Security Research
Security and risk research for organisations navigating emerging technology exposures.
Research library

From Control Boundary to Insurance Claim: The CER Framework
When an AI system causes a loss, can it be controlled, reconstructed, and recovered through insurance? A framework for answering that question.
Explore the framework
OneInfinity: Insuring Web3
An independent CUHK teaching case exploring how OneInfinity’s insurance capabilities and technical understanding could shape its position in the Web3 market.
View the case study
Recent Centralized Platform Hack Tactics & Mitigation
Mapping the attack tactics behind over $2 billion in centralized platform losses and the layered controls that can disrupt them.
Read the analysis
Bybit Incident Research
How a supply-chain compromise bypassed multi-signature controls in the largest crypto theft in history, and what custody operations can learn from it.
Read the analysis
DMM Bitcoin May 2024 Incident Analysis
Reconstructing the probable attack behind DMM Bitcoin’s $305 million loss through on-chain forensic evidence.
Read the analysis
Decentralized Insurance Alternatives: Market Landscape, Opportunities and Challenges
Examining whether peer-to-peer capital pools and on-chain claims assessment can scale into sustainable alternatives to traditional insurance.
Read the report
A Risk Classification Framework for Decentralized Finance Protocols
Classifying the technical, economic, operational and infrastructure risks of DeFi protocols - giving insurers a consistent basis for comparing exposures.
Read the reportExplore what we can build together
Our research programme is actively expanding across Web3, cybersecurity and AI. If you are working on related problems or see opportunities for collaboration, we would like to hear from you.
Research disclaimer
The research materials on this page are provided for informational purposes only and do not constitute professional advice, an offer of insurance, or a recommendation to purchase any product or service. Views expressed are those of the named contributors and do not necessarily reflect the position of OneInfinity, OneDegree Hong Kong Limited, or any affiliated entity. Conclusions drawn from incident analyses are based on information available at the time of publication and may be subject to change.

