Name: Pablo Sabbatella (pablito.eth)
Statement: I agree with the new security council mandate and charter and will act only in accordance with it.
Eligibility:
I am Pablo Sabbatella, also known as pablito.eth. I am a web3 operational security researcher, member of SEAL (Security Alliance) and founder of Opsek. I also created the “Blockchain Security series” podcast.
I am fully committed to improving the security of the ecosystem. I am totally convinced that security is the biggest issue the industry is facing right now, stopping it from achieving mass adoption. If we continue on this path, with DPRK being funded by large hacks like Bybit, we are gonna be a total failure.
I know for sure that my knowledge and experience will be valuable in order to enhance the security of ENS’s Security Council, infrastructure, team and community.
I am fully doxxed and dedicate lots of resources to talk about the importance of Security in the Web3 ecosystem from my Twitter account with more than 83K followers, with the Blockchain Security Series podcast and with lots of free Blockchain security courses you can check at at Defy Education Youtube Channel.
I know how security councils work and what they expect from signers and I can fulfil all those requirements.
I started with cybersecurity back in 1999, when I founded Hackemate and have been involved in technology since then. Today I am a signer in the Arbitrum Security Council, Optimism Security Council and the Polygon Protocol Council.
I founded Opsek, where we do operational security audits and training for Web3 organizations (DeFi, CEXs, L1s, L2s, VCs, service providers) and HNWIs. The reason behind my work and founding Opsek is very simple: 99% of funds being lost are due to operational security issues (Private key leakage, malware, 0day exploits, blind signingm, social engineering, phishing, account takeovers, domain hijacking, insider threat, etc) and not due to smart contract hacks anymore.
My expertise is understanding an organization, defining and protecting its attack surface: what does the organization do? Who is the team? What are the tools and tack that they use? What does the day to day operation look like? What are the most valuable assets it’s protecting? Which are the biggest risks? We also train the teams on physical security.
Part of our auditing process includes multisigs: how were they created? Who are the signers? What’s the appropriate threshold? How are private keys generated? How are seeds handled? Are they backed up or deleted? How do you travel with your hardware wallet? Have signers developed a threat model? Hardware wallet diversity, frontend diversity, transactions verification and simulation, definition of procedures and policies, etc. I spend a lot of time researching more and more on transactions signature procedures and how to make this processes safer.
We have already audited many firms (many of them we do not make public, but more than 50bn TVL). Some of them: Optimism, Electric Capital, Sky (ex MakerDao), Centrifuge, Contango, Midas, Aligned Layer, and many more.
I have participated in many war rooms, incident response and helped many people and companies save funds during attacks (and still do this daily).
Some of my presentations:
-
TOTP apps are dead and why you are doing 2FA wrong @ darkMode (Denver - 02/2026)
TOTP apps are dead and why you are doing 2FA wrong :: darkMode 2026 :: pretalx -
Professionals hack people, not systems @ DeFi Security Summit (Bangkok - 11/2024)
https://www.youtube.com/watch?v=1ZQIDkEfY5w -
Web3 Operational Security 101 @ DeFi Security Summit 101 (Buenos Aires - 11/2025)
https://www.youtube.com/watch?v=9KFyJiyjxfE -
Apple Stack Hardening: Security Essentials for macOS, iOS & AppleID @ DeFi Security Summit (Buenos Aires - 11/2025)
https://www.youtube.com/watch?v=jgc4z_gQ6vg -
OpSec for the Dark Forest (or how to avoid getting rekt) @ Devcon 7 (Bangkok - 11/2024)
Devcon Archive -
Operational security in Web3: a review of major OpSec incidents @ DSS Webinars (Online - 04/2025)
https://www.youtube.com/watch?v=GuQXUyMDd_s -
Physical and Operational Security 101 @ Ethereum Community Conference 8 (Cannes - 07/2025)
Physical and Operational Security 101 | EthCC[9] -
How to securely configure and use Telegram & Twitter @ Ethereum Community Conference 7 (Brussels - 07/2024)
How to securely configure and use Telegram & Twitter | EthCC[9] Archives
Projects I created but where I am not involved anymore:
- I co-founded Ethereum Argentina.
- I created the first “Blockchain and DeFi" subject in an Argentinian University and served as teacher for two years.
- I founded Defy Education.
Disclosure: I am an active signer in the Arbitrum Security Council, Optimism Security Council and the Polygon Protocol Council. None of them have conflicts of interest.
Links:
- Website: https://pablosabbatella.com
- Opsek: https://opsek.io
- Security Alliance (SEAL): https://www.securityalliance.org/members/user_NOdX506vRbyrYH2U
- Cybersecurity alerts: Telegram: Join Group Chat
- Blockchain Security Series: https://bss.fm
- X profile: Pablo Sabbatella (@PabloSabbatella) / X
- Linkedin: Pablo Sabbatella - Opsek | LinkedIn
Confirmation: I have made no statements contradicting the security council mandate and charter. If elected I agree to sign the appointment agreement and undergo a KYC and background check.