fake-CEX",
        "pig-butchering platform",
        "fake custodian",
        "investment-fraud platform",
        "MLM fake-cryptocurrency Ponzi",
        "rug platform"
      ],
      "citations": [
        "bbc2019cryptoqueenpodcast",
        "behindmlmonecoin",
        "chainalysis2025rug",
        "coindesk2026onecoinvictims",
        "doj2017ignatovaindictment",
        "doj2022greenwoodguiltyplea",
        "doj2023greenwoodsentencing",
        "fbi2022ignatovamostwanted",
        "state2024ignatovareward"
      ],
      "source_file": "techniques/T11.005-operator-side-fake-platform-fraud.md"
    },
    {
      "id": "OAK-T11.005.001",
      "name": "Fake-CEX / Pig-Butchering Platform",
      "parent_tactics": [
        "OAK-T11",
        "OAK-T1"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (deposit substrate is BTC / ETH / stablecoins on-chain; the fraud \"platform\" is off-chain operator-controlled UI/database)"
      ],
      "first_documented": "2018–2020 (pig-butchering model emergence); 2023 JPEX Hong Kong case as the highest-profile public enforcement action",
      "aliases": [
        "pig-butchering platform",
        "fake-CEX",
        "romance-scam investment platform",
        "Sha Zhu Pan",
        "BeurAx-class platform",
        "unlicensed-offshore-exchange fraud"
      ],
      "citations": [
        "chainalysis2025rug",
        "fbiic32024",
        "fincentra2023pigbutchering"
      ],
      "source_file": "techniques/T11.005.001-fake-cex-pig-butchering-platform.md"
    },
    {
      "id": "OAK-T11.005.002",
      "name": "Fake-Custodian / Fake-Asset-Manager Fraud",
      "parent_tactics": [
        "OAK-T11",
        "OAK-T1"
      ],
      "maturity": "observed",
      "chains": [
        "chain-agnostic (deposit substrate is BTC / ETH / stablecoins on-chain; the fraud \"platform\" is off-chain operator-controlled UI/database)"
      ],
      "first_documented": "2011 (Bitcoin Savings & Trust as the earliest structurally characterised case); 2018–2019 (PlusToken as the largest-value multi-asset wallet Ponzi); 2020-onward (HyperVerse / CryptoFX / Forsage / CoinDeal as the modern enforcement-record cohort)",
      "aliases": [
        "fake custodian",
        "fake asset manager",
        "MLM crypto Ponzi",
        "AI-trading Ponzi",
        "fake yield fund",
        "fake wealth-management platform",
        "multi-asset wallet Ponzi"
      ],
      "citations": [
        "dojhyperverse2024",
        "seccoindeal2023",
        "seccryptofx2024",
        "secforsage2022",
        "secvshavers2013"
      ],
      "source_file": "techniques/T11.005.002-fake-custodian-fake-asset-manager-fraud.md"
    },
    {
      "id": "OAK-T11.005.003",
      "name": "Compound-Operated Investment-Fraud Platforms",
      "parent_tactics": [
        "OAK-T11",
        "OAK-T1"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic; deposit substrate is BTC / ETH / stablecoins (USDT on Tron dominant); industrial-scale victim-acquisition infrastructure predominantly in Southeast Asia"
      ],
      "first_documented": "2020 (emergence of industrial-scale scam compounds); 2024 OFAC Ly Yong Phat / O-Smach Resort designation; 2025 DOJ Chen Zhi / Prince Group $15B Bitcoin forfeiture",
      "aliases": [
        "Southeast Asia scam compound",
        "forced-labour investment fraud",
        "industrial pig-butchering",
        "compound-operated fraud",
        "Cambodia/Myanmar scam compound"
      ],
      "citations": [
        "dojjune2025philippinescompound",
        "dojoctober2025chenzhi",
        "fincenoctober2025huione",
        "ofacseptember2024lyyongphat"
      ],
      "source_file": "techniques/T11.005.003-compound-operated-investment-fraud-platforms.md"
    },
    {
      "id": "OAK-T11.006",
      "name": "Cold-storage Seed-phrase Exfiltration at Rest",
      "parent_tactics": [
        "OAK-T11"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (the substrate-of-extraction is the BIP39 seed phrase / private key material itself; downstream extraction occurs across whichever chains the affected wallet holds)"
      ],
      "first_documented": "2022-04 (iCloud-backup MetaMask / Iacovone case) for the implicit-cloud-custody sub-pattern; 2022-12 (LastPass encrypted-vault exfiltration) for the user-initiated plaintext-storage sub-pattern; cohort window remains open at v0.1 reporting horizon",
      "aliases": [
        "seed-phrase at rest exfiltration",
        "password-manager seed-storage compromise",
        "iCloud-backup wallet drain",
        "third-party-storage seed-phrase compromise"
      ],
      "citations": [
        "bleepinglastpass2025",
        "cointelegraphlarsen2024",
        "hackernewslastpass2025",
        "infosecuritylastpass2023",
        "krebslastpass2023",
        "krebslastpass2025",
        "lastpassbreachdisclosure2022",
        "theblocklastpass2023",
        "trmlabslastpass2025",
        "zachxbtlastpass2023"
      ],
      "source_file": "techniques/T11.006-cold-storage-seed-phrase-exfiltration-at-rest.md"
    },
    {
      "id": "OAK-T11.006.001",
      "name": "User-Initiated Plaintext-Equivalent Seed Storage",
      "parent_tactics": [
        "OAK-T11",
        "OAK-T1"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (BIP39 seed phrase / private key material stored in third-party service; downstream extraction across all chains the affected wallet holds)"
      ],
      "first_documented": "2022-12 (LastPass encrypted-vault exfiltration → 2023–2025 multi-year crypto-drain cohort)",
      "aliases": [
        "password-manager seed storage compromise",
        "LastPass-class seed-phrase exfiltration",
        "plaintext-equivalent seed storage"
      ],
      "citations": [],
      "source_file": "techniques/T11.006.001-user-initiated-plaintext-seed-storage.md"
    },
    {
      "id": "OAK-T11.006.002",
      "name": "Implicit Cloud-Custody via Default-On Cloud-Backup",
      "parent_tactics": [
        "OAK-T11",
        "OAK-T1"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (wallet vault auto-backed-up to iCloud / Google Drive / OneDrive; downstream extraction across all chains the wallet supports)"
      ],
      "first_documented": "2022-04-15 (iCloud-backup MetaMask / Dominic Iacovone case, ~$650K)",
      "aliases": [
        "iCloud-backup wallet drain",
        "cloud-backup seed exfiltration",
        "default-on backup compromise",
        "iOS-backup wallet compromise"
      ],
      "citations": [],
      "source_file": "techniques/T11.006.002-implicit-cloud-custody-default-backup.md"
    },
    {
      "id": "OAK-T11.007",
      "name": "Hardware-wallet Supply-chain / Physical-access Compromise",
      "parent_tactics": [
        "OAK-T11"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (the substrate-of-extraction is the BIP39 seed phrase / hardware-wallet-controlled private-key material; downstream extraction occurs across whichever chains the affected wallet supports)"
      ],
      "first_documented": "2017 (early Ledger Nano S inserts cohort) at the cohort-shape layer; 2020-01-31 (Trezor One / Model T RDP-downgrade Kraken disclosure) for the physical-access capability anchor; 2025 counterfeit Ledger Nano S Plus cohort for the deployed-attack anchor; 2023–2026 fake-firmware-update / recovery-app phishing cohort for the active-phishing sub-pattern",
      "aliases": [
        "counterfeit hardware wallet",
        "fake Ledger / fake Trezor",
        "pre-seeded recovery card",
        "hardware-wallet phishing",
        "physical-access seed extraction"
      ],
      "citations": [],
      "source_file": "techniques/T11.007-hardware-wallet-supply-chain-physical-access-compromise.md"
    },
    {
      "id": "OAK-T11.007.001",
      "name": "Counterfeit-Hardware Substitution",
      "parent_tactics": [
        "OAK-T11",
        "OAK-T1"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (counterfeit device substitutes the legitimate hardware wallet; downstream extraction across all chains the affected wallet supports)"
      ],
      "first_documented": "2017 (early Ledger Nano S inserts cohort) at the cohort-shape layer; 2025 counterfeit Ledger Nano S Plus cohort for the deployed-attack anchor",
      "aliases": [
        "counterfeit hardware wallet",
        "fake Ledger / fake Trezor",
        "pre-seeded recovery card",
        "hardware-wallet supply-chain substitution"
      ],
      "citations": [],
      "source_file": "techniques/T11.007.001-counterfeit-hardware-substitution.md"
    },
    {
      "id": "OAK-T11.007.002",
      "name": "Physical-Access Hardware-Side Seed Extraction",
      "parent_tactics": [
        "OAK-T11",
        "OAK-T1"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (physical-access attack against the hardware wallet's microcontroller; downstream extraction across all chains the wallet supports)"
      ],
      "first_documented": "2020-01-31 (Trezor One / Model T RDP-downgrade voltage-glitch attack, Kraken Security Labs disclosure)",
      "aliases": [
        "voltage-glitch seed extraction",
        "side-channel hardware wallet attack",
        "RDP-downgrade attack",
        "chip-tampering seed extraction"
      ],
      "citations": [],
      "source_file": "techniques/T11.007.002-physical-access-hardware-seed-extraction.md"
    },
    {
      "id": "OAK-T11.007.003",
      "name": "Brand-Trust-Leveraged Active Phishing for Seed-Phrase Exfiltration",
      "parent_tactics": [
        "OAK-T11",
        "OAK-T1"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (phishing campaigns target hardware-wallet users across all chains their devices support)"
      ],
      "first_documented": "2020 (Ledger customer-data-breach-leveraged phishing onset); 2023 Kaspersky spring cohort (85,000+ scam emails in a single quarter); 2023 trojanised companion-app cohort",
      "aliases": [
        "fake firmware update phishing",
        "hardware-wallet recovery phishing",
        "brand-impersonation seed solicitation",
        "Ledger-data-breach-leveraged phishing"
      ],
      "citations": [],
      "source_file": "techniques/T11.007.003-brand-trust-active-phishing-seed-exfiltration.md"
    },
    {
      "id": "OAK-T11.008",
      "name": "Embedded-Wallet Identity-Provider Compromise",
      "parent_tactics": [
        "OAK-T11"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Polygon-resident Polymarket / Magic Labs canonical at v0.1; cross-chain analogues across Privy / Web3Auth / Dynamic deployments on Ethereum, Base, Arbitrum, Solana, others)"
      ],
      "first_documented": "2024-09 (Polymarket Magic-Labs takeover); cohort scale-out 2024–2026 across Polymarket-class platforms whose user onboarding runs through third-party email-auth / OAuth / MPC-social-login providers",
      "aliases": [
        "Magic Labs takeover",
        "Privy / Web3Auth / Dynamic compromise",
        "embedded-wallet auth-provider compromise",
        "email-magic-link wallet hijack",
        "social-login wallet drain"
      ],
      "citations": [],
      "source_file": "techniques/T11.008-embedded-wallet-identity-provider-compromise.md"
    },
    {
      "id": "OAK-T11.009",
      "name": "Trader-Tooling Supply-Chain Compromise targeting `.env` Private Keys",
      "parent_tactics": [
        "OAK-T11"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (the substrate-of-extraction is the developer-environment plaintext key file; downstream extraction occurs across whichever chains the bot operates on — Polygon, Solana, Ethereum, Base, Arbitrum, BNB Chain are all in scope across the cohort)"
      ],
      "first_documented": "2025-12 / 2026-01 (Polymarket trader-tooling supply-chain compromise via npm `polymarket-clob` and `dev-protocol` GitHub-org hijack); the broader cohort context spans 2024–2026 with overlapping infrastructure to DPRK-attributed BeaverTail / InvisibleFerret npm campaigns",
      "aliases": [
        "trader-bot npm supply-chain",
        "developer-environment .env exfiltration",
        "GitHub-org-hijack trojan-bot distribution",
        "wallet.json infostealer via package registry"
      ],
      "citations": [],
      "source_file": "techniques/T11.009-trader-tooling-supply-chain-env-key-compromise.md"
    },
    {
      "id": "OAK-T11.010",
      "name": "Off-chain Counterparty-Risk Insolvency",
      "parent_tactics": [
        "OAK-T11"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (deposit substrate is BTC / ETH / stablecoins on-chain; the failure mode is off-chain operator credit decision → counterparty default → customer-asset shortfall)"
      ],
      "first_documented": "2020-11-07 (Cred Inc. Chapter 11, D. Del. Case No. 20-12836)",
      "aliases": [
        "counterparty-risk insolvency",
        "yield-without-due-diligence failure",
        "custodial-lending default cascade",
        "CeFi yield-platform collapse",
        "re-lending concentration risk"
      ],
      "citations": [],
      "source_file": "techniques/T11.010-off-chain-counterparty-risk-insolvency.md"
    },
    {
      "id": "OAK-T11.011",
      "name": "Multi-chain Key-store Co-location",
      "parent_tactics": [
        "OAK-T11"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (the anti-pattern is an operator-side architectural decision, not a chain-specific vulnerability)"
      ],
      "first_documented": "2023-11-10 (Poloniex hot-wallet drain — simultaneous multi-chain extraction across ETH, TRX, BTTC, and others)",
      "aliases": [
        "multi-chain key co-location",
        "shared signing-infrastructure compromise",
        "cross-chain hot-wallet co-location",
        "single-point-of-compromise multi-chain extraction"
      ],
      "citations": [],
      "source_file": "techniques/T11.011-multi-chain-key-store-co-location.md"
    },
    {
      "id": "OAK-T11.012",
      "name": "Server-side Raw Private-Key Storage (Custodial Trading-Bot Anti-pattern)",
      "parent_tactics": [
        "OAK-T11"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (the anti-pattern is an operator-side architectural decision, not a chain-specific vulnerability)"
      ],
      "first_documented": "2024-09 (DEXX trading-bot platform cohort; the pattern predates DEXX but DEXX is the first cleanly-documented OAK worked example)",
      "aliases": [
        "custodial-private-key-storage anti-pattern",
        "server-side raw-key storage",
        "trading-bot key-storage compromise",
        "raw-private-key-holding platform"
      ],
      "citations": [],
      "source_file": "techniques/T11.012-server-side-raw-private-key-storage.md"
    },
    {
      "id": "OAK-T11.013",
      "name": "Legacy-Version Maintenance Attack Surface",
      "parent_tactics": [
        "OAK-T11"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (primary); structurally generalisable to any chain where protocol operators maintain multiple deployed versions"
      ],
      "first_documented": "2023-02 (Yearn V1 — structurally related but with a configuration-rot dimension); 2025-07 (GMX V1 — cleaner instance of the pure legacy-version-maintenance decision class)",
      "aliases": [
        "deprecated-version attack surface",
        "legacy-version residual vulnerability",
        "multi-version rollout security gap",
        "deprecation-without-decommission"
      ],
      "citations": [],
      "source_file": "techniques/T11.013-legacy-version-maintenance-attack-surface.md"
    },
    {
      "id": "OAK-T12.001",
      "name": "NFT Wash-Trade Volume Inflation",
      "parent_tactics": [
        "OAK-T12"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (primary; Ethereum / Polygon)",
        "Solana (Magic Eden, Tensor)"
      ],
      "first_documented": "2021–2022 (Chainalysis NFT retrospective; LooksRare incentive-wash episode)",
      "aliases": [
        "NFT volume wash",
        "collection-rank inflation",
        "floor-price wash",
        "marketplace-incentive wash"
      ],
      "citations": [
        "chainalysis2022nft",
        "chainalysis2025rug",
        "victor2021washtrade"
      ],
      "source_file": "techniques/T12.001-nft-wash-trade-volume-inflation.md"
    },
    {
      "id": "OAK-T12.002",
      "name": "Fake-Mint / Counterfeit Collection",
      "parent_tactics": [
        "OAK-T12"
      ],
      "maturity": "stable",
      "chains": [
        "EVM (primary; Ethereum / Polygon)",
        "Solana (Magic Eden cohort)"
      ],
      "first_documented": "2021 (early counterfeit cohort on OpenSea); industrial-scale through 2022 Discord-compromise wave",
      "aliases": [
        "fake mint",
        "counterfeit collection",
        "copymint",
        "spoofed collection",
        "impersonation drop"
      ],
      "citations": [
        "baycdiscord2022",
        "certikpremint2022",
        "chainalysis2022nft",
        "chainalysisnftcounterfeit2022",
        "fortunebaycjune2022",
        "magicedeny00ts2023",
        "openseamoderation2022",
        "theblock2022boredape"
      ],
      "source_file": "techniques/T12.002-fake-mint-counterfeit-collection.md"
    },
    {
      "id": "OAK-T12.003",
      "name": "Royalty Bypass / Marketplace Manipulation",
      "parent_tactics": [
        "OAK-T12"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (primary; Ethereum / Polygon / other ERC-721-bearing chains)"
      ],
      "first_documented": "2022 (Blur launch and the LooksRare / X2Y2 royalty-optional shift); structural problem ongoing",
      "aliases": [
        "royalty stripping",
        "royalty-optional trading",
        "marketplace royalty disregard"
      ],
      "citations": [
        "blurzeroroyalty2022",
        "chainalysis2022nft",
        "eip2981",
        "openseaoperatorfilter2022"
      ],
      "source_file": "techniques/T12.003-royalty-bypass-marketplace-manipulation.md"
    },
    {
      "id": "OAK-T12.004",
      "name": "Timelock-Free Protocol Upgrade Execution (DEPRECATED)",
      "parent_tactics": [],
      "maturity": "deprecated",
      "chains": [],
      "first_documented": "",
      "aliases": [],
      "citations": [],
      "source_file": "techniques/T12.004-timelock-free-protocol-upgrade-execution.md"
    },
    {
      "id": "OAK-T12.005",
      "name": "Flash-Loan Governance Vote Manipulation (DEPRECATED)",
      "parent_tactics": [],
      "maturity": "deprecated",
      "chains": [],
      "first_documented": "",
      "aliases": [],
      "citations": [],
      "source_file": "techniques/T12.005-flash-loan-governance-vote-manipulation.md"
    },
    {
      "id": "OAK-T12.006",
      "name": "NFT-Collateral Lending Manipulation",
      "parent_tactics": [
        "OAK-T12"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (primary — the NFT-lending population is overwhelmingly ERC-721 on Ethereum); structurally applicable to any chain with non-fungible collateral"
      ],
      "first_documented": "2022-06-27 (XCarnival, ~\\$3.8M); second independent anchor 2022-07-10 (Omni Protocol, ~\\$1.4M)",
      "aliases": [
        "NFT lending exploit",
        "NFT collateral drain",
        "NFT money-market exploit",
        "collateral-state desync",
        "pledge-order reuse"
      ],
      "citations": [],
      "source_file": "techniques/T12.006-nft-collateral-lending-manipulation.md"
    },
    {
      "id": "OAK-T12.007",
      "name": "Mint-Outcome Reroll (Revert-Until-Rare)",
      "parent_tactics": [
        "OAK-T12"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (primary — requires atomic same-transaction revelation and a revertable transaction); applicable to any chain whose transactions are atomic and whose mint outcome is readable before commitment"
      ],
      "first_documented": "2021-05-08 (Meebits / Larva Labs)",
      "aliases": [
        "revert-until-rare",
        "mint reroll",
        "rarity sniping at mint",
        "gacha reroll attack",
        "atomic mint filtering"
      ],
      "citations": [],
      "source_file": "techniques/T12.007-mint-outcome-reroll-revert-until-rare.md"
    },
    {
      "id": "OAK-T12.008",
      "name": "Hybrid Fungible / Non-Fungible Standard Accounting Divergence",
      "parent_tactics": [
        "OAK-T12"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (the ERC-404 / BT404 hybrid family and the NFT-fractionalisation population are overwhelmingly EVM)"
      ],
      "first_documented": "2026-06-08 (Flooring Protocol V2 / BitmapPunks)",
      "aliases": [
        "ERC-404 accounting bug",
        "BT404 packed-ownership flaw",
        "ghost ownership",
        "fractionalisation seam bug",
        "hybrid-token divergence"
      ],
      "citations": [],
      "source_file": "techniques/T12.008-hybrid-fungible-non-fungible-accounting-divergence.md"
    },
    {
      "id": "OAK-T13.001",
      "name": "Paymaster Compromise",
      "parent_tactics": [
        "OAK-T13"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (ERC-4337 EntryPoint v0.6 / v0.7 / v0.8 / v0.9 deployments); EVM L2s with native account abstraction (zkSync Era, Starknet) where the paymaster role is analogous; conceptually portable to any chain whose execution model separates gas-sponsorship validation from execution"
      ],
      "first_documented": "2023 (Alchemy / OpenZeppelin disclosure of the UserOperation packing inconsistency in EntryPoint v0.6 affecting `VerifyingPaymaster`); class characterised continuously through 2024–2026 in audit-firm advisories on deployed paymasters",
      "aliases": [
        "paymaster drain",
        "sponsorship policy bypass",
        "postOp griefing",
        "paymaster DoS",
        "validatePaymasterUserOp bypass",
        "gasless-transaction abuse"
      ],
      "citations": [
        "aviggiano4337checklist",
        "erc4337spec",
        "osecpaymasters2025",
        "ozaa4337audit",
        "tobsixmistakes2026"
      ],
      "source_file": "techniques/T13.001-paymaster-compromise.md"
    },
    {
      "id": "OAK-T13.001.001",
      "name": "Paymaster Accounting Drain",
      "parent_tactics": [
        "OAK-T13"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (ERC-4337 EntryPoint v0.6 / v0.7 / v0.8 / v0.9 deployments); EVM L2s with native account abstraction (zkSync Era, Starknet) where the paymaster role is analogous"
      ],
      "first_documented": "2025 (OSEC paymaster security review enumerates the `postOp` revert / gas-token-mechanic surfaces explicitly); class characterised continuously through audit-firm advisories on deployed paymasters",
      "aliases": [
        "paymaster drain",
        "postOp revert drain",
        "gas-token-mechanic accounting drain",
        "validation-time-debit not unwound"
      ],
      "citations": [
        "aviggiano4337checklist",
        "erc4337spec",
        "osecpaymasters2025",
        "ozaa4337audit",
        "tobsixmistakes2026"
      ],
      "source_file": "techniques/T13.001.001-paymaster-accounting-drain.md"
    },
    {
      "id": "OAK-T13.001.002",
      "name": "Paymaster Policy Bypass",
      "parent_tactics": [
        "OAK-T13"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (ERC-4337 EntryPoint v0.6 / v0.7 / v0.8 / v0.9 deployments); EVM L2s with native account abstraction; Solana (analogous fee-payer / Token-2022 paymaster surfaces — Kora advisory)"
      ],
      "first_documented": "2023 (Alchemy / OpenZeppelin disclosure of the UserOperation-packing inconsistency in EntryPoint v0.6 affecting `VerifyingPaymaster`); Solana / Token-2022 analogue documented 2025 (Kora paymaster advisory)",
      "aliases": [
        "sponsorship policy bypass",
        "validatePaymasterUserOp bypass",
        "off-chain-signer / on-chain-hash parity violation",
        "fail-open instruction parser"
      ],
      "citations": [
        "alchemyuoppack2023",
        "aviggiano4337checklist",
        "dailycvekora2025",
        "erc4337spec",
        "ozaa4337audit",
        "quantstampalchemypm",
        "tobsixmistakes2026"
      ],
      "source_file": "techniques/T13.001.002-paymaster-policy-bypass.md"
    },
    {
      "id": "OAK-T13.001.003",
      "name": "Paymaster Reentrancy",
      "parent_tactics": [
        "OAK-T13"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (ERC-4337 EntryPoint v0.6 / v0.7 / v0.8 / v0.9 deployments); EVM L2s with native account abstraction"
      ],
      "first_documented": "2023 (ERC-4337 reference-implementation guidance warns explicitly against external calls before sponsorship-accounting finalisation); class continues to surface in audit-firm advisories on deployed paymasters",
      "aliases": [
        "validatePaymasterUserOp reentrancy",
        "postOp reentrancy",
        "paymaster validation-surface reentrancy",
        "paymaster-specific T9.005"
      ],
      "citations": [
        "aviggiano4337checklist",
        "erc4337spec",
        "osecpaymasters2025",
        "owaspscstop10",
        "ozaa4337audit",
        "tobsixmistakes2026",
        "zhou2023sok"
      ],
      "source_file": "techniques/T13.001.003-paymaster-reentrancy.md"
    },
    {
      "id": "OAK-T13.001.004",
      "name": "Paymaster Griefing",
      "parent_tactics": [
        "OAK-T13"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (ERC-4337 EntryPoint v0.6 / v0.7 / v0.8 / v0.9 deployments); EVM L2s with native account abstraction"
      ],
      "first_documented": "2023 (EntryPoint v0.7 added the unused-gas-penalty mechanism specifically to address paymaster-DoS surface); 2026 (EntryPoint v0.9 closed the temporary-revert griefing vector)",
      "aliases": [
        "paymaster DoS",
        "paymaster balance griefing",
        "postOp griefing",
        "unused-gas-penalty abuse",
        "bundler-reputation griefing"
      ],
      "citations": [
        "aviggiano4337checklist",
        "erc4337spec",
        "osecpaymasters2025",
        "ozaa4337audit",
        "projecteleven2026v09",
        "tobsixmistakes2026"
      ],
      "source_file": "techniques/T13.001.004-paymaster-griefing.md"
    },
    {
      "id": "OAK-T13.002",
      "name": "Bundler MEV",
      "parent_tactics": [
        "OAK-T13"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (any chain with deployed ERC-4337 EntryPoint, including Ethereum mainnet, Polygon, Arbitrum, Optimism, Base, BNB Chain)"
      ],
      "first_documented": "2023 (concurrent with EntryPoint v0.6 mainnet deployment and the first vendor-side analyses of the alt-mempool)",
      "aliases": [
        "UserOp MEV",
        "AA sandwich",
        "4337 front-run"
      ],
      "citations": [
        "blockpi2023bundlermempool",
        "daian2019flashboys",
        "eigenphi2023aamev",
        "eigenphijared2023",
        "erc4337eip",
        "etherspot2023bundlermev",
        "fastlane2024erc4337mev",
        "gmu2024aaempirical"
      ],
      "source_file": "techniques/T13.002-bundler-mev.md"
    },
    {
      "id": "OAK-T13.003",
      "name": "Session-Key Hijacking",
      "parent_tactics": [
        "OAK-T13"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (ERC-4337 / ERC-7579 smart accounts); Solana analogues out of scope at v0.1"
      ],
      "first_documented": "vendor advisories 2023 onward; class-level discussion in `[zhou2023sok]`; cohort of public incident write-ups remains thin at v0.1 freeze",
      "aliases": [
        "session-key compromise",
        "delegated-signer hijack",
        "smart-session abuse",
        "scoped-key drainer"
      ],
      "citations": [
        "openfortssa2026",
        "owaspscstop10",
        "smartsessions2024",
        "zhou2023sok"
      ],
      "source_file": "techniques/T13.003-session-key-hijacking.md"
    },
    {
      "id": "OAK-T13.004",
      "name": "EIP-7702 Delegation Abuse",
      "parent_tactics": [
        "OAK-T13"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Ethereum mainnet primary; cross-chain replay surface across all EIP-7702-activated chains)"
      ],
      "first_documented": "Pectra hard-fork activation 2025-05-07; cohort onset within first weeks; canonical Wintermute \"CrimeEnjoyor\" tag 2025-06-02",
      "aliases": [
        "EIP-7702 phishing",
        "set-code transaction abuse",
        "CrimeEnjoyor delegation",
        "persistent-execution-authority abuse",
        "delegator sweeper"
      ],
      "citations": [
        "coindeskcrimeenjoyor2025",
        "cryptopolitan7702aug2025",
        "cryptotimes7702quant2026",
        "devohmygodcrimeenjoyor2025",
        "eip7702phishingarxiv",
        "eip7702spec",
        "goplus7702malicious2025",
        "hacken7702aa2025",
        "slowmist7702aug2025",
        "slowmistinferno7702may2025",
        "threesigma7702wallets2025",
        "wintermute7702crimeenjoyor2025"
      ],
      "source_file": "techniques/T13.004-eip7702-delegation-abuse.md"
    },
    {
      "id": "OAK-T14.001",
      "name": "Slashing-Condition Exploit",
      "parent_tactics": [
        "OAK-T14"
      ],
      "maturity": "emerging",
      "chains": [
        "Ethereum (Beacon Chain / consensus layer)",
        "Cosmos-SDK family (Cosmos Hub, Osmosis, Injective, Terra, etc.)",
        "Polkadot / Kusama (NPoS)",
        "Solana (lite slashing model)",
        "restaking layers (EigenLayer, Symbiotic, Karak)",
        "interchain-security consumer chains"
      ],
      "first_documented": "2020 (concept characterised at Beacon Chain genesis; first Ethereum slashings 2020-2021; ICS-style equivocation slashing extended in Cosmos 2023; mass-correlated incidents on Ethereum mainnet through 2024-2025; Ethereum 2025-09 SSV-Network operator-procedural-error correlated-self-slashing event as the canonical operator-side sub-surface anchor)",
      "aliases": [
        "slashing griefing",
        "forced equivocation",
        "slashing-as-MEV",
        "whistleblower-reward race",
        "consumer-chain equivocation slash",
        "slashable-message attack",
        "operator-procedural-error correlated self-slashing",
        "DVT-failover mass slashing"
      ],
      "citations": [
        "a16zslashingecon",
        "coindeskssv2025",
        "cosmosasa2024005",
        "eigenlayerslashing2025",
        "eth2bookslashing",
        "neuder2021posattacks",
        "polkadotoffenses",
        "zhou2023sok"
      ],
      "source_file": "techniques/T14.001-slashing-condition-exploit.md"
    },
    {
      "id": "OAK-T14.002",
      "name": "MEV-Boost Relay Attack",
      "parent_tactics": [
        "OAK-T14"
      ],
      "maturity": "stable",
      "chains": [
        "Ethereum (mainnet PoS; secondarily any EVM L1 running an MEV-Boost-compatible PBS sidecar — Holesky/Hoodi testnets, Gnosis Chain, etc.)"
      ],
      "first_documented": "2023 (April 3rd unbundling incident; concurrent vendor disclosures of equivocation-class timing issues)",
      "aliases": [
        "relay unbundling",
        "MEV-Boost timing exploit",
        "block equivocation attack",
        "low-carb-crusader attack"
      ],
      "citations": [
        "aestusverticalintegration2023",
        "blocksecmevboost2023",
        "bloxroutemevboost2023",
        "chainlightpbs2023",
        "daian2019flashboys",
        "dojmevbros2024",
        "eigenphijared2023",
        "flashbotsequivocation2023",
        "flashbotsmevboost2023",
        "mevwatch2024",
        "paradigmpbstime2023"
      ],
      "source_file": "techniques/T14.002-mev-boost-relay-attack.md"
    },
    {
      "id": "OAK-T14.003",
      "name": "Restaking Cascading Risk",
      "parent_tactics": [
        "OAK-T14"
      ],
      "maturity": "emerging",
      "chains": [
        "Ethereum L1 (canonical)",
        "EVM L2s with restaking-secured AVS",
        "Cosmos-style shared-security analogues"
      ],
      "first_documented": "2023 (concept characterised in Vitalik Buterin's \"Don't overload Ethereum's consensus\" essay; class formalised through 2024 in restaking risk-analysis literature; mainnet slashing enabled by EigenLayer 2025-04)",
      "aliases": [
        "shared-security cascade",
        "AVS slashing-cascade",
        "LRT depeg cascade",
        "restaking systemic risk",
        "pooled-security contagion"
      ],
      "citations": [
        "alexanderleveragedrestaking2024",
        "eigenlabsslashinglive2025",
        "gauntletrestaking2024",
        "steakhouselrt2024",
        "vitalikrestaking2023",
        "zhou2023sok"
      ],
      "source_file": "techniques/T14.003-restaking-cascading-risk.md"
    },
    {
      "id": "OAK-T14.003.001",
      "name": "LST/LRT Depeg-Cascade as Constrained-Primitive Sub-class",
      "parent_tactics": [
        "OAK-T14",
        "OAK-T1"
      ],
      "maturity": "emerging",
      "chains": [
        "Ethereum L1 canonical (Lido stETH; Renzo ezETH); EVM L2s and L1s with LST / LRT collateral integration into lending markets"
      ],
      "first_documented": "2022-05/06 (Lido stETH cascade, pre-Shapella, chain-level redemption-absence sub-class); 2024-04 (Renzo ezETH cascade, operator-blocked redemption sub-class); 2025-07 (Lido stETH / Aave / Justin-Sun-driven cascade, withdrawal-queue-depth saturation sub-class)",
      "aliases": [
        "stETH depeg cascade",
        "ezETH depeg cascade",
        "LRT depeg cascade",
        "constrained-redemption depeg",
        "looped-leverage liquidation cascade"
      ],
      "citations": [],
      "source_file": "techniques/T14.003.001-lst-lrt-depeg-cascade-constrained-primitive.md"
    },
    {
      "id": "OAK-T14.004",
      "name": "Liquid Restaking Token Pricing Manipulation",
      "parent_tactics": [
        "OAK-T14"
      ],
      "maturity": "emerging",
      "chains": [
        "Ethereum L1 (canonical); any chain with restaking-secured AVS and liquid-restaking-token derivatives"
      ],
      "first_documented": "2024 (concurrent with the EigenLayer mainnet launch, LRT protocol launches, and the first LRT depeg events; Renzo ezETH April 2024 depeg is the earliest operational anchor)",
      "aliases": [
        "LRT depeg exploitation",
        "AVS yield manipulation",
        "EigenLayer withdrawal-queue gaming",
        "restaking-derivative price attack",
        "LRT oracle manipulation",
        "slashing-event arbitrage"
      ],
      "citations": [
        "alexanderleveragedrestaking2024",
        "eigenlabsslashinglive2025",
        "gauntletrestaking2024",
        "steakhouselrt2024"
      ],
      "source_file": "techniques/T14.004-liquid-restaking-token-pricing-manipulation.md"
    },
    {
      "id": "OAK-T14.005",
      "name": "Builder Censorship MEV Extraction",
      "parent_tactics": [
        "OAK-T14"
      ],
      "maturity": "emerging",
      "chains": [
        "Ethereum L1 (canonical, via PBS/MEV-Boost); any chain with a proposer-builder separation (PBS) architecture where block builders can censor transactions at the block-construction layer"
      ],
      "first_documented": "2020–2021 (the Flashbots / MEV-Boost ecosystem formalised PBS and builder-censorship as a surface; the class is characterised in MEV research literature from inception)",
      "aliases": [
        "builder censorship",
        "PBS censorship",
        "block-construction censorship",
        "MEV-Boost builder exclusion",
        "transaction-suppression MEV",
        "builder-level sandwich infrastructure"
      ],
      "citations": [
        "daian2019flashboys",
        "wahrstatter2023censorship",
        "zhou2023sok"
      ],
      "source_file": "techniques/T14.005-builder-censorship-mev-extraction.md"
    },
    {
      "id": "OAK-T14.006",
      "name": "Validator/Proposer Liveness-Fault Griefing",
      "parent_tactics": [
        "OAK-T14"
      ],
      "maturity": "emerging",
      "chains": [
        "Ethereum L1 (validator liveness faults and inactivity-leak penalties); Solana (validator downtime slash); Cosmos (jail-for-downtime); Polkadot (offline-slash); any Proof-of-Stake chain with liveness-fault penalties"
      ],
      "first_documented": "2020–2022 (Ethereum Beacon Chain liveness-fault penalties characterised in consensus research; validator-downtime griefing discussed in Ethereum R&D forums)",
      "aliases": [
        "liveness-fault griefing",
        "validator downtime attack",
        "proposer-withholding griefing",
        "inactivity-leak exploitation"
      ],
      "citations": [
        "daian2019flashboys",
        "zhou2023sok"
      ],
      "source_file": "techniques/T14.006-validator-proposer-liveness-fault-griefing.md"
    },
    {
      "id": "OAK-T15.001",
      "name": "Social Engineering of Operator Personnel",
      "parent_tactics": [
        "OAK-T15"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (the social-engineering vector is off-chain; downstream on-chain manifestation is per-incident)"
      ],
      "first_documented": "systematically 2019 onward (DragonEx WFC Proof \"trading-bot\" lure as the canonical pre-2020 anchor); the LinkedIn fake-job-offer / Telegram fake-recruiter / fake-investor / fake-trading-bot variants stabilised across 2020–2026 OAK-G01 operations",
      "aliases": [
        "TraderTraitor entry vector",
        "LinkedIn fake-job-offer",
        "fake-recruiter lure",
        "DPRK fake-coding-test",
        "fake-investor pretext",
        "Penpie audit-report lure",
        "WFC Proof",
        "Contagious Interview / Wagemole"
      ],
      "citations": [
        "chainalysis2024dprk",
        "ellipticronin2022",
        "mandiantradiant2024",
        "radiantpostmortem2024"
      ],
      "source_file": "techniques/T15.001-social-engineering-of-operator-personnel.md"
    },
    {
      "id": "OAK-T15.002",
      "name": "Supply-Chain / Vendor-Pipeline Compromise",
      "parent_tactics": [
        "OAK-T15"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (the supply-chain compromise is off-chain; downstream on-chain manifestation is per-incident)"
      ],
      "first_documented": "systematically 2023 onward (Atomic Wallet, Ledger Connect Kit), with earlier antecedents in npm / package-registry compromise outside crypto",
      "aliases": [
        "supply-chain attack",
        "build-pipeline injection",
        "npm package compromise",
        "CI/CD compromise",
        "post-install backdoor",
        "vendor-pipeline compromise"
      ],
      "citations": [
        "chainalysis2024dprk",
        "mandiant3cx2023"
      ],
      "source_file": "techniques/T15.002-supply-chain-vendor-pipeline-compromise.md"
    },
    {
      "id": "OAK-T15.003",
      "name": "Operator-Endpoint Compromise (Developer Workstation / Signing Machine)",
      "parent_tactics": [
        "OAK-T15"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (the endpoint compromise is off-chain; downstream on-chain manifestation is per-incident)"
      ],
      "first_documented": "systematically 2017 onward (Bithumb employee-laptop with customer-data DB as the canonical pre-2020 anchor); the developer-workstation / signing-host sub-shape stabilised across the 2024-2025 OAK-G01 wave",
      "aliases": [
        "developer workstation compromise",
        "signing-host compromise",
        "MITM on signing host",
        "INLETDRIFT-class macOS implant",
        "signing-machine takeover",
        "employee endpoint compromise"
      ],
      "citations": [
        "chainalysis2024dprk",
        "mandiantradiant2024",
        "radiantpostmortem2024"
      ],
      "source_file": "techniques/T15.003-operator-endpoint-compromise.md"
    },
    {
      "id": "OAK-T15.004",
      "name": "Operator-Side Credential Compromise (SSO / Cloud / Registrar / DNS / Package Registry)",
      "parent_tactics": [
        "OAK-T15"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (the credential compromise is off-chain; downstream on-chain manifestation is per-incident)"
      ],
      "first_documented": "systematically 2022 onward (Curve DNS hijack as a canonical anchor)",
      "aliases": [
        "registrar credential compromise",
        "DNS hijack",
        "SSO compromise",
        "cloud-account takeover",
        "package-publisher credential compromise",
        "domain-control compromise"
      ],
      "citations": [],
      "source_file": "techniques/T15.004-operator-credential-compromise.md"
    },
    {
      "id": "OAK-T15.005",
      "name": "Operator-Communication-Channel Takeover (Discord / X / Telegram)",
      "parent_tactics": [
        "OAK-T15"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (the channel takeover is off-chain; downstream on-chain manifestation is per-incident)"
      ],
      "first_documented": "systematically 2022 onward (the Bored Ape / Yuga / Ronin Discord wave is the foundational cohort)",
      "aliases": [
        "Discord compromise",
        "X account compromise",
        "Telegram channel takeover",
        "operator-brand-channel compromise",
        "community-manager account compromise",
        "official-channel phishing"
      ],
      "citations": [],
      "source_file": "techniques/T15.005-operator-communication-channel-takeover.md"
    },
    {
      "id": "OAK-T15.006",
      "name": "Impersonation via Verified Social-Account Compromise",
      "parent_tactics": [
        "OAK-T15"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (the account compromise is off-chain; downstream on-chain extraction is per-incident)"
      ],
      "first_documented": "systematically 2022 onward (the Bored Ape / BAYC Discord wave, 2022-04, is the foundational NFT-community cohort; the Solana X-account compromise wave, 2025-02, is the canonical brand-X-account cohort); the class has been institutional attacker TTP since at least 2022",
      "aliases": [
        "verified-account takeover",
        "X gold-checkmark compromise",
        "Discord admin account compromise",
        "Telegram channel admin takeover",
        "social-brand impersonation via compromise",
        "social-platform credential hijack"
      ],
      "citations": [],
      "source_file": "techniques/T15.006-impersonation-via-verified-social-account-compromise.md"
    },
    {
      "id": "OAK-T16.001",
      "name": "Vote Takeover via Flash-Loan",
      "parent_tactics": [
        "OAK-T16"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (canonical anchors); cross-chain governance contracts inherit the surface where flash-loan liquidity exists in the same execution context as the voting-power-eligibility check"
      ],
      "first_documented": "2022 (Beanstalk April 2022 as the canonical anchor)",
      "aliases": [
        "flash-loan governance attack",
        "same-block flash-borrow vote",
        "BIP attack",
        "voting-power flash-borrow",
        "governance flash-loan"
      ],
      "citations": [
        "zhou2023sok"
      ],
      "source_file": "techniques/T16.001-vote-takeover-via-flash-loan.md"
    },
    {
      "id": "OAK-T16.002",
      "name": "Hostile-Vote Treasury Drain",
      "parent_tactics": [
        "OAK-T16"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM",
        "Solana",
        "cross-chain (any DAO with on-chain governance over a treasury whose voting-token can be acquired or inflated by the attacker)"
      ],
      "first_documented": "2022 (Mango Markets October 2022 as the canonical anchor)",
      "aliases": [
        "DAO settlement vote",
        "treasury self-pay vote",
        "post-exploit governance settlement",
        "hostile DAO vote",
        "negotiated extraction vote"
      ],
      "citations": [
        "cftcmango2023",
        "compoundforumproposal289_2024",
        "compoundproposal289_2024",
        "goldenboyscompound2024",
        "tallygovernancecompound2024",
        "zhou2023sok"
      ],
      "source_file": "techniques/T16.002-hostile-vote-treasury-drain.md"
    },
    {
      "id": "OAK-T16.003",
      "name": "Delegation-Cluster Vote Takeover",
      "parent_tactics": [
        "OAK-T16"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (canonical anchors at Compound, Balancer, SushiSwap); cross-chain governance contracts inherit the surface where delegation-graph mechanics exist"
      ],
      "first_documented": "2022-2024 (Humpy pattern-of-conduct at Balancer / SushiSwap as antecedents; Compound Proposal 289 July 2024 as the canonical anchor)",
      "aliases": [
        "delegation pull attack",
        "delegate-takeover",
        "delegation cluster",
        "delegate-coordination governance attack",
        "cohort-coordinated vote",
        "Humpy-class governance accumulation"
      ],
      "citations": [
        "blocksecgovernance2024",
        "compoundforumproposal289_2024",
        "compoundproposal289_2024",
        "goldenboyscompound2024",
        "tallygovernancecompound2024",
        "zhou2023sok"
      ],
      "source_file": "techniques/T16.003-delegation-cluster-vote-takeover.md"
    },
    {
      "id": "OAK-T16.004",
      "name": "Snapshot / Off-chain Voting Exploitation",
      "parent_tactics": [
        "OAK-T16"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (off-chain Snapshot.org-class voting platforms operate independently of any specific chain; signature schemes vary)"
      ],
      "first_documented": "Class anchored conceptually 2020-2022 (Snapshot.org production deployment 2020); no canonical extraction-scale anchor at v0.1",
      "aliases": [
        "off-chain governance attack",
        "Snapshot Sybil",
        "off-chain vote without binding",
        "non-binding-vote exploitation",
        "signature-replay governance",
        "social-consensus governance attack"
      ],
      "citations": [
        "zhou2023sok"
      ],
      "source_file": "techniques/T16.004-snapshot-off-chain-voting-exploitation.md"
    },
    {
      "id": "OAK-T16.005",
      "name": "Malicious Proposal Snowballing",
      "parent_tactics": [
        "OAK-T16"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (canonical anchors at Tornado Cash, Audius, Curio); cross-chain governance contracts inherit the surface where proposal payloads can contain `delegatecall` or storage-collision-mediated authority capture"
      ],
      "first_documented": "2022 (Audius July 2022 storage-collision case as the earliest canonical anchor); refined by Tornado Cash governance May 2023 self-modifying-contract case",
      "aliases": [
        "hidden malicious proposal",
        "self-modifying proposal",
        "storage-collision governance attack",
        "delegatecall governance attack",
        "proposal-payload-as-attack-vector",
        "Tornado-class governance attack",
        "proposal text-vs-execution divergence"
      ],
      "citations": [
        "blocksectornadogov2023",
        "peckshieldtornado2023",
        "slowmisttornadogov2023",
        "tornadocomm2023",
        "zhou2023sok"
      ],
      "source_file": "techniques/T16.005-malicious-proposal-snowballing.md"
    },
    {
      "id": "OAK-T16.006",
      "name": "Timelock-Free Governance Execution",
      "parent_tactics": [
        "OAK-T16"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (primary); any chain with proxy-upgrade patterns and governance-controlled upgrade authority"
      ],
      "first_documented": "2020–2021 (proxy-upgrade pattern proliferation; timelock-bypass incidents characterized in audit literature)",
      "aliases": [
        "instant upgrade attack",
        "timelockless governance",
        "governance-timelock bypass",
        "immediate proxy upgrade",
        "unguarded upgrade authority"
      ],
      "citations": [
        "compoundtimelock2020",
        "eip1967",
        "openzeppelintimelock2021",
        "trailofbits2021governance"
      ],
      "source_file": "techniques/T16.006-timelock-free-governance-execution.md"
    },
    {
      "id": "OAK-T17.001",
      "name": "Cross-Venue Arbitrage-Driven Price-Discovery Distortion",
      "parent_tactics": [
        "OAK-T17"
      ],
      "maturity": "observed",
      "chains": [
        "chain-agnostic (cross-venue arbitrage is a continuous phenomenon across CEX / DEX venues on every chain with non-trivial trading activity; the load-bearing surface is the inter-venue spread, not the chain-level state)"
      ],
      "first_documented": "Class anchored conceptually 2017-2020 (CEX / DEX arbitrage as a continuous phenomenon throughout the period); no canonical extraction-scale OAK anchor at v0.4",
      "aliases": [
        "cross-venue arbitrage manipulation",
        "spread-driven price-discovery distortion",
        "lagging-venue victim cohort",
        "cross-CEX/DEX arbitrage exploit"
      ],
      "citations": [
        "chainalysis2025rug",
        "zhou2023sok"
      ],
      "source_file": "techniques/T17.001-cross-venue-arbitrage-price-distortion.md"
    },
    {
      "id": "OAK-T17.002",
      "name": "Liquidation-Cascade Engineering",
      "parent_tactics": [
        "OAK-T17"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Aave / Compound / Maker / Liquity / Morpho / Spark canonical); Solana (Solend / Marginfi / Kamino); cross-chain liquidation-engine designs broadly inherit the surface"
      ],
      "first_documented": "Class anchored 2020-2022 (early DeFi liquidation-engine designs); systematic cascade-engineering 2022+ (Terra / UST collapse May 2022, stETH-Aave cascade June 2022 as canonical anchors)",
      "aliases": [
        "predatory liquidation",
        "cascade ignition",
        "liquidation harvesting",
        "thin-liquidity liquidation farming",
        "depeg-cascade harvest"
      ],
      "citations": [
        "chainalysis2025rug",
        "zhou2023sok"
      ],
      "source_file": "techniques/T17.002-liquidation-cascade-engineering.md"
    },
    {
      "id": "OAK-T17.003",
      "name": "Spoofing / Cancel-Flood Order-Book Manipulation",
      "parent_tactics": [
        "OAK-T17"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM-L2 (dYdX / GMX V2 perps / Aevo); Hyperliquid HyperEVM; Solana (Drift, Phoenix, Mango v4); cross-chain order-book-DEX designs broadly inherit the surface"
      ],
      "first_documented": "Class anchored conceptually 2010-2015 (CFTC enforcement against Sarao 2015 in equity-futures CME context); crypto-DEX-specific class anchored 2022-2024 (operational deployment of order-book DEXes); no canonical extraction-scale OAK anchor at v0.4",
      "aliases": [
        "spoofing",
        "cancel-flood",
        "layering",
        "phantom liquidity",
        "spoof-and-cancel",
        "DEX order-book manipulation",
        "perp spoofing"
      ],
      "citations": [
        "chainalysis2025rug",
        "zhou2023sok"
      ],
      "source_file": "techniques/T17.003-orderbook-spoofing-cancel-flood.md"
    },
    {
      "id": "OAK-T17.004",
      "name": "TWAP / Time-Window Manipulation Against DAO Treasury / Vesting Math",
      "parent_tactics": [
        "OAK-T17"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Uniswap V2/V3 TWAP windows used as oracle reference; OpenZeppelin TimelockController / Compound Timelock-class windows; vesting-contract designs across OpenZeppelin VestingWallet / Sablier / Hedgey); cross-chain TWAP-consuming designs broadly inherit the surface"
      ],
      "first_documented": "Class anchored conceptually 2020-2022 (Uniswap V2 / V3 TWAP-as-oracle deployment); canonical extraction-scale OAK anchor not yet landed at v0.4",
      "aliases": [
        "TWAP manipulation",
        "window timing attack",
        "vesting-window manipulation",
        "treasury-swap window manipulation",
        "time-weighted price manipulation",
        "settlement-window timing"
      ],
      "citations": [
        "chainalysis2025rug",
        "zhou2023sok"
      ],
      "source_file": "techniques/T17.004-twap-window-manipulation.md"
    },
    {
      "id": "OAK-T17.005",
      "name": "TWAP Oracle Manipulation via Multi-Block MEV",
      "parent_tactics": [
        "OAK-T17"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (primary); any chain with TWAP-based price oracles and public mempool"
      ],
      "first_documented": "2021–2022 (multi-block MEV characterized by Flashbots research; TWAP manipulation via multi-block bundles documented in academic and audit literature)",
      "aliases": [
        "multi-block MEV oracle attack",
        "TWAP manipulation via proposer control",
        "stale-oracle manipulation via MEV",
        "multi-block oracle grinding",
        "sequence-length oracle attack"
      ],
      "citations": [
        "daian2020flashboys",
        "eigenphi2023mev",
        "ethereumpbs2022",
        "flashbotsmultiblock2022",
        "zhou2023sok"
      ],
      "source_file": "techniques/T17.005-multi-block-mev-twap-oracle-manipulation.md"
    },
    {
      "id": "OAK-T2.001",
      "name": "Single-Sided Liquidity Plant",
      "parent_tactics": [
        "OAK-T2"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana"
      ],
      "first_documented": "empirical (no canonical academic citation)",
      "aliases": [
        "thin LP",
        "shallow pool",
        "single-side seed",
        "asymmetric seed"
      ],
      "citations": [
        "chainalysis2025rug",
        "cointelegraphanubismixer2022",
        "decryptanubis2021",
        "slowmist2024report",
        "solrpds",
        "tmrugpull2026",
        "trmsquid2021"
      ],
      "source_file": "techniques/T2.001-single-sided-liquidity-plant.md"
    },
    {
      "id": "OAK-T2.002",
      "name": "Locked-Liquidity Spoof",
      "parent_tactics": [
        "OAK-T2",
        "OAK-T6"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "BNB Chain",
        "Solana"
      ],
      "first_documented": "2021 (industry reports)",
      "aliases": [
        "fake lock",
        "soft lock",
        "LP lock theatre",
        "partial lock",
        "lock receipt forgery"
      ],
      "citations": [
        "chainalysis2025rug",
        "secsafemoon2023",
        "slowmist2024report"
      ],
      "source_file": "techniques/T2.002-locked-liquidity-spoof.md"
    },
    {
      "id": "OAK-T2.003",
      "name": "Cross-Chain Locked-Liquidity Spoof",
      "parent_tactics": [
        "OAK-T2",
        "OAK-T6"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (Ethereum, BSC, Polygon, Arbitrum, Base)",
        "Solana",
        "cross-chain"
      ],
      "first_documented": "2022 (concept characterised in cohort-scale rug-pull retrospectives; recurring in multi-chain launch venues)",
      "aliases": [
        "off-chain lock claim",
        "wrong-chain lock receipt",
        "split-chain LP lock",
        "lock-on-A pool-on-B"
      ],
      "citations": [
        "chainalysis2025rug",
        "solrpds",
        "tmrugpull2026"
      ],
      "source_file": "techniques/T2.003-cross-chain-locked-liquidity-spoof.md"
    },
    {
      "id": "OAK-T2.004",
      "name": "Initial-Liquidity Backdoor",
      "parent_tactics": [
        "OAK-T2",
        "OAK-T6"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (Ethereum, BSC, Polygon, Arbitrum, Base)",
        "Solana"
      ],
      "first_documented": "empirical (industry-survey scale; characterised in rug-pull retrospectives and backdoor-code static-analysis research)",
      "aliases": [
        "shadow LP mint",
        "router-mint backdoor",
        "creation-time LP backdoor",
        "privileged pool admin"
      ],
      "citations": [
        "applsci2025backdoor",
        "chainalysis2025rug",
        "quillauditsbackdoor",
        "rphunter2025",
        "slowmist2024report",
        "solrpds",
        "tmrugpull2026"
      ],
      "source_file": "techniques/T2.004-initial-liquidity-backdoor.md"
    },
    {
      "id": "OAK-T2.005",
      "name": "Token Metadata Spoofing",
      "parent_tactics": [
        "OAK-T2",
        "OAK-T6"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (primary — ERC-20 name/symbol/decimals can differ from the canonical token the contract impersonates); Solana (secondary — SPL Token metadata URI manipulation); BSC (PancakeSwap token-impersonation wave 2021)"
      ],
      "first_documented": "2020-2021 (token-impersonation wave on Uniswap V2/V3; fake USDT/USDC/ETH tokens with manipulated name/symbol/decimals fields)",
      "aliases": [
        "token symbol spoofing",
        "fake token metadata",
        "ERC-20 name impersonation",
        "counterfeit token branding",
        "metadata deception"
      ],
      "citations": [
        "coingeckotokenlist",
        "metaplextokenmetadata",
        "oneinchtokenlist",
        "pancakeswap2021fake",
        "solanaspltokenmetadata",
        "uniswaptokenlist"
      ],
      "source_file": "techniques/T2.005-token-metadata-spoofing.md"
    },
    {
      "id": "OAK-T3.001",
      "name": "Sybil-Bundled Launch",
      "parent_tactics": [
        "OAK-T3"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana"
      ],
      "first_documented": "2024–2025 (industry observation; Liu et al. 2025 covers the related airdrop-sybil case with transferable methodology)",
      "aliases": [
        "bundled buys",
        "atomic launch",
        "sniper bundle",
        "bundler-cluster launch"
      ],
      "citations": [
        "dydx2024sybil",
        "jitobundlepolicies2024",
        "liu2025sybil",
        "pumpfunbundlerbubblemaps2024",
        "pumpfunlaunchruganalytics2024"
      ],
      "source_file": "techniques/T3.001-sybil-bundled-launch.md"
    },
    {
      "id": "OAK-T3.002",
      "name": "Wash-Trade Volume Inflation",
      "parent_tactics": [
        "OAK-T3",
        "OAK-T17"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana",
        "CEX (cross-venue)"
      ],
      "first_documented": "2019 (Bitwise SEC filing on CEX wash); 2021 (Victor & Weintraud, DEX academic cohort)",
      "aliases": [
        "self-trading",
        "circular volume",
        "fake volume",
        "incentive-farming wash"
      ],
      "citations": [
        "bitwise2019fakevolumes",
        "chainalysis2022nft",
        "chainalysis2025rug",
        "victor2021washtrade"
      ],
      "source_file": "techniques/T3.002-wash-trade-volume-inflation.md"
    },
    {
      "id": "OAK-T3.003",
      "name": "Coordinated Pump-and-Dump",
      "parent_tactics": [
        "OAK-T3",
        "OAK-T5",
        "OAK-T17"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana",
        "BSC",
        "CEX (cross-venue)"
      ],
      "first_documented": "2017–2018 (Telegram-group studies); 2021 (Bitwise CEX-cohort context); systematic 2024–2025",
      "aliases": [
        "P&D",
        "coordinated pump",
        "group pump",
        "shill-coordinated dump"
      ],
      "citations": [
        "bolz2024",
        "chainalysis2025rug",
        "karbalaii2025",
        "pumpfunbundlerbubblemaps2024",
        "pumpfunlaunchruganalytics2024",
        "secsafemoon2023"
      ],
      "source_file": "techniques/T3.003-pump-and-dump-coordination.md"
    },
    {
      "id": "OAK-T3.004",
      "name": "Influencer-Amplified Promotion-and-Dump",
      "parent_tactics": [
        "OAK-T3",
        "OAK-T17"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Ethereum, Solana via Pump.fun, BNB Chain); cross-chain"
      ],
      "first_documented": "2021-06 (Save the Kids / $KIDS — FaZe Clan / Frazier Kay / RiceGum / Sommer Ray); 2021-12 (CryptoZoo — Logan Paul); cohort scale-out 2024–2026 with the Pump.fun celebrity-launch wave (DADDY / JENNER / MOTHER / DJT)",
      "aliases": [
        "celebrity coin rug",
        "influencer pump and dump",
        "celebrity NFT rug",
        "external-to-crypto promoter dump",
        "YouTube / X / Twitch celebrity-coin promotion-and-dump"
      ],
      "citations": [],
      "source_file": "techniques/T3.004-influencer-amplified-promotion-and-dump.md"
    },
    {
      "id": "OAK-T3.005",
      "name": "Fake-Validator Staking-Frontend Phishing",
      "parent_tactics": [
        "OAK-T3",
        "OAK-T4"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Lido staking, Rocket Pool); Solana (Marinade, Jito staking); Cosmos (validator delegation scams)"
      ],
      "first_documented": "2021-2022 (Lido stETH staking-interface phishing campaigns; fake validator-delegation portals)",
      "aliases": [
        "staking-frontend phishing",
        "fake validator portal",
        "liquid-staking phishing",
        "validator-impersonation phishing"
      ],
      "citations": [
        "cosmosvalidatorphishing",
        "lidophishing2022",
        "marinadephishing2023",
        "phishingdomainreputation",
        "rocketpoolphishing2022"
      ],
      "source_file": "techniques/T3.005-fake-validator-staking-frontend-phishing.md"
    },
    {
      "id": "OAK-T3.006",
      "name": "Insider Multi-Vector Supply Extraction",
      "parent_tactics": [
        "OAK-T3",
        "OAK-T17"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Ethereum, Solana via Pump.fun); cross-chain"
      ],
      "first_documented": "2026-05 (LABtrade — ZachXBT investigation)",
      "aliases": [
        "multi-vector insider extraction",
        "coordinated insider supply dump",
        "insider multi-mechanism rug"
      ],
      "citations": [
        "zachxbtlabtrade2026"
      ],
      "source_file": "techniques/T3.006-insider-multi-vector-supply-extraction.md"
    },
    {
      "id": "OAK-T4.001",
      "name": "Permit2 Signature-Based Authority Misuse",
      "parent_tactics": [
        "OAK-T4"
      ],
      "maturity": "stable",
      "chains": [
        "EVM"
      ],
      "first_documented": "2022–2023 (industry incident reports)",
      "aliases": [
        "permit2 phishing",
        "signature-based asset transfer",
        "off-chain approval drainer"
      ],
      "citations": [
        "checkpoint2023drainers",
        "scamsniffer2024lineage",
        "scamsniffer2024pink",
        "slowmist2024report",
        "zachxbtmonkey2023"
      ],
      "source_file": "techniques/T4.001-permit2-authority-misuse.md"
    },
    {
      "id": "OAK-T4.002",
      "name": "Compromised Front-End Permit Solicitation",
      "parent_tactics": [
        "OAK-T4",
        "OAK-T6"
      ],
      "maturity": "observed",
      "chains": [
        "EVM"
      ],
      "first_documented": "2022 (Curve Finance DNS hijack)",
      "aliases": [
        "frontend hijack permit",
        "DNS-takeover permit",
        "BGP-hijack frontend"
      ],
      "citations": [
        "blocksec_coinstats2024",
        "coinstats20240622",
        "dexxstatements2024",
        "galxepostmortem2023",
        "peckshieldcoinstats2024",
        "peckshielddexx2024",
        "peckshieldgalxe2023",
        "rektcurve2022",
        "rektgalxe2023",
        "slowmist2024report",
        "slowmistcoinstats2024",
        "slowmistdexx2024",
        "zachxbtcoinstats2024",
        "zachxbtdexx2024"
      ],
      "source_file": "techniques/T4.002-compromised-frontend-permit-solicitation.md"
    },
    {
      "id": "OAK-T4.003",
      "name": "Address Poisoning",
      "parent_tactics": [
        "OAK-T4",
        "OAK-T6"
      ],
      "maturity": "stable",
      "chains": [
        "EVM (primary)",
        "Solana",
        "Tron"
      ],
      "first_documented": "2022 (early reports); industrial-scale 2023 onward (Tsuchiya et al. 2025 USENIX Security cohort)",
      "aliases": [
        "zero-value transfer scam",
        "lookalike-address phishing",
        "wallet-history poisoning"
      ],
      "citations": [
        "chainalysis2024poisoning",
        "chainalysisnftcounterfeit2022",
        "tsuchiya2025poisoning"
      ],
      "source_file": "techniques/T4.003-address-poisoning.md"
    },
    {
      "id": "OAK-T4.004",
      "name": "Allowance / Approve-Pattern Drainer",
      "parent_tactics": [
        "OAK-T4"
      ],
      "maturity": "stable",
      "chains": [
        "EVM (primary)"
      ],
      "first_documented": "widespread from approximately 2022; characterised in `[checkpoint2023drainers]`",
      "aliases": [
        "approve drainer",
        "unlimited allowance phishing",
        "ERC-20 approve scam"
      ],
      "citations": [
        "blocksec_coinstats2024",
        "checkpoint2023drainers",
        "coinstats20240622",
        "dexxstatements2024",
        "peckshieldcoinstats2024",
        "peckshielddexx2024",
        "scamsniffer2024lineage",
        "scamsniffer2024pink",
        "slowmist2024report",
        "slowmistcoinstats2024",
        "slowmistdexx2024",
        "theblock2022boredape",
        "zachxbtcoinstats2024",
        "zachxbtdexx2024"
      ],
      "source_file": "techniques/T4.004-allowance-approve-drainer.md"
    },
    {
      "id": "OAK-T4.005",
      "name": "`setApprovalForAll` NFT Drainer",
      "parent_tactics": [
        "OAK-T4"
      ],
      "maturity": "stable",
      "chains": [
        "EVM (primary; Ethereum / Polygon / BNB Chain)"
      ],
      "first_documented": "2021 (early Bored Ape phishing wave); industrial-scale 2022+",
      "aliases": [
        "NFT phishing drainer",
        "approval-for-all phishing",
        "BAYC phishing"
      ],
      "citations": [
        "baycdiscord2022",
        "checkpoint2023drainers",
        "fortunebaycjune2022",
        "openseamoderation2022",
        "openseaoperatorfilter2022",
        "peckshieldyugaotherside2022",
        "slowmist2024report",
        "slowmistyugaotherside2022",
        "theblock2022boredape",
        "theblockyugaotherside2022",
        "yugaotherside2022",
        "zachxbtyugaotherside2022"
      ],
      "source_file": "techniques/T4.005-setapprovalforall-nft-drainer.md"
    },
    {
      "id": "OAK-T4.006",
      "name": "WalletConnect Session Hijack",
      "parent_tactics": [
        "OAK-T4"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (primary)",
        "Solana",
        "multi-chain (any chain WalletConnect supports)"
      ],
      "first_documented": "systematic 2023 onward; mobile-app-impersonation cases at scale 2024",
      "aliases": [
        "WalletConnect phishing",
        "fake-dApp pairing",
        "QR-code wallet hijack"
      ],
      "citations": [],
      "source_file": "techniques/T4.006-walletconnect-session-hijack.md"
    },
    {
      "id": "OAK-T4.007",
      "name": "Native-app Social Phishing on Engagement-Weighted Platforms",
      "parent_tactics": [
        "OAK-T4"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Polygon-resident Polymarket canonical at v0.1; cross-platform analogues across Friend.tech, Pump.fun, Farcaster, and any platform with engagement-weighted in-platform distribution)"
      ],
      "first_documented": "2025-10/11 (Polymarket comment-section phishing campaign exploiting comment-pinning mechanic)",
      "aliases": [
        "comment-section phishing",
        "engagement-weighted phishing",
        "in-platform paid-pinning phishing",
        "native-app social phishing"
      ],
      "citations": [],
      "source_file": "techniques/T4.007-native-app-social-phishing-engagement-weighted-platforms.md"
    },
    {
      "id": "OAK-T4.008",
      "name": "Fake-DEX Clone-Frontend Phishing",
      "parent_tactics": [
        "OAK-T4"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM dominant (Uniswap / PancakeSwap / Lido / Curve / Stargate / Orbiter / Radiant / Zapper / DefiLlama clone-frontends); Solana (Raydium clone-frontends); cross-chain"
      ],
      "first_documented": "2023-03 (MS Drainer kit cohort initial deployment); class-level industrial cohort observable across 2023–2026 with continuing distribution surface",
      "aliases": [
        "fake DEX phishing",
        "clone-frontend phishing",
        "typosquat DEX UI",
        "paid-ad fake-DEX cohort",
        "Inferno-Drainer fake-frontend"
      ],
      "citations": [
        "bleepingmsdrainer2023",
        "bleepingtelegrambots2024",
        "cointelegraphmsdrainer2023",
        "cryptonewsuniswap12m2025",
        "cyblecryptophishingapps2024",
        "gateuniswap2025",
        "hackreadgoogleplaypishing2024",
        "kasperskytelegram2025",
        "protosuniswap2025",
        "scamsniffermsdrainer2023",
        "techradarcryptoplaystore2024"
      ],
      "source_file": "techniques/T4.008-fake-dex-clone-frontend-phishing.md"
    },
    {
      "id": "OAK-T4.009",
      "name": "Pre-token Brand-Anticipation Phishing",
      "parent_tactics": [
        "OAK-T4"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (primary); Solana (secondary; EigenLayer / zkSync anticipation cohort has cross-chain analogues on Solana-based protocol token-anticipation campaigns)"
      ],
      "first_documented": "~2023-10 (zkSync airdrop-anticipation phishing cohort); class-level scaling accelerated through EigenLayer anticipation (early 2024) and Polymarket POLY anticipation (post-October-2025 CMO confirmation)",
      "aliases": [
        "pre-token phishing",
        "airdrop-anticipation scam",
        "future-token typosquat",
        "brand-ambiguity phishing",
        "pre-launch anticipation drainer"
      ],
      "citations": [],
      "source_file": "techniques/T4.009-pre-token-brand-anticipation-phishing.md"
    },
    {
      "id": "OAK-T4.010",
      "name": "Fake Security-Tool / Browser-Extension Phishing",
      "parent_tactics": [
        "OAK-T4"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM",
        "Solana (wallet-browser-extension surface is cross-chain; fake MetaMask, Rabby, Phantom, Trust Wallet extensions target the respective chain ecosystems); cross-chain"
      ],
      "first_documented": "2022–2023 (fake MetaMask extension campaigns; fake \"Ledger Live\" Chrome extensions)",
      "aliases": [
        "fake browser extension",
        "counterfeit security tool",
        "fake wallet extension",
        "malicious browser extension phishing"
      ],
      "citations": [
        "scamsniffermetamaskext2023"
      ],
      "source_file": "techniques/T4.010-fake-security-tool-browser-extension-phishing.md"
    },
    {
      "id": "OAK-T4.011",
      "name": "Push-Notification Infrastructure Compromise",
      "parent_tactics": [
        "OAK-T4"
      ],
      "maturity": "emerging",
      "chains": [
        "cross-chain (iOS/Android push-notification infrastructure is chain-agnostic; the downstream wallet-compromise surface spans all chains the affected wallet application supports)"
      ],
      "first_documented": "2024-06 (CoinStats iOS push-notification infrastructure compromise)",
      "aliases": [
        "push-notification hijack",
        "mobile-notification compromise",
        "wallet-app notification-channel attack"
      ],
      "citations": [
        "blocksec_coinstats2024",
        "coinstats20240622",
        "peckshieldcoinstats2024",
        "slowmistcoinstats2024",
        "zachxbtcoinstats2024"
      ],
      "source_file": "techniques/T4.011-push-notification-infrastructure-compromise.md"
    },
    {
      "id": "OAK-T4.012",
      "name": "Clipboard-Hijacker (Clipper) Address Substitution",
      "parent_tactics": [
        "OAK-T4",
        "OAK-T6"
      ],
      "maturity": "emerging",
      "chains": [
        "cross-chain (clippers are coin-agnostic — Bitcoin, Ethereum, Litecoin, Monero, Dogecoin, Tron, XRP, Solana, Cardano, Zcash, and others are matched by per-format address regex)"
      ],
      "first_documented": "2017 (CryptoShuffler clipboard trojan); commodity scale 2018 onward (ESET clipboard-hijacker family); resurgence 2023 (trojanised Tor Browser clipper, ~$400K) and 2026 (Microsoft `CryptoBandits` USB-worm clipper; Check Point Rust-clipper reputation-laundering campaign)",
      "aliases": [
        "clipper",
        "crypto clipper",
        "clipboard hijacker",
        "ClipBanker",
        "address-swap malware",
        "clipboard wallet-address replacement"
      ],
      "citations": [
        "checkpointclipper2026",
        "microsoftcryptobandits2026",
        "thehackernewsclipper2026",
        "windowsnewsclipbanker2026"
      ],
      "source_file": "techniques/T4.012-clipboard-hijacker-clipper-address-substitution.md"
    },
    {
      "id": "OAK-T4.013",
      "name": "Endpoint Infostealer Wallet-Material and Credential Exfiltration",
      "parent_tactics": [
        "OAK-T4"
      ],
      "maturity": "emerging",
      "chains": [
        "cross-chain (commodity infostealers enumerate every browser-extension wallet and desktop wallet application present on the host regardless of chain — MetaMask, Phantom, Trust Wallet, Exodus, Electrum, and dozens more — plus raw key/keystore files)"
      ],
      "first_documented": "2011-06 (allInVain `wallet.dat` theft from a Windows PC — the earliest documented host-malware wallet-file extraction); commodity malware-as-a-service scale 2016 onward (Azorult), with the modern crypto-targeting stealer families RedLine (2020), Raccoon, Vidar, and Lumma / LummaC2 (2022 onward); trusted-platform game/content delivery anchors 2025–2026 (Steam game Chemia, July 2025; Steam Workshop / Wallpaper Engine campaign, June 2026)",
      "aliases": [
        "infostealer",
        "info-stealer",
        "stealer malware",
        "crypto stealer",
        "wallet stealer",
        "RedLine / Vidar / Lumma stealer",
        "wallet-data exfiltration malware"
      ],
      "citations": [
        "bleepingsteamworkshop2026",
        "decryptsteamwallpaper2026",
        "kasperskysteamwallpaper2026",
        "prodaftchemia2025"
      ],
      "source_file": "techniques/T4.013-endpoint-infostealer-wallet-credential-exfiltration.md"
    },
    {
      "id": "OAK-T5.001",
      "name": "Hard LP Drain",
      "parent_tactics": [
        "OAK-T5"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana"
      ],
      "first_documented": "2020 (industry reports)",
      "aliases": [
        "hard rug",
        "LP withdrawal event"
      ],
      "citations": [
        "chainalysis2021scams",
        "chainalysis2025rug",
        "cointelegraphanubismixer2022",
        "decryptanubis2021",
        "slowmist2024report",
        "solrpds",
        "trmsquid2021"
      ],
      "source_file": "techniques/T5.001-hard-lp-drain.md"
    },
    {
      "id": "OAK-T5.002",
      "name": "Slow LP Trickle Removal",
      "parent_tactics": [
        "OAK-T5",
        "OAK-T6"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM",
        "Solana"
      ],
      "first_documented": "2024–2026 (TM-RugPull research, 2026; Tran et al. 2025 Fragmented Rug Pull)",
      "aliases": [
        "slow rug",
        "trickle drain",
        "patient drain",
        "fragmented rug pull (FRP)"
      ],
      "citations": [
        "frp2025",
        "fullycryptosoftrug",
        "secsafemoon2023",
        "tmrugpull2026"
      ],
      "source_file": "techniques/T5.002-slow-lp-trickle-removal.md"
    },
    {
      "id": "OAK-T5.003",
      "name": "Hidden-Mint Dilution",
      "parent_tactics": [
        "OAK-T5"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana"
      ],
      "first_documented": "2021 (Xia et al. canonical Uniswap scam-token cohort)",
      "aliases": [
        "stealth mint",
        "hidden inflation",
        "post-launch mint"
      ],
      "citations": [
        "badgerpostmortem2021",
        "chainalysisbadger2021",
        "halbornbadger2021",
        "neodyme2024token2022",
        "solana2024permdelegate",
        "tmrugpull2026",
        "xia2021mintdump"
      ],
      "source_file": "techniques/T5.003-hidden-mint-dilution.md"
    },
    {
      "id": "OAK-T5.004",
      "name": "Sandwich / MEV Extraction",
      "parent_tactics": [
        "OAK-T5",
        "OAK-T17"
      ],
      "maturity": "stable",
      "chains": [
        "EVM"
      ],
      "first_documented": "2019 (Daian et al., \"Flash Boys 2.0\")",
      "aliases": [
        "sandwich",
        "MEV sandwich",
        "front-run + back-run"
      ],
      "citations": [
        "daian2019flashboys",
        "eigenphijared2023"
      ],
      "source_file": "techniques/T5.004-sandwich-mev-extraction.md"
    },
    {
      "id": "OAK-T5.005",
      "name": "Treasury-Management Exit",
      "parent_tactics": [
        "OAK-T5",
        "OAK-T6"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana"
      ],
      "first_documented": "2021 (Polywhale-class incidents); regulatory record 2023 (SafeMoon federal complaint)",
      "aliases": [
        "soft rug via treasury",
        "treasury draw exit",
        "team-unlock dump",
        "salary-rug"
      ],
      "citations": [
        "chainalysis2025rug",
        "fullycryptosoftrug",
        "secsafemoon2023"
      ],
      "source_file": "techniques/T5.005-treasury-management-exit.md"
    },
    {
      "id": "OAK-T5.006",
      "name": "Vesting Cliff Dump",
      "parent_tactics": [
        "OAK-T5"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM",
        "Solana",
        "Cosmos",
        "BNB Chain (any chain hosting time-locked allocation contracts)"
      ],
      "first_documented": "2021–2024 (industry retrospectives at token-unlock-tracker level)",
      "aliases": [
        "cliff dump",
        "unlock dump",
        "investor unlock sell-pressure"
      ],
      "citations": [
        "chainalysis2025rug",
        "cryptorank2026unlock",
        "defillama2026unlocks",
        "tokenunlocks2026platform"
      ],
      "source_file": "techniques/T5.006-vesting-cliff-dump.md"
    },
    {
      "id": "OAK-T5.007",
      "name": "Third-party Brand-impersonation Custodial Soft-rug",
      "parent_tactics": [
        "OAK-T5"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Polygon-resident Polymarket-branded canonical case at v0.1; cross-platform analogues across any high-trust platform whose brand can be impersonated by off-platform services — Polymarket, Hyperliquid, dYdX, Pump.fun, GMX, prediction-market and trader-tooling ecosystems)"
      ],
      "first_documented": "2026-01 (Polycule trading bot — Polymarket-branded but unaffiliated, ~$230K, exit-via-\"hack\" announcement followed by communication blackout)",
      "aliases": [
        "third-party brand-impersonation soft rug",
        "Polymarket-branded bot exit",
        "fake-affiliated trading-bot rug",
        "custodial soft-rug exit-as-hack"
      ],
      "citations": [],
      "source_file": "techniques/T5.007-third-party-brand-impersonation-custodial-soft-rug.md"
    },
    {
      "id": "OAK-T5.008",
      "name": "Ransomware Extortion Payment",
      "parent_tactics": [
        "OAK-T5"
      ],
      "maturity": "observed",
      "chains": [
        "Bitcoin (primary)",
        "Ethereum",
        "Monero (limited on-chain observability)"
      ],
      "first_documented": "2013 (CryptoLocker — first Bitcoin-ransomware at scale); the ransomware-as-a-service (RaaS) operational model consolidated 2019–2021; large-loss enterprise ransomware payments became the dominant crypto-crime vector by dollar volume circa 2020",
      "aliases": [
        "ransomware payment",
        "crypto extortion",
        "ransom payment on-chain",
        "RaaS payment collection"
      ],
      "citations": [
        "chainalysis2025ransomware",
        "cisa2023ransomware",
        "colonialpipeline2021doj",
        "fbiic32023",
        "kaseya2021revil",
        "ofacransomware2021"
      ],
      "source_file": "techniques/T5.008-ransomware-extortion-payment.md"
    },
    {
      "id": "OAK-T5.009",
      "name": "Physical-Coercion Extraction (Wrench Attack)",
      "parent_tactics": [
        "OAK-T5"
      ],
      "maturity": "observed",
      "chains": [
        "chain-agnostic (any self-custodied or credential-accessible asset; the coercion is off-chain, the extraction transaction is on any chain the victim holds)"
      ],
      "first_documented": "physical robbery of Bitcoin holders appears from the mid-2010s; the pattern scaled with crypto-wealth concentration into kidnapping-for-ransom by the early 2020s (TeufeurS, 2023), produced a concentrated France/Europe wave of kidnappings and home invasions in 2024–2025 (the Ledger co-founder Balland case, 2025-01), and became a CertiK-tracked global surge in 2026 (dozens of verified attacks; documented shift toward targeting victims' families)",
      "aliases": [
        "wrench attack",
        "$5 wrench attack\" (after xkcd #538)",
        "physical extortion",
        "crypto kidnapping / ransom",
        "home-invasion crypto robbery",
        "rubber-hose extraction"
      ],
      "citations": [],
      "source_file": "techniques/T5.009-physical-coercion-extraction.md"
    },
    {
      "id": "OAK-T6.001",
      "name": "Source-Verification Mismatch",
      "parent_tactics": [
        "OAK-T6"
      ],
      "maturity": "stable",
      "chains": [
        "EVM (primary)"
      ],
      "first_documented": "widespread from approximately 2020 onward",
      "aliases": [
        "verified-but-not-really",
        "fake source verification",
        "bytecode-source mismatch"
      ],
      "citations": [
        "chainalysis2025rug"
      ],
      "source_file": "techniques/T6.001-source-verification-mismatch.md"
    },
    {
      "id": "OAK-T6.002",
      "name": "Fake Audit-Claim",
      "parent_tactics": [
        "OAK-T6"
      ],
      "maturity": "stable",
      "chains": [
        "chain-agnostic (the failure mode lives off-chain; the underlying Technique it modifies may be on any chain)"
      ],
      "first_documented": "widespread from approximately 2021 onward",
      "aliases": [
        "audit fraud",
        "fake CertiK audit",
        "audit-affiliation impersonation"
      ],
      "citations": [
        "certikfakeaudit",
        "dlnewsswaprum2023"
      ],
      "source_file": "techniques/T6.002-fake-audit-claim.md"
    },
    {
      "id": "OAK-T6.003",
      "name": "Audit-of-Different-Bytecode-Version",
      "parent_tactics": [
        "OAK-T6"
      ],
      "maturity": "stable",
      "chains": [
        "chain-agnostic (the failure mode is the audit-vs-deployed gap; the underlying Technique it modifies may be on any chain)"
      ],
      "first_documented": "widespread from approximately 2021 onward",
      "aliases": [
        "audit-deployed mismatch",
        "post-audit redeploy",
        "audit-version drift",
        "audit of fork"
      ],
      "citations": [
        "certikfakeaudit",
        "chainalysis2025rug",
        "dlnewsswaprum2023"
      ],
      "source_file": "techniques/T6.003-audit-of-different-bytecode-version.md"
    },
    {
      "id": "OAK-T6.004",
      "name": "Audit-Pending Marketing Claim",
      "parent_tactics": [
        "OAK-T6"
      ],
      "maturity": "stable",
      "chains": [
        "chain-agnostic (the failure mode lives off-chain at the marketing-claim layer; the underlying Technique it modifies may be on any chain)"
      ],
      "first_documented": "widespread from approximately 2021 onward",
      "aliases": [
        "audit pending",
        "audit in progress",
        "audit forthcoming",
        "working with [firm]",
        "audit Q[X]"
      ],
      "citations": [
        "certikfakeaudit",
        "chainalysis2025rug",
        "slowmist2024report"
      ],
      "source_file": "techniques/T6.004-audit-pending-marketing-claim.md"
    },
    {
      "id": "OAK-T6.005",
      "name": "Proxy-Upgrade Malicious Switching",
      "parent_tactics": [
        "OAK-T6",
        "OAK-T1",
        "OAK-T9",
        "OAK-T10"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (primary); cross-chain bridge variants (Polkadot ⇄ EVM canonical at v0.1)"
      ],
      "first_documented": "structural class anchored from approximately 2022; canonical contract-layer-message-forgery 2026-04 (Hyperbridge)",
      "aliases": [
        "verified-then-malicious upgrade",
        "proxy implementation switching",
        "upgrade-as-attack-vector",
        "post-verification implementation substitution"
      ],
      "citations": [
        "ambcryptohyperbridge2026",
        "audiuspostmortem2022",
        "autheobridgesecurity2026",
        "cmcacademyhyperbridge2026",
        "coindeskhyperbridge2026",
        "cointelegraphhyperbridge2026",
        "cryptobriefinghyperbridge2026",
        "cryptobriefinghyperbridgejump2026",
        "dlnewshyperbridge2026",
        "halbornaudius2022",
        "peckshieldaudius2022",
        "polkadotforumhyperbridge2026",
        "theblockaudius2022",
        "theblockhyperbridge2026",
        "thedefianthyperbridge2026"
      ],
      "source_file": "techniques/T6.005-proxy-upgrade-malicious-switching.md"
    },
    {
      "id": "OAK-T6.006",
      "name": "Counterfeit Token Impersonation",
      "parent_tactics": [
        "OAK-T6",
        "OAK-T4",
        "OAK-T5"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (primary); cross-chain bridge variants (Polkadot ⇄ EVM canonical at v0.1)"
      ],
      "first_documented": "dust-attack-lure / fake-LP cohort widespread from approximately 2022; canonical bridge-internal-mint sub-class 2026-04 (Hyperbridge)",
      "aliases": [
        "fake-symbol-matching token",
        "bridge-token impersonation",
        "counterfeit-mint",
        "dust-attack lure",
        "fake LP-token"
      ],
      "citations": [
        "ambcryptohyperbridge2026",
        "autheobridgesecurity2026",
        "chainalysis2025rug",
        "cmcacademyhyperbridge2026",
        "coindeskhyperbridge2026",
        "cointelegraphhyperbridge2026",
        "cryptobriefinghyperbridge2026",
        "cryptobriefinghyperbridgejump2026",
        "dlnewshyperbridge2026",
        "polkadotforumhyperbridge2026",
        "theblockhyperbridge2026",
        "thedefianthyperbridge2026"
      ],
      "source_file": "techniques/T6.006-counterfeit-token-impersonation.md"
    },
    {
      "id": "OAK-T6.007",
      "name": "Trust-substrate Shift / Vendor-side Promise Revocation",
      "parent_tactics": [
        "OAK-T6"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (the substrate-of-revocation is the vendor / regulator / infrastructure-policy claim; the realised effect is on user-side threat-model construction across whichever chains the affected product operates)"
      ],
      "first_documented": "2023-05-16 (Ledger Recover seed-recovery service announcement collapsing the \"seed never leaves the device\" trust-substrate claim that had informed Ledger users' threat-model construction since 2016)",
      "aliases": [
        "vendor-policy promise revocation",
        "trust-substrate revocation event",
        "non-attack defender-credibility event",
        "vendor-policy-as-defense-evasion"
      ],
      "citations": [],
      "source_file": "techniques/T6.007-trust-substrate-shift-vendor-promise-revocation.md"
    },
    {
      "id": "OAK-T6.008",
      "name": "Verified-but-Malicious Frontend Routing",
      "parent_tactics": [
        "OAK-T6"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (primary); cross-chain DEX-router analogues (Solana Jupiter routing-manipulation, cross-chain bridge routing-path insertion) are pipeline anchor candidates at v0.x"
      ],
      "first_documented": "~2024 (SwapKit router impersonation cohort; class-level visibility accelerated through 2025 with Uniswap routing-manipulation incidents)",
      "aliases": [
        "malicious routing frontend",
        "helper-contract injection",
        "router-impersonator phishing",
        "verified-contract routing attack",
        "intermediate-hop extraction"
      ],
      "citations": [],
      "source_file": "techniques/T6.008-verified-but-malicious-frontend-routing.md"
    },
    {
      "id": "OAK-T7.001",
      "name": "Mixer-Routed Hop",
      "parent_tactics": [
        "OAK-T7"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Bitcoin",
        "cross-chain"
      ],
      "first_documented": "2017 (academic interest), enforcement attention 2022+",
      "aliases": [
        "mixer hop",
        "obfuscation hop",
        "anonymity-set hop"
      ],
      "citations": [
        "chainalysis2024laundering",
        "coindeskthorchainlazarus2025",
        "cointelegraphanubismixer2022",
        "ellipticronin2022",
        "fbiharmony2023",
        "ofac2022tornado"
      ],
      "source_file": "techniques/T7.001-mixer-routed-hop.md"
    },
    {
      "id": "OAK-T7.002",
      "name": "CEX Deposit-Address Layering",
      "parent_tactics": [
        "OAK-T7"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana",
        "Bitcoin",
        "cross-chain"
      ],
      "first_documented": "systematic from 2020 onward; characterised at scale in `[chainalysis2024laundering]`",
      "aliases": [
        "deposit layering",
        "diversified-deposit laundering",
        "structured CEX off-ramp"
      ],
      "citations": [
        "chainalysis2024laundering",
        "chainalysis2025garantex",
        "doj2025garantex",
        "ellipticatomic2023",
        "ofac2022garantex",
        "treasury2025garantexnetwork",
        "trmlabs2025grinex"
      ],
      "source_file": "techniques/T7.002-cex-deposit-layering.md"
    },
    {
      "id": "OAK-T7.003",
      "name": "Cross-Chain Bridge Laundering",
      "parent_tactics": [
        "OAK-T7"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana",
        "Bitcoin",
        "cross-chain"
      ],
      "first_documented": "systematic from approximately 2022 onward; emerged as the dominant Lazarus laundering rail post Tornado Cash sanctions",
      "aliases": [
        "chain hopping",
        "bridge laundering",
        "THORChain laundering\" (the dominant rail)"
      ],
      "citations": [
        "chainalysis2024laundering",
        "chainalysismultichain2023",
        "coindeskthorchainlazarus2025",
        "dlnewsmultichain2023",
        "ellipticharmony2022",
        "ellipticronin2022",
        "fbiharmony2023",
        "halbornharmony2022",
        "halbornmultichain2023",
        "ofac2022tornado"
      ],
      "source_file": "techniques/T7.003-cross-chain-bridge-laundering.md"
    },
    {
      "id": "OAK-T7.004",
      "name": "NFT Wash-Laundering",
      "parent_tactics": [
        "OAK-T7"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (primary; Ethereum / Polygon)"
      ],
      "first_documented": "2021 (early NFT-marketplace surge); systematic 2022 onward",
      "aliases": [
        "NFT money laundering",
        "self-financed NFT trade",
        "wash-laundering through art"
      ],
      "citations": [
        "blurzeroroyalty2022",
        "chainalysis2022nft",
        "chainalysisnftcounterfeit2022",
        "theblock2022boredape",
        "victor2021washtrade"
      ],
      "source_file": "techniques/T7.004-nft-wash-laundering.md"
    },
    {
      "id": "OAK-T7.005",
      "name": "Privacy-Chain Hops",
      "parent_tactics": [
        "OAK-T7"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Bitcoin",
        "cross-chain",
        "Monero",
        "Zcash"
      ],
      "first_documented": "systematic from approximately 2017 onward (Monero gained darknet-market dominance in 2016–2017); enforcement-relevant attention 2020+",
      "aliases": [
        "privacy-coin hop",
        "XMR hop",
        "Monero off-ramp",
        "shielded-pool hop"
      ],
      "citations": [
        "binancexmrdelist2024",
        "chainalysis2024dprk",
        "chainalysis2024laundering",
        "chainalysisprivacychain2024",
        "ofac2022tornado"
      ],
      "source_file": "techniques/T7.005-privacy-chain-hops.md"
    },
    {
      "id": "OAK-T7.006",
      "name": "DeFi Yield-Strategy Laundering",
      "parent_tactics": [
        "OAK-T7"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana",
        "cross-chain (within-chain laundering rail per chain)"
      ],
      "first_documented": "systematic from approximately 2021 onward (DeFi-summer-and-after) as DeFi liquidity-and-yield surface grew large enough to absorb laundering flows; cohort-scale industry attention 2023+",
      "aliases": [
        "yield-farm laundering",
        "LP-cover laundering",
        "staking-derivative laundering",
        "yield-user-persona laundering"
      ],
      "citations": [
        "chainalysis2024dprk",
        "chainalysis2024laundering",
        "ofac2022tornado"
      ],
      "source_file": "techniques/T7.006-defi-yield-strategy-laundering.md"
    },
    {
      "id": "OAK-T7.007",
      "name": "DEX Aggregator Routing Laundering",
      "parent_tactics": [
        "OAK-T7"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (primary); DEX aggregator deployments (1inch, 0x/Matcha, Paraswap, CowSwap, Odos, KyberSwap aggregator) are predominantly EVM-native; cross-chain aggregators (Li.Fi, Socket/Bungee, Across) compound the surface with T7.003 bridging"
      ],
      "first_documented": "The aggregator-as-laundering-rail pattern was operationalised systematically post-2022 Tornado Cash sanctions, as laundering operators sought non-mixer obfuscation primitives; cohort-scale documentation 2023+",
      "aliases": [
        "aggregator-hop laundering",
        "split-route laundering",
        "multi-hop-routing obfuscation",
        "aggregator-churn laundering"
      ],
      "citations": [
        "chainalysis2024dprk",
        "chainalysis2024laundering"
      ],
      "source_file": "techniques/T7.007-dex-aggregator-routing-laundering.md"
    },
    {
      "id": "OAK-T7.008",
      "name": "Stablecoin Issuer Freeze-Asymmetry Laundering",
      "parent_tactics": [
        "OAK-T7"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (USDC/USDT/DAI primary); cross-chain (issuer freeze capability varies by chain deployment); the technique is chain-agnostic wherever a freeze-capable stablecoin is deployed"
      ],
      "first_documented": "The freeze-policy asymmetry was operationalised as a laundering primitive systematically from 2022 onward (post-OFAC Tornado Cash sanctions, which demonstrated real-world freeze willingness divergence between Circle/USDC and Tether/USDT)",
      "aliases": [
        "freeze-arbitrage laundering",
        "issuer-policy hopping",
        "stablecoin-freeze-asymmetry exploitation",
        "compliance-jurisdiction laundering"
      ],
      "citations": [
        "chainalysis2024dprk",
        "chainalysis2024laundering",
        "ofac2022tornado"
      ],
      "source_file": "techniques/T7.008-stablecoin-issuer-coordination-laundering.md"
    },
    {
      "id": "OAK-T7.009",
      "name": "Sanctioned-Entity and Illicit-Purpose Financing",
      "parent_tactics": [
        "OAK-T7",
        "OAK-T8"
      ],
      "maturity": "observed",
      "chains": [
        "Bitcoin (primary for OFAC-designated addresses)",
        "Ethereum",
        "TRON (increasing share of illicit-purpose transaction volume post-2022)"
      ],
      "first_documented": "2013 (Silk Road-era designated-entity tracking); formalised 2018–2020 with OFAC crypto-designation framework and FATF Travel Rule",
      "aliases": [
        "designated-entity financing",
        "sanctions-evasion crypto",
        "illicit-content monetisation",
        "terrorism-financing crypto",
        "KYT red-flag screening"
      ],
      "citations": [
        "chainalysis2025illicit",
        "ellipticsanctions",
        "fatf2021virtualassets",
        "iwfcrypto",
        "ofacsdncrypto",
        "trmlabsillicit"
      ],
      "source_file": "techniques/T7.009-sanctioned-entity-illicit-purpose-financing.md"
    },
    {
      "id": "OAK-T7.010",
      "name": "Travel Rule Evasion",
      "parent_tactics": [
        "OAK-T7"
      ],
      "maturity": "observed",
      "chains": [
        "all (Travel Rule applies at the VASP layer, not the chain layer)"
      ],
      "first_documented": "2019 (FATF Recommendation 16 extended to virtual assets); systematic evasion documented 2020 onward",
      "aliases": [
        "Travel Rule bypass",
        "sub-threshold structuring",
        "VASP-data-gap exploitation",
        "FATF Rec.16 evasion"
      ],
      "citations": [
        "chainalysis2024laundering",
        "coindeskthorchainlazarus2025",
        "fatf2021virtualassets",
        "fatftravelrule2023"
      ],
      "source_file": "techniques/T7.010-travel-rule-evasion.md"
    },
    {
      "id": "OAK-T8.001",
      "name": "Common-Funder Cluster Reuse",
      "parent_tactics": [
        "OAK-T8"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana"
      ],
      "first_documented": "2021 (TRM SQUID cross-incident attribution); systematic 2024–2025",
      "aliases": [
        "operator cluster",
        "funder reuse",
        "deployer fingerprint",
        "operator-graph reuse"
      ],
      "citations": [
        "chainalysis2024dprk",
        "chainalysisdprktradertraitor",
        "liu2025sybil",
        "scamsniffer2024lineage",
        "scamsniffer2024pink",
        "slowmist2024report",
        "treasury2025garantexnetwork",
        "trmlabs2025grinex",
        "trmsquid2021"
      ],
      "source_file": "techniques/T8.001-cluster-reuse.md"
    },
    {
      "id": "OAK-T8.002",
      "name": "Cross-Chain Operator Continuity",
      "parent_tactics": [
        "OAK-T8"
      ],
      "maturity": "observed",
      "chains": [
        "cross-chain"
      ],
      "first_documented": "systematic 2023 onward as multi-chain operator activity has scaled",
      "aliases": [
        "multi-chain operator profile",
        "cross-chain attribution",
        "chain-hop operator"
      ],
      "citations": [
        "chainalysis2024dprk",
        "chainalysis2024laundering",
        "chainalysis2025ransomware",
        "chainalysisbybitthorchain",
        "coindeskthorchainlazarus2025",
        "liu2025sybil",
        "scamsniffer2024lineage",
        "slowmist2024report",
        "trilateraldprkstatement2025"
      ],
      "source_file": "techniques/T8.002-cross-chain-operator-continuity.md"
    },
    {
      "id": "OAK-T8.003",
      "name": "On-Chain Transaction Graph De-Anonymization",
      "parent_tactics": [
        "OAK-T8"
      ],
      "maturity": "observed",
      "chains": [
        "chain-agnostic (Bitcoin UTXO graph, Ethereum account graph, Solana account graph)"
      ],
      "first_documented": "2013–2015 (Chainalysis, Elliptic, CipherTrace founding era; academic literature on Bitcoin transaction graph clustering)",
      "aliases": [
        "blockchain transaction clustering",
        "UTXO taint analysis",
        "address attribution",
        "on-chain deanonymization",
        "exchange-deposit clustering",
        "Chainalysis-style graph analysis"
      ],
      "citations": [
        "chainalysis2024dprk",
        "elliptic2024crosschain",
        "meiklejohn2013fistful",
        "ron2013quantitative",
        "trmlabs2024forensics"
      ],
      "source_file": "techniques/T8.003-on-chain-transaction-graph-de-anonymization.md"
    },
    {
      "id": "OAK-T8.004",
      "name": "Exchange Account Farming / Sybil Account Creation",
      "parent_tactics": [
        "OAK-T8"
      ],
      "maturity": "observed",
      "chains": [
        "chain-agnostic (exchange-side operational surface)"
      ],
      "first_documented": "2011–2013 (BTC-e era — account-farming infrastructure as systemic exchange-laundering rail); formalised as a distinct detection surface 2017–2025",
      "aliases": [
        "exchange account farming",
        "Sybil exchange accounts",
        "synthetic-identity onboarding",
        "KYC factory",
        "account-rotation laundering",
        "verification-farm accounts"
      ],
      "citations": [
        "chainalysis2022hydra",
        "chainalysis2024dprk",
        "coindesk2024dprkinfiltration",
        "dojbtce2017",
        "elliptic2024crosschain",
        "fbidprkitworker2022",
        "treasury2025garantexnetwork",
        "trmlabs2025grinex"
      ],
      "source_file": "techniques/T8.004-exchange-account-farming-sybil-accounts.md"
    },
    {
      "id": "OAK-T8.005",
      "name": "Operational Security Procedural Failure (Non-Technical OpSec)",
      "parent_tactics": [
        "OAK-T8"
      ],
      "maturity": "stable",
      "chains": [
        "chain-agnostic (off-chain attribution surface)"
      ],
      "first_documented": "2013 (Silk Road \"altoid\" forum-handle reuse — earliest documented case of off-chain opsec failure enabling darknet-marketplace operator attribution in the public record); academic literature on stylometric attribution predates blockchain applications",
      "aliases": [
        "procedural opsec failure",
        "off-chain attribution bridge",
        "handle-reuse attribution",
        "opsec hygiene failure",
        "non-technical operational security failure",
        "stylometric fingerprinting",
        "attribution-enabling opsec failure"
      ],
      "citations": [
        "bkahydra2022",
        "chainalysis2024dprk",
        "dojalphabay2023",
        "dojbitcoinfog2021",
        "dojwelcome2018",
        "ellipticronin2022",
        "fbiulbrichtcomplaint2013",
        "wiredalphabay2021"
      ],
      "source_file": "techniques/T8.005-operational-security-procedural-failure.md"
    },
    {
      "id": "OAK-T9.001",
      "name": "Oracle Price Manipulation",
      "parent_tactics": [
        "OAK-T9",
        "OAK-T17"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana"
      ],
      "first_documented": "2020 (early cases on Compound and bZx); systematic 2022+",
      "aliases": [
        "oracle attack",
        "price-feed manipulation",
        "single-block oracle exploit"
      ],
      "citations": [
        "blocksecbonq2023",
        "blocksecveefinance2021",
        "bonqpostmortem2023",
        "cftcmango2023",
        "chainalysis2025rug",
        "creamfinance2021postmortem",
        "halbornbonq2023",
        "halborncream2021oct",
        "halbornveefinance2021",
        "immunefikream2021",
        "muditgupta2021cream",
        "owaspscstop10",
        "peckshieldbonq2023",
        "rektveefinance2021",
        "slowmistveefinance2021",
        "tellorbonq2023",
        "veefinancepostmortem2021",
        "zhou2023sok"
      ],
      "source_file": "techniques/T9.001-oracle-price-manipulation.md"
    },
    {
      "id": "OAK-T9.002",
      "name": "Flash-Loan-Enabled Exploit",
      "parent_tactics": [
        "OAK-T9"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana",
        "cross-chain"
      ],
      "first_documented": "2020 (early bZx cases)",
      "aliases": [
        "flash-loan attack",
        "atomic-borrow exploit"
      ],
      "citations": [
        "owaspscstop10",
        "zhou2023sok"
      ],
      "source_file": "techniques/T9.002-flash-loan-enabled-exploit.md"
    },
    {
      "id": "OAK-T9.003",
      "name": "Governance Attack",
      "parent_tactics": [
        "OAK-T9"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "cross-chain"
      ],
      "first_documented": "2022 (Beanstalk canonical case)",
      "aliases": [
        "DAO governance exploit",
        "voting-power attack",
        "BIP attack",
        "malicious proposal"
      ],
      "citations": [
        "blocksectornadogov2023",
        "compoundforumproposal289_2024",
        "compoundproposal289_2024",
        "goldenboyscompound2024",
        "owaspscstop10",
        "peckshieldtornado2023",
        "slowmisttornadogov2023",
        "tallygovernancecompound2024",
        "tornadocomm2023",
        "zhou2023sok"
      ],
      "source_file": "techniques/T9.003-governance-attack.md"
    },
    {
      "id": "OAK-T9.004",
      "name": "Access-Control Misconfiguration",
      "parent_tactics": [
        "OAK-T9"
      ],
      "maturity": "stable",
      "chains": [
        "EVM",
        "Solana",
        "cross-chain"
      ],
      "first_documented": "widespread; canonical modern cases 2022+",
      "aliases": [
        "broken access control",
        "missing authorization check",
        "guardian-bypass",
        "logic-flaw extraction",
        "privilege-boundary violation"
      ],
      "citations": [
        "blocksec2023euler",
        "blocksecsuikiloex2025",
        "chainalysiseuler2023",
        "chainalysismultichain2023",
        "chainalysispoly2021",
        "dlnewsmultichain2023",
        "elliptipeuler2023",
        "elliptipoly2021",
        "eulerlabs2023statement",
        "halborneuler2023",
        "halbornmultichain2023",
        "kiloexpostmortem2025",
        "kudelskipoly2021",
        "owaspscstop10",
        "peckshieldkiloex2025",
        "slowmistkiloex2025",
        "zhou2023sok"
      ],
      "source_file": "techniques/T9.004-access-control-misconfiguration.md"
    },
    {
      "id": "OAK-T9.005",
      "name": "Reentrancy",
      "parent_tactics": [
        "OAK-T9"
      ],
      "maturity": "stable",
      "chains": [
        "EVM (primary); EVM-compatible L2s; conceptually applicable to any chain whose execution model allows external calls before state finalisation"
      ],
      "first_documented": "2016 (The DAO); modern hook-based and cross-protocol variants 2020+",
      "aliases": [
        "recursive call attack",
        "callback reentry",
        "cross-function reentrancy",
        "cross-protocol reentrancy",
        "read-only reentrancy",
        "ERC-777 hook reentrancy",
        "ERC-721/1155 receive-hook reentrancy"
      ],
      "citations": [
        "daoreentrancy2016retrospective",
        "owaspscstop10",
        "zhou2023sok"
      ],
      "source_file": "techniques/T9.005-reentrancy.md"
    },
    {
      "id": "OAK-T9.006",
      "name": "Subjective-Oracle Resolution Manipulation",
      "parent_tactics": [
        "OAK-T9",
        "OAK-T17"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Polygon-resident Polymarket / Ethereum-resident UMA DVM canonical at v0.1; cross-chain analogues across Kleros, Reality.eth, Augur REP)"
      ],
      "first_documented": "Polymarket UMA whale-vote-capture March 2025; cohort scale-out 2025–2026 across Polymarket-class subjective-oracle prediction markets",
      "aliases": [
        "subjective oracle attack",
        "DVM vote capture",
        "resolution-spec manipulation",
        "prediction-market oracle attack",
        "non-numeric oracle manipulation"
      ],
      "citations": [],
      "source_file": "techniques/T9.006-subjective-oracle-resolution-manipulation.md"
    },
    {
      "id": "OAK-T9.006.001",
      "name": "DVM Vote Capture by Economically-Interested Holder",
      "parent_tactics": [
        "OAK-T9",
        "OAK-T17"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Polymarket on Polygon / UMA DVM on Ethereum canonical at v0.1)"
      ],
      "first_documented": "2025-03 (Polymarket Ukraine mineral deal)",
      "aliases": [
        "UMA whale vote capture",
        "DVM governance attack",
        "oracle-vote corruption"
      ],
      "citations": [],
      "source_file": "techniques/T9.006.001-dvm-vote-capture.md"
    },
    {
      "id": "OAK-T9.006.002",
      "name": "Resolution-Spec Ambiguity Exploitation",
      "parent_tactics": [
        "OAK-T9",
        "OAK-T17"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Polymarket on Polygon / UMA DVM on Ethereum canonical at v0.1)"
      ],
      "first_documented": "2025-07 (Polymarket Zelenskyy-suit market)",
      "aliases": [
        "spec-ambiguity attack",
        "natural-language oracle ambiguity",
        "interpretive-resolution exploitation"
      ],
      "citations": [],
      "source_file": "techniques/T9.006.002-resolution-spec-ambiguity-exploitation.md"
    },
    {
      "id": "OAK-T9.006.003",
      "name": "Off-chain Resolution-Source Coercion",
      "parent_tactics": [
        "OAK-T9",
        "OAK-T17"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Polymarket on Polygon canonical at v0.1)"
      ],
      "first_documented": "2026-03 (Times of Israel correspondent Emanuel Fabian, Iran-strike market)",
      "aliases": [
        "journalist coercion",
        "off-chain reporter extortion",
        "resolution-input-layer attack",
        "oracle-input physical-coercion"
      ],
      "citations": [],
      "source_file": "techniques/T9.006.003-off-chain-resolution-source-coercion.md"
    },
    {
      "id": "OAK-T9.006.004",
      "name": "Operational-Insider Trading on Subjective-Resolution Prediction Markets",
      "parent_tactics": [
        "OAK-T9",
        "OAK-T17"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Polymarket on Polygon canonical at v0.1)"
      ],
      "first_documented": "2025-12 (Van Dyke / Operation Absolute Resolve betting window) → 2026-01 (real-world execution) → 2026-04 (DOJ SDNY indictment + CFTC parallel civil action). Multi-jurisdictional confirmation 2026-02 (Tel Aviv District Court indictment of IDF reservist).",
      "aliases": [
        "operational-insider Polymarket",
        "classified-information prediction-market trading",
        "causal-actor insider trading"
      ],
      "citations": [],
      "source_file": "techniques/T9.006.004-operational-insider-trading.md"
    },
    {
      "id": "OAK-T9.006.005",
      "name": "Platform-Override of Oracle Outcome",
      "parent_tactics": [
        "OAK-T9",
        "OAK-T17"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (Polymarket on Polygon / UMA DVM on Ethereum canonical at v0.1)"
      ],
      "first_documented": "2024-06 (Polymarket / DJT memecoin / Barron Trump market)",
      "aliases": [
        "platform override",
        "oracle-outcome override",
        "discretionary-resolution override",
        "ultimate-discretion clause attack"
      ],
      "citations": [],
      "source_file": "techniques/T9.006.005-platform-override-oracle-outcome.md"
    },
    {
      "id": "OAK-T9.007",
      "name": "Fork-Substrate Vulnerability (Not Mitigated at Fork Time)",
      "parent_tactics": [
        "OAK-T9"
      ],
      "maturity": "stable",
      "chains": [
        "EVM (primary); cross-chain analogues (forked-protocols deployed on non-EVM chains) are pipeline anchor candidates at v0.x"
      ],
      "first_documented": "~2022-04 (Hundred Finance → Midas Capital cohort initial fork-and-exploit chain); class-level awareness solidified through 2023–2024 with the Compound V2 fork cohort cascade (Midas → Sonne → Onyx → Resupply)",
      "aliases": [
        "fork-vulnerability cascade",
        "unpatched-fork exploit",
        "upstream-disclosure-failure",
        "inherited vulnerability",
        "Compound V2 fork vulnerability chain",
        "fork-and-forget pattern"
      ],
      "citations": [],
      "source_file": "techniques/T9.007-fork-substrate-vulnerability-not-mitigated.md"
    },
    {
      "id": "OAK-T9.008",
      "name": "Diamond-Pattern Facet-Audit Incomplete",
      "parent_tactics": [
        "OAK-T9",
        "OAK-T6"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (primary; EIP-2535 diamond pattern is EVM-native); non-EVM diamond-pattern analogues (proxy-facet architectures on Solana, Sui, Aptos) are pipeline anchor candidates at v0.x"
      ],
      "first_documented": "~2022-07 (Li.Fi exploit ~$600K, v1 diamond-pattern facet-addition vulnerability); class-level calibration anchor Li.Fi July 2024 (~$10M, post-audit facet addition)",
      "aliases": [
        "diamond-proxy facet gap",
        "post-audit facet addition",
        "unaudited-facet exploit",
        "EIP-2535 audit-scope gap",
        "facet-upgrade-path exploitation",
        "diamond-cut attack"
      ],
      "citations": [],
      "source_file": "techniques/T9.008-diamond-pattern-facet-audit-incomplete.md"
    },
    {
      "id": "OAK-T9.009",
      "name": "Cross-Contract Reinitialization Attack",
      "parent_tactics": [
        "OAK-T9"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (primary); any chain whose execution model allows cross-contract calls during initialisation (upgradeable proxy patterns are EVM-native but the reinitialisation surface generalises)"
      ],
      "first_documented": "2023 (class characterised in audit-firm literature post-UUPS/transparent-proxy proliferation; specific named exploits from 2023 onward)",
      "aliases": [
        "reinitialization attack",
        "double-init attack",
        "cross-contract init callback",
        "proxy reinitialization",
        "init-state injection"
      ],
      "citations": [
        "owaspscstop10",
        "zhou2023sok"
      ],
      "source_file": "techniques/T9.009-cross-contract-reinitialization-attack.md"
    },
    {
      "id": "OAK-T9.010",
      "name": "Read-Only Reentrancy",
      "parent_tactics": [
        "OAK-T9"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (primary); any chain whose execution model allows `staticcall` to a contract that is mid-execution in the same transaction"
      ],
      "first_documented": "2022 (class characterised in ChainSecurity's Curve-LP-oracle advisories; Market.xyz on QuickSwap, October 2022, is the earliest clean in-the-wild operational anchor)",
      "aliases": [
        "view reentrancy",
        "staticcall reentrancy",
        "stale-read reentrancy",
        "cross-protocol view manipulation"
      ],
      "citations": [
        "curvepostmortem2023",
        "vyperpostmortem2023",
        "zhou2023sok"
      ],
      "source_file": "techniques/T9.010-read-only-reentrancy.md"
    },
    {
      "id": "OAK-T9.011",
      "name": "Precision-Loss Rounding Attack",
      "parent_tactics": [
        "OAK-T9"
      ],
      "maturity": "stable",
      "chains": [
        "EVM (primary); any chain whose arithmetic model uses integer division with floor/truncation rounding"
      ],
      "first_documented": "2021–2022 (ERC-4626 vault share-price manipulation via donation + rounding formally characterised by the Yearn, Solmate, and OpenZeppelin communities; the first large-loss operational anchors follow in 2023)",
      "aliases": [
        "rounding-error exploit",
        "donation attack",
        "inflation attack",
        "vault-share-price manipulation",
        "dust-accumulation attack",
        "share-price front-running via donation"
      ],
      "citations": [
        "hundredfinance2023postmortem",
        "owaspscstop10",
        "sonnefinance2024postmortem",
        "zhou2023sok"
      ],
      "source_file": "techniques/T9.011-precision-loss-rounding-attack.md"
    },
    {
      "id": "OAK-T9.012",
      "name": "Initial Liquidity Sandwich Attack",
      "parent_tactics": [
        "OAK-T9"
      ],
      "maturity": "emerging",
      "chains": [
        "EVM (primary); any chain with a public mempool and AMM-based token-deployment pattern (Uniswap V2/V3, PancakeSwap, Raydium-equivalent AMMs)"
      ],
      "first_documented": "2020–2021 (the \"sniping\" pattern emerged with the Uniswap V2 token-deployment wave; the sandwich-at-addLiquidity variant is a refinement characterised by MEV researchers)",
      "aliases": [
        "token-launch sandwich",
        "addLiquidity snipe",
        "initial-liquidity front-run",
        "token-genesis sandwich",
        "liquidity-addition MEV"
      ],
      "citations": [
        "daian2019flashboys",
        "zhou2023sok"
      ],
      "source_file": "techniques/T9.012-initial-liquidity-sandwich-attack.md"
    },
    {
      "id": "OAK-T9.013",
      "name": "Slippage-Manipulation Sandwich Attack",
      "parent_tactics": [
        "OAK-T9"
      ],
      "maturity": "observed",
      "chains": [
        "EVM (primary — Uniswap-style AMMs with user-specified slippage tolerance); Solana (Jupiter DCA / limit-order slippage surface); any chain with an AMM that exposes user-configurable slippage parameters in swap transactions"
      ],
      "first_documented": "2020–2021 (slippage-manipulation attacks characterised alongside the MEV sandwich literature)",
      "aliases": [
        "slippage-tolerance exploitation",
        "max-slippage sandwich",
        "sandwich-via-slippage-setting",
        "slippage-override attack"
      ],
      "citations": [
        "daian2019flashboys",
        "zhou2023sok"
      ],
      "source_file": "techniques/T9.013-slippage-manipulation-sandwich-attack.md"
    },
    {
      "id": "OAK-T9.014",
      "name": "Protocol-Client Consensus Bug",
      "parent_tactics": [
        "OAK-T9"
      ],
      "maturity": "emerging",
      "chains": [
        "Bitcoin (canonical anchor); structurally generalisable to any blockchain whose consensus is determined by a reference-client implementation (Ethereum, Solana, Cosmos SDK chains, etc.)"
      ],
      "first_documented": "2010-08-15 (Bitcoin value overflow bug, block 74638, CVE-2010-5139)",
      "aliases": [
        "reference-client bug",
        "consensus-layer integer overflow",
        "client-implementation vulnerability",
        "protocol-level arithmetic bug",
        "consensus-code validation bypass"
      ],
      "citations": [],
      "source_file": "techniques/T9.014-protocol-client-consensus-bug.md"
    },
    {
      "id": "OAK-T9.015",
      "name": "Degenerate-Input Signature-Verification Bypass",
      "parent_tactics": [
        "OAK-T9"
      ],
      "maturity": "emerging",
      "chains": [
        "chain-agnostic (any runtime whose contracts verify signatures or proofs over an elliptic curve — EVM, Hedera, Cosmos, Solana, Move-family; the defect is in the verifier's input validation, not in the chain)"
      ],
      "first_documented": "2026-07 (Bonzo Lend / Supra on-demand oracle verifier — first documented on-chain crypto-theft anchor). The underlying cryptographic hazard is long-known in the protocol-engineering literature: subgroup-membership and identity-element handling are explicit requirements in the IRTF CFRG BLS-signature specification (`KeyValidate`, subgroup checks), and small-subgroup / invalid-curve attacks predate crypto by well over a decade.",
      "aliases": [
        "zero signature bypass",
        "identity-element forgery",
        "point-at-infinity attack",
        "small-subgroup attack",
        "missing subgroup check",
        "degenerate pairing input",
        "zeroed signature"
      ],
      "citations": [
        "coindeskbonzo2026",
        "cryptonewsbonzo2026",
        "cryptoslatebonzo2026",
        "theblockbonzo2026"
      ],
      "source_file": "techniques/T9.015-degenerate-input-signature-verification-bypass.md"
    }
  ],
  "mitigations": [
    {
      "id": "OAK-M01",
      "name": "Source-Bytecode Verification",
      "class": "detection",
      "audience": [
        "vendor",
        "risk-team",
        "venue"
      ],
      "maps_to_techniques": [
        "OAK-T1.001",
        "OAK-T1.003",
        "OAK-T1.004",
        "OAK-T1.005",
        "OAK-T2.004",
        "OAK-T6.001",
        "OAK-T6.003"
      ],
      "citations": [
        "certikfakeaudit",
        "chainalysis2025rug",
        "quillauditsbackdoor",
        "slowmist2024report"
      ],
      "source_file": "mitigations/OAK-M01-source-bytecode-verification.md"
    },
    {
      "id": "OAK-M02",
      "name": "Static-Analysis Pre-Deployment",
      "class": "architecture",
      "audience": [
        "protocol",
        "designer"
      ],
      "maps_to_techniques": [
        "OAK-T1.001",
        "OAK-T1.003",
        "OAK-T1.004",
        "OAK-T1.005",
        "OAK-T6.001",
        "OAK-T6.002",
        "OAK-T9.004",
        "OAK-T9.005",
        "OAK-T13.001"
      ],
      "citations": [
        "chainalysiseuler2023",
        "halborneuler2023",
        "osecpaymasters2025",
        "owaspscstop10",
        "ozaa4337audit",
        "slowmist2024report"
      ],
      "source_file": "mitigations/OAK-M02-static-analysis-pre-deployment.md"
    },
    {
      "id": "OAK-M03",
      "name": "Continuous Bytecode-Diff Monitoring",
      "class": "detection",
      "audience": [
        "vendor",
        "risk-team"
      ],
      "maps_to_techniques": [
        "OAK-T1.003",
        "OAK-T1.004",
        "OAK-T2.004",
        "OAK-T6.001",
        "OAK-T6.003",
        "OAK-T9.004",
        "OAK-T11.003"
      ],
      "citations": [
        "chainalysis2025rug",
        "halbornwintermute2022",
        "nomicproxybackdoor",
        "quillauditsbackdoor"
      ],
      "source_file": "mitigations/OAK-M03-continuous-bytecode-diff-monitoring.md"
    },
    {
      "id": "OAK-M04",
      "name": "Funder-Graph Clustering",
      "class": "detection",
      "audience": [
        "vendor",
        "risk-team"
      ],
      "maps_to_techniques": [
        "OAK-T2.001",
        "OAK-T3.001",
        "OAK-T3.002",
        "OAK-T3.003",
        "OAK-T8.001",
        "OAK-T8.002",
        "OAK-T1.001",
        "OAK-T2.004"
      ],
      "citations": [
        "chainalysis2024dprk",
        "chainalysis2025rug",
        "chainalysisprivacychain2024",
        "dydx2024sybil",
        "slowmist2024report"
      ],
      "source_file": "mitigations/OAK-M04-funder-graph-clustering.md"
    },
    {
      "id": "OAK-M05",
      "name": "Authority-Graph Enumeration",
      "class": "detection",
      "audience": [
        "custody-customer",
        "risk-team",
        "vendor"
      ],
      "maps_to_techniques": [
        "OAK-T1.003",
        "OAK-T1.004",
        "OAK-T9.003",
        "OAK-T9.004",
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T11.003"
      ],
      "citations": [
        "chainalysisbadger2021",
        "checkpoint2023drainers",
        "halbornwintermute2022",
        "ofac2022tornado"
      ],
      "source_file": "mitigations/OAK-M05-authority-graph-enumeration.md"
    },
    {
      "id": "OAK-M06",
      "name": "Mempool / Pre-Block Telemetry",
      "class": "detection",
      "audience": [
        "vendor",
        "trader",
        "protocol"
      ],
      "maps_to_techniques": [
        "OAK-T5.004",
        "OAK-T13.002",
        "OAK-T14.002"
      ],
      "citations": [
        "blockpi2023bundlermempool",
        "blocksecmevboost2023",
        "bloxroutemevboost2023",
        "dojmevbros2024",
        "eigenphi2023aamev",
        "eigenphijared2023",
        "etherspot2023bundlermev",
        "fastlane2024erc4337mev",
        "flashbotsequivocation2023",
        "flashbotsmevboost2023",
        "mevwatch2024",
        "paradigmpbstime2023"
      ],
      "source_file": "mitigations/OAK-M06-mempool-pre-block-telemetry.md"
    },
    {
      "id": "OAK-M07",
      "name": "Cross-Chain Attribution Graph",
      "class": "detection",
      "audience": [
        "vendor",
        "risk-team",
        "venue"
      ],
      "maps_to_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T7.003",
        "OAK-T7.004",
        "OAK-T7.005",
        "OAK-T7.006",
        "OAK-T8.002",
        "OAK-T11.001"
      ],
      "citations": [
        "chainalysis2022nft",
        "chainalysis2024dprk",
        "chainalysis2024laundering",
        "chainalysisprivacychain2024",
        "coindeskthorchainlazarus2025",
        "crystalwazirx2024",
        "ellipticronin2022",
        "trmlabs2024nomadextradition"
      ],
      "source_file": "mitigations/OAK-M07-cross-chain-attribution-graph.md"
    },
    {
      "id": "OAK-M08",
      "name": "Per-Spender Approval Audit and Revocation",
      "class": "wallet-ux",
      "audience": [
        "wallet",
        "custody-customer",
        "vendor"
      ],
      "maps_to_techniques": [
        "OAK-T4.001",
        "OAK-T4.004",
        "OAK-T4.005",
        "OAK-T4.006"
      ],
      "citations": [
        "checkpoint2023drainers",
        "rektcurve2022",
        "slowmist2024report",
        "theblock2022boredape"
      ],
      "source_file": "mitigations/OAK-M08-per-spender-approval-audit-and-revocation.md"
    },
    {
      "id": "OAK-M09",
      "name": "TWAP + Multi-Venue Oracle with Deviation Circuit-Breaker",
      "class": "architecture",
      "audience": [
        "protocol",
        "designer"
      ],
      "maps_to_techniques": [
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "citations": [
        "cftcmango2023",
        "chainalysis2025rug",
        "owaspscstop10",
        "zhou2023sok"
      ],
      "source_file": "mitigations/OAK-M09-twap-multi-venue-oracle-with-deviation-circuit-breaker.md"
    },
    {
      "id": "OAK-M10",
      "name": "Checks-Effects-Interactions and ReentrancyGuard",
      "class": "architecture",
      "audience": [
        "protocol",
        "designer"
      ],
      "maps_to_techniques": [
        "OAK-T9.005",
        "OAK-T9.002"
      ],
      "citations": [
        "creamfinance2021postmortem",
        "daoreentrancy2016retrospective",
        "halborncream2021oct",
        "muditgupta2021cream",
        "owaspscstop10",
        "vyperpostmortem2023",
        "zhou2023sok"
      ],
      "source_file": "mitigations/OAK-M10-checks-effects-interactions-and-reentrancy-guard.md"
    },
    {
      "id": "OAK-M11",
      "name": "Rate-Limiting and Per-Block Caps",
      "class": "architecture",
      "audience": [
        "protocol",
        "designer"
      ],
      "maps_to_techniques": [
        "OAK-T5.001",
        "OAK-T5.002",
        "OAK-T9.001",
        "OAK-T9.002",
        "OAK-T10.001",
        "OAK-T10.002"
      ],
      "citations": [
        "chainalysis2025rug",
        "ellipticronin2022",
        "ethfoundationdaohardfork2016",
        "mandiantnomad2022",
        "owaspscstop10",
        "rektcurve2022",
        "vyperpostmortem2023"
      ],
      "source_file": "mitigations/OAK-M11-rate-limiting-and-per-block-caps.md"
    },
    {
      "id": "OAK-M12",
      "name": "Per-Message Replay Binding",
      "class": "architecture",
      "audience": [
        "protocol",
        "designer (bridge / cross-chain)"
      ],
      "maps_to_techniques": [
        "OAK-T10.002",
        "OAK-T10.003"
      ],
      "citations": [
        "bhuptanioptbridges2022",
        "halbornnomadoptimistic2022",
        "mandiantnomad2022",
        "zhou2023sok"
      ],
      "source_file": "mitigations/OAK-M12-per-message-replay-binding.md"
    },
    {
      "id": "OAK-M13",
      "name": "Long Challenge Window with Economic Challenger Incentives",
      "class": "architecture",
      "audience": [
        "protocol",
        "designer (optimistic-bridge / rollup)"
      ],
      "maps_to_techniques": [
        "OAK-T10.004"
      ],
      "citations": [
        "bhuptanioptbridges2022",
        "halbornnomadoptimistic2022",
        "hollowvictory2025",
        "zhou2023sok"
      ],
      "source_file": "mitigations/OAK-M13-long-challenge-window-with-economic-challenger-incentives.md"
    },
    {
      "id": "OAK-M14",
      "name": "Multi-Prover Redundancy",
      "class": "architecture",
      "audience": [
        "protocol",
        "designer (zk-bridge / zk-rollup)"
      ],
      "maps_to_techniques": [
        "OAK-T10.005"
      ],
      "citations": [
        "soksnarkvulns2024",
        "verichainsdragonberry2022",
        "xie2022zkbridge",
        "zhou2023sok",
        "zkbugtracker"
      ],
      "source_file": "mitigations/OAK-M14-multi-prover-redundancy.md"
    },
    {
      "id": "OAK-M15",
      "name": "Threshold Signing with Operator Separation",
      "class": "architecture",
      "audience": [
        "custody-customer",
        "custody-vendor",
        "protocol (bridge)"
      ],
      "maps_to_techniques": [
        "OAK-T10.001",
        "OAK-T11.001",
        "OAK-T11.003"
      ],
      "citations": [
        "chainalysis2024dprk",
        "crystalwazirx2024",
        "ellipticharmony2022",
        "ellipticronin2022",
        "fbiharmony2023",
        "halbornharmony2022",
        "halbornmultichain2023",
        "wazirxwiki2024"
      ],
      "source_file": "mitigations/OAK-M15-threshold-signing-with-operator-separation.md"
    },
    {
      "id": "OAK-M16",
      "name": "Pre-Deployment Audit and Formal Verification",
      "class": "architecture",
      "audience": [
        "protocol",
        "designer"
      ],
      "maps_to_techniques": [
        "OAK-T1.001",
        "OAK-T1.003",
        "OAK-T1.004",
        "OAK-T6.001",
        "OAK-T6.002",
        "OAK-T6.003",
        "OAK-T6.004",
        "OAK-T9.001",
        "OAK-T9.002",
        "OAK-T9.003",
        "OAK-T9.004",
        "OAK-T9.005",
        "OAK-T10.001",
        "OAK-T10.002",
        "OAK-T10.003",
        "OAK-T10.004",
        "OAK-T10.005"
      ],
      "citations": [
        "certikfakeaudit",
        "chainalysis2025rug",
        "daoreentrancy2016retrospective",
        "dlnewsswaprum2023",
        "halbornnomadoptimistic2022",
        "owaspscstop10",
        "slowmist2024report",
        "soksnarkvulns2024",
        "verichainsdragonberry2022",
        "zhou2023sok"
      ],
      "source_file": "mitigations/OAK-M16-pre-deployment-audit-and-formal-verification.md"
    },
    {
      "id": "OAK-M17",
      "name": "Time-Locked Governance and Multi-Block Quorum",
      "class": "architecture",
      "audience": [
        "protocol",
        "designer (governance)"
      ],
      "maps_to_techniques": [
        "OAK-T9.003"
      ],
      "citations": [
        "owaspscstop10",
        "zhou2023sok"
      ],
      "source_file": "mitigations/OAK-M17-time-locked-governance-and-multi-block-quorum.md"
    },
    {
      "id": "OAK-M18",
      "name": "Out-of-Band Destination Verification",
      "class": "operational",
      "audience": [
        "custody-customer",
        "custody-vendor"
      ],
      "maps_to_techniques": [
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T11.003",
        "OAK-T4.001",
        "OAK-T4.002",
        "OAK-T4.003",
        "OAK-T4.004",
        "OAK-T4.005",
        "OAK-T4.006"
      ],
      "citations": [
        "chainalysis2024dprk",
        "chainalysis2024poisoning",
        "checkpoint2023drainers",
        "crystalwazirx2024",
        "ellipticatomic2023",
        "slowmist2024report",
        "tsuchiya2025poisoning",
        "wazirxwiki2024"
      ],
      "source_file": "mitigations/OAK-M18-out-of-band-destination-verification.md"
    },
    {
      "id": "OAK-M19",
      "name": "Air-Gap Cold-Wallet Signing",
      "class": "operational",
      "audience": [
        "custody-customer"
      ],
      "maps_to_techniques": [
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T11.003"
      ],
      "citations": [
        "chainalysis2024dprk",
        "ellipticatomic2023",
        "mandiantradiant2024",
        "radiantpostmortem2024"
      ],
      "source_file": "mitigations/OAK-M19-air-gap-cold-wallet-signing.md"
    },
    {
      "id": "OAK-M20",
      "name": "Vendor Breach-Notification SLA",
      "class": "operational",
      "audience": [
        "custody-customer",
        "risk-team",
        "venue"
      ],
      "maps_to_techniques": [
        "OAK-T11.001",
        "OAK-T11.002"
      ],
      "citations": [
        "chainalysis2024dprk",
        "crystalwazirx2024",
        "ellipticatomic2023",
        "radiantpostmortem2024"
      ],
      "source_file": "mitigations/OAK-M20-vendor-breach-notification-sla.md"
    },
    {
      "id": "OAK-M21",
      "name": "Anti-Phishing Training for Privileged Staff",
      "class": "operational",
      "audience": [
        "custody-customer",
        "custody-vendor",
        "protocol"
      ],
      "maps_to_techniques": [
        "OAK-T11.001",
        "OAK-T11.002"
      ],
      "citations": [
        "chainalysis2024dprk",
        "fbidmm2024",
        "mandiantradiant2024",
        "microsoftcitrineradiant2024",
        "radiantpostmortem2024"
      ],
      "source_file": "mitigations/OAK-M21-anti-phishing-training-privileged-staff.md"
    },
    {
      "id": "OAK-M22",
      "name": "Rotate-on-Disclosure Discipline",
      "class": "operational",
      "audience": [
        "custody-customer",
        "custody-vendor",
        "protocol"
      ],
      "maps_to_techniques": [
        "OAK-T1.003",
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T11.003",
        "OAK-T9.004"
      ],
      "citations": [
        "chainalysis2024dprk",
        "crystalwazirx2024",
        "halbornwintermute2022",
        "radiantpostmortem2024"
      ],
      "source_file": "mitigations/OAK-M22-rotate-on-disclosure-discipline.md"
    },
    {
      "id": "OAK-M23",
      "name": "Audit-Attestation Public-Registry Verification",
      "class": "venue",
      "audience": [
        "venue",
        "risk-team",
        "trader"
      ],
      "maps_to_techniques": [
        "OAK-T6.001",
        "OAK-T6.002",
        "OAK-T6.003",
        "OAK-T6.004",
        "OAK-T1.001"
      ],
      "citations": [
        "certikfakeaudit",
        "chainalysis2025rug",
        "dlnewsswaprum2023",
        "slowmist2024report"
      ],
      "source_file": "mitigations/OAK-M23-audit-attestation-public-registry-verification.md"
    },
    {
      "id": "OAK-M24",
      "name": "Out-of-Band Audit-Engagement Verification",
      "class": "venue",
      "audience": [
        "venue",
        "risk-team",
        "trader"
      ],
      "maps_to_techniques": [
        "OAK-T6.002",
        "OAK-T6.004"
      ],
      "citations": [
        "certikfakeaudit",
        "chainalysis2025rug",
        "dlnewsswaprum2023",
        "slowmist2024report"
      ],
      "source_file": "mitigations/OAK-M24-out-of-band-audit-engagement-verification.md"
    },
    {
      "id": "OAK-M25",
      "name": "Listing-Time Source-Verification + Audit-Status Gate",
      "class": "venue",
      "audience": [
        "venue (CEX, DEX aggregator)",
        "aggregator (token-data, market-data)",
        "launchpad"
      ],
      "maps_to_techniques": [
        "OAK-T1.001",
        "OAK-T1.002",
        "OAK-T1.003",
        "OAK-T1.004",
        "OAK-T1.005",
        "OAK-T2.001",
        "OAK-T2.002",
        "OAK-T2.003",
        "OAK-T2.004",
        "OAK-T6.001",
        "OAK-T6.002",
        "OAK-T6.003",
        "OAK-T6.004"
      ],
      "citations": [
        "certikfakeaudit",
        "chainalysis2025rug",
        "slowmist2024report",
        "torres2019",
        "trmsquid2021"
      ],
      "source_file": "mitigations/OAK-M25-listing-time-source-verification-and-audit-status-gate.md"
    },
    {
      "id": "OAK-M26",
      "name": "Wash-Trade-Rate Metrics at Marketplace Layer",
      "class": "venue",
      "audience": [
        "venue (NFT marketplace, DEX)",
        "aggregator (analytics)",
        "risk-team"
      ],
      "maps_to_techniques": [
        "OAK-T3.002",
        "OAK-T7.004",
        "OAK-T12.001"
      ],
      "citations": [
        "chainalysis2022nft",
        "chainalysis2024laundering",
        "theblock2022boredape"
      ],
      "source_file": "mitigations/OAK-M26-wash-trade-rate-metrics-at-marketplace-layer.md"
    },
    {
      "id": "OAK-M27",
      "name": "Travel Rule and KYC at Privacy-Chain Boundary",
      "class": "venue",
      "audience": [
        "venue (CEX, OTC desk, instant-swap service)",
        "regulator",
        "risk-team"
      ],
      "maps_to_techniques": [
        "OAK-T7.002",
        "OAK-T7.003",
        "OAK-T7.005"
      ],
      "citations": [
        "binancexmrdelist2024",
        "chainalysis2024dprk",
        "chainalysis2024laundering",
        "chainalysisprivacychain2024",
        "coindeskthorchainlazarus2025",
        "ofac2022tornado"
      ],
      "source_file": "mitigations/OAK-M27-travel-rule-and-kyc-at-privacy-chain-boundary.md"
    },
    {
      "id": "OAK-M28",
      "name": "Token-Unlock Calendar Integration",
      "class": "venue",
      "audience": [
        "venue (DEX aggregator, CEX, market-data aggregator)",
        "risk-team",
        "trader"
      ],
      "maps_to_techniques": [
        "OAK-T5.006"
      ],
      "citations": [
        "chainalysis2025rug",
        "cryptorank2026unlock",
        "defillama2026unlocks",
        "tokenunlocks2026platform"
      ],
      "source_file": "mitigations/OAK-M28-token-unlock-calendar-integration.md"
    },
    {
      "id": "OAK-M29",
      "name": "Full-Address Verification and Lookalike Detection",
      "class": "wallet-ux",
      "audience": [
        "wallet (mobile, browser-extension, hardware-wallet companion)",
        "custody-customer",
        "risk-team"
      ],
      "maps_to_techniques": [
        "OAK-T4.003"
      ],
      "citations": [
        "chainalysis2024poisoning",
        "tsuchiya2025poisoning"
      ],
      "source_file": "mitigations/OAK-M29-full-address-verification-and-lookalike-detection.md"
    },
    {
      "id": "OAK-M30",
      "name": "Per-dApp Domain and App-Store-Package Allowlist",
      "class": "wallet-ux",
      "audience": [
        "wallet (mobile, browser-extension)",
        "custody-customer"
      ],
      "maps_to_techniques": [
        "OAK-T4.001",
        "OAK-T4.005",
        "OAK-T4.006"
      ],
      "citations": [
        "checkpoint2023drainers",
        "slowmist2024report",
        "theblock2022boredape"
      ],
      "source_file": "mitigations/OAK-M30-per-dapp-domain-and-app-store-package-allowlist.md"
    },
    {
      "id": "OAK-M31",
      "name": "EIP-712 Permit Display and Signing-Risk Heuristics",
      "class": "wallet-ux",
      "audience": [
        "wallet (mobile, browser-extension, hardware-wallet companion)",
        "custody-customer"
      ],
      "maps_to_techniques": [
        "OAK-T4.001",
        "OAK-T4.004",
        "OAK-T4.005"
      ],
      "citations": [
        "checkpoint2023drainers",
        "slowmist2024report",
        "theblock2022boredape"
      ],
      "source_file": "mitigations/OAK-M31-eip-712-permit-display-and-signing-risk-heuristics.md"
    },
    {
      "id": "OAK-M32",
      "name": "Bug Bounty Programs",
      "class": "operational",
      "audience": [
        "protocol",
        "designer",
        "vendor"
      ],
      "maps_to_techniques": [
        "OAK-T1.001",
        "OAK-T1.002",
        "OAK-T1.003",
        "OAK-T1.004",
        "OAK-T1.005",
        "OAK-T6.001",
        "OAK-T6.002",
        "OAK-T6.003",
        "OAK-T6.004",
        "OAK-T9.001",
        "OAK-T9.002",
        "OAK-T9.003",
        "OAK-T9.004",
        "OAK-T9.005",
        "OAK-T10.001",
        "OAK-T10.002",
        "OAK-T10.003",
        "OAK-T10.004",
        "OAK-T10.005"
      ],
      "citations": [
        "chainalysis2024dprk",
        "chainalysiseuler2023",
        "immunefikream2021",
        "slowmist2024report",
        "zhou2023sok"
      ],
      "source_file": "mitigations/OAK-M32-bug-bounty-programs.md"
    },
    {
      "id": "OAK-M33",
      "name": "Decentralized Insurance Protocols",
      "class": "operational",
      "audience": [
        "trader",
        "protocol",
        "custody-customer"
      ],
      "maps_to_techniques": [
        "OAK-T9.001",
        "OAK-T9.002",
        "OAK-T9.003",
        "OAK-T9.004",
        "OAK-T9.005",
        "OAK-T10.001",
        "OAK-T10.002",
        "OAK-T10.003",
        "OAK-T10.004",
        "OAK-T10.005",
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T11.003"
      ],
      "citations": [
        "chainalysis2024dprk",
        "chainalysis2025rug",
        "chainalysiseuler2023",
        "crystalwazirx2024",
        "slowmist2024report",
        "zhou2023sok"
      ],
      "source_file": "mitigations/OAK-M33-decentralized-insurance-protocols.md"
    },
    {
      "id": "OAK-M34",
      "name": "Pause-by-Default Emergency Pause",
      "class": "architecture",
      "audience": [
        "protocol",
        "designer"
      ],
      "maps_to_techniques": [
        "OAK-T9.001",
        "OAK-T9.002",
        "OAK-T9.003",
        "OAK-T9.004",
        "OAK-T9.005",
        "OAK-T10.001",
        "OAK-T10.002",
        "OAK-T10.003",
        "OAK-T10.004",
        "OAK-T10.005",
        "OAK-T11.003"
      ],
      "citations": [
        "blocksecsaddle2022",
        "chainalysiseuler2023",
        "crystalwazirx2024",
        "openzeppelinupgradesstorage",
        "saddleincidentreport2022",
        "zhou2023sok"
      ],
      "source_file": "mitigations/OAK-M34-pause-by-default-emergency-pause.md"
    },
    {
      "id": "OAK-M35",
      "name": "Whitehat-Rescue Coordination",
      "class": "operational",
      "audience": [
        "protocol",
        "designer",
        "vendor"
      ],
      "maps_to_techniques": [
        "OAK-T9.001",
        "OAK-T9.002",
        "OAK-T9.003",
        "OAK-T9.004",
        "OAK-T9.005",
        "OAK-T10.001",
        "OAK-T10.002",
        "OAK-T10.003",
        "OAK-T10.004",
        "OAK-T10.005",
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T11.003"
      ],
      "citations": [
        "blocksec2023euler",
        "chainalysis2024dprk",
        "chainalysiseuler2023",
        "elliptipeuler2023",
        "eulerlabs2023statement",
        "halborneuler2023",
        "hypernativeronin2024",
        "ronin2024postmortem",
        "skymavisronin2024"
      ],
      "source_file": "mitigations/OAK-M35-whitehat-rescue-coordination.md"
    },
    {
      "id": "OAK-M36",
      "name": "Proof-of-Reserves Cryptographic Auditing",
      "class": "venue",
      "audience": [
        "venue (CEX)",
        "risk-team",
        "regulator"
      ],
      "maps_to_techniques": [
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T11.003"
      ],
      "citations": [
        "bitfinexpostmortem2016",
        "chainalysis2024dprk",
        "mtgoxbankruptcy2014",
        "mtgoxtrustee2024",
        "wizsecmtgox2015",
        "wizsecmtgox2017",
        "wizsecmtgox2020"
      ],
      "source_file": "mitigations/OAK-M36-proof-of-reserves-cryptographic-auditing.md"
    },
    {
      "id": "OAK-M37",
      "name": "HSM and MPC Custody Architectures",
      "class": "operational",
      "audience": [
        "custody-customer",
        "custody-vendor",
        "protocol (treasury)",
        "risk-team"
      ],
      "maps_to_techniques": [
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T11.003",
        "OAK-T10.001"
      ],
      "citations": [
        "chainalysis2024dprk",
        "ellipticatomic2023",
        "fbidmm2024",
        "halbornwintermute2022",
        "mandiantradiant2024"
      ],
      "source_file": "mitigations/OAK-M37-hsm-mpc-custody.md"
    },
    {
      "id": "OAK-M38",
      "name": "Time-Windowed Withdrawal Limits",
      "class": "architecture",
      "audience": [
        "protocol",
        "designer",
        "custody-vendor"
      ],
      "maps_to_techniques": [
        "OAK-T5.001",
        "OAK-T5.002",
        "OAK-T5.005",
        "OAK-T9.001",
        "OAK-T9.002",
        "OAK-T9.004",
        "OAK-T9.005",
        "OAK-T10.001",
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T11.003"
      ],
      "citations": [
        "chainalysis2024dprk",
        "chainalysis2024lockbit",
        "chainalysis2025rug",
        "ellipticronin2022",
        "halbornwintermute2022"
      ],
      "source_file": "mitigations/OAK-M38-time-windowed-withdrawal-limits.md"
    },
    {
      "id": "OAK-M39",
      "name": "Cross-Protocol Watcher Network",
      "class": "detection",
      "audience": [
        "vendor",
        "risk-team",
        "protocol",
        "designer"
      ],
      "maps_to_techniques": [
        "OAK-T9.001",
        "OAK-T9.002",
        "OAK-T9.003",
        "OAK-T9.004",
        "OAK-T9.005",
        "OAK-T10.001",
        "OAK-T10.002",
        "OAK-T10.003",
        "OAK-T10.004",
        "OAK-T10.005",
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T11.003",
        "OAK-T8.001",
        "OAK-T8.002"
      ],
      "citations": [
        "blocksecparaspace2023",
        "blocksecronin2024",
        "chainalysis2024dprk",
        "hypernativeronin2024",
        "mandiantradiant2024"
      ],
      "source_file": "mitigations/OAK-M39-cross-protocol-watcher-network.md"
    },
    {
      "id": "OAK-M40",
      "name": "Supply-Chain Package Integrity",
      "class": "operational",
      "audience": [
        "protocol (engineering staff)",
        "designer",
        "custody-customer",
        "custody-vendor",
        "wallet"
      ],
      "maps_to_techniques": [
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T1.003",
        "OAK-T4.001",
        "OAK-T4.002",
        "OAK-T4.005",
        "OAK-T4.006"
      ],
      "citations": [
        "chainalysis2024dprk",
        "ellipticatomic2023",
        "mandiant3cx2023",
        "mandiantucsx2023",
        "unit42beavertail2023"
      ],
      "source_file": "mitigations/OAK-M40-supply-chain-package-integrity.md"
    },
    {
      "id": "OAK-M41",
      "name": "Asset Freeze and Confiscate Coordination Workflow",
      "class": "venue",
      "audience": [
        "venue (CEX, OTC desk, stablecoin issuer, bridge protocol)",
        "regulator",
        "law-enforcement agency",
        "risk-team"
      ],
      "maps_to_techniques": [
        "OAK-T7.002",
        "OAK-T7.003",
        "OAK-T7.006",
        "OAK-T7.007",
        "OAK-T7.008",
        "OAK-T5.008"
      ],
      "citations": [],
      "source_file": "mitigations/OAK-M41-asset-freeze-confiscate-coordination-workflow.md"
    },
    {
      "id": "OAK-M42",
      "name": "SAR/STR Filing and Financial Intelligence Feedback Loop",
      "class": "venue",
      "audience": [
        "venue (CEX, OTC desk, custodian, stablecoin issuer)",
        "regulator",
        "financial-intelligence unit (FIU)",
        "risk-team"
      ],
      "maps_to_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T7.003",
        "OAK-T7.005",
        "OAK-T5.008"
      ],
      "citations": [],
      "source_file": "mitigations/OAK-M42-sar-str-filing-and-financial-intelligence-feedback.md"
    },
    {
      "id": "OAK-M43",
      "name": "KYT Operational Practice and Cross-VASP Coordination",
      "class": "venue",
      "audience": [
        "venue (CEX, OTC desk, custodian, bridge protocol)",
        "compliance-provider vendor",
        "risk-team"
      ],
      "maps_to_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T7.003",
        "OAK-T7.006",
        "OAK-T7.007",
        "OAK-T7.008",
        "OAK-T8.001",
        "OAK-T8.002"
      ],
      "citations": [],
      "source_file": "mitigations/OAK-M43-kyt-operational-practice-and-cross-vasp-coordination.md"
    },
    {
      "id": "OAK-M44",
      "name": "Seed-Phrase Disclosure Refusal and Storage Isolation",
      "class": "user-behavioural",
      "audience": [
        "retail-user",
        "custody-customer",
        "wallet",
        "vendor"
      ],
      "maps_to_techniques": [
        "OAK-T11.006",
        "OAK-T11.006.001",
        "OAK-T11.006.002",
        "OAK-T11.007.003",
        "OAK-T4.010"
      ],
      "citations": [],
      "source_file": "mitigations/OAK-M44-seed-phrase-disclosure-refusal.md"
    },
    {
      "id": "OAK-M45",
      "name": "Inbound-Contact Refusal and Out-of-Band Callback",
      "class": "user-behavioural",
      "audience": [
        "retail-user",
        "custody-customer",
        "venue",
        "vendor"
      ],
      "maps_to_techniques": [
        "OAK-T11.007.003",
        "OAK-T11.005.001",
        "OAK-T11.005.002",
        "OAK-T4.010"
      ],
      "citations": [],
      "source_file": "mitigations/OAK-M45-inbound-contact-refusal.md"
    },
    {
      "id": "OAK-M46",
      "name": "Small-Test-Withdrawal Invariant and Advance-Fee Refusal",
      "class": "user-behavioural",
      "audience": [
        "retail-user",
        "custody-customer",
        "venue",
        "regulator"
      ],
      "maps_to_techniques": [
        "OAK-T11.005",
        "OAK-T11.005.001",
        "OAK-T11.005.002",
        "OAK-T11.005.003",
        "OAK-T11.010"
      ],
      "citations": [],
      "source_file": "mitigations/OAK-M46-small-test-withdrawal-invariant.md"
    },
    {
      "id": "OAK-M47",
      "name": "First-Party Acquisition and Self-Typed Navigation",
      "class": "user-behavioural",
      "audience": [
        "retail-user",
        "custody-customer",
        "wallet",
        "vendor"
      ],
      "maps_to_techniques": [
        "OAK-T11.007.001",
        "OAK-T4.008",
        "OAK-T4.010",
        "OAK-T6.006",
        "OAK-T11.002"
      ],
      "citations": [],
      "source_file": "mitigations/OAK-M47-first-party-acquisition.md"
    },
    {
      "id": "OAK-M48",
      "name": "Unsolicited-Code Quarantine and Pre-Execution Manifest Review",
      "class": "operational",
      "audience": [
        "developer",
        "protocol",
        "custody-vendor",
        "trading-desk"
      ],
      "maps_to_techniques": [
        "OAK-T15.001",
        "OAK-T15.003",
        "OAK-T11.009",
        "OAK-T15.002"
      ],
      "citations": [],
      "source_file": "mitigations/OAK-M48-unsolicited-code-quarantine.md"
    }
  ],
  "software": [
    {
      "id": "OAK-S01",
      "name": "Inferno Drainer",
      "type": "drainer-kit",
      "aliases": [
        "Inferno",
        "Inferno DaaS",
        "Discord-link drainer kit\" (per affiliate-channel framing in `[checkpoint2023drainers]`)."
      ],
      "active": "sunset — Inferno publicly announced its shutdown on Telegram on November 26, 2023 (`[slowmist2024report]`). Affiliates and tooling re-emerged in successor families through 2024 (Angel Drainer / OAK-S02 absorbed a meaningful share of the Inferno affiliate base, but the November 2023 announcement is the primary-source shutdown event, not an October 2024 \"handover\"). The kit-and-affiliate-base persistence under successor branding is the structural OAK-G02 lesson; the original-branded operation was already retired by end-2023.",
      "first_observed": "approximately 2022, contemporaneous with broader Permit2 adoption.",
      "host_platforms": [],
      "used_by_groups": [
        "OAK-G02"
      ],
      "observed_techniques": [
        "OAK-T4.001",
        "OAK-T4.002",
        "OAK-T4.004",
        "OAK-T4.005",
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T8.001",
        "OAK-T8.002"
      ],
      "citations": [
        "chainalysis2024dprk",
        "checkpoint2023drainers",
        "slowmist2024report"
      ],
      "source_file": "software/OAK-S01-inferno-drainer.md"
    },
    {
      "id": "OAK-S02",
      "name": "Angel Drainer",
      "type": "drainer-kit",
      "aliases": [
        "Angel",
        "Angel DaaS",
        "Angel-X\" (occasional rebranding suffix observed in industry forensic posts)."
      ],
      "active": "yes — in market since approximately early 2023; received the Inferno Drainer (OAK-S01) affiliate base and infrastructure tooling in the October 19, 2024 service-layer handover (`[slowmist2024report]`); primary heir to Inferno's market share through end-of-2024.",
      "first_observed": "approximately early 2023.",
      "host_platforms": [],
      "used_by_groups": [
        "OAK-G02"
      ],
      "observed_techniques": [
        "OAK-T4.001",
        "OAK-T4.002",
        "OAK-T4.004",
        "OAK-T4.005",
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T8.001",
        "OAK-T8.002"
      ],
      "citations": [
        "checkpoint2023drainers",
        "slowmist2024report"
      ],
      "source_file": "software/OAK-S02-angel-drainer.md"
    },
    {
      "id": "OAK-S03",
      "name": "Pink Drainer",
      "type": "drainer-kit",
      "aliases": [
        "Pink",
        "Pinkdrainer",
        "Pink-X\" (occasional industry shorthand for the operator-of-record team behind the kit)."
      ],
      "active": "yes — in market since approximately mid-2023.",
      "first_observed": "approximately mid-2023.",
      "host_platforms": [],
      "used_by_groups": [
        "OAK-G02"
      ],
      "observed_techniques": [
        "OAK-T4.001",
        "OAK-T4.002",
        "OAK-T4.004",
        "OAK-T4.005",
        "OAK-T4.006",
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T8.001"
      ],
      "citations": [
        "checkpoint2023drainers",
        "scamsniffer2024pink",
        "slowmist2024report"
      ],
      "source_file": "software/OAK-S03-pink-drainer.md"
    },
    {
      "id": "OAK-S04",
      "name": "Monkey Drainer",
      "type": "drainer-kit",
      "aliases": [
        "Monkey",
        "Monkey-Drainer.eth\" (one of the historically-associated naming patterns in industry forensic posts)."
      ],
      "active": "sunset — operator announced retirement in approximately March 2023, framed publicly as burn-out / \"moving on\" rather than as a transfer of operations to a successor; affiliate base is generally understood to have migrated into Inferno (OAK-S01) and other contemporaneous kits.",
      "first_observed": "approximately 2022.",
      "host_platforms": [],
      "used_by_groups": [
        "OAK-G02"
      ],
      "observed_techniques": [
        "OAK-T4.001",
        "OAK-T4.004",
        "OAK-T4.005",
        "OAK-T7.001",
        "OAK-T8.001"
      ],
      "citations": [
        "checkpoint2023drainers",
        "slowmist2024report",
        "zachxbtmonkey2023"
      ],
      "source_file": "software/OAK-S04-monkey-drainer.md"
    },
    {
      "id": "OAK-S05",
      "name": "Venom Drainer",
      "type": "drainer-kit",
      "aliases": [
        "Venom",
        "Venom DaaS."
      ],
      "active": "yes — in market since approximately mid-2023.",
      "first_observed": "approximately mid-2023.",
      "host_platforms": [],
      "used_by_groups": [
        "OAK-G02"
      ],
      "observed_techniques": [
        "OAK-T4.001",
        "OAK-T4.004",
        "OAK-T4.005",
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T8.001"
      ],
      "citations": [
        "checkpoint2023drainers",
        "slowmist2024report"
      ],
      "source_file": "software/OAK-S05-venom-drainer.md"
    },
    {
      "id": "OAK-S06",
      "name": "Vanilla Drainer",
      "type": "drainer-kit",
      "aliases": [
        "Vanilla",
        "Vanilla DaaS."
      ],
      "active": "yes — in market since approximately 2024; newer entrant in the OAK-G02 category.",
      "first_observed": "approximately 2024 (industry forensic posts begin tracking the brand as a distinct kit in this period).",
      "host_platforms": [],
      "used_by_groups": [
        "OAK-G02"
      ],
      "observed_techniques": [
        "OAK-T4.001",
        "OAK-T4.004",
        "OAK-T4.005",
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T8.001",
        "OAK-T8.002"
      ],
      "citations": [
        "checkpoint2023drainers",
        "scamsniffer2024lineage",
        "slowmist2024report"
      ],
      "source_file": "software/OAK-S06-vanilla-drainer.md"
    },
    {
      "id": "OAK-S07",
      "name": "Chick Drainer",
      "type": "drainer-kit",
      "aliases": [
        "Chick",
        "Chick DaaS."
      ],
      "active": "yes — in market since approximately 2024; recent entrant in the OAK-G02 category cited in SlowMist's cohort tracking.",
      "first_observed": "approximately 2024.",
      "host_platforms": [],
      "used_by_groups": [
        "OAK-G02"
      ],
      "observed_techniques": [
        "OAK-T4.001",
        "OAK-T4.004",
        "OAK-T4.005",
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T8.001"
      ],
      "citations": [
        "checkpoint2023drainers",
        "slowmist2024report"
      ],
      "source_file": "software/OAK-S07-chick-drainer.md"
    },
    {
      "id": "OAK-S08",
      "name": "TraderTraitor",
      "type": "malware",
      "aliases": [
        "TraderTraitor (FBI / CISA naming for the DPRK cross-platform job-lure trojan family); naming overlaps with the broader FBI-tracked DPRK-crypto-theft operator label of the same name (the malware family and the operator-cluster nomenclature were aligned by the U.S. government in the April 2022 advisory rather than separated). Industry-side aliases for related/derived loaders include \"JS_TraderTraitor\" (npm-package-delivery variants)",
        "ManuscryptCrypto\" sub-family overlaps as documented by Kaspersky and Mandiant",
        "and \"Hidden Risk\" / \"RustBucket\" successors tracked separately by SentinelOne and Jamf for macOS evolution."
      ],
      "active": "yes",
      "first_observed": "2022-04 (CISA AA22-108A canonical advisory date; underlying campaign activity tracked by FBI from 2020 forward).",
      "host_platforms": [
        "cross-platform (macOS-focused — both Intel and Apple Silicon builds documented; Windows builds also distributed via the same lure infrastructure; Linux builds reported in narrower vendor-corroborated cases)."
      ],
      "used_by_groups": [
        "OAK-G01"
      ],
      "observed_techniques": [
        "OAK-T11.001",
        "OAK-T11.002"
      ],
      "citations": [
        "chainalysis2024dprk",
        "chainalysisdprktradertraitor",
        "cisaaa22108a",
        "fbidmm2024",
        "mandiantradiant2024"
      ],
      "source_file": "software/OAK-S08-tradertraitor.md"
    },
    {
      "id": "OAK-S09",
      "name": "AppleJeus",
      "type": "malware",
      "aliases": [
        "AppleJeus (Kaspersky-original 2018 naming, retained by CISA / FBI as canonical); UNC4736 (Mandiant operator-cluster designation that runs the AppleJeus toolset alongside related macOS payloads); Citrine Sleet (Microsoft, post-2023 weather-system naming convention); CryptoCore (overlapping but distinct industry naming used by F-Secure / WithSecure for related DPRK macOS activity); BLINDINGCAN",
        "COPPERHEDGE",
        "and INLETDRIFT are CISA / Mandiant naming for components and successor tooling within the broader AppleJeus toolset; \"Hidden Cobra\" is the legacy U.S.-government umbrella label that subsumes AppleJeus along with other DPRK families."
      ],
      "active": "yes (continuous evolution since 2018; Citrine Sleet / UNC4736 lineage active through 2024–2025 per Mandiant Radiant Capital attribution).",
      "first_observed": "2018-08 (Kaspersky's original \"Operation AppleJeus\" report, August 2018, documenting the Celas Trade Pro distribution); CISA / FBI joint advisory AA21-048A of February 17, 2021 (`[cisaaa21048a]`) is the canonical U.S.-government reference.",
      "host_platforms": [
        "cross-platform (macOS-focused with foundational role in establishing the macOS-targeting DPRK tradecraft; Windows builds distributed in parallel through 2018–2021)."
      ],
      "used_by_groups": [
        "OAK-G01"
      ],
      "observed_techniques": [
        "OAK-T11.002",
        "OAK-T11.001"
      ],
      "citations": [
        "chainalysis2024dprk",
        "cisaaa21048a",
        "mandiantradiant2024"
      ],
      "source_file": "software/OAK-S09-applejeus.md"
    },
    {
      "id": "OAK-S10",
      "name": "Manuscrypt",
      "type": "malware",
      "aliases": [
        "Manuscrypt (Kaspersky-original naming, retained as the most-used industry label); KEYMARBLE (NCCIC / US-CERT 2018 catalogue naming for an overlapping component / variant); FALLCHILL (CISA / FBI naming for an earlier Lazarus Windows backdoor with documented code overlap with later Manuscrypt builds); NukeSped (alternate naming used by some CTI vendors for related Lazarus Windows tooling); Volgmer is a related-but-distinct Lazarus Windows backdoor sometimes confused with Manuscrypt in older catalogues; the Manuscrypt name is canonical for the multi-stage Windows backdoor family used by Lazarus through 2017–2024 and is anchored in external cyber-threat-intel taxonomy Software entry S0259."
      ],
      "active": "yes (continued evolution; updated builds observed in incidents through 2024 per Kaspersky, ESET, and AhnLab reporting).",
      "first_observed": "~2014–2015 (early variants under FALLCHILL naming); Manuscrypt naming consolidated approximately 2017 alongside the Lazarus crypto-pivot; long-running family that pre-dates the modern crypto-theft cluster but has been adapted continuously into it.",
      "host_platforms": [
        "Windows (long-running Windows-only family; macOS and Linux-side DPRK tooling sits in the AppleJeus / RustBucket / KandyKorn lineage rather than the Manuscrypt lineage)."
      ],
      "used_by_groups": [
        "OAK-G01"
      ],
      "observed_techniques": [
        "OAK-T11.001",
        "OAK-T10.001"
      ],
      "citations": [
        "chainalysis2024dprk",
        "chainalysiskucoinlazarus",
        "mandiantcoincheck2018"
      ],
      "source_file": "software/OAK-S10-manuscrypt.md"
    },
    {
      "id": "OAK-S11",
      "name": "3CX VoIP Client Trojan",
      "type": "malware",
      "aliases": [
        "3CX Desktop App trojan; \"3CX supply-chain compromise\" (incident-naming convention used by Mandiant, Volexity, SentinelOne, CrowdStrike, and Sophos in the March-April 2023 reporting cohort); UNC4736 (Mandiant operator-cluster naming for the DPRK financial-funding operator within the broader Lazarus cluster that ran the 3CX intrusion); SmoothOperator (SentinelOne campaign naming); ICONIC (CrowdStrike naming); the trojanized binaries themselves are `3CXDesktopApp` (macOS Mach-O) and `3CXDesktopApp.exe` (Windows PE) and the second-stage payloads include ICONICSTEALER (Windows infostealer) and UNC4736's macOS payload chain. The cascading X_Trader supply-chain compromise that enabled the 3CX intrusion is tracked under separate naming (Mandiant: VEILEDSIGNAL backdoor; the X_Trader package itself is the Trading Technologies trading-software family)."
      ],
      "active": "sunset (March 2023 incident; incident-specific binaries and infrastructure burned during the public response in April 2023; UNC4736 operator continues to operate under follow-on tooling — see Radiant Capital September 2024 attribution to the same cluster).",
      "first_observed": "2023-03-22 (initial public detection by SentinelOne and CrowdStrike; Mandiant retained as 3CX's incident-response provider; public attribution to UNC4736 / DPRK published April 11, 2023).",
      "host_platforms": [
        "cross-platform (Windows and macOS — both `3CXDesktopApp.exe` and `3CXDesktopApp` Mach-O binaries were trojanized in the supply-chain compromise; Linux 3CX builds were not affected per public reporting)."
      ],
      "used_by_groups": [
        "OAK-G01"
      ],
      "observed_techniques": [
        "OAK-T11.001"
      ],
      "citations": [
        "chainalysis2024dprk",
        "mandiant3cx2023",
        "mandiantradiant2024",
        "mandiantucsx2023"
      ],
      "source_file": "software/OAK-S11-3cx-trojan.md"
    },
    {
      "id": "OAK-S12",
      "name": "JADESNOW",
      "type": "malware",
      "aliases": [
        "JADESNOW (Mandiant-original naming, retained as the canonical industry label per the March 2023 APT43 attribution report); related Mandiant-tracked components in the APT43 toolset that JADESNOW operates alongside include LATEOP (initial-access loader)",
        "BABYSHARK (PowerShell-based reconnaissance / staging family also documented in Kimsuky activity by multiple vendors)",
        "and QUASARRAT customisations attributed to the cluster; the broader Kimsuky / APT43 toolset is tracked under external Group ID G0094 with a software-entry list that overlaps JADESNOW's operational role."
      ],
      "active": "yes (continued use within APT43 / Kimsuky operations through 2024–2025 per Mandiant, Microsoft, and Recorded Future reporting; specific JADESNOW build-versioning is not consolidated in public reporting at the level of detail that AppleJeus or Manuscrypt enjoy).",
      "first_observed": "2023-03 (Mandiant March 28, 2023 APT43 attribution report public-naming date; underlying tool-development-and-deployment activity dates to earlier within Kimsuky's operational history per Mandiant's longitudinal tracking).",
      "host_platforms": [
        "Windows (the dominant deployment target for JADESNOW within the APT43 / Kimsuky operational profile, consistent with the cluster's spear-phishing-into-Windows-victim-environment tradecraft against policy researchers, journalists, and government targets)."
      ],
      "used_by_groups": [
        "OAK-G07"
      ],
      "observed_techniques": [
        "OAK-T8.001"
      ],
      "citations": [
        "bfvnis2023kimsuky",
        "chainalysis2024dprk",
        "mandiantapt432023",
        "mofakimsuky2023",
        "ofac2023kimsuky"
      ],
      "source_file": "software/OAK-S12-jadesnow.md"
    },
    {
      "id": "OAK-S13",
      "name": "RedLine Stealer",
      "type": "infostealer",
      "aliases": [
        "RedLine",
        "RedLine Infostealer"
      ],
      "active": "yes (2020-present; intermittent disruption efforts but no confirmed sunset as of 2026)",
      "first_observed": "2020-03 (early forum advertisements; broadly distributed by mid-2020)",
      "host_platforms": [
        "Windows (primary); cross-platform browser-data targets (Chromium-family, Gecko-family)"
      ],
      "used_by_groups": [],
      "observed_techniques": [
        "OAK-T11.002",
        "OAK-T4.004",
        "OAK-T4.005"
      ],
      "citations": [
        "opmagnus2024",
        "redlineflashpoint2021"
      ],
      "source_file": "software/OAK-S13-redline-stealer.md"
    },
    {
      "id": "OAK-S14",
      "name": "Lumma Stealer",
      "type": "infostealer",
      "aliases": [
        "LummaC2",
        "Lumma",
        "Lumma C2 Stealer"
      ],
      "active": "yes (2022-present; significant disruption May 2025; partial reconstitution observed thereafter)",
      "first_observed": "2022-08 (early forum advertisements under the LummaC2 brand)",
      "host_platforms": [
        "Windows (primary)"
      ],
      "used_by_groups": [],
      "observed_techniques": [
        "OAK-T11.002",
        "OAK-T4.004",
        "OAK-T4.005"
      ],
      "citations": [
        "clickfixproofpoint2024",
        "lummasekoia2023",
        "lummatakedown2025"
      ],
      "source_file": "software/OAK-S14-lumma-stealer.md"
    },
    {
      "id": "OAK-S15",
      "name": "AsyncRAT",
      "type": "malware (open-source remote access trojan)",
      "aliases": [
        "Async RAT",
        "AsyncRAT C#"
      ],
      "active": "yes (2019-present; continuously forked and rebuilt)",
      "first_observed": "2019-01 (initial public release of the open-source C# project on GitHub)",
      "host_platforms": [
        "Windows (primary; .NET Framework / .NET Core targets)"
      ],
      "used_by_groups": [],
      "observed_techniques": [
        "OAK-T11.002",
        "OAK-T4.004",
        "OAK-T4.005"
      ],
      "citations": [
        "asyncratmandiant2023",
        "asyncratorigingithub2019"
      ],
      "source_file": "software/OAK-S15-asyncrat.md"
    },
    {
      "id": "OAK-S16",
      "name": "Profanity",
      "type": "tool / vanity-gen (open-source Ethereum vanity-address generator)",
      "aliases": [
        "Profanity (johguse/profanity)"
      ],
      "active": "sunset / deprecated (2022-09; upstream archived and explicitly marked unsafe following the 1inch disclosure; some forks persist but are not treated as safe by the defender community)",
      "first_observed": "2017 (initial release as a GPU-accelerated Ethereum vanity-address generator)",
      "host_platforms": [
        "Linux / Windows / macOS (GPU-accelerated, OpenCL)"
      ],
      "used_by_groups": [],
      "observed_techniques": [
        "OAK-T11.004"
      ],
      "citations": [
        "halbornwintermute2022"
      ],
      "source_file": "software/OAK-S16-profanity.md"
    },
    {
      "id": "OAK-S17",
      "name": "jaredfromsubway.eth",
      "type": "mev-bot",
      "aliases": [
        "Jared",
        "jaredfromsubway",
        "Jared 2.0\" (2024 iteration tracked by EigenPhi)"
      ],
      "active": "yes (operating since 2023-02-27; continuously tracked publicly through 2024 and beyond)",
      "first_observed": "2023-02-27 (first publicly-tracked transactions on Ethereum mainnet)",
      "host_platforms": [
        "Ethereum mainnet (sandwich-MEV operation); off-chain searcher infrastructure not publicly characterised"
      ],
      "used_by_groups": [],
      "observed_techniques": [
        "OAK-T5.004"
      ],
      "citations": [
        "daian2019flashboys",
        "eigenphijared2023"
      ],
      "source_file": "software/OAK-S17-jaredfromsubway.md"
    },
    {
      "id": "OAK-S18",
      "name": "Pump.fun-style Bundlers",
      "type": "tool / mev-bot (class)",
      "aliases": [
        "Pump.fun bundlers",
        "launch bundlers",
        "dev-snipe bundlers",
        "Jito bundlers (in this context)"
      ],
      "active": "yes (2023-present; continuous activity tracking the lifecycle of Pump.fun and similar Solana token-launch venues)",
      "first_observed": "2023-Q4 (emergence alongside Pump.fun's launch and rapid growth in late 2023 / early 2024)",
      "host_platforms": [
        "Solana (primary); equivalent classes have emerged on other chains' token-launch venues"
      ],
      "used_by_groups": [],
      "observed_techniques": [
        "OAK-T3.001",
        "OAK-T2.001",
        "OAK-T13.002"
      ],
      "citations": [
        "jitobundlepolicies2024",
        "pumpfunbundlerbubblemaps2024",
        "pumpfunlaunchruganalytics2024"
      ],
      "source_file": "software/OAK-S18-pumpfun-bundlers.md"
    },
    {
      "id": "OAK-S19",
      "name": "KandyKorn",
      "type": "malware",
      "aliases": [
        "KANDYKORN (Elastic Security Labs original naming, November 2023, retained as the canonical industry label); SUGARLOADER (Elastic naming for the early-stage component within the same intrusion chain that loads the KandyKorn Mach-O backdoor); HLOADER (Elastic naming for the LaunchAgent-persistence helper observed in the same chain — sometimes catalogued separately, sometimes folded into the KandyKorn family entry depending on vendor); naming-overlap caveat: KandyKorn is operationally tracked by Mandiant within the broader UNC4736 / AppleJeus / Citrine Sleet umbrella and by Microsoft within the Citrine Sleet weather-name lineage",
        "so the same observed activity may be reported as \"KandyKorn detected\" or as \"Citrine Sleet macOS staging\" depending on the reporting vendor."
      ],
      "active": "yes (Elastic's original 2023 reporting characterised the family as actively-evolving; subsequent industry coverage through 2024–2025 places it within the continuing macOS DPRK lineage).",
      "first_observed": "2023-11 (Elastic Security Labs, \"KANDYKORN: Inside the Stash,\" November 1, 2023 — the canonical first-public-documentation date; underlying campaign activity tracked by Elastic from earlier in 2023).",
      "host_platforms": [
        "macOS (Intel and Apple Silicon — Elastic's original reporting documented Mach-O builds for both architectures within the same campaign infrastructure, consistent with the broader DPRK macOS lineage's shift to universal-binary distribution from 2022 onward)."
      ],
      "used_by_groups": [
        "OAK-G01"
      ],
      "observed_techniques": [
        "OAK-T11.001",
        "OAK-T11.002"
      ],
      "citations": [
        "chainalysis2024dprk",
        "cisaaa22108a",
        "elastickandykorn2023",
        "mandiantradiant2024",
        "microsoftcitrineradiant2024"
      ],
      "source_file": "software/OAK-S19-kandykorn.md"
    },
    {
      "id": "OAK-S20",
      "name": "RustBucket",
      "type": "malware",
      "aliases": [
        "RustBucket (Jamf Threat Labs original naming, April 2023, retained as the canonical industry label); naming overlap with the Mandiant UNC4899 / TraderTraitor sub-cluster tracking and with the Microsoft Sapphire Sleet weather-name lineage that covers BlueNoroff macOS activity through 2024; \"Hidden Risk\" is a related but operationally distinct subsequent-campaign naming used by SentinelOne / Phil Stokes for the late-2024 BlueNoroff macOS lure cohort that re-uses elements of the RustBucket toolset; the family is sometimes catalogued under the broader BlueNoroff macOS umbrella alongside ObjCShellz (OAK-S22) and SwiftLoader (OAK-S21) rather than as a wholly-distinct entry",
        "but Jamf's original RustBucket naming remains the canonical industry label for the Rust-language second-stage loader specifically."
      ],
      "active": "yes (Jamf's April 2023 reporting was followed by SentinelOne's continuing coverage through 2023–2024 documenting iterative variants and the RustBucket → ObjCShellz chain; the family remains in active service per multi-vendor reporting).",
      "first_observed": "2023-04 (Jamf Threat Labs, \"BlueNoroff Targets macOS — RustBucket,\" April 21, 2023 — the canonical first-public-documentation date; underlying campaign activity tracked by Jamf from earlier in 2023).",
      "host_platforms": [
        "macOS (Intel-first, with Apple Silicon variants documented in subsequent Jamf and SentinelOne reporting through 2023–2024 consistent with the broader DPRK macOS lineage's shift to universal-binary distribution)."
      ],
      "used_by_groups": [
        "OAK-G08",
        "OAK-G01"
      ],
      "observed_techniques": [
        "OAK-T11.001",
        "OAK-T11.002"
      ],
      "citations": [
        "chainalysis2024dprk",
        "jamfrustbucket2023",
        "microsoftsapphiresleet2023",
        "sentinelhiddenrisk2024",
        "sentinelobjcshellz2023"
      ],
      "source_file": "software/OAK-S20-rustbucket.md"
    },
    {
      "id": "OAK-S21",
      "name": "SwiftLoader",
      "type": "malware",
      "aliases": [
        "SwiftLoader (SentinelOne / Phil Stokes naming used through 2023–2024 reporting, retained as the canonical industry label for the Swift-language initial-stage downloader); naming-overlap caveat: SwiftLoader is operationally tracked alongside RustBucket (OAK-S20)",
        "ObjCShellz (OAK-S22)",
        "and the Hidden Risk campaign cohort within the broader BlueNoroff and Lazarus macOS lineages",
        "so the same observed activity may be reported as \"SwiftLoader detected\" or as \"BlueNoroff macOS staging\" or as \"Citrine Sleet macOS downloader\" depending on the reporting vendor; the Microsoft weather-name conventions (Sapphire Sleet for BlueNoroff, Citrine Sleet for the AppleJeus / UNC4736 cluster) cover SwiftLoader-lineage staging on both sides; some reporting catalogues SwiftLoader as a stage within the broader Hidden Risk campaign rather than as a wholly-distinct family entry."
      ],
      "active": "yes (continuing service through 2024–2025 per SentinelOne and corroborating-vendor reporting; the Swift-implementation initial-stage downloader role is one of the persistently-utilised slots in the cross-cluster DPRK macOS toolset).",
      "first_observed": "2023 (SentinelOne / Phil Stokes coverage through late 2023 documented the Swift-language initial-stage downloader role within observed BlueNoroff macOS chains; subsequent 2024 reporting expanded the family-level coverage); precise first-public-documentation date varies by which SentinelOne post is cited, with continuing iterative documentation through the Hidden Risk reporting cohort (`[sentinelhiddenrisk2024]`).",
      "host_platforms": [
        "macOS (Intel and Apple Silicon — universal-binary distribution consistent with the broader DPRK macOS lineage's 2022-onward shift to universal builds)."
      ],
      "used_by_groups": [
        "OAK-G01",
        "OAK-G08"
      ],
      "observed_techniques": [
        "OAK-T11.001",
        "OAK-T11.002"
      ],
      "citations": [
        "chainalysis2024dprk",
        "jamfrustbucket2023",
        "microsoftcitrineradiant2024",
        "microsoftsapphiresleet2023",
        "sentinelhiddenrisk2024",
        "sentinelobjcshellz2023",
        "sentinelswiftloader2023"
      ],
      "source_file": "software/OAK-S21-swiftloader.md"
    },
    {
      "id": "OAK-S22",
      "name": "ObjCShellz",
      "type": "malware",
      "aliases": [
        "ObjCShellz (SentinelOne / Phil Stokes original naming, November 2023, retained as the canonical industry label); naming-overlap caveat: ObjCShellz is operationally tracked alongside RustBucket (OAK-S20)",
        "SwiftLoader (OAK-S21)",
        "and the Hidden Risk campaign cohort within the broader BlueNoroff and Lazarus macOS lineages; Microsoft's weather-name conventions (Sapphire Sleet for BlueNoroff, Citrine Sleet for the AppleJeus / UNC4736 cluster) cover ObjCShellz-lineage staging on both sides; some reporting catalogues ObjCShellz as a third-stage component within the broader RustBucket → ObjCShellz chain rather than as a wholly-distinct family entry",
        "but SentinelOne's original naming remains the canonical industry label for the Objective-C-language reverse-shell specifically."
      ],
      "active": "yes (continuing service through 2024–2025 per SentinelOne and corroborating-vendor reporting; the lightweight Objective-C reverse-shell role is one of the persistently-utilised post-loader components in the cross-cluster DPRK macOS toolset).",
      "first_observed": "2023-11 (SentinelOne / Phil Stokes, \"BlueNoroff Strikes Again with New macOS Malware,\" November 6, 2023 — the canonical first-public-documentation date; underlying campaign activity tracked by SentinelOne from earlier in 2023).",
      "host_platforms": [
        "macOS (Intel and Apple Silicon — universal-binary distribution consistent with the broader DPRK macOS lineage's 2022-onward shift to universal builds)."
      ],
      "used_by_groups": [
        "OAK-G01",
        "OAK-G08"
      ],
      "observed_techniques": [
        "OAK-T11.001",
        "OAK-T11.002"
      ],
      "citations": [
        "chainalysis2024dprk",
        "jamfrustbucket2023",
        "microsoftsapphiresleet2023",
        "sentinelhiddenrisk2024",
        "sentinelobjcshellz2023"
      ],
      "source_file": "software/OAK-S22-objcshellz.md"
    },
    {
      "id": "OAK-S23",
      "name": "LockBit ransomware",
      "type": "ransomware",
      "aliases": [
        "LockBit (the encryptor brand maintained by the LockBitSupp / Khoroshev development line, January 2020 onward); LockBit 1.0 / \"ABCD\" ransomware (the .abcd-extension first variant from January 2020 that gave the family its earliest informal name); LockBit 2.0 / LockBit Red (June 2021, introduced StealBit data-exfiltration tooling and the \"automated\" affiliate-onboarding model); LockBit 3.0 / LockBit Black (June 2022, introduced the bug-bounty programme on the leak site and partial code reuse from the leaked BlackMatter source); LockBit Green (January 2023, a build incorporating leaked Conti v3 source code and re-released under LockBit branding); LockBit-NG-Dev (a 2024 pre-release Rust-language rewrite recovered during Operation Cronos and not field-deployed). Industry-side cross-attribution labels include the external cyber-threat-intel taxonomy ID S1180."
      ],
      "active": "degraded — Operation Cronos disruption February 19–20, 2024 (`[nca2024operationcronos]`); brand-attributable extortion volume down approximately 79% in H2 2024 versus H1 2024 per `[chainalysis2025ransomware]`; LockBit-branded leak-site activity continued at much-reduced cadence into 2025 but the operator network's operational continuity is structurally damaged. Khoroshev remained at large in Russia as of v0.1.",
      "first_observed": "2020-01 (LockBit 1.0 first observed in the wild; January 2020 advertisements on Russian-language criminal forums marked the brand's debut).",
      "host_platforms": [
        "Windows (primary, all major versions); Linux (LockBit 2.0 onward, with dedicated Linux/ESXi targeting in LockBit 3.0); VMware ESXi (the dedicated ESXi-hypervisor variant from 2021 onward is one of the family's defining technical features and shaped the ESXi-targeting trend across the broader RaaS sector); cross-platform aspirations in the unreleased LockBit-NG-Dev Rust rewrite (which mirrored the BlackCat / ALPHV cross-platform-Rust design choice)."
      ],
      "used_by_groups": [
        "OAK-G05",
        "OAK-G06"
      ],
      "observed_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T7.003"
      ],
      "citations": [
        "chainalysis2024khoroshev",
        "chainalysis2024lockbit",
        "chainalysis2025ransomware",
        "cisaaa23165a",
        "doj2024khoroshev",
        "doj2024ryzhenkov",
        "mandiant2022unc2165lockbit",
        "nca2024operationcronos",
        "ofac2024khoroshev",
        "ofac2024lockbitaffiliates",
        "sophos2024lockbit",
        "trendmicro2024lockbit",
        "unit42lockbit2023"
      ],
      "source_file": "software/OAK-S23-lockbit.md"
    },
    {
      "id": "OAK-S24",
      "name": "BlackCat / ALPHV ransomware",
      "type": "ransomware",
      "aliases": [
        "ALPHV (the operator-side preferred name on Russian-language criminal forums and the leak-site branding); BlackCat (the industry / vendor naming convention adopted from the leak-site logo and the cat-iconography in the encryptor's ransom-note theming); Noberus (Symantec / Broadcom analyst naming); ALPHV/BlackCat (the conjoined form used in U.S. government advisories and in most CTI vendor reporting); external cyber-threat-intel taxonomy ID S1068."
      ],
      "active": "sunset (2024-03) — the ALPHV operators executed an exit-scam in early March 2024 after receiving an approximately $22M ransom payment from Change Healthcare / UnitedHealth Group affiliate \"Notchy,\" redirecting the payment from the affiliate to operator-controlled wallets and posting a fabricated \"FBI seizure\" banner on the leak site (the FBI itself disclaimed the takedown, distinguishing the self-exit-scam from the prior December 2023 FBI-led disruption). No genuine ALPHV-branded operations have been observed post-exit; affiliate-side migration to RansomHub, Cl0p, and other brands is documented through 2024.",
      "first_observed": "2021-11 (first leak-site postings November 2021; FBI Flash CU-000167-MW April 19, 2022 was the first U.S.-government public reference).",
      "host_platforms": [
        "Windows (primary, with Windows-server enterprise targeting the dominant deployment surface); Linux (parity build released alongside Windows); VMware ESXi (a dedicated hypervisor variant, mirroring the LockBit-3.0-era sector pivot to ESXi-targeting); the Rust-language implementation produces structurally identical builds across these platforms",
        "which is the family's defining technical innovation and the principal reason for ALPHV's 2022–2023 affiliate-attractiveness."
      ],
      "used_by_groups": [
        "OAK-G10"
      ],
      "observed_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T7.003"
      ],
      "citations": [
        "chainalysis2024changehealthcare",
        "chainalysis2025ransomware",
        "cisaaa23061a",
        "cisaaa24061a",
        "doj2023alphvtakedown",
        "fbiflashalphv2022",
        "mandiant2023unc3944",
        "microsoft2024blackcat",
        "symantecnoberus2022",
        "witty2024testimony"
      ],
      "source_file": "software/OAK-S24-blackcat-alphv.md"
    },
    {
      "id": "OAK-S25",
      "name": "Maui ransomware",
      "type": "ransomware",
      "aliases": [
        "Maui (the canonical CISA / FBI naming, established by joint advisory AA22-187A on July 6, 2022); industry-side alternative naming is sparse because the family was never offered as a commodity-or-affiliate product and so does not have the parallel vendor-naming proliferation of LockBit / ALPHV / Conti; Mandiant attributes operationally to the Andariel sub-cluster of the broader Lazarus / DPRK constellation; CrowdStrike-side overlap with the Stonefly / Silent Chollima naming for the same operator cohort."
      ],
      "active": "dormant — no public Maui-attributed deployments observed post-2023 in open-source CTI; the family was always low-volume and operator-bespoke rather than commodity, and Andariel cluster activity has rotated through several subsequent ransomware families (e.g. Maui → H0lyGh0st / PLAY-affiliated activity → SiennaPurple / SiennaBlue successors per Microsoft tracking). Treat as dormant rather than confirmed-sunset because operator continuity is documented and re-emergence under the same Andariel umbrella with rebadged tooling is expected.",
      "first_observed": "2021-05 (the earliest deployment documented in CISA AA22-187A is May 2021 against an unnamed U.S. healthcare-sector victim; the advisory itself was published July 6, 2022).",
      "host_platforms": [
        "Windows (the only platform observed in public reporting; CISA AA22-187A and the subsequent Mandiant / Microsoft / Stairwell technical analyses describe a Windows-only x86 implementation)."
      ],
      "used_by_groups": [
        "OAK-G09",
        "OAK-G01"
      ],
      "observed_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T8.002"
      ],
      "citations": [
        "chainalysis2024dprk",
        "chainalysisdprkmaui2024",
        "cisaaa22187a",
        "doj2024rimjonghyok",
        "mandiantandariel2022",
        "microsoftonyxsleet2022",
        "stairwell2022maui"
      ],
      "source_file": "software/OAK-S25-maui.md"
    },
    {
      "id": "OAK-S26",
      "name": "Conti ransomware",
      "type": "ransomware",
      "aliases": [
        "Conti (the operator-side and leak-site-branded name, May 2020 onward); Wizard Spider (CrowdStrike's intrusion-set naming for the operator cohort, predating the Conti brand and continuing through Conti-successor-brand era); UNC1878 (Mandiant's earlier intrusion-set naming for the same cohort, partially superseded by the operator-cohort-rebranding pattern post-2022); TrickBot Group (informal industry naming linking the cohort to its earlier banker-trojan operating substrate); external cyber-threat-intel taxonomy ID S0575. Conti is operationally the successor brand to Ryuk (2018–2020) within the same operator-cohort identity",
        "and predecessor brand-of-record to the post-May-2022 dispersal cohort (Black Basta, Royal / BlackSuit, Karakurt, BlackByte, Quantum / Zeon, AvosLocker partial overlap, and broader Conti-diaspora affiliate placements)."
      ],
      "active": "sunset (2022-05) — operator-cluster dissolution announced internally during May 2022 following the late-February-2022 ContiLeaks insider-disclosure event in which a pro-Ukraine cluster member published approximately 60,000 internal chat-log messages, source code, and operational documents in retaliation for the operator's public alignment with the Russian state's invasion of Ukraine. The Conti-branded leak site went offline in late May / early June 2022; the operator cohort dispersed into multiple successor brands while retaining operator continuity at the personnel level. *No genuine Conti-branded operations have been observed post-mid-2022; the brand is fully sunset, but operator continuity into the successor brands is the dominant 2022–2025 ransomware-sector trajectory.*",
      "first_observed": "2020-05 (Conti leak-site debut May 2020; Wizard-Spider-cohort ransomware operations under earlier branding, principally Ryuk, dated to August 2018).",
      "host_platforms": [
        "Windows (primary, all variants); Linux (a Conti-Linux variant emerged in late 2021 with VMware ESXi targeting, mirroring the broader RaaS-sector ESXi pivot; partial code reuse of the Conti-Linux variant is documented in Hive's Linux build per Mandiant); the Conti v3 Windows codebase was leaked in full during the ContiLeaks dump and has since been forked / rebadged by multiple unrelated groups (LockBit Green is the highest-profile rebadge — see OAK-S23 — but unaffiliated commodity-tier Conti-fork builds also circulate)."
      ],
      "used_by_groups": [
        "OAK-G06",
        "OAK-G05"
      ],
      "observed_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T8.001"
      ],
      "citations": [
        "chainalysis2022conti",
        "chainalysis2025ransomware",
        "cisaaa21265a",
        "cisaaa22046a",
        "contileaks2022",
        "costaricaconti2022",
        "crowdstrikewizardspider2022",
        "mandiantcontileaks2022",
        "ofac2022garantex",
        "recordedfuturecontihse2021"
      ],
      "source_file": "software/OAK-S26-conti.md"
    },
    {
      "id": "OAK-S27",
      "name": "Black Basta ransomware",
      "type": "ransomware",
      "aliases": [
        "Black Basta (the operator-side and leak-site-branded name from the brand's April 2022 debut); industry-side cross-attribution labels include UNC4393 (Mandiant intrusion-set naming for the operator cluster)",
        "Storm-1811 (Microsoft Threat Intelligence naming, partially overlapping the broader Conti-successor-cohort surface)",
        "and the informal \"Conti Team 3\" / \"Conti Black\" naming used in early 2022 industry reporting that documented the operator-cohort continuity from Conti at the personnel level. The brand is operationally the most-prominent direct-successor brand in the Conti-cohort dispersal network (see OAK-S26 Discussion for the broader Conti-successor framing). The internal-chat-leak event of February 2024 (the \"BlackBastaGPT\" / `[blackbastaleaks2024]` corpus) provides a primary-source record of the operator cohort's internal organisation comparable in evidentiary weight to the ContiLeaks corpus for Conti."
      ],
      "active": "degraded — brand-attributable extortion volume declined materially through H2 2024 and into early 2025 following the February 2024 internal-chat-leak event and subsequent affiliate migration; some affiliate-cohort members rotated onto Cactus and BlackSuit affiliate panels per Mandiant and Microsoft post-leak tracking. Brand had not been formally sunset as of v0.1 but operational-continuity is structurally damaged in the same idiom as OAK-S23 LockBit post-Cronos.",
      "first_observed": "2022-04 (Black Basta leak-site debut April 2022; brand emergence is read as immediately pre-Conti-dissolution, with operator personnel migration from the Conti cohort into the new brand identity documented at the internal-chat-recovered level via the February 2024 leak corpus).",
      "host_platforms": [
        "Windows (primary, all enterprise-server variants); Linux / VMware ESXi (a dedicated ESXi-hypervisor variant emerged June 2022, mirroring the broader RaaS-sector pivot to hypervisor-targeted attacks established by LockBit and ALPHV). The Windows codebase is C++-authored with structural-and-stylistic similarities to Conti v3 documented by Trend Micro",
        "Sophos",
        "and Mandiant; the lineage is read as *Conti-codebase-derivative-with-rewrites* rather than a clean fork."
      ],
      "used_by_groups": [
        "OAK-G11"
      ],
      "observed_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T8.001"
      ],
      "citations": [
        "blackbastaleaks2024",
        "chainalysis2025ransomware",
        "chainalysisblackbasta2024",
        "cisaaa24131a",
        "mandiantunc4393",
        "microsoftstorm1811",
        "ofac2022garantex",
        "sophosblackbasta2022",
        "trendmicroblackbasta2022"
      ],
      "source_file": "software/OAK-S27-black-basta.md"
    },
    {
      "id": "OAK-S28",
      "name": "Royal / BlackSuit ransomware",
      "type": "ransomware",
      "aliases": [
        "Royal (the operator-side and leak-site-branded name from the brand's September 2022 debut through mid-2023); BlackSuit (the rebranded operator-and-encryptor identity from June 2023 onward); industry-side cross-attribution labels include DEV-0569 / Storm-0569 (early Microsoft Threat Intelligence naming for the operator cluster prior to the BlackSuit rebrand)",
        "the informal \"Royal/BlackSuit\" conjoined naming used in CISA AA23-061A and the November 2023 / August 2024 update advisories",
        "and the \"Zeon\" naming used in earlier 2022 Conti-successor-brand reporting that documented the encryptor's lineage to Conti's Zeon variant. The brand-rotation event from Royal to BlackSuit in mid-2023 is widely read by Mandiant",
        "Microsoft",
        "and CISA as a *brand-toxicity-management response to attribution-graph tracking* — an attempt to shed the Royal-name accumulation of attributable victim count and U.S.-government advisory surface (CISA AA23-061A specifically) and continue operations under a fresh brand identity. The encryptor-codebase",
        "leak-site infrastructure",
        "and operator-cohort were continuous across the rebrand at the wallet-cluster and tradecraft-fingerprint levels."
      ],
      "active": "active — BlackSuit-branded operations continued through 2024 and into 2025 with the OFAC December 2023 designation surface providing institutional pressure but not operational disruption; the brand had not been formally sunset as of v0.1 and remains an active-detection target. Brand-attributable extortion volume placed BlackSuit in the top-five ransomware brands by leak-site postings through 2024 per Recorded Future / Coveware tracking.",
      "first_observed": "2022-09 (Royal-branded operations debuted September 2022; the Royal encryptor was forked from Conti's Zeon variant per Mandiant and Microsoft attribution work, providing direct codebase continuity to the Conti-cohort dispersal network); brand rebrand to BlackSuit in June 2023.",
      "host_platforms": [
        "Windows (primary, all enterprise-server variants); Linux / VMware ESXi (a dedicated ESXi-hypervisor variant emerged in early 2023, mirroring the broader RaaS-sector pivot to hypervisor-targeted attacks). The Windows codebase's lineage to Conti's Zeon variant is the cleanest documented case of *direct Conti-codebase fork as a successor-brand encryptor* — Royal forked from Zeon rather than being a clean rewrite",
        "distinguishing it from the Black Basta lineage where the Conti v3 codebase was substantively rewritten before redeployment."
      ],
      "used_by_groups": [],
      "observed_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T8.001"
      ],
      "citations": [
        "chainalysis2025ransomware",
        "chainalysisroyalblacksuit2024",
        "cisaaa23061a",
        "cisaaa24228a",
        "mandiantroyalblacksuit2023",
        "microsoftstorm0569",
        "ofac2023royalblacksuit",
        "sophosroyalblacksuit2023",
        "trendmicroroyalblacksuit2023"
      ],
      "source_file": "software/OAK-S28-royal-blacksuit.md"
    },
    {
      "id": "OAK-S29",
      "name": "BeaverTail",
      "type": "malware (npm-package supply-chain malware / first-stage JavaScript loader and infostealer)",
      "aliases": [
        "BeaverTail (the Palo Alto Unit 42 naming established in the canonical July 2023 publication that first publicly documented the family); industry-side cross-attribution labels include the broader campaign naming \"Contagious Interview\" (Unit 42 campaign-level naming for the recruiter-pretext intrusion set carrying BeaverTail and InvisibleFerret payloads) and \"Wagemole\" (an adjacent / partially-overlapping campaign naming used by Unit 42 and Mandiant for the DPRK-IT-worker-fraud surface that shares operator cohort and tooling with Contagious Interview); operator-cluster naming overlaps with the broader DPRK Lazarus / TraderTraitor / BlueNoroff intrusion set (CrowdStrike's Famous Chollima naming and Microsoft's Sapphire Sleet / Moonstone Sleet naming for related operator-cohort surfaces)."
      ],
      "active": "yes — continuous variants observed through 2024–2025 with sustained npm-registry submission cadence; Unit 42, SentinelOne, ReversingLabs, and Sonatype track ongoing variant-rotation and registry-submission patterns; the principal mitigation surface is npm-registry-side takedown of malicious packages, but operator-side rotation onto new fake-author personas and new package-name surfaces is faster than registry-side takedown response.",
      "first_observed": "2023-07 (Palo Alto Unit 42 canonical publication date, `[unit42beavertail2023]`; the underlying campaign activity is attributed back at least into early 2023 by retrospective registry-submission analysis).",
      "host_platforms": [
        "cross-platform (Windows, macOS, Linux — the JavaScript implementation runs natively in the Node.js runtime that the npm-package delivery surface presupposes; this cross-platform property is itself a defining family-architectural feature, distinguishing BeaverTail from the platform-specific macOS-focused TraderTraitor / RustBucket / KandyKorn / SwiftLoader / ObjCShellz lineage at OAK-S08 / S20 / S21 / S22)."
      ],
      "used_by_groups": [
        "OAK-G01",
        "OAK-G08"
      ],
      "observed_techniques": [
        "OAK-T11.001",
        "OAK-T11.002"
      ],
      "citations": [
        "chainalysis2024dprk",
        "crowdstrikefamouschollima2024",
        "mandiantwagemole2024",
        "unit42beavertail2023",
        "unit42contagiousinterview2024"
      ],
      "source_file": "software/OAK-S29-beavertail.md"
    },
    {
      "id": "OAK-S30",
      "name": "InvisibleFerret",
      "type": "malware (Python second-stage backdoor / credential-and-wallet-data infostealer)",
      "aliases": [
        "InvisibleFerret (the Palo Alto Unit 42 naming established alongside the BeaverTail naming in the canonical July 2023 publication that first publicly documented both families); industry-side cross-attribution labels include the broader campaign naming \"Contagious Interview\" (Unit 42 campaign-level naming for the recruiter-pretext intrusion set carrying the BeaverTail → InvisibleFerret payload chain) and \"Wagemole\" (the adjacent DPRK-IT-worker-fraud campaign sharing operator cohort and tooling); operator-cluster naming overlaps with the broader DPRK Lazarus / TraderTraitor / BlueNoroff intrusion set under CrowdStrike's Famous Chollima naming and Microsoft's Sapphire Sleet / Moonstone Sleet naming."
      ],
      "active": "yes — continuous variants tracked through 2024–2025 with Unit 42, SentinelOne, and Mandiant documenting per-version evolution; the family operates as the persistent-second-stage backdoor in the BeaverTail-led Contagious Interview / Wagemole campaign and is paired with BeaverTail in essentially all observed campaign deployments rather than operating standalone.",
      "first_observed": "2023-07 (Palo Alto Unit 42 canonical publication date, paired with the BeaverTail family disclosure in `[unit42beavertail2023]`; the underlying campaign activity is attributed back at least into early 2023 by retrospective analysis).",
      "host_platforms": [
        "cross-platform (Windows, macOS, Linux — the Python implementation runs natively in any Python-3 runtime that the BeaverTail first-stage establishes; cross-platform property mirrors BeaverTail and distinguishes the family from the platform-specific macOS-focused TraderTraitor lineage at OAK-S08)."
      ],
      "used_by_groups": [
        "OAK-G01",
        "OAK-G08"
      ],
      "observed_techniques": [
        "OAK-T11.001",
        "OAK-T11.002"
      ],
      "citations": [
        "chainalysis2024dprk",
        "crowdstrikefamouschollima2024",
        "jamfinvisibleferret2024",
        "mandiantwagemole2024",
        "sentineloneinvisibleferret2024",
        "unit42beavertail2023",
        "unit42invisibleferret2024"
      ],
      "source_file": "software/OAK-S30-invisibleferret.md"
    },
    {
      "id": "OAK-S31",
      "name": "TigerRAT",
      "type": "malware (Windows backdoor / persistent-access remote-access-trojan)",
      "aliases": [
        "TigerRAT (the canonical KrCERT/CC + AhnLab naming established in 2022 publications and sustained across continuous Korean-side CTI reporting through 2024–2025); industry-side cross-attribution labels include the broader Andariel cluster naming surface — Silent Chollima (CrowdStrike)",
        "Onyx Sleet / Plutonium (Microsoft Threat Intelligence's continuous Andariel-cluster naming)",
        "Stonefly (Symantec / Broadcom)",
        "DarkSeoul-cohort historical naming for the broader DPRK destructive-and-espionage cluster from which Andariel is the contemporary financially-motivated sub-cluster",
        "and the external Group ID G0138 Andariel Group profile under which TigerRAT activity is documented."
      ],
      "active": "yes — continuous variants tracked through 2024–2025 by KrCERT/CC, AhnLab, Mandiant, Microsoft, and Symantec; the family is a sustained-deployment Andariel-cluster persistence-and-staging tool rather than a campaign-bounded payload, and its operational tempo is paced by Andariel's broader campaign cadence rather than by per-version-release boundaries.",
      "first_observed": "2022 (KrCERT/CC + AhnLab canonical publications established the family naming in 2022; underlying Andariel-cluster activity using the family is attributed back further by retrospective analysis but the public-record family-naming anchor is 2022).",
      "host_platforms": [
        "Windows (the only platform observed in public reporting; KrCERT/CC, AhnLab, and Mandiant analyses describe a Windows-only x86 implementation; no macOS or Linux variants documented as of v0.1)."
      ],
      "used_by_groups": [
        "OAK-G09"
      ],
      "observed_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T8.002"
      ],
      "citations": [
        "ahnlabtigerrat2022",
        "chainalysisdprkmaui2024",
        "cisa2024andarieladvisory",
        "cisaaa22187a",
        "cisaaa22321a",
        "doj2024rimjonghyok",
        "krcerttigerrat2022",
        "mandiantandariel2022",
        "microsoftonyxsleet2022",
        "symantec2024stonefly"
      ],
      "source_file": "software/OAK-S31-tigerrat.md"
    },
    {
      "id": "OAK-S32",
      "name": "AppleSeed",
      "type": "malware (Windows backdoor / persistent-access remote-access-trojan with HWP-document-borne delivery surface)",
      "aliases": [
        "AppleSeed (the canonical industry naming established across Cisco Talos, ESET, Mandiant, AhnLab, and KISA / KrCERT/CC publications and sustained as the dominant naming convention in continuous CTI reporting from approximately 2019 forward); industry-side cross-attribution labels include the broader Kimsuky / APT43 cluster naming surface — Kimsuky (the canonical Korean and U.S.-government naming for the operator cluster)",
        "Thallium (Microsoft Threat Intelligence's earlier Kimsuky naming)",
        "Black Banshee (CrowdStrike's Kimsuky-cluster naming)",
        "Velvet Chollima and the broader Chollima-family naming",
        "APT43 (Mandiant's March 2023 cluster-naming consolidation)",
        "TA406 (Proofpoint's Kimsuky naming)",
        "and the external Group ID G0094 Kimsuky Group profile under which AppleSeed activity is documented."
      ],
      "active": "yes — continuous variants tracked through 2024–2025 by Talos, ESET, Mandiant, AhnLab, KISA, and KrCERT/CC; the family is the primary Kimsuky persistence tool from approximately 2019 forward and the operational tempo is paced by Kimsuky's broader spear-phishing-campaign cadence rather than by per-version-release boundaries.",
      "first_observed": "2019 (the public-record family-naming anchor is approximately 2019 across early Kimsuky-cluster CTI reporting; underlying Kimsuky-cluster activity is attributed back further by retrospective analysis but the AppleSeed family naming and the documented HWP-document-borne delivery surface stabilised in industry reporting around 2019–2020).",
      "host_platforms": [
        "Windows (the only platform observed in public reporting; Talos, ESET, Mandiant, AhnLab, and KISA analyses describe a Windows-only x86 implementation; no macOS or Linux variants documented as of v0.1, consistent with the family's HWP-document-borne delivery surface that presupposes a Korean-language Windows-host target population)."
      ],
      "used_by_groups": [
        "OAK-G07"
      ],
      "observed_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T8.002"
      ],
      "citations": [
        "ahnlabappleseed2021",
        "bfvnis2023kimsuky",
        "chainalysis2024dprk",
        "esetkimsuky2021",
        "mandiantapt43_2023",
        "mofakimsuky2023",
        "ofac2023kimsuky",
        "talosappleseed2021"
      ],
      "source_file": "software/OAK-S32-appleseed.md"
    },
    {
      "id": "OAK-S33",
      "name": "Akira ransomware",
      "type": "ransomware",
      "aliases": [
        "Akira (the operator-side and leak-site-branded name from the brand's March 2023 debut, with the leak-site visual identity adopting a deliberate retro-1980s green-on-black terminal aesthetic that became the family's most-recognisable surface signature); Megazord (a short-lived Rust-language Linux/ESXi variant identifier used in mid-2023 builds before consolidation back under the Akira brand); industry-side cross-attribution labels include the informal \"Akira-Conti-derivative\" naming used in 2023 industry reporting that documented partial code-reuse signals between the Akira Windows codebase and the Conti v3 leaked source. Akira is widely read by Mandiant",
        "Sophos",
        "and Avast as a Conti-cohort-adjacent operator emergence rather than a direct Conti-cohort-continuity case in the idiom of OAK-S27 Black Basta or OAK-S28 Royal/BlackSuit; the lineage relationship is *partial-codebase-derivative-with-distinct-operator-cohort* rather than full cohort-continuity."
      ],
      "active": "active — Akira-branded operations continued through 2024 and into 2025 with sustained leak-site cadence and over 250 confirmed victim organisations through early 2024 per the April 2024 CISA / FBI / EC3 / NCSC-NL joint advisory AA24-109A (`[cisaaa24109a]`); the brand had not been subjected to a government takedown comparable to Operation Cronos (LockBit) or the December 2023 ALPHV action as of v0.1, and remains an active-detection target. Recorded Future / Coveware tracking placed Akira in the top-five ransomware brands by leak-site postings through 2024.",
      "first_observed": "2023-03 (Akira-branded operations debuted March 2023 with the Windows C++ encryptor; the Rust-language Linux / VMware ESXi variant followed in April–May 2023, mirroring the broader RaaS-sector pivot to Rust-implemented hypervisor variants established by ALPHV / BlackCat).",
      "host_platforms": [
        "Windows (primary, all enterprise-server variants, C++-authored codebase with partial structural similarities to Conti v3 documented by Sophos and Avast); Linux / VMware ESXi (a Rust-language variant emerged April–May 2023 under the temporary \"Megazord\" naming before consolidation back to the Akira brand). The dual-language architecture — C++ Windows + Rust ESXi/Linux — mirrors the ALPHV-influenced sector-wide pattern of Rust-for-cross-platform-hypervisor-variants while retaining C++ for the Windows codebase",
        "a hybrid pattern that became more common across 2023–2024 RaaS emergences."
      ],
      "used_by_groups": [
        "OAK-G16"
      ],
      "observed_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T8.001"
      ],
      "citations": [
        "avast2023akira",
        "chainalysis2025ransomware",
        "chainalysisakira2024",
        "cisaaa24109a",
        "mandiantakira2023",
        "ofac2022garantex",
        "sophosakira2023",
        "trendmicroakira2023"
      ],
      "source_file": "software/OAK-S33-akira-ransomware.md"
    },
    {
      "id": "OAK-S34",
      "name": "RansomHub ransomware",
      "type": "ransomware",
      "aliases": [
        "RansomHub (the operator-side and leak-site-branded name from the brand's February 2024 debut on Russian-language criminal forums); industry-side cross-attribution labels include the informal \"Knight-derivative\" naming used in mid-2024 industry reporting that documented partial code-reuse signals between the RansomHub Windows codebase and the prior Knight / Cyclops-Blink-class encryptor codebase (the operator-cohort behind Knight is widely read as having sold or licensed source code to the RansomHub developer team)",
        "and the \"post-ALPHV-affiliate-absorber\" descriptive used across CTI-vendor reporting to characterise the brand's principal market-positioning function in 2024. RansomHub is the canonical worked example of *operator-cohort opportunism in the wake of a competitor brand's exit-scam-driven dissolution* — the brand's rapid Q2–Q4 2024 growth is widely attributed to its capacity to absorb the high-tier ALPHV affiliate diaspora following the March 2024 ALPHV exit-scam (see OAK-S24 Discussion)",
        "with the \"Notchy\" affiliate behind the Change Healthcare attack widely-reported as having rotated onto the RansomHub affiliate panel."
      ],
      "active": "active — RansomHub-branded operations continued through 2024 and into 2025 with sustained leak-site cadence; brand-attributable extortion volume placed RansomHub as the top-by-leak-site-postings RaaS brand in H2 2024 per Recorded Future / Coveware tracking, displacing both the post-Cronos LockBit and the post-exit-scam ALPHV from their prior market-share positions. The brand had not been subjected to a government takedown comparable to Operation Cronos or the December 2023 ALPHV action as of v0.1, and remains an active-detection target.",
      "first_observed": "2024-02 (RansomHub leak-site debut February 2024; advertisements on Russian-language criminal forums marked the brand's debut and the affiliate-onboarding panel was operational immediately, suggesting a substantial pre-launch development period and an operator-side cohort with prior RaaS-operational experience).",
      "host_platforms": [
        "Windows (primary, all enterprise-server variants, with the encryptor codebase showing partial structural similarities to the prior Knight / Cyclops-class codebase per Mandiant and Microsoft attribution work); Linux / VMware ESXi (a dedicated ESXi-hypervisor variant emerged in mid-2024); Go-language and Rust-language partial implementations have been documented in different RansomHub builds across 2024",
        "with the dual-language architecture mirroring the broader sector pattern of hybrid-codebase RaaS designs established by Akira (OAK-S33) and the LockBit NG-Dev rewrite."
      ],
      "used_by_groups": [
        "OAK-G15"
      ],
      "observed_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T7.003",
        "OAK-T8.001"
      ],
      "citations": [
        "chainalysis2025ransomware",
        "chainalysisransomhub2024",
        "cisaaa24242a",
        "mandiantransomhub2024",
        "microsoftransomhub2024",
        "ofac2022garantex",
        "recordedfutureransomhub2024",
        "sophosransomhub2024",
        "trendmicroransomhub2024"
      ],
      "source_file": "software/OAK-S34-ransomhub-ransomware.md"
    },
    {
      "id": "OAK-S35",
      "name": "BlackByte ransomware",
      "type": "ransomware",
      "aliases": [
        "BlackByte (the operator-side and leak-site-branded name from the brand's July 2021 debut, retained continuously across the multi-language codebase rotation through 2024); industry-side cross-attribution labels include the Wizard-Spider-cohort-adjacent / Conti-cohort-partial-overlap descriptive used in 2022 industry reporting that documented operator-personnel overlap with the broader Conti-cohort dispersal network",
        "and the BlackByte 2.0 / NT / 3.0 version-string naming used to disambiguate the multi-language codebase rotations across .NET (2021–2022)",
        "Go (2022–2023)",
        "and C++ (2023–2025) implementations. BlackByte sits in the Conti-cohort-adjacent category alongside Akira (OAK-S33) — operator-personnel overlap with the broader post-Conti dispersal network is documented but the lineage relationship is partial-overlap rather than full cohort-continuity in the idiom of OAK-S27 Black Basta or OAK-S28 Royal/BlackSuit."
      ],
      "active": "active — BlackByte-branded operations continued through 2024 and into 2025 with sustained leak-site cadence; the brand had not been subjected to a government takedown comparable to Operation Cronos (LockBit) or the December 2023 ALPHV action as of v0.1, and remains an active-detection target. Brand-attributable extortion volume placed BlackByte as a mid-tier RaaS strain across 2022–2024 — below the top-three by leak-site postings but with sustained presence and continued multi-vertical targeting per Recorded Future / Coveware tracking.",
      "first_observed": "2021-07 (BlackByte-branded operations debuted July 2021 with the .NET-language Windows encryptor; subsequent codebase rotations to Go (2022) and C++ (2023+) reflect a sustained operator-side investment in encryptor-codebase modernisation across the brand's lifetime, distinguishing BlackByte from the more-typical RaaS-sector pattern of either single-language codebase persistence or single-rewrite codebase rotation).",
      "host_platforms": [
        "Windows (primary, all enterprise-server variants, with the codebase rotated across .NET (2021–2022) → Go (2022–2023) → C++ (2023–2025) per Trustwave, Microsoft, and Sophos attribution work); Linux / VMware ESXi (a dedicated ESXi-hypervisor variant emerged in 2022, mirroring the broader RaaS-sector pivot to hypervisor-targeted attacks established by LockBit and ALPHV). The multi-language codebase rotation is the family's defining technical history and provides a useful comparative reference for understanding the *operator-side codebase-modernisation cadence* across a long-lifetime mid-tier RaaS brand — distinct from both single-language persistence (Conti's C++-only history) and single-rewrite rotation (LockBit's NG-Dev Rust rewrite recovered pre-deployment)."
      ],
      "used_by_groups": [
        "OAK-G17"
      ],
      "observed_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T8.001"
      ],
      "citations": [
        "chainalysis2025ransomware",
        "chainalysisblackbyte2024",
        "cisaaa22039a",
        "microsoftblackbyte2023",
        "ofac2022garantex",
        "sophosblackbyte2023",
        "trendmicroblackbyte2022",
        "trustwaveblackbyte2021"
      ],
      "source_file": "software/OAK-S35-blackbyte-ransomware.md"
    },
    {
      "id": "OAK-S36",
      "name": "Karakurt extortion-only kit",
      "type": "tool / extortion-only operation tooling",
      "aliases": [
        "Karakurt extortion kit; Karakurt Lair (operator leak-site branding); part of the Conti-spinoff cohort tracked by Mandiant and CrowdStrike under the Wizard Spider successor-brand umbrella."
      ],
      "active": "yes (continuous May 2021 → present, with periodic operating-tempo dips). Activity tracked through 2024–2025.",
      "first_observed": "2021-05.",
      "host_platforms": [
        "Cross-platform-by-tool-stack — Karakurt does not develop or deploy a custom encryptor and is not",
        "in the strict sense",
        "a \"ransomware family.\" Its operating tooling is a curated configuration of commodity post-exploitation and exfiltration utilities: Cobalt Strike (OAK-S37)",
        "Mimikatz",
        "AnyDesk",
        "rclone (the dominant Karakurt-fingerprint exfiltration utility)",
        "Filezilla / WinSCP",
        "Mega.io's MEGAsync",
        "and a custom set of automated victim-data-publication scripts running against the Karakurt Lair leak site."
      ],
      "used_by_groups": [
        "OAK-G18"
      ],
      "observed_techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T8.001",
        "OAK-T8.002"
      ],
      "citations": [
        "chainalysis2022conti",
        "cisaaa22152a",
        "contileaks2022",
        "crowdstrikewizardspider2022",
        "mandiantcontileaks2022"
      ],
      "source_file": "software/OAK-S36-karakurt-extortion-kit.md"
    },
    {
      "id": "OAK-S37",
      "name": "Cobalt Strike",
      "type": "tool / commodity post-exploitation framework (legitimate red-team product, widely abused)",
      "aliases": [
        "Cobalt Strike Beacon (the canonical implant component); CS (industry shorthand). Originally developed by Raphael Mudge (commercial release 2012); acquired by HelpSystems / Fortra in 2020. external cyber-threat-intel taxonomy ID S0154."
      ],
      "active": "yes — both legitimate licensed deployments (red-team, penetration-testing) and the much-larger cracked-and-trojaned threat-actor population. Continuous abuse since approximately 2015; remains the dominant single post-exploitation framework in OAK-relevant ransomware-and-targeted-intrusion deployments through 2025.",
      "first_observed": "2012 (legitimate commercial release); first widely-documented criminal abuse approximately 2015–2016; ubiquity in major-RaaS-deployment chains established by 2020.",
      "host_platforms": [
        "Windows (primary, all variants); cross-platform Beacon variants (Linux, macOS) exist in legitimate licensed deployments and have been observed in some cracked-criminal deployments through 2024."
      ],
      "used_by_groups": [
        "OAK-G05",
        "OAK-G09",
        "OAK-G10",
        "OAK-G11",
        "OAK-G14",
        "OAK-G15",
        "OAK-G16",
        "OAK-G17",
        "OAK-G18",
        "OAK-G06"
      ],
      "observed_techniques": [
        "OAK-T11.001",
        "OAK-T8.001"
      ],
      "citations": [
        "cisaaa22046a",
        "cisaaa22152a",
        "cisaaa24131a",
        "mandiant3cx2023",
        "mandiantradiant2024",
        "microsoftcitrineradiant2024"
      ],
      "source_file": "software/OAK-S37-cobalt-strike.md"
    },
    {
      "id": "OAK-S38",
      "name": "IcedID + Pikabot loaders",
      "type": "malware / commodity loader (initial-access broker class)",
      "aliases": [
        "IcedID — also tracked as BokBot (CrowdStrike) and as TA551-and-derivatives (Proofpoint historical naming for some delivery cohorts). Pikabot — successor-and-overlap loader to Qakbot (OAK-S40)",
        "tracked by Trend Micro",
        "Elastic",
        "and Zscaler from early 2023. The two are combined into a single OAK-S entry because they share the Russian-cybercrime-ecosystem operator substrate",
        "the initial-access-broker operating role",
        "and the May 2024 Operation Endgame disruption-event scope."
      ],
      "active": "IcedID — yes (2017 → present, with reduced post-Operation-Endgame tempo). Pikabot — yes (2023 → present, with reduced post-Operation-Endgame tempo).",
      "first_observed": "IcedID — 2017 (originally a banking-trojan; pivoted to ransomware-loader role from approximately 2020 onward). Pikabot — early 2023 (post-Qakbot-takedown gap-filling role established by Q2 2023).",
      "host_platforms": [
        "Windows (primary, all variants)."
      ],
      "used_by_groups": [
        "OAK-G05",
        "OAK-G10",
        "OAK-G11",
        "OAK-G14",
        "OAK-G16",
        "OAK-G17",
        "OAK-G18"
      ],
      "observed_techniques": [
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T8.001"
      ],
      "citations": [
        "chainalysis2024lockbit",
        "cisaaa24131a",
        "mandiantcontileaks2022",
        "microsoftstorm1811"
      ],
      "source_file": "software/OAK-S38-icedid-pikabot.md"
    },
    {
      "id": "OAK-S39",
      "name": "DanaBot",
      "type": "malware / banking trojan + commodity loader",
      "aliases": [
        "DanaBot (the canonical industry naming since 2018); external cyber-threat-intel taxonomy ID S0634. Some early 2018 reporting tracked DanaBot under the placeholder name \"Trojan.Win32.Spy\" before family-level naming stabilised."
      ],
      "active": "yes through May 2024 (Operation Endgame target). Post-Operation-Endgame the operating-tempo has been significantly reduced; activity continues through 2025 at lower volume.",
      "first_observed": "2018-05.",
      "host_platforms": [
        "Windows (primary, all variants)."
      ],
      "used_by_groups": [
        "OAK-G05",
        "OAK-G10",
        "OAK-G11",
        "OAK-G16"
      ],
      "observed_techniques": [
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T8.001"
      ],
      "citations": [
        "chainalysis2024lockbit",
        "cisaaa24131a",
        "microsoftstorm1811"
      ],
      "source_file": "software/OAK-S39-danabot.md"
    },
    {
      "id": "OAK-S40",
      "name": "Qakbot / Pinkslipbot / QBot",
      "type": "malware / banking trojan + commodity loader",
      "aliases": [
        "Qakbot (the dominant industry naming since approximately 2010); QBot (CrowdStrike historical naming); Pinkslipbot (an earlier-era name from Symantec / Broadcom). external cyber-threat-intel taxonomy ID S0650. One of the longest-running individual malware families on the OAK-relevant timeline."
      ],
      "active": "sunset for original infrastructure post-August 2023 (Operation Duck Hunt). Cohort-level operating substrate persists in OAK-S38 Pikabot which is structurally a successor-and-overlap loader rebuilt by the same Russian-cybercrime-ecosystem operator cohort.",
      "first_observed": "approximately 2008 (initial banking-trojan operation; some pre-2008 ancestor variants are documented but the family-level naming stabilises at 2008–2010).",
      "host_platforms": [
        "Windows (primary, all variants)."
      ],
      "used_by_groups": [
        "OAK-G05",
        "OAK-G10",
        "OAK-G11",
        "OAK-G14"
      ],
      "observed_techniques": [
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T8.001"
      ],
      "citations": [
        "chainalysis2024lockbit",
        "cisaaa22046a",
        "cisaaa24131a",
        "mandiantcontileaks2022",
        "microsoftstorm1811"
      ],
      "source_file": "software/OAK-S40-qakbot-pinkslipbot.md"
    },
    {
      "id": "OAK-S41",
      "name": "RemotePE",
      "type": "malware (Windows fileless remote-access-trojan)",
      "aliases": [
        "RemotePE (canonical Fox-IT / NCC Group naming, September 2025); DPAPILoader / RemotePELoader (the two preceding loader stages in the three-stage chain, sometimes reported as part of the same family)."
      ],
      "active": "yes — first discovered September 2025; active campaigns tracked through Q1–Q2 2026.",
      "first_observed": "2025-09 (Fox-IT / NCC Group discovery and public disclosure; the Iassvc.dll DPAPILoader stage has been observed in the wild since November 2023, suggesting the loader infrastructure predates the RemotePE final-stage payload).",
      "host_platforms": [
        "Windows (the only platform observed in public reporting; Fox-IT analysis describes a Windows-only implementation; DPAPI environmental keying is a Windows-native mechanism; no macOS or Linux variants documented as of v0.1)."
      ],
      "used_by_groups": [
        "OAK-G01"
      ],
      "observed_techniques": [
        "OAK-T15.001",
        "OAK-T15.003",
        "OAK-T11.001"
      ],
      "citations": [
        "chainalysis2024dprk",
        "chainalysis2024laundering",
        "cisaaa22108a",
        "foxitremotepe2025",
        "trmlabsdprk2026"
      ],
      "source_file": "software/OAK-S41-remotepe.md"
    }
  ],
  "groups": [
    {
      "id": "OAK-G01",
      "name": "Lazarus Group / DPRK-attributed crypto theft",
      "aliases": [
        "APT38",
        "BlueNoroff",
        "Hidden Cobra",
        "Andariel",
        "TraderTraitor\" (FBI naming for DPRK crypto-theft cluster)."
      ],
      "attribution_status": "**confirmed** by FBI public statements, U.S. Treasury OFAC designations, U.S. Department of Justice indictments, and multiple national CERT bodies (KISA, NCSC, BSI). Attribution to the Reconnaissance General Bureau of the DPRK is the standing public position of the U.S. government.",
      "first_observed": "approximately 2017 (Sony Pictures intrusions and SWIFT-targeting predate; crypto pivot consolidated 2017–2018).",
      "active": "yes (as of v0.1).",
      "source_file": "actors/OAK-G01-lazarus.md"
    },
    {
      "id": "OAK-G02",
      "name": "Drainer-as-a-Service operators",
      "aliases": [
        "Phishing-as-a-Service crypto wallet drainers. Specific named operators include Inferno Drainer",
        "Angel Drainer",
        "Pink Drainer / Pinkdrainer",
        "Monkey Drainer",
        "Venom Drainer",
        "and their successors."
      ],
      "attribution_status": "**inferred-strong** at the service-family level (industry forensic providers with consistent published attributions). Per-incident operator-of-record attribution within a service family is generally **inferred-weak** and is not published per-incident at v0.1.",
      "first_observed": "approximately 2022 (commercial drainer services emerge alongside Permit2 adoption).",
      "active": "yes; significant continuity-of-infrastructure across operator handovers (e.g., Inferno → Angel handover October 2024 per `[slowmist2024report]`).",
      "source_file": "actors/OAK-G02-drainer-services.md"
    },
    {
      "id": "OAK-G03",
      "name": "Russian-attributed crypto-laundering infrastructure cluster (Garantex / Grinex / A7A5 lineage)",
      "aliases": [
        "Garantex (April 2022 – March 2025 operational; sanctioned)",
        "Garantex Europe OÜ (Estonian-incorporated entity)",
        "Grinex (March 2025 successor exchange)",
        "the A7A5 ruble-stablecoin network (sanctioned August 2025)",
        "and the broader Russia-clustered laundering-rail cohort that has historically also included Hydra Market (Russian-language darknet market, sanctioned April 2022 alongside Garantex). For OAK-G03 purposes the *cluster* is the Garantex–Grinex–A7A5 successor chain plus its persistently-overlapping operator network",
        "not any single brand."
      ],
      "attribution_status": "**confirmed** at the *infrastructure-and-named-operator* level for the Garantex sub-cluster — U.S. Treasury OFAC SDN designation April 5, 2022 (`[ofac2022garantex]`); DOJ Eastern District of Virginia indictment unsealed February 27, 2025 against named administrators Aleksej Besciokov and Aleksandr Mira Serda (`[doj2025garantex]`); coordinated U.S. Secret Service / German BKA / Finnish NBI takedown action March 6, 2025; second OFAC designation round August 14, 2025 against Grinex and the A7A5 token network (`[treasury2025garantexnetwork]`). Attribution that the Garantex cluster *received and processed proceeds* from specific upstream criminal categories — Conti ransomware (\\~\\$6M direct inflow), Hydra darknet market (\\~\\$2.6M direct inflow), and a longer tail of ransomware-affiliate flows — is **inferred-strong** from industry forensic providers (Chainalysis, Elliptic, TRM Labs) cited in the Treasury press releases.",
      "first_observed": "approximately 2019 (Garantex incorporated; Estonian licensing 2019, license revoked February 2022).",
      "active": "yes (as of v0.1) — Garantex original-domain operations dismantled March 6 2025, but Grinex successor and A7A5 token network operationally active through 2025; Treasury's August 14 2025 designation describes Grinex as having \"facilitated the transfer of billions of dollars in cryptocurrency transactions\" since its post-takedown creation, and the A7A5 token network as processing approximately \\$1B in transactions daily at the time of designation.",
      "source_file": "actors/OAK-G03-russian-laundering-infrastructure.md"
    },
    {
      "id": "OAK-G04",
      "name": "DPRK IT-Worker Placement Scheme",
      "aliases": [
        "DPRK IT workers",
        "North Korean IT worker fraud scheme",
        "remote-IT-worker placement scheme",
        "sometimes referred to in industry forensic reporting as the \"insider-as-revenue-channel\" complement to Lazarus / TraderTraitor (OAK-G01) cyber operations. Named operator-network entities in the public record include the Chinyong Information Technology Cooperation Company (a.k.a. Jinyong IT Cooperation Company; sanctioned May 23, 2023) and U.S.-based laptop-farm facilitators (Christina Marie Chapman, Erick Ntekereze Prince, Emanuel Ashtor, and others named in DOJ indictments)."
      ],
      "attribution_status": "**confirmed** at the *scheme-and-named-facilitator* level — joint U.S. State / Treasury / FBI advisory dated May 16, 2022 (`[fbidprkitworker2022]`); OFAC SDN designations of Chinyong IT Cooperation Company and Kim Sang Man on May 23, 2023 (`[treasurydprkitworker2023]`); multiple DOJ indictments and convictions, including the Christina Marie Chapman \"laptop farm\" prosecution (guilty plea February 2024; sentenced 102 months / July 2025) (`[dojchapmanindictment2024]`) and the Jin Sung-Il / Pak Jin-Song et al. five-defendant indictment (Southern District of Florida, January 2025); March 2026 OFAC round designating six individuals and two entities for IT-worker fraud (`[ofac2026dprkitworker]`). Attribution that *specific crypto-firm exploits* are downstream of an OAK-G04 placement (Munchables March 2024; Solareum and other industry-reported cases) is **inferred-strong** from forensic providers (Chainalysis, TRM Labs, ZachXBT) where the on-chain signature, hire-then-exploit timeline, and identity-overlap evidence are jointly documented.",
      "first_observed": "approximately 2018, per industry forensic reporting that DPRK IT workers were obtaining engineering roles at crypto and Web3 firms under false identities by at least that year. Public attribution and enforcement action accelerate from 2022 forward.",
      "active": "yes (as of v0.1) — Chainalysis estimates the IT-worker stream generated approximately \\$800M for the DPRK in 2024 and the channel is continuing to expand into 2025–2026 per `[chainalysis2024dprk]` and follow-on Chainalysis reporting; OFAC is sustaining a tempo of designations against the network, and DOJ indictments and laptop-farm prosecutions are ongoing.",
      "source_file": "actors/OAK-G04-dprk-it-worker-scheme.md"
    },
    {
      "id": "OAK-G05",
      "name": "LockBit Ransomware-as-a-Service operation",
      "aliases": [
        "LockBit (operating brand 2019–present, with version lineage LockBit 1.0 / LockBit 2.0 a.k.a. LockBit Red / LockBit 3.0 a.k.a. LockBit Black / LockBit Green / a 2024 LockBit-NG-Dev pre-release recovered during Operation Cronos)",
        "LockBitSupp\" (the principal operator persona on Russian-language criminal forums, publicly identified May 7, 2024 as Dmitry Yuryevich Khoroshev)",
        "and the affiliate cohort named in DOJ indictments (Mikhail Vasiliev, Ruslan Magomedovich Astamirov, Mikhail Pavlovich Matveev a.k.a. \"Wazawaka,\" Artur Sungatov, Ivan Gennadievich Kondratyev a.k.a. \"Bassterlord\"). For OAK-G05 purposes the *cluster* is the LockBit RaaS operation — the core operator network around Khoroshev plus the indicted-and-named affiliate set — not any single LockBit-encryptor variant."
      ],
      "attribution_status": "**confirmed** at the *operator-and-named-affiliate* level — coordinated U.K. National Crime Agency / U.S. FBI / Europol \"Operation Cronos\" disruption announced February 20, 2024 (`[nca2024operationcronos]`); U.S. Treasury OFAC SDN designations of Russian nationals Artur Sungatov and Ivan Kondratyev with ten cryptocurrency addresses listed as SDN identifiers, February 20, 2024 (`[ofac2024lockbitaffiliates]`); U.S. Department of Justice 26-count indictment unsealed May 7, 2024 against Dmitry Yuryevich Khoroshev as the LockBit developer-and-administrator, accompanied by OFAC SDN designation of Khoroshev personally and a U.S. Department of State \\$10M reward (`[doj2024khoroshev]`, `[ofac2024khoroshev]`); coordinated U.K. FCDO and Australia DFAT designations the same day; subsequent OFAC action against the Russian web-hosting provider Aeza Group for hosting LockBit infrastructure (`[ofac2025aeza]`). Attribution that *specific ransom-payment flows* trace through specific downstream laundering infrastructure (Garantex / OAK-G03, Sinbad mixer, Bitzlato) is **inferred-strong** from industry forensic providers (Chainalysis, TRM Labs) and the U.K. NCA's \"Behind the Screens\" wallet-tracing publication.",
      "first_observed": "approximately January 2020 (LockBit 1.0 first observed; the RaaS model with cryptocurrency-denominated ransom payments has been the operational default since inception).",
      "active": "degraded but not extinct (as of v0.1) — Operation Cronos seized 34 servers, took control of the leak site, recovered approximately 7,000 decryption keys, froze approximately 200 cryptocurrency accounts, and closed 14,000 affiliate-rogue accounts on February 19–20, 2024. Per `[chainalysis2025ransomware]`, LockBit ransom-payment volume in H2 2024 fell approximately 79% versus H1, and the brand's market share among RaaS strains collapsed through 2024–2025. Khoroshev remained at large in Russia as of v0.1 publication (the \\$10M reward is for information leading to apprehension); LockBit-branded extortion activity continued at a much-reduced cadence post-Cronos, and successor or splinter-affiliate activity rebranding off the LockBit codebase is ongoing.",
      "source_file": "actors/OAK-G05-lockbit.md"
    },
    {
      "id": "OAK-G06",
      "name": "Evil Corp",
      "aliases": [
        "Evil Corp (the public name in OFAC, DOJ, NCA, FCDO, and DFAT designations from 2019 onward); the operational lineage variously tracked in industry reporting as Indrik Spider (CrowdStrike)",
        "TA505-adjacent (Proofpoint, with caveats — TA505 and Evil Corp are distinct clusters that have been confused in early reporting)",
        "UNC2165 (Mandiant, used specifically for the WastedLocker / Hades / Phoenix CryptoLocker / PayloadBIN / Macaw Locker post-2019 ransomware-rotation phase)",
        "the original \"Jabber Zeus Crew\" / \"Business Club\" Moscow circle from which the operation evolved circa 2007–2014",
        "and the persona \"aqua\" / \"aquamo\" attached publicly to Maksim Viktorovich Yakubets per the December 2019 DOJ indictment. The named-defendant set across the December 2019 and October 2024 actions includes Maksim Viktorovich Yakubets (founder, principal)",
        "Igor Olegovich Turashev (administrator)",
        "Viktor Yakubets (Maksim's father)",
        "Artem Yakubets (Maksim's brother)",
        "Eduard Benderskiy (Maksim's father-in-law, former FSB Spetsnaz officer designated October 1, 2024 as the FSB-link node)",
        "and Aleksandr Viktorovich Ryzhenkov a.k.a. \"Lizardking\" (designated and indicted October 1, 2024 as Yakubets's deputy and as a LockBit affiliate operating under the handle \"Beverley\"). For OAK-G06 purposes the *cluster* is the Evil Corp operator family — the Yakubets-centred Russia-resident operator network plus the named-defendant set across the 2019 and 2024 actions — not any single malware strain in their portfolio."
      ],
      "attribution_status": "**confirmed** at the *operator-and-named-defendant* level — U.S. Treasury OFAC SDN designation of Evil Corp as an entity together with seventeen named individuals on December 5, 2019, pursuant to E.O. 13694 / E.O. 13757 (`[ofac2019evilcorp]`); same-day U.S. Department of Justice unsealed indictments in the Western District of Pennsylvania and the District of Nebraska charging Yakubets and Turashev with conspiracy, computer hacking, wire fraud, and bank fraud (`[doj2019yakubets]`); U.S. Department of State \\$5M reward for information leading to the arrest of Yakubets (the largest such reward for a cybercriminal at the time of issuance); coordinated trilateral sanctions architecture announced October 1, 2024 with U.S. Treasury OFAC, U.K. Foreign, Commonwealth and Development Office (FCDO) via the National Crime Agency, and Australia Department of Foreign Affairs and Trade (DFAT) jointly designating sixteen Evil Corp members and associates including Viktor Yakubets and Eduard Benderskiy as the FSB-link node (`[ofac2024evilcorp]`, `[nca2024evilcorp]`); same-day U.S. DOJ unsealed seven-count indictment of Aleksandr Ryzhenkov in the Northern District of Texas explicitly naming the BitPaymer-and-LockBit-affiliate dual-track activity (`[doj2024ryzhenkov]`); explicit Treasury and NCA findings that Yakubets has provided material assistance to the Russian Federal Security Service (FSB) — the FSB-link finding was the December 2019 designation's stated rationale and was reinforced in the October 2024 designation through the Benderskiy nexus. Attribution that *specific ransom-payment flows* trace through specific downstream laundering venues (Garantex / OAK-G03, mixers, non-KYC exchanges) is **inferred-strong** from industry forensic providers (Chainalysis, TRM Labs) and from the U.K. NCA's October 2024 \"Behind the Screens\" publication (`[chainalysisevilcorp2024]`, `[trmevilcorp2024]`).",
      "first_observed": "approximately 2014 (Dridex banking-trojan operation began circa 2014 with cryptocurrency-wallet credential-theft modules added by approximately September 2016; ransomware-with-cryptocurrency-payments operation began with BitPaymer in 2017).",
      "active": "yes (degraded but operationally persistent as of v0.1) — the December 2019 sanctions produced a documented step-change in Evil Corp's operating model: ransomware-negotiation firms refused to process payments to Evil Corp-attributable wallets due to OFAC-violation exposure, which triggered a sustained brand-rotation cycle through WastedLocker (June 2020), Hades (December 2020), Phoenix CryptoLocker (2021), PayloadBIN (2021), Macaw Locker (2021), and ultimately a documented migration of senior operators including Ryzhenkov onto third-party RaaS platforms — most importantly LockBit (OAK-G05) — to \"blend in\" with the broader affiliate cohort and re-enable ransom collection from sanctions-cautious victims (`[mandiantunc2165]`). The October 2024 trilateral action and the public unmasking of Ryzhenkov as a LockBit affiliate explicitly closed the Evil-Corp-via-LockBit blend-in route. As of v0.1 publication, no named Evil Corp operator has been apprehended; all remained at large in Russia.",
      "source_file": "actors/OAK-G06-evil-corp.md"
    },
    {
      "id": "OAK-G07",
      "name": "APT43 / Kimsuky (DPRK espionage-and-self-funding cluster)",
      "aliases": [
        "APT43 (Mandiant)",
        "Kimsuky (industry-default name; in widest current public use; tracked under external Group ID G0094)",
        "Velvet Chollima (CrowdStrike)",
        "Black Banshee",
        "Emerald Sleet (Microsoft)",
        "Thallium (Microsoft legacy)",
        "TA427 (Proofpoint)",
        "ARCHIPELAGO (Google TAG)",
        "Nickel Kimball",
        "Springtail. For OAK-G07 purposes the *cluster* is the DPRK Reconnaissance General Bureau (RGB) sub-element whose primary mission is strategic cyber-espionage with cryptocurrency theft and laundering as a *self-funding* support function — operationally and missionally distinct from the OAK-G01 Lazarus Group / APT38 / BlueNoroff cluster whose primary mission is regime-revenue-generating crypto theft",
        "and from the OAK-G04 IT-worker-placement scheme."
      ],
      "attribution_status": "**confirmed** at the *cluster-and-state-attribution* level — U.S. Department of the Treasury OFAC SDN designation of Kimsuky on November 30, 2023 (`[ofac2023kimsuky]`, Treasury press release JY1938) carried out in coordination with Australia, Japan, and the Republic of Korea, attributing the cluster to the DPRK Reconnaissance General Bureau (RGB) and citing intelligence-gathering in support of the DPRK's strategic objectives following the November 1, 2023 reconnaissance-satellite launch; Republic of Korea sanctions designation of Kimsuky by the Ministry of Foreign Affairs / NIS, June 2, 2023 (`[mofakimsuky2023]`), the first time South Korea sanctioned a North Korean hacking group; joint cyber-security advisory of March 20, 2023 issued by the German Bundesamt für Verfassungsschutz (BfV) and the Republic of Korea National Intelligence Service (NIS) characterising Kimsuky's tooling and TTPs (`[bfvnis2023kimsuky]`); Mandiant APT43 report of March 28, 2023 attributing the cluster to the RGB at *moderate confidence* and documenting the cryptocurrency-funded operational model in technical detail (`[mandiantapt432023]`); external Group ID G0094 with sustained multi-vendor corroboration (CrowdStrike, Microsoft, Proofpoint, Google TAG, Recorded Future, Kaspersky). Attribution that *specific cryptocurrency-theft incidents* are downstream of an OAK-G07 placement (rather than an OAK-G01 placement) is **inferred-strong** in most cases — the cluster boundary between G01 (BlueNoroff / APT38 financial-theft sub-cluster) and G07 (APT43 / Kimsuky espionage-and-self-funding sub-cluster) is operationally meaningful but not always cleanly resolvable per-incident from public reporting.",
      "first_observed": "approximately 2018–2019 (Kimsuky activity dates to at least 2012 per multiple national-CERT advisories; the cryptocurrency-funded operational model is documented from Mandiant's 2018-onwards tracking forward, with public characterisation crystallising in the March 2023 Mandiant APT43 report).",
      "active": "yes (as of v0.1) — sanctions tempo sustained through 2024–2026; Mandiant-, CrowdStrike-, and Microsoft-tracked campaigns ongoing; recent reporting documents continued targeting of cryptocurrency-wallet credentials (MetaMask, Trust Wallet) via VBScript / PowerShell loaders alongside the cluster's traditional spear-phishing-against-policy-targets campaigns.",
      "source_file": "actors/OAK-G07-apt43-kimsuky.md"
    },
    {
      "id": "OAK-G08",
      "name": "BlueNoroff (DPRK financial-institution and crypto-firm intrusion sub-cluster)",
      "aliases": [
        "BlueNoroff (Kaspersky GReAT, industry-default name; in widest current public use)",
        "APT38 (Mandiant / FBI taxonomy — see Discussion on the BlueNoroff / APT38 partial-overlap)",
        "Sapphire Sleet (Microsoft, post-2023 sub-cluster naming; some sources also map to Stardust Chollima / CryptoCore depending on the campaign window)",
        "CageyChameleon",
        "Copernicium",
        "TA444 (Proofpoint, primarily for the cluster's macOS-targeted activity). For OAK-G08 purposes the *cluster* is the DPRK Reconnaissance General Bureau (RGB) sub-element whose primary mission is direct financial-institution and crypto-firm intrusion via macOS-targeted spear-phishing of engineering and finance staff under fake-investor / fake-VC / fake-partnership lures",
        "and via supply-chain-inserted malicious npm and PyPI packages — operationally distinct from the OAK-G01 Lazarus / TraderTraitor cluster (which centres the trojanized-trading-app and recruiter-on-LinkedIn-to-engineering-staff vector per CISA AA22-108A) and from the OAK-G09 Andariel cluster (espionage-and-ransomware-funded sub-element with a defence-industrial and healthcare-sector targeting profile)."
      ],
      "attribution_status": "**confirmed** at the *cluster-and-state-attribution* level — U.S. Department of the Treasury OFAC SDN designation of BlueNoroff on September 13, 2019 under Executive Orders 13694 and 13757 (Treasury press release SM-774, designating Lazarus Group, BlueNoroff, and Andariel as three separate sub-cluster entries belonging to the DPRK Reconnaissance General Bureau) (`[ofac2019dprkclusters]`); external Group ID G0082 (BlueNoroff) and G0079 / G0138 mappings for the APT38 / TraderTraitor naming overlap; CISA / FBI / Treasury joint cybersecurity advisory AA22-108A of April 2022 documenting the *TraderTraitor* sub-set of cluster activity — partially but not entirely co-extensive with BlueNoroff (`[cisa2022tradertraitor]`); long-running multi-vendor industry-forensic record across Kaspersky GReAT (BlueNoroff naming origin, 2017 onward), Mandiant (APT38 naming, 2018 onward), Jamf Threat Labs (RustBucket macOS family, 2023 onward), SentinelOne (ObjCShellz / RustBucket follow-on, 2023), Volexity, and Microsoft Threat Intelligence (Sapphire Sleet naming, 2023 onward). Attribution that *specific cryptocurrency-theft incidents* are downstream of an OAK-G08 placement (rather than an OAK-G01 placement) is **inferred-strong** in most cases — the BlueNoroff / TraderTraitor sub-cluster boundary inside the broader Lazarus / RGB whole is operationally meaningful but not always cleanly resolvable per-incident from public reporting; some incidents (DMM Bitcoin, May 2024) are attributed to TraderTraitor in primary FBI / DC3 / NPA documents while concurrent industry write-ups discuss BlueNoroff overlap.",
      "first_observed": "approximately 2017 (Kaspersky-attributed Lazarus / BlueNoroff splits from the broader Lazarus framing in early 2017; SWIFT-network targeting against the Bangladesh Bank in February 2016 — the canonical \\$81M pre-crypto BlueNoroff event — is the cluster's documented financial-institution origin point; the crypto-exchange and crypto-VC pivot is documented from 2017–2018 onward, with the SnatchCrypto campaign tracked from at least 2017 by Kaspersky GReAT).",
      "active": "yes (as of v0.1) — sustained 2023–2026 reporting tempo; the 2023 RustBucket / ObjCShellz / KandyKorn macOS family, the 2024 Hidden Risk fake-crypto-news-PDF campaign (SentinelOne / Jamf), and ongoing 2024–2025 npm and PyPI supply-chain insertion activity (Phylum, Socket, Datadog Security Labs reporting) all attributed to or substantially overlapping with this cluster.",
      "source_file": "actors/OAK-G08-bluenoroff.md"
    },
    {
      "id": "OAK-G09",
      "name": "Andariel (DPRK ransomware-and-ICS sub-cluster within the Lazarus / RGB ecosystem)",
      "aliases": [
        "Andariel (industry-default name; KISA / ROK National Police Agency naming; tracked under external Group ID G0138)",
        "Silent Chollima (CrowdStrike)",
        "Onyx Sleet (Microsoft, post-Plutonium rename)",
        "Plutonium (Microsoft legacy)",
        "DarkSeoul (legacy ROK incident-cluster name applied by some industry retrospectives)",
        "Stonefly (Symantec / Broadcom — partial overlap, used for the cluster's healthcare-and-DIB intrusion sub-stream)",
        "and APT45 (Mandiant — partial overlap; Mandiant uses APT45 for a DPRK ransomware-and-financial-cyber-cluster that overlaps substantially with the Andariel set tracked by KISA and CISA, with non-trivial fingerprint differences from the BlueNoroff / APT38 cluster). For OAK-G09 purposes the *cluster* is the DPRK Reconnaissance General Bureau (RGB) sub-element responsible for ransomware operations against healthcare and critical-infrastructure targets",
        "intelligence-collection intrusions against the defence-industrial base (DIB) and engineering / energy verticals",
        "and opportunistic cryptocurrency-mining-as-monetization on compromised systems — operationally and missionally distinct from the OAK-G01 Lazarus / TraderTraitor cluster (crypto-firm engineering compromise) and from the OAK-G08 BlueNoroff / APT38 cluster (macOS-engineering-led crypto-firm intrusion)",
        "with which Andariel shares parent-organisation substrate but not operator behaviour."
      ],
      "attribution_status": "**confirmed** at the *cluster-and-state-attribution* level — U.S. Department of the Treasury OFAC SDN designation of Andariel under Executive Orders 13694 and 13722 on September 13, 2019 (`[ofac2019dprkcyber]`, Treasury press release SM-774), in coordinated action that designated Lazarus, BlueNoroff, and Andariel as three separate but related DPRK state-sponsored sub-clusters subordinate to the Reconnaissance General Bureau; CISA / FBI / U.S. Treasury joint cybersecurity advisory AA22-187A of July 6, 2022, \"North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector,\" with explicit Andariel attribution and the canonical public characterisation of the Maui-ransomware-against-healthcare operational pattern (`[cisa2022aa22187a]`); U.S. Department of Justice unsealed indictment of Rim Jong Hyok of July 25, 2024, charging the named Andariel operator with a multi-year campaign of healthcare-sector ransomware attacks and DIB-intrusion espionage, accompanied by a U.S. Department of State \\$10M reward (`[doj2024rimjonghyok]`); CISA / FBI / NSA / ROK NIS / NPA / DSA / U.K. NCSC joint cybersecurity advisory of July 25, 2024, \"North Korea state-sponsored cyber group conducts global espionage campaign to advance regime's military and nuclear programs\" (`[cisa2024andarieladvisory]`); ROK National Police Agency public attribution actions of 2023–2024; sustained multi-vendor industry-forensic record (Mandiant APT45 reporting, Microsoft Onyx Sleet reporting, Kaspersky Andariel reporting, SentinelOne, Symantec / Broadcom Stonefly reporting). Attribution that *specific cryptocurrency ransom-payment flows* trace to G09 versus other DPRK ransomware-touching activity is **inferred-strong** in most cases — the Maui-ransomware-attributed payment surface is small relative to the Lazarus crypto-theft surface, and per-victim public reporting of payment-trail forensics is sparse. Attribution that *specific Black Basta–attributed payments* trace to Andariel rather than to the Russian-speaking Black Basta core is **inferred-strong** at best and is flagged in Discussion below; OAK does not publish the Andariel × Black Basta overlap as confirmed at v0.1.",
      "first_observed": "approximately 2017 (DTrack / similar pre-Maui intrusion tooling pre-dates; the *cryptocurrency-denominated-ransom-payment* operational model crystallises with the Maui ransomware family from 2021 onwards per the CISA / FBI / Treasury joint advisory AA22-187A of July 6, 2022; cryptocurrency-mining intrusions on compromised DIB and engineering systems via xmrig deployments are documented across multiple industry reports from 2022 onward).",
      "active": "yes (as of v0.1) — sanctions and indictment tempo sustained through 2024 (the Rim Jong Hyok indictment and multi-government joint advisory both date from July 25, 2024); Mandiant-, Microsoft-, Kaspersky-, and Symantec-tracked campaigns ongoing; healthcare-sector and DIB-vertical targeting continues, with cryptocurrency-mining intrusions on compromised systems documented across 2024–2026 industry reporting.",
      "source_file": "actors/OAK-G09-andariel.md"
    },
    {
      "id": "OAK-G10",
      "name": "ALPHV / BlackCat Ransomware-as-a-Service operation",
      "aliases": [
        "ALPHV (the operating brand on the Russian-language criminal-forum side, Nov 2021 — Mar 2024)",
        "BlackCat (the industry-default name derived from the leak-site icon and binary self-identification)",
        "Noberus (Symantec / Broadcom tracker name)",
        "and the affiliate cohort that overlapped with the *Scattered Spider* / *UNC3944* / *Octo Tempest* / *Muddled Libra* social-engineering crew (named in subsequent DOJ indictments unsealed across 2024). For OAK-G10 purposes the *cluster* is the ALPHV/BlackCat RaaS operation — the core operator network behind the Rust-based ALPHV encryptor and its affiliate-management infrastructure",
        "considered jointly with the Scattered-Spider-aligned affiliate stream that ran the highest-impact ALPHV intrusions of 2023 — not any single ALPHV-encryptor variant and not Scattered Spider as a standalone actor (Scattered Spider operated against multiple RaaS strains and warrants its own future OAK-Gnn entry on the same per-cluster identity principle that motivated splitting G07 from G01)."
      ],
      "attribution_status": "**confirmed** at the *operator-cluster-and-named-affiliate* level — U.S. Federal Bureau of Investigation / Department of Justice disruption operation announced December 19, 2023, including FBI access to the ALPHV decryptor and a CISA / FBI joint advisory characterising the cluster's TTPs (`[fbi2023blackcatdisruption]`, `[cisa2023blackcatadvisory]`); DOJ indictments unsealed across 2024 against multiple Scattered Spider members for the September 2023 MGM Resorts and Caesars Entertainment campaigns and earlier Reddit-targeting activity (`[doj2024scatteredspider]`); HHS / U.S. Department of Health and Human Services public advisories on the February 21, 2024 Change Healthcare incident (`[hhs2024changehealthcare]`); sustained multi-vendor industry-forensic corroboration (Mandiant, Microsoft, Sophos, SentinelOne, Recorded Future, Chainalysis, TRM Labs, Symantec) characterising the Rust-based encryptor lineage, the Russian-language operator-forum substrate, the affiliate-cut economics, and the February-to-March 2024 self-exit-scam dynamic. ALPHV itself was not OFAC-designated as a cluster within its operating window; that distinction makes G10 a *confirmed-by-disruption-and-indictment* rather than *confirmed-by-OFAC-SDN-designation* case at v0.1, which is operationally important for the *asset-freeze counter-factual* discussed below. Attribution that *specific ransom-payment flows* trace to specific affiliate wallets within the ALPHV cluster is **inferred-strong** from industry forensic providers; the canonical instance is the \\~\\$22M Bitcoin payment from Change Healthcare that was traced on-chain by Chainalysis and TRM Labs to an affiliate wallet before the operator-side exit-scam diverted the funds out of affiliate control (`[chainalysis2024alphvexit]`, `[trm2024changehealthcare]`).",
      "first_observed": "approximately November 2021 (ALPHV leak-site / RaaS-recruitment posts first observed on Russian-language criminal forums; the RaaS model with Bitcoin- and Monero-denominated ransom payments has been the operational default since inception, with Monero offered at a discount versus Bitcoin to reduce the operator-side laundering load).",
      "active": "**inactive** as of v0.1 — the ALPHV-branded operation effectively ended on or around March 1–5, 2024 with the operator-side *exit-scam shutdown*: after the Change Healthcare ransom was paid in late February 2024, the ALPHV operator absconded with the affiliate's share of the proceeds, staged a fake \"FBI seizure\" banner on the ALPHV leak site (visibly distinguishable from the real Operation Cronos LockBit takedown banner), and shuttered the RaaS infrastructure. Per `[chainalysis2025ransomware]` and `[trm2024changehealthcare]`, the affiliate (\"Notchy\") publicly accused the ALPHV operator on the RAMP forum of stealing the \\~\\$22M Change Healthcare payment. Per multiple industry trackers, ALPHV-branded extortion activity ceased after early March 2024; affiliate continuity dispersed into successor RaaS strains (RansomHub being the most-cited successor brand for Notchy and overlapping affiliates), and the Scattered-Spider-aligned affiliate stream continued operating against other RaaS providers. OAK-G10 should be read as a *closed* cluster on the operator side and a *dispersed* cluster on the affiliate side, parallel to the Conti-2022 dispersal pattern.",
      "source_file": "actors/OAK-G10-alphv-blackcat.md"
    },
    {
      "id": "OAK-G11",
      "name": "Black Basta Ransomware-as-a-Service operation",
      "aliases": [
        "Black Basta (operating brand on Russian-language criminal forums and the cluster's Tor-hosted \"Basta News\" leak site, April 2022 → late-2024 internal wind-down with successor activity continuing)",
        "Storm-1811 / Storm-0506 (Microsoft tracker names for affiliate sub-clusters that overlapped with the Black Basta cohort during the cluster's active window)",
        "UNC4393 (Mandiant tracker name)",
        "and the Conti-splinter operator-cohort identified across multiple industry-forensic write-ups as carrying Conti-2022 organisational continuity into the Black Basta operating brand. For OAK-G11 purposes the *cluster* is the Black Basta RaaS operation — the core operator network behind the Basta encryptor (Rust-and-C++ lineage with Linux/ESXi cross-platform builds)",
        "the affiliate-management infrastructure",
        "and the leaked-internal-chats operator cohort — not any single Basta-encryptor variant and not the broader Conti-successor cohort as a whole (Conti-successor brands include Black Basta, Royal, Akira, Quantum, BlackByte, and Karakurt; each warrants its own per-cluster identity treatment on the same principle that motivated splitting OAK-G07 from OAK-G01)."
      ],
      "attribution_status": "**confirmed** at the *cluster-and-tooling* level — joint CISA / FBI / HHS / MS-ISAC cyber-security advisory AA24-131A \"StopRansomware: Black Basta,\" May 10, 2024 (`[cisa2024aa24131ablackbasta]`), characterising the cluster's TTPs across the healthcare and other critical-infrastructure sectors and naming Black Basta as a closed RaaS operating brand with hundreds of named victims; sustained multi-vendor industry-forensic corroboration (Mandiant UNC4393 tracking, Microsoft Storm-1811 / Storm-0506 sub-cluster attribution, Recorded Future, SentinelOne, Sophos, Symantec) characterising the encryptor lineage, the Russian-language operator-forum substrate, the Conti-2022-organisational-continuity dispersal pattern, and the affiliate-cut economics; the February 2025 leaked Black Basta internal-chats archive (\"BlackBastaLeaks\"), which surfaced operator-and-affiliate Jabber/Matrix communications and externally validated the cluster-internal organisational structure inferred from prior industry-forensic tracking. The Conti-organisational-continuity claim is *inferred-strong* — overlap of operator personas, Bitcoin-funder-cluster reuse across the Conti-shutdown / Black Basta-launch window, and shared TTPs (QakBot loader chain, Cobalt Strike post-exploit tooling, Empire / BloodHound lateral-movement) are documented across Mandiant, CrowdStrike, and Recorded Future tracking but the cluster has not been individually OFAC-designated or DOJ-indicted at the principal-operator level as of v0.1. Attribution that *specific ransom-payment flows* trace to specific affiliate wallets within the Black Basta cluster is **inferred-strong** from industry forensic providers; the Elliptic 2024 retrospective traced approximately \\$107M in confirmed Bitcoin ransom payments to Black Basta-attributable wallet clusters across the cluster's first 18 months of operation (`[elliptic2024blackbasta]`), with downstream laundering routes sharing the broader Russian-language commercial-criminal off-ramp profile.",
      "first_observed": "April 2022 (Black Basta leak-site / RaaS-recruitment posts first observed on Russian-language criminal forums following the February-to-May 2022 ContiLeaks dispersal; the RaaS model with Bitcoin-denominated ransom payments and Monero-conversion downstream has been the operational default since inception).",
      "active": "**dormant** as of v0.1 — Black Basta-branded extortion activity wound down internally across late 2024 and into Q1 2025 following the February 2025 internal-chats leak, with attributed leak-site posts trailing off and the operator cohort dispersing into successor RaaS strains and into direct affiliate-of-RansomHub / Akira / Cactus engagements per the multi-vendor industry-forensic record. Per `[cisa2024aa24131ablackbasta]` and `[elliptic2024blackbasta]`, Black Basta affiliate continuity is documented across multiple successor brands; OAK-G11 should be read as a *closed-on-operating-brand / dispersed-on-affiliate-side* cluster, structurally parallel to the OAK-G10 ALPHV terminal-phase pattern.",
      "source_file": "actors/OAK-G11-black-basta.md"
    },
    {
      "id": "OAK-G12",
      "name": "Scattered Spider / UNC3944 (English-speaking financially-motivated affiliate cluster)",
      "aliases": [
        "Scattered Spider (industry-default name; in widest current public use)",
        "UNC3944 (Mandiant tracker name)",
        "Octo Tempest (Microsoft)",
        "Muddled Libra (Palo Alto Unit 42)",
        "Roasted 0ktapus / 0ktapus (Group-IB tracker name for the August 2022 Twilio-and-cohort campaign)",
        "Scatter Swine (Okta tracker name)",
        "Storm-0875 (Microsoft sub-cluster tracker)",
        "and the affiliate cohort named in DOJ indictments unsealed across 2024 (notably the November 13, 2024 indictment of five U.S.-and-U.K.-resident defendants — Ahmed Hossam Eldin Elbadawy, Noah Michael Urban, Evans Onyeaka Osiebo, Joel Martin Evans, and Tyler Robert Buchanan — for the MGM Resorts, Caesars Entertainment, and earlier campaigns). For OAK-G12 purposes the *cluster* is the Scattered Spider / UNC3944 affiliate-collective — a loose-network cybercrime cohort that has operated as an affiliate of multiple ransomware-as-a-service brands rather than as a stand-alone RaaS operator — distinct from the OAK-G10 ALPHV / BlackCat operating brand whose ransomware tooling Scattered Spider used during the September 2023 MGM and Caesars campaigns and other 2023 intrusions",
        "and distinct from the broader RansomHub-and-successor cohort that Scattered Spider members migrated to following the March 2024 ALPHV exit-scam."
      ],
      "attribution_status": "**confirmed** at the *cluster-and-named-affiliate* level — U.S. Department of Justice indictments unsealed across 2024 against multiple Scattered Spider members, notably the November 13, 2024 indictment of five U.S.-and-U.K.-resident defendants (Elbadawy, Urban, Osiebo, Evans, Buchanan) for wire fraud, conspiracy, and aggravated identity theft tied to the MGM Resorts and Caesars Entertainment campaigns and earlier intrusions (`[doj2024scatteredspider]`); the July 2024 Spanish National Police arrest of Tyler Robert Buchanan in Palma de Mallorca pursuant to U.S. and U.K. extradition requests; U.K. National Crime Agency arrests of multiple U.K.-resident members through 2024-and-2025; sustained multi-vendor industry-forensic corroboration (Mandiant UNC3944, Microsoft Octo Tempest, Palo Alto Unit 42 Muddled Libra, Group-IB 0ktapus, Okta Scatter Swine, Trellix, CrowdStrike, Recorded Future) characterising the cluster's social-engineering-led intrusion style, the predominantly-English-speaking-and-Western-passport member composition, and the multi-RaaS-affiliate operating model. Attribution that *specific cryptocurrency-firm intrusions* are downstream of a Scattered Spider placement is **inferred-strong** for most cases — multiple 2022-to-2024 cryptocurrency-firm SIM-swap and social-engineering intrusions show TTPs consistent with the Scattered Spider operational profile per Mandiant, Microsoft, and Trellix tracking, but per-incident affiliate-attribution to the named DOJ defendants requires court-filing-level evidentiary specificity that is not always publicly available.",
      "first_observed": "approximately April-to-August 2022 (early Scattered-Spider-attributable intrusions trace to the spring of 2022; the August 2022 Twilio / 0ktapus campaign is the cohort's first widely-reported credential-phishing-and-MFA-fatigue mass campaign and produced the first concentrated industry-forensic attribution write-ups; the cluster's cryptocurrency-firm targeting activity dates to 2022 and intensified across 2022-to-2024 in parallel with the SIM-swap and social-engineering operational profile).",
      "active": "**yes** as of v0.1 — DOJ indictments and arrests through 2024-and-2025 have degraded but not extinguished the cluster; Scattered-Spider-affiliated activity continued through 2025 against multiple sectors (notably the May-to-July 2025 retail-sector campaigns against Marks & Spencer, Co-op, and other U.K. retail brands documented at *inferred-strong* per Mandiant and Microsoft tracking, and continued financial-services and insurance-sector targeting); Tyler Robert Buchanan's extradition from Spain to the U.S. was completed in 2025 with subsequent guilty plea coverage in U.S. federal court. The cluster is structurally a *loose-network* affiliate-collective rather than a centralised operating brand; the November 2024 DOJ indictments named five U.S.-and-U.K.-resident defendants but did not exhaust the cluster, and successor-affiliate activity remains active.",
      "source_file": "actors/OAK-G12-scattered-spider.md"
    },
    {
      "id": "OAK-G13",
      "name": "Iranian financially-motivated cyber operators (MuddyWater + Charming Kitten + Pioneer Kitten cluster set)",
      "aliases": [
        "For OAK-G13 purposes the *cluster set* is the IRGC-and-MOIS-affiliated Iranian cyber-actor cohort whose activity has produced documented cryptocurrency-economy exposure — a composite of three named sub-clusters tracked in the conventional cyber-threat-intel taxonomy: **MuddyWater** (Mandiant tracked as Static Kitten / Mercury / Seedworm; Microsoft Mango Sandstorm / formerly Mercury; external Group ID G0069; Iran's Ministry of Intelligence and Security (MOIS)-attributed per the January 2022 U.S. Cyber Command attribution); **Charming Kitten / APT35** (CrowdStrike tracked; Mandiant APT35 / Newscaster; Microsoft Mint Sandstorm / formerly Phosphorus; external Group ID G0058; IRGC-Intelligence-Organization (IRGC-IO)-attributed per FBI / CISA AA22-055A and prior); and **Pioneer Kitten / Fox Kitten / Lemon Sandstorm / UNC757** (Microsoft Lemon Sandstorm; CrowdStrike Pioneer Kitten; Mandiant UNC757; ClearSky Fox Kitten; FBI / CISA AA20-259A and August 2024 FBI Flash; IRGC-affiliated per multi-vendor industry-forensic and FBI attribution). For OAK-G13 purposes these three sub-clusters are documented jointly because (a) they share IRGC-or-MOIS state-substrate",
        "(b) their *cryptocurrency-economy exposure* (ransomware-with-crypto-payments, cryptocurrency-mining intrusions, OFAC-designated wallet clusters) follows similar patterns despite distinct primary missions",
        "and (c) per-incident sub-cluster partition is *inferred-strong* rather than *confirmed* in many publicly-reported cases. The Pay2Key ransomware operation of late-2020 is the canonical Iranian-state-aligned-with-financially-motivated-cryptocurrency-payment case for the cluster set."
      ],
      "attribution_status": "**confirmed** at the *cluster-set-and-state-attribution* level — multiple OFAC SDN designations against IRGC-affiliated cyber units and individuals across 2018-to-2024 (`[ofac2018samsam]`, `[ofac2020apt39]`, `[ofac2022irgcyber]`); CISA AA22-257A \"Iranian Islamic Revolutionary Guard Corps-Affiliated Cyber Actors Exploiting Vulnerabilities for Data Extortion and Ransomware Operations,\" September 14, 2022 (`[cisa2022aa22257a]`); CISA AA22-055A \"Iranian Government-Sponsored MuddyWater Actors Conducting Malicious Cyber Operations,\" February 24, 2022 (`[cisa2022aa22055a]`); CISA AA20-259A \"Iran-Based Threat Actor Exploits VPN Vulnerabilities,\" September 15, 2020 (`[cisa2020aa20259a]`); FBI Flash on Pioneer Kitten / Fox Kitten / Lemon Sandstorm activity, August 28, 2024 (`[fbi2024pioneerkittenflash]`); January 2022 U.S. Cyber Command attribution of MuddyWater to MOIS; sustained multi-vendor industry-forensic corroboration (Mandiant, Microsoft, CrowdStrike, ClearSky, Recorded Future, Kaspersky, Check Point, ESET) characterising the cluster set's TTPs and the IRGC-vs-MOIS sub-cluster boundary. Attribution that *specific cryptocurrency-theft or ransomware-payment incidents* are downstream of a specific Iranian sub-cluster placement is **inferred-strong** in many cases — the per-incident MuddyWater-vs-Charming-Kitten-vs-Pioneer-Kitten partition is operationally meaningful but not always cleanly resolvable from public reporting.",
      "first_observed": "approximately 2018–2019 (early IRGC-affiliated cryptocurrency-mining intrusions and Bitcoin-payment-related ransomware activity documented from 2018 onward, with the cryptocurrency-economy footprint expanding sharply across the 2020-to-2024 window; the November 2018 OFAC designation of two Iranian nationals — Ali Khorashadizadeh and Mohammad Ghorbaniyan — for laundering SamSam ransomware proceeds was the first OFAC inclusion of cryptocurrency addresses on the SDN List as identifiers and is the foundational sanctions-precedent for the cluster set).",
      "active": "**yes** as of v0.1 — sanctions tempo sustained through 2022–2024 with the August 2024 FBI Flash on Pioneer Kitten / Fox Kitten the most recent confirmed-grade public-attribution event; multi-vendor industry-forensic tracking documents continued activity across the cluster set against U.S., U.K., Israeli, Saudi, U.A.E., and broader Middle Eastern targets, with cryptocurrency-economy exposure continuing through ransomware-with-crypto-payments operations, cryptocurrency-mining intrusions on compromised infrastructure, and (per multi-vendor industry-forensic tracking) involvement in pseudo-financial-fraud and sanctions-evasion adjacent operations.",
      "source_file": "actors/OAK-G13-iranian-crypto-operators.md"
    },
    {
      "id": "OAK-G14",
      "name": "Cl0p / Clop Ransomware-and-Data-Extortion operation",
      "aliases": [
        "Cl0p (operating brand on Russian-language criminal forums and the cluster's Tor-hosted \"CL0P^_- LEAKS\" leak site, 2019 → present, with the *zero* in \"Cl0p\" rendered with a literal numeral in the cluster's own self-identification and frequently transliterated as \"Clop\" in industry-forensic and regulatory write-ups)",
        "TA505 (Proofpoint tracker name for the broader operator-cohort, with TA505-attributed activity dating to 2014 and the Cl0p-branded ransomware operation a sub-activity of the TA505 cohort from 2019 onward)",
        "FIN11 (Mandiant tracker name for the financially-motivated activity cohort overlapping with TA505 / Cl0p; Mandiant tracking documents the FIN11 / Cl0p relationship as overlapping but not identical)",
        "Lace Tempest (Microsoft tracker name for the Cl0p-affiliated MOVEit-campaign-running sub-cluster)",
        "DEV-0950 (Microsoft legacy tracker)",
        "Hive0065 (IBM X-Force)",
        "and the affiliate cohort named in the June 2023 OFAC and FBI / CISA AA23-158A advisories. For OAK-G14 purposes the *cluster* is the Cl0p ransomware-and-data-extortion operation — the core operator network behind the Cl0p encryptor (and from 2023 onward, the Cl0p data-extortion-only operating model)",
        "the affiliate-management infrastructure",
        "and the leak-site operation — considered jointly with the TA505 operator cohort substrate from which Cl0p emerged. The cluster's *signature operational pattern* is mass-exploitation campaigns against managed-file-transfer (MFT) products: the December 2020-to-early-2021 Accellion FTA campaign",
        "the February 2023 GoAnywhere MFT campaign",
        "and the *canonical* June 2023 MOVEit Transfer mass-exploitation campaign (CVE-2023-34362)",
        "each of which produced a multi-thousand-organisation-victim cohort."
      ],
      "attribution_status": "**confirmed** at the *cluster-and-named-affiliate* level — U.S. Department of the Treasury OFAC June 2023 designations of multiple Cl0p-affiliated Russian nationals (`[ofac2023clopaffiliates]`); CISA / FBI / NSA / U.S. Cyber Command joint cyber-security advisory AA23-158A \"CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability,\" June 7, 2023 (`[cisa2023aa23158aclop]`); CISA / FBI joint cyber-security advisory AA23-039A \"#StopRansomware: CLOP Ransomware,\" February 8, 2023 (`[cisa2023aa23039aclop]`); June 2021 Ukrainian Cyber Police arrests of multiple Cl0p-affiliated individuals in coordination with the U.S. and South Korean law enforcement (`[ukrcyberpolice2021clop]`); U.S. Department of State Rewards for Justice \\$10M reward for information on Cl0p leadership and affiliates (consistent with the broader RfJ ransomware-leadership reward architecture); sustained multi-vendor industry-forensic corroboration (Mandiant, Microsoft, CrowdStrike, Sophos, Recorded Future, Coveware, Chainalysis, TRM Labs, Sangfor) characterising the encryptor lineage, the TA505 / FIN11 operator-cohort substrate, the data-extortion-only pivot of mid-2023, and the mass-exploitation operational signature. Attribution that *specific ransom-payment flows or data-extortion-payment flows* trace to specific affiliate wallets within the Cl0p cluster is **inferred-strong** from industry forensic providers; per Coveware and Chainalysis aggregate tracking, Cl0p-attributable extortion proceeds across the cluster's operating window exceed \\$100M and place the cluster in the top-tier of ransomware-and-data-extortion volume per the 2023-and-2024 Chainalysis ransomware reports (`[chainalysis2025ransomware]`).",
      "first_observed": "February-to-March 2019 (Cl0p-branded encryptor first observed on Russian-language criminal forums; the RaaS / ransomware operating model with Bitcoin-denominated ransom payments has been the operational default since inception, with the cluster pivoting to a *data-extortion-only* operating model from mid-2023 onward in which encryption is no longer deployed and the negotiation surface is entirely the leaked-data-disclosure threat).",
      "active": "**yes** as of v0.1 — Cl0p-branded extortion activity continued through 2024-and-2025 with continued mass-exploitation campaigns against managed-file-transfer and adjacent enterprise-software products (notably the late-2024 Cleo CVE-2024-50623 / CVE-2024-55956 mass-exploitation campaign attributed to Cl0p per multiple industry-forensic write-ups), sustained leak-site operation, and continued ransom-payment flow tracked by industry-forensic providers. The cluster has been the most operationally durable of the major Russian-language ransomware-and-data-extortion clusters across the 2022-to-2025 window, with no public-record exit-scam (unlike OAK-G10 ALPHV), no law-enforcement-disruption-and-OFAC-listing-of-cluster-wallets event (unlike OAK-G05 LockBit), and no internal-wind-down-following-internal-chats-leak event (unlike OAK-G11 Black Basta).",
      "source_file": "actors/OAK-G14-clop-cl0p.md"
    },
    {
      "id": "OAK-G15",
      "name": "RansomHub Ransomware-as-a-Service operation",
      "aliases": [
        "RansomHub (operating brand on Russian-language criminal forums and the cluster's Tor-hosted leak site, February 2024 → present, with the cluster's recruitment posts on RAMP and other Russian-language criminal-forum substrate explicitly positioning the brand as the post-ALPHV-exit-scam home for displaced affiliates)",
        "Greenbottle (some industry-forensic write-ups; minority usage)",
        "and the affiliate cohort identified across multiple industry-forensic write-ups as carrying ALPHV-cluster organisational continuity into the RansomHub operating brand following the early-March 2024 ALPHV exit-scam (notably \"Notchy,\" the affiliate behind the Change Healthcare intrusion under OAK-G10, who publicly accused the ALPHV operator of stealing the affiliate share of the \\~\\$22M Bitcoin payment and surfaced on RAMP and other Russian-language forums under reused persona signatures in the months following). For OAK-G15 purposes the *cluster* is the RansomHub RaaS operation — the core operator network behind the RansomHub encryptor (Go-language with cross-platform Windows / Linux / VMware ESXi builds)",
        "the affiliate-management infrastructure",
        "and the leak-site operation — considered jointly with the ALPHV-and-LockBit-displaced affiliate stream that ran the highest-impact RansomHub intrusions of 2024. RansomHub is *not* a Conti-successor brand on the same lineage axis as OAK-G11 Black Basta",
        "OAK-G16 Akira",
        "OAK-G17 BlackByte",
        "or OAK-G18 Karakurt — its organisational substrate is post-ALPHV-exit-scam absorber rather than post-ContiLeaks dispersal — and the cluster-boundary discipline matters for defender-side affiliate-cluster-reuse attribution work."
      ],
      "attribution_status": "**confirmed** at the *cluster-and-tooling* level — joint CISA / FBI / HHS / MS-ISAC cyber-security advisory AA24-242A \"StopRansomware: RansomHub Ransomware,\" August 29, 2024 (`[cisa2024aa24242aransomhub]`), characterising the cluster's TTPs across the healthcare and other critical-infrastructure sectors and naming RansomHub as the largest RaaS strain by victim-count in the immediate post-ALPHV-exit-scam window with more than 200 named victims through August 2024; sustained multi-vendor industry-forensic corroboration (Mandiant's UNC4393-adjacent and Notchy-affiliate tracking, Microsoft Threat Intelligence, Sophos, Symantec, Recorded Future, Coveware, Chainalysis, TRM Labs) characterising the Go-language encryptor lineage, the Russian-language operator-forum substrate, the affiliate-cut economics (\\~90 / 10 affiliate / operator split per industry-forensic tracking, more affiliate-favourable than the ALPHV \\~85 / 15 baseline and substantially more affiliate-favourable than the LockBit \\~80 / 20 baseline), and the post-ALPHV-affiliate-absorption pattern; Mandiant 2024 reporting describing RansomHub as \"the largest 2024 RaaS by post-ALPHV-exit-scam affiliate-absorption volume\" (`[mandiant2024ransomhub]`). RansomHub itself was not OFAC-designated as a cluster within its first 18 months of operation; that distinction makes G15 a *confirmed-by-CISA-advisory-and-industry-forensic-corroboration* rather than *confirmed-by-OFAC-SDN-designation* case at v0.1, structurally adjacent to OAK-G11 Black Basta on the attribution-strength axis. Attribution that *specific ransom-payment flows* trace to specific affiliate wallets within the RansomHub cluster is **inferred-strong** from industry forensic providers; the canonical instance is the cluster-continuity attestation linking Notchy and other ALPHV-displaced affiliates to RansomHub-cluster wallet activity in the months following the March 2024 ALPHV exit-scam (`[chainalysis2025ransomware]`, `[trm2024ransomhub]`).",
      "first_observed": "approximately February 2024 (RansomHub leak-site / RaaS-recruitment posts first observed on Russian-language criminal forums in February 2024, weeks before the early-March 2024 ALPHV operator-side exit-scam shutdown; the timing of RansomHub's launch positioned the cluster to absorb displaced ALPHV affiliates, and per multi-vendor industry-forensic tracking the post-March 2024 affiliate-onboarding tempo was unusually rapid for a new RaaS brand and is the canonical worked example of *RaaS-affiliate-displacement-and-rapid-rebrand-absorption* in the public record).",
      "active": "**yes** as of v0.1 — RansomHub-branded extortion activity continued through 2024-and-2025 with sustained leak-site operation and continued ransom-payment flow tracked by industry-forensic providers. Per `[chainalysis2025ransomware]` the cluster's market-share among RaaS strains rose sharply across Q2-to-Q4 2024 in step with the post-ALPHV-exit-scam affiliate-displacement and the post-Operation-Cronos LockBit-volume-collapse, with RansomHub becoming the dominant single-strain RaaS brand by victim-count for substantial portions of 2024 (per Coveware and per CISA AA24-242A's victim-count metrics). The cluster is the canonical 2024 case in the public record of *RaaS-brand-rotation absorbing displaced affiliates from prior-cluster terminations* and warrants its own per-cluster identity treatment.",
      "source_file": "actors/OAK-G15-ransomhub.md"
    },
    {
      "id": "OAK-G16",
      "name": "Akira Ransomware-as-a-Service operation",
      "aliases": [
        "Akira (operating brand on Russian-language criminal forums and the cluster's Tor-hosted leak site, March 2023 → present, with a self-styled retro-1980s-terminal leak-site aesthetic that has been used as a low-fidelity operator-self-identification signal in industry-forensic tracking)",
        "GOLD SAHARA (Secureworks Counter Threat Unit tracker name)",
        "Storm-1567 (Microsoft tracker name for the Akira-affiliated principal sub-cluster)",
        "Punk Spider (some industry-forensic write-ups; minority usage)",
        "and the affiliate cohort identified across multiple industry-forensic write-ups as carrying Conti-codebase-related lineage from the February-to-May 2022 ContiLeaks dispersal into the Akira operating brand. The Akira-as-Conti-successor lineage is *separate from but parallel to* OAK-G11 Black Basta — both clusters carry distinct Conti-codebase-related lineage attestations but were launched by different sub-cohorts within the broader post-ContiLeaks operator dispersal",
        "and the operator-cohort tracking across Mandiant",
        "Microsoft",
        "and Sophos write-ups treats Akira and Black Basta as *separate Conti-successor brands* with distinct affiliate cohorts and distinct encryptor-codebase development trajectories. For OAK-G16 purposes the *cluster* is the Akira RaaS operation — the core operator network behind the Akira encryptor (C++-and-Rust lineage with cross-platform Windows / Linux / VMware ESXi variants, with the Megazord encryptor-variant introduced in late-2023 as a Rust-based redevelopment)",
        "the affiliate-management infrastructure",
        "and the leak-site operation — considered jointly with the Conti-codebase-related affiliate cohort that ran the cluster's first 18 months of intrusions."
      ],
      "attribution_status": "**confirmed** at the *cluster-and-tooling* level — joint CISA / FBI / Europol EC3 / Netherlands NCSC-NL cyber-security advisory AA24-109A \"StopRansomware: Akira Ransomware,\" April 18, 2024 (`[cisa2024aa24109aakira]`), characterising the cluster's TTPs across the manufacturing, education, financial-services, and other sectors, naming Akira as a high-volume RaaS strain with approximately 250 victim organisations and approximately \\$42M in confirmed ransom-payment proceeds through January 2024, and identifying the Akira-affiliate cohort's exploitation-of-public-facing-vulnerabilities and Cisco-VPN-without-MFA initial-access vectors; sustained multi-vendor industry-forensic corroboration (Mandiant tracking, Microsoft Storm-1567, Sophos X-Ops, Recorded Future, Coveware, Chainalysis, TRM Labs) characterising the C++-and-Rust encryptor lineage, the Russian-language operator-forum substrate, the Conti-codebase-related lineage attestation, and the affiliate-cut economics; Sophos late-2023 reporting on the Megazord encryptor-variant as a Rust-based redevelopment of the Akira codebase (`[sophos2023akira]`). The Conti-codebase-related lineage claim is *inferred-strong* — overlap of operator personas, encryptor-architecture decisions, and TTP-fingerprint signal across the Conti-shutdown / Akira-launch window are documented across Mandiant, Microsoft, and Sophos tracking but the cluster has not been individually OFAC-designated or DOJ-indicted at the principal-operator level as of v0.1. Attribution that *specific ransom-payment flows* trace to specific affiliate wallets within the Akira cluster is **inferred-strong** from industry forensic providers; per CISA AA24-109A and Chainalysis aggregate tracking, Akira-attributable ransom-payment proceeds across the cluster's first 10 months of operation total approximately \\$42M, with downstream laundering routes sharing the broader Russian-language commercial-criminal off-ramp profile.",
      "first_observed": "approximately March 2023 (Akira leak-site / RaaS-recruitment posts first observed on Russian-language criminal forums in March 2023, with cluster-attributed intrusions documented from late-March 2023 onward; the RaaS model with Bitcoin-denominated ransom payments has been the operational default since inception).",
      "active": "**yes** as of v0.1 — Akira-branded extortion activity continued through 2024-and-2025 with sustained leak-site operation, continued ransom-payment flow tracked by industry-forensic providers, and continued cross-platform encryptor-variant development (Megazord Rust-based variant from late-2023 onward, with continued ESXi-and-Linux-targeting development). Per `[chainalysis2025ransomware]` the cluster's market-share among RaaS strains has been sustained across 2024-and-2025 in step with the post-Operation-Cronos LockBit-volume-collapse, the post-ALPHV-exit-scam affiliate-displacement, and the post-Black-Basta-internal-wind-down dispersal, with Akira positioned as one of the durable mid-volume RaaS strains across the 2023-to-2025 window.",
      "source_file": "actors/OAK-G16-akira.md"
    },
    {
      "id": "OAK-G17",
      "name": "BlackByte Ransomware-as-a-Service operation",
      "aliases": [
        "BlackByte (operating brand on Russian-language criminal forums and the cluster's Tor-hosted leak site, July 2021 → present, with multi-language encryptor-variant development across the cluster's operating window)",
        "Hecamede (some early industry-forensic write-ups; minority usage)",
        "and the Conti-splinter operator-cohort identified across multiple industry-forensic write-ups as carrying Conti-codebase-related lineage from the broader Conti-organisational substrate into the BlackByte operating brand. BlackByte's Conti-splinter lineage is *separate from but parallel to* OAK-G11 Black Basta",
        "OAK-G16 Akira",
        "and OAK-G18 Karakurt — BlackByte is the *earliest-launching* of the major Conti-codebase-related successor brands tracked in OAK v0.1",
        "predating the February-to-May 2022 ContiLeaks event by approximately seven months and operating through the dispersal window with continuity into the post-2022 period",
        "which gives the cluster a structurally distinct relationship to the post-ContiLeaks dispersal substrate compared to the post-2022-launching Black Basta and Akira clusters. For OAK-G17 purposes the *cluster* is the BlackByte RaaS operation — the core operator network behind the BlackByte encryptor (with multi-language variant development across .NET / C++ / Go through the cluster's operating window, and the Go-language variant a defender-relevant marker tracked through 2022-and-2023 industry-forensic write-ups)",
        "the affiliate-management infrastructure",
        "and the leak-site operation — considered jointly with the Conti-codebase-related operator-cohort substrate from which BlackByte emerged."
      ],
      "attribution_status": "**confirmed** at the *cluster-and-tooling* level — joint FBI / U.S. Secret Service cyber-security advisory CU-000167-MW (Feb 11 2022 FBI Flash) and the joint FBI / U.S. Secret Service Joint Cybersecurity Advisory TLP:WHITE on BlackByte Ransomware (the same February 2022 advisory cycle frequently referenced by industry-forensic write-ups as \"TA22-039A-equivalent\" though the canonical CISA advisory tracker uses the FBI Flash format rather than the AA-NNNNN tracker number) (`[fbi2022blackbyteflash]`), characterising the cluster's TTPs across U.S. critical-infrastructure entities including the February 2022 attack against the San Francisco 49ers professional sports franchise; sustained multi-vendor industry-forensic corroboration (Mandiant tracking, Microsoft Threat Intelligence, Sophos X-Ops, Trustwave SpiderLabs, Symantec Threat Hunter Team, Recorded Future, Coveware, Chainalysis, TRM Labs) characterising the multi-language encryptor lineage, the Russian-language operator-forum substrate, the Conti-splinter lineage attestation, and sustained 2022-and-2023 cross-platform encryptor-variant development including the Go-language variant; Trustwave SpiderLabs late-2021 reporting on the BlackByte encryptor's symmetric-key-reuse implementation flaw that allowed the publication of a free decryptor (`[trustwave2021blackbyte]`); subsequent BlackByte-encryptor redevelopment to address the cryptographic flaw and extend the cross-platform variant set. The Conti-splinter lineage claim is *inferred-strong* — overlap of operator personas, encryptor-architecture decisions, and TTP-fingerprint signal across the Conti-organisational substrate are documented across Mandiant, Microsoft, and Sophos tracking but the cluster has not been individually OFAC-designated or DOJ-indicted at the principal-operator level as of v0.1. Attribution that *specific ransom-payment flows* trace to specific affiliate wallets within the BlackByte cluster is **inferred-strong** from industry forensic providers.",
      "first_observed": "July 2021 (BlackByte-branded encryptor first observed in incident-response engagements in July 2021, with cluster-attributed intrusions documented from mid-2021 onward; the RaaS / ransomware operating model with Bitcoin-and-Monero-denominated ransom payments has been the operational default since inception, with the cluster active across the entire post-2021 ransomware-evolution window through v0.1).",
      "active": "**yes** as of v0.1 — BlackByte-branded extortion activity continued through 2024-and-2025 with sustained leak-site operation, continued cross-platform encryptor-variant development, and continued ransom-payment flow tracked by industry-forensic providers, though at lower victim-count throughput than the dominant 2024 RaaS strains (RansomHub, LockBit residuals, Akira). Per `[chainalysis2025ransomware]` BlackByte's market-share among RaaS strains has been sustained in the long-tail mid-volume RaaS-strain segment across 2024-and-2025, with the cluster positioned as one of the most operationally durable Conti-codebase-related successor brands by total operating-window length (July 2021 → present, exceeding four years by v0.1).",
      "source_file": "actors/OAK-G17-blackbyte.md"
    },
    {
      "id": "OAK-G18",
      "name": "Karakurt extortion-only data-theft operation",
      "aliases": [
        "Karakurt (the operator-side and leak-site-branded name from the cluster's mid-2021 emergence onward, named for the Karakurt black-widow spider species native to Central Asia and southern Russia, with a distinctive black-and-red leak-site visual identity that was carried forward across the cluster's 2021–present operating window); Karakurt Lair (the cluster's leak-site brand and Tor-hosted disclosure-portal naming used in the cluster's own self-identification on the leak site); Karakurt Team (the operator-cohort's internal self-naming as recovered in industry-forensic reporting and in the cluster's victim-negotiation portal communications). The cluster is documented in industry-forensic reporting as a *Conti-side-channel* spin-off — it emerged in mid-2021 as a data-extortion-only sub-team operating within the broader Conti / Wizard Spider operator-cohort substrate and survived the May 2022 Conti dissolution as a standalone operating brand. For OAK-G18 purposes the *cluster* is the Karakurt operator network behind the Karakurt encryptor-free data-theft-and-extortion operation",
        "the affiliate-management infrastructure",
        "and the Karakurt Lair leak-site operation",
        "considered jointly with the broader Conti-successor cohort substrate (see Discussion for the cluster-boundary distinctions with OAK-G11 Black Basta, OAK-G16 Akira, OAK-G17 BlackByte, and OAK-S26 Conti). The cluster's *signature operational pattern* is *encryption-free data-theft-and-extortion* — Karakurt does not deploy a ransomware encryptor and the negotiation surface is entirely the leaked-data-disclosure threat — making it the *prototype* of the data-extortion-only operating model that OAK-G14 Cl0p adopted at scale from mid-2023 onward."
      ],
      "attribution_status": "**confirmed** at the *cluster-and-CISA-advisory* level — CISA / FBI / U.S. Department of the Treasury / FinCEN joint cyber-security advisory AA22-152A \"Karakurt Data Extortion Group,\" June 1, 2022 (`[cisaaa22152a]`), with a March 2023 update extending the Karakurt-cohort tracking through 2023; multi-vendor industry-forensic corroboration (Mandiant, Microsoft, CrowdStrike, Sophos, Recorded Future, Coveware, Chainalysis, TRM Labs) characterising the Conti-cohort-continuity attribution at the operator-cohort level and the data-extortion-only operating-model signature; Tetra Defense and Infinitum I.T. cross-vendor reporting on Karakurt-attributed intrusions and the recovery-and-negotiation behaviour profile. Attribution that *specific extortion-payment flows trace to specific Conti-successor affiliate wallets within the Karakurt cluster* is **inferred-strong** from industry-forensic providers; per Chainalysis and Mandiant cross-cohort analysis, Karakurt affiliate wallet clusters share funder addresses with documented Conti-era and Black Basta affiliate clusters, supporting the Conti-cohort-continuity attribution at the on-chain layer.",
      "first_observed": "mid-2021 (Karakurt-branded leak-site activity first observed in industry-forensic reporting around June–August 2021 as a Conti-side-channel data-extortion sub-team; the data-extortion-only operating model with cryptocurrency-denominated ransom payments has been the operational default since inception).",
      "active": "**yes** as of v0.1 — Karakurt-branded extortion activity continued through 2024-and-2025 with sustained leak-site operation and continued data-extortion-payment flow tracked by industry-forensic providers; the cluster has been one of the more operationally durable Conti-successor brands in the broader 2022–2025 dispersal network alongside G11 Black Basta (operationally degraded post-February-2024 internal-chat leak), G16 Akira (active), and G17 BlackByte (active). No public-record disruption-or-takedown event has been observed against Karakurt at v0.1 cutoff; CISA / FBI advisory tempo has been the principal external pressure surface.",
      "source_file": "actors/OAK-G18-karakurt.md"
    },
    {
      "id": "OAK-G19",
      "name": "DarkSide Ransomware-as-a-Service operation",
      "aliases": [
        "DarkSide (operating brand on Russian-language criminal forums from August 2020 through May 2021); BlackMatter (successor brand, July–November 2021, widely assessed by industry forensic providers as a rebrand of the DarkSide core operator group after the May 2021 shutdown). The DarkSide brand was publicly retired by the operators on May 13",
        "2021",
        "citing loss of infrastructure access and law-enforcement pressure following the Colonial Pipeline attack."
      ],
      "attribution_status": "**confirmed** — FBI attributed the Colonial Pipeline attack to DarkSide (May 2021); DOJ seizure warrant filed in the Northern District of California recovered 63.7 BTC of the 75 BTC ransom payment via private-key recovery (June 2021); CISA Alert AA21-131A on DarkSide ransomware TTPs (May 2021). Attribution of the DarkSide-to-BlackMatter rebrand is **inferred-strong** per multi-vendor industry forensic consensus (Chainalysis, TRM Labs, Mandiant, CrowdStrike), based on code-overlap analysis, shared infrastructure, overlapping affiliate roster, and identical RaaS revenue-split structure.",
      "first_observed": "August 2020 (DarkSide RaaS launch announcement on Russian-language criminal forums; Bitcoin-denominated ransom payments operational from inception).",
      "active": "**inactive** as of v0.1 — the DarkSide-branded operation was publicly shut down on May 13, 2021. The core operator cohort rebranded as BlackMatter (July 2021), which in turn shut down in November 2021. Post-BlackMatter, the operator cohort is assessed to have dispersed into successor RaaS strains and small-group operations. OAK-G19 should be read as a *closed* cluster whose operational window (August 2020–May 2021) was brief but whose impact on U.S. ransomware policy was transformational.",
      "source_file": "actors/OAK-G19-darkside.md"
    }
  ],
  "data_sources": [
    {
      "id": "OAK-DS-01",
      "name": "Token Deployment Events and Bytecode",
      "layer": "on-chain",
      "chains": [
        "EVM",
        "Solana",
        "cross-chain"
      ],
      "access_path": "RPC node `eth_getTransactionReceipt` for the deployment tx + `eth_getCode` for the deployed bytecode; equivalent on Solana via mint-account inspection; block explorers (Etherscan, Solscan) and indexers (The Graph, Dune Analytics, Allium) provide enriched access.",
      "source_file": "data-sources/OAK-DS-01-token-deployment.md"
    },
    {
      "id": "OAK-DS-02",
      "name": "DEX Pool Creation and Liquidity Events",
      "layer": "on-chain",
      "chains": [
        "EVM",
        "Solana"
      ],
      "access_path": "DEX-factory pool-creation events (Uniswap V2 / V3 PoolCreated, Sushiswap, Raydium, Orca); liquidity-add and liquidity-remove events at each pool.",
      "source_file": "data-sources/OAK-DS-02-lp-pool-events.md"
    },
    {
      "id": "OAK-DS-03",
      "name": "Token Approval Events",
      "layer": "on-chain",
      "chains": [
        "EVM (primary)",
        "Solana (token-account delegate authority)"
      ],
      "access_path": "ERC-20 `Approval` and ERC-721 / ERC-1155 `ApprovalForAll` events; per-token-account delegate-authority changes on Solana.",
      "source_file": "data-sources/OAK-DS-03-erc20-approvals.md"
    },
    {
      "id": "OAK-DS-04",
      "name": "Permit / Permit2 Off-Chain Signatures",
      "layer": "off-chain (signature) + on-chain (consumption)",
      "chains": [
        "EVM (primary)"
      ],
      "access_path": "wallet-side telemetry (signing-flow logs); on-chain `Permit` / Permit2 `transferFrom` consumption events.",
      "source_file": "data-sources/OAK-DS-04-permit-signatures.md"
    },
    {
      "id": "OAK-DS-05",
      "name": "Oracle Price Feeds and Oracle-Input Trades",
      "layer": "on-chain",
      "chains": [
        "EVM",
        "Solana",
        "cross-chain"
      ],
      "access_path": "Chainlink / Pyth / API3 / TWAP-on-DEX feed contracts (price-update events); per-feed input-venue trade events.",
      "source_file": "data-sources/OAK-DS-05-oracle-price-feeds.md"
    },
    {
      "id": "OAK-DS-06",
      "name": "Token Mint and Burn Events",
      "layer": "on-chain",
      "chains": [
        "EVM",
        "Solana"
      ],
      "access_path": "ERC-20 `Transfer` events with `from = 0x00...0` (mint) or `to = 0x00...0` (burn); equivalent on Solana via mint-account state changes.",
      "source_file": "data-sources/OAK-DS-06-mint-burn-events.md"
    },
    {
      "id": "OAK-DS-07",
      "name": "DEX Trade and Swap Events",
      "layer": "on-chain",
      "chains": [
        "EVM",
        "Solana",
        "cross-chain"
      ],
      "access_path": "Per-DEX `Swap` events (Uniswap V2 / V3 Swap, Balancer SwapLog, Curve TokenExchange, Raydium swaps, Orca whirlpools); per-aggregator routing flows (1inch, Matcha, Jupiter).",
      "source_file": "data-sources/OAK-DS-07-trade-swap-events.md"
    },
    {
      "id": "OAK-DS-08",
      "name": "Bridge Validator Messages and VAAs",
      "layer": "on-chain (consumption) + off-chain (signature aggregation)",
      "chains": [
        "cross-chain bridges (Wormhole, LayerZero, Axelar, Hyperlane, Across, Synapse, etc.)"
      ],
      "access_path": "per-bridge consumption-side event logs; bridge-operator-published guardian / validator message archives where available.",
      "source_file": "data-sources/OAK-DS-08-bridge-validator-messages.md"
    },
    {
      "id": "OAK-DS-09",
      "name": "Funder Graph (Derived)",
      "layer": "derived (from on-chain transfer events)",
      "chains": [
        "EVM",
        "Solana",
        "cross-chain"
      ],
      "access_path": "custom graph indexer; vendor cluster-attribution products (Chainalysis Reactor, TRM Forensics, Elliptic Investigator) provide curated funder-graph access.",
      "source_file": "data-sources/OAK-DS-09-funder-graph.md"
    },
    {
      "id": "OAK-DS-10",
      "name": "Cross-Chain Bridge and Swap Flows",
      "layer": "on-chain (per-chain) + derived (cross-chain attribution)",
      "chains": [
        "cross-chain bridges and DEX-style cross-chain swap protocols (THORChain, LI.FI, Across, Stargate, Synapse, Hop, Wormhole token bridge, etc.)"
      ],
      "access_path": "per-bridge inflow / outflow event logs; vendor cross-chain attribution products for the linkage layer.",
      "source_file": "data-sources/OAK-DS-10-cross-chain-bridge-flows.md"
    },
    {
      "id": "OAK-DS-11",
      "name": "Mempool and Pre-Block Order Flow",
      "layer": "mempool / pre-block",
      "chains": [
        "EVM (primary)",
        "Solana (validator-side mempool access)"
      ],
      "access_path": "private mempool subscriptions (Flashbots Protect, MEV-Share, BloXroute); public-mempool monitoring (less reliable post-private-pool-adoption); validator-side telemetry where accessible.",
      "source_file": "data-sources/OAK-DS-11-mempool-orderflow.md"
    },
    {
      "id": "OAK-DS-12",
      "name": "Off-Chain CTI Feeds",
      "layer": "off-chain",
      "chains": [
        "N/A (telemetry sources are off-chain)"
      ],
      "access_path": "commercial CTI providers; public CTI sources (CISA, FBI IC3, NCSC); platform-side telemetry (Discord moderation, Twitter / X security teams); registrar / DNS change-control feeds.",
      "source_file": "data-sources/OAK-DS-12-off-chain-cti.md"
    }
  ],
  "examples": [
    {
      "id": "2010-07-mtgox-bitcoin-exchange-launch",
      "file": "2010-07-mtgox-bitcoin-exchange-launch.md",
      "title": "Mt. Gox Bitcoin exchange launch — Bitcoin — 2010-07",
      "date_prefix": "2010-07",
      "techniques": [],
      "attribution": "unattributed",
      "source_file": "examples/2010-07-mtgox-bitcoin-exchange-launch.md"
    },
    {
      "id": "2010-08-bitcoin-value-overflow-bug",
      "file": "2010-08-bitcoin-value-overflow-bug.md",
      "title": "Bitcoin Value Overflow Bug — Bitcoin protocol — 2010-08-15 (block 74638)",
      "date_prefix": "2010-08",
      "techniques": [
        "OAK-T9.014"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2010-08-bitcoin-value-overflow-bug.md"
    },
    {
      "id": "2010-12-slush-pool-first-mining-pool",
      "file": "2010-12-slush-pool-first-mining-pool.md",
      "title": "Slush Pool — first Bitcoin mining pool launch — Bitcoin — 2010-12-16",
      "date_prefix": "2010-12",
      "techniques": [
        "OAK-T14",
        "OAK-T14.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2010-12-slush-pool-first-mining-pool.md"
    },
    {
      "id": "2010-2015-navinder-sarao-cme-futures-spoofing",
      "file": "2010-2015-navinder-sarao-cme-futures-spoofing.md",
      "title": "Navinder Sarao CME futures spoofing — CME Globex (equity futures) — 2010–2015",
      "date_prefix": "2010-20",
      "techniques": [
        "OAK-T17.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2010-2015-navinder-sarao-cme-futures-spoofing.md"
    },
    {
      "id": "2011-06-allinvain-first-major-bitcoin-theft",
      "file": "2011-06-allinvain-first-major-bitcoin-theft.md",
      "title": "Allinvain first major Bitcoin theft — Bitcoin — 2011-06-13",
      "date_prefix": "2011-06",
      "techniques": [
        "OAK-T11.005",
        "OAK-T15.003",
        "OAK-T15.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2011-06-allinvain-first-major-bitcoin-theft.md"
    },
    {
      "id": "2011-06-mtgox-auditor-account-compromise",
      "file": "2011-06-mtgox-auditor-account-compromise.md",
      "title": "Mt. Gox auditor account compromise — Bitcoin — 2011-06-19",
      "date_prefix": "2011-06",
      "techniques": [
        "OAK-T15.003",
        "OAK-T15.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2011-06-mtgox-auditor-account-compromise.md"
    },
    {
      "id": "2011-07-bitcoinica-first-hack",
      "file": "2011-07-bitcoinica-first-hack.md",
      "title": "Bitcoinica First Server-Side Hot-Wallet Compromise — 2011-07-29",
      "date_prefix": "2011-07",
      "techniques": [
        "OAK-T11.001",
        "OAK-T5.001",
        "OAK-T8.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2011-07-bitcoinica-first-hack.md"
    },
    {
      "id": "2011-07-mybitcoin",
      "file": "2011-07-mybitcoin.md",
      "title": "MyBitcoin wallet-service collapse — Bitcoin — 2011-07 to 2011-08",
      "date_prefix": "2011-07",
      "techniques": [
        "OAK-T11.005.002",
        "OAK-T5.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2011-07-mybitcoin.md"
    },
    {
      "id": "2011-2013-silk-road",
      "file": "2011-2013-silk-road.md",
      "title": "Silk Road darknet marketplace — Bitcoin — 2011-02 to 2013-10",
      "date_prefix": "2011-20",
      "techniques": [
        "OAK-T3.001",
        "OAK-T7.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2011-2013-silk-road.md"
    },
    {
      "id": "2011-2017-btc-e-account-infrastructure",
      "file": "2011-2017-btc-e-account-infrastructure.md",
      "title": "BTC-e exchange account farming and sybil infrastructure — 2011–2017",
      "date_prefix": "2011-20",
      "techniques": [
        "OAK-T7.002",
        "OAK-T8.004"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2011-2017-btc-e-account-infrastructure.md"
    },
    {
      "id": "2011-2025-darknet-marketplace-operations-cohort",
      "file": "2011-2025-darknet-marketplace-operations-cohort.md",
      "title": "Darknet Marketplace Operations and Takedowns Cohort — 2011–2025 — 9 Landmarks",
      "date_prefix": "2011-20",
      "techniques": [
        "OAK-T5.005",
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T8.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2011-2025-darknet-marketplace-operations-cohort.md"
    },
    {
      "id": "2012-03-bitcoinica-exchange-hack",
      "file": "2012-03-bitcoinica-exchange-hack.md",
      "title": "Bitcoinica exchange server compromise — Bitcoin — 2012-03-01",
      "date_prefix": "2012-03",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2012-03-bitcoinica-exchange-hack.md"
    },
    {
      "id": "2012-03-linode-bitcoin-service-hacks",
      "file": "2012-03-linode-bitcoin-service-hacks.md",
      "title": "Linode Server Compromise — Bitcoin Service Infrastructure Attacks — 2012-03-01/02",
      "date_prefix": "2012-03",
      "techniques": [
        "OAK-T11.001",
        "OAK-T5.001",
        "OAK-T8.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2012-03-linode-bitcoin-service-hacks.md"
    },
    {
      "id": "2012-05-bitfloor",
      "file": "2012-05-bitfloor.md",
      "title": "Bitfloor exchange hot-wallet compromise — Bitcoin — 2012-05-02",
      "date_prefix": "2012-05",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2012-05-bitfloor.md"
    },
    {
      "id": "2012-08-bitcoin-savings-trust",
      "file": "2012-08-bitcoin-savings-trust.md",
      "title": "Bitcoin Savings & Trust Ponzi — Bitcoin — 2011-11 to 2012-08",
      "date_prefix": "2012-08",
      "techniques": [
        "OAK-T11.005.002",
        "OAK-T3.001",
        "OAK-T5.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2012-08-bitcoin-savings-trust.md"
    },
    {
      "id": "2012-09-glbse-shutdown",
      "file": "2012-09-glbse-shutdown.md",
      "title": "GLBSE (Global Bitcoin Stock Exchange) operator shutdown — Bitcoin — 2012-09",
      "date_prefix": "2012-09",
      "techniques": [
        "OAK-T11.005",
        "OAK-T15.003",
        "OAK-T6.007"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2012-09-glbse-shutdown.md"
    },
    {
      "id": "2013-04-atlas-dns-bitcoin-hijack-phishing",
      "file": "2013-04-atlas-dns-bitcoin-hijack-phishing.md",
      "title": "Atlas DNS Bitcoin-domain hijack phishing campaign — Bitcoin — April 2013",
      "date_prefix": "2013-04",
      "techniques": [
        "OAK-T15.004",
        "OAK-T4.008",
        "OAK-T6.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2013-04-atlas-dns-bitcoin-hijack-phishing.md"
    },
    {
      "id": "2013-10-inputs-io",
      "file": "2013-10-inputs-io.md",
      "title": "Inputs.io web-wallet hack — Bitcoin — 2013-10",
      "date_prefix": "2013-10",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2013-10-inputs-io.md"
    },
    {
      "id": "2013-11-sheep-marketplace",
      "file": "2013-11-sheep-marketplace.md",
      "title": "Sheep Marketplace exit scam — Bitcoin — 2013-11 to 2013-12",
      "date_prefix": "2013-11",
      "techniques": [
        "OAK-T11.005.002",
        "OAK-T5.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2013-11-sheep-marketplace.md"
    },
    {
      "id": "2013-12-gbl-bitcoin-exchange-scam",
      "file": "2013-12-gbl-bitcoin-exchange-scam.md",
      "title": "GBL Bitcoin Exchange Ponzi / Exit Scam — 2013-12",
      "date_prefix": "2013-12",
      "techniques": [
        "OAK-T11.005.001",
        "OAK-T5.001",
        "OAK-T6.001",
        "OAK-T8.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2013-12-gbl-bitcoin-exchange-scam.md"
    },
    {
      "id": "2013-2015-blockchain-forensics-emergence",
      "file": "2013-2015-blockchain-forensics-emergence.md",
      "title": "Emergence of blockchain transaction-graph forensics — Bitcoin — 2013–2015",
      "date_prefix": "2013-20",
      "techniques": [
        "OAK-T7.001",
        "OAK-T8.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2013-2015-blockchain-forensics-emergence.md"
    },
    {
      "id": "2013-2024-off-chain-opsec-failure-attribution-cohort",
      "file": "2013-2024-off-chain-opsec-failure-attribution-cohort.md",
      "title": "Off-chain opsec failure cohort enabling attribution — chain-agnostic (off-chain attribution surface) — 2013–2024",
      "date_prefix": "2013-20",
      "techniques": [
        "OAK-T8.001",
        "OAK-T8.003",
        "OAK-T8.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2013-2024-off-chain-opsec-failure-attribution-cohort.md"
    },
    {
      "id": "2013-2025-illicit-purpose-designated-entity-financing-cohort",
      "file": "2013-2025-illicit-purpose-designated-entity-financing-cohort.md",
      "title": "Illicit-Purpose and Designated-Entity Financing Cohort — 2013–2025",
      "date_prefix": "2013-20",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T7.009",
        "OAK-T8.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2013-2025-illicit-purpose-designated-entity-financing-cohort.md"
    },
    {
      "id": "2013-2025-on-chain-deanonymization-and-exchange-account-farming-cohort",
      "file": "2013-2025-on-chain-deanonymization-and-exchange-account-farming-cohort.md",
      "title": "On-Chain De-Anonymization and Exchange Account-Farming Cohort — 2013–2025",
      "date_prefix": "2013-20",
      "techniques": [
        "OAK-T8.003",
        "OAK-T8.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2013-2025-on-chain-deanonymization-and-exchange-account-farming-cohort.md"
    },
    {
      "id": "2013-meiklejohn-bitcoin-clustering",
      "file": "2013-meiklejohn-bitcoin-clustering.md",
      "title": "Meiklejohn Bitcoin address clustering research — 2013",
      "date_prefix": "2013",
      "techniques": [
        "OAK-T8.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2013-meiklejohn-bitcoin-clustering.md"
    },
    {
      "id": "2013-silk-road-altoid-handle",
      "file": "2013-silk-road-altoid-handle.md",
      "title": "Silk Road \"altoid\" handle cross-layer de-anonymization — 2013",
      "date_prefix": "2013",
      "techniques": [
        "OAK-T8.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2013-silk-road-altoid-handle.md"
    },
    {
      "id": "2014-01-cryptsy",
      "file": "2014-01-cryptsy.md",
      "title": "Cryptsy multi-asset hot-wallet drain + operator-fraud collapse — multi-asset / US altcoin exchange — 2014-01 (drained); 2016-01 (publicly disclosed); 2016 (Florida bankruptcy and civil judgement)",
      "date_prefix": "2014-01",
      "techniques": [
        "OAK-T11.005",
        "OAK-T7.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2014-01-cryptsy.md"
    },
    {
      "id": "2014-02-mt-gox",
      "file": "2014-02-mt-gox.md",
      "title": "Mt. Gox exchange collapse — Bitcoin — 2011-09 to 2014-02 (filing); recovery through 2024–2025",
      "date_prefix": "2014-02",
      "techniques": [
        "OAK-T11",
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T11.003",
        "OAK-T7.002",
        "OAK-T8.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2014-02-mt-gox.md"
    },
    {
      "id": "2014-03-flexcoin-bitcoin-bank-closure",
      "file": "2014-03-flexcoin-bitcoin-bank-closure.md",
      "title": "Flexcoin Bitcoin bank closure after hot-wallet hack — Bitcoin — 2014-03-02 to 2014-03-04",
      "date_prefix": "2014-03",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.003",
        "OAK-T6.007"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2014-03-flexcoin-bitcoin-bank-closure.md"
    },
    {
      "id": "2014-03-poloniex",
      "file": "2014-03-poloniex.md",
      "title": "Poloniex hot-wallet compromise — Bitcoin — 2014-03-06",
      "date_prefix": "2014-03",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2014-03-poloniex.md"
    },
    {
      "id": "2014-09-mintpal",
      "file": "2014-09-mintpal.md",
      "title": "MintPal hot-wallet compromise + operator-fraud collapse — multi-asset / UK altcoin exchange — 2014-09 to 2014-10",
      "date_prefix": "2014-09",
      "techniques": [
        "OAK-T11.001",
        "OAK-T11.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2014-09-mintpal.md"
    },
    {
      "id": "2014-10-moolah-alex-green-fraud",
      "file": "2014-10-moolah-alex-green-fraud.md",
      "title": "Moolah / Alex Green (Ryan Kennedy) Exchange Fraud — 2014-10",
      "date_prefix": "2014-10",
      "techniques": [
        "OAK-T11.005.001",
        "OAK-T5.005",
        "OAK-T6.001",
        "OAK-T8.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2014-10-moolah-alex-green-fraud.md"
    },
    {
      "id": "2014-2017-onecoin-ignatova",
      "file": "2014-2017-onecoin-ignatova.md",
      "title": "OneCoin — Ruja Ignatova / Karl Sebastian Greenwood multi-level fake-cryptocurrency Ponzi — global — 2014-2017 (operating) / 2017-onward (federal action)",
      "date_prefix": "2014-20",
      "techniques": [
        "OAK-T11.005.002",
        "OAK-T7"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2014-2017-onecoin-ignatova.md"
    },
    {
      "id": "2014-chainalysis-founding-silk-road-tracing",
      "file": "2014-chainalysis-founding-silk-road-tracing.md",
      "title": "Chainalysis founding and Silk Road tracing — 2014",
      "date_prefix": "2014",
      "techniques": [
        "OAK-T8.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2014-chainalysis-founding-silk-road-tracing.md"
    },
    {
      "id": "2015-01-bitstamp",
      "file": "2015-01-bitstamp.md",
      "title": "Bitstamp hot-wallet compromise — Bitcoin — 2015-01-04",
      "date_prefix": "2015-01",
      "techniques": [
        "OAK-T11",
        "OAK-T11.002",
        "OAK-T15.001",
        "OAK-T15.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2015-01-bitstamp.md"
    },
    {
      "id": "2015-01-coinmx-unlicensed-bitcoin-exchange",
      "file": "2015-01-coinmx-unlicensed-bitcoin-exchange.md",
      "title": "Coin.mx first US federal criminal prosecution of unlicensed Bitcoin exchange — Bitcoin — 2015-01-26 (indictment unsealed)",
      "date_prefix": "2015-01",
      "techniques": [
        "OAK-T15.005",
        "OAK-T6.007",
        "OAK-T7.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2015-01-coinmx-unlicensed-bitcoin-exchange.md"
    },
    {
      "id": "2015-01-localbitcoins",
      "file": "2015-01-localbitcoins.md",
      "title": "LocalBitcoins social-engineering compromise — Bitcoin — 2015-01-27",
      "date_prefix": "2015-01",
      "techniques": [
        "OAK-T15.003",
        "OAK-T4.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2015-01-localbitcoins.md"
    },
    {
      "id": "2015-02-bter",
      "file": "2015-02-bter.md",
      "title": "BTER hot-wallet drain — Bitcoin — 2015-02-14",
      "date_prefix": "2015-02",
      "techniques": [
        "OAK-T11",
        "OAK-T11.001",
        "OAK-T11.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2015-02-bter.md"
    },
    {
      "id": "2015-03-evolution-darknet-exit-scam",
      "file": "2015-03-evolution-darknet-exit-scam.md",
      "title": "Evolution Darknet Market Exit Scam — 2015-03",
      "date_prefix": "2015-03",
      "techniques": [
        "OAK-T5.005",
        "OAK-T6.001",
        "OAK-T8.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2015-03-evolution-darknet-exit-scam.md"
    },
    {
      "id": "2015-05-bitfinex",
      "file": "2015-05-bitfinex.md",
      "title": "Bitfinex hot-wallet compromise — Bitcoin — 2015-05-22",
      "date_prefix": "2015-05",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2015-05-bitfinex.md"
    },
    {
      "id": "2016-01-cryptsy-exchange-collapse",
      "file": "2016-01-cryptsy-exchange-collapse.md",
      "title": "Cryptsy exchange collapse and operator-side theft — Bitcoin / altcoins — 2016-01-14",
      "date_prefix": "2016-01",
      "techniques": [
        "OAK-T11.001",
        "OAK-T11.005",
        "OAK-T6.007"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2016-01-cryptsy-exchange-collapse.md"
    },
    {
      "id": "2016-05-gatecoin",
      "file": "2016-05-gatecoin.md",
      "title": "Gatecoin exchange hot-wallet compromise — Bitcoin / Ethereum — 2016-05-13",
      "date_prefix": "2016-05",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2016-05-gatecoin.md"
    },
    {
      "id": "2016-06-the-dao",
      "file": "2016-06-the-dao.md",
      "title": "The DAO reentrancy exploit — Ethereum — 2016-06-17",
      "date_prefix": "2016-06",
      "techniques": [
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2016-06-the-dao.md"
    },
    {
      "id": "2016-08-bitfinex",
      "file": "2016-08-bitfinex.md",
      "title": "Bitfinex exchange theft — Bitcoin — 2016-08-02",
      "date_prefix": "2016-08",
      "techniques": [
        "OAK-T11.001",
        "OAK-T7.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2016-08-bitfinex.md"
    },
    {
      "id": "2016-11-coinbase-irs-john-doe-summons",
      "file": "2016-11-coinbase-irs-john-doe-summons.md",
      "title": "IRS Coinbase John Doe Summons — 2016-11-30",
      "date_prefix": "2016-11",
      "techniques": [
        "OAK-T14.005",
        "OAK-T6.007",
        "OAK-T8.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2016-11-coinbase-irs-john-doe-summons.md"
    },
    {
      "id": "2017-01-big-pump-signal-telegram-cohort",
      "file": "2017-01-big-pump-signal-telegram-cohort.md",
      "title": "Big Pump Signal Telegram / Discord coordinated pump-and-dump cohort — multi-CEX (Binance / Cryptopia / Bittrex) — 2017–2018 (canonical academic anchor); cohort recurs through 2024",
      "date_prefix": "2017-01",
      "techniques": [
        "OAK-T3.003",
        "OAK-T6",
        "OAK-T8.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2017-01-big-pump-signal-telegram-cohort.md"
    },
    {
      "id": "2017-04-yapizon",
      "file": "2017-04-yapizon.md",
      "title": "Yapizon (Youbit) exchange hack — Bitcoin — 2017-04-22",
      "date_prefix": "2017-04",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.003"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2017-04-yapizon.md"
    },
    {
      "id": "2017-06-bithumb",
      "file": "2017-06-bithumb.md",
      "title": "Bithumb employee-laptop compromise + downstream phishing wave — multi-asset / Korean exchange — 2017-06 to 2017-09",
      "date_prefix": "2017-06",
      "techniques": [
        "OAK-T11.002",
        "OAK-T15.003"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2017-06-bithumb.md"
    },
    {
      "id": "2017-07-btc-e-seizure",
      "file": "2017-07-btc-e-seizure.md",
      "title": "BTC-e exchange seizure and Alexander Vinnik arrest — Bitcoin — 2017-07-25 to 2017-07-26",
      "date_prefix": "2017-07",
      "techniques": [
        "OAK-T11.001",
        "OAK-T7.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2017-07-btc-e-seizure.md"
    },
    {
      "id": "2017-07-parity-multisig",
      "file": "2017-07-parity-multisig.md",
      "title": "Parity Multisig Wallet — Ethereum — 2017-07-19 and 2017-11-06",
      "date_prefix": "2017-07",
      "techniques": [
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2017-07-parity-multisig.md"
    },
    {
      "id": "2017-11-tether-treasury",
      "file": "2017-11-tether-treasury.md",
      "title": "Tether treasury hack — Bitcoin (Omni Layer) — 2017-11-19",
      "date_prefix": "2017-11",
      "techniques": [
        "OAK-T1.002",
        "OAK-T11.001",
        "OAK-T7.001",
        "OAK-T7.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2017-11-tether-treasury.md"
    },
    {
      "id": "2017-12-nicehash",
      "file": "2017-12-nicehash.md",
      "title": "NiceHash mining-marketplace wallet compromise — Bitcoin — 2017-12-06",
      "date_prefix": "2017-12",
      "techniques": [
        "OAK-T11.002",
        "OAK-T15.001",
        "OAK-T15.003",
        "OAK-T7.001",
        "OAK-T8.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2017-12-nicehash.md"
    },
    {
      "id": "2017-2019-ledger-nano-s-counterfeit-cohort",
      "file": "2017-2019-ledger-nano-s-counterfeit-cohort.md",
      "title": "Early Ledger Nano S Counterfeit Cohort — 2017–2019",
      "date_prefix": "2017-20",
      "techniques": [
        "OAK-T11.007.001",
        "OAK-T8.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2017-2019-ledger-nano-s-counterfeit-cohort.md"
    },
    {
      "id": "2017-2025-exchange-account-farming-cohort",
      "file": "2017-2025-exchange-account-farming-cohort.md",
      "title": "Cross-exchange account farming infrastructure — chain-agnostic (exchange-side) — 2017–2025",
      "date_prefix": "2017-20",
      "techniques": [
        "OAK-T7.002",
        "OAK-T8.001",
        "OAK-T8.004",
        "OAK-T8.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2017-2025-exchange-account-farming-cohort.md"
    },
    {
      "id": "2017-2025-hardware-wallet-physical-compromise-cohort",
      "file": "2017-2025-hardware-wallet-physical-compromise-cohort.md",
      "title": "Hardware-Wallet Physical Compromise Cohort — 2017–2025",
      "date_prefix": "2017-20",
      "techniques": [
        "OAK-T11.007",
        "OAK-T11.007.001",
        "OAK-T11.007.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2017-2025-hardware-wallet-physical-compromise-cohort.md"
    },
    {
      "id": "2018-01-bitconnect",
      "file": "2018-01-bitconnect.md",
      "title": "BitConnect Ponzi collapse — Bitcoin / BitConnect — 2018-01-16",
      "date_prefix": "2018-01",
      "techniques": [
        "OAK-T11.005",
        "OAK-T3.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2018-01-bitconnect.md"
    },
    {
      "id": "2018-01-coincheck",
      "file": "2018-01-coincheck.md",
      "title": "Coincheck exchange hot-wallet theft — NEM / XEM — 2018-01-26",
      "date_prefix": "2018-01",
      "techniques": [
        "OAK-T15.001",
        "OAK-T15.003"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2018-01-coincheck.md"
    },
    {
      "id": "2018-02-bitgrail",
      "file": "2018-02-bitgrail.md",
      "title": "BitGrail exchange compromise — Nano (XRB / NANO) — 2017-10 to 2018-02-08 (disclosure)",
      "date_prefix": "2018-02",
      "techniques": [
        "OAK-T11",
        "OAK-T5.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2018-02-bitgrail.md"
    },
    {
      "id": "2018-03-binance-api-phishing",
      "file": "2018-03-binance-api-phishing.md",
      "title": "Binance API-key phishing campaign — Binance (CEX) — 2018-03-07",
      "date_prefix": "2018-03",
      "techniques": [
        "OAK-T15.003",
        "OAK-T4.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2018-03-binance-api-phishing.md"
    },
    {
      "id": "2018-06-bithumb",
      "file": "2018-06-bithumb.md",
      "title": "Bithumb exchange hack — Multi-asset (BTC, ETH, XRP, others) — 2018-06-20",
      "date_prefix": "2018-06",
      "techniques": [
        "OAK-T11.001",
        "OAK-T7.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2018-06-bithumb.md"
    },
    {
      "id": "2018-06-coinrail",
      "file": "2018-06-coinrail.md",
      "title": "Coinrail exchange compromise — multi-asset (ERC-20 token portfolio) — 2018-06-09 / 2018-06-10",
      "date_prefix": "2018-06",
      "techniques": [
        "OAK-T11",
        "OAK-T11.002",
        "OAK-T15.001",
        "OAK-T15.003"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2018-06-coinrail.md"
    },
    {
      "id": "2018-07-bancor",
      "file": "2018-07-bancor.md",
      "title": "Bancor — Ethereum DEX — 2018-07-09",
      "date_prefix": "2018-07",
      "techniques": [
        "OAK-T1.004",
        "OAK-T11",
        "OAK-T4.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2018-07-bancor.md"
    },
    {
      "id": "2018-09-zaif",
      "file": "2018-09-zaif.md",
      "title": "Zaif exchange hack — Multi-asset (BTC, BCH, MONA) — 2018-09-14",
      "date_prefix": "2018-09",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2018-09-zaif.md"
    },
    {
      "id": "2018-2025-apt43-kimsuky-crypto-funded-espionage",
      "file": "2018-2025-apt43-kimsuky-crypto-funded-espionage.md",
      "title": "APT43 / Kimsuky crypto-funded espionage — 2018–2025",
      "date_prefix": "2018-20",
      "techniques": [
        "OAK-T15.001",
        "OAK-T4.001",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2018-2025-apt43-kimsuky-crypto-funded-espionage.md"
    },
    {
      "id": "2018-2025-dprk-it-worker-exchange-account-farming",
      "file": "2018-2025-dprk-it-worker-exchange-account-farming.md",
      "title": "DPRK IT worker exchange account farming — 2018–2025",
      "date_prefix": "2018-20",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.001",
        "OAK-T8.004"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2018-2025-dprk-it-worker-exchange-account-farming.md"
    },
    {
      "id": "2018-2025-iranian-cyber-operators-crypto-economy",
      "file": "2018-2025-iranian-cyber-operators-crypto-economy.md",
      "title": "Iranian state-aligned financially-motivated cyber operations — 2018–2025",
      "date_prefix": "2018-20",
      "techniques": [
        "OAK-T5.008",
        "OAK-T7.002",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2018-2025-iranian-cyber-operators-crypto-economy.md"
    },
    {
      "id": "2018-welcome-to-video-son-jong-woo-cross-layer",
      "file": "2018-welcome-to-video-son-jong-woo-cross-layer.md",
      "title": "Welcome to Video Son Jong-woo cross-layer de-anonymization — 2018",
      "date_prefix": "2018",
      "techniques": [
        "OAK-T7.002",
        "OAK-T8.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2018-welcome-to-video-son-jong-woo-cross-layer.md"
    },
    {
      "id": "2019-01-cryptopia",
      "file": "2019-01-cryptopia.md",
      "title": "Cryptopia exchange sustained drain — Ethereum and ERC-20 tokens — 2019-01-14 to 2019-01-28",
      "date_prefix": "2019-01",
      "techniques": [
        "OAK-T11",
        "OAK-T5.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2019-01-cryptopia.md"
    },
    {
      "id": "2019-01-quadrigacx",
      "file": "2019-01-quadrigacx.md",
      "title": "QuadrigaCX exchange collapse — multi-chain (BTC, ETH, LTC, BCH) — 2019-01 to 2019-04",
      "date_prefix": "2019-01",
      "techniques": [
        "OAK-T11.001",
        "OAK-T11.005.002",
        "OAK-T5.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2019-01-quadrigacx.md"
    },
    {
      "id": "2019-03-dragonex",
      "file": "2019-03-dragonex.md",
      "title": "DragonEx exchange compromise — multi-asset cross-chain — 2019-03-24",
      "date_prefix": "2019-03",
      "techniques": [
        "OAK-T11",
        "OAK-T15.001",
        "OAK-T15.003"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2019-03-dragonex.md"
    },
    {
      "id": "2019-05-binance-hot-wallet",
      "file": "2019-05-binance-hot-wallet.md",
      "title": "Binance hot-wallet compromise — Bitcoin — 2019-05-07",
      "date_prefix": "2019-05",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.003",
        "OAK-T7.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2019-05-binance-hot-wallet.md"
    },
    {
      "id": "2019-06-binance-kyc-leak",
      "file": "2019-06-binance-kyc-leak.md",
      "title": "Binance KYC data leak — Binance (CEX) via third-party KYC vendor — 2019-06 (breach date) / 2019-08-06 (public disclosure)",
      "date_prefix": "2019-06",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.003",
        "OAK-T8.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2019-06-binance-kyc-leak.md"
    },
    {
      "id": "2019-06-plus-token",
      "file": "2019-06-plus-token.md",
      "title": "PlusToken (Plus Token) Ponzi — multi-chain — collapse 2019-06",
      "date_prefix": "2019-06",
      "techniques": [
        "OAK-T11.005.002",
        "OAK-T7.001",
        "OAK-T7.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2019-06-plus-token.md"
    },
    {
      "id": "2019-07-bitpoint",
      "file": "2019-07-bitpoint.md",
      "title": "Bitpoint exchange hack — Multi-asset (BTC, ETH, XRP, LTC, BCH) — 2019-07-11",
      "date_prefix": "2019-07",
      "techniques": [
        "OAK-T11.001",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2019-07-bitpoint.md"
    },
    {
      "id": "2019-08-wallet-fail-trezor-keepkey-35c3-disclosure",
      "file": "2019-08-wallet-fail-trezor-keepkey-35c3-disclosure.md",
      "title": "Wallet.fail Trezor / KeepKey Hardware-Side Seed Extraction Disclosure — 35C3 — 2018-12-27",
      "date_prefix": "2019-08",
      "techniques": [
        "OAK-T11.007.001",
        "OAK-T11.007.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2019-08-wallet-fail-trezor-keepkey-35c3-disclosure.md"
    },
    {
      "id": "2019-11-upbit",
      "file": "2019-11-upbit.md",
      "title": "Upbit exchange hack — Ethereum — 2019-11-27",
      "date_prefix": "2019-11",
      "techniques": [
        "OAK-T11.001",
        "OAK-T7.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2019-11-upbit.md"
    },
    {
      "id": "2019-2025-crypto-exchange-orderbook-spoofing-wash-trading-cohort",
      "file": "2019-2025-crypto-exchange-orderbook-spoofing-wash-trading-cohort.md",
      "title": "Crypto Exchange Orderbook Spoofing and Wash-Trading Cohort — 2019–2025",
      "date_prefix": "2019-20",
      "techniques": [
        "OAK-T12.001",
        "OAK-T17.001",
        "OAK-T17.003",
        "OAK-T6.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2019-2025-crypto-exchange-orderbook-spoofing-wash-trading-cohort.md"
    },
    {
      "id": "2020-01-trezor-kraken-rdp-downgrade",
      "file": "2020-01-trezor-kraken-rdp-downgrade.md",
      "title": "Trezor One / Model T RDP-downgrade voltage-glitch seed extraction (Kraken Security Labs disclosure) — hardware wallets — 2020-01-31",
      "date_prefix": "2020-01",
      "techniques": [
        "OAK-T11.007",
        "OAK-T11.007.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2020-01-trezor-kraken-rdp-downgrade.md"
    },
    {
      "id": "2020-02-bzx",
      "file": "2020-02-bzx.md",
      "title": "bZx Protocol flash-loan-funded exploits — Ethereum — 2020-02-15 and 2020-02-18",
      "date_prefix": "2020-02",
      "techniques": [
        "OAK-T17.001",
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-02-bzx.md"
    },
    {
      "id": "2020-03-makerdao-black-thursday",
      "file": "2020-03-makerdao-black-thursday.md",
      "title": "MakerDAO Black Thursday liquidation-cascade zero-bid auctions — Ethereum — 2020-03-12",
      "date_prefix": "2020-03",
      "techniques": [
        "OAK-T17.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2020-03-makerdao-black-thursday.md"
    },
    {
      "id": "2020-04-lendf-me",
      "file": "2020-04-lendf-me.md",
      "title": "Lendf.me reentrancy via ERC-777 callback chain — Ethereum — 2020-04-19",
      "date_prefix": "2020-04",
      "techniques": [
        "OAK-T1.007",
        "OAK-T7.001",
        "OAK-T9.002",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-04-lendf-me.md"
    },
    {
      "id": "2020-06-bancor",
      "file": "2020-06-bancor.md",
      "title": "Bancor v0.6 upgrade pool-drain exploit — Ethereum — 2020-06-18",
      "date_prefix": "2020-06",
      "techniques": [
        "OAK-T16.006",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-06-bancor.md"
    },
    {
      "id": "2020-07-garmin-wastedlocker-evil-corp",
      "file": "2020-07-garmin-wastedlocker-evil-corp.md",
      "title": "Evil Corp WastedLocker ransomware — Garmin incident — 2020-07",
      "date_prefix": "2020-07",
      "techniques": [
        "OAK-T5.008",
        "OAK-T7.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2020-07-garmin-wastedlocker-evil-corp.md"
    },
    {
      "id": "2020-07-ledger-data-breach",
      "file": "2020-07-ledger-data-breach.md",
      "title": "Ledger customer-data breach and follow-on phishing campaign — e-commerce / multi-chain — 2020-07 (disclosed 2020-07-29)",
      "date_prefix": "2020-07",
      "techniques": [
        "OAK-T15.004",
        "OAK-T4.001",
        "OAK-T4.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2020-07-ledger-data-breach.md"
    },
    {
      "id": "2020-07-twitter-hack",
      "file": "2020-07-twitter-hack.md",
      "title": "Twitter internal-tool compromise and Bitcoin scam campaign — 2020-07-15",
      "date_prefix": "2020-07",
      "techniques": [
        "OAK-T15.001",
        "OAK-T4.007",
        "OAK-T7.001",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2020-07-twitter-hack.md"
    },
    {
      "id": "2020-08-yam-finance",
      "file": "2020-08-yam-finance.md",
      "title": "Yam Finance rebase-bug governance-capture — Ethereum — 2020-08-12 to 2020-08-13",
      "date_prefix": "2020-08",
      "techniques": [
        "OAK-T16.001",
        "OAK-T3.001",
        "OAK-T9.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2020-08-yam-finance.md"
    },
    {
      "id": "2020-09-eminence-defi-flash-loan-exploit",
      "file": "2020-09-eminence-defi-flash-loan-exploit.md",
      "title": "Eminence DeFi flash-loan exploit — Ethereum — 2020-09-28 to 2020-09-29",
      "date_prefix": "2020-09",
      "techniques": [
        "OAK-T17.001",
        "OAK-T5.002",
        "OAK-T9.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-09-eminence-defi-flash-loan-exploit.md"
    },
    {
      "id": "2020-09-kucoin",
      "file": "2020-09-kucoin.md",
      "title": "KuCoin exchange hot-wallet theft — multi-chain — 2020-09-25",
      "date_prefix": "2020-09",
      "techniques": [
        "OAK-T15.001",
        "OAK-T15.003",
        "OAK-T4.003",
        "OAK-T7.001",
        "OAK-T8.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2020-09-kucoin.md"
    },
    {
      "id": "2020-09-sushiswap-chef-nomi",
      "file": "2020-09-sushiswap-chef-nomi.md",
      "title": "SushiSwap dev-fund T5.005 + vampire-attack launch — Ethereum — 2020-08-26 to 2020-09-11",
      "date_prefix": "2020-09",
      "techniques": [
        "OAK-T1.004",
        "OAK-T2.001",
        "OAK-T5.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-09-sushiswap-chef-nomi.md"
    },
    {
      "id": "2020-09-yfdexf-finance-exit-scam",
      "file": "2020-09-yfdexf-finance-exit-scam.md",
      "title": "Yfdexf.Finance liquidity-mining exit scam — Ethereum — 2020-09-08 to 2020-09-10",
      "date_prefix": "2020-09",
      "techniques": [
        "OAK-T1.003",
        "OAK-T11.005",
        "OAK-T2.001",
        "OAK-T5.001",
        "OAK-T6.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-09-yfdexf-finance-exit-scam.md"
    },
    {
      "id": "2020-10-harvest-finance",
      "file": "2020-10-harvest-finance.md",
      "title": "Harvest Finance flash-loan-funded oracle manipulation — Ethereum — 2020-10-26",
      "date_prefix": "2020-10",
      "techniques": [
        "OAK-T17.001",
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-10-harvest-finance.md"
    },
    {
      "id": "2020-10-unicats",
      "file": "2020-10-unicats.md",
      "title": "UniCats yield-farm approval backdoor — Ethereum — 2020-10-05",
      "date_prefix": "2020-10",
      "techniques": [
        "OAK-T1.003",
        "OAK-T4.004",
        "OAK-T6.001",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-10-unicats.md"
    },
    {
      "id": "2020-11-akropolis",
      "file": "2020-11-akropolis.md",
      "title": "Akropolis Delphi flash-loan-funded reentrancy — Ethereum — 2020-11-12",
      "date_prefix": "2020-11",
      "techniques": [
        "OAK-T9.002",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-11-akropolis.md"
    },
    {
      "id": "2020-11-cred",
      "file": "2020-11-cred.md",
      "title": "Cred Inc. custodial-fraud / counterparty-risk insolvency — multi-chain (custodial) — 2020-11-07",
      "date_prefix": "2020-11",
      "techniques": [
        "OAK-T11.010",
        "OAK-T6.007"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2020-11-cred.md"
    },
    {
      "id": "2020-11-origin-dollar",
      "file": "2020-11-origin-dollar.md",
      "title": "Origin Dollar (OUSD) flash-loan-funded reentrancy — Ethereum — 2020-11-17",
      "date_prefix": "2020-11",
      "techniques": [
        "OAK-T7.001",
        "OAK-T9.002",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-11-origin-dollar.md"
    },
    {
      "id": "2020-11-pickle-finance",
      "file": "2020-11-pickle-finance.md",
      "title": "Pickle Finance Evil Jar exploit — Ethereum — 2020-11-21",
      "date_prefix": "2020-11",
      "techniques": [
        "OAK-T5.001",
        "OAK-T9.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2020-11-pickle-finance.md"
    },
    {
      "id": "2020-12-compounder-finance",
      "file": "2020-12-compounder-finance.md",
      "title": "Compounder Finance strategy-swap LP drain — Ethereum — 2020-11-30 to 2020-12-02",
      "date_prefix": "2020-12",
      "techniques": [
        "OAK-T1.001",
        "OAK-T11.005",
        "OAK-T2.001",
        "OAK-T5.001",
        "OAK-T5.003",
        "OAK-T6.002",
        "OAK-T6.003",
        "OAK-T6.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-12-compounder-finance.md"
    },
    {
      "id": "2020-12-cover-protocol-blacksmith-mint",
      "file": "2020-12-cover-protocol-blacksmith-mint.md",
      "title": "Cover Protocol Blacksmith infinite-mint exploit — Ethereum — 2020-12-28",
      "date_prefix": "2020-12",
      "techniques": [
        "OAK-T5.003",
        "OAK-T9.002",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-12-cover-protocol-blacksmith-mint.md"
    },
    {
      "id": "2020-12-livecoin",
      "file": "2020-12-livecoin.md",
      "title": "Livecoin exchange infrastructure seizure and hot-wallet drain — Bitcoin / Ethereum / multi-asset (CEX) — 2020-12-23",
      "date_prefix": "2020-12",
      "techniques": [
        "OAK-T15.003",
        "OAK-T15.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-12-livecoin.md"
    },
    {
      "id": "2020-12-warp-finance",
      "file": "2020-12-warp-finance.md",
      "title": "Warp Finance flash-loan oracle exploit — Ethereum — 2020-12-17",
      "date_prefix": "2020-12",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2020-12-warp-finance.md"
    },
    {
      "id": "2020-2020-uniswap-honeypot-wave",
      "file": "2020-2020-uniswap-honeypot-wave.md",
      "title": "Uniswap honeypot-token wave and serial deployer cluster — Ethereum — 2020 (cohort)",
      "date_prefix": "2020-20",
      "techniques": [
        "OAK-T1.001",
        "OAK-T1.005",
        "OAK-T1.006",
        "OAK-T4.008",
        "OAK-T6.001",
        "OAK-T8.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-2020-uniswap-honeypot-wave.md"
    },
    {
      "id": "2020-2021-defi-timelock-free-upgrade-cohort",
      "file": "2020-2021-defi-timelock-free-upgrade-cohort.md",
      "title": "DeFi \"move fast\" era timelock-free protocol upgrade cohort — EVM — 2020–2021",
      "date_prefix": "2020-20",
      "techniques": [
        "OAK-T12.002",
        "OAK-T16.006"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2020-2021-defi-timelock-free-upgrade-cohort.md"
    },
    {
      "id": "2020-2021-uniswap-fake-token-impersonation-wave",
      "file": "2020-2021-uniswap-fake-token-impersonation-wave.md",
      "title": "Uniswap V2/V3 fake-token impersonation wave — Ethereum — 2020-2021",
      "date_prefix": "2020-20",
      "techniques": [
        "OAK-T2.005",
        "OAK-T6.006"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2020-2021-uniswap-fake-token-impersonation-wave.md"
    },
    {
      "id": "2020-2023-lazarus-group-200m-laundering",
      "file": "2020-2023-lazarus-group-200m-laundering.md",
      "title": "Lazarus Group — $200M Fiat Cash-Out from 25+ Hacks — 2020-2023",
      "date_prefix": "2020-20",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T7.003",
        "OAK-T8.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2020-2023-lazarus-group-200m-laundering.md"
    },
    {
      "id": "2020-2024-ransomware-extortion-landmark-cohort",
      "file": "2020-2024-ransomware-extortion-landmark-cohort.md",
      "title": "Landmark Ransomware Extortion Cohort — 2020–2024 — 12 Incidents — Aggregate ~$225M+",
      "date_prefix": "2020-20",
      "techniques": [
        "OAK-T5.008",
        "OAK-T7.001",
        "OAK-T7.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2020-2024-ransomware-extortion-landmark-cohort.md"
    },
    {
      "id": "2020-2025-initial-liquidity-sandwich-cohort",
      "file": "2020-2025-initial-liquidity-sandwich-cohort.md",
      "title": "Initial liquidity sandwich MEV cohort — EVM / multi-chain — 2020–2025 (ongoing)",
      "date_prefix": "2020-20",
      "techniques": [
        "OAK-T5.004",
        "OAK-T9.012"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2020-2025-initial-liquidity-sandwich-cohort.md"
    },
    {
      "id": "2020-2025-mev-sandwich-attack-cohort",
      "file": "2020-2025-mev-sandwich-attack-cohort.md",
      "title": "MEV Sandwich Attack Cohort — 2020–2025",
      "date_prefix": "2020-20",
      "techniques": [
        "OAK-T17.005",
        "OAK-T9.012",
        "OAK-T9.013"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2020-2025-mev-sandwich-attack-cohort.md"
    },
    {
      "id": "2021-02-furucombo",
      "file": "2021-02-furucombo.md",
      "title": "Furucombo proxy-authority exploit — Ethereum — 2021-02-27",
      "date_prefix": "2021-02",
      "techniques": [
        "OAK-T16.006",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-02-furucombo.md"
    },
    {
      "id": "2021-03-mcafee-cftc-pump-dump",
      "file": "2021-03-mcafee-cftc-pump-dump.md",
      "title": "McAfee / Watson digital-asset pump-and-dump CFTC + DOJ enforcement — multi-CEX (Twitter-amplified) — 2017-12 / 2018-01 conduct; charges 2021-03-05",
      "date_prefix": "2021-03",
      "techniques": [
        "OAK-T17.001",
        "OAK-T3.003",
        "OAK-T6"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2021-03-mcafee-cftc-pump-dump.md"
    },
    {
      "id": "2021-03-meerkat-finance",
      "file": "2021-03-meerkat-finance.md",
      "title": "Meerkat Finance deployer-drain exit scam — BSC — 2021-03-04",
      "date_prefix": "2021-03",
      "techniques": [
        "OAK-T5.001",
        "OAK-T5.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-03-meerkat-finance.md"
    },
    {
      "id": "2021-03-safemoon",
      "file": "2021-03-safemoon.md",
      "title": "SafeMoon (SFM) token-launch mechanics — BNB Chain — 2021-03",
      "date_prefix": "2021-03",
      "techniques": [
        "OAK-T1.001",
        "OAK-T17.001",
        "OAK-T2.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-03-safemoon.md"
    },
    {
      "id": "2021-03-true-seigniorage-dollar",
      "file": "2021-03-true-seigniorage-dollar.md",
      "title": "True Seigniorage Dollar (TSD) hostile-vote mint flooding — Binance Smart Chain — 2021-03-13",
      "date_prefix": "2021-03",
      "techniques": [
        "OAK-T16.002",
        "OAK-T9.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-03-true-seigniorage-dollar.md"
    },
    {
      "id": "2021-04-easyfi",
      "file": "2021-04-easyfi.md",
      "title": "EasyFi admin-key compromise — Polygon — 2021-04-19",
      "date_prefix": "2021-04",
      "techniques": [
        "OAK-T11.002",
        "OAK-T4.003",
        "OAK-T5.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-04-easyfi.md"
    },
    {
      "id": "2021-04-uranium-finance",
      "file": "2021-04-uranium-finance.md",
      "title": "Uranium Finance migration-pair arithmetic error — BSC — 2021-04-28",
      "date_prefix": "2021-04",
      "techniques": [
        "OAK-T9.004",
        "OAK-T9.011"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-04-uranium-finance.md"
    },
    {
      "id": "2021-05-bogged-finance",
      "file": "2021-05-bogged-finance.md",
      "title": "Bogged Finance flash-loan governance attack — BNB Chain — 2021-05-22",
      "date_prefix": "2021-05",
      "techniques": [
        "OAK-T16.001",
        "OAK-T5.001",
        "OAK-T7.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-05-bogged-finance.md"
    },
    {
      "id": "2021-05-colonial-pipeline",
      "file": "2021-05-colonial-pipeline.md",
      "title": "Colonial Pipeline ransomware extortion payment — 2021-05",
      "date_prefix": "2021-05",
      "techniques": [
        "OAK-T5.008"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2021-05-colonial-pipeline.md"
    },
    {
      "id": "2021-05-dfinity-icp-vesting-cliff-dump",
      "file": "2021-05-dfinity-icp-vesting-cliff-dump.md",
      "title": "DFINITY Internet Computer (ICP) insider vesting-cliff token dump — Ethereum — 2021-05-10 onward",
      "date_prefix": "2021-05",
      "techniques": [
        "OAK-T5.006",
        "OAK-T6.001",
        "OAK-T8.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2021-05-dfinity-icp-vesting-cliff-dump.md"
    },
    {
      "id": "2021-05-meebits-mint-outcome-reroll-rarity-exploit",
      "file": "2021-05-meebits-mint-outcome-reroll-rarity-exploit.md",
      "title": "Meebits — the mint told you what you got before you had to keep it, and an archived attribute file told you what it was worth, so a contract minted and reverted until a rare one came out — Meebits / Larva Labs (Ethereum) — 2021-05-08",
      "date_prefix": "2021-05",
      "techniques": [
        "OAK-T12.002",
        "OAK-T12.007"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-05-meebits-mint-outcome-reroll-rarity-exploit.md"
    },
    {
      "id": "2021-05-pancake-bunny",
      "file": "2021-05-pancake-bunny.md",
      "title": "PancakeBunny yield-aggregator mint-pricing exploit — BNB Smart Chain — 2021-05-19",
      "date_prefix": "2021-05",
      "techniques": [
        "OAK-T5.001",
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-05-pancake-bunny.md"
    },
    {
      "id": "2021-05-spartan-protocol",
      "file": "2021-05-spartan-protocol.md",
      "title": "Spartan Protocol AMM-LP-pricing exploit — BNB Smart Chain — 2021-05-02",
      "date_prefix": "2021-05",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-05-spartan-protocol.md"
    },
    {
      "id": "2021-06-iron-finance",
      "file": "2021-06-iron-finance.md",
      "title": "Iron Finance (IRON / TITAN) — Polygon — collapse 2021-06-16",
      "date_prefix": "2021-06",
      "techniques": [
        "OAK-T2.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-06-iron-finance.md"
    },
    {
      "id": "2021-07-chainswap",
      "file": "2021-07-chainswap.md",
      "title": "ChainSwap bridge token-deployment exploit — multi-chain (Ethereum, BSC, Polygon) — 2021-07-02 and 2021-07-11",
      "date_prefix": "2021-07",
      "techniques": [
        "OAK-T10.002",
        "OAK-T7.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-07-chainswap.md"
    },
    {
      "id": "2021-07-thorchain",
      "file": "2021-07-thorchain.md",
      "title": "THORChain — Bifröst module — 2021-07-15, 2021-07-23, 2021-08-12 (cluster)",
      "date_prefix": "2021-07",
      "techniques": [
        "OAK-T10.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-07-thorchain.md"
    },
    {
      "id": "2021-08-liquid-global",
      "file": "2021-08-liquid-global.md",
      "title": "Liquid Global warm-wallet compromise — multi-chain — 2021-08-19",
      "date_prefix": "2021-08",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.001",
        "OAK-T15.003",
        "OAK-T4.003",
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T8.002"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2021-08-liquid-global.md"
    },
    {
      "id": "2021-08-poly-network",
      "file": "2021-08-poly-network.md",
      "title": "Poly Network — Cross-Chain Bridge — 2021-08-10",
      "date_prefix": "2021-08",
      "techniques": [
        "OAK-T10.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-08-poly-network.md"
    },
    {
      "id": "2021-09-compound",
      "file": "2021-09-compound.md",
      "title": "Compound Comptroller distribution bug — Ethereum — 2021-09-30",
      "date_prefix": "2021-09",
      "techniques": [
        "OAK-T9.003",
        "OAK-T9.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2021-09-compound.md"
    },
    {
      "id": "2021-09-evolved-apes",
      "file": "2021-09-evolved-apes.md",
      "title": "Evolved Apes NFT rug pull — Ethereum — 2021-09-24 / 2021-10-05",
      "date_prefix": "2021-09",
      "techniques": [
        "OAK-T1.003",
        "OAK-T12.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2021-09-evolved-apes.md"
    },
    {
      "id": "2021-09-vee-finance",
      "file": "2021-09-vee-finance.md",
      "title": "Vee Finance oracle manipulation — Avalanche — 2021-09-21",
      "date_prefix": "2021-09",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-09-vee-finance.md"
    },
    {
      "id": "2021-10-anubisdao",
      "file": "2021-10-anubisdao.md",
      "title": "AnubisDAO (ANKH) — Ethereum — 2021-10-28 / 2021-10-29",
      "date_prefix": "2021-10",
      "techniques": [
        "OAK-T5.001",
        "OAK-T6.001",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-10-anubisdao.md"
    },
    {
      "id": "2021-10-cream-finance",
      "file": "2021-10-cream-finance.md",
      "title": "Cream Finance oracle manipulation — Ethereum — 2021-10-27",
      "date_prefix": "2021-10",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-10-cream-finance.md"
    },
    {
      "id": "2021-11-squid",
      "file": "2021-11-squid.md",
      "title": "SQUID (Squid Game token) — BNB Chain — 2021-10 / 2021-11-01",
      "date_prefix": "2021-11",
      "techniques": [
        "OAK-T1.001",
        "OAK-T2.001",
        "OAK-T5.001",
        "OAK-T8.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-11-squid.md"
    },
    {
      "id": "2021-12-ascendex",
      "file": "2021-12-ascendex.md",
      "title": "AscendEX hot-wallet compromise — multi-chain (Ethereum, BSC, Polygon) — 2021-12-11",
      "date_prefix": "2021-12",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.003",
        "OAK-T4.003",
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T8.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2021-12-ascendex.md"
    },
    {
      "id": "2021-12-badgerdao",
      "file": "2021-12-badgerdao.md",
      "title": "BadgerDAO frontend compromise via Cloudflare Workers — Ethereum — 2021-12",
      "date_prefix": "2021-12",
      "techniques": [
        "OAK-T15.003",
        "OAK-T4.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-12-badgerdao.md"
    },
    {
      "id": "2021-12-bitmart",
      "file": "2021-12-bitmart.md",
      "title": "BitMart hot-wallet compromise — Ethereum/BNB Chain — 2021-12-05",
      "date_prefix": "2021-12",
      "techniques": [
        "OAK-T11.001",
        "OAK-T5.001",
        "OAK-T7.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2021-12-bitmart.md"
    },
    {
      "id": "2021-12-visor-finance",
      "file": "2021-12-visor-finance.md",
      "title": "Visor Finance Uniswap V3 TWAP oracle manipulation — Ethereum — 2021-12-21",
      "date_prefix": "2021-12",
      "techniques": [
        "OAK-T17.004",
        "OAK-T5.002",
        "OAK-T9.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-12-visor-finance.md"
    },
    {
      "id": "2021-12-vulcan-forged",
      "file": "2021-12-vulcan-forged.md",
      "title": "Vulcan Forged wallet-server compromise — Polygon/Ethereum — December 2021",
      "date_prefix": "2021-12",
      "techniques": [
        "OAK-T11.001",
        "OAK-T5.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2021-12-vulcan-forged.md"
    },
    {
      "id": "2021-2023-uranium-finance-exploit-seizure",
      "file": "2021-2023-uranium-finance-exploit-seizure.md",
      "title": "Uranium Finance — Smart Contract Exploit / $31M Seized — 2021 / 2025-02",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T7.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2021-2023-uranium-finance-exploit-seizure.md"
    },
    {
      "id": "2021-2024-andariel-maui-ransomware-healthcare",
      "file": "2021-2024-andariel-maui-ransomware-healthcare.md",
      "title": "Andariel Maui ransomware — healthcare-sector targeting — 2021–2024",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T15.001",
        "OAK-T5.008",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2021-2024-andariel-maui-ransomware-healthcare.md"
    },
    {
      "id": "2021-2024-magnate-kokomo-repeat-rug-pull-cluster",
      "file": "2021-2024-magnate-kokomo-repeat-rug-pull-cluster.md",
      "title": "Magnate/Kokomo/Lendora/Solfire — Cross-Project Repeat Rug Pull Operation — 2021-2024",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T8.001",
        "OAK-T8.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-2024-magnate-kokomo-repeat-rug-pull-cluster.md"
    },
    {
      "id": "2021-2024-rekt-uncovered-incidents-cohort",
      "file": "2021-2024-rekt-uncovered-incidents-cohort.md",
      "title": "2021–2024 Rekt.Uncovered Incidents Cohort",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T10.002",
        "OAK-T11.001",
        "OAK-T5.003",
        "OAK-T5.005",
        "OAK-T9.001",
        "OAK-T9.002",
        "OAK-T9.004",
        "OAK-T9.007",
        "OAK-T9.011"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2021-2024-rekt-uncovered-incidents-cohort.md"
    },
    {
      "id": "2021-2025-blackbyte-raas",
      "file": "2021-2025-blackbyte-raas.md",
      "title": "BlackByte Ransomware-as-a-Service — 2021–2025",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T5.008",
        "OAK-T7.005",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2021-2025-blackbyte-raas.md"
    },
    {
      "id": "2021-2025-defi-and-nft-laundering-infrastructure-cohort",
      "file": "2021-2025-defi-and-nft-laundering-infrastructure-cohort.md",
      "title": "DeFi and NFT Laundering-Infrastructure Cohort — 2021–2025",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T7.004",
        "OAK-T7.006"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2021-2025-defi-and-nft-laundering-infrastructure-cohort.md"
    },
    {
      "id": "2021-2025-governance-timelock-design-anti-pattern-cohort",
      "file": "2021-2025-governance-timelock-design-anti-pattern-cohort.md",
      "title": "Governance Timelock Design Anti-Pattern Cohort — 2021–2025 — Amplification Factor Across Multiple Technique Classes",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T16.001",
        "OAK-T16.006",
        "OAK-T9.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2021-2025-governance-timelock-design-anti-pattern-cohort.md"
    },
    {
      "id": "2021-2025-initial-liquidity-backdoor-and-lock-spoof-cohort",
      "file": "2021-2025-initial-liquidity-backdoor-and-lock-spoof-cohort.md",
      "title": "Initial-Liquidity Backdoor and Locked-Liquidity Spoof Cohort — 2021–2025 — Aggregate $100M+",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T2.002",
        "OAK-T2.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2021-2025-initial-liquidity-backdoor-and-lock-spoof-cohort.md"
    },
    {
      "id": "2021-2025-karakurt-data-extortion",
      "file": "2021-2025-karakurt-data-extortion.md",
      "title": "Karakurt encryption-free data-theft extortion operation — 2021–2025",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T15.001",
        "OAK-T5.008",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2021-2025-karakurt-data-extortion.md"
    },
    {
      "id": "2021-2025-multi-block-mev-twap-cohort",
      "file": "2021-2025-multi-block-mev-twap-cohort.md",
      "title": "Multi-block MEV TWAP oracle manipulation cohort — EVM — 2021–2025",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T14.005",
        "OAK-T17.004",
        "OAK-T17.005",
        "OAK-T9.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-2025-multi-block-mev-twap-cohort.md"
    },
    {
      "id": "2021-2025-pancakeswap-token-launch-mev-bsc",
      "file": "2021-2025-pancakeswap-token-launch-mev-bsc.md",
      "title": "PancakeSwap token-launch MEV sandwich cohort — BSC — 2021–2025",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T9.012"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-2025-pancakeswap-token-launch-mev-bsc.md"
    },
    {
      "id": "2021-2025-slippage-manipulation-sandwich-cohort",
      "file": "2021-2025-slippage-manipulation-sandwich-cohort.md",
      "title": "Slippage-manipulation sandwich MEV cohort — EVM (primary), Solana — 2021–2025",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T5.004",
        "OAK-T9.013"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-2025-slippage-manipulation-sandwich-cohort.md"
    },
    {
      "id": "2021-2026-fake-audit-claims-and-audit-pending-marketing-cohort",
      "file": "2021-2026-fake-audit-claims-and-audit-pending-marketing-cohort.md",
      "title": "Fake Audit Claims and Audit-Pending Marketing Cohort — 2021–2026 — Aggregate ~$50M+",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T6.002",
        "OAK-T6.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2021-2026-fake-audit-claims-and-audit-pending-marketing-cohort.md"
    },
    {
      "id": "2021-2026-influencer-amplified-non-memecoin-rug-cohort",
      "file": "2021-2026-influencer-amplified-non-memecoin-rug-cohort.md",
      "title": "Influencer-amplified non-memecoin promotion-and-dump cohort — multi-chain — 2021 onward (multi-year cohort)",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T1.001",
        "OAK-T1.003",
        "OAK-T17.001",
        "OAK-T3.003",
        "OAK-T3.004",
        "OAK-T5.001"
      ],
      "attribution": "mixed",
      "source_file": "examples/2021-2026-influencer-amplified-non-memecoin-rug-cohort.md"
    },
    {
      "id": "2021-2026-vesting-cliff-dump-and-brand-impersonation-custodial-soft-rug-cohort",
      "file": "2021-2026-vesting-cliff-dump-and-brand-impersonation-custodial-soft-rug-cohort.md",
      "title": "Vesting-Cliff Dump and Brand-Impersonation Custodial Soft-Rug Cohort — 2021–2026",
      "date_prefix": "2021-20",
      "techniques": [
        "OAK-T5.006",
        "OAK-T5.007"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2021-2026-vesting-cliff-dump-and-brand-impersonation-custodial-soft-rug-cohort.md"
    },
    {
      "id": "2021-bitcoin-fog-sterlingov-exchange-funding",
      "file": "2021-bitcoin-fog-sterlingov-exchange-funding.md",
      "title": "Bitcoin Fog Roman Sterlingov exchange-funding de-anonymization — 2021",
      "date_prefix": "2021",
      "techniques": [
        "OAK-T7.001",
        "OAK-T8.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2021-bitcoin-fog-sterlingov-exchange-funding.md"
    },
    {
      "id": "2021-bsc-pancakeswap-token-impersonation-wave",
      "file": "2021-bsc-pancakeswap-token-impersonation-wave.md",
      "title": "PancakeSwap token-impersonation wave — BSC — 2021",
      "date_prefix": "2021",
      "techniques": [
        "OAK-T2.005",
        "OAK-T6.006"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2021-bsc-pancakeswap-token-impersonation-wave.md"
    },
    {
      "id": "2022-01-arbix-finance",
      "file": "2022-01-arbix-finance.md",
      "title": "Arbix Finance audit-scope-mismatch rug pull — Binance Smart Chain — 2022-01-04",
      "date_prefix": "2022-01",
      "techniques": [
        "OAK-T1.001",
        "OAK-T2.001",
        "OAK-T5.001",
        "OAK-T5.003",
        "OAK-T6.003",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-01-arbix-finance.md"
    },
    {
      "id": "2022-01-big-daddy-ape-club",
      "file": "2022-01-big-daddy-ape-club.md",
      "title": "Big Daddy Ape Club NFT rug pull — Solana — 2022-01-10",
      "date_prefix": "2022-01",
      "techniques": [
        "OAK-T1.003",
        "OAK-T12",
        "OAK-T5.001",
        "OAK-T7.003",
        "OAK-T8.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-01-big-daddy-ape-club.md"
    },
    {
      "id": "2022-01-frosties",
      "file": "2022-01-frosties.md",
      "title": "Frosties NFT rug pull — Solana — 2022-01-09",
      "date_prefix": "2022-01",
      "techniques": [
        "OAK-T1.003",
        "OAK-T12",
        "OAK-T7.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-01-frosties.md"
    },
    {
      "id": "2022-01-looksrare-wash-trading-launch",
      "file": "2022-01-looksrare-wash-trading-launch.md",
      "title": "LooksRare wash-trading launch incentive — Ethereum — 2022-01-10 onward",
      "date_prefix": "2022-01",
      "techniques": [
        "OAK-T12.001",
        "OAK-T2.001",
        "OAK-T3.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-01-looksrare-wash-trading-launch.md"
    },
    {
      "id": "2022-01-looksrare-x2y2-wash-trading-cohort",
      "file": "2022-01-looksrare-x2y2-wash-trading-cohort.md",
      "title": "LooksRare / X2Y2 wash-trading reward-farming cohort — Ethereum — 2022",
      "date_prefix": "2022-01",
      "techniques": [
        "OAK-T5.002",
        "OAK-T7.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-01-looksrare-x2y2-wash-trading-cohort.md"
    },
    {
      "id": "2022-01-qubit-bridge",
      "file": "2022-01-qubit-bridge.md",
      "title": "Qubit Bridge — BNB Smart Chain ↔ Ethereum — 2022-01-27",
      "date_prefix": "2022-01",
      "techniques": [
        "OAK-T10.002",
        "OAK-T7.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-01-qubit-bridge.md"
    },
    {
      "id": "2022-01-wonderland-sifu-patryn",
      "file": "2022-01-wonderland-sifu-patryn.md",
      "title": "Wonderland Money — concealed-pseudonym treasury operator (Sifu / Michael Patryn) — Avalanche / multi-chain — 2022-01-27",
      "date_prefix": "2022-01",
      "techniques": [
        "OAK-T3.003",
        "OAK-T6.001",
        "OAK-T7.001",
        "OAK-T8.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2022-01-wonderland-sifu-patryn.md"
    },
    {
      "id": "2022-02-akutar-nft-influencer-rug",
      "file": "2022-02-akutar-nft-influencer-rug.md",
      "title": "Akutar NFT influencer-backed rug — Ethereum — 2022-02 to 2022-04",
      "date_prefix": "2022-02",
      "techniques": [
        "OAK-T12",
        "OAK-T3.004",
        "OAK-T5.005"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2022-02-akutar-nft-influencer-rug.md"
    },
    {
      "id": "2022-02-build-finance-dao",
      "file": "2022-02-build-finance-dao.md",
      "title": "Build Finance DAO hostile-takeover — Ethereum — 2022-02-09 to 2022-02-14",
      "date_prefix": "2022-02",
      "techniques": [
        "OAK-T1.003",
        "OAK-T15.005",
        "OAK-T16.002",
        "OAK-T5.005",
        "OAK-T7.001",
        "OAK-T9.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-02-build-finance-dao.md"
    },
    {
      "id": "2022-02-meter-bridge",
      "file": "2022-02-meter-bridge.md",
      "title": "Meter.io Passport Bridge — Ethereum ↔ BNB Smart Chain ↔ Moonriver — 2022-02-05",
      "date_prefix": "2022-02",
      "techniques": [
        "OAK-T10.002",
        "OAK-T7.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-02-meter-bridge.md"
    },
    {
      "id": "2022-02-wormhole",
      "file": "2022-02-wormhole.md",
      "title": "Wormhole Bridge — Ethereum ↔ Solana — 2022-02-02",
      "date_prefix": "2022-02",
      "techniques": [
        "OAK-T10.002",
        "OAK-T10.007",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-02-wormhole.md"
    },
    {
      "id": "2022-02-x2y2-marketplace-incentive-wash-cohort",
      "file": "2022-02-x2y2-marketplace-incentive-wash-cohort.md",
      "title": "X2Y2 marketplace-incentive wash-trade cohort — Ethereum — 2022-02-15 onward",
      "date_prefix": "2022-02",
      "techniques": [
        "OAK-T12.001",
        "OAK-T3.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-02-x2y2-marketplace-incentive-wash-cohort.md"
    },
    {
      "id": "2022-03-agave",
      "file": "2022-03-agave.md",
      "title": "Agave / Hundred Finance reentrancy exploit — Gnosis Chain — 2022-03-15",
      "date_prefix": "2022-03",
      "techniques": [
        "OAK-T1.007",
        "OAK-T9.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-03-agave.md"
    },
    {
      "id": "2022-03-bsc-yield-farm-liquidity-plant-cohort",
      "file": "2022-03-bsc-yield-farm-liquidity-plant-cohort.md",
      "title": "BSC yield-farm single-sided liquidity-plant cohort — Binance Smart Chain — 2022-Q1 through 2022-Q3",
      "date_prefix": "2022-03",
      "techniques": [
        "OAK-T1.003",
        "OAK-T2.001",
        "OAK-T5.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-03-bsc-yield-farm-liquidity-plant-cohort.md"
    },
    {
      "id": "2022-03-cashio",
      "file": "2022-03-cashio.md",
      "title": "Cashio infinite-mint via missing input validation — Solana — 2022-03-23",
      "date_prefix": "2022-03",
      "techniques": [
        "OAK-T7",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-03-cashio.md"
    },
    {
      "id": "2022-03-nft-proxy-upgrade-rug-cohort",
      "file": "2022-03-nft-proxy-upgrade-rug-cohort.md",
      "title": "NFT collection proxy-upgrade rug cohort — upgradeable contracts without timelock executed within same block — Ethereum — 2021–2023",
      "date_prefix": "2022-03",
      "techniques": [
        "OAK-T16.006"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-03-nft-proxy-upgrade-rug-cohort.md"
    },
    {
      "id": "2022-03-paraluni",
      "file": "2022-03-paraluni.md",
      "title": "Paraluni flash-loan exploit — BNB Chain — 2022-03-13",
      "date_prefix": "2022-03",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-03-paraluni.md"
    },
    {
      "id": "2022-03-ronin-bridge",
      "file": "2022-03-ronin-bridge.md",
      "title": "Ronin Bridge — Ethereum ↔ Ronin sidechain — 2022-03-23",
      "date_prefix": "2022-03",
      "techniques": [
        "OAK-T10.001",
        "OAK-T10.007",
        "OAK-T15.001",
        "OAK-T15.003",
        "OAK-T7.001",
        "OAK-T8.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-03-ronin-bridge.md"
    },
    {
      "id": "2022-04-beanstalk",
      "file": "2022-04-beanstalk.md",
      "title": "Beanstalk Farms flash-loan governance attack — Ethereum — 2022-04-17",
      "date_prefix": "2022-04",
      "techniques": [
        "OAK-T16.001",
        "OAK-T6.001",
        "OAK-T7.001",
        "OAK-T9.002",
        "OAK-T9.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-04-beanstalk.md"
    },
    {
      "id": "2022-04-bored-ape-discord-wave",
      "file": "2022-04-bored-ape-discord-wave.md",
      "title": "Bored Ape Yacht Club / Yuga Labs operator-side credential-compromise wave — Ethereum — 2022-04 → 2024-08",
      "date_prefix": "2022-04",
      "techniques": [
        "OAK-T11",
        "OAK-T12.002",
        "OAK-T15.005",
        "OAK-T15.006",
        "OAK-T4.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-04-bored-ape-discord-wave.md"
    },
    {
      "id": "2022-04-elephant-money-flash-loan-governance-attack",
      "file": "2022-04-elephant-money-flash-loan-governance-attack.md",
      "title": "Elephant Money flash-loan governance attack — BNB Chain — 2022-04-12",
      "date_prefix": "2022-04",
      "techniques": [
        "OAK-T16.001",
        "OAK-T9.002",
        "OAK-T9.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-04-elephant-money-flash-loan-governance-attack.md"
    },
    {
      "id": "2022-04-icloud-metamask-seed-phrase-cohort",
      "file": "2022-04-icloud-metamask-seed-phrase-cohort.md",
      "title": "iCloud-backup MetaMask seed-phrase cohort — multi-chain (EVM-dominant) — 2022-04 (canonical Iacovone case) onward",
      "date_prefix": "2022-04",
      "techniques": [
        "OAK-T11.006",
        "OAK-T11.006.002",
        "OAK-T4",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-04-icloud-metamask-seed-phrase-cohort.md"
    },
    {
      "id": "2022-04-inverse-finance-twap",
      "file": "2022-04-inverse-finance-twap.md",
      "title": "Inverse Finance TWAP-oracle window-manipulation lending exploit — Ethereum — 2022-04-02",
      "date_prefix": "2022-04",
      "techniques": [
        "OAK-T17.004",
        "OAK-T7.001",
        "OAK-T9.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-04-inverse-finance-twap.md"
    },
    {
      "id": "2022-04-inverse-finance",
      "file": "2022-04-inverse-finance.md",
      "title": "Inverse Finance recurring oracle exploits — Ethereum — 2022-04-02 and 2022-06-16",
      "date_prefix": "2022-04",
      "techniques": [
        "OAK-T7.001",
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-04-inverse-finance.md"
    },
    {
      "id": "2022-04-rari-fuse-twap-oracle-window-manipulation",
      "file": "2022-04-rari-fuse-twap-oracle-window-manipulation.md",
      "title": "Rari Fuse TWAP Oracle Window-Manipulation Lending Exploit — Ethereum — 2022-04-30",
      "date_prefix": "2022-04",
      "techniques": [
        "OAK-T17.004",
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-04-rari-fuse-twap-oracle-window-manipulation.md"
    },
    {
      "id": "2022-04-ronin-discord",
      "file": "2022-04-ronin-discord.md",
      "title": "Ronin Bridge Discord-impersonation followups — Axie Infinity / Ronin community — 2022-04 (cohort)",
      "date_prefix": "2022-04",
      "techniques": [
        "OAK-T11",
        "OAK-T15.005",
        "OAK-T4.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-04-ronin-discord.md"
    },
    {
      "id": "2022-04-saddle-finance",
      "file": "2022-04-saddle-finance.md",
      "title": "Saddle Finance virtual-price manipulation — Ethereum — 2022-04-30",
      "date_prefix": "2022-04",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-04-saddle-finance.md"
    },
    {
      "id": "2022-05-fortress-protocol-flash-loan-governance-attack",
      "file": "2022-05-fortress-protocol-flash-loan-governance-attack.md",
      "title": "Fortress Protocol flash-loan governance attack — BNB Chain — 2022-05-08",
      "date_prefix": "2022-05",
      "techniques": [
        "OAK-T16.001",
        "OAK-T9.002",
        "OAK-T9.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-05-fortress-protocol-flash-loan-governance-attack.md"
    },
    {
      "id": "2022-05-pixelmon-reveal",
      "file": "2022-05-pixelmon-reveal.md",
      "title": "Pixelmon NFT reveal-rug — Ethereum — 2022-02 mint, 2022-05 reveal",
      "date_prefix": "2022-05",
      "techniques": [
        "OAK-T12",
        "OAK-T17.001",
        "OAK-T3.003",
        "OAK-T5.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-05-pixelmon-reveal.md"
    },
    {
      "id": "2022-05-terra-luna-collapse",
      "file": "2022-05-terra-luna-collapse.md",
      "title": "Terra/Luna / UST algorithmic-stablecoin collapse — Terra — 2022-05-07 to 2022-05-13",
      "date_prefix": "2022-05",
      "techniques": [
        "OAK-T14.001",
        "OAK-T17",
        "OAK-T2.001",
        "OAK-T3.001",
        "OAK-T5.003",
        "OAK-T9.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-05-terra-luna-collapse.md"
    },
    {
      "id": "2022-06-harmony-horizon-bridge",
      "file": "2022-06-harmony-horizon-bridge.md",
      "title": "Harmony Horizon Bridge light-client verification economic-security gap — Ethereum / Harmony — 2022-06-23/24",
      "date_prefix": "2022-06",
      "techniques": [
        "OAK-T10.001",
        "OAK-T10.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-06-harmony-horizon-bridge.md"
    },
    {
      "id": "2022-06-harmony-horizon-economic-incentive-gap",
      "file": "2022-06-harmony-horizon-economic-incentive-gap.md",
      "title": "Harmony Horizon Bridge validator economic-incentive gap — Ethereum / BSC / Harmony — 2022-06-23/24",
      "date_prefix": "2022-06",
      "techniques": [
        "OAK-T10.001",
        "OAK-T10.005",
        "OAK-T10.007"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-06-harmony-horizon-economic-incentive-gap.md"
    },
    {
      "id": "2022-06-harmony-horizon",
      "file": "2022-06-harmony-horizon.md",
      "title": "Harmony Horizon Bridge — Ethereum ↔ Harmony — 2022-06-23/24",
      "date_prefix": "2022-06",
      "techniques": [
        "OAK-T10.001",
        "OAK-T7.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-06-harmony-horizon.md"
    },
    {
      "id": "2022-06-lido-steth-depeg",
      "file": "2022-06-lido-steth-depeg.md",
      "title": "Lido stETH depeg and Aave / Curve looped-leverage liquidation cascade — Ethereum L1 — 2022-05 to 2022-06",
      "date_prefix": "2022-06",
      "techniques": [
        "OAK-T14.001",
        "OAK-T14.003",
        "OAK-T14.003.001",
        "OAK-T17.002",
        "OAK-T9.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-06-lido-steth-depeg.md"
    },
    {
      "id": "2022-06-opensea-insider-trading",
      "file": "2022-06-opensea-insider-trading.md",
      "title": "OpenSea insider trading — Nate Chastain — Ethereum — 2021-09 to 2022-06",
      "date_prefix": "2022-06",
      "techniques": [
        "OAK-T12",
        "OAK-T6.001",
        "OAK-T9.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-06-opensea-insider-trading.md"
    },
    {
      "id": "2022-06-xcarnival-withdrawn-nft-collateral-order-reuse",
      "file": "2022-06-xcarnival-withdrawn-nft-collateral-order-reuse.md",
      "title": "XCarnival — the borrow path checked that a pledge order existed, never that the Ape was still in the vault, so one BAYC backed loan after loan — XCarnival (Ethereum) — 2022-06-26/27",
      "date_prefix": "2022-06",
      "techniques": [
        "OAK-T12.006",
        "OAK-T5.001",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-06-xcarnival-withdrawn-nft-collateral-order-reuse.md"
    },
    {
      "id": "2022-07-audius",
      "file": "2022-07-audius.md",
      "title": "Audius governance storage-collision attack — Ethereum — 2022-07-23",
      "date_prefix": "2022-07",
      "techniques": [
        "OAK-T16.005",
        "OAK-T7.001",
        "OAK-T9.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-07-audius.md"
    },
    {
      "id": "2022-07-crema-finance",
      "file": "2022-07-crema-finance.md",
      "title": "Crema Finance fake-tick-array exploit — Solana — 2022-07-02",
      "date_prefix": "2022-07",
      "techniques": [
        "OAK-T9.002",
        "OAK-T9.004"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-07-crema-finance.md"
    },
    {
      "id": "2022-07-li-fi-v1-diamond-facet-exploit",
      "file": "2022-07-li-fi-v1-diamond-facet-exploit.md",
      "title": "Li.Fi v1 diamond-facet vulnerability — EVM — 2022-07",
      "date_prefix": "2022-07",
      "techniques": [
        "OAK-T9.004",
        "OAK-T9.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-07-li-fi-v1-diamond-facet-exploit.md"
    },
    {
      "id": "2022-07-nirvana-finance",
      "file": "2022-07-nirvana-finance.md",
      "title": "Nirvana Finance flash-loan-driven price manipulation — Solana — 2022-07-28",
      "date_prefix": "2022-07",
      "techniques": [
        "OAK-T7",
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-07-nirvana-finance.md"
    },
    {
      "id": "2022-07-nomad-optimistic-verification-gap",
      "file": "2022-07-nomad-optimistic-verification-gap.md",
      "title": "Nomad optimistic bridge challenger-network gap — EVM — 2022 (architecture-review)",
      "date_prefix": "2022-07",
      "techniques": [
        "OAK-T10.002",
        "OAK-T10.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-07-nomad-optimistic-verification-gap.md"
    },
    {
      "id": "2022-07-omni-protocol-erc721-callback-double-reentrancy",
      "file": "2022-07-omni-protocol-erc721-callback-double-reentrancy.md",
      "title": "Omni Protocol — handing an NFT back with `safeTransferFrom` calls the borrower's code mid-transition, and two unguarded functions turned that callback into a double reentrancy — Omni Protocol (Ethereum) — 2022-07-10",
      "date_prefix": "2022-07",
      "techniques": [
        "OAK-T12.006",
        "OAK-T7.001",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-07-omni-protocol-erc721-callback-double-reentrancy.md"
    },
    {
      "id": "2022-07-premint-phishing",
      "file": "2022-07-premint-phishing.md",
      "title": "Premint NFT-allowlist platform front-end JavaScript injection — Ethereum — 2022-07-17",
      "date_prefix": "2022-07",
      "techniques": [
        "OAK-T12.002",
        "OAK-T4.002",
        "OAK-T4.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-07-premint-phishing.md"
    },
    {
      "id": "2022-08-curve-dns-hijack",
      "file": "2022-08-curve-dns-hijack.md",
      "title": "Curve Finance frontend DNS hijack — Ethereum — 2022-08",
      "date_prefix": "2022-08",
      "techniques": [
        "OAK-T15.004",
        "OAK-T4.002",
        "OAK-T6",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-08-curve-dns-hijack.md"
    },
    {
      "id": "2022-08-nomad-bridge",
      "file": "2022-08-nomad-bridge.md",
      "title": "Nomad Bridge — Ethereum / Moonbeam / Avalanche / Evmos — 2022-08-01",
      "date_prefix": "2022-08",
      "techniques": [
        "OAK-T10.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-08-nomad-bridge.md"
    },
    {
      "id": "2022-08-optifi",
      "file": "2022-08-optifi.md",
      "title": "OptiFi accidental program closure — Solana — 2022-08-29",
      "date_prefix": "2022-08",
      "techniques": [
        "OAK-T9.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-08-optifi.md"
    },
    {
      "id": "2022-08-slope-phantom",
      "file": "2022-08-slope-phantom.md",
      "title": "Slope Wallet (Solana) — 2022-08-02",
      "date_prefix": "2022-08",
      "techniques": [
        "OAK-T11.001",
        "OAK-T11.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-08-slope-phantom.md"
    },
    {
      "id": "2022-08-tornado-cash-ofac-sanctions",
      "file": "2022-08-tornado-cash-ofac-sanctions.md",
      "title": "Tornado Cash OFAC sanctions — trust-substrate shift via regulatory action — Ethereum — 2022-08-08",
      "date_prefix": "2022-08",
      "techniques": [
        "OAK-T14.005",
        "OAK-T6.007",
        "OAK-T7.009"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-08-tornado-cash-ofac-sanctions.md"
    },
    {
      "id": "2022-08-yuga-otherside",
      "file": "2022-08-yuga-otherside.md",
      "title": "Yuga Labs Otherside Discord-phishing wave — Ethereum + multi-chain — 2022-08-04",
      "date_prefix": "2022-08",
      "techniques": [
        "OAK-T11",
        "OAK-T15.005",
        "OAK-T4.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-08-yuga-otherside.md"
    },
    {
      "id": "2022-09-cryptofx-chavez",
      "file": "2022-09-cryptofx-chavez.md",
      "title": "CryptoFX / Mauricio Chavez fake-asset-manager Ponzi targeting Latino community — Houston, Texas + ten-state US footprint + two foreign countries — 2020-05 onward / SEC emergency action 2022-09",
      "date_prefix": "2022-09",
      "techniques": [
        "OAK-T11.005.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-09-cryptofx-chavez.md"
    },
    {
      "id": "2022-09-ethereum-pow-fork-replay-cohort",
      "file": "2022-09-ethereum-pow-fork-replay-cohort.md",
      "title": "Ethereum PoW fork cross-chain replay — Ethereum / ETHPoW — September 2022",
      "date_prefix": "2022-09",
      "techniques": [
        "OAK-T10",
        "OAK-T10.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-09-ethereum-pow-fork-replay-cohort.md"
    },
    {
      "id": "2022-09-snapshot-sybil-governance-cohort",
      "file": "2022-09-snapshot-sybil-governance-cohort.md",
      "title": "Snapshot.org off-chain voting Sybil-attack cohort — chain-agnostic — 2022–2025 (cohort)",
      "date_prefix": "2022-09",
      "techniques": [
        "OAK-T16.004",
        "OAK-T3.001",
        "OAK-T8.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-09-snapshot-sybil-governance-cohort.md"
    },
    {
      "id": "2022-09-wintermute-profanity-cohort",
      "file": "2022-09-wintermute-profanity-cohort.md",
      "title": "Profanity vanity-address cohort — Ethereum — 2022-09-15 to 2022-12 (cohort case)",
      "date_prefix": "2022-09",
      "techniques": [
        "OAK-T11",
        "OAK-T11.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-09-wintermute-profanity-cohort.md"
    },
    {
      "id": "2022-09-wintermute",
      "file": "2022-09-wintermute.md",
      "title": "Wintermute DeFi vault drain — Ethereum — 2022-09-20",
      "date_prefix": "2022-09",
      "techniques": [
        "OAK-T11",
        "OAK-T11.004",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-09-wintermute.md"
    },
    {
      "id": "2022-10-binance-bsc-bridge",
      "file": "2022-10-binance-bsc-bridge.md",
      "title": "BSC Token Hub (BNB Bridge) — Beacon Chain ↔ BSC — 2022-10-06",
      "date_prefix": "2022-10",
      "techniques": [
        "OAK-T10.002",
        "OAK-T10.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-10-binance-bsc-bridge.md"
    },
    {
      "id": "2022-10-mango-markets",
      "file": "2022-10-mango-markets.md",
      "title": "Mango Markets oracle manipulation — Solana — 2022-10-11",
      "date_prefix": "2022-10",
      "techniques": [
        "OAK-T16.002",
        "OAK-T17.001",
        "OAK-T5.005",
        "OAK-T8.001",
        "OAK-T9.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-10-mango-markets.md"
    },
    {
      "id": "2022-10-market-xyz-curve-lp-oracle-read-only-reentrancy",
      "file": "2022-10-market-xyz-curve-lp-oracle-read-only-reentrancy.md",
      "title": "Market.xyz — a lending market prices Curve LP collateral through `get_virtual_price()` and is drained by re-entering the pool's view during `remove_liquidity` — Market.xyz / QuickSwap (Polygon) — 2022-10-24",
      "date_prefix": "2022-10",
      "techniques": [
        "OAK-T9.002",
        "OAK-T9.010"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-10-market-xyz-curve-lp-oracle-read-only-reentrancy.md"
    },
    {
      "id": "2022-10-team-finance",
      "file": "2022-10-team-finance.md",
      "title": "Team Finance liquidity-locker `migrate()` exploit — Ethereum / BNB Chain — 2022-10-27",
      "date_prefix": "2022-10",
      "techniques": [
        "OAK-T2.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-10-team-finance.md"
    },
    {
      "id": "2022-10-transit-swap",
      "file": "2022-10-transit-swap.md",
      "title": "Transit Swap DEX aggregator exploit — Multi-chain (Ethereum, BNB Chain) — 2022-10-02",
      "date_prefix": "2022-10",
      "techniques": [
        "OAK-T4.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-10-transit-swap.md"
    },
    {
      "id": "2022-11-ftx-collapse",
      "file": "2022-11-ftx-collapse.md",
      "title": "FTX exchange collapse — multi-chain (CEX) — 2022-11-11 (Chapter 11 filing)",
      "date_prefix": "2022-11",
      "techniques": [
        "OAK-T11.005",
        "OAK-T5.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-11-ftx-collapse.md"
    },
    {
      "id": "2022-11-x2y2-looksrare-royalty-optional",
      "file": "2022-11-x2y2-looksrare-royalty-optional.md",
      "title": "X2Y2 + LooksRare royalty-optional shift — Ethereum — 2022-08 through 2023 (cohort case)",
      "date_prefix": "2022-11",
      "techniques": [
        "OAK-T12.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-11-x2y2-looksrare-royalty-optional.md"
    },
    {
      "id": "2022-12-ankr-abnbc-liquid-staking-exploit",
      "file": "2022-12-ankr-abnbc-liquid-staking-exploit.md",
      "title": "Ankr aBNBc Liquid Staking Token Exploit via Unlimited Mint — BNB Chain — 2022-12-02",
      "date_prefix": "2022-12",
      "techniques": [
        "OAK-T14.003",
        "OAK-T14.004",
        "OAK-T9.004"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2022-12-ankr-abnbc-liquid-staking-exploit.md"
    },
    {
      "id": "2022-12-ankr",
      "file": "2022-12-ankr.md",
      "title": "Ankr deployer-key compromise and malicious upgrade — BNB Chain — 2022-12-01",
      "date_prefix": "2022-12",
      "techniques": [
        "OAK-T11.002",
        "OAK-T5.003",
        "OAK-T9.004"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2022-12-ankr.md"
    },
    {
      "id": "2022-12-defrost-finance",
      "file": "2022-12-defrost-finance.md",
      "title": "Defrost Finance exit scam — Avalanche — 2022-12-23",
      "date_prefix": "2022-12",
      "techniques": [
        "OAK-T5.001",
        "OAK-T5.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-12-defrost-finance.md"
    },
    {
      "id": "2022-12-lastpass-vault-cohort",
      "file": "2022-12-lastpass-vault-cohort.md",
      "title": "LastPass encrypted-vault exfiltration → multi-year crypto-drain cohort — multi-chain — 2022-12 (breach) / 2023-2025 (drains)",
      "date_prefix": "2022-12",
      "techniques": [
        "OAK-T11.006",
        "OAK-T11.006.001",
        "OAK-T7.001",
        "OAK-T7.002"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2022-12-lastpass-vault-cohort.md"
    },
    {
      "id": "2022-2023-lido-steth-staking-phishing-cohort",
      "file": "2022-2023-lido-steth-staking-phishing-cohort.md",
      "title": "Lido stETH staking-interface phishing cohort — Ethereum — 2022-2023",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T3.005",
        "OAK-T4.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-2023-lido-steth-staking-phishing-cohort.md"
    },
    {
      "id": "2022-2024-android-google-drive-wallet-backup-cohort",
      "file": "2022-2024-android-google-drive-wallet-backup-cohort.md",
      "title": "Android Google-Drive Wallet-Backup Seed Exfiltration Cohort — 2022–2024",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T11.001",
        "OAK-T11.006.002",
        "OAK-T4.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-2024-android-google-drive-wallet-backup-cohort.md"
    },
    {
      "id": "2022-2024-black-basta-raas",
      "file": "2022-2024-black-basta-raas.md",
      "title": "Black Basta Ransomware-as-a-Service — 2022–2024",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T5.008",
        "OAK-T7.005",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-2024-black-basta-raas.md"
    },
    {
      "id": "2022-2024-flash-loan-governance-attack-cohort",
      "file": "2022-2024-flash-loan-governance-attack-cohort.md",
      "title": "Flash-Loan Governance Attack Cohort — 2022–2024 — Aggregate $200M+ Nominal, ~$190M+ Realised",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T16.001",
        "OAK-T16.006",
        "OAK-T9.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2024-flash-loan-governance-attack-cohort.md"
    },
    {
      "id": "2022-2024-snapshot-voting-exploitation-cohort",
      "file": "2022-2024-snapshot-voting-exploitation-cohort.md",
      "title": "Snapshot off-chain voting exploitation via flash-loaned and delegated voting power — Ethereum — 2022–2024",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T16.002",
        "OAK-T16.004",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-2024-snapshot-voting-exploitation-cohort.md"
    },
    {
      "id": "2022-2025-arbitrum-one-optimistic-bridge-validator-set-gap",
      "file": "2022-2025-arbitrum-one-optimistic-bridge-validator-set-gap.md",
      "title": "Arbitrum One optimistic bridge validator-set gap — Ethereum / Arbitrum One — 2022–2025 (architecture-review)",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T10.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-arbitrum-one-optimistic-bridge-validator-set-gap.md"
    },
    {
      "id": "2022-2025-coinbase-cbeth-structural-discount",
      "file": "2022-2025-coinbase-cbeth-structural-discount.md",
      "title": "Coinbase cbETH Structural Discount and Liquid Staking Token Pricing Surface — Ethereum — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T14.003",
        "OAK-T14.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-coinbase-cbeth-structural-discount.md"
    },
    {
      "id": "2022-2025-cosmos-validator-downtime-jailing-slashing-evasion",
      "file": "2022-2025-cosmos-validator-downtime-jailing-slashing-evasion.md",
      "title": "Cosmos-SDK Validator Downtime Jailing and Slashing-Evasion Patterns — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T14.001",
        "OAK-T14.006"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-cosmos-validator-downtime-jailing-slashing-evasion.md"
    },
    {
      "id": "2022-2025-cross-chain-lock-spoof-cohort",
      "file": "2022-2025-cross-chain-lock-spoof-cohort.md",
      "title": "Cross-chain locked-liquidity spoof cohort — multi-chain — 2022–2025 (cohort)",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T2.002",
        "OAK-T2.003",
        "OAK-T5.001",
        "OAK-T6.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-2025-cross-chain-lock-spoof-cohort.md"
    },
    {
      "id": "2022-2025-cross-chain-lock-spoof-named-cases",
      "file": "2022-2025-cross-chain-lock-spoof-named-cases.md",
      "title": "Cross-chain locked-liquidity spoof via split-chain lock-receipt claims — multi-chain — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T2.002",
        "OAK-T2.003",
        "OAK-T6"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-2025-cross-chain-lock-spoof-named-cases.md"
    },
    {
      "id": "2022-2025-cross-chain-locked-liquidity-and-token-metadata-spoofing-cohort",
      "file": "2022-2025-cross-chain-locked-liquidity-and-token-metadata-spoofing-cohort.md",
      "title": "Cross-Chain Locked-Liquidity and Token Metadata Spoofing Cohort — 2022–2025 — Aggregate $20M+",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T2.003",
        "OAK-T2.005",
        "OAK-T6.006"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-cross-chain-locked-liquidity-and-token-metadata-spoofing-cohort.md"
    },
    {
      "id": "2022-2025-cross-chain-replay-cohort",
      "file": "2022-2025-cross-chain-replay-cohort.md",
      "title": "Cross-chain replay vulnerability cohort — multi-chain — 2022–2025 (cohort)",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T10.002",
        "OAK-T10.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-cross-chain-replay-cohort.md"
    },
    {
      "id": "2022-2025-custody-infrastructure-compromise-cohort",
      "file": "2022-2025-custody-infrastructure-compromise-cohort.md",
      "title": "Custody Infrastructure Compromise Cohort — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T11.003",
        "OAK-T11.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-custody-infrastructure-compromise-cohort.md"
    },
    {
      "id": "2022-2025-dao-governance-exploitation-cohort",
      "file": "2022-2025-dao-governance-exploitation-cohort.md",
      "title": "DAO Governance Exploitation Cohort — 2022–2025 — Aggregate $30M+ Attempted, ~$8M Realised",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T16.003",
        "OAK-T16.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-dao-governance-exploitation-cohort.md"
    },
    {
      "id": "2022-2025-erc20-transferfrom-return-value-spoofing-cohort",
      "file": "2022-2025-erc20-transferfrom-return-value-spoofing-cohort.md",
      "title": "ERC-20 transferFrom return-value spoofing cohort — EVM — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T2.005",
        "OAK-T9.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-erc20-transferfrom-return-value-spoofing-cohort.md"
    },
    {
      "id": "2022-2025-ethereum-beacon-chain-inactivity-leak-griefing",
      "file": "2022-2025-ethereum-beacon-chain-inactivity-leak-griefing.md",
      "title": "Ethereum Beacon Chain Inactivity-Leak Griefing and Correlation-Penalty Economics — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T14.001",
        "OAK-T14.003",
        "OAK-T14.006"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-ethereum-beacon-chain-inactivity-leak-griefing.md"
    },
    {
      "id": "2022-2025-ethereum-block-builder-eof-centralization",
      "file": "2022-2025-ethereum-block-builder-eof-centralization.md",
      "title": "Ethereum Block Builder Exclusive Order-Flow Centralization and Censorship — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T14.002",
        "OAK-T14.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-ethereum-block-builder-eof-centralization.md"
    },
    {
      "id": "2022-2025-ethereum-validator-ddos-extortion-campaigns",
      "file": "2022-2025-ethereum-validator-ddos-extortion-campaigns.md",
      "title": "Ethereum Validator DDoS Extortion and Liveness-Fault Griefing Campaigns — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T14.006",
        "OAK-T5.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-ethereum-validator-ddos-extortion-campaigns.md"
    },
    {
      "id": "2022-2025-fake-browser-extension-phishing-cohort",
      "file": "2022-2025-fake-browser-extension-phishing-cohort.md",
      "title": "Fake browser-extension phishing cohort — cross-chain — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T11.007.003",
        "OAK-T4.001",
        "OAK-T4.004",
        "OAK-T4.005",
        "OAK-T4.010"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-2025-fake-browser-extension-phishing-cohort.md"
    },
    {
      "id": "2022-2025-mev-boost-relay-bid-withholding-auction-gaming",
      "file": "2022-2025-mev-boost-relay-bid-withholding-auction-gaming.md",
      "title": "MEV-Boost Relay Bid Withholding and Builder Auction Gaming — Ethereum L1 — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T14.002",
        "OAK-T14.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-mev-boost-relay-bid-withholding-auction-gaming.md"
    },
    {
      "id": "2022-2025-mev-boost-relay-operator-trust-surface",
      "file": "2022-2025-mev-boost-relay-operator-trust-surface.md",
      "title": "MEV-Boost Relay Operator Trust-Surface and MEV Theft Risk — Ethereum — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T14.002",
        "OAK-T14.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-mev-boost-relay-operator-trust-surface.md"
    },
    {
      "id": "2022-2025-nft-marketplace-wash-trading-and-royalty-bypass-infrastructure",
      "file": "2022-2025-nft-marketplace-wash-trading-and-royalty-bypass-infrastructure.md",
      "title": "NFT Marketplace Wash-Trading and Royalty-Bypass Infrastructure — 2022–2025 — Aggregate Revenue Loss in Hundreds of Millions",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T12.001",
        "OAK-T12.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-nft-marketplace-wash-trading-and-royalty-bypass-infrastructure.md"
    },
    {
      "id": "2022-2025-optimism-cross-chain-governance-relay-gap",
      "file": "2022-2025-optimism-cross-chain-governance-relay-gap.md",
      "title": "Optimism L1-to-L2 cross-chain governance relay gap — Ethereum / Optimism — 2022–2025 (architecture-review)",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T10.006",
        "OAK-T9.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-optimism-cross-chain-governance-relay-gap.md"
    },
    {
      "id": "2022-2025-optimistic-bridge-fraud-proof-cohort",
      "file": "2022-2025-optimistic-bridge-fraud-proof-cohort.md",
      "title": "Optimistic-bridge fraud-proof gap cohort — multi-chain — 2022–2025 (cohort)",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T10.002",
        "OAK-T10.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-optimistic-bridge-fraud-proof-cohort.md"
    },
    {
      "id": "2022-2025-seed-phrase-at-rest-exfiltration-cohort",
      "file": "2022-2025-seed-phrase-at-rest-exfiltration-cohort.md",
      "title": "Seed-Phrase At-Rest Exfiltration Cohort — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T11.006",
        "OAK-T11.006.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-seed-phrase-at-rest-exfiltration-cohort.md"
    },
    {
      "id": "2022-2025-smart-contract-architecture-exploit-cohort",
      "file": "2022-2025-smart-contract-architecture-exploit-cohort.md",
      "title": "Smart-Contract Architecture Exploit Cohort — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T9.008",
        "OAK-T9.009",
        "OAK-T9.010"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-smart-contract-architecture-exploit-cohort.md"
    },
    {
      "id": "2022-2025-social-engineering-entry-vector-cohort",
      "file": "2022-2025-social-engineering-entry-vector-cohort.md",
      "title": "Social-Engineering Entry-Vector Cohort — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T15.006",
        "OAK-T3.005",
        "OAK-T4.006"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-social-engineering-entry-vector-cohort.md"
    },
    {
      "id": "2022-2025-stablecoin-issuer-freeze-asymmetry-and-bridge-fraud-proof-gap-cohort",
      "file": "2022-2025-stablecoin-issuer-freeze-asymmetry-and-bridge-fraud-proof-gap-cohort.md",
      "title": "Stablecoin Issuer Freeze-Asymmetry and Optimistic Bridge Fraud-Proof Gap Cohort — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T10.004",
        "OAK-T7.008"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-stablecoin-issuer-freeze-asymmetry-and-bridge-fraud-proof-gap-cohort.md"
    },
    {
      "id": "2022-2025-tornado-cash-ofac-builder-censorship",
      "file": "2022-2025-tornado-cash-ofac-builder-censorship.md",
      "title": "OFAC-compliance builder censorship of Tornado Cash transactions — Ethereum — 2022–2025 (ongoing)",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T14.002",
        "OAK-T14.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-tornado-cash-ofac-builder-censorship.md"
    },
    {
      "id": "2022-2025-travel-rule-gap-exploitation",
      "file": "2022-2025-travel-rule-gap-exploitation.md",
      "title": "Travel Rule Gap Exploitation — Sub-Threshold Structuring and VASP-Avoidant Routing — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T7.002",
        "OAK-T7.005",
        "OAK-T7.010"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2022-2025-travel-rule-gap-exploitation.md"
    },
    {
      "id": "2022-2025-validator-liveness-fault-griefing-cohort",
      "file": "2022-2025-validator-liveness-fault-griefing-cohort.md",
      "title": "Validator liveness-fault griefing cohort — Ethereum L1 (primary), Solana, Cosmos — 2022–2025",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T14.001",
        "OAK-T14.005",
        "OAK-T14.006"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2022-2025-validator-liveness-fault-griefing-cohort.md"
    },
    {
      "id": "2022-2026-circle-usdc-compliance-failures",
      "file": "2022-2026-circle-usdc-compliance-failures.md",
      "title": "Circle USDC — $420M+ Compliance Failures / Stablecoin Issuer Inaction — 2022-2026",
      "date_prefix": "2022-20",
      "techniques": [
        "OAK-T7",
        "OAK-T7.008"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-2026-circle-usdc-compliance-failures.md"
    },
    {
      "id": "2022-hydra-marketplace-german-server-seizure",
      "file": "2022-hydra-marketplace-german-server-seizure.md",
      "title": "Hydra Marketplace German server-seizure takedown — 2022",
      "date_prefix": "2022",
      "techniques": [
        "OAK-T7.001",
        "OAK-T8.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-hydra-marketplace-german-server-seizure.md"
    },
    {
      "id": "2022-post-tornado-cash-usdc-usdt-freeze-asymmetry",
      "file": "2022-post-tornado-cash-usdc-usdt-freeze-asymmetry.md",
      "title": "Post-Tornado-Cash USDC/USDT freeze-policy asymmetry laundering — 2022",
      "date_prefix": "2022",
      "techniques": [
        "OAK-T7.008"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2022-post-tornado-cash-usdc-usdt-freeze-asymmetry.md"
    },
    {
      "id": "2023-01-ledger-donjon-side-channel",
      "file": "2023-01-ledger-donjon-side-channel.md",
      "title": "Ledger Donjon side-channel seed-extraction research — hardware — 2023",
      "date_prefix": "2023-01",
      "techniques": [
        "OAK-T11.007.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-01-ledger-donjon-side-channel.md"
    },
    {
      "id": "2023-01-magic-eden-y00ts",
      "file": "2023-01-magic-eden-y00ts.md",
      "title": "Magic Eden y00ts indexer-bug counterfeit-listing exploit — Solana — 2023-01-04",
      "date_prefix": "2023-01",
      "techniques": [
        "OAK-T12.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-01-magic-eden-y00ts.md"
    },
    {
      "id": "2023-02-blur-airdrop-wash-cohort",
      "file": "2023-02-blur-airdrop-wash-cohort.md",
      "title": "Blur airdrop incentive-wash cohort — Ethereum — 2022-10-19 through 2024 (cohort case)",
      "date_prefix": "2023-02",
      "techniques": [
        "OAK-T12.001",
        "OAK-T3.002",
        "OAK-T7.004"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2023-02-blur-airdrop-wash-cohort.md"
    },
    {
      "id": "2023-02-bonqdao",
      "file": "2023-02-bonqdao.md",
      "title": "BonqDAO Tellor oracle manipulation — Polygon — 2023-02-01",
      "date_prefix": "2023-02",
      "techniques": [
        "OAK-T17.002",
        "OAK-T7.001",
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-02-bonqdao.md"
    },
    {
      "id": "2023-02-hopefinance",
      "file": "2023-02-hopefinance.md",
      "title": "Hope Finance router-rerouting rug pull — Arbitrum — 2023-02-21",
      "date_prefix": "2023-02",
      "techniques": [
        "OAK-T1.003",
        "OAK-T5.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-02-hopefinance.md"
    },
    {
      "id": "2023-02-jaredfromsubway-mev",
      "file": "2023-02-jaredfromsubway-mev.md",
      "title": "`jaredfromsubway.eth` sandwich-MEV operator — Ethereum — operating since 2023-02-27",
      "date_prefix": "2023-02",
      "techniques": [
        "OAK-T5.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-02-jaredfromsubway-mev.md"
    },
    {
      "id": "2023-02-metabirkins-hermes-judgment",
      "file": "2023-02-metabirkins-hermes-judgment.md",
      "title": "MetaBirkins (Hermès vs Mason Rothschild) — Ethereum + civil-court judgment — minted 2021-12; verdict 2023-02-08",
      "date_prefix": "2023-02",
      "techniques": [
        "OAK-T12.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-02-metabirkins-hermes-judgment.md"
    },
    {
      "id": "2023-02-platypus",
      "file": "2023-02-platypus.md",
      "title": "Platypus Finance emergency-withdrawal logic flaw — Avalanche — 2023-02-16",
      "date_prefix": "2023-02",
      "techniques": [
        "OAK-T9.002",
        "OAK-T9.004"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-02-platypus.md"
    },
    {
      "id": "2023-02-yearn-v2",
      "file": "2023-02-yearn-v2.md",
      "title": "Yearn iearnUSDT v1 deprecated-vault misconfiguration — Ethereum — 2023-02-02",
      "date_prefix": "2023-02",
      "techniques": [
        "OAK-T7.001",
        "OAK-T9.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-02-yearn-v2.md"
    },
    {
      "id": "2023-03-euler-finance",
      "file": "2023-03-euler-finance.md",
      "title": "Euler Finance lending exploit — Ethereum — 2023-03-13",
      "date_prefix": "2023-03",
      "techniques": [
        "OAK-T9.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-03-euler-finance.md"
    },
    {
      "id": "2023-03-paraspace",
      "file": "2023-03-paraspace.md",
      "title": "ParaSpace whitehat rescue by BlockSec — an attacker inflates cAPE collateral value via a rebasingIndex manipulation, fails on gas, and BlockSec redeploys the attack to rescue the funds first — Ethereum — 2023-03-17",
      "date_prefix": "2023-03",
      "techniques": [
        "OAK-T5.004",
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-03-paraspace.md"
    },
    {
      "id": "2023-03-rocket-pool-validator-slashing",
      "file": "2023-03-rocket-pool-validator-slashing.md",
      "title": "Rocket Pool node operator slashing — Ethereum — 2023-03",
      "date_prefix": "2023-03",
      "techniques": [
        "OAK-T14.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-03-rocket-pool-validator-slashing.md"
    },
    {
      "id": "2023-04-allbridge",
      "file": "2023-04-allbridge.md",
      "title": "Allbridge stable-pool virtual-price manipulation — BNB Chain — 2023-04-01",
      "date_prefix": "2023-04",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-04-allbridge.md"
    },
    {
      "id": "2023-04-arbitrum-governance-bypass",
      "file": "2023-04-arbitrum-governance-bypass.md",
      "title": "Arbitrum Foundation governance bypass and treasury transfer — Ethereum — 2023-03/04",
      "date_prefix": "2023-04",
      "techniques": [
        "OAK-T16.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-04-arbitrum-governance-bypass.md"
    },
    {
      "id": "2023-04-cross-chain-bridge-signature-replay-cohort",
      "file": "2023-04-cross-chain-bridge-signature-replay-cohort.md",
      "title": "Cross-chain bridge signature replay across shared-validator-set instances — multi-chain — 2022–2024",
      "date_prefix": "2023-04",
      "techniques": [
        "OAK-T10.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-04-cross-chain-bridge-signature-replay-cohort.md"
    },
    {
      "id": "2023-04-hundred-finance",
      "file": "2023-04-hundred-finance.md",
      "title": "Hundred Finance empty-market rounding-error exploit — Gnosis Chain — 2023-04-15",
      "date_prefix": "2023-04",
      "techniques": [
        "OAK-T7.001",
        "OAK-T9.002",
        "OAK-T9.005",
        "OAK-T9.007",
        "OAK-T9.011"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-04-hundred-finance.md"
    },
    {
      "id": "2023-04-mev-boost-equivocation",
      "file": "2023-04-mev-boost-equivocation.md",
      "title": "MEV-Boost relay equivocation / unbundling — Ethereum mainnet — 2023-04-03",
      "date_prefix": "2023-04",
      "techniques": [
        "OAK-T14.002",
        "OAK-T5.004",
        "OAK-T7"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-04-mev-boost-equivocation.md"
    },
    {
      "id": "2023-04-optimism-goerli-cross-chain-replay-incident",
      "file": "2023-04-optimism-goerli-cross-chain-replay-incident.md",
      "title": "Optimism Goerli Testnet Governance Replay — Optimism — 2023-04",
      "date_prefix": "2023-04",
      "techniques": [
        "OAK-T10.002",
        "OAK-T10.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-04-optimism-goerli-cross-chain-replay-incident.md"
    },
    {
      "id": "2023-04-paribus-diamond-facet-exploit",
      "file": "2023-04-paribus-diamond-facet-exploit.md",
      "title": "Paribus diamond-facet exploit — EVM — 2023-04",
      "date_prefix": "2023-04",
      "techniques": [
        "OAK-T9.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-04-paribus-diamond-facet-exploit.md"
    },
    {
      "id": "2023-04-sentiment",
      "file": "2023-04-sentiment.md",
      "title": "Sentiment Protocol read-only reentrancy via Balancer LP integration — Arbitrum — 2023-04-04",
      "date_prefix": "2023-04",
      "techniques": [
        "OAK-T9.002",
        "OAK-T9.005",
        "OAK-T9.010"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-04-sentiment.md"
    },
    {
      "id": "2023-05-ethereum-finality-loss",
      "file": "2023-05-ethereum-finality-loss.md",
      "title": "Ethereum Beacon Chain finality loss event — Ethereum — 2023-05-11 to 2023-05-12",
      "date_prefix": "2023-05",
      "techniques": [
        "OAK-T14.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-05-ethereum-finality-loss.md"
    },
    {
      "id": "2023-05-ledger-recover-trust-substrate-shift",
      "file": "2023-05-ledger-recover-trust-substrate-shift.md",
      "title": "Ledger Recover seed-recovery service trust-substrate-shift event — Ledger hardware-wallet ecosystem — 2023-05-16",
      "date_prefix": "2023-05",
      "techniques": [
        "OAK-T11",
        "OAK-T6",
        "OAK-T6.007"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-05-ledger-recover-trust-substrate-shift.md"
    },
    {
      "id": "2023-05-mango-markets-orderbook-spoofing",
      "file": "2023-05-mango-markets-orderbook-spoofing.md",
      "title": "Mango Markets orderbook spoofing via fake-liquidity deployment — Solana — 2023-05 to 2023-08",
      "date_prefix": "2023-05",
      "techniques": [
        "OAK-T17.001",
        "OAK-T17.003",
        "OAK-T8.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-05-mango-markets-orderbook-spoofing.md"
    },
    {
      "id": "2023-05-sudoswap-wash-pools",
      "file": "2023-05-sudoswap-wash-pools.md",
      "title": "Sudoswap wash-trade laundering pools — Ethereum — 2023-05 to 2023-10",
      "date_prefix": "2023-05",
      "techniques": [
        "OAK-T12.002",
        "OAK-T7.001",
        "OAK-T7.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-05-sudoswap-wash-pools.md"
    },
    {
      "id": "2023-05-tornado-cash-dao-snapshot-attack",
      "file": "2023-05-tornado-cash-dao-snapshot-attack.md",
      "title": "Tornado Cash DAO Snapshot off-chain voting exploitation via governance-token Sybil deployment — chain-agnostic — 2023-05",
      "date_prefix": "2023-05",
      "techniques": [
        "OAK-T16.002",
        "OAK-T16.004",
        "OAK-T3.001",
        "OAK-T8.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-05-tornado-cash-dao-snapshot-attack.md"
    },
    {
      "id": "2023-05-tornado-cash-governance",
      "file": "2023-05-tornado-cash-governance.md",
      "title": "Tornado Cash governance attack — Ethereum — 2023-05-20",
      "date_prefix": "2023-05",
      "techniques": [
        "OAK-T16.005",
        "OAK-T9.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-05-tornado-cash-governance.md"
    },
    {
      "id": "2023-06-atlantis-loans",
      "file": "2023-06-atlantis-loans.md",
      "title": "Atlantis Loans audit-bytecode-mismatch exploit — BNB Chain — 2023-06-10",
      "date_prefix": "2023-06",
      "techniques": [
        "OAK-T6.003",
        "OAK-T7.003",
        "OAK-T9.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-06-atlantis-loans.md"
    },
    {
      "id": "2023-06-atomic-wallet",
      "file": "2023-06-atomic-wallet.md",
      "title": "Atomic Wallet — multi-chain — 2023-06-03",
      "date_prefix": "2023-06",
      "techniques": [
        "OAK-T11.002",
        "OAK-T15.002",
        "OAK-T4.001",
        "OAK-T7.001",
        "OAK-T7.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-06-atomic-wallet.md"
    },
    {
      "id": "2023-06-chibi-finance-onlygov-arbitrum",
      "file": "2023-06-chibi-finance-onlygov-arbitrum.md",
      "title": "Chibi Finance `panic` / `onlyGov` residual-authority exit-scam — Arbitrum — 2023-06-27",
      "date_prefix": "2023-06",
      "techniques": [
        "OAK-T1.003",
        "OAK-T2.001",
        "OAK-T5.001",
        "OAK-T6.001",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-06-chibi-finance-onlygov-arbitrum.md"
    },
    {
      "id": "2023-06-moveit-clop-campaign",
      "file": "2023-06-moveit-clop-campaign.md",
      "title": "MOVEit Transfer mass-extortion campaign — Cl0p — 2023-05-27 onward",
      "date_prefix": "2023-06",
      "techniques": [
        "OAK-T5.008",
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-06-moveit-clop-campaign.md"
    },
    {
      "id": "2023-07-alphapo",
      "file": "2023-07-alphapo.md",
      "title": "Alphapo payment-processor hot-wallet compromise — Multi-chain (BTC, ETH, TRON) — 2023-07-23",
      "date_prefix": "2023-07",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.003"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2023-07-alphapo.md"
    },
    {
      "id": "2023-07-curve-finance-freeze-coordination",
      "file": "2023-07-curve-finance-freeze-coordination.md",
      "title": "Curve Finance Exploit Freeze Coordination — Multi-Exchange Compliance Response — 2023-07",
      "date_prefix": "2023-07",
      "techniques": [
        "OAK-T7.002",
        "OAK-T9.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-07-curve-finance-freeze-coordination.md"
    },
    {
      "id": "2023-07-curve-vyper",
      "file": "2023-07-curve-vyper.md",
      "title": "Curve Finance Vyper compiler-level reentrancy — Ethereum — 2023-07-30",
      "date_prefix": "2023-07",
      "techniques": [
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-07-curve-vyper.md"
    },
    {
      "id": "2023-07-italian-gov-email-twitter-legal-portal",
      "file": "2023-07-italian-gov-email-twitter-legal-portal.md",
      "title": "Italian Government Email Compromise — Twitter Legal Request Portal Hijack — 2023-07",
      "date_prefix": "2023-07",
      "techniques": [],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-07-italian-gov-email-twitter-legal-portal.md"
    },
    {
      "id": "2023-07-multichain-mpc-bridge-verification-model-collapse",
      "file": "2023-07-multichain-mpc-bridge-verification-model-collapse.md",
      "title": "Multichain MPC bridge verification-model collapse — multi-chain — 2023-07-06/07",
      "date_prefix": "2023-07",
      "techniques": [
        "OAK-T10.001",
        "OAK-T10.005",
        "OAK-T10.007"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-07-multichain-mpc-bridge-verification-model-collapse.md"
    },
    {
      "id": "2023-07-multichain",
      "file": "2023-07-multichain.md",
      "title": "Multichain — cross-chain bridge protocol — 2023-07-06",
      "date_prefix": "2023-07",
      "techniques": [
        "OAK-T10.001",
        "OAK-T7.001",
        "OAK-T7.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-07-multichain.md"
    },
    {
      "id": "2023-08-balancer-v2",
      "file": "2023-08-balancer-v2.md",
      "title": "Balancer V2 Boosted Pools exploitation — Ethereum + multi-chain — 2023-08-22",
      "date_prefix": "2023-08",
      "techniques": [
        "OAK-T9.002",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-08-balancer-v2.md"
    },
    {
      "id": "2023-08-cypher",
      "file": "2023-08-cypher.md",
      "title": "Cypher Protocol sub-account isolation flaw — Solana — 2023-08-07",
      "date_prefix": "2023-08",
      "techniques": [
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-08-cypher.md"
    },
    {
      "id": "2023-08-exactly-protocol",
      "file": "2023-08-exactly-protocol.md",
      "title": "Exactly Protocol cross-chain debt-ceiling bypass — Optimism — 2023-08-18",
      "date_prefix": "2023-08",
      "techniques": [
        "OAK-T10.002",
        "OAK-T7.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-08-exactly-protocol.md"
    },
    {
      "id": "2023-08-exactly-reinitialization",
      "file": "2023-08-exactly-reinitialization.md",
      "title": "Exactly Protocol cross-contract reinitialization exploit — Optimism — 2023-08-18",
      "date_prefix": "2023-08",
      "techniques": [
        "OAK-T9.004",
        "OAK-T9.009"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-08-exactly-reinitialization.md"
    },
    {
      "id": "2023-08-magnate-finance-base-deployer-cluster",
      "file": "2023-08-magnate-finance-base-deployer-cluster.md",
      "title": "Magnate Finance / Solfire / Kokomo deployer-cluster exit-scam cohort — Solana / BNB Chain / Base — 2022-01 → 2023-08",
      "date_prefix": "2023-08",
      "techniques": [
        "OAK-T1.003",
        "OAK-T2.001",
        "OAK-T5.001",
        "OAK-T9.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-08-magnate-finance-base-deployer-cluster.md"
    },
    {
      "id": "2023-08-milk-sad-libbitcoin-bx-mersenne-twister-entropy-collapse",
      "file": "2023-08-milk-sad-libbitcoin-bx-mersenne-twister-entropy-collapse.md",
      "title": "Milk Sad — `bx seed` documents 128–256 bits of entropy and delivers 32, because Mersenne Twister is seeded on the system clock: same second, same \"random\" wallet — Libbitcoin Explorer (CVE-2023-39910) — theft 2023-07-12, disclosed 2023-08-08",
      "date_prefix": "2023-08",
      "techniques": [
        "OAK-T11.004",
        "OAK-T5.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-08-milk-sad-libbitcoin-bx-mersenne-twister-entropy-collapse.md"
    },
    {
      "id": "2023-08-opensea-operator-filter-sunset",
      "file": "2023-08-opensea-operator-filter-sunset.md",
      "title": "OpenSea Operator Filter Registry sunset — Ethereum + multi-chain — 2023-08-17 (announcement) to 2024-02-29 (grace-period end)",
      "date_prefix": "2023-08",
      "techniques": [
        "OAK-T12.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-08-opensea-operator-filter-sunset.md"
    },
    {
      "id": "2023-08-steadefi",
      "file": "2023-08-steadefi.md",
      "title": "Steadefi deployer-key compromise and malicious-upgrade extraction — Arbitrum — 2023-08-07",
      "date_prefix": "2023-08",
      "techniques": [
        "OAK-T11.002",
        "OAK-T7.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-08-steadefi.md"
    },
    {
      "id": "2023-08-verified-org-phishing-account-farms",
      "file": "2023-08-verified-org-phishing-account-farms.md",
      "title": "Verified Organization Phishing — Fake Verified Org Account Farms on X/Twitter — 2023-08",
      "date_prefix": "2023-08",
      "techniques": [
        "OAK-T15.006"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-08-verified-org-phishing-account-farms.md"
    },
    {
      "id": "2023-08-zunami",
      "file": "2023-08-zunami.md",
      "title": "Zunami Protocol price-manipulation drain via Curve pool — Ethereum — 2023-08-13",
      "date_prefix": "2023-08",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-08-zunami.md"
    },
    {
      "id": "2023-09-caesars-entertainment",
      "file": "2023-09-caesars-entertainment.md",
      "title": "Caesars Entertainment ransom payment — ALPHV / Scattered Spider — 2023-09",
      "date_prefix": "2023-09",
      "techniques": [
        "OAK-T5.008",
        "OAK-T7.002",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-09-caesars-entertainment.md"
    },
    {
      "id": "2023-09-caesars-ransomware-12m-seizure",
      "file": "2023-09-caesars-ransomware-12m-seizure.md",
      "title": "Caesar's Ransomware — $12M Seized / Multi-Agency Recovery — 2023-09",
      "date_prefix": "2023-09",
      "techniques": [
        "OAK-T5.008"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-09-caesars-ransomware-12m-seizure.md"
    },
    {
      "id": "2023-09-coinex",
      "file": "2023-09-coinex.md",
      "title": "CoinEx exchange hot-wallet compromise — Multi-chain (ETH, TRON, Polygon) — 2023-09-12",
      "date_prefix": "2023-09",
      "techniques": [
        "OAK-T11.001",
        "OAK-T7.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2023-09-coinex.md"
    },
    {
      "id": "2023-09-gitcoin-dao-snapshot-governance-attack",
      "file": "2023-09-gitcoin-dao-snapshot-governance-attack.md",
      "title": "Gitcoin DAO Snapshot Off-Chain Governance Attack — Ethereum — 2023-09",
      "date_prefix": "2023-09",
      "techniques": [
        "OAK-T16.002",
        "OAK-T16.004",
        "OAK-T3.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-09-gitcoin-dao-snapshot-governance-attack.md"
    },
    {
      "id": "2023-09-jpex-hong-kong",
      "file": "2023-09-jpex-hong-kong.md",
      "title": "JPEX Hong Kong unlicensed-exchange fraud — Hong Kong — 2023-09-13 onward",
      "date_prefix": "2023-09",
      "techniques": [
        "OAK-T11",
        "OAK-T11.005",
        "OAK-T11.005.001",
        "OAK-T15"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-09-jpex-hong-kong.md"
    },
    {
      "id": "2023-09-mgm-resorts",
      "file": "2023-09-mgm-resorts.md",
      "title": "MGM Resorts ransomware intrusion — ALPHV / Scattered Spider — 2023-09-10",
      "date_prefix": "2023-09",
      "techniques": [
        "OAK-T5.008",
        "OAK-T8.001",
        "OAK-T8.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-09-mgm-resorts.md"
    },
    {
      "id": "2023-09-mixin-network",
      "file": "2023-09-mixin-network.md",
      "title": "Mixin Network — multi-chain — 2023-09-23",
      "date_prefix": "2023-09",
      "techniques": [
        "OAK-T11.001",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-09-mixin-network.md"
    },
    {
      "id": "2023-09-nouns-dao-fork-arbitrage",
      "file": "2023-09-nouns-dao-fork-arbitrage.md",
      "title": "Nouns DAO rage-quit fork arbitrage — Ethereum — 2023-09-15",
      "date_prefix": "2023-09",
      "techniques": [
        "OAK-T16.002",
        "OAK-T5.005",
        "OAK-T9.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-09-nouns-dao-fork-arbitrage.md"
    },
    {
      "id": "2023-09-stake-com",
      "file": "2023-09-stake-com.md",
      "title": "Stake.com hot-wallet theft — multi-chain — 2023-09-04",
      "date_prefix": "2023-09",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-09-stake-com.md"
    },
    {
      "id": "2023-09-stargate-layerzero-governance-relay-multisig",
      "file": "2023-09-stargate-layerzero-governance-relay-multisig.md",
      "title": "Stargate / LayerZero cross-chain governance relay multisig configuration — bridge parameter update relay path — multi-chain — 2023–2024",
      "date_prefix": "2023-09",
      "techniques": [
        "OAK-T10.006"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-09-stargate-layerzero-governance-relay-multisig.md"
    },
    {
      "id": "2023-10-lastpass-breach-crypto-drain",
      "file": "2023-10-lastpass-breach-crypto-drain.md",
      "title": "LastPass Breach → Crypto Drain — Multi-Victim Seed Phrase Exposure — 2023-10",
      "date_prefix": "2023-10",
      "techniques": [
        "OAK-T11.006",
        "OAK-T11.006.001",
        "OAK-T5",
        "OAK-T6"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-10-lastpass-breach-crypto-drain.md"
    },
    {
      "id": "2023-11-dydx-sushi-yfi-manipulation",
      "file": "2023-11-dydx-sushi-yfi-manipulation.md",
      "title": "dYdX V3 SUSHI/YFI targeted market manipulation and insurance-fund drain — dYdX V3 (StarkEx L2) — 2023-10-29 to 2023-11-18",
      "date_prefix": "2023-11",
      "techniques": [
        "OAK-T17.001",
        "OAK-T17.002",
        "OAK-T6",
        "OAK-T8.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-11-dydx-sushi-yfi-manipulation.md"
    },
    {
      "id": "2023-11-htx-heco-bridge",
      "file": "2023-11-htx-heco-bridge.md",
      "title": "HTX hot wallet + HECO Bridge — Ethereum ↔ HECO — 2023-11-22",
      "date_prefix": "2023-11",
      "techniques": [
        "OAK-T10.001",
        "OAK-T11",
        "OAK-T7.001",
        "OAK-T7.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-11-htx-heco-bridge.md"
    },
    {
      "id": "2023-11-icbc-financial-services",
      "file": "2023-11-icbc-financial-services.md",
      "title": "ICBC Financial Services LockBit intrusion — U.S. Treasury market disruption — 2023-11-09",
      "date_prefix": "2023-11",
      "techniques": [
        "OAK-T7.002",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-11-icbc-financial-services.md"
    },
    {
      "id": "2023-11-kyberswap",
      "file": "2023-11-kyberswap.md",
      "title": "KyberSwap Elastic tick-state-manipulation exploit — multi-chain — 2023-11-22",
      "date_prefix": "2023-11",
      "techniques": [
        "OAK-T8",
        "OAK-T9.002",
        "OAK-T9.004",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-11-kyberswap.md"
    },
    {
      "id": "2023-11-poloniex",
      "file": "2023-11-poloniex.md",
      "title": "Poloniex hot-wallet drain — multi-chain — 2023-11-10",
      "date_prefix": "2023-11",
      "techniques": [
        "OAK-T11.011",
        "OAK-T15.003",
        "OAK-T4.001",
        "OAK-T7.003"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2023-11-poloniex.md"
    },
    {
      "id": "2023-11-pulsechain-fake-audit",
      "file": "2023-11-pulsechain-fake-audit.md",
      "title": "PulseChain ecosystem fake-audit-claim token launches — PulseChain — 2023-11 to 2024-02",
      "date_prefix": "2023-11",
      "techniques": [
        "OAK-T2.001",
        "OAK-T5.001",
        "OAK-T6.002",
        "OAK-T6.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-11-pulsechain-fake-audit.md"
    },
    {
      "id": "2023-11-safemoon-charges",
      "file": "2023-11-safemoon-charges.md",
      "title": "SafeMoon (SFM) — BNB Chain — federal action 2023-11-01",
      "date_prefix": "2023-11",
      "techniques": [
        "OAK-T1.001",
        "OAK-T2.002",
        "OAK-T3.002",
        "OAK-T3.003",
        "OAK-T5.005",
        "OAK-T6"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-11-safemoon-charges.md"
    },
    {
      "id": "2023-11-snowdog-dao-avalanche-cross-chain-lock-spoof",
      "file": "2023-11-snowdog-dao-avalanche-cross-chain-lock-spoof.md",
      "title": "Snowdog DAO cross-chain locked-liquidity spoof — Avalanche / Ethereum — 2023-11 to 2023-12",
      "date_prefix": "2023-11",
      "techniques": [
        "OAK-T2.002",
        "OAK-T2.003",
        "OAK-T6"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-11-snowdog-dao-avalanche-cross-chain-lock-spoof.md"
    },
    {
      "id": "2023-11-solana-jito-relayer-eclipse-griefing",
      "file": "2023-11-solana-jito-relayer-eclipse-griefing.md",
      "title": "Solana Jito relayer eclipse griefing — Solana — November 2023",
      "date_prefix": "2023-11",
      "techniques": [
        "OAK-T14.001",
        "OAK-T14.006"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-11-solana-jito-relayer-eclipse-griefing.md"
    },
    {
      "id": "2023-12-galxe-dns",
      "file": "2023-12-galxe-dns.md",
      "title": "Galxe frontend DNS hijack pair — Ethereum / multi-chain — 2023-10-06 + 2023-12",
      "date_prefix": "2023-12",
      "techniques": [
        "OAK-T1.003",
        "OAK-T15.004",
        "OAK-T4.005",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-12-galxe-dns.md"
    },
    {
      "id": "2023-12-ledger-connect-kit-library-supply-chain-compromise",
      "file": "2023-12-ledger-connect-kit-library-supply-chain-compromise.md",
      "title": "Ledger Connect Kit Library Supply-Chain Compromise — multi-chain (EVM dApps) — 2023-12-14",
      "date_prefix": "2023-12",
      "techniques": [
        "OAK-T11.006",
        "OAK-T15.002",
        "OAK-T4.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-12-ledger-connect-kit-library-supply-chain-compromise.md"
    },
    {
      "id": "2023-12-ledger-connect-kit",
      "file": "2023-12-ledger-connect-kit.md",
      "title": "Ledger Connect Kit npm supply-chain compromise — multi-chain (EVM) — 2023-12-14",
      "date_prefix": "2023-12",
      "techniques": [
        "OAK-T1.003",
        "OAK-T11.002",
        "OAK-T15.002",
        "OAK-T15.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-12-ledger-connect-kit.md"
    },
    {
      "id": "2023-12-orbit-chain-bridge-exploit",
      "file": "2023-12-orbit-chain-bridge-exploit.md",
      "title": "Orbit Chain $81M Cross-Chain Bridge Exploit — 2023-12",
      "date_prefix": "2023-12",
      "techniques": [
        "OAK-T10.001",
        "OAK-T10.002",
        "OAK-T7.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-12-orbit-chain-bridge-exploit.md"
    },
    {
      "id": "2023-12-tellor-trb-manipulation",
      "file": "2023-12-tellor-trb-manipulation.md",
      "title": "Tellor (TRB) spot-perpetual manipulation and liquidation cascade — Ethereum / CEX — 2023-12-31",
      "date_prefix": "2023-12",
      "techniques": [
        "OAK-T17.001",
        "OAK-T17.002",
        "OAK-T8.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-12-tellor-trb-manipulation.md"
    },
    {
      "id": "2023-2024-argent-smart-wallet-escape-guardian-vulnerability",
      "file": "2023-2024-argent-smart-wallet-escape-guardian-vulnerability.md",
      "title": "Argent Smart Wallet Escape-Guardian Recovery-Flow Exploitation — 2023–2024 — $0 (patched)",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T13.003",
        "OAK-T15"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-2024-argent-smart-wallet-escape-guardian-vulnerability.md"
    },
    {
      "id": "2023-2024-balancer-vebal-delegation-takeover",
      "file": "2023-2024-balancer-vebal-delegation-takeover.md",
      "title": "Balancer veBAL delegation-cluster vote takeover — Ethereum — 2023–2024",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T16.001",
        "OAK-T16.003",
        "OAK-T9.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-2024-balancer-vebal-delegation-takeover.md"
    },
    {
      "id": "2023-2024-counterfeit-token-dust-attack-lure-cohort",
      "file": "2023-2024-counterfeit-token-dust-attack-lure-cohort.md",
      "title": "Counterfeit-token dust-attack-lure cohort — EVM — 2022–2024 (cohort)",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T4.003",
        "OAK-T4.004",
        "OAK-T6.006"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-2024-counterfeit-token-dust-attack-lure-cohort.md"
    },
    {
      "id": "2023-2024-dao-proposal-snowballing-cohort",
      "file": "2023-2024-dao-proposal-snowballing-cohort.md",
      "title": "DAO governance proposal-snowballing cohort — multi-proposal submission to overwhelm voter attention and divide quorum — multi-chain — 2023–2024",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T16.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-2024-dao-proposal-snowballing-cohort.md"
    },
    {
      "id": "2023-2024-erc4337-bundler-mev-cohort",
      "file": "2023-2024-erc4337-bundler-mev-cohort.md",
      "title": "ERC-4337 bundler MEV extraction cohort — Ethereum / EVM L2s — 2023–2025 (cohort)",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T13.002",
        "OAK-T5.004"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-2024-erc4337-bundler-mev-cohort.md"
    },
    {
      "id": "2023-2024-erc4337-bundler-mev-extraction-cohort",
      "file": "2023-2024-erc4337-bundler-mev-extraction-cohort.md",
      "title": "ERC-4337 Bundler MEV Extraction Cohort — Ethereum / Polygon / Arbitrum / Optimism / Base — 2023–2025",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T13.001",
        "OAK-T13.002",
        "OAK-T5.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-2024-erc4337-bundler-mev-extraction-cohort.md"
    },
    {
      "id": "2023-2024-french-streamer-kidnapping-ransom-crypto",
      "file": "2023-2024-french-streamer-kidnapping-ransom-crypto.md",
      "title": "TeufeurS Kidnapping — $2M Crypto Ransom / $800K Frozen — 2023",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T5.009"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-2024-french-streamer-kidnapping-ransom-crypto.md"
    },
    {
      "id": "2023-2024-layerzero-governance-relay-misconfiguration-audit-cohort",
      "file": "2023-2024-layerzero-governance-relay-misconfiguration-audit-cohort.md",
      "title": "LayerZero OFT governance relay misconfiguration audit-finding cohort — cross-chain — 2023–2024",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T10.006"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-2024-layerzero-governance-relay-misconfiguration-audit-cohort.md"
    },
    {
      "id": "2023-2024-squeeth-volatility-auction-slippage-sandwich",
      "file": "2023-2024-squeeth-volatility-auction-slippage-sandwich.md",
      "title": "Squeeth volatility auction slippage sandwich — Ethereum — 2023–2024",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T9.013"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-2024-squeeth-volatility-auction-slippage-sandwich.md"
    },
    {
      "id": "2023-2024-starknet-strk-pre-token-anticipation-phishing",
      "file": "2023-2024-starknet-strk-pre-token-anticipation-phishing.md",
      "title": "StarkNet STRK Pre-Token Anticipation Phishing — 2023–2024",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T4.008",
        "OAK-T4.009",
        "OAK-T6.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-2024-starknet-strk-pre-token-anticipation-phishing.md"
    },
    {
      "id": "2023-2024-uk-scammer-ape31-fake-pnl-services",
      "file": "2023-2024-uk-scammer-ape31-fake-pnl-services.md",
      "title": "UK Scammer @ape_31 — Fake PNL Screenshot Funnel to Paid Scam Services — 2023-2024",
      "date_prefix": "2023-20",
      "techniques": [],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-2024-uk-scammer-ape31-fake-pnl-services.md"
    },
    {
      "id": "2023-2024-zksync-airdrop-anticipation-phishing",
      "file": "2023-2024-zksync-airdrop-anticipation-phishing.md",
      "title": "zkSync airdrop-anticipation phishing campaign — 2023–2024",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T4.009"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-2024-zksync-airdrop-anticipation-phishing.md"
    },
    {
      "id": "2023-2025-akira-raas",
      "file": "2023-2025-akira-raas.md",
      "title": "Akira Ransomware-as-a-Service — 2023–2025",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T5.008",
        "OAK-T7.005",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-2025-akira-raas.md"
    },
    {
      "id": "2023-2025-cloud-doc-email-seed-storage-compromise-cohort",
      "file": "2023-2025-cloud-doc-email-seed-storage-compromise-cohort.md",
      "title": "Cloud-Document / Email-Draft Seed-Phrase Storage Compromise Cohort — 2023–2025",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T11.001",
        "OAK-T11.006.001",
        "OAK-T4.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-2025-cloud-doc-email-seed-storage-compromise-cohort.md"
    },
    {
      "id": "2023-2025-defi-yield-strategy-laundering-cohort",
      "file": "2023-2025-defi-yield-strategy-laundering-cohort.md",
      "title": "DeFi yield-strategy laundering via liquidity-provision and staking-as-rail — multi-chain — 2023–2025",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T7.006",
        "OAK-T7.007"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-2025-defi-yield-strategy-laundering-cohort.md"
    },
    {
      "id": "2023-2025-dprk-it-worker-exchange-account-farming",
      "file": "2023-2025-dprk-it-worker-exchange-account-farming.md",
      "title": "DPRK IT-worker program exchange-account farming — multi-chain — 2023–2025",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T8.001",
        "OAK-T8.004",
        "OAK-T8.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-2025-dprk-it-worker-exchange-account-farming.md"
    },
    {
      "id": "2023-2025-dprk-post-tornado-cash-aggregator-laundering",
      "file": "2023-2025-dprk-post-tornado-cash-aggregator-laundering.md",
      "title": "DPRK post-Tornado-Cash DEX aggregator routing laundering — 2023–2025",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T7.007"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-2025-dprk-post-tornado-cash-aggregator-laundering.md"
    },
    {
      "id": "2023-2025-fake-crypto-wallet-google-play-app-store-phishing",
      "file": "2023-2025-fake-crypto-wallet-google-play-app-store-phishing.md",
      "title": "Fake Crypto Wallet App Google Play / App Store Phishing — 2023–2025",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T11.007.003",
        "OAK-T4.007",
        "OAK-T4.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-2025-fake-crypto-wallet-google-play-app-store-phishing.md"
    },
    {
      "id": "2023-2025-fake-revoke-cash-wallet-security-extension-phishing",
      "file": "2023-2025-fake-revoke-cash-wallet-security-extension-phishing.md",
      "title": "Fake Revoke.cash / Wallet-Security Browser-Extension Phishing — 2023–2025",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T11.007.003",
        "OAK-T4.010",
        "OAK-T6.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-2025-fake-revoke-cash-wallet-security-extension-phishing.md"
    },
    {
      "id": "2023-2025-fee-on-transfer-token-accounting-exploit-cohort",
      "file": "2023-2025-fee-on-transfer-token-accounting-exploit-cohort.md",
      "title": "Fee-on-Transfer Token Accounting Exploit Cohort — multi-chain (EVM, BNB Chain, Polygon, Arbitrum) — 2023–2025",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T1.005",
        "OAK-T5.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-2025-fee-on-transfer-token-accounting-exploit-cohort.md"
    },
    {
      "id": "2023-2025-multi-block-mev-twap-oracle-grinding-cohort",
      "file": "2023-2025-multi-block-mev-twap-oracle-grinding-cohort.md",
      "title": "Multi-block MEV TWAP oracle grinding via proposer-builder coordination — Ethereum L1 — 2023–2025",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T17.005",
        "OAK-T5.004",
        "OAK-T9.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-2025-multi-block-mev-twap-oracle-grinding-cohort.md"
    },
    {
      "id": "2023-2025-sec-staking-service-enforcement-kraken-coinbase",
      "file": "2023-2025-sec-staking-service-enforcement-kraken-coinbase.md",
      "title": "Kraken and Coinbase Staking-as-a-Service SEC Enforcement and Validator-Set Disruption — 2023–2025",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T14.001",
        "OAK-T14.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-2025-sec-staking-service-enforcement-kraken-coinbase.md"
    },
    {
      "id": "2023-2025-walletconnect-phishing-campaigns-cohort",
      "file": "2023-2025-walletconnect-phishing-campaigns-cohort.md",
      "title": "WalletConnect session-hijack phishing campaigns — multi-chain — 2023–2025",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T13.004",
        "OAK-T15.001",
        "OAK-T4.001",
        "OAK-T4.006"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-2025-walletconnect-phishing-campaigns-cohort.md"
    },
    {
      "id": "2023-2026-coinbase-support-impersonation",
      "file": "2023-2026-coinbase-support-impersonation.md",
      "title": "Coinbase Support Impersonation — Multi-Victim Social Engineering — 2023–2026",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T4.007"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-2026-coinbase-support-impersonation.md"
    },
    {
      "id": "2023-2026-erc4337-paymaster-griefing-and-dos-cohort",
      "file": "2023-2026-erc4337-paymaster-griefing-and-dos-cohort.md",
      "title": "ERC-4337 Paymaster Griefing and DoS Attack Surface Cohort — 2023–2026",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T13.001",
        "OAK-T13.001.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-2026-erc4337-paymaster-griefing-and-dos-cohort.md"
    },
    {
      "id": "2023-2026-fake-dex-clone-frontend-cohort",
      "file": "2023-2026-fake-dex-clone-frontend-cohort.md",
      "title": "Fake DEX / clone-frontend distribution cohort — multi-chain — 2023 onward (multi-year cohort)",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T4.001",
        "OAK-T4.004",
        "OAK-T4.005",
        "OAK-T4.008"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2023-2026-fake-dex-clone-frontend-cohort.md"
    },
    {
      "id": "2023-2026-fake-firmware-update-phishing-cohort",
      "file": "2023-2026-fake-firmware-update-phishing-cohort.md",
      "title": "Fake hardware-wallet firmware-update / recovery-app phishing cohort — Ledger / Trezor user base — 2023 onward (multi-year cohort)",
      "date_prefix": "2023-20",
      "techniques": [
        "OAK-T11.007",
        "OAK-T11.007.003",
        "OAK-T4",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-2026-fake-firmware-update-phishing-cohort.md"
    },
    {
      "id": "2023-hundred-finance-compound-v2-fork-cascade",
      "file": "2023-hundred-finance-compound-v2-fork-cascade.md",
      "title": "Hundred Finance Compound V2 fork exploit — multi-chain — 2023-04-15",
      "date_prefix": "2023",
      "techniques": [
        "OAK-T9.004",
        "OAK-T9.007"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-hundred-finance-compound-v2-fork-cascade.md"
    },
    {
      "id": "2023-jaredfromsubway-mev",
      "file": "2023-jaredfromsubway-mev.md",
      "title": "Jaredfromsubway MEV sandwich bot — Ethereum — 2023",
      "date_prefix": "2023",
      "techniques": [
        "OAK-T5.004",
        "OAK-T9.013"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-jaredfromsubway-mev.md"
    },
    {
      "id": "2023-mev-boost-equivocation",
      "file": "2023-mev-boost-equivocation.md",
      "title": "MEV-Boost relay equivocation attack surface — Ethereum — 2023",
      "date_prefix": "2023",
      "techniques": [
        "OAK-T14.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2023-mev-boost-equivocation.md"
    },
    {
      "id": "2023-sim-swap-crypto-wave",
      "file": "2023-sim-swap-crypto-wave.md",
      "title": "SIM Swap Wave — Multi-Victim Telecom Attack — 2023",
      "date_prefix": "2023",
      "techniques": [
        "OAK-T4.007",
        "OAK-T6"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-sim-swap-crypto-wave.md"
    },
    {
      "id": "2023-tornado-cash-25m-collectibles-laundering",
      "file": "2023-tornado-cash-25m-collectibles-laundering.md",
      "title": "Tornado Cash → Magic: The Gathering Cards — $25M Collectibles Laundering — 2023",
      "date_prefix": "2023",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T8.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2023-tornado-cash-25m-collectibles-laundering.md"
    },
    {
      "id": "2024-01-1password-encrypted-note-seed-storage-cohort",
      "file": "2024-01-1password-encrypted-note-seed-storage-cohort.md",
      "title": "1Password encrypted-note seed-storage cohort — multi-chain — 2024–2025",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T11.006.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-01-1password-encrypted-note-seed-storage-cohort.md"
    },
    {
      "id": "2024-01-astaria-reinitialization",
      "file": "2024-01-astaria-reinitialization.md",
      "title": "Astaria reinitialization vulnerability disclosure — EVM — 2024",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T9.009"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-01-astaria-reinitialization.md"
    },
    {
      "id": "2024-01-coinspaid-lazarus-endpoint-compromise",
      "file": "2024-01-coinspaid-lazarus-endpoint-compromise.md",
      "title": "CoinsPaid $37M Lazarus Group Attack — Payment Processor Exploit — 2024-01",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.001",
        "OAK-T15.003",
        "OAK-T7.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-01-coinspaid-lazarus-endpoint-compromise.md"
    },
    {
      "id": "2024-01-cointelegraph-walletconnect-email-phishing",
      "file": "2024-01-cointelegraph-walletconnect-email-phishing.md",
      "title": "Email Impersonation Phishing Wave — CoinTelegraph/WalletConnect/Token Terminal Impersonation — 2024-01",
      "date_prefix": "2024-01",
      "techniques": [],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-01-cointelegraph-walletconnect-email-phishing.md"
    },
    {
      "id": "2024-01-concentric",
      "file": "2024-01-concentric.md",
      "title": "Concentric Finance multisig signing-key social-engineering compromise — Arbitrum — 2024-01-22",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T11.001",
        "OAK-T11.002",
        "OAK-T15.001",
        "OAK-T15.003",
        "OAK-T7.001",
        "OAK-T9.004"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-01-concentric.md"
    },
    {
      "id": "2024-01-defi-bluechip-yield-laundering",
      "file": "2024-01-defi-bluechip-yield-laundering.md",
      "title": "Blue-chip DeFi yield-protocol laundering via LST and lending-market cover — Ethereum — 2024",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T7.006"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-01-defi-bluechip-yield-laundering.md"
    },
    {
      "id": "2024-01-dprk-chain-hop-laundering",
      "file": "2024-01-dprk-chain-hop-laundering.md",
      "title": "DPRK-attributed multi-stage chain-hop laundering via privacy-chain conversions — cross-chain — 2024",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T7.005"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-01-dprk-chain-hop-laundering.md"
    },
    {
      "id": "2024-01-fake-metamask-extension-chrome-store",
      "file": "2024-01-fake-metamask-extension-chrome-store.md",
      "title": "Fake MetaMask Chrome extension campaign — EVM/multi-chain — 2024-01 to 2024-06",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T11.007.003",
        "OAK-T4.001",
        "OAK-T4.010"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-01-fake-metamask-extension-chrome-store.md"
    },
    {
      "id": "2024-01-fake-trezor-suite-download",
      "file": "2024-01-fake-trezor-suite-download.md",
      "title": "Fake Trezor Suite download phishing campaign — multi-chain — 2024",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T11.007.003"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-01-fake-trezor-suite-download.md"
    },
    {
      "id": "2024-01-gamma-strategies-flash-loan-exploit",
      "file": "2024-01-gamma-strategies-flash-loan-exploit.md",
      "title": "Gamma Strategies $3.4M Flash Loan Price Manipulation — 2024-01",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.013"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-01-gamma-strategies-flash-loan-exploit.md"
    },
    {
      "id": "2024-01-hyperverse-hyperfund",
      "file": "2024-01-hyperverse-hyperfund.md",
      "title": "HyperVerse / HyperFund — Sam Lee / Ryan Xu fake-asset-manager Ponzi (HyperTech ecosystem) — global — 2020-06 to 2022-11 (operating) / DOJ + SEC charges 2024-01",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T11.005.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-01-hyperverse-hyperfund.md"
    },
    {
      "id": "2024-01-ios-whatsapp-icloud-wallet-backup-cohort",
      "file": "2024-01-ios-whatsapp-icloud-wallet-backup-cohort.md",
      "title": "iOS WhatsApp iCloud-backup wallet-seed exfiltration cohort — multi-chain — 2024",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T11.006.001",
        "OAK-T11.006.002"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-01-ios-whatsapp-icloud-wallet-backup-cohort.md"
    },
    {
      "id": "2024-01-kk-park-compound-takedown",
      "file": "2024-01-kk-park-compound-takedown.md",
      "title": "KK Park compound-operated investment-fraud takedown — Myanmar/Thailand border — 2024",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T11.005.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-01-kk-park-compound-takedown.md"
    },
    {
      "id": "2024-01-nft-royalty-bypass",
      "file": "2024-01-nft-royalty-bypass.md",
      "title": "NFT marketplace royalty-enforcement sunset and creator-revenue bypass — multi-chain (Ethereum, Solana, Bitcoin ordinals) — 2024",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T12.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-01-nft-royalty-bypass.md"
    },
    {
      "id": "2024-01-orbit-bridge",
      "file": "2024-01-orbit-bridge.md",
      "title": "Orbit Bridge — Ethereum ↔ multi-chain — 2024-01-01",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T10.001",
        "OAK-T7.001",
        "OAK-T7.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-01-orbit-bridge.md"
    },
    {
      "id": "2024-01-post-tornado-defi-yield-laundering",
      "file": "2024-01-post-tornado-defi-yield-laundering.md",
      "title": "Post-Tornado-Cash DeFi yield-protocol laundering shift — cross-chain — 2024 onward",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T7.006"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-01-post-tornado-defi-yield-laundering.md"
    },
    {
      "id": "2024-01-ripple-hot-wallet-compromise",
      "file": "2024-01-ripple-hot-wallet-compromise.md",
      "title": "Ripple — Private Key Compromise — 2024-01-31",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T7.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-01-ripple-hot-wallet-compromise.md"
    },
    {
      "id": "2024-01-sec-x-account-compromise",
      "file": "2024-01-sec-x-account-compromise.md",
      "title": "U.S. SEC verified X-account compromise and fake Bitcoin ETF approval — chain-agnostic — 2024-01-09",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T15.006",
        "OAK-T17.001",
        "OAK-T4"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-01-sec-x-account-compromise.md"
    },
    {
      "id": "2024-01-socket-bungee-bridge",
      "file": "2024-01-socket-bungee-bridge.md",
      "title": "Socket / Bungee bridge infinite-approval call-injection exploit — Ethereum — 2024-01-16",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T10",
        "OAK-T4.001",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-01-socket-bungee-bridge.md"
    },
    {
      "id": "2024-01-socket-bungee",
      "file": "2024-01-socket-bungee.md",
      "title": "Socket/Bungee bridge exploit — Ethereum — 2024-01-16",
      "date_prefix": "2024-01",
      "techniques": [
        "OAK-T10.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-01-socket-bungee.md"
    },
    {
      "id": "2024-02-bitforex",
      "file": "2024-02-bitforex.md",
      "title": "BitForex hot-wallet drain (operator-driven exit-scam pattern) — multi-chain — 2024-02-23",
      "date_prefix": "2024-02",
      "techniques": [
        "OAK-T11",
        "OAK-T7.001",
        "OAK-T7.003"
      ],
      "attribution": "inferred-weak",
      "source_file": "examples/2024-02-bitforex.md"
    },
    {
      "id": "2024-02-blur-wash-trading-ring",
      "file": "2024-02-blur-wash-trading-ring.md",
      "title": "Blur points-farming wash-trading ring — coordinated circular NFT trades across linked wallet clusters — Ethereum — 2023–2024",
      "date_prefix": "2024-02",
      "techniques": [
        "OAK-T12.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-02-blur-wash-trading-ring.md"
    },
    {
      "id": "2024-02-change-healthcare-ransom",
      "file": "2024-02-change-healthcare-ransom.md",
      "title": "Change Healthcare ransom payment — Bitcoin — 2024-02-21 to 2024-03-05",
      "date_prefix": "2024-02",
      "techniques": [
        "OAK-T5.008",
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T7.005",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-02-change-healthcare-ransom.md"
    },
    {
      "id": "2024-02-dydx-vesting-unlock-dump",
      "file": "2024-02-dydx-vesting-unlock-dump.md",
      "title": "dYdX DYDX token vesting-cliff unlock and investor sell-pressure — Ethereum — 2024-02-01",
      "date_prefix": "2024-02",
      "techniques": [
        "OAK-T5.006",
        "OAK-T8.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-02-dydx-vesting-unlock-dump.md"
    },
    {
      "id": "2024-02-eigenlayer-token-anticipation-phishing",
      "file": "2024-02-eigenlayer-token-anticipation-phishing.md",
      "title": "EigenLayer pre-token anticipation phishing — Ethereum — early 2024",
      "date_prefix": "2024-02",
      "techniques": [
        "OAK-T4.008",
        "OAK-T4.009"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-02-eigenlayer-token-anticipation-phishing.md"
    },
    {
      "id": "2024-02-fixedfloat",
      "file": "2024-02-fixedfloat.md",
      "title": "FixedFloat instant-swap hot-wallet drain — multi-chain — 2024-02-16",
      "date_prefix": "2024-02",
      "techniques": [
        "OAK-T11",
        "OAK-T7.001",
        "OAK-T8.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-02-fixedfloat.md"
    },
    {
      "id": "2024-02-honeypot-token-cohort-cross-chain",
      "file": "2024-02-honeypot-token-cohort-cross-chain.md",
      "title": "Honeypot-by-design token cohort — Ethereum / BNB Chain / Base — 2024-02 onward",
      "date_prefix": "2024-02",
      "techniques": [
        "OAK-T1.004",
        "OAK-T1.005",
        "OAK-T1.006",
        "OAK-T6.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-02-honeypot-token-cohort-cross-chain.md"
    },
    {
      "id": "2024-02-lockbit-operation-cronos",
      "file": "2024-02-lockbit-operation-cronos.md",
      "title": "LockBit Operation Cronos disruption — multi-jurisdiction takedown — 2024-02-19 to 2024-02-20",
      "date_prefix": "2024-02",
      "techniques": [
        "OAK-T5.008",
        "OAK-T7.002",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-02-lockbit-operation-cronos.md"
    },
    {
      "id": "2024-02-playdapp-private-key-compromise",
      "file": "2024-02-playdapp-private-key-compromise.md",
      "title": "PlayDapp $290M Private Key Compromise — Gaming Platform Exploit — 2024-02",
      "date_prefix": "2024-02",
      "techniques": [
        "OAK-T11.001",
        "OAK-T5.001",
        "OAK-T7.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-02-playdapp-private-key-compromise.md"
    },
    {
      "id": "2024-02-stader-ethx-lst-discount",
      "file": "2024-02-stader-ethx-lst-discount.md",
      "title": "Stader ETHx LST secondary-market discount to ETH NAV — DEX liquidity pool pricing divergence during LRT-season liquidity migration — Ethereum — 2024-02",
      "date_prefix": "2024-02",
      "techniques": [
        "OAK-T14.003.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-02-stader-ethx-lst-discount.md"
    },
    {
      "id": "2024-03-arbitrum-arb-vesting-cliff-dump",
      "file": "2024-03-arbitrum-arb-vesting-cliff-dump.md",
      "title": "Arbitrum ARB team-and-investor vesting-cliff unlock and coordinated sell-pressure — Ethereum — 2024-03-16",
      "date_prefix": "2024-03",
      "techniques": [
        "OAK-T16",
        "OAK-T5.005",
        "OAK-T5.006"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-03-arbitrum-arb-vesting-cliff-dump.md"
    },
    {
      "id": "2024-03-blknoiz06-impersonation-reply-phishing",
      "file": "2024-03-blknoiz06-impersonation-reply-phishing.md",
      "title": "@blknoiz06 Impersonation — $2.6M Meme Coin Reply Phishing — 2024-03",
      "date_prefix": "2024-03",
      "techniques": [],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-03-blknoiz06-impersonation-reply-phishing.md"
    },
    {
      "id": "2024-03-coinbase-smart-wallet-disclosure",
      "file": "2024-03-coinbase-smart-wallet-disclosure.md",
      "title": "Coinbase Smart Wallet pre-launch audit disclosure (H-01 ownership-recovery loss-of-funds) — Base — 2024-03",
      "date_prefix": "2024-03",
      "techniques": [
        "OAK-T11",
        "OAK-T13.003",
        "OAK-T9.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-03-coinbase-smart-wallet-disclosure.md"
    },
    {
      "id": "2024-03-curio",
      "file": "2024-03-curio.md",
      "title": "Curio DAO governance attack — Ethereum + multi-chain — 2024-03-23",
      "date_prefix": "2024-03",
      "techniques": [
        "OAK-T16.001",
        "OAK-T16.005",
        "OAK-T9.002",
        "OAK-T9.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-03-curio.md"
    },
    {
      "id": "2024-03-cygnus-finance-read-only-reentrancy",
      "file": "2024-03-cygnus-finance-read-only-reentrancy.md",
      "title": "Cygnus Finance read-only reentrancy via LP-token oracle — EVM — 2024-03",
      "date_prefix": "2024-03",
      "techniques": [
        "OAK-T9.002",
        "OAK-T9.010"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-03-cygnus-finance-read-only-reentrancy.md"
    },
    {
      "id": "2024-03-ether-fi-profanity-entropy-cohort",
      "file": "2024-03-ether-fi-profanity-entropy-cohort.md",
      "title": "Profanity vanity-address entropy cohort tail — Ethereum — 2023–2024 (cohort-extended case)",
      "date_prefix": "2024-03",
      "techniques": [
        "OAK-T11",
        "OAK-T11.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-03-ether-fi-profanity-entropy-cohort.md"
    },
    {
      "id": "2024-03-jolan-lacroix-presale-theft",
      "file": "2024-03-jolan-lacroix-presale-theft.md",
      "title": "Jolan Lacroix — $900K Presale Theft / Gambling on Meme Coins and Milady NFTs — 2024-03",
      "date_prefix": "2024-03",
      "techniques": [],
      "attribution": "confirmed",
      "source_file": "examples/2024-03-jolan-lacroix-presale-theft.md"
    },
    {
      "id": "2024-03-kyle-nuddies-nft-fake-hack",
      "file": "2024-03-kyle-nuddies-nft-fake-hack.md",
      "title": "Kyle DeGods — Fake Hack / Insider Theft from Nuddies NFT Project — 2024-03",
      "date_prefix": "2024-03",
      "techniques": [
        "OAK-T5.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-03-kyle-nuddies-nft-fake-hack.md"
    },
    {
      "id": "2024-03-munchables",
      "file": "2024-03-munchables.md",
      "title": "Munchables — Blast L2 — 2024-03-26",
      "date_prefix": "2024-03",
      "techniques": [
        "OAK-T11",
        "OAK-T7.002",
        "OAK-T9.004"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-03-munchables.md"
    },
    {
      "id": "2024-03-prisma-finance",
      "file": "2024-03-prisma-finance.md",
      "title": "Prisma Finance MigrateTroveZap delegatecall exploit — Ethereum — 2024-03-28",
      "date_prefix": "2024-03",
      "techniques": [
        "OAK-T9.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-03-prisma-finance.md"
    },
    {
      "id": "2024-03-woofi",
      "file": "2024-03-woofi.md",
      "title": "WOOFi Pro sPMM curve flash-loan manipulation — Arbitrum — 2024-03-05",
      "date_prefix": "2024-03",
      "techniques": [
        "OAK-T7.001",
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-03-woofi.md"
    },
    {
      "id": "2024-04-change-healthcare-reextortion",
      "file": "2024-04-change-healthcare-reextortion.md",
      "title": "Change Healthcare data-leak re-extortion — Bitcoin / RansomHub brand — 2024-04",
      "date_prefix": "2024-04",
      "techniques": [
        "OAK-T5.008",
        "OAK-T7.002",
        "OAK-T8.001",
        "OAK-T8.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-04-change-healthcare-reextortion.md"
    },
    {
      "id": "2024-04-hedgey",
      "file": "2024-04-hedgey.md",
      "title": "Hedgey Finance claim-function input-validation exploit — multi-chain — 2024-04-19",
      "date_prefix": "2024-04",
      "techniques": [
        "OAK-T7.001",
        "OAK-T9.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-04-hedgey.md"
    },
    {
      "id": "2024-04-nft-wrapper-royalty-circumvention-cohort",
      "file": "2024-04-nft-wrapper-royalty-circumvention-cohort.md",
      "title": "NFT wrapper / fractionalisation protocol royalty circumvention cohort — NFTX / FloorDAO / Sudoswap — Ethereum — 2022–2025",
      "date_prefix": "2024-04",
      "techniques": [
        "OAK-T12.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-04-nft-wrapper-royalty-circumvention-cohort.md"
    },
    {
      "id": "2024-04-pike-finance",
      "file": "2024-04-pike-finance.md",
      "title": "Pike Finance Wormhole-NTT cross-chain message-handling exploit — multi-chain — 2024-04-30 / 2024-05-05",
      "date_prefix": "2024-04",
      "techniques": [
        "OAK-T10.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-04-pike-finance.md"
    },
    {
      "id": "2024-04-renzo-ezeth-depeg",
      "file": "2024-04-renzo-ezeth-depeg.md",
      "title": "Renzo ezETH liquid-restaking-token depeg and looped-leverage liquidation cascade — Ethereum L1 + multi-chain — 2024-04-24",
      "date_prefix": "2024-04",
      "techniques": [
        "OAK-T14.003",
        "OAK-T14.003.001",
        "OAK-T14.004",
        "OAK-T17.002",
        "OAK-T9.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-04-renzo-ezeth-depeg.md"
    },
    {
      "id": "2024-04-zkasino-bridge-exit",
      "file": "2024-04-zkasino-bridge-exit.md",
      "title": "ZKasino gambling-platform bridge-exit — Ethereum / L2s — 2024-04-20 onward",
      "date_prefix": "2024-04",
      "techniques": [
        "OAK-T11.005",
        "OAK-T15",
        "OAK-T5.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-04-zkasino-bridge-exit.md"
    },
    {
      "id": "2024-05-address-poisoning-68m",
      "file": "2024-05-address-poisoning-68m.md",
      "title": "Address Poisoning — Ethereum — 2024-05-03 (\\$68M WBTC, returned)",
      "date_prefix": "2024-05",
      "techniques": [
        "OAK-T4.003",
        "OAK-T6"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-05-address-poisoning-68m.md"
    },
    {
      "id": "2024-05-cypher-hoak-insider-redemption-theft",
      "file": "2024-05-cypher-hoak-insider-redemption-theft.md",
      "title": "Cypher Protocol Hoak insider theft from redemption fund — Solana — 2024-05",
      "date_prefix": "2024-05",
      "techniques": [
        "OAK-T11",
        "OAK-T5.005",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-05-cypher-hoak-insider-redemption-theft.md"
    },
    {
      "id": "2024-05-dmm-bitcoin",
      "file": "2024-05-dmm-bitcoin.md",
      "title": "DMM Bitcoin exchange hack — Bitcoin — 2024-05-31",
      "date_prefix": "2024-05",
      "techniques": [
        "OAK-T11.001",
        "OAK-T7.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-05-dmm-bitcoin.md"
    },
    {
      "id": "2024-05-eigenlayer-restaking-airdrop",
      "file": "2024-05-eigenlayer-restaking-airdrop.md",
      "title": "EigenLayer restaking airdrop dispute and AVS slashing-condition cohort — Ethereum L1 — 2024-05 onward",
      "date_prefix": "2024-05",
      "techniques": [
        "OAK-T14.001",
        "OAK-T14.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-05-eigenlayer-restaking-airdrop.md"
    },
    {
      "id": "2024-05-eigenlayer-withdrawal-sandwich",
      "file": "2024-05-eigenlayer-withdrawal-sandwich.md",
      "title": "EigenLayer withdrawal slippage sandwich — Ethereum — 2024-05",
      "date_prefix": "2024-05",
      "techniques": [
        "OAK-T5.004",
        "OAK-T9.013"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-05-eigenlayer-withdrawal-sandwich.md"
    },
    {
      "id": "2024-05-ether-fi-weeth-discount-depeg",
      "file": "2024-05-ether-fi-weeth-discount-depeg.md",
      "title": "Ether.fi weETH liquid-restaking-token discount-to-NAV event — Ethereum L1 — 2024-05",
      "date_prefix": "2024-05",
      "techniques": [
        "OAK-T14.003",
        "OAK-T14.004",
        "OAK-T9.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-05-ether-fi-weeth-discount-depeg.md"
    },
    {
      "id": "2024-05-gala-games",
      "file": "2024-05-gala-games.md",
      "title": "Gala Games admin-key compromise emergency-recovery — Ethereum — 2024-05-20",
      "date_prefix": "2024-05",
      "techniques": [
        "OAK-T11.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-05-gala-games.md"
    },
    {
      "id": "2024-05-gcrclassic-hack-hyperliquid-insider-longs",
      "file": "2024-05-gcrclassic-hack-hyperliquid-insider-longs.md",
      "title": "GCR Classic Hack → $3.3M Insider Longs on Hyperliquid — 2024-05",
      "date_prefix": "2024-05",
      "techniques": [
        "OAK-T15.006"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-05-gcrclassic-hack-hyperliquid-insider-longs.md"
    },
    {
      "id": "2024-05-sonne-finance",
      "file": "2024-05-sonne-finance.md",
      "title": "Sonne Finance empty-market rounding-error exploit — Optimism — 2024-05-14",
      "date_prefix": "2024-05",
      "techniques": [
        "OAK-T7.001",
        "OAK-T9.002",
        "OAK-T9.005",
        "OAK-T9.007",
        "OAK-T9.011"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-05-sonne-finance.md"
    },
    {
      "id": "2024-05-uniswap-dao-delegation-governance-concentration",
      "file": "2024-05-uniswap-dao-delegation-governance-concentration.md",
      "title": "Uniswap DAO delegation governance concentration — delegate voting-weight accumulation and community governance dynamics — Ethereum — 2023–2025",
      "date_prefix": "2024-05",
      "techniques": [
        "OAK-T16.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-05-uniswap-dao-delegation-governance-concentration.md"
    },
    {
      "id": "2024-06-bera-chain-fake-airdrop-token-metadata-spoofing",
      "file": "2024-06-bera-chain-fake-airdrop-token-metadata-spoofing.md",
      "title": "BeraChain fake-airdrop token-metadata-spoofing wave — BeraChain EVM — 2024-06 to 2024-09",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T2.005",
        "OAK-T4.009",
        "OAK-T6.006"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-06-bera-chain-fake-airdrop-token-metadata-spoofing.md"
    },
    {
      "id": "2024-06-btcturk",
      "file": "2024-06-btcturk.md",
      "title": "BtcTurk hot-wallet drain (first incident) — multi-chain — 2024-06-22",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T11",
        "OAK-T7.001",
        "OAK-T8.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-06-btcturk.md"
    },
    {
      "id": "2024-06-coinstats-snap",
      "file": "2024-06-coinstats-snap.md",
      "title": "CoinStats MetaMask-Snap-related compromise — Ethereum + multi-chain — 2024-06-22",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T11.002",
        "OAK-T15.002",
        "OAK-T15.004",
        "OAK-T4.004",
        "OAK-T4.005",
        "OAK-T4.011"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-06-coinstats-snap.md"
    },
    {
      "id": "2024-06-erc4337-bundler-mev-polygon-operator",
      "file": "2024-06-erc4337-bundler-mev-polygon-operator.md",
      "title": "ERC-4337 bundler MEV extraction on Polygon — specific operator-level bundler front-running incident — 2024-06",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T13.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-06-erc4337-bundler-mev-polygon-operator.md"
    },
    {
      "id": "2024-06-holograph",
      "file": "2024-06-holograph.md",
      "title": "Holograph deployer-key compromise unlimited-mint-and-dump — Ethereum — 2024-06-13",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T11.002",
        "OAK-T5.001",
        "OAK-T7.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-06-holograph.md"
    },
    {
      "id": "2024-06-kelp-rseth-depeg",
      "file": "2024-06-kelp-rseth-depeg.md",
      "title": "Kelp rsETH liquid-restaking-token depeg — Ethereum L1 — 2024-06",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T14.003.001",
        "OAK-T14.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-06-kelp-rseth-depeg.md"
    },
    {
      "id": "2024-06-loopring-smart-wallet",
      "file": "2024-06-loopring-smart-wallet.md",
      "title": "Loopring Smart Wallet guardian-recovery exploit — Ethereum — 2024-06-09",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T11.008",
        "OAK-T13.003",
        "OAK-T5.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-06-loopring-smart-wallet.md"
    },
    {
      "id": "2024-06-loopring",
      "file": "2024-06-loopring.md",
      "title": "Loopring Smart Wallet 2FA-bypass guardian-recovery exploit — Ethereum — 2024-06-09",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T11.002",
        "OAK-T13.003",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-06-loopring.md"
    },
    {
      "id": "2024-06-mark-cuban-wallet-social-engineering",
      "file": "2024-06-mark-cuban-wallet-social-engineering.md",
      "title": "Mark Cuban — Public Figure Wallet Social Engineering Compromise — 2024-06",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T8.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-06-mark-cuban-wallet-social-engineering.md"
    },
    {
      "id": "2024-06-opensea-royalty-shift",
      "file": "2024-06-opensea-royalty-shift.md",
      "title": "OpenSea creator-royalty enforcement sunset — EVM NFT marketplaces — 2024-06 to 2025-01",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T13",
        "OAK-T6.007"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-06-opensea-royalty-shift.md"
    },
    {
      "id": "2024-06-polymarket-djt-oracle-override",
      "file": "2024-06-polymarket-djt-oracle-override.md",
      "title": "Polymarket Barron Trump / DJT memecoin oracle-override dispute — 2024",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T9.006.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-06-polymarket-djt-oracle-override.md"
    },
    {
      "id": "2024-06-solana-validator-sandwich-mev-cohort",
      "file": "2024-06-solana-validator-sandwich-mev-cohort.md",
      "title": "Solana validator-coordinated sandwich-attack MEV cohort and Foundation delegation-program removal — Solana — 2024-06",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T14.002",
        "OAK-T17.001",
        "OAK-T5.004",
        "OAK-T6",
        "OAK-T8.001",
        "OAK-T9"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-06-solana-validator-sandwich-mev-cohort.md"
    },
    {
      "id": "2024-06-uplift-dao-proxy-upgrade",
      "file": "2024-06-uplift-dao-proxy-upgrade.md",
      "title": "Uplift DAO malicious proxy-upgrade treasury drain — Ethereum — 2024-06-18",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T5.001",
        "OAK-T6.001",
        "OAK-T6.005"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-06-uplift-dao-proxy-upgrade.md"
    },
    {
      "id": "2024-06-uwu-bittensor",
      "file": "2024-06-uwu-bittensor.md",
      "title": "Bittensor `bittensor` PyPI supply-chain coldkey-exfiltration compromise — Bittensor / TAO — 2024-07-02",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T11.002",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-06-uwu-bittensor.md"
    },
    {
      "id": "2024-06-uwu-lend",
      "file": "2024-06-uwu-lend.md",
      "title": "UwU Lend sUSDe oracle thin-input manipulation — Ethereum — 2024-06-10",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T7.001",
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-06-uwu-lend.md"
    },
    {
      "id": "2024-06-velocore",
      "file": "2024-06-velocore.md",
      "title": "Velocore CPMM fee-rate underflow exploit — zkSync Era / Linea — 2024-06-02",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T7.001",
        "OAK-T9.002",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-06-velocore.md"
    },
    {
      "id": "2024-06-walletconnect-multisig-drain",
      "file": "2024-06-walletconnect-multisig-drain.md",
      "title": "WalletConnect multisig-drain via fake MEV-bot session — EVM/multi-chain — 2024-06",
      "date_prefix": "2024-06",
      "techniques": [
        "OAK-T4.004",
        "OAK-T4.006"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-06-walletconnect-multisig-drain.md"
    },
    {
      "id": "2024-07-compound-cross-chain-governance-relay",
      "file": "2024-07-compound-cross-chain-governance-relay.md",
      "title": "Compound cross-chain governance relay misconfiguration — Ethereum / multi-chain — 2023–2024 (audit-finding class)",
      "date_prefix": "2024-07",
      "techniques": [
        "OAK-T10.006"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-07-compound-cross-chain-governance-relay.md"
    },
    {
      "id": "2024-07-compound-vote-takeover",
      "file": "2024-07-compound-vote-takeover.md",
      "title": "Compound DAO Proposal 289 attempted governance takeover — Ethereum — 2024-07-28",
      "date_prefix": "2024-07",
      "techniques": [
        "OAK-T16.002",
        "OAK-T16.003",
        "OAK-T9.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-07-compound-vote-takeover.md"
    },
    {
      "id": "2024-07-gmx-brand-impersonation-fork",
      "file": "2024-07-gmx-brand-impersonation-fork.md",
      "title": "GMX-brand-impersonation Telegram copy-trading bot soft rug — Arbitrum — 2024-07 to 2024-09",
      "date_prefix": "2024-07",
      "techniques": [
        "OAK-T5.007",
        "OAK-T6.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-07-gmx-brand-impersonation-fork.md"
    },
    {
      "id": "2024-07-gurv-celebrity-x-account-compromise",
      "file": "2024-07-gurv-celebrity-x-account-compromise.md",
      "title": "Gurvinder Bhangu (Gurv) — Celebrity X Account Compromise → Meme Coin Scams — 2024-07",
      "date_prefix": "2024-07",
      "techniques": [
        "OAK-T15.006",
        "OAK-T3.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-07-gurv-celebrity-x-account-compromise.md"
    },
    {
      "id": "2024-07-li-finance",
      "file": "2024-07-li-finance.md",
      "title": "Li.Fi cross-chain aggregator facet exploit — multi-chain — 2024-07-16",
      "date_prefix": "2024-07",
      "techniques": [
        "OAK-T4.004",
        "OAK-T7.001",
        "OAK-T7.007",
        "OAK-T9.004",
        "OAK-T9.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-07-li-finance.md"
    },
    {
      "id": "2024-07-neiro-solana-bundled-launch-rug",
      "file": "2024-07-neiro-solana-bundled-launch-rug.md",
      "title": "$NEIRO Solana memecoin bundled-launch concentration rug — Solana — 2024-07-27",
      "date_prefix": "2024-07",
      "techniques": [
        "OAK-T2.001",
        "OAK-T3.001",
        "OAK-T5.002",
        "OAK-T6"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-07-neiro-solana-bundled-launch-rug.md"
    },
    {
      "id": "2024-07-puffer-pufeth-depeg",
      "file": "2024-07-puffer-pufeth-depeg.md",
      "title": "Puffer pufETH LRT depeg event — EigenLayer restaking withdrawal-cap constraint — Ethereum — 2024-07",
      "date_prefix": "2024-07",
      "techniques": [
        "OAK-T14.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-07-puffer-pufeth-depeg.md"
    },
    {
      "id": "2024-07-wazirx",
      "file": "2024-07-wazirx.md",
      "title": "WazirX — Ethereum — 2024-07-18",
      "date_prefix": "2024-07",
      "techniques": [
        "OAK-T11.001",
        "OAK-T11.003",
        "OAK-T7.003",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-07-wazirx.md"
    },
    {
      "id": "2024-08-4064-btc-multi-hop-cross-chain-laundering",
      "file": "2024-08-4064-btc-multi-hop-cross-chain-laundering.md",
      "title": "4064 BTC — Instant Exchange + Cross-Chain Bridge Laundering — 2024-08",
      "date_prefix": "2024-08",
      "techniques": [
        "OAK-T7.003",
        "OAK-T7.005",
        "OAK-T7.010"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-08-4064-btc-multi-hop-cross-chain-laundering.md"
    },
    {
      "id": "2024-08-bittensor-coldkey-cohort",
      "file": "2024-08-bittensor-coldkey-cohort.md",
      "title": "Bittensor PyPI compromise — coldkey-cohort impact — Bittensor / TAO — 2024-07 to 2024-08 (cohort)",
      "date_prefix": "2024-08",
      "techniques": [
        "OAK-T11.002",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-08-bittensor-coldkey-cohort.md"
    },
    {
      "id": "2024-08-discord-bookmark-drainer",
      "file": "2024-08-discord-bookmark-drainer.md",
      "title": "Discord bookmark-phishing drainer campaign via server-boost mechanic — EVM/Solana — 2024-08 to 2024-10",
      "date_prefix": "2024-08",
      "techniques": [
        "OAK-T4.001",
        "OAK-T4.004",
        "OAK-T4.007"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-08-discord-bookmark-drainer.md"
    },
    {
      "id": "2024-08-dprk-it-worker-infiltration",
      "file": "2024-08-dprk-it-worker-infiltration.md",
      "title": "DPRK IT Worker Crypto Team Infiltration — Multi-Protocol — 2024-08",
      "date_prefix": "2024-08",
      "techniques": [
        "OAK-T11.007",
        "OAK-T4.007"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-08-dprk-it-worker-infiltration.md"
    },
    {
      "id": "2024-08-erc4337-paymaster-validation-bypass",
      "file": "2024-08-erc4337-paymaster-validation-bypass.md",
      "title": "ERC-4337 paymaster validation-bypass disclosure cohort — EVM — 2024",
      "date_prefix": "2024-08",
      "techniques": [
        "OAK-T13.001",
        "OAK-T13.001.001",
        "OAK-T13.001.002",
        "OAK-T13.001.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-08-erc4337-paymaster-validation-bypass.md"
    },
    {
      "id": "2024-08-genesis-creditor-social-engineering",
      "file": "2024-08-genesis-creditor-social-engineering.md",
      "title": "Genesis Creditor — Multi-Stage Impersonation Social Engineering — 2024-08-19",
      "date_prefix": "2024-08",
      "techniques": [
        "OAK-T4.007",
        "OAK-T7"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-08-genesis-creditor-social-engineering.md"
    },
    {
      "id": "2024-08-nexera",
      "file": "2024-08-nexera.md",
      "title": "Nexera (formerly AllianceBlock) NXRA proxy-admin compromise — Ethereum — 2024-08-06",
      "date_prefix": "2024-08",
      "techniques": [
        "OAK-T11.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-08-nexera.md"
    },
    {
      "id": "2024-08-penpie-yield",
      "file": "2024-08-penpie-yield.md",
      "title": "Penpie Finance yield-optimizer reward-accounting exploit — Ethereum + Arbitrum — 2024-09-03",
      "date_prefix": "2024-08",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-08-penpie-yield.md"
    },
    {
      "id": "2024-08-rocket-pool-validator-downtime-outage",
      "file": "2024-08-rocket-pool-validator-downtime-outage.md",
      "title": "Rocket Pool node-operator infrastructure-concentration downtime event — AWS/Hetzner correlated outage induced material inactivity-leak penalties across concentrated validator set — Ethereum — 2024-08",
      "date_prefix": "2024-08",
      "techniques": [
        "OAK-T14.006"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-08-rocket-pool-validator-downtime-outage.md"
    },
    {
      "id": "2024-08-ronin-bridge-rescue",
      "file": "2024-08-ronin-bridge-rescue.md",
      "title": "Ronin Bridge whitehat MEV-bot rescue — Ronin / Ethereum — 2024-08-06",
      "date_prefix": "2024-08",
      "techniques": [
        "OAK-T10.001",
        "OAK-T5.004",
        "OAK-T7",
        "OAK-T7.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-08-ronin-bridge-rescue.md"
    },
    {
      "id": "2024-08-ronin-bridge-upgrade",
      "file": "2024-08-ronin-bridge-upgrade.md",
      "title": "Ronin Bridge upgrade-function misconfiguration — Ronin / Ethereum — 2024-08-06",
      "date_prefix": "2024-08",
      "techniques": [
        "OAK-T10.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-08-ronin-bridge-upgrade.md"
    },
    {
      "id": "2024-09-banana-gun",
      "file": "2024-09-banana-gun.md",
      "title": "Banana Gun oracle-messenger information leak — Ethereum — 2024-09-19",
      "date_prefix": "2024-09",
      "techniques": [
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-09-banana-gun.md"
    },
    {
      "id": "2024-09-bingx",
      "file": "2024-09-bingx.md",
      "title": "BingX hot-wallet drain — multi-chain — 2024-09-20",
      "date_prefix": "2024-09",
      "techniques": [
        "OAK-T11",
        "OAK-T7.001",
        "OAK-T8.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-09-bingx.md"
    },
    {
      "id": "2024-09-deltaprime",
      "file": "2024-09-deltaprime.md",
      "title": "DeltaPrime admin-key compromise + malicious upgrade — Arbitrum + Avalanche — 2024-09-16/17",
      "date_prefix": "2024-09",
      "techniques": [
        "OAK-T11",
        "OAK-T7.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-09-deltaprime.md"
    },
    {
      "id": "2024-09-dexx-cohort",
      "file": "2024-09-dexx-cohort.md",
      "title": "DEXX trading-bot platform compromise cohort — Solana + EVM — 2024-09 to 2024-11",
      "date_prefix": "2024-09",
      "techniques": [
        "OAK-T11.012",
        "OAK-T15.003",
        "OAK-T4.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-09-dexx-cohort.md"
    },
    {
      "id": "2024-09-ens-dao-delegation-concentration",
      "file": "2024-09-ens-dao-delegation-concentration.md",
      "title": "ENS DAO delegation-concentration governance dynamics — delegate voting-weight accumulation and proposal-outcome influence — Ethereum — 2023–2024",
      "date_prefix": "2024-09",
      "techniques": [
        "OAK-T16.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-09-ens-dao-delegation-concentration.md"
    },
    {
      "id": "2024-09-indodax",
      "file": "2024-09-indodax.md",
      "title": "Indodax hot-wallet drain — multi-chain — 2024-09-11",
      "date_prefix": "2024-09",
      "techniques": [
        "OAK-T11",
        "OAK-T7.001",
        "OAK-T7.003"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-09-indodax.md"
    },
    {
      "id": "2024-09-onyx",
      "file": "2024-09-onyx.md",
      "title": "Onyx Protocol empty-market rounding exploit — Ethereum — 2024-09-26",
      "date_prefix": "2024-09",
      "techniques": [
        "OAK-T7.001",
        "OAK-T9.002",
        "OAK-T9.005",
        "OAK-T9.007"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-09-onyx.md"
    },
    {
      "id": "2024-09-penpie",
      "file": "2024-09-penpie.md",
      "title": "Penpie Finance reward-claim exploit — Ethereum + Arbitrum — 2024-09-03",
      "date_prefix": "2024-09",
      "techniques": [
        "OAK-T7.001",
        "OAK-T9.002",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-09-penpie.md"
    },
    {
      "id": "2024-09-polymarket-magic-labs-takeover",
      "file": "2024-09-polymarket-magic-labs-takeover.md",
      "title": "Polymarket account takeover via third-party auth — Polygon — 2024-09",
      "date_prefix": "2024-09",
      "techniques": [
        "OAK-T11.008"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-09-polymarket-magic-labs-takeover.md"
    },
    {
      "id": "2024-09-solana-permanent-delegate-burn-on-buy-cohort",
      "file": "2024-09-solana-permanent-delegate-burn-on-buy-cohort.md",
      "title": "Solana Token-2022 PermanentDelegate burn-on-buy cohort — Solana — 2024-09 onward",
      "date_prefix": "2024-09",
      "techniques": [
        "OAK-T1.002",
        "OAK-T6"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-09-solana-permanent-delegate-burn-on-buy-cohort.md"
    },
    {
      "id": "2024-09-solana-token-2022-permanent-delegate-cohort",
      "file": "2024-09-solana-token-2022-permanent-delegate-cohort.md",
      "title": "Solana Token-2022 PermanentDelegate malicious-exercise cohort — Solana — 2024–2025",
      "date_prefix": "2024-09",
      "techniques": [
        "OAK-T1.002",
        "OAK-T1.006",
        "OAK-T5.001",
        "OAK-T6"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-09-solana-token-2022-permanent-delegate-cohort.md"
    },
    {
      "id": "2024-09-walletconnect-google-play-drainer",
      "file": "2024-09-walletconnect-google-play-drainer.md",
      "title": "WalletConnect-impersonating Google Play mobile drainer — Android/multi-chain — 2024-03 to 2024-09",
      "date_prefix": "2024-09",
      "techniques": [
        "OAK-T4.004",
        "OAK-T4.006",
        "OAK-T6.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-09-walletconnect-google-play-drainer.md"
    },
    {
      "id": "2024-10-ethereum-block-proposer-griefing",
      "file": "2024-10-ethereum-block-proposer-griefing.md",
      "title": "Ethereum block-proposer griefing via targeted missed-slot campaign — Ethereum L1 — 2024-10",
      "date_prefix": "2024-10",
      "techniques": [
        "OAK-T14.005",
        "OAK-T14.006"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-10-ethereum-block-proposer-griefing.md"
    },
    {
      "id": "2024-10-inferno-drainer-handover",
      "file": "2024-10-inferno-drainer-handover.md",
      "title": "Inferno Drainer service ecosystem — multi-chain — operating ~2022 through November 2023 (Telegram-announced shutdown; affiliate / kit re-emergence under successor branding)",
      "date_prefix": "2024-10",
      "techniques": [
        "OAK-T4.001",
        "OAK-T4.002",
        "OAK-T4.004",
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T8.001",
        "OAK-T8.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-10-inferno-drainer-handover.md"
    },
    {
      "id": "2024-10-operation-token-mirrors-nexfundai",
      "file": "2024-10-operation-token-mirrors-nexfundai.md",
      "title": "Operation Token Mirrors — FBI NexFundAI sting against crypto market-maker wash-trading-as-pump cohort — multi-CEX (centred on FBI-deployed token, NexFundAI on Ethereum) — initial charges 2024-10-09; guilty pleas + sentencings through 2025–2026",
      "date_prefix": "2024-10",
      "techniques": [
        "OAK-T3.002",
        "OAK-T3.003",
        "OAK-T6"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-10-operation-token-mirrors-nexfundai.md"
    },
    {
      "id": "2024-10-radiant-capital",
      "file": "2024-10-radiant-capital.md",
      "title": "Radiant Capital cross-chain lending compromise — Arbitrum / BNB Chain — 2024-10-16",
      "date_prefix": "2024-10",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.001",
        "OAK-T15.003",
        "OAK-T7.003",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-10-radiant-capital.md"
    },
    {
      "id": "2024-10-sharpei-solana-funnel-collapse-rug",
      "file": "2024-10-sharpei-solana-funnel-collapse-rug.md",
      "title": "$SHAR / Sharpei Solana memecoin funnel-collapse rug — Solana — 2024-10-23/24",
      "date_prefix": "2024-10",
      "techniques": [
        "OAK-T2.001",
        "OAK-T3.001",
        "OAK-T3.004",
        "OAK-T5.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-10-sharpei-solana-funnel-collapse-rug.md"
    },
    {
      "id": "2024-10-tapioca",
      "file": "2024-10-tapioca.md",
      "title": "Tapioca DAO DSO logic flaw + key compromise — Arbitrum — 2024-10-18",
      "date_prefix": "2024-10",
      "techniques": [
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-10-tapioca.md"
    },
    {
      "id": "2024-11-makerdao-snapshot-governance-endgame-dispute",
      "file": "2024-11-makerdao-snapshot-governance-endgame-dispute.md",
      "title": "MakerDAO Endgame Snapshot governance legitimacy dispute — off-chain signal-vote treated as binding for multi-billion-dollar protocol restructuring — Ethereum — 2024-11",
      "date_prefix": "2024-11",
      "techniques": [
        "OAK-T16.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-11-makerdao-snapshot-governance-endgame-dispute.md"
    },
    {
      "id": "2024-11-thala",
      "file": "2024-11-thala.md",
      "title": "Thala Labs farming-contract Move-language flaw — Aptos — 2024-11-15",
      "date_prefix": "2024-11",
      "techniques": [
        "OAK-T9.004"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-11-thala.md"
    },
    {
      "id": "2024-12-hawk-tuah-celebrity-memecoin",
      "file": "2024-12-hawk-tuah-celebrity-memecoin.md",
      "title": "$HAWK / Hawk Tuah celebrity-memecoin sniper-distribution pump-and-dump — Solana — 2024-12",
      "date_prefix": "2024-12",
      "techniques": [
        "OAK-T1.004",
        "OAK-T17.001",
        "OAK-T3.001",
        "OAK-T3.004",
        "OAK-T5.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-12-hawk-tuah-celebrity-memecoin.md"
    },
    {
      "id": "2024-12-movement-move-otc-dump",
      "file": "2024-12-movement-move-otc-dump.md",
      "title": "Movement Network ($MOVE) market-maker insider dump — Binance / Coinbase — 2024-12",
      "date_prefix": "2024-12",
      "techniques": [
        "OAK-T1.004",
        "OAK-T5.005",
        "OAK-T6.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-12-movement-move-otc-dump.md"
    },
    {
      "id": "2024-12-pimlico-erc20-paymaster-permit-cross-chain-replay",
      "file": "2024-12-pimlico-erc20-paymaster-permit-cross-chain-replay.md",
      "title": "Pimlico ERC-20 Paymaster EIP-2612 Permit Cross-Chain Replay — Late 2024 — $0 (patched)",
      "date_prefix": "2024-12",
      "techniques": [
        "OAK-T10.003",
        "OAK-T13.001",
        "OAK-T13.001.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-12-pimlico-erc20-paymaster-permit-cross-chain-replay.md"
    },
    {
      "id": "2024-12-pudgy-penguins-google-ads-nft-drainer",
      "file": "2024-12-pudgy-penguins-google-ads-nft-drainer.md",
      "title": "Pudgy Penguins Google-Ads NFT-drainer phishing campaign — multi-chain (Ethereum-NFT-centric) — 2024-12",
      "date_prefix": "2024-12",
      "techniques": [
        "OAK-T12.002",
        "OAK-T4.005",
        "OAK-T4.008",
        "OAK-T6"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-12-pudgy-penguins-google-ads-nft-drainer.md"
    },
    {
      "id": "2024-12-solana-web3js-npm-supply-chain",
      "file": "2024-12-solana-web3js-npm-supply-chain.md",
      "title": "`@solana/web3.js` npm supply-chain compromise — Solana — 2024-12-03",
      "date_prefix": "2024-12",
      "techniques": [
        "OAK-T11.002",
        "OAK-T15.001",
        "OAK-T15.002",
        "OAK-T15.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-12-solana-web3js-npm-supply-chain.md"
    },
    {
      "id": "2024-12-targeted-x-account-phishing-15-accounts",
      "file": "2024-12-targeted-x-account-phishing-15-accounts.md",
      "title": "Organization-Targeted Phishing — 15+ X Accounts Compromised via Email Phishing — 2024-12",
      "date_prefix": "2024-12",
      "techniques": [
        "OAK-T15.005",
        "OAK-T15.006"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-12-targeted-x-account-phishing-15-accounts.md"
    },
    {
      "id": "2024-2025-doj-sec-pig-butchering-enforcement-cohort",
      "file": "2024-2025-doj-sec-pig-butchering-enforcement-cohort.md",
      "title": "DOJ/SEC Pig-Butchering Platform Enforcement Cohort — 2024–2025",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T11.005.001",
        "OAK-T8.001",
        "OAK-T8.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-2025-doj-sec-pig-butchering-enforcement-cohort.md"
    },
    {
      "id": "2024-2025-eigenlayer-airdrop-staking-frontend-phishing-cohort",
      "file": "2024-2025-eigenlayer-airdrop-staking-frontend-phishing-cohort.md",
      "title": "EigenLayer restaking-frontend phishing cohort — Ethereum — 2024–2025",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T3.005",
        "OAK-T4.002",
        "OAK-T4.009"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-2025-eigenlayer-airdrop-staking-frontend-phishing-cohort.md"
    },
    {
      "id": "2024-2025-eigenlayer-restaking-deposit-caps-lrt-nav-dilution",
      "file": "2024-2025-eigenlayer-restaking-deposit-caps-lrt-nav-dilution.md",
      "title": "EigenLayer Restaking Deposit Caps and LRT NAV Dilution — Ethereum L1 — 2024–2025",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T14.003",
        "OAK-T14.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-2025-eigenlayer-restaking-deposit-caps-lrt-nav-dilution.md"
    },
    {
      "id": "2024-2025-eip7702-delegation-abuse-research-advisory-cohort",
      "file": "2024-2025-eip7702-delegation-abuse-research-advisory-cohort.md",
      "title": "EIP-7702 delegation abuse research and advisory cohort — Ethereum / multi-chain — 2024–2025 (pre-deployment and post-deployment advisory class)",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T13.004",
        "OAK-T4.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-2025-eip7702-delegation-abuse-research-advisory-cohort.md"
    },
    {
      "id": "2024-2025-john-daghita-gov-seizure-theft",
      "file": "2024-2025-john-daghita-gov-seizure-theft.md",
      "title": "John Daghita (\"Lick\") — US Government Seizure Address Theft — 2024–2025",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T8.001",
        "OAK-T8.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-2025-john-daghita-gov-seizure-theft.md"
    },
    {
      "id": "2024-2025-jupiter-dca-solana-twap-oracle-manipulation",
      "file": "2024-2025-jupiter-dca-solana-twap-oracle-manipulation.md",
      "title": "Jupiter DCA TWAP oracle manipulation on Solana — Solana — 2024–2025",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T17.004",
        "OAK-T17.005",
        "OAK-T9.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-2025-jupiter-dca-solana-twap-oracle-manipulation.md"
    },
    {
      "id": "2024-2025-polymarket-spec-ambiguity-dispute-cohort",
      "file": "2024-2025-polymarket-spec-ambiguity-dispute-cohort.md",
      "title": "Polymarket Spec-Ambiguity Resolution Dispute Cohort — 2024–2025",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T9.006",
        "OAK-T9.006.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-2025-polymarket-spec-ambiguity-dispute-cohort.md"
    },
    {
      "id": "2024-2025-pump-fun-bonding-curve-rug-cohort",
      "file": "2024-2025-pump-fun-bonding-curve-rug-cohort.md",
      "title": "Pump.fun bonding-curve memecoin rug-pull cohort — Solana — 2024-2025",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T2.004",
        "OAK-T3.001",
        "OAK-T5.001",
        "OAK-T6"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-2025-pump-fun-bonding-curve-rug-cohort.md"
    },
    {
      "id": "2024-2025-pump-fun-solana-launch-sniping",
      "file": "2024-2025-pump-fun-solana-launch-sniping.md",
      "title": "Pump.fun / Solana token-launch MEV sniping cohort — Solana — 2024–2025",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T5.004",
        "OAK-T9.012"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-2025-pump-fun-solana-launch-sniping.md"
    },
    {
      "id": "2024-2025-rocket-pool-rpl-staking-phishing-cohort",
      "file": "2024-2025-rocket-pool-rpl-staking-phishing-cohort.md",
      "title": "Rocket Pool fake-staking-frontend phishing campaigns — Ethereum — 2024–2025",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T3.005",
        "OAK-T4.002",
        "OAK-T4.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-2025-rocket-pool-rpl-staking-phishing-cohort.md"
    },
    {
      "id": "2024-2025-safe-4337-module-integration-security-issues",
      "file": "2024-2025-safe-4337-module-integration-security-issues.md",
      "title": "Safe {Wallet} ERC-4337 Module Integration Security Issues — 2024–2025 — $0 (audit disclosures)",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T13.001.002",
        "OAK-T13.001.003",
        "OAK-T15"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-2025-safe-4337-module-integration-security-issues.md"
    },
    {
      "id": "2024-2025-solana-token-2022-multi-extension-scam-cohort",
      "file": "2024-2025-solana-token-2022-multi-extension-scam-cohort.md",
      "title": "Solana Token-2022 Multi-Extension Scam Token Cohort — 2024–2025 — Aggregate $150M+",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T1.002",
        "OAK-T1.005",
        "OAK-T1.007"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-2025-solana-token-2022-multi-extension-scam-cohort.md"
    },
    {
      "id": "2024-2025-swapkit-router-impersonator-phishing",
      "file": "2024-2025-swapkit-router-impersonator-phishing.md",
      "title": "SwapKit router impersonator phishing cohort — EVM — 2024–2025",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T4.008",
        "OAK-T6.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-2025-swapkit-router-impersonator-phishing.md"
    },
    {
      "id": "2024-2025-token-2022-transfer-hook-class-vulnerability",
      "file": "2024-2025-token-2022-transfer-hook-class-vulnerability.md",
      "title": "Solana Token-2022 transfer-hook class vulnerability and ZK-ElGamal proof zero-day — Solana — 2024-2025",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T1.007",
        "OAK-T6"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-2025-token-2022-transfer-hook-class-vulnerability.md"
    },
    {
      "id": "2024-2025-uniswap-permit2-phishing-cohort",
      "file": "2024-2025-uniswap-permit2-phishing-cohort.md",
      "title": "Uniswap Permit2 Phishing Cohort — Ethereum / multi-chain EVM — 2024–2025",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T4.001",
        "OAK-T4.002",
        "OAK-T6.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-2025-uniswap-permit2-phishing-cohort.md"
    },
    {
      "id": "2024-2025-us-treasury-ofac-blockchain-analytics-tooling-cohort",
      "file": "2024-2025-us-treasury-ofac-blockchain-analytics-tooling-cohort.md",
      "title": "US Treasury OFAC/IRS-CI blockchain analytics deployment — chain-agnostic — 2024–2025",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T7.009",
        "OAK-T8.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-2025-us-treasury-ofac-blockchain-analytics-tooling-cohort.md"
    },
    {
      "id": "2024-2026-cross-chain-bridge-observer-signature-scope-audit",
      "file": "2024-2026-cross-chain-bridge-observer-signature-scope-audit.md",
      "title": "Cross-Chain Bridge Observer Signature Scope Audit — 2024–2026",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T10.002",
        "OAK-T10.008"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-2026-cross-chain-bridge-observer-signature-scope-audit.md"
    },
    {
      "id": "2024-2026-embedded-wallet-and-trader-tooling-supply-chain-cohort",
      "file": "2024-2026-embedded-wallet-and-trader-tooling-supply-chain-cohort.md",
      "title": "Embedded-Wallet and Trader-Tooling Supply-Chain Compromise Cohort — 2024–2026",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T11.008",
        "OAK-T11.009"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-2026-embedded-wallet-and-trader-tooling-supply-chain-cohort.md"
    },
    {
      "id": "2024-2026-nft-marketplace-insider-trading-wash-trading",
      "file": "2024-2026-nft-marketplace-insider-trading-wash-trading.md",
      "title": "NFT Marketplace Insider Trading and Wash-Trading Infrastructure — 2024–2026 — structural",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T12.001",
        "OAK-T12.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-2026-nft-marketplace-insider-trading-wash-trading.md"
    },
    {
      "id": "2024-2026-solana-npm-trader-key-exfiltration",
      "file": "2024-2026-solana-npm-trader-key-exfiltration.md",
      "title": "Solana / multi-chain npm trader-tooling supply-chain key exfiltration cohort — Solana / EVM — 2024–2026",
      "date_prefix": "2024-20",
      "techniques": [
        "OAK-T11.009",
        "OAK-T15.002"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2024-2026-solana-npm-trader-key-exfiltration.md"
    },
    {
      "id": "2024-Q4-honeypot-token-cohort-cross-chain",
      "file": "2024-Q4-honeypot-token-cohort-cross-chain.md",
      "title": "Honeypot token cohort — cross-chain — 2024 Q4",
      "date_prefix": "2024",
      "techniques": [
        "OAK-T1.004",
        "OAK-T1.005",
        "OAK-T1.006"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-Q4-honeypot-token-cohort-cross-chain.md"
    },
    {
      "id": "2024-bittensor-insider-hack-nft-forensics",
      "file": "2024-bittensor-insider-hack-nft-forensics.md",
      "title": "Bittensor — Insider-Linked Exploit / Whitehat Recovery — 2024 / 2025-10",
      "date_prefix": "2024",
      "techniques": [
        "OAK-T8.001",
        "OAK-T8.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-bittensor-insider-hack-nft-forensics.md"
    },
    {
      "id": "2024-chainalysis-laundering-report-aggregator-cohort",
      "file": "2024-chainalysis-laundering-report-aggregator-cohort.md",
      "title": "Chainalysis laundering report — DEX aggregator routing cohort — 2024",
      "date_prefix": "2024",
      "techniques": [
        "OAK-T7.007"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-chainalysis-laundering-report-aggregator-cohort.md"
    },
    {
      "id": "2024-chainalysis-laundering-report-issuer-selection",
      "file": "2024-chainalysis-laundering-report-issuer-selection.md",
      "title": "Chainalysis laundering report — stablecoin issuer-selection laundering — 2024",
      "date_prefix": "2024",
      "techniques": [
        "OAK-T7.008"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-chainalysis-laundering-report-issuer-selection.md"
    },
    {
      "id": "2024-curio-makerdao-fork-chain",
      "file": "2024-curio-makerdao-fork-chain.md",
      "title": "Curio DAO MakerDAO fork-chain governance exploit — Ethereum — 2024-03",
      "date_prefix": "2024",
      "techniques": [
        "OAK-T16.002",
        "OAK-T9.003",
        "OAK-T9.007"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-curio-makerdao-fork-chain.md"
    },
    {
      "id": "2024-eigenlayer-restaking-airdrop",
      "file": "2024-eigenlayer-restaking-airdrop.md",
      "title": "EigenLayer restaking airdrop — AVS slashing and cascading-risk context — 2024",
      "date_prefix": "2024",
      "techniques": [
        "OAK-T14.001",
        "OAK-T14.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-eigenlayer-restaking-airdrop.md"
    },
    {
      "id": "2024-eigenlayer-token-anticipation-phishing",
      "file": "2024-eigenlayer-token-anticipation-phishing.md",
      "title": "EigenLayer token-anticipation phishing campaign — 2024",
      "date_prefix": "2024",
      "techniques": [
        "OAK-T4.009"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2024-eigenlayer-token-anticipation-phishing.md"
    },
    {
      "id": "2024-fake-ledger-live-microsoft-store",
      "file": "2024-fake-ledger-live-microsoft-store.md",
      "title": "Fake Ledger Live — Microsoft App Store — 2023-11",
      "date_prefix": "2024",
      "techniques": [
        "OAK-T4.010",
        "OAK-T6"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-fake-ledger-live-microsoft-store.md"
    },
    {
      "id": "2024-murad-memecoin-insider-wallets",
      "file": "2024-murad-memecoin-insider-wallets.md",
      "title": "Murad — $24M Meme Coin Insider Wallet Cluster — 2024",
      "date_prefix": "2024",
      "techniques": [
        "OAK-T3.003",
        "OAK-T8.001",
        "OAK-T8.002"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-murad-memecoin-insider-wallets.md"
    },
    {
      "id": "2024-onyx-protocol-year-plus-exposure",
      "file": "2024-onyx-protocol-year-plus-exposure.md",
      "title": "Onyx Protocol year-plus fork-vulnerability exposure — Ethereum — 2024",
      "date_prefix": "2024",
      "techniques": [
        "OAK-T9.004",
        "OAK-T9.007"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-onyx-protocol-year-plus-exposure.md"
    },
    {
      "id": "2024-post-tornado-defi-yield-laundering",
      "file": "2024-post-tornado-defi-yield-laundering.md",
      "title": "Post-Tornado-Cash DeFi yield-protocol laundering shift — cross-chain — 2024",
      "date_prefix": "2024",
      "techniques": [
        "OAK-T7.003",
        "OAK-T7.006"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2024-post-tornado-defi-yield-laundering.md"
    },
    {
      "id": "2024-sonne-finance-14-month-exposure",
      "file": "2024-sonne-finance-14-month-exposure.md",
      "title": "Sonne Finance 14-month fork-vulnerability exposure — Optimism — 2024-05-14",
      "date_prefix": "2024",
      "techniques": [
        "OAK-T9.004",
        "OAK-T9.007"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2024-sonne-finance-14-month-exposure.md"
    },
    {
      "id": "2025-01-bullx-solana-launch-sandwich-cohort",
      "file": "2025-01-bullx-solana-launch-sandwich-cohort.md",
      "title": "BullX / Solana token-launch MEV sandwich cohort — Solana — 2025",
      "date_prefix": "2025-01",
      "techniques": [
        "OAK-T9.012"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-01-bullx-solana-launch-sandwich-cohort.md"
    },
    {
      "id": "2025-01-counterfeit-ledger-nano-s-plus-cohort",
      "file": "2025-01-counterfeit-ledger-nano-s-plus-cohort.md",
      "title": "Counterfeit Ledger Nano S Plus hardware-wallet supply-chain compromise cohort — multi-chain — 2025 (cohort surfacing)",
      "date_prefix": "2025-01",
      "techniques": [
        "OAK-T11.007",
        "OAK-T11.007.001",
        "OAK-T7.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2025-01-counterfeit-ledger-nano-s-plus-cohort.md"
    },
    {
      "id": "2025-01-hayden-davis-kelsier-cluster",
      "file": "2025-01-hayden-davis-kelsier-cluster.md",
      "title": "Hayden Davis / Kelsier Ventures memecoin operator-cluster cohort — Solana — 2025-Q1",
      "date_prefix": "2025-01",
      "techniques": [
        "OAK-T1.003",
        "OAK-T3.001",
        "OAK-T3.004",
        "OAK-T5",
        "OAK-T6",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2025-01-hayden-davis-kelsier-cluster.md"
    },
    {
      "id": "2025-01-huione-guarantee-fake-cex",
      "file": "2025-01-huione-guarantee-fake-cex.md",
      "title": "Huione Guarantee fake-CEX / pig-butchering platform — Southeast Asia / multi-chain — 2025",
      "date_prefix": "2025-01",
      "techniques": [
        "OAK-T11.005.001",
        "OAK-T11.005.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2025-01-huione-guarantee-fake-cex.md"
    },
    {
      "id": "2025-01-hyperliquid-dex-brand-impersonation-custodial-soft-rug-cohort",
      "file": "2025-01-hyperliquid-dex-brand-impersonation-custodial-soft-rug-cohort.md",
      "title": "Hyperliquid / DEX brand-impersonation custodial soft-rug cohort — multi-chain (Arbitrum, EVM) — 2025",
      "date_prefix": "2025-01",
      "techniques": [
        "OAK-T5.007"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-01-hyperliquid-dex-brand-impersonation-custodial-soft-rug-cohort.md"
    },
    {
      "id": "2025-01-hyperliquid-trading-bot-malware-campaign",
      "file": "2025-01-hyperliquid-trading-bot-malware-campaign.md",
      "title": "Hyperliquid trading-bot malware campaign — Arbitrum / Hyperliquid — 2025",
      "date_prefix": "2025-01",
      "techniques": [
        "OAK-T11.009",
        "OAK-T4.010"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-01-hyperliquid-trading-bot-malware-campaign.md"
    },
    {
      "id": "2025-01-ledger-cofounder-balland-kidnapping",
      "file": "2025-01-ledger-cofounder-balland-kidnapping.md",
      "title": "David Balland (Ledger co-founder) kidnapping — crypto ransom, France — 2025-01",
      "date_prefix": "2025-01",
      "techniques": [
        "OAK-T5.009",
        "OAK-T7",
        "OAK-T8.005"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2025-01-ledger-cofounder-balland-kidnapping.md"
    },
    {
      "id": "2025-01-mango-markets-shutdown",
      "file": "2025-01-mango-markets-shutdown.md",
      "title": "Mango Markets SEC settlement and protocol shutdown — Solana — 2024-09 to 2025-01",
      "date_prefix": "2025-01",
      "techniques": [
        "OAK-T6.007",
        "OAK-T9.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2025-01-mango-markets-shutdown.md"
    },
    {
      "id": "2025-01-mev-boost-relay-censorship",
      "file": "2025-01-mev-boost-relay-censorship.md",
      "title": "MEV-Boost relay censorship and OFAC-compliance validator concentration — Ethereum — 2025",
      "date_prefix": "2025-01",
      "techniques": [
        "OAK-T14.002",
        "OAK-T14.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2025-01-mev-boost-relay-censorship.md"
    },
    {
      "id": "2025-01-phemex",
      "file": "2025-01-phemex.md",
      "title": "Phemex hot-wallet theft — multi-chain — 2025-01-23",
      "date_prefix": "2025-01",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T7.008",
        "OAK-T8.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2025-01-phemex.md"
    },
    {
      "id": "2025-01-polymarket-us-election-insider-trading-cohort",
      "file": "2025-01-polymarket-us-election-insider-trading-cohort.md",
      "title": "Polymarket US election operational-insider trading cohort — multi-chain — 2025",
      "date_prefix": "2025-01",
      "techniques": [
        "OAK-T9.006.004"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2025-01-polymarket-us-election-insider-trading-cohort.md"
    },
    {
      "id": "2025-01-prediction-market-journalist-safety-cohort",
      "file": "2025-01-prediction-market-journalist-safety-cohort.md",
      "title": "Prediction-market journalist safety / resolution-source intimidation cohort — global — 2025–2026",
      "date_prefix": "2025-01",
      "techniques": [
        "OAK-T9.006",
        "OAK-T9.006.003"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2025-01-prediction-market-journalist-safety-cohort.md"
    },
    {
      "id": "2025-01-solana-nft-x-account-drainer-cohort",
      "file": "2025-01-solana-nft-x-account-drainer-cohort.md",
      "title": "Solana NFT X-account-compromise fake-mint drainer cohort — Solana — 2025-Q1",
      "date_prefix": "2025-01",
      "techniques": [
        "OAK-T12.002",
        "OAK-T15.001",
        "OAK-T4.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-01-solana-nft-x-account-drainer-cohort.md"
    },
    {
      "id": "2025-01-trump-melania-presidential-memecoin",
      "file": "2025-01-trump-melania-presidential-memecoin.md",
      "title": "$TRUMP and $MELANIA presidential / first-spouse memecoin launches — Solana — 2025-01",
      "date_prefix": "2025-01",
      "techniques": [
        "OAK-T1.004",
        "OAK-T17.001",
        "OAK-T3.001",
        "OAK-T3.004",
        "OAK-T5.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2025-01-trump-melania-presidential-memecoin.md"
    },
    {
      "id": "2025-02-bybit-thorchain-laundering",
      "file": "2025-02-bybit-thorchain-laundering.md",
      "title": "Bybit aftermath — \\$1.4B THORChain laundering — Ethereum → BTC / DAI — 2025-02 to 2025-03",
      "date_prefix": "2025-02",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T7.007"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-02-bybit-thorchain-laundering.md"
    },
    {
      "id": "2025-02-bybit",
      "file": "2025-02-bybit.md",
      "title": "Bybit cold-wallet theft — Ethereum — 2025-02-21",
      "date_prefix": "2025-02",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.001",
        "OAK-T15.002",
        "OAK-T15.003",
        "OAK-T7.003",
        "OAK-T7.007",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2025-02-bybit.md"
    },
    {
      "id": "2025-02-cardex-session-key-frontend-leak",
      "file": "2025-02-cardex-session-key-frontend-leak.md",
      "title": "Cardex session-signer-key frontend leak — Abstract Chain — 2025-02-18",
      "date_prefix": "2025-02",
      "techniques": [
        "OAK-T13.003",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-02-cardex-session-key-frontend-leak.md"
    },
    {
      "id": "2025-02-infini",
      "file": "2025-02-infini.md",
      "title": "Infini neobank treasury drain — Ethereum / multi-chain — 2025-02-24",
      "date_prefix": "2025-02",
      "techniques": [
        "OAK-T11.002",
        "OAK-T9.004"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2025-02-infini.md"
    },
    {
      "id": "2025-02-libra-milei-presidential-pump-dump",
      "file": "2025-02-libra-milei-presidential-pump-dump.md",
      "title": "$LIBRA / Milei presidential-endorsement pump-and-dump — Solana — 2025-02",
      "date_prefix": "2025-02",
      "techniques": [
        "OAK-T1.004",
        "OAK-T3.001",
        "OAK-T3.004",
        "OAK-T5.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2025-02-libra-milei-presidential-pump-dump.md"
    },
    {
      "id": "2025-02-solana-x-account-compromise-cohort",
      "file": "2025-02-solana-x-account-compromise-cohort.md",
      "title": "Solana brand-X-account compromise cohort (Jupiter / Pump.fun / DogWifCoin) — Solana — 2024-11 to 2025-02",
      "date_prefix": "2025-02",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.005",
        "OAK-T15.006",
        "OAK-T4",
        "OAK-T7"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-02-solana-x-account-compromise-cohort.md"
    },
    {
      "id": "2025-02-wemix-play-bridge-vault-shared-repo-key-compromise",
      "file": "2025-02-wemix-play-bridge-vault-shared-repo-key-compromise.md",
      "title": "WEMIX — a developer uploads NFT-platform monitoring keys to a shared repository for convenience, and two months later 13 of 15 withdrawals empty the Play Bridge Vault — WEMIX / Wemade (Play Bridge Vault) — 2025-02-28",
      "date_prefix": "2025-02",
      "techniques": [
        "OAK-T10.001",
        "OAK-T15.004",
        "OAK-T5.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2025-02-wemix-play-bridge-vault-shared-repo-key-compromise.md"
    },
    {
      "id": "2025-02-zklend",
      "file": "2025-02-zklend.md",
      "title": "zkLend empty-market rounding-error exploit — Starknet — 2025-02-12",
      "date_prefix": "2025-02",
      "techniques": [
        "OAK-T7.001",
        "OAK-T9.002",
        "OAK-T9.005",
        "OAK-T9.007",
        "OAK-T9.011"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-02-zklend.md"
    },
    {
      "id": "2025-03-1inch-resolver",
      "file": "2025-03-1inch-resolver.md",
      "title": "1inch resolver-contract patch-not-propagated exploit — Ethereum + BNB Chain — 2025-03-05",
      "date_prefix": "2025-03",
      "techniques": [
        "OAK-T7.007",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-03-1inch-resolver.md"
    },
    {
      "id": "2025-03-hyperliquid-jelly-self-liquidation-cross-venue",
      "file": "2025-03-hyperliquid-jelly-self-liquidation-cross-venue.md",
      "title": "Hyperliquid JELLY self-liquidation + cross-venue spot-pump cascade — Hyperliquid (HyperEVM L1) + Solana spot — 2025-03-26",
      "date_prefix": "2025-03",
      "techniques": [
        "OAK-T17.001",
        "OAK-T17.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-03-hyperliquid-jelly-self-liquidation-cross-venue.md"
    },
    {
      "id": "2025-03-hyperliquid-whale-illicit-trading",
      "file": "2025-03-hyperliquid-whale-illicit-trading.md",
      "title": "Hyperliquid Whale — Illicit Trading via Highly Leveraged Positions — 2025-03",
      "date_prefix": "2025-03",
      "techniques": [
        "OAK-T8.001"
      ],
      "attribution": "inferred-weak",
      "source_file": "examples/2025-03-hyperliquid-whale-illicit-trading.md"
    },
    {
      "id": "2025-03-polymarket-uma-ukraine-mineral-deal",
      "file": "2025-03-polymarket-uma-ukraine-mineral-deal.md",
      "title": "Polymarket UMA governance attack — Ukraine mineral deal market — 2025-03",
      "date_prefix": "2025-03",
      "techniques": [
        "OAK-T9.006",
        "OAK-T9.006.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2025-03-polymarket-uma-ukraine-mineral-deal.md"
    },
    {
      "id": "2025-03-solflare-base-x-homograph-cve",
      "file": "2025-03-solflare-base-x-homograph-cve.md",
      "title": "Solflare base-x library homograph-attack vulnerability (CVE-2025-27611) — Solana — 2025-03",
      "date_prefix": "2025-03",
      "techniques": [
        "OAK-T11.002",
        "OAK-T4.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2025-03-solflare-base-x-homograph-cve.md"
    },
    {
      "id": "2025-03-sushiswap-delegation-governance-takeover",
      "file": "2025-03-sushiswap-delegation-governance-takeover.md",
      "title": "SushiSwap delegation-cluster governance takeover — Ethereum — 2025-03 to 2025-04",
      "date_prefix": "2025-03",
      "techniques": [
        "OAK-T16.002",
        "OAK-T16.003",
        "OAK-T8.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2025-03-sushiswap-delegation-governance-takeover.md"
    },
    {
      "id": "2025-03-uniswap-routing-manipulation-phishing",
      "file": "2025-03-uniswap-routing-manipulation-phishing.md",
      "title": "Uniswap routing-manipulation frontend phishing cohort — EVM — 2025",
      "date_prefix": "2025-03",
      "techniques": [
        "OAK-T4.008",
        "OAK-T6.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-03-uniswap-routing-manipulation-phishing.md"
    },
    {
      "id": "2025-03-zklend",
      "file": "2025-03-zklend.md",
      "title": "zkLend precision-loss collateral-accounting exploit — Starknet — 2025-02-12",
      "date_prefix": "2025-03",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-03-zklend.md"
    },
    {
      "id": "2025-04-3520-btc-instant-exchange-xmr-laundering",
      "file": "2025-04-3520-btc-instant-exchange-xmr-laundering.md",
      "title": "3520 BTC — Instant Exchange → Monero Laundering — 2025-04",
      "date_prefix": "2025-04",
      "techniques": [
        "OAK-T7.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-04-3520-btc-instant-exchange-xmr-laundering.md"
    },
    {
      "id": "2025-04-eigenlayer-mainnet-slashing-launch",
      "file": "2025-04-eigenlayer-mainnet-slashing-launch.md",
      "title": "EigenLayer Mainnet Slashing Launch and AVS Slashing-Condition Activation — Ethereum L1 — 2025-04-17",
      "date_prefix": "2025-04",
      "techniques": [
        "OAK-T14.001",
        "OAK-T14.003",
        "OAK-T14.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2025-04-eigenlayer-mainnet-slashing-launch.md"
    },
    {
      "id": "2025-04-erc4337-paymaster",
      "file": "2025-04-erc4337-paymaster.md",
      "title": "ERC-4337 paymaster compromise cohort — EVM mainnets — 2024–2025 (April 2025 anchor)",
      "date_prefix": "2025-04",
      "techniques": [
        "OAK-T13.001",
        "OAK-T13.001.001",
        "OAK-T13.001.002",
        "OAK-T13.001.003",
        "OAK-T13.001.004",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-04-erc4337-paymaster.md"
    },
    {
      "id": "2025-04-exch-shutdown",
      "file": "2025-04-exch-shutdown.md",
      "title": "eXch instant-exchange shutdown — Bybit-laundering substrate sanctions response — 2025-04 to 2025-05",
      "date_prefix": "2025-04",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T7.005",
        "OAK-T8.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-04-exch-shutdown.md"
    },
    {
      "id": "2025-04-kiloex",
      "file": "2025-04-kiloex.md",
      "title": "KiloEx oracle-feed manipulation — multi-chain (BNB Chain, Base, Manta, Taiko) — 2025-04-14",
      "date_prefix": "2025-04",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-04-kiloex.md"
    },
    {
      "id": "2025-04-loopscale",
      "file": "2025-04-loopscale.md",
      "title": "Loopscale RateX-token-pricing exploit — Solana — 2025-04-26",
      "date_prefix": "2025-04",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-04-loopscale.md"
    },
    {
      "id": "2025-04-mango-markets-solana-governance",
      "file": "2025-04-mango-markets-solana-governance.md",
      "title": "Mango Markets MNGO governance-token expiry and protocol wind-down — Solana — 2025-01 to 2025-04",
      "date_prefix": "2025-04",
      "techniques": [
        "OAK-T16.002",
        "OAK-T5.005",
        "OAK-T9.001"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2025-04-mango-markets-solana-governance.md"
    },
    {
      "id": "2025-04-meteora-m3m3-class-action",
      "file": "2025-04-meteora-m3m3-class-action.md",
      "title": "Meteora M3M3 launch class-action and MET airdrop controversy — Solana — 2024-12 to 2025-10",
      "date_prefix": "2025-04",
      "techniques": [
        "OAK-T1.003",
        "OAK-T2.004",
        "OAK-T5.005",
        "OAK-T6"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2025-04-meteora-m3m3-class-action.md"
    },
    {
      "id": "2025-04-zksync-airdrop",
      "file": "2025-04-zksync-airdrop.md",
      "title": "ZKsync unclaimed-airdrop pool drain — Ethereum / ZKsync Era — 2025-04-15",
      "date_prefix": "2025-04",
      "techniques": [
        "OAK-T11.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-04-zksync-airdrop.md"
    },
    {
      "id": "2025-05-cetus",
      "file": "2025-05-cetus.md",
      "title": "Cetus Protocol concentrated-liquidity overflow exploit — Sui — 2025-05-22",
      "date_prefix": "2025-05",
      "techniques": [
        "OAK-T7.003",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-05-cetus.md"
    },
    {
      "id": "2025-05-eip7702-crimeenjoyor-delegation-phishing-cohort",
      "file": "2025-05-eip7702-crimeenjoyor-delegation-phishing-cohort.md",
      "title": "EIP-7702 CrimeEnjoyor delegation-phishing cohort — Ethereum mainnet — 2025-05 onward",
      "date_prefix": "2025-05",
      "techniques": [
        "OAK-T13",
        "OAK-T13.004",
        "OAK-T4.001",
        "OAK-T7.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2025-05-eip7702-crimeenjoyor-delegation-phishing-cohort.md"
    },
    {
      "id": "2025-05-inferno-drainer-reloaded-encrypted-onchain-config",
      "file": "2025-05-inferno-drainer-reloaded-encrypted-onchain-config.md",
      "title": "Inferno Drainer \"Reloaded\" — encrypted on-chain config + single-use smart contracts + fake CollabLand Discord phishing — multi-chain — September 2024 to March 2025 (Check Point disclosure 2025-05)",
      "date_prefix": "2025-05",
      "techniques": [
        "OAK-T4.001",
        "OAK-T4.005",
        "OAK-T4.008",
        "OAK-T6",
        "OAK-T8.001",
        "OAK-T8.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2025-05-inferno-drainer-reloaded-encrypted-onchain-config.md"
    },
    {
      "id": "2025-06-force-bridge",
      "file": "2025-06-force-bridge.md",
      "title": "Force Bridge admin-key drainage — Ethereum / BNB Chain — 2025-06-01",
      "date_prefix": "2025-06",
      "techniques": [
        "OAK-T10.001",
        "OAK-T7.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-06-force-bridge.md"
    },
    {
      "id": "2025-06-nobitex-hot-wallet-multi-chain-key-compromise",
      "file": "2025-06-nobitex-hot-wallet-multi-chain-key-compromise.md",
      "title": "Nobitex — multi-chain hot-wallet key compromise drains Iran's largest exchange — EVM chains + Tron — 2025-06-18",
      "date_prefix": "2025-06",
      "techniques": [
        "OAK-T11.011",
        "OAK-T11.012",
        "OAK-T15.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-06-nobitex-hot-wallet-multi-chain-key-compromise.md"
    },
    {
      "id": "2025-06-pepe-creator-nft-contract-hijack",
      "file": "2025-06-pepe-creator-nft-contract-hijack.md",
      "title": "Pepe Creator (Matt Furie) NFT contract hijack via fake-IT-worker social engineering — Ethereum — 2025-06-18 to 2025-06-25",
      "date_prefix": "2025-06",
      "techniques": [
        "OAK-T12",
        "OAK-T12.002",
        "OAK-T15.001",
        "OAK-T7.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-06-pepe-creator-nft-contract-hijack.md"
    },
    {
      "id": "2025-06-resupply-finance",
      "file": "2025-06-resupply-finance.md",
      "title": "Resupply Finance wstUSR empty-market donation exploit — Ethereum — 2025-06-26",
      "date_prefix": "2025-06",
      "techniques": [
        "OAK-T7.001",
        "OAK-T9.002",
        "OAK-T9.005",
        "OAK-T9.007"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-06-resupply-finance.md"
    },
    {
      "id": "2025-07-central-bank-brazil-breach-crypto-exit",
      "file": "2025-07-central-bank-brazil-breach-crypto-exit.md",
      "title": "Central Bank of Brazil — Service Provider Breach → Crypto Conversion — 2025-07",
      "date_prefix": "2025-07",
      "techniques": [],
      "attribution": "unattributed",
      "source_file": "examples/2025-07-central-bank-brazil-breach-crypto-exit.md"
    },
    {
      "id": "2025-07-coindcx",
      "file": "2025-07-coindcx.md",
      "title": "CoinDCX operational-wallet drain — Solana — 2025-07-19",
      "date_prefix": "2025-07",
      "techniques": [
        "OAK-T11",
        "OAK-T7.001",
        "OAK-T7.003"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2025-07-coindcx.md"
    },
    {
      "id": "2025-07-crypto-beast-alt-insider-dump",
      "file": "2025-07-crypto-beast-alt-insider-dump.md",
      "title": "ALT Token — Influencer Insider Dump — 2025-07-14",
      "date_prefix": "2025-07",
      "techniques": [
        "OAK-T3.003",
        "OAK-T3.004"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2025-07-crypto-beast-alt-insider-dump.md"
    },
    {
      "id": "2025-07-gmx-v1",
      "file": "2025-07-gmx-v1.md",
      "title": "GMX V1 GLP global-short-tracking exploit — Arbitrum — 2025-07-09",
      "date_prefix": "2025-07",
      "techniques": [
        "OAK-T11.013",
        "OAK-T9.001",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-07-gmx-v1.md"
    },
    {
      "id": "2025-07-lido-steth-aave-cascade",
      "file": "2025-07-lido-steth-aave-cascade.md",
      "title": "Lido stETH / Aave validator-exit-queue and looped-leverage depeg cascade — Ethereum L1 — 2025-07",
      "date_prefix": "2025-07",
      "techniques": [
        "OAK-T14.001",
        "OAK-T14.003",
        "OAK-T14.003.001",
        "OAK-T17.002",
        "OAK-T9.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-07-lido-steth-aave-cascade.md"
    },
    {
      "id": "2025-07-polymarket-zelenskyy-suit",
      "file": "2025-07-polymarket-zelenskyy-suit.md",
      "title": "Polymarket Zelenskyy-suit market — UMA resolution-spec ambiguity — 2025-07",
      "date_prefix": "2025-07",
      "techniques": [
        "OAK-T9.006",
        "OAK-T9.006.002"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2025-07-polymarket-zelenskyy-suit.md"
    },
    {
      "id": "2025-08-btcturk",
      "file": "2025-08-btcturk.md",
      "title": "BtcTurk hot-wallet drain (recurrence) — multi-chain — 2025-08-14",
      "date_prefix": "2025-08",
      "techniques": [
        "OAK-T11",
        "OAK-T7.001",
        "OAK-T8.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-08-btcturk.md"
    },
    {
      "id": "2025-08-erc4337-paymaster-exploit-cohort",
      "file": "2025-08-erc4337-paymaster-exploit-cohort.md",
      "title": "ERC-4337 paymaster exploit cohort — EVM mainnets — 2025-08",
      "date_prefix": "2025-08",
      "techniques": [
        "OAK-T13.001.001",
        "OAK-T13.001.002",
        "OAK-T13.001.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-08-erc4337-paymaster-exploit-cohort.md"
    },
    {
      "id": "2025-08-hypervault-finance-exit-scam",
      "file": "2025-08-hypervault-finance-exit-scam.md",
      "title": "Hypervault Finance exit scam via fake-audit-claims — Hyperliquid / Ethereum — 2025-08",
      "date_prefix": "2025-08",
      "techniques": [
        "OAK-T2.001",
        "OAK-T5.001",
        "OAK-T6.001",
        "OAK-T6.002",
        "OAK-T6.004",
        "OAK-T7.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-08-hypervault-finance-exit-scam.md"
    },
    {
      "id": "2025-09-erc4337-entrypoint-v09-griefing-disclosure",
      "file": "2025-09-erc4337-entrypoint-v09-griefing-disclosure.md",
      "title": "ERC-4337 EntryPoint griefing-vector responsible disclosure (TrustSec / HackenProof / Ethereum Foundation) — coordinated disclosure 2025-09 → patched in v0.9 — 2025",
      "date_prefix": "2025-09",
      "techniques": [
        "OAK-T13.001",
        "OAK-T13.001.004",
        "OAK-T13.002",
        "OAK-T9.005"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2025-09-erc4337-entrypoint-v09-griefing-disclosure.md"
    },
    {
      "id": "2025-09-sbi-crypto",
      "file": "2025-09-sbi-crypto.md",
      "title": "SBI Crypto mining-pool drain — Bitcoin / multi-chain — 2025-09-24",
      "date_prefix": "2025-09",
      "techniques": [
        "OAK-T11.001",
        "OAK-T7.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2025-09-sbi-crypto.md"
    },
    {
      "id": "2025-09-shibarium-bridge",
      "file": "2025-09-shibarium-bridge.md",
      "title": "Shibarium bridge validator-key + flash-loan-amplified PoS-bridge exploit — Ethereum ↔ Shibarium — 2025-09-12",
      "date_prefix": "2025-09",
      "techniques": [
        "OAK-T10.001",
        "OAK-T16.001",
        "OAK-T7.001",
        "OAK-T9.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-09-shibarium-bridge.md"
    },
    {
      "id": "2025-09-ssv-network-mass-slashing",
      "file": "2025-09-ssv-network-mass-slashing.md",
      "title": "SSV Network correlated mass-slashing event — Ethereum Beacon Chain — 2025-09-10",
      "date_prefix": "2025-09",
      "techniques": [
        "OAK-T14.001",
        "OAK-T14.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2025-09-ssv-network-mass-slashing.md"
    },
    {
      "id": "2025-09-swissborg",
      "file": "2025-09-swissborg.md",
      "title": "SwissBorg SOL-Earn third-party-API supply-chain compromise — Solana — 2025-09-08",
      "date_prefix": "2025-09",
      "techniques": [
        "OAK-T11.001",
        "OAK-T15.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-09-swissborg.md"
    },
    {
      "id": "2025-09-uxlink",
      "file": "2025-09-uxlink.md",
      "title": "UXLINK multisig delegate-call hijack — Ethereum / Arbitrum — 2025-09-22",
      "date_prefix": "2025-09",
      "techniques": [
        "OAK-T11.002",
        "OAK-T5.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-09-uxlink.md"
    },
    {
      "id": "2025-10-cyb3rhawk-polymarket-filter-bypass",
      "file": "2025-10-cyb3rhawk-polymarket-filter-bypass.md",
      "title": "Polymarket filter-bypass manipulation — Polygon — 2025-10",
      "date_prefix": "2025-10",
      "techniques": [
        "OAK-T17.001",
        "OAK-T6"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-10-cyb3rhawk-polymarket-filter-bypass.md"
    },
    {
      "id": "2025-10-garden-finance",
      "file": "2025-10-garden-finance.md",
      "title": "Garden Finance solver-key compromise — multi-chain — 2025-10-30",
      "date_prefix": "2025-10",
      "techniques": [
        "OAK-T10.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-10-garden-finance.md"
    },
    {
      "id": "2025-10-huione-compound-fraud-cohort",
      "file": "2025-10-huione-compound-fraud-cohort.md",
      "title": "Huione Group / Prince Group Southeast Asia compound-operated investment-fraud cohort — multi-chain (BTC / ETH / USDT on Tron dominant) — 2020–2025",
      "date_prefix": "2025-10",
      "techniques": [
        "OAK-T11.005",
        "OAK-T11.005.003",
        "OAK-T15",
        "OAK-T7",
        "OAK-T8"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2025-10-huione-compound-fraud-cohort.md"
    },
    {
      "id": "2025-10-polymarket-pre-token-anticipation-phishing",
      "file": "2025-10-polymarket-pre-token-anticipation-phishing.md",
      "title": "Polymarket POLY pre-token brand-anticipation phishing — EVM — 2025-10 onward",
      "date_prefix": "2025-10",
      "techniques": [
        "OAK-T4.008",
        "OAK-T4.009"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-10-polymarket-pre-token-anticipation-phishing.md"
    },
    {
      "id": "2025-11-balancer-v2",
      "file": "2025-11-balancer-v2.md",
      "title": "Balancer V2 ComposableStablePool rounding-error exploit — multi-chain — 2025-11-03",
      "date_prefix": "2025-11",
      "techniques": [
        "OAK-T9.002",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-11-balancer-v2.md"
    },
    {
      "id": "2025-11-hyperliquid-popcat-spoof-and-pull",
      "file": "2025-11-hyperliquid-popcat-spoof-and-pull.md",
      "title": "Hyperliquid POPCAT spoofed-buy-wall + cancel-flood manipulation — Hyperliquid (HyperEVM L1) — 2025-11-12 to 2025-11-13",
      "date_prefix": "2025-11",
      "techniques": [
        "OAK-T17.001",
        "OAK-T17.002",
        "OAK-T17.003",
        "OAK-T8.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2025-11-hyperliquid-popcat-spoof-and-pull.md"
    },
    {
      "id": "2025-11-polymarket-comment-section-phishing",
      "file": "2025-11-polymarket-comment-section-phishing.md",
      "title": "Polymarket comment-section phishing campaign — Polygon — 2025-11",
      "date_prefix": "2025-11",
      "techniques": [
        "OAK-T11.008",
        "OAK-T4.007"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2025-11-polymarket-comment-section-phishing.md"
    },
    {
      "id": "2025-12-hnut-solana-bundled-rug",
      "file": "2025-12-hnut-solana-bundled-rug.md",
      "title": "HNUT (Holly The Squirrel) bundled-rug Pull — Solana / Pump.fun — 2025-12-30",
      "date_prefix": "2025-12",
      "techniques": [
        "OAK-T1.004",
        "OAK-T2.004",
        "OAK-T3.001",
        "OAK-T5.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-12-hnut-solana-bundled-rug.md"
    },
    {
      "id": "2025-12-polymarket-ufo-declassification-uma-vote-capture",
      "file": "2025-12-polymarket-ufo-declassification-uma-vote-capture.md",
      "title": "Polymarket UFO Declassification UMA Vote-Capture Dispute — 2025-12",
      "date_prefix": "2025-12",
      "techniques": [
        "OAK-T9.006",
        "OAK-T9.006.001",
        "OAK-T9.006.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-12-polymarket-ufo-declassification-uma-vote-capture.md"
    },
    {
      "id": "2025-12-unleash-protocol",
      "file": "2025-12-unleash-protocol.md",
      "title": "Unleash Protocol multisig governance hijack — Story Protocol — 2025-12-30",
      "date_prefix": "2025-12",
      "techniques": [
        "OAK-T16.005",
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-12-unleash-protocol.md"
    },
    {
      "id": "2025-12-uspd-cpimp-clandestine-proxy",
      "file": "2025-12-uspd-cpimp-clandestine-proxy.md",
      "title": "USPD CPIMP \"Clandestine Proxy In the Middle of Proxy\" stablecoin exploit — Ethereum — admin-frontrun 2025-09-16; mint event 2025-12",
      "date_prefix": "2025-12",
      "techniques": [
        "OAK-T5.003",
        "OAK-T6.001",
        "OAK-T6.005",
        "OAK-T9.004",
        "OAK-T9.009"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2025-12-uspd-cpimp-clandestine-proxy.md"
    },
    {
      "id": "2025-2026-polymarket-subjective-oracle-resolution-manipulation-cohort",
      "file": "2025-2026-polymarket-subjective-oracle-resolution-manipulation-cohort.md",
      "title": "Polymarket Subjective-Oracle Resolution Manipulation Cohort — 2025–2026",
      "date_prefix": "2025-20",
      "techniques": [
        "OAK-T9.006.001",
        "OAK-T9.006.002",
        "OAK-T9.006.003",
        "OAK-T9.006.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2025-2026-polymarket-subjective-oracle-resolution-manipulation-cohort.md"
    },
    {
      "id": "2025-2026-prediction-market-source-harassment-cohort",
      "file": "2025-2026-prediction-market-source-harassment-cohort.md",
      "title": "Prediction-Market Resolution-Source Harassment Cohort — 2025–2026",
      "date_prefix": "2025-20",
      "techniques": [
        "OAK-T9.006",
        "OAK-T9.006.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2025-2026-prediction-market-source-harassment-cohort.md"
    },
    {
      "id": "2025-2026-tangem-donjon-physical-access-disclosures",
      "file": "2025-2026-tangem-donjon-physical-access-disclosures.md",
      "title": "Tangem card physical-access disclosures (Ledger Donjon) — hardware — 2025-09 → 2026-07",
      "date_prefix": "2025-20",
      "techniques": [
        "OAK-T11.007.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2025-2026-tangem-donjon-physical-access-disclosures.md"
    },
    {
      "id": "2025-2026-trezor-impersonating-physical-mail-campaign",
      "file": "2025-2026-trezor-impersonating-physical-mail-campaign.md",
      "title": "Trezor-impersonating physical-mail seed-phrase phishing campaign — 2025–2026",
      "date_prefix": "2025-20",
      "techniques": [
        "OAK-T11.007.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2025-2026-trezor-impersonating-physical-mail-campaign.md"
    },
    {
      "id": "2025-axiom-exchange-insider-trading",
      "file": "2025-axiom-exchange-insider-trading.md",
      "title": "Axiom Exchange — Employee Insider Trading via Internal Data Access — 2025",
      "date_prefix": "2025",
      "techniques": [],
      "attribution": "confirmed",
      "source_file": "examples/2025-axiom-exchange-insider-trading.md"
    },
    {
      "id": "2025-rekt-uncovered-incidents-cohort",
      "file": "2025-rekt-uncovered-incidents-cohort.md",
      "title": "2025 Rekt.Uncovered Incidents Cohort — 23 Incidents — Aggregate ~$14.2B (incl. Lubian $14.8B legacy) / ~$297M excl. Lubian",
      "date_prefix": "2025",
      "techniques": [
        "OAK-T11.001",
        "OAK-T12.002",
        "OAK-T15.002",
        "OAK-T16.002",
        "OAK-T5.003",
        "OAK-T5.005",
        "OAK-T9.001",
        "OAK-T9.004",
        "OAK-T9.011"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2025-rekt-uncovered-incidents-cohort.md"
    },
    {
      "id": "2026-01-hardware-wallet-social-engineering",
      "file": "2026-01-hardware-wallet-social-engineering.md",
      "title": "Hardware Wallet Social Engineering — LTC/BTC — 2026-01-10",
      "date_prefix": "2026-01",
      "techniques": [
        "OAK-T7.003",
        "OAK-T7.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-01-hardware-wallet-social-engineering.md"
    },
    {
      "id": "2026-01-polymarket-polycule-bot",
      "file": "2026-01-polymarket-polycule-bot.md",
      "title": "Polycule trading bot — third-party brand-impersonation soft rug — 2026-01",
      "date_prefix": "2026-01",
      "techniques": [
        "OAK-T5.007"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2026-01-polymarket-polycule-bot.md"
    },
    {
      "id": "2026-01-polymarket-trader-tooling-supply-chain",
      "file": "2026-01-polymarket-trader-tooling-supply-chain.md",
      "title": "Polymarket trader-tooling supply-chain compromise — npm + GitHub — 2026-01",
      "date_prefix": "2026-01",
      "techniques": [
        "OAK-T11.009",
        "OAK-T15.002",
        "OAK-T15.004"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2026-01-polymarket-trader-tooling-supply-chain.md"
    },
    {
      "id": "2026-01-polymarket-venezuela-maduro-soldier-insider",
      "file": "2026-01-polymarket-venezuela-maduro-soldier-insider.md",
      "title": "Polymarket Venezuela / Maduro-capture market — operational-insider trading by US Special Forces NCO — 2026-01",
      "date_prefix": "2026-01",
      "techniques": [
        "OAK-T9.006",
        "OAK-T9.006.004"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2026-01-polymarket-venezuela-maduro-soldier-insider.md"
    },
    {
      "id": "2026-02-polymarket-iran-strike-idf-reservist-insider",
      "file": "2026-02-polymarket-iran-strike-idf-reservist-insider.md",
      "title": "Polymarket Iran-strike timing market — operational-insider trading by IDF Air Force reservist — 2026-02",
      "date_prefix": "2026-02",
      "techniques": [
        "OAK-T9.006",
        "OAK-T9.006.004"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2026-02-polymarket-iran-strike-idf-reservist-insider.md"
    },
    {
      "id": "2026-03-aave-wsteth-oracle-misconfiguration-liquidation",
      "file": "2026-03-aave-wsteth-oracle-misconfiguration-liquidation.md",
      "title": "Aave wstETH Oracle Misconfiguration Liquidation Cascade — Mar 2026 — $27.78M",
      "date_prefix": "2026-03",
      "techniques": [
        "OAK-T14.003",
        "OAK-T17.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-03-aave-wsteth-oracle-misconfiguration-liquidation.md"
    },
    {
      "id": "2026-03-panic-account-farm-scam-funnel",
      "file": "2026-03-panic-account-farm-scam-funnel.md",
      "title": "Panic-Account Farm — $0 Direct Loss / Scam Traffic Funnel via Doomposting — 2026-03",
      "date_prefix": "2026-03",
      "techniques": [],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-03-panic-account-farm-scam-funnel.md"
    },
    {
      "id": "2026-03-polymarket-iran-strike-journalist-coercion",
      "file": "2026-03-polymarket-iran-strike-journalist-coercion.md",
      "title": "Polymarket Iran-strike market — physical coercion of resolution source — 2026-03",
      "date_prefix": "2026-03",
      "techniques": [
        "OAK-T9.006",
        "OAK-T9.006.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2026-03-polymarket-iran-strike-journalist-coercion.md"
    },
    {
      "id": "2026-03-resolv-labs-usr-unlimited-mint-key-compromise",
      "file": "2026-03-resolv-labs-usr-unlimited-mint-key-compromise.md",
      "title": "Resolv Labs Private-Key Compromise and Unlimited USR Mint — Mar 2026 — $25M",
      "date_prefix": "2026-03",
      "techniques": [
        "OAK-T11",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-03-resolv-labs-usr-unlimited-mint-key-compromise.md"
    },
    {
      "id": "2026-03-venus-protocol-supply-cap-donation-attack",
      "file": "2026-03-venus-protocol-supply-cap-donation-attack.md",
      "title": "Venus Protocol Supply-Cap Donation-Attack Exploit — BNB Chain — 2026-03-15",
      "date_prefix": "2026-03",
      "techniques": [
        "OAK-T17.001",
        "OAK-T9.011"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-03-venus-protocol-supply-cap-donation-attack.md"
    },
    {
      "id": "2026-04-drift-protocol-durable-nonces-dprk",
      "file": "2026-04-drift-protocol-durable-nonces-dprk.md",
      "title": "Drift Protocol durable-nonce admin-takeover and fictitious-collateral drain — Solana — 2026-04-01",
      "date_prefix": "2026-04",
      "techniques": [
        "OAK-T11.001",
        "OAK-T11.003",
        "OAK-T8.002",
        "OAK-T9.001",
        "OAK-T9.004"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2026-04-drift-protocol-durable-nonces-dprk.md"
    },
    {
      "id": "2026-04-erc4337-paymaster-griefing-mass-bundler-dos",
      "file": "2026-04-erc4337-paymaster-griefing-mass-bundler-dos.md",
      "title": "ERC-4337 paymaster mass-griefing campaign — EVM mainnets — 2026",
      "date_prefix": "2026-04",
      "techniques": [
        "OAK-T13.001.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-04-erc4337-paymaster-griefing-mass-bundler-dos.md"
    },
    {
      "id": "2026-04-hyperbridge-merkle-proof-counterfeit-mint",
      "file": "2026-04-hyperbridge-merkle-proof-counterfeit-mint.md",
      "title": "Hyperbridge Merkle-proof forgery and counterfeit-DOT mint — Polkadot ⇄ Ethereum / Base / BNB / Arbitrum — 2026-04-13",
      "date_prefix": "2026-04",
      "techniques": [
        "OAK-T10",
        "OAK-T10.002",
        "OAK-T6.005",
        "OAK-T6.006"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-04-hyperbridge-merkle-proof-counterfeit-mint.md"
    },
    {
      "id": "2026-04-kelpdai-rseth-bridge-layerzero-compromise",
      "file": "2026-04-kelpdai-rseth-bridge-layerzero-compromise.md",
      "title": "KelpDao rsETH Bridge Hack via LayerZero Infrastructure Compromise — Apr 2026 — $290M",
      "date_prefix": "2026-04",
      "techniques": [
        "OAK-T10",
        "OAK-T10.001",
        "OAK-T14.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-04-kelpdai-rseth-bridge-layerzero-compromise.md"
    },
    {
      "id": "2026-04-polymarket-uma-us-iran-ceasefire-vote-capture",
      "file": "2026-04-polymarket-uma-us-iran-ceasefire-vote-capture.md",
      "title": "Polymarket UMA vote capture — US-Iran ceasefire market — 2026-04",
      "date_prefix": "2026-04",
      "techniques": [
        "OAK-T16.004",
        "OAK-T9.006.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2026-04-polymarket-uma-us-iran-ceasefire-vote-capture.md"
    },
    {
      "id": "2026-04-rave-market-manipulation-cex-intervention",
      "file": "2026-04-rave-market-manipulation-cex-intervention.md",
      "title": "RAVE Token — -95% Market Manipulation / CEX Intervention — 2026-04",
      "date_prefix": "2026-04",
      "techniques": [],
      "attribution": "inferred-strong",
      "source_file": "examples/2026-04-rave-market-manipulation-cex-intervention.md"
    },
    {
      "id": "2026-04-ravedao-otc-pump-dump",
      "file": "2026-04-ravedao-otc-pump-dump.md",
      "title": "RaveDAO ($RAVE) insider OTC distribution and coordinated dump — Multi-CEX (Binance / Bitget / Gate) — 2026-04",
      "date_prefix": "2026-04",
      "techniques": [
        "OAK-T1.004",
        "OAK-T2.001",
        "OAK-T3.004",
        "OAK-T5.001"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2026-04-ravedao-otc-pump-dump.md"
    },
    {
      "id": "2026-04-rhea-finance-margin-parser-exploit",
      "file": "2026-04-rhea-finance-margin-parser-exploit.md",
      "title": "Rhea Finance Margin-Parser Exploit — Apr 2026 — $18.4M",
      "date_prefix": "2026-04",
      "techniques": [
        "OAK-T7.005",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-04-rhea-finance-margin-parser-exploit.md"
    },
    {
      "id": "2026-04-volo-admin-key-social-engineering",
      "file": "2026-04-volo-admin-key-social-engineering.md",
      "title": "Volo Admin-Key Social-Engineering Compromise — Sui — 2026-04-21",
      "date_prefix": "2026-04",
      "techniques": [
        "OAK-T11.001",
        "OAK-T9.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-04-volo-admin-key-social-engineering.md"
    },
    {
      "id": "2026-04-wasabi-protocol-uups-proxy-admin-key-exploit",
      "file": "2026-04-wasabi-protocol-uups-proxy-admin-key-exploit.md",
      "title": "Wasabi Protocol UUPS Proxy-Upgrade Admin-Key Exploit — Apr 2026 — $5.9M",
      "date_prefix": "2026-04",
      "techniques": [
        "OAK-T6.005",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-04-wasabi-protocol-uups-proxy-admin-key-exploit.md"
    },
    {
      "id": "2026-04-zondacrypto-ceo-custody-key-failure",
      "file": "2026-04-zondacrypto-ceo-custody-key-failure.md",
      "title": "Zondacrypto Exchange CEO-Transition Custody Failure and Alleged Russian Mafia Takeover — Apr 2026 — ~$96M",
      "date_prefix": "2026-04",
      "techniques": [],
      "attribution": "unattributed",
      "source_file": "examples/2026-04-zondacrypto-ceo-custody-key-failure.md"
    },
    {
      "id": "2026-05-dritan-kapllani-social-engineering",
      "file": "2026-05-dritan-kapllani-social-engineering.md",
      "title": "Dritan Kapllani Jr — Social Engineering Theft — 2024–2026",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T4.007",
        "OAK-T7"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2026-05-dritan-kapllani-social-engineering.md"
    },
    {
      "id": "2026-05-dsj-exchange-ponzi-collapse",
      "file": "2026-05-dsj-exchange-ponzi-collapse.md",
      "title": "DSJ Exchange (DSJEX) — Ponzi Collapse — 2026-04/05",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T11.005.002",
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T7.003"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2026-05-dsj-exchange-ponzi-collapse.md"
    },
    {
      "id": "2026-05-dxsale-legacy-locker-backdoor",
      "file": "2026-05-dxsale-legacy-locker-backdoor.md",
      "title": "DxSale — legacy BNB-Chain liquidity-locker backdoor (`setFee`→1 wei + obscured ownership) — 2026-05-29",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T11.013",
        "OAK-T3.006",
        "OAK-T7.002",
        "OAK-T9.004"
      ],
      "attribution": "inferred-weak",
      "source_file": "examples/2026-05-dxsale-legacy-locker-backdoor.md"
    },
    {
      "id": "2026-05-echoprotocol-ebtc-bridge-message-forgery",
      "file": "2026-05-echoprotocol-ebtc-bridge-message-forgery.md",
      "title": "EchoProtocol eBTC Bridge Signature-Verification Bypass and Unbounded Mint — Monad — 2026-05-19",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T10.002",
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-05-echoprotocol-ebtc-bridge-message-forgery.md"
    },
    {
      "id": "2026-05-ill-bloom-mobile-wallet-weak-prng-recovery-phrase-sweep",
      "file": "2026-05-ill-bloom-mobile-wallet-weak-prng-recovery-phrase-sweep.md",
      "title": "Ill Bloom — recovery phrases from less-common mobile wallets were generated by an insecure PRNG, and 431 accounts across five chains were swept in one coordinated action — multi-wallet cohort (multi-chain) — first sweep 2026-05-27, disclosed July 2026, root cause named 2026-08-05 as `CryptoJS.lib.WordArray.random()` (CVE-2026-71851)",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T11.004",
        "OAK-T5.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-05-ill-bloom-mobile-wallet-weak-prng-recovery-phrase-sweep.md"
    },
    {
      "id": "2026-05-kraken-coinbase-coordinated-physical-wallet-compromise",
      "file": "2026-05-kraken-coinbase-coordinated-physical-wallet-compromise.md",
      "title": "Kraken / Coinbase users — coordinated physical-coercion + wallet-compromise theft — 2026-05",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T5.009",
        "OAK-T7",
        "OAK-T8.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-05-kraken-coinbase-coordinated-physical-wallet-compromise.md"
    },
    {
      "id": "2026-05-labtrade-insider-manipulation",
      "file": "2026-05-labtrade-insider-manipulation.md",
      "title": "LABtrade — Insider OTC/Vesting/Supply Manipulation — 2026-05-14",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T3.004",
        "OAK-T3.006"
      ],
      "attribution": "confirmed",
      "source_file": "examples/2026-05-labtrade-insider-manipulation.md"
    },
    {
      "id": "2026-05-map-protocol-butter-bridge-encodepacked-collision",
      "file": "2026-05-map-protocol-butter-bridge-encodepacked-collision.md",
      "title": "MAP Protocol — Butter Bridge `abi.encodePacked` hash-collision + retry-message replay — 2026-05-20",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T10",
        "OAK-T10.002",
        "OAK-T10.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-05-map-protocol-butter-bridge-encodepacked-collision.md"
    },
    {
      "id": "2026-05-nx-console-vscode-extension-supply-chain-compromise",
      "file": "2026-05-nx-console-vscode-extension-supply-chain-compromise.md",
      "title": "Nx Console VS Code extension — trojanised release (`nrwl.angular-console` v18.95.0) credential stealer — 2026-05-18",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T11.009",
        "OAK-T15.002",
        "OAK-T15.004"
      ],
      "attribution": "inferred-strong",
      "source_file": "examples/2026-05-nx-console-vscode-extension-supply-chain-compromise.md"
    },
    {
      "id": "2026-05-retoswap-haveno-arbitrator-ack-spoof-multisig-hijack",
      "file": "2026-05-retoswap-haveno-arbitrator-ack-spoof-multisig-hijack.md",
      "title": "RetoSwap / Haveno — unauthenticated ACK → arbitrator impersonation → 2-of-3 multisig instantiation hijack — 2026-05-21",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T11.001",
        "OAK-T11.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-05-retoswap-haveno-arbitrator-ack-spoof-multisig-hijack.md"
    },
    {
      "id": "2026-05-roaring-kitty-x-account-compromise-rkc-memecoin",
      "file": "2026-05-roaring-kitty-x-account-compromise-rkc-memecoin.md",
      "title": "Roaring Kitty (@TheRoaringKitty) — verified X-account compromise → $RKC Pump.fun memecoin — 2026-05-11",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T15.006",
        "OAK-T3.001",
        "OAK-T3.003",
        "OAK-T3.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-05-roaring-kitty-x-account-compromise-rkc-memecoin.md"
    },
    {
      "id": "2026-05-squidroutermodule-safe-module-constant-string-authorization",
      "file": "2026-05-squidroutermodule-safe-module-constant-string-authorization.md",
      "title": "SquidRouterModule — counterfeit Safe module with public-constant-string \"authorization\" — 2026-05-25",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T11.003",
        "OAK-T6.006",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-05-squidroutermodule-safe-module-constant-string-authorization.md"
    },
    {
      "id": "2026-05-stake-dao-vsdcrv-layerzero-oft-peer-redirect",
      "file": "2026-05-stake-dao-vsdcrv-layerzero-oft-peer-redirect.md",
      "title": "Stake DAO — deployer-key compromise → LayerZero OFT peer redirect → 5.4T vsdCRV mint — 2026-05-27",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T10.002",
        "OAK-T10.006",
        "OAK-T10.009",
        "OAK-T11.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-05-stake-dao-vsdcrv-layerzero-oft-peer-redirect.md"
    },
    {
      "id": "2026-05-superfortune-gua-multisig-destination-tampering",
      "file": "2026-05-superfortune-gua-multisig-destination-tampering.md",
      "title": "Superfortune ($GUA) — multisig airdrop-transfer destination tampering to a lookalike address — 2026-05-27",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T11.001",
        "OAK-T11.003",
        "OAK-T4.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-05-superfortune-gua-multisig-destination-tampering.md"
    },
    {
      "id": "2026-05-thorchain-router-exploit",
      "file": "2026-05-thorchain-router-exploit.md",
      "title": "THORChain Router — Ethereum / BSC / Base / Bitcoin — 2026-05-15",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T10.008"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-05-thorchain-router-exploit.md"
    },
    {
      "id": "2026-05-trustedvolumes-rfq-authorization-failure",
      "file": "2026-05-trustedvolumes-rfq-authorization-failure.md",
      "title": "TrustedVolumes RFQ Authorization-Boundary Failure — Ethereum — 2026-05-07",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T9.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-05-trustedvolumes-rfq-authorization-failure.md"
    },
    {
      "id": "2026-05-verus-ethereum-bridge-source-amount-validation",
      "file": "2026-05-verus-ethereum-bridge-source-amount-validation.md",
      "title": "Verus ⇄ Ethereum Bridge — missing source-amount validation (`checkCCEValues`) — 2026-05-18",
      "date_prefix": "2026-05",
      "techniques": [
        "OAK-T10",
        "OAK-T10.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-05-verus-ethereum-bridge-source-amount-validation.md"
    },
    {
      "id": "2026-06-aztec-deprecated-rollup-forged-proof-cohort",
      "file": "2026-06-aztec-deprecated-rollup-forged-proof-cohort.md",
      "title": "Aztec deprecated rollup infrastructure — forged rollup proofs drain two immutable, abandoned bridges within a week — Ethereum — 2026-06 (≈06-14 and ≈06-17) (cohort)",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T10.002",
        "OAK-T11.013"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-06-aztec-deprecated-rollup-forged-proof-cohort.md"
    },
    {
      "id": "2026-06-cryptobandits-usb-worm-tor-clipper",
      "file": "2026-06-cryptobandits-usb-worm-tor-clipper.md",
      "title": "CryptoBandits — USB-worm crypto-clipper with Tor C2 and clipboard secret-harvesting — Windows / cross-chain — disclosed 2026-06-17",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T4.012",
        "OAK-T4.012.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-06-cryptobandits-usb-worm-tor-clipper.md"
    },
    {
      "id": "2026-06-eleven-drainer-legit-subdomain-frontend-compromise-cohort",
      "file": "2026-06-eleven-drainer-legit-subdomain-frontend-compromise-cohort.md",
      "title": "\"Eleven drainer\" injected into legitimate project subdomains — Gitcoin and Yield Yak — Ethereum / Avalanche — 2026-06 (June 21 and 24)",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T15.004",
        "OAK-T4.004",
        "OAK-T6.008"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-06-eleven-drainer-legit-subdomain-frontend-compromise-cohort.md"
    },
    {
      "id": "2026-06-flooring-protocol-bt404-ghost-ownership-underflow",
      "file": "2026-06-flooring-protocol-bt404-ghost-ownership-underflow.md",
      "title": "Flooring Protocol — a crafted high-bit token-ID alias made an ownership check pass for a token the caller did not own, and the balance update behind it underflowed, turning a little WETH into effectively unlimited fpTokens — Flooring Protocol V2 / BitmapPunks (Ethereum) — 2026-06-08",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T12.008",
        "OAK-T5.001",
        "OAK-T9.004",
        "OAK-T9.007"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-06-flooring-protocol-bt404-ghost-ownership-underflow.md"
    },
    {
      "id": "2026-06-gnosis-pay-zodiac-delay-module-fallback-handler-bypass",
      "file": "2026-06-gnosis-pay-zodiac-delay-module-fallback-handler-bypass.md",
      "title": "Gnosis Pay — Zodiac Delay/Roles modifier fallback-handler bypass — 2026-06-01",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T11",
        "OAK-T11.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-06-gnosis-pay-zodiac-delay-module-fallback-handler-bypass.md"
    },
    {
      "id": "2026-06-humanity-protocol-developer-machine-multisig-quorum-compromise",
      "file": "2026-06-humanity-protocol-developer-machine-multisig-quorum-compromise.md",
      "title": "Humanity Protocol ($H) — single developer-machine compromise defeats two multisig quorums across two chains — Ethereum + BNB Chain — 2026-06-08/09",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T11.011",
        "OAK-T15.003",
        "OAK-T5.001",
        "OAK-T6.005",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-06-humanity-protocol-developer-machine-multisig-quorum-compromise.md"
    },
    {
      "id": "2026-06-jaredfromsubway-mev-bot-counter-mev-honeypot-allowance-drain",
      "file": "2026-06-jaredfromsubway-mev-bot-counter-mev-honeypot-allowance-drain.md",
      "title": "jaredfromsubway.eth — a counter-MEV honeypot lures the sandwich bot into leaving standing token allowances, then sweeps them — Ethereum — 2026-06-20",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T4.004",
        "OAK-T6.006",
        "OAK-T7.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-06-jaredfromsubway-mev-bot-counter-mev-honeypot-allowance-drain.md"
    },
    {
      "id": "2026-06-joe-agent-removeliquidity-reentrancy",
      "file": "2026-06-joe-agent-removeliquidity-reentrancy.md",
      "title": "Joe Agent ($JOE) — `_removeLiquidityViaContract` single-function reentrancy — 2026-06",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T9",
        "OAK-T9.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-06-joe-agent-removeliquidity-reentrancy.md"
    },
    {
      "id": "2026-06-myswap-cl-starknet-fake-token-shared-vault-accounting-drain",
      "file": "2026-06-myswap-cl-starknet-fake-token-shared-vault-accounting-drain.md",
      "title": "mySwap CL — a fake \"EVIL\" token abuses shared-vault concentrated-liquidity accounting to drain residual LP — Starknet — 2026-06-19",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-06-myswap-cl-starknet-fake-token-shared-vault-accounting-drain.md"
    },
    {
      "id": "2026-06-namada-masp-ibc-transfer-logic-shielded-drain",
      "file": "2026-06-namada-masp-ibc-transfer-logic-shielded-drain.md",
      "title": "Namada — an IBC transfer-logic flaw drains the Multi-Asset Shielded Pool while a stale indexer masks the loss — Namada (Cosmos / IBC) — 2026-06-19",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T10.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-06-namada-masp-ibc-transfer-logic-shielded-drain.md"
    },
    {
      "id": "2026-06-openmonero-server-misconfig-wallet-rpc-hot-wallet-drain",
      "file": "2026-06-openmonero-server-misconfig-wallet-rpc-hot-wallet-drain.md",
      "title": "OpenMonero — server misconfiguration exposes wallet-RPC, hot wallet drained — Monero — 2026-06-08",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T15.003",
        "OAK-T5.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-06-openmonero-server-misconfig-wallet-rpc-hot-wallet-drain.md"
    },
    {
      "id": "2026-06-polymarket-frontend-vendor-js-injection-approval-drain",
      "file": "2026-06-polymarket-frontend-vendor-js-injection-approval-drain.md",
      "title": "Polymarket — a compromised third-party frontend vendor injects wallet-draining JavaScript into the live site — Polygon / Ethereum — 2026-06-25",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T15.002",
        "OAK-T4.002",
        "OAK-T7.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-06-polymarket-frontend-vendor-js-injection-approval-drain.md"
    },
    {
      "id": "2026-06-rust-clipper-fake-reputation-ghost-network",
      "file": "2026-06-rust-clipper-fake-reputation-ghost-network.md",
      "title": "Rust crypto-clipper — fake-reputation \"Ghost Network\" distribution of trojanised trading tools — Windows + macOS / cross-chain — disclosed 2026-06-17",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T4.012",
        "OAK-T4.012.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-06-rust-clipper-fake-reputation-ghost-network.md"
    },
    {
      "id": "2026-06-secondfi-cardano-web-wallet-predictable-key-generation-drain",
      "file": "2026-06-secondfi-cardano-web-wallet-predictable-key-generation-drain.md",
      "title": "SecondFi — predictable web-wallet key generation drains Cardano (ADA) wallets — Cardano — 2026-06-23",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T11.004",
        "OAK-T11.005.002",
        "OAK-T11.010",
        "OAK-T5.007",
        "OAK-T6.007"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-06-secondfi-cardano-web-wallet-predictable-key-generation-drain.md"
    },
    {
      "id": "2026-06-secret-network-axelar-ics20-forged-ibc-packet-unbacked-mint",
      "file": "2026-06-secret-network-axelar-ics20-forged-ibc-packet-unbacked-mint.md",
      "title": "Secret Network — a forked CW20-ICS20 bridge contract skips source-channel and escrow checks, minting unbacked tokens redeemed over the real Axelar route — Secret Network / Axelar (Cosmos IBC) — 2026-06-10",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T10.002",
        "OAK-T11.013",
        "OAK-T7.002",
        "OAK-T7.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-06-secret-network-axelar-ics20-forged-ibc-packet-unbacked-mint.md"
    },
    {
      "id": "2026-06-steam-workshop-wallpaper-engine-infostealer",
      "file": "2026-06-steam-workshop-wallpaper-engine-infostealer.md",
      "title": "Steam Workshop / Wallpaper Engine malicious wallpapers — Lumma + Vidar infostealers harvesting Steam sessions and crypto wallets — Windows / cross-chain — disclosed 2026-06-16",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T4.010",
        "OAK-T4.013",
        "OAK-T4.013.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-06-steam-workshop-wallpaper-engine-infostealer.md"
    },
    {
      "id": "2026-06-syscoin-bridge-spv-proof-parsing-unauthorized-mint",
      "file": "2026-06-syscoin-bridge-spv-proof-parsing-unauthorized-mint.md",
      "title": "Syscoin bridge — SPV-proof-parsing flaw mints ~5B SYS without a burn — Syscoin UTXO ⇄ NEVM — 2026-06-07",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T10.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-06-syscoin-bridge-spv-proof-parsing-unauthorized-mint.md"
    },
    {
      "id": "2026-06-taiko-bridge-leaked-sgx-prover-key-forged-proof-withdrawal",
      "file": "2026-06-taiko-bridge-leaked-sgx-prover-key-forged-proof-withdrawal.md",
      "title": "Taiko bridge — a leaked SGX prover signing key forges L2-state proofs to drain the L1 bridge — Ethereum L1 ⇄ Taiko Alethia L2 — 2026-06-21",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T10.002",
        "OAK-T15.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-06-taiko-bridge-leaked-sgx-prover-key-forged-proof-withdrawal.md"
    },
    {
      "id": "2026-06-tesseradao-tsr-admin-key-unauthorized-mint",
      "file": "2026-06-tesseradao-tsr-admin-key-unauthorized-mint.md",
      "title": "TesseraDAO ($TSR) — admin-key compromise → unauthorised mint-and-dump — 2026-06-01",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T11.002",
        "OAK-T5.001",
        "OAK-T7.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-06-tesseradao-tsr-admin-key-unauthorized-mint.md"
    },
    {
      "id": "2026-06-token-of-power-top-low-float-governance-takeover-mint",
      "file": "2026-06-token-of-power-top-low-float-governance-takeover-mint.md",
      "title": "Token of Power ($TOP) — low-float governance takeover mints 10B TOP in one block — Ethereum — 2026-06-09",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T16.002",
        "OAK-T5.001",
        "OAK-T7.001",
        "OAK-T9.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-06-token-of-power-top-low-float-governance-takeover-mint.md"
    },
    {
      "id": "2026-06-zcash-orchard-counterfeiting-circuit-underconstraint-disclosure",
      "file": "2026-06-zcash-orchard-counterfeiting-circuit-underconstraint-disclosure.md",
      "title": "Zcash Orchard counterfeiting vulnerability — under-constrained halo2 scalar-mul gadget (AI-discovered responsible disclosure) — 2026-05-29 / 2026-06-02",
      "date_prefix": "2026-06",
      "techniques": [
        "OAK-T9",
        "OAK-T9.004",
        "OAK-T9.014"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-06-zcash-orchard-counterfeiting-circuit-underconstraint-disclosure.md"
    },
    {
      "id": "2026-07-42dao-balance-btcb-oracle-downward-liquidation-seizure",
      "file": "2026-07-42dao-balance-btcb-oracle-downward-liquidation-seizure.md",
      "title": "42DAO / Balance Protocol — the attacker pokes an abnormally *low* BTCB price into the vault-health contract, making solvent vaults look insolvent, and liquidates them — 42DAO / Balance Coin (BNB Chain) — 2026-07-22",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T5.001",
        "OAK-T9.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-42dao-balance-btcb-oracle-downward-liquidation-seizure.md"
    },
    {
      "id": "2026-07-across-solana-relayer-anchor-event-discriminator-forgery",
      "file": "2026-07-across-solana-relayer-anchor-event-discriminator-forgery.md",
      "title": "Across Protocol — a missing 8-byte Anchor discriminator check lets an attacker forge Solana deposit events that never moved funds, and the relayer fills 581 of them — Across / Risk Labs (Solana) — 2026-07-17",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T10",
        "OAK-T10.002",
        "OAK-T10.002.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-across-solana-relayer-anchor-event-discriminator-forgery.md"
    },
    {
      "id": "2026-07-afx-trade-bridge-hot-validator-key-quorum-compromise",
      "file": "2026-07-afx-trade-bridge-hot-validator-key-quorum-compromise.md",
      "title": "AFX Trade — five compromised hot-validator keys meet the bridge's two-thirds quorum, and a 200-second dispute window passes with nobody watching it — AFX Trade (Arbitrum) — 2026-07-22",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T10.001",
        "OAK-T10.004",
        "OAK-T7.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-afx-trade-bridge-hot-validator-key-quorum-compromise.md"
    },
    {
      "id": "2026-07-allbridge-core-solana-flash-loan-pool-ratio-manipulation",
      "file": "2026-07-allbridge-core-solana-flash-loan-pool-ratio-manipulation.md",
      "title": "Allbridge Core — a $1.12M Kamino flash loan skews the USDC/USDT pool ratio, liquidity is withdrawn at the distorted valuation, and the loan repays in the same transaction — Allbridge Core (Solana) — 2026-07-19",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-allbridge-core-solana-flash-loan-pool-ratio-manipulation.md"
    },
    {
      "id": "2026-07-b2-network-staking-contract-upgrade-authority-seizure",
      "file": "2026-07-b2-network-staking-contract-upgrade-authority-seizure.md",
      "title": "B² Network — an attacker takes the staking contract's upgrade authority, rewrites what the contract does, and sells 8.59M B2 into the market — B² Network (Bitcoin Layer 2) — 2026-07-23",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T6.005",
        "OAK-T7.003",
        "OAK-T7.007",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-b2-network-staking-contract-upgrade-authority-seizure.md"
    },
    {
      "id": "2026-07-bonkdao-low-quorum-governance-treasury-drain",
      "file": "2026-07-bonkdao-low-quorum-governance-treasury-drain.md",
      "title": "BonkDAO — an attacker buys just over 1% of supply on KYC exchanges, meets a low quorum in a 2.9%-turnout ballot, and votes the treasury to itself — BonkDAO / Realms (Solana) — 2026-07-06",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T16.002",
        "OAK-T9.001",
        "OAK-T9.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-bonkdao-low-quorum-governance-treasury-drain.md"
    },
    {
      "id": "2026-07-bonzo-lend-supra-oracle-zeroed-signature-drain",
      "file": "2026-07-bonzo-lend-supra-oracle-zeroed-signature-drain.md",
      "title": "Bonzo Lend — an all-zero signature satisfies Supra's oracle verifier trivially, inflating SAUCE by ~12 orders of magnitude to borrow $9.05M against 250 tokens — Bonzo Lend / Supra (Hedera) — 2026-07-12",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.003",
        "OAK-T9.001",
        "OAK-T9.015"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-bonzo-lend-supra-oracle-zeroed-signature-drain.md"
    },
    {
      "id": "2026-07-cascade-cls-vault-prelaunch-locked-deposit-drain",
      "file": "2026-07-cascade-cls-vault-prelaunch-locked-deposit-drain.md",
      "title": "Cascade — pre-launch depositors farming reward points had their USDC locked until mainnet, so when the CLS vault was drained none of them could have withdrawn first — Cascade (Arbitrum) — 2026-07-16",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T7.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-cascade-cls-vault-prelaunch-locked-deposit-drain.md"
    },
    {
      "id": "2026-07-coldcard-firmware-rng-fallback-entropy-collapse-sweep",
      "file": "2026-07-coldcard-firmware-rng-fallback-entropy-collapse-sweep.md",
      "title": "Coldcard — a 2021 library migration left an RNG config check that tested whether a setting existed but not whether it was on, silently dropping seed entropy from 128 bits to 40, and five years of seeds were swept — Coldcard / Coinkite (Bitcoin) — 2026-07-30/31 onward, ongoing",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T11.002",
        "OAK-T11.004",
        "OAK-T11.007",
        "OAK-T5.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-coldcard-firmware-rng-fallback-entropy-collapse-sweep.md"
    },
    {
      "id": "2026-07-defituna-product-seam-lending-pool-usdc-deficit",
      "file": "2026-07-defituna-product-seam-lending-pool-usdc-deficit.md",
      "title": "DeFiTuna — concentrated liquidity, lending, and 5x leverage in one protocol, and the attack landed on the seams between them rather than inside any of them — DeFiTuna (Solana) — 2026-07-16",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T9.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-defituna-product-seam-lending-pool-usdc-deficit.md"
    },
    {
      "id": "2026-07-dprk-military-operators-state-bank-diversion-broker-offramp",
      "file": "2026-07-dprk-military-operators-state-bank-diversion-broker-offramp.md",
      "title": "DPRK state banks breached from the inside — former military operators are reported arrested for diverting state funds into overseas crypto wallets and structuring them out through Chinese border brokers — Central Bank of the DPRK / Foreign Trade Bank — 2026-07-12 (reported 2026-07-25)",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T7.010",
        "OAK-T8.005"
      ],
      "attribution": "inferred-weak",
      "source_file": "examples/2026-07-dprk-military-operators-state-bank-diversion-broker-offramp.md"
    },
    {
      "id": "2026-07-injective-sdk-npm-trusted-publisher-key-exfiltration",
      "file": "2026-07-injective-sdk-npm-trusted-publisher-key-exfiltration.md",
      "title": "Injective Labs SDK — a commit from a trusted maintainer account rides the OIDC auto-publish pipeline into 18 npm packages that exfiltrate seed phrases at key-derivation time — Injective Labs / npm (chain-agnostic) — 2026-07-08",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T11.009",
        "OAK-T15.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-07-injective-sdk-npm-trusted-publisher-key-exfiltration.md"
    },
    {
      "id": "2026-07-layerzero-executor-multi-chain-simultaneous-wallet-drain",
      "file": "2026-07-layerzero-executor-multi-chain-simultaneous-wallet-drain.md",
      "title": "LayerZero Executor — hot wallets for the message-execution role drain simultaneously across eight chains, the signature of co-located key material — LayerZero (cross-chain) — 2026-07-15",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T11.011",
        "OAK-T7.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-07-layerzero-executor-multi-chain-simultaneous-wallet-drain.md"
    },
    {
      "id": "2026-07-lien-finance-bond-rate-calculation-overvaluation-drain",
      "file": "2026-07-lien-finance-bond-rate-calculation-overvaluation-drain.md",
      "title": "Lien Finance — an internal rate function prices attacker-crafted bonds far above the collateral actually backing them — Lien Finance (Ethereum) — 2026-07-24",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-lien-finance-bond-rate-calculation-overvaluation-drain.md"
    },
    {
      "id": "2026-07-ostium-oracle-signer-future-dated-price-report-vault-drain",
      "file": "2026-07-ostium-oracle-signer-future-dated-price-report-vault-drain.md",
      "title": "Ostium — an authorised price-report path settles a BTC long opened at $5,000 and closed at ~$60,000 in one transaction, draining the OLP vault — Ostium (Arbitrum) — 2026-07-15",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T9.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-ostium-oracle-signer-future-dated-price-report-vault-drain.md"
    },
    {
      "id": "2026-07-solido-cash-stale-feed-fallback-collateral-overvaluation-mint",
      "file": "2026-07-solido-cash-stale-feed-fallback-collateral-overvaluation-mint.md",
      "title": "Solido Cash — a stale price feed on the backstop collateral token trips fallback logic that values it far above market, and 809,052 CASH are minted against it — Solido Money (SUPRA) — 2026-07-23",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T7.002",
        "OAK-T9.001",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-solido-cash-stale-feed-fallback-collateral-overvaluation-mint.md"
    },
    {
      "id": "2026-07-summer-fi-lazy-summer-stale-ark-nav-donation-drain",
      "file": "2026-07-summer-fi-lazy-summer-stale-ark-nav-donation-drain.md",
      "title": "Summer.fi (Lazy Summer Protocol) — a market capped for offboarding stays priced into vault NAV, so a donation of stale Stream-Finance-era tokens inflates the share price for an atomic redemption — Summer.fi / Lazy Summer (Ethereum) — 2026-07-06",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T7.001",
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-summer-fi-lazy-summer-stale-ark-nav-donation-drain.md"
    },
    {
      "id": "2026-07-triple-a-hot-wallet-compromise-deposit-addresses-left-live",
      "file": "2026-07-triple-a-hot-wallet-compromise-deposit-addresses-left-live.md",
      "title": "Triple-A — a licensed payment processor's hot wallets are swept for 31 hours because pausing the service never disabled the on-chain deposit addresses still receiving merchant settlements — Triple-A (Singapore) — 2026-07-24/25",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T15.004",
        "OAK-T5.001",
        "OAK-T7.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-triple-a-hot-wallet-compromise-deposit-addresses-left-live.md"
    },
    {
      "id": "2026-07-verus-ethereum-bridge-repeat-exploit-unfixed-import-path",
      "file": "2026-07-verus-ethereum-bridge-repeat-exploit-unfixed-import-path.md",
      "title": "Verus ⇄ Ethereum Bridge, second time — the May attacker returns the funds, the team redeposits them into the unfixed contract, and a different attacker takes them out through the same import path — Verus / Ethereum — 2026-07-23",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T10",
        "OAK-T10.002",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-verus-ethereum-bridge-repeat-exploit-unfixed-import-path.md"
    },
    {
      "id": "2026-07-wanchain-cardano-bridge-non-injective-encoding-signature-reuse",
      "file": "2026-07-wanchain-cardano-bridge-non-injective-encoding-signature-reuse.md",
      "title": "Wanchain Cardano bridge — 14 variable-length fields concatenated without separators make the signed message non-injective, so a signature for 3,110 NIGHT authorises 203,001,692 — Wanchain / Midnight NIGHT (Cardano ⇄ BNB Chain) — 2026-07-20/21",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T10",
        "OAK-T10.002",
        "OAK-T10.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-wanchain-cardano-bridge-non-injective-encoding-signature-reuse.md"
    },
    {
      "id": "2026-07-wemix-stablecoin-contract-ownership-unauthorized-mint",
      "file": "2026-07-wemix-stablecoin-contract-ownership-unauthorized-mint.md",
      "title": "WEMIX — an attacker takes administrator privileges over the WEMIX$ stablecoin contract and mints 5.2M units out of nothing, forcing the network to shut its own bridges, DEX, and marketplace — WEMIX (Wemix3.0) — 2026-07-26",
      "date_prefix": "2026-07",
      "techniques": [
        "OAK-T5.003",
        "OAK-T7.002",
        "OAK-T7.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-07-wemix-stablecoin-contract-ownership-unauthorized-mint.md"
    },
    {
      "id": "2026-08-allbridge-dormant-forged-cctp-attestation",
      "file": "2026-08-allbridge-dormant-forged-cctp-attestation.md",
      "title": "Allbridge — a forged CCTP attestation was minted on 26 July, left to sit for 24 days, and redeemed on 19 August the moment the target router had a balance worth taking — Allbridge / Polygon → Base — 2026-08-19",
      "date_prefix": "2026-08",
      "techniques": [
        "OAK-T10.002",
        "OAK-T9.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-08-allbridge-dormant-forged-cctp-attestation.md"
    },
    {
      "id": "2026-08-bouncebit-evmos-stack-authorization-flaw-chain-retirement",
      "file": "2026-08-bouncebit-evmos-stack-authorization-flaw-chain-retirement.md",
      "title": "BounceBit — an inherited Evmos authorisation flaw let a caller name any account as the source of funds, and the chain was retired rather than patched — BounceBit Chain — 2026-08-19",
      "date_prefix": "2026-08",
      "techniques": [
        "OAK-T9.004",
        "OAK-T9.007"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-08-bouncebit-evmos-stack-authorization-flaw-chain-retirement.md"
    },
    {
      "id": "2026-08-coinsbuy-payment-processor-multi-chain-hot-wallet-drain",
      "file": "2026-08-coinsbuy-payment-processor-multi-chain-hot-wallet-drain.md",
      "title": "Coinsbuy — a B2B payment processor's Ethereum and TRON wallets emptied in the same hour, the signature of one signing infrastructure rather than two compromises — Coinsbuy (Ethereum, TRON) — 2026-08-09",
      "date_prefix": "2026-08",
      "techniques": [
        "OAK-T11.011",
        "OAK-T5.001",
        "OAK-T7.002",
        "OAK-T7.005"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-08-coinsbuy-payment-processor-multi-chain-hot-wallet-drain.md"
    },
    {
      "id": "2026-08-coreum-xrpl-bridge-forged-deposit-memo-relayer-verification",
      "file": "2026-08-coreum-xrpl-bridge-forged-deposit-memo-relayer-verification.md",
      "title": "Coreum–XRPL bridge — relayers verified that a deposit *message* was well-formed and never that the XRP had arrived, so self-transfers carrying a forged memo released 199,916 real XRP — Coreum / XRP Ledger — 2026-08-09",
      "date_prefix": "2026-08",
      "techniques": [
        "OAK-T10.001",
        "OAK-T10.002",
        "OAK-T10.002.001"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-08-coreum-xrpl-bridge-forged-deposit-memo-relayer-verification.md"
    },
    {
      "id": "2026-08-harmony-cross-shard-receipt-quorum-bypass-unauthorized-mint",
      "file": "2026-08-harmony-cross-shard-receipt-quorum-bypass-unauthorized-mint.md",
      "title": "Harmony — a committee verifier that counted the roster instead of the signers accepted an all-zero signature mask, and unauthenticated receipt-proof fields let spent cross-shard receipts be credited again — Harmony Mainnet (ONE) — 2026-08-12",
      "date_prefix": "2026-08",
      "techniques": [
        "OAK-T10.001",
        "OAK-T10.002",
        "OAK-T10.003",
        "OAK-T5.003",
        "OAK-T7.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-08-harmony-cross-shard-receipt-quorum-bypass-unauthorized-mint.md"
    },
    {
      "id": "2026-08-maya-protocol-observed-tx-voter-overwrite-uncapped-subsidy",
      "file": "2026-08-maya-protocol-observed-tx-voter-overwrite-uncapped-subsidy.md",
      "title": "Maya Protocol — one deposit carrying 23 messages overwrote the chain's own observed-transaction voter, so a safety mechanism paid a 49.45M CACAO \"compensation\" into a pool holding 0.11 LINK — MAYAChain — 2026-08-18",
      "date_prefix": "2026-08",
      "techniques": [
        "OAK-T10.002",
        "OAK-T5.003"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-08-maya-protocol-observed-tx-voter-overwrite-uncapped-subsidy.md"
    },
    {
      "id": "2026-08-onchainattack-maintainer-fake-assessment-lure",
      "file": "2026-08-onchainattack-maintainer-fake-assessment-lure.md",
      "title": "OAK field-collects a live fake-recruiter lure to check its own T15.001 page against a real specimen — and finds the page wrong on two points: the trigger is npm `prepare`, and the repository carries no payload at all — OnChainAttack, first-party collection — 2026-08-27",
      "date_prefix": "2026-08",
      "techniques": [
        "OAK-T11.009",
        "OAK-T15.001",
        "OAK-T15.003"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-08-onchainattack-maintainer-fake-assessment-lure.md"
    },
    {
      "id": "2026-08-oraichain-evm-transfer-path-unauthorized-mint-network-halt",
      "file": "2026-08-oraichain-evm-transfer-path-unauthorized-mint-network-halt.md",
      "title": "Oraichain — an EVM cross-chain transfer path allowed ORAI to be minted without a backing deposit, and the team stopped the entire chain four hours in rather than let the supply keep moving — Oraichain (Cosmos SDK / OraichainEVM) — 2026-08-09",
      "date_prefix": "2026-08",
      "techniques": [
        "OAK-T10.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-08-oraichain-evm-transfer-path-unauthorized-mint-network-halt.md"
    },
    {
      "id": "2026-08-repeat-victim-whale-approval-phishing-second-drain",
      "file": "2026-08-repeat-victim-whale-approval-phishing-second-drain.md",
      "title": "Repeat-victim whale — the same address that lost \\$24.2M to approval phishing in 2023 was drained again for \\$25.6M three years later, and this time nothing came back — unidentified individual (Ethereum) — 2026-08-12 (first drain 2023-09)",
      "date_prefix": "2026-08",
      "techniques": [
        "OAK-T4.001",
        "OAK-T4.004",
        "OAK-T5.001",
        "OAK-T7.007"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-08-repeat-victim-whale-approval-phishing-second-drain.md"
    },
    {
      "id": "2026-08-sandbox-sand-layerzero-oft-delegate-hijack-unbacked-mint",
      "file": "2026-08-sandbox-sand-layerzero-oft-delegate-hijack-unbacked-mint.md",
      "title": "The Sandbox — hijacked LayerZero OFT delegate permissions minted \\$49B of face-value SAND across 400+ transactions, and the pools could only pay out \\$675K of it — The Sandbox / Base + BNB Smart Chain — 2026-08-22",
      "date_prefix": "2026-08",
      "techniques": [
        "OAK-T10.006",
        "OAK-T10.009",
        "OAK-T5.003",
        "OAK-T9.004"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-08-sandbox-sand-layerzero-oft-delegate-hijack-unbacked-mint.md"
    },
    {
      "id": "2026-08-term-finance-vault-governance-quorum-capture",
      "file": "2026-08-term-finance-vault-governance-quorum-capture.md",
      "title": "Term Finance — \\$951 bought 90.66% of a vault's voting power, because voting required opt-in staking and almost nobody had opted in — Term Labs / Ethereum — 2026-08-23",
      "date_prefix": "2026-08",
      "techniques": [
        "OAK-T16.001",
        "OAK-T16.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-08-term-finance-vault-governance-quorum-capture.md"
    },
    {
      "id": "2026-08-usm-defund-split-arithmetic-mean-redemption-pricing",
      "file": "2026-08-usm-defund-split-arithmetic-mean-redemption-pricing.md",
      "title": "USM — redeeming the same position in 64 slices paid more than redeeming it once, because the redemption price was an arithmetic mean over the path rather than a function of the position — USM Protocol (Ethereum) — 2026-08-10",
      "date_prefix": "2026-08",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.002",
        "OAK-T9.011"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-08-usm-defund-split-arithmetic-mean-redemption-pricing.md"
    },
    {
      "id": "2026-bybit-hack-laundering-continuation-thorchain-dprk",
      "file": "2026-bybit-hack-laundering-continuation-thorchain-dprk.md",
      "title": "Bybit $1.5B Hack Laundering Continuation into 2026 — DPRK / Lazarus — 2026",
      "date_prefix": "2026",
      "techniques": [
        "OAK-T7.001",
        "OAK-T7.002",
        "OAK-T7.005",
        "OAK-T8.001"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-bybit-hack-laundering-continuation-thorchain-dprk.md"
    },
    {
      "id": "2026-cowswap-large-trade-mev-routing-liquidity-fragmentation",
      "file": "2026-cowswap-large-trade-mev-routing-liquidity-fragmentation.md",
      "title": "CoWSwap $50M Institutional Trade MEV Routing / Liquidity Fragmentation Event — 2026 — ~$50M price impact",
      "date_prefix": "2026",
      "techniques": [
        "OAK-T17.001",
        "OAK-T5.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-cowswap-large-trade-mev-routing-liquidity-fragmentation.md"
    },
    {
      "id": "2026-eip7702-crimeenjoyor-delegation-phishing-continuation",
      "file": "2026-eip7702-crimeenjoyor-delegation-phishing-continuation.md",
      "title": "EIP-7702 Delegation Phishing — Continued 2026 CrimeEnjoyor Cluster Operations — 2026 — ~$3M+",
      "date_prefix": "2026",
      "techniques": [
        "OAK-T13.004",
        "OAK-T4.007"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-eip7702-crimeenjoyor-delegation-phishing-continuation.md"
    },
    {
      "id": "2026-q1-nft-marketplace-wash-trade-fake-mint-cohort",
      "file": "2026-q1-nft-marketplace-wash-trade-fake-mint-cohort.md",
      "title": "NFT marketplace wash-trade and fake-mint cohort — 2026 Q1",
      "date_prefix": "2026",
      "techniques": [
        "OAK-T1.005",
        "OAK-T12.001",
        "OAK-T12.002"
      ],
      "attribution": "pseudonymous",
      "source_file": "examples/2026-q1-nft-marketplace-wash-trade-fake-mint-cohort.md"
    },
    {
      "id": "2026-q1-q2-access-control-auth-cohort",
      "file": "2026-q1-q2-access-control-auth-cohort.md",
      "title": "Q1–Q2 2026 Access-Control and Authorisation-Gap Cohort — Sweat Foundation, Ekubo, Giddy, Aftermath Perps — Aggregate ~$7.3M",
      "date_prefix": "2026",
      "techniques": [
        "OAK-T9.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-q1-q2-access-control-auth-cohort.md"
    },
    {
      "id": "2026-q1-q2-crosschain-bridge-otc-cohort",
      "file": "2026-q1-q2-crosschain-bridge-otc-cohort.md",
      "title": "Q1–Q2 2026 Cross-Chain, Bridge and OTC Exploit Cohort — CrossCurve, Purrlend, Transit Finance, Meteora DAMM V2, TAC Protocol, Alephium — Aggregate ~$11.4M",
      "date_prefix": "2026",
      "techniques": [
        "OAK-T10.002",
        "OAK-T9.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-q1-q2-crosschain-bridge-otc-cohort.md"
    },
    {
      "id": "2026-q1-q2-flashloan-approval-slippage-cohort",
      "file": "2026-q1-q2-flashloan-approval-slippage-cohort.md",
      "title": "Q1–Q2 2026 Flash-Loan, Approval and Slippage Exploit Cohort — Matcha, Cyrus Finance, YO Protocol, Aperture LM — Aggregate ~$24.4M",
      "date_prefix": "2026",
      "techniques": [
        "OAK-T9.002",
        "OAK-T9.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-q1-q2-flashloan-approval-slippage-cohort.md"
    },
    {
      "id": "2026-q1-q2-key-compromise-cohort",
      "file": "2026-q1-q2-key-compromise-cohort.md",
      "title": "Q1–Q2 2026 Key Compromise Cohort — Step Finance, IoTeX, Grinex, Gravity Bridge, Polymarket UMA — Aggregate ~$68.7M",
      "date_prefix": "2026",
      "techniques": [
        "OAK-T10.001",
        "OAK-T11.001",
        "OAK-T9.004"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-q1-q2-key-compromise-cohort.md"
    },
    {
      "id": "2026-q1-q2-mint-and-tokenomics-exploit-cohort",
      "file": "2026-q1-q2-mint-and-tokenomics-exploit-cohort.md",
      "title": "Q1–Q2 2026 Mint and Tokenomics Exploit Cohort — Truebit, Saga, SolvBTC, FOOM Cash, TMX TRIBE — Aggregate ~$40.1M",
      "date_prefix": "2026",
      "techniques": [
        "OAK-T5.003",
        "OAK-T9.004",
        "OAK-T9.011"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-q1-q2-mint-and-tokenomics-exploit-cohort.md"
    },
    {
      "id": "2026-q1-q2-oracle-price-manipulation-cohort",
      "file": "2026-q1-q2-oracle-price-manipulation-cohort.md",
      "title": "Q1–Q2 2026 Oracle and Price-Manipulation Cohort — Blend Pools V2, Makina, Moonwell, BSC TMM/USDT — Aggregate ~$18.6M",
      "date_prefix": "2026",
      "techniques": [
        "OAK-T9.001",
        "OAK-T9.002"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-q1-q2-oracle-price-manipulation-cohort.md"
    },
    {
      "id": "2026-q1-q2-sub-million-exploit-cohort",
      "file": "2026-q1-q2-sub-million-exploit-cohort.md",
      "title": "Q1–Q2 2026 Sub-Million Exploit Cohort — 36 Incidents Across 13 Chains — Aggregate ~$10.1M",
      "date_prefix": "2026",
      "techniques": [
        "OAK-T10.002",
        "OAK-T11.001",
        "OAK-T9.001",
        "OAK-T9.002",
        "OAK-T9.004",
        "OAK-T9.011"
      ],
      "attribution": "unattributed",
      "source_file": "examples/2026-q1-q2-sub-million-exploit-cohort.md"
    }
  ],
  "relationships": [
    {
      "type": "mitigates",
      "source": "OAK-M01",
      "target": "OAK-T1.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M01",
      "target": "OAK-T1.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M01",
      "target": "OAK-T1.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M01",
      "target": "OAK-T1.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M01",
      "target": "OAK-T2.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M01",
      "target": "OAK-T6.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M01",
      "target": "OAK-T6.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M02",
      "target": "OAK-T1.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M02",
      "target": "OAK-T1.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M02",
      "target": "OAK-T1.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M02",
      "target": "OAK-T1.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M02",
      "target": "OAK-T6.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M02",
      "target": "OAK-T6.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M02",
      "target": "OAK-T9.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M02",
      "target": "OAK-T9.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M02",
      "target": "OAK-T13.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M03",
      "target": "OAK-T1.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M03",
      "target": "OAK-T1.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M03",
      "target": "OAK-T2.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M03",
      "target": "OAK-T6.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M03",
      "target": "OAK-T6.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M03",
      "target": "OAK-T9.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M03",
      "target": "OAK-T11.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M04",
      "target": "OAK-T2.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M04",
      "target": "OAK-T3.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M04",
      "target": "OAK-T3.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M04",
      "target": "OAK-T3.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M04",
      "target": "OAK-T8.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M04",
      "target": "OAK-T8.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M04",
      "target": "OAK-T1.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M04",
      "target": "OAK-T2.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M05",
      "target": "OAK-T1.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M05",
      "target": "OAK-T1.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M05",
      "target": "OAK-T9.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M05",
      "target": "OAK-T9.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M05",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M05",
      "target": "OAK-T11.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M05",
      "target": "OAK-T11.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M06",
      "target": "OAK-T5.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M06",
      "target": "OAK-T13.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M06",
      "target": "OAK-T14.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M07",
      "target": "OAK-T7.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M07",
      "target": "OAK-T7.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M07",
      "target": "OAK-T7.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M07",
      "target": "OAK-T7.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M07",
      "target": "OAK-T7.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M07",
      "target": "OAK-T7.006"
    },
    {
      "type": "mitigates",
      "source": "OAK-M07",
      "target": "OAK-T8.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M07",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M08",
      "target": "OAK-T4.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M08",
      "target": "OAK-T4.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M08",
      "target": "OAK-T4.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M08",
      "target": "OAK-T4.006"
    },
    {
      "type": "mitigates",
      "source": "OAK-M09",
      "target": "OAK-T9.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M09",
      "target": "OAK-T9.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M10",
      "target": "OAK-T9.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M10",
      "target": "OAK-T9.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M11",
      "target": "OAK-T5.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M11",
      "target": "OAK-T5.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M11",
      "target": "OAK-T9.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M11",
      "target": "OAK-T9.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M11",
      "target": "OAK-T10.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M11",
      "target": "OAK-T10.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M12",
      "target": "OAK-T10.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M12",
      "target": "OAK-T10.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M13",
      "target": "OAK-T10.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M14",
      "target": "OAK-T10.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M15",
      "target": "OAK-T10.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M15",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M15",
      "target": "OAK-T11.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T1.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T1.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T1.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T6.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T6.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T6.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T6.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T9.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T9.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T9.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T9.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T9.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T10.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T10.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T10.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T10.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M16",
      "target": "OAK-T10.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M17",
      "target": "OAK-T9.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M18",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M18",
      "target": "OAK-T11.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M18",
      "target": "OAK-T11.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M18",
      "target": "OAK-T4.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M18",
      "target": "OAK-T4.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M18",
      "target": "OAK-T4.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M18",
      "target": "OAK-T4.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M18",
      "target": "OAK-T4.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M18",
      "target": "OAK-T4.006"
    },
    {
      "type": "mitigates",
      "source": "OAK-M19",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M19",
      "target": "OAK-T11.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M19",
      "target": "OAK-T11.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M20",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M20",
      "target": "OAK-T11.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M21",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M21",
      "target": "OAK-T11.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M22",
      "target": "OAK-T1.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M22",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M22",
      "target": "OAK-T11.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M22",
      "target": "OAK-T11.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M22",
      "target": "OAK-T9.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M23",
      "target": "OAK-T6.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M23",
      "target": "OAK-T6.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M23",
      "target": "OAK-T6.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M23",
      "target": "OAK-T6.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M23",
      "target": "OAK-T1.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M24",
      "target": "OAK-T6.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M24",
      "target": "OAK-T6.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M25",
      "target": "OAK-T1.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M25",
      "target": "OAK-T1.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M25",
      "target": "OAK-T1.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M25",
      "target": "OAK-T1.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M25",
      "target": "OAK-T1.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M25",
      "target": "OAK-T2.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M25",
      "target": "OAK-T2.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M25",
      "target": "OAK-T2.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M25",
      "target": "OAK-T2.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M25",
      "target": "OAK-T6.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M25",
      "target": "OAK-T6.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M25",
      "target": "OAK-T6.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M25",
      "target": "OAK-T6.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M26",
      "target": "OAK-T3.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M26",
      "target": "OAK-T7.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M26",
      "target": "OAK-T12.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M27",
      "target": "OAK-T7.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M27",
      "target": "OAK-T7.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M27",
      "target": "OAK-T7.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M28",
      "target": "OAK-T5.006"
    },
    {
      "type": "mitigates",
      "source": "OAK-M29",
      "target": "OAK-T4.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M30",
      "target": "OAK-T4.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M30",
      "target": "OAK-T4.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M30",
      "target": "OAK-T4.006"
    },
    {
      "type": "mitigates",
      "source": "OAK-M31",
      "target": "OAK-T4.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M31",
      "target": "OAK-T4.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M31",
      "target": "OAK-T4.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T1.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T1.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T1.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T1.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T1.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T6.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T6.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T6.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T6.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T9.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T9.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T9.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T9.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T9.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T10.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T10.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T10.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T10.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M32",
      "target": "OAK-T10.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M33",
      "target": "OAK-T9.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M33",
      "target": "OAK-T9.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M33",
      "target": "OAK-T9.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M33",
      "target": "OAK-T9.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M33",
      "target": "OAK-T9.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M33",
      "target": "OAK-T10.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M33",
      "target": "OAK-T10.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M33",
      "target": "OAK-T10.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M33",
      "target": "OAK-T10.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M33",
      "target": "OAK-T10.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M33",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M33",
      "target": "OAK-T11.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M33",
      "target": "OAK-T11.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M34",
      "target": "OAK-T9.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M34",
      "target": "OAK-T9.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M34",
      "target": "OAK-T9.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M34",
      "target": "OAK-T9.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M34",
      "target": "OAK-T9.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M34",
      "target": "OAK-T10.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M34",
      "target": "OAK-T10.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M34",
      "target": "OAK-T10.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M34",
      "target": "OAK-T10.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M34",
      "target": "OAK-T10.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M34",
      "target": "OAK-T11.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M35",
      "target": "OAK-T9.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M35",
      "target": "OAK-T9.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M35",
      "target": "OAK-T9.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M35",
      "target": "OAK-T9.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M35",
      "target": "OAK-T9.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M35",
      "target": "OAK-T10.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M35",
      "target": "OAK-T10.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M35",
      "target": "OAK-T10.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M35",
      "target": "OAK-T10.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M35",
      "target": "OAK-T10.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M35",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M35",
      "target": "OAK-T11.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M35",
      "target": "OAK-T11.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M36",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M36",
      "target": "OAK-T11.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M36",
      "target": "OAK-T11.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M37",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M37",
      "target": "OAK-T11.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M37",
      "target": "OAK-T11.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M37",
      "target": "OAK-T10.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M38",
      "target": "OAK-T5.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M38",
      "target": "OAK-T5.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M38",
      "target": "OAK-T5.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M38",
      "target": "OAK-T9.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M38",
      "target": "OAK-T9.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M38",
      "target": "OAK-T9.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M38",
      "target": "OAK-T9.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M38",
      "target": "OAK-T10.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M38",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M38",
      "target": "OAK-T11.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M38",
      "target": "OAK-T11.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T9.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T9.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T9.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T9.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T9.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T10.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T10.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T10.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T10.004"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T10.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T11.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T11.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T8.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M39",
      "target": "OAK-T8.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M40",
      "target": "OAK-T11.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M40",
      "target": "OAK-T11.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M40",
      "target": "OAK-T1.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M40",
      "target": "OAK-T4.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M40",
      "target": "OAK-T4.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M40",
      "target": "OAK-T4.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M40",
      "target": "OAK-T4.006"
    },
    {
      "type": "mitigates",
      "source": "OAK-M41",
      "target": "OAK-T7.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M41",
      "target": "OAK-T7.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M41",
      "target": "OAK-T7.006"
    },
    {
      "type": "mitigates",
      "source": "OAK-M41",
      "target": "OAK-T7.007"
    },
    {
      "type": "mitigates",
      "source": "OAK-M41",
      "target": "OAK-T7.008"
    },
    {
      "type": "mitigates",
      "source": "OAK-M41",
      "target": "OAK-T5.008"
    },
    {
      "type": "mitigates",
      "source": "OAK-M42",
      "target": "OAK-T7.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M42",
      "target": "OAK-T7.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M42",
      "target": "OAK-T7.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M42",
      "target": "OAK-T7.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M42",
      "target": "OAK-T5.008"
    },
    {
      "type": "mitigates",
      "source": "OAK-M43",
      "target": "OAK-T7.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M43",
      "target": "OAK-T7.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M43",
      "target": "OAK-T7.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M43",
      "target": "OAK-T7.006"
    },
    {
      "type": "mitigates",
      "source": "OAK-M43",
      "target": "OAK-T7.007"
    },
    {
      "type": "mitigates",
      "source": "OAK-M43",
      "target": "OAK-T7.008"
    },
    {
      "type": "mitigates",
      "source": "OAK-M43",
      "target": "OAK-T8.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M43",
      "target": "OAK-T8.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M44",
      "target": "OAK-T11.006"
    },
    {
      "type": "mitigates",
      "source": "OAK-M44",
      "target": "OAK-T11.006.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M44",
      "target": "OAK-T11.006.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M44",
      "target": "OAK-T11.007.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M44",
      "target": "OAK-T4.010"
    },
    {
      "type": "mitigates",
      "source": "OAK-M45",
      "target": "OAK-T11.007.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M45",
      "target": "OAK-T11.005.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M45",
      "target": "OAK-T11.005.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M45",
      "target": "OAK-T4.010"
    },
    {
      "type": "mitigates",
      "source": "OAK-M46",
      "target": "OAK-T11.005"
    },
    {
      "type": "mitigates",
      "source": "OAK-M46",
      "target": "OAK-T11.005.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M46",
      "target": "OAK-T11.005.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M46",
      "target": "OAK-T11.005.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M46",
      "target": "OAK-T11.010"
    },
    {
      "type": "mitigates",
      "source": "OAK-M47",
      "target": "OAK-T11.007.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M47",
      "target": "OAK-T4.008"
    },
    {
      "type": "mitigates",
      "source": "OAK-M47",
      "target": "OAK-T4.010"
    },
    {
      "type": "mitigates",
      "source": "OAK-M47",
      "target": "OAK-T6.006"
    },
    {
      "type": "mitigates",
      "source": "OAK-M47",
      "target": "OAK-T11.002"
    },
    {
      "type": "mitigates",
      "source": "OAK-M48",
      "target": "OAK-T15.001"
    },
    {
      "type": "mitigates",
      "source": "OAK-M48",
      "target": "OAK-T15.003"
    },
    {
      "type": "mitigates",
      "source": "OAK-M48",
      "target": "OAK-T11.009"
    },
    {
      "type": "mitigates",
      "source": "OAK-M48",
      "target": "OAK-T15.002"
    },
    {
      "type": "uses",
      "source": "OAK-S01",
      "target": "OAK-T4.001"
    },
    {
      "type": "uses",
      "source": "OAK-S01",
      "target": "OAK-T4.002"
    },
    {
      "type": "uses",
      "source": "OAK-S01",
      "target": "OAK-T4.004"
    },
    {
      "type": "uses",
      "source": "OAK-S01",
      "target": "OAK-T4.005"
    },
    {
      "type": "uses",
      "source": "OAK-S01",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S01",
      "target": "OAK-T7.003"
    },
    {
      "type": "uses",
      "source": "OAK-S01",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-S01",
      "target": "OAK-T8.002"
    },
    {
      "type": "uses",
      "source": "OAK-G02",
      "target": "OAK-S01"
    },
    {
      "type": "uses",
      "source": "OAK-S02",
      "target": "OAK-T4.001"
    },
    {
      "type": "uses",
      "source": "OAK-S02",
      "target": "OAK-T4.002"
    },
    {
      "type": "uses",
      "source": "OAK-S02",
      "target": "OAK-T4.004"
    },
    {
      "type": "uses",
      "source": "OAK-S02",
      "target": "OAK-T4.005"
    },
    {
      "type": "uses",
      "source": "OAK-S02",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S02",
      "target": "OAK-T7.003"
    },
    {
      "type": "uses",
      "source": "OAK-S02",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-S02",
      "target": "OAK-T8.002"
    },
    {
      "type": "uses",
      "source": "OAK-G02",
      "target": "OAK-S02"
    },
    {
      "type": "uses",
      "source": "OAK-S03",
      "target": "OAK-T4.001"
    },
    {
      "type": "uses",
      "source": "OAK-S03",
      "target": "OAK-T4.002"
    },
    {
      "type": "uses",
      "source": "OAK-S03",
      "target": "OAK-T4.004"
    },
    {
      "type": "uses",
      "source": "OAK-S03",
      "target": "OAK-T4.005"
    },
    {
      "type": "uses",
      "source": "OAK-S03",
      "target": "OAK-T4.006"
    },
    {
      "type": "uses",
      "source": "OAK-S03",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S03",
      "target": "OAK-T7.003"
    },
    {
      "type": "uses",
      "source": "OAK-S03",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-G02",
      "target": "OAK-S03"
    },
    {
      "type": "uses",
      "source": "OAK-S04",
      "target": "OAK-T4.001"
    },
    {
      "type": "uses",
      "source": "OAK-S04",
      "target": "OAK-T4.004"
    },
    {
      "type": "uses",
      "source": "OAK-S04",
      "target": "OAK-T4.005"
    },
    {
      "type": "uses",
      "source": "OAK-S04",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S04",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-G02",
      "target": "OAK-S04"
    },
    {
      "type": "uses",
      "source": "OAK-S05",
      "target": "OAK-T4.001"
    },
    {
      "type": "uses",
      "source": "OAK-S05",
      "target": "OAK-T4.004"
    },
    {
      "type": "uses",
      "source": "OAK-S05",
      "target": "OAK-T4.005"
    },
    {
      "type": "uses",
      "source": "OAK-S05",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S05",
      "target": "OAK-T7.003"
    },
    {
      "type": "uses",
      "source": "OAK-S05",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-G02",
      "target": "OAK-S05"
    },
    {
      "type": "uses",
      "source": "OAK-S06",
      "target": "OAK-T4.001"
    },
    {
      "type": "uses",
      "source": "OAK-S06",
      "target": "OAK-T4.004"
    },
    {
      "type": "uses",
      "source": "OAK-S06",
      "target": "OAK-T4.005"
    },
    {
      "type": "uses",
      "source": "OAK-S06",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S06",
      "target": "OAK-T7.003"
    },
    {
      "type": "uses",
      "source": "OAK-S06",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-S06",
      "target": "OAK-T8.002"
    },
    {
      "type": "uses",
      "source": "OAK-G02",
      "target": "OAK-S06"
    },
    {
      "type": "uses",
      "source": "OAK-S07",
      "target": "OAK-T4.001"
    },
    {
      "type": "uses",
      "source": "OAK-S07",
      "target": "OAK-T4.004"
    },
    {
      "type": "uses",
      "source": "OAK-S07",
      "target": "OAK-T4.005"
    },
    {
      "type": "uses",
      "source": "OAK-S07",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S07",
      "target": "OAK-T7.003"
    },
    {
      "type": "uses",
      "source": "OAK-S07",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-G02",
      "target": "OAK-S07"
    },
    {
      "type": "uses",
      "source": "OAK-S08",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-S08",
      "target": "OAK-T11.002"
    },
    {
      "type": "uses",
      "source": "OAK-G01",
      "target": "OAK-S08"
    },
    {
      "type": "uses",
      "source": "OAK-S09",
      "target": "OAK-T11.002"
    },
    {
      "type": "uses",
      "source": "OAK-S09",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-G01",
      "target": "OAK-S09"
    },
    {
      "type": "uses",
      "source": "OAK-S10",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-S10",
      "target": "OAK-T10.001"
    },
    {
      "type": "uses",
      "source": "OAK-G01",
      "target": "OAK-S10"
    },
    {
      "type": "uses",
      "source": "OAK-S11",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-G01",
      "target": "OAK-S11"
    },
    {
      "type": "uses",
      "source": "OAK-S12",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-G07",
      "target": "OAK-S12"
    },
    {
      "type": "uses",
      "source": "OAK-S13",
      "target": "OAK-T11.002"
    },
    {
      "type": "uses",
      "source": "OAK-S13",
      "target": "OAK-T4.004"
    },
    {
      "type": "uses",
      "source": "OAK-S13",
      "target": "OAK-T4.005"
    },
    {
      "type": "uses",
      "source": "OAK-S14",
      "target": "OAK-T11.002"
    },
    {
      "type": "uses",
      "source": "OAK-S14",
      "target": "OAK-T4.004"
    },
    {
      "type": "uses",
      "source": "OAK-S14",
      "target": "OAK-T4.005"
    },
    {
      "type": "uses",
      "source": "OAK-S15",
      "target": "OAK-T11.002"
    },
    {
      "type": "uses",
      "source": "OAK-S15",
      "target": "OAK-T4.004"
    },
    {
      "type": "uses",
      "source": "OAK-S15",
      "target": "OAK-T4.005"
    },
    {
      "type": "uses",
      "source": "OAK-S16",
      "target": "OAK-T11.004"
    },
    {
      "type": "uses",
      "source": "OAK-S17",
      "target": "OAK-T5.004"
    },
    {
      "type": "uses",
      "source": "OAK-S18",
      "target": "OAK-T3.001"
    },
    {
      "type": "uses",
      "source": "OAK-S18",
      "target": "OAK-T2.001"
    },
    {
      "type": "uses",
      "source": "OAK-S18",
      "target": "OAK-T13.002"
    },
    {
      "type": "uses",
      "source": "OAK-S19",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-S19",
      "target": "OAK-T11.002"
    },
    {
      "type": "uses",
      "source": "OAK-G01",
      "target": "OAK-S19"
    },
    {
      "type": "uses",
      "source": "OAK-S20",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-S20",
      "target": "OAK-T11.002"
    },
    {
      "type": "uses",
      "source": "OAK-G08",
      "target": "OAK-S20"
    },
    {
      "type": "uses",
      "source": "OAK-G01",
      "target": "OAK-S20"
    },
    {
      "type": "uses",
      "source": "OAK-S21",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-S21",
      "target": "OAK-T11.002"
    },
    {
      "type": "uses",
      "source": "OAK-G01",
      "target": "OAK-S21"
    },
    {
      "type": "uses",
      "source": "OAK-G08",
      "target": "OAK-S21"
    },
    {
      "type": "uses",
      "source": "OAK-S22",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-S22",
      "target": "OAK-T11.002"
    },
    {
      "type": "uses",
      "source": "OAK-G01",
      "target": "OAK-S22"
    },
    {
      "type": "uses",
      "source": "OAK-G08",
      "target": "OAK-S22"
    },
    {
      "type": "uses",
      "source": "OAK-S23",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S23",
      "target": "OAK-T7.002"
    },
    {
      "type": "uses",
      "source": "OAK-S23",
      "target": "OAK-T7.003"
    },
    {
      "type": "uses",
      "source": "OAK-G05",
      "target": "OAK-S23"
    },
    {
      "type": "uses",
      "source": "OAK-G06",
      "target": "OAK-S23"
    },
    {
      "type": "uses",
      "source": "OAK-S24",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S24",
      "target": "OAK-T7.002"
    },
    {
      "type": "uses",
      "source": "OAK-S24",
      "target": "OAK-T7.003"
    },
    {
      "type": "uses",
      "source": "OAK-G10",
      "target": "OAK-S24"
    },
    {
      "type": "uses",
      "source": "OAK-S25",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S25",
      "target": "OAK-T7.002"
    },
    {
      "type": "uses",
      "source": "OAK-S25",
      "target": "OAK-T8.002"
    },
    {
      "type": "uses",
      "source": "OAK-G09",
      "target": "OAK-S25"
    },
    {
      "type": "uses",
      "source": "OAK-G01",
      "target": "OAK-S25"
    },
    {
      "type": "uses",
      "source": "OAK-S26",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S26",
      "target": "OAK-T7.002"
    },
    {
      "type": "uses",
      "source": "OAK-S26",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-G06",
      "target": "OAK-S26"
    },
    {
      "type": "uses",
      "source": "OAK-G05",
      "target": "OAK-S26"
    },
    {
      "type": "uses",
      "source": "OAK-S27",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S27",
      "target": "OAK-T7.002"
    },
    {
      "type": "uses",
      "source": "OAK-S27",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-G11",
      "target": "OAK-S27"
    },
    {
      "type": "uses",
      "source": "OAK-S28",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S28",
      "target": "OAK-T7.002"
    },
    {
      "type": "uses",
      "source": "OAK-S28",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-S29",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-S29",
      "target": "OAK-T11.002"
    },
    {
      "type": "uses",
      "source": "OAK-G01",
      "target": "OAK-S29"
    },
    {
      "type": "uses",
      "source": "OAK-G08",
      "target": "OAK-S29"
    },
    {
      "type": "uses",
      "source": "OAK-S30",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-S30",
      "target": "OAK-T11.002"
    },
    {
      "type": "uses",
      "source": "OAK-G01",
      "target": "OAK-S30"
    },
    {
      "type": "uses",
      "source": "OAK-G08",
      "target": "OAK-S30"
    },
    {
      "type": "uses",
      "source": "OAK-S31",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S31",
      "target": "OAK-T7.002"
    },
    {
      "type": "uses",
      "source": "OAK-S31",
      "target": "OAK-T8.002"
    },
    {
      "type": "uses",
      "source": "OAK-G09",
      "target": "OAK-S31"
    },
    {
      "type": "uses",
      "source": "OAK-S32",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S32",
      "target": "OAK-T7.002"
    },
    {
      "type": "uses",
      "source": "OAK-S32",
      "target": "OAK-T8.002"
    },
    {
      "type": "uses",
      "source": "OAK-G07",
      "target": "OAK-S32"
    },
    {
      "type": "uses",
      "source": "OAK-S33",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S33",
      "target": "OAK-T7.002"
    },
    {
      "type": "uses",
      "source": "OAK-S33",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-G16",
      "target": "OAK-S33"
    },
    {
      "type": "uses",
      "source": "OAK-S34",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S34",
      "target": "OAK-T7.002"
    },
    {
      "type": "uses",
      "source": "OAK-S34",
      "target": "OAK-T7.003"
    },
    {
      "type": "uses",
      "source": "OAK-S34",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-G15",
      "target": "OAK-S34"
    },
    {
      "type": "uses",
      "source": "OAK-S35",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S35",
      "target": "OAK-T7.002"
    },
    {
      "type": "uses",
      "source": "OAK-S35",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-G17",
      "target": "OAK-S35"
    },
    {
      "type": "uses",
      "source": "OAK-S36",
      "target": "OAK-T7.001"
    },
    {
      "type": "uses",
      "source": "OAK-S36",
      "target": "OAK-T7.002"
    },
    {
      "type": "uses",
      "source": "OAK-S36",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-S36",
      "target": "OAK-T8.002"
    },
    {
      "type": "uses",
      "source": "OAK-G18",
      "target": "OAK-S36"
    },
    {
      "type": "uses",
      "source": "OAK-S37",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-S37",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-G05",
      "target": "OAK-S37"
    },
    {
      "type": "uses",
      "source": "OAK-G09",
      "target": "OAK-S37"
    },
    {
      "type": "uses",
      "source": "OAK-G10",
      "target": "OAK-S37"
    },
    {
      "type": "uses",
      "source": "OAK-G11",
      "target": "OAK-S37"
    },
    {
      "type": "uses",
      "source": "OAK-G14",
      "target": "OAK-S37"
    },
    {
      "type": "uses",
      "source": "OAK-G15",
      "target": "OAK-S37"
    },
    {
      "type": "uses",
      "source": "OAK-G16",
      "target": "OAK-S37"
    },
    {
      "type": "uses",
      "source": "OAK-G17",
      "target": "OAK-S37"
    },
    {
      "type": "uses",
      "source": "OAK-G18",
      "target": "OAK-S37"
    },
    {
      "type": "uses",
      "source": "OAK-G06",
      "target": "OAK-S37"
    },
    {
      "type": "uses",
      "source": "OAK-S38",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-S38",
      "target": "OAK-T11.002"
    },
    {
      "type": "uses",
      "source": "OAK-S38",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-G05",
      "target": "OAK-S38"
    },
    {
      "type": "uses",
      "source": "OAK-G10",
      "target": "OAK-S38"
    },
    {
      "type": "uses",
      "source": "OAK-G11",
      "target": "OAK-S38"
    },
    {
      "type": "uses",
      "source": "OAK-G14",
      "target": "OAK-S38"
    },
    {
      "type": "uses",
      "source": "OAK-G16",
      "target": "OAK-S38"
    },
    {
      "type": "uses",
      "source": "OAK-G17",
      "target": "OAK-S38"
    },
    {
      "type": "uses",
      "source": "OAK-G18",
      "target": "OAK-S38"
    },
    {
      "type": "uses",
      "source": "OAK-S39",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-S39",
      "target": "OAK-T11.002"
    },
    {
      "type": "uses",
      "source": "OAK-S39",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-G05",
      "target": "OAK-S39"
    },
    {
      "type": "uses",
      "source": "OAK-G10",
      "target": "OAK-S39"
    },
    {
      "type": "uses",
      "source": "OAK-G11",
      "target": "OAK-S39"
    },
    {
      "type": "uses",
      "source": "OAK-G16",
      "target": "OAK-S39"
    },
    {
      "type": "uses",
      "source": "OAK-S40",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-S40",
      "target": "OAK-T11.002"
    },
    {
      "type": "uses",
      "source": "OAK-S40",
      "target": "OAK-T8.001"
    },
    {
      "type": "uses",
      "source": "OAK-G05",
      "target": "OAK-S40"
    },
    {
      "type": "uses",
      "source": "OAK-G10",
      "target": "OAK-S40"
    },
    {
      "type": "uses",
      "source": "OAK-G11",
      "target": "OAK-S40"
    },
    {
      "type": "uses",
      "source": "OAK-G14",
      "target": "OAK-S40"
    },
    {
      "type": "uses",
      "source": "OAK-S41",
      "target": "OAK-T15.001"
    },
    {
      "type": "uses",
      "source": "OAK-S41",
      "target": "OAK-T15.003"
    },
    {
      "type": "uses",
      "source": "OAK-S41",
      "target": "OAK-T11.001"
    },
    {
      "type": "uses",
      "source": "OAK-G01",
      "target": "OAK-S41"
    }
  ]
}
