Mitigations
48 defender controls, each mapped to the Techniques it blunts.
Mitigations (48)
- OAK-M01 Source-Bytecode Verification — detection, 7 Techniques
- OAK-M02 Static-Analysis Pre-Deployment — architecture, 9 Techniques
- OAK-M03 Continuous Bytecode-Diff Monitoring — detection, 7 Techniques
- OAK-M04 Funder-Graph Clustering — detection, 8 Techniques
- OAK-M05 Authority-Graph Enumeration — detection, 7 Techniques
- OAK-M06 Mempool / Pre-Block Telemetry — detection, 3 Techniques
- OAK-M07 Cross-Chain Attribution Graph — detection, 8 Techniques
- OAK-M08 Per-Spender Approval Audit and Revocation — wallet-ux, 4 Techniques
- OAK-M09 TWAP + Multi-Venue Oracle with Deviation Circuit-Breaker — architecture, 2 Techniques
- OAK-M10 Checks-Effects-Interactions and ReentrancyGuard — architecture, 2 Techniques
- OAK-M11 Rate-Limiting and Per-Block Caps — architecture, 6 Techniques
- OAK-M12 Per-Message Replay Binding — architecture, 2 Techniques
- OAK-M13 Long Challenge Window with Economic Challenger Incentives — architecture, 1 Techniques
- OAK-M14 Multi-Prover Redundancy — architecture, 1 Techniques
- OAK-M15 Threshold Signing with Operator Separation — architecture, 3 Techniques
- OAK-M16 Pre-Deployment Audit and Formal Verification — architecture, 17 Techniques
- OAK-M17 Time-Locked Governance and Multi-Block Quorum — architecture, 1 Techniques
- OAK-M18 Out-of-Band Destination Verification — operational, 9 Techniques
- OAK-M19 Air-Gap Cold-Wallet Signing — operational, 3 Techniques
- OAK-M20 Vendor Breach-Notification SLA — operational, 2 Techniques
- OAK-M21 Anti-Phishing Training for Privileged Staff — operational, 2 Techniques
- OAK-M22 Rotate-on-Disclosure Discipline — operational, 5 Techniques
- OAK-M23 Audit-Attestation Public-Registry Verification — venue, 5 Techniques
- OAK-M24 Out-of-Band Audit-Engagement Verification — venue, 2 Techniques
- OAK-M25 Listing-Time Source-Verification + Audit-Status Gate — venue, 13 Techniques
- OAK-M26 Wash-Trade-Rate Metrics at Marketplace Layer — venue, 3 Techniques
- OAK-M27 Travel Rule and KYC at Privacy-Chain Boundary — venue, 3 Techniques
- OAK-M28 Token-Unlock Calendar Integration — venue, 1 Techniques
- OAK-M29 Full-Address Verification and Lookalike Detection — wallet-ux, 1 Techniques
- OAK-M30 Per-dApp Domain and App-Store-Package Allowlist — wallet-ux, 3 Techniques
- OAK-M31 EIP-712 Permit Display and Signing-Risk Heuristics — wallet-ux, 3 Techniques
- OAK-M32 Bug Bounty Programs — operational, 19 Techniques
- OAK-M33 Decentralized Insurance Protocols — operational, 13 Techniques
- OAK-M34 Pause-by-Default Emergency Pause — architecture, 11 Techniques
- OAK-M35 Whitehat-Rescue Coordination — operational, 13 Techniques
- OAK-M36 Proof-of-Reserves Cryptographic Auditing — venue, 3 Techniques
- OAK-M37 HSM and MPC Custody Architectures — operational, 4 Techniques
- OAK-M38 Time-Windowed Withdrawal Limits — architecture, 11 Techniques
- OAK-M39 Cross-Protocol Watcher Network — detection, 15 Techniques
- OAK-M40 Supply-Chain Package Integrity — operational, 7 Techniques
- OAK-M41 Asset Freeze and Confiscate Coordination Workflow — venue, 6 Techniques
- OAK-M42 SAR/STR Filing and Financial Intelligence Feedback Loop — venue, 5 Techniques
- OAK-M43 KYT Operational Practice and Cross-VASP Coordination — venue, 8 Techniques
- OAK-M44 Seed-Phrase Disclosure Refusal and Storage Isolation — user-behavioural, 5 Techniques
- OAK-M45 Inbound-Contact Refusal and Out-of-Band Callback — user-behavioural, 4 Techniques
- OAK-M46 Small-Test-Withdrawal Invariant and Advance-Fee Refusal — user-behavioural, 5 Techniques
- OAK-M47 First-Party Acquisition and Self-Typed Navigation — user-behavioural, 5 Techniques
- OAK-M48 Unsolicited-Code Quarantine and Pre-Execution Manifest Review — operational, 4 Techniques