Message Authentication Code (MAC)
A Message Authentication Code is a keyed cryptographic tag used to verify message integrity and authenticity between parties sharing secret material. A…
Security controls, fraud, operational risk and regulatory compliance.
A Message Authentication Code is a keyed cryptographic tag used to verify message integrity and authenticity between parties sharing secret material. A…
Metadata Privacy is a compliance or privacy requirement that protects contextual information about communications or transactions, including participants, timing, location, size, devices,…
An MFA fatigue attack repeatedly sends authentication prompts or approval requests to pressure, confuse, or trick a user into approving one, often…
Mobile Security is a security mechanism or control discipline that protects smartphones, tablets, applications, identities, communications, sensors, and stored data from compromise,…
Model risk is the possibility of harmful decisions or estimates caused by flawed models, data, assumptions, implementation, interpretation, or use. Model Risk…
MPC risk is exposure arising from the design, implementation, participation, communication, and recovery assumptions of secure multi-party computation. A score for MPC…
Multi-Factor Authentication (MFA) is a security mechanism or control discipline that requires evidence from at least two independent factor categories before granting…
Multi-Round Fraud Proof is a fraud or abuse pattern that resolves a disputed computation through successive challenge messages that isolate an invalid…
Multisig risk is exposure created by multi-signature thresholds, signer concentration, key custody, coordination, transaction review, and recovery arrangements. Multisig Risk must specify…
Network detection and response is the capability to analyze network traffic and related telemetry for suspicious behavior, investigate threats, and support containment…
A network partition attack deliberately separates nodes or services so different groups receive inconsistent information or cannot coordinate normally. Network Partition Attack…
Network Privacy is a compliance or privacy requirement that limits disclosure of communicating parties, addresses, routes, timing, traffic volume, and behavioral relationships…
Network risk is the possibility of loss caused by connectivity, routing, consensus, congestion, security, dependency, or availability failures within a network. A…
Network Security is a security mechanism or control discipline that protects communications, devices, services, and control planes from unauthorized access, interception, manipulation,…
A no-KYC payment allows a transaction without requiring the payer or merchant to complete a provider's standard identity-verification process beforehand. No- KYC…
A nonce reuse attack exploits the repeated use of a value that a cryptographic protocol requires to be unique, potentially revealing private…
Operational custody risk is the possibility that procedures, people, systems, or records fail while safeguarding, signing, moving, or recovering assets. A score…
Operational risk is the possibility of loss from failed processes, people, systems, external events, or inadequate execution of business activities. Decision-makers use…
Operational Security is a security mechanism or control discipline that protects sensitive activities and information by identifying what adversaries could observe, infer,…
Oracle Attack is an attack or weakness pattern that manipulates, delays, corrupts, or selectively exploits external data used by a protocol to…
An oracle exploit is a practical attack that abuses vulnerable data feeds or oracle-dependent logic to extract value or corrupt system state.…
Oracle risk is exposure created when systems rely on external data whose accuracy, availability, timing, incentives, or governance may fail. Oracle Risk…
Origin authentication verifies that data, software, requests, or messages came from the claimed source rather than an impersonator or substitute. Origin authentication…
Out of band authorization (OOB) is a security mechanism or control discipline that out-of-band authorization approves an action through a separate communication…
Core concepts behind cryptocurrency, blockchain and distributed systems.
367 terms
Networks, consensus systems, protocols and blockchain infrastructure.
543 terms
Digital assets, token standards, cryptocurrencies and stablecoins.
351 terms