The cryptography may hold while the surrounding interpretation fails.
Why it matters
A threat model organized around trust boundaries is more durable than a list of yesterday's malware names.
Signing without understanding
Blind signing, deceptive interfaces and address substitution exploit the gap between machine-readable authorization and human intent.
Dependencies and deployment
Package accounts, build systems, DNS, front ends and browser extensions can alter what reaches a user without breaking a base-layer protocol.
Concentrated bridges and governance
Bridges and upgrade keys can gather authority into small committees. Multisignature arithmetic is not enough if members, devices or policies share one failure mode.
Defensive reading
Ask what was known at the time, which boundary failed, how far authority reached, what contained damage, and whether remediation changed incentives—not merely software versions.