Evidence discipline has materially changed the response in all four cases. On Notional V1, the supported figure is $1,727,782.23 in gross nominal stablecoin outflow; roughly 689 ETH is the reported swap output, not an additional loss. The unsafe uint128 downcast and Tornado Cash routing remain reported rather than fully reconciled at transaction level, so net loss, attribution, recovery, and final ownership are unresolved. The immediate operational conclusion is still clear: quarantine or migrate the legacy escrow and close its approvals, privileges, integrations, and monitoring gaps.
The same calibration applies elsewhere. Elena does not support a blanket 10/10 rating for US control-system operators. Iranian-affiliated targeting of exposed OT is supportable, but state direction, a coordinated sabotage campaign, and major operational damage are not established. Urgency becomes critical where matching indicators or unauthorized engineering activity are present; every operator should nevertheless remove public PLC exposure, restrict engineering access, enforce MFA, validate safety logic, and inspect the relevant indicators. For ShipMonk and Trezor, controller–processor roles and notification clocks cannot be settled from labels alone. They depend on contracts, actual data use, affected jurisdictions, exposed fields, evidence of access or extraction, and each party’s awareness date. Those facts, logs, timestamps, and notification decisions need preservation now.
On Pegasus, the distinction is equally important: one infection is confirmed, while at least 14 Apple notifications indicate targeting, not 14 infections. Confirmed and notified users should preserve devices for qualified forensic collection where help is promptly available; where immediate personal safety outweighs evidentiary value, patching and Lockdown Mode take priority. Other high-risk users should update to the latest supported iOS and enable Lockdown Mode.
These four tracks reinforce why James’s close now needs revision: confirmed compromise, suspected exploitation, exposure reduction, browser deployment, and regulatory triage should not sit under one undifferentiated Sev-1. The next step is to separate those response categories while preserving urgency where the evidence actually supports it.