🥷 Security-First Solidity Dev 🏅 SSCD+ | QWS+ certified @CyfrinUpdraft ✍️ Co-author SSCD+ study guides 🗣️ Ambassador @Cyfrin 🤝 Contributor SEAL Frameworks

Pinned Tweet
Blessed to have earned my second certification from @CyfrinUpdraft! Now, I’m officially a QWS (Qualified Web3 Signer) certified along with SSCD+. A huge thank you to the @cyfrin team and @PatrickAlphaC for creating such amazing tools like Safe Hash and Wise Signer.
35
5
113
19,710
Some news: I’m no longer at Aztec following the recent restructuring I’m on the hunt for a new role in DevRel or technical sales, so if you’re hiring, reach out! In the meantime, I will be getting back to making videos again after a much needed rest 🩷
30
18
327
23,521
we're heading towards complete retardation man. the vast majority of the world is not fucking ready for self-sovereignty and probably never will be. wallets have sucked ass at protecting normal users for over a decade. seed phrases & private keys are an utterly shit security model for humans (oh, and multisigs are great but people protect their 3/5 multisig with the same seed, so also full retard mode). and yet we're still pretending this is the future of finance. it's fucking not. most of this industry is a VC exit-liquidity circle jerk where the end user ultimately eats the loss in some form. maybe the answer isn't mass adoption. maybe the answer is staying fucking small. small, weird, technical, paranoid, adversarial, and hard to capture. the smaller and more niche we stay, the more dangerous and long-lasting this industry becomes. being small is a feature.
60
48
488
31,152
Usman retweeted
Next week, we'll be releasing the first version of the phishing dojo. We're looking for founding customers! More on this soon.
2
19
315
Not only DPRK. A vibe-coded phishing frontend for Microsoft Teams, found in the wild. With the proliferation of capable, unrestricted LLMs, we often observe unaffiliated threat actors deploying fully vibe-coded malware infrastructure. In this example, an endpoint misconfiguration exposed the phishing kit's assets along with the LLM's comments. Interestingly, the threat actor most likely framed the task as a benign development job - a custom video conferencing platform called "Lassy Meet" - traces of which can also be found on the suspicious GitHub organization that also appears to be LLM-automated. However, the comments reveal the intent. IOCs: 223.165.6[.]141 netwitz.zoom01[.]us teams.mlcrosoff[.]com github[.]com/altosecteam-org
1
5
21
3,393
Usman retweeted
I've outreached to 10 teams that recently went live on @arc recently All live, all holding funds, 0 audits between them I connect with them and I ask, what's the timeline on a security review and if @EgisSec can help (even tho they are already live...) Their responses: > "We conducted one internally, an external audit isn't necessary" > "We already engaged a firm" (I followup by asking which firm and I get ghosted) > Seen I got kicked out of 1 tg group because I asked publicly and they didn't want me to cause "fud" People, if you are using a product that doesn't have a security review, you have no business using that product
8
2
52
2,563
Urgent security advisory for iOS users! Install the latest iOS update immediately. Security researchers report that financially motivated attackers are now using a complete, in-the-wild exploit chain that can quietly steal cryptocurrency private keys and mnemonic seed phrases from iPhones. The reported attack begins when a target is socially engineered into opening a malicious page in Safari. That page is said to abuse a memory-corruption flaw in WebKit / JavaScriptCore to gain arbitrary read/write access from JavaScript, then bypass Pointer Authentication Codes (PAC) to run native code, break out of the WebContent sandbox, and escalate to kernel/root privileges. With that access, attackers can pull data from the device Keychain and from local crypto wallet apps. The claimed impact range is iOS 13 through iOS 26.5; that range has not been independently confirmed in full. Until more is known, treat any unpatched device as potentially exposed and update as soon as a newer build is available. Also avoid untrusted links in Safari, especially if you keep wallet keys or seed phrases on the phone.
69
226
1,015
665,850
lol nah, privacy is _not_ dead, we've just built the wrong defaults so far. any kind of privacy must be part of the _runtime_ (can be an execution layer, can be a browser, etc.), not something users have to configure. that's why i've been saying for years: we must ship _L1 enshrined unconditional_ privacy. if the default tx is private by default, you scale privacy and you win. i won't stop until i can replace my xmr txs with eth txs. build the right system defaults, and you win. ethereum enshrined privacy will win.
the main thing i think about is how dead privacy is from here on forward
37
38
267
14,127
Usman retweeted
Replying to @blinkbtc
@blinkbtc warms of a security issue and is currently at risk. Be safe👇
We've paused Blink services while we investigate a security incident. An attacker accessed a limited number of custodial accounts and withdrew funds. The large majority of funds are secure. Non-custodial wallets are not affected.
1
2
137
if you're building a self-custodial _software_ wallet, add _max_ friction to creating hot wallets & push users toward hardware wallets. idgaf if it hurts onboarding. your main job is keeping users' funds safe and in a world full of malware, making hot wallets the easy default is fucking _reckless_.
30
10
113
12,746
How to send ETH to any address without SELFDESTRUCT? 1. Deposit 32 ETH, create a validator with withdraw credential set to the target address 2. Exit the validator (not EIP 7002 request) 3. 32 ETH + rewards sent to target (silently, no fallback triggered)
5
8
132
11,223
Speed is a risk in multisig ops. Actions that affect user funds or protocol security should be made deliberately slow through timelocks and review windows. Forced urgency is one of the primary tools attackers use in social engineering and key compromise scenarios. More on multisig security and the controls that keep small mistakes small: frameworks.securityalliance.…
1
52
Usman retweeted
Arc Mainnet launched yesterday and is gaining a lot of hype around it. It is EVM-compatible but there are some significant differences with the EVM that you should be aware of if you plan to launch a project. Always check the chain docs 👇 docs.arc.io/arc/references/e…
3
10
376
Usman retweeted
The racism in crypto has gotten genuinely disgusting. The degen/memecoin side of the industry has normalized this shit to a level I've never really seen anywhere else. This also isn't just harmless internet banter. I've worked with hundreds of founders and spoken to a lot of ecosystem leads, and I've heard countless stories of founders deliberately hiding where they're from because they know they'll be stereotyped, treated differently, or have their startup dismissed before anyone even looks at what they're building. Crypto was supposed to be an open and accessible place. Unfortunately, it's gotten to a point where I can't think of many industries more toxic. We're doing a terrible job of living up to the ideals we claim to believe in. PS: This tweet is from last year, and honestly, I think it's gotten worse.
Esse é o time da @arc, devo me preocupar? 🤔 Estão me falando pra vender.
17
7
119
33,235
Usman retweeted
⚛️ Bitcoin does not have a quantum computer problem today. It has a migration problem, and migrations could take years to get right. SHRINCS is the first Bitcoin-specific post-quantum proposal I have seen that makes a serious end-to-end trade-off, and it deserves to be read carefully rather than cheered or dismissed. Their work is the proposal. I wrote an analysis of the challenges that come with it, the ones that only become visible when you look past the signature scheme and into the wallets that have to run it. The migration really has three questions: - which scheme Bitcoin should support - what that scheme does to the protocol and the wallet ecosystem - what happens to coins that have never been moved by their owner. Almost all of the public discussion is still on the first one, which is probably the easiest of the three. SHRINCS is conservative where it matters. It is hash-based, so it leans on the SHA-256 that Bitcoin already depends on instead of stacking a lattice assumption on top. A single 48-byte public key commits to both a compact stateful path (Flexible XMSS and WOTS+C) and a stateless SLH-DSA fallback. Verification is the pleasant surprise. It is mostly SHA-256, and the draft reports a worst-case cost per signature byte below BIP340 Schnorr. The stateful path uses one-time keys, and each one must sign exactly once. The counter must never move backwards, it must be committed to persistent storage before the signature leaves the device, and it must never be restored from a backup. Sign two different messages from the same slot and an observer can steal your fund. SHRINCS handles this better than a purely stateful scheme. If the state is lost or merely uncertain, the seed still derives the stateless key, so you lose efficiency rather than funds. The cost is that wallet state stops being application data and becomes cryptographic state whose rollback can take user funds: hundreds of counters for hundreds of UTXOs, across several devices and several software wallets, on hardware where hash-based keygen already takes minutes. There are also capabilities we do not get back. Non-hardened BIP32 derivation, and with it watch-only wallets as we build them today. Compact Schnorr-style threshold signing. None of this makes SHRINCS a bad proposal, and the spec is honest about its own status: non-standard SLH-DSA parameters, constructions outside the NIST standard, security proof pending. It does mean the cost of this migration cannot be only measured in signature bytes. The stateful aspect of SHRINCS would be very challenging in terms of security and UX. The uncomfortable part is that picking the signature scheme may be the easiest question here. ledger.com/blog-shrincs-bitc…
17
24
123
16,780
Usman retweeted
Day 15/30 Your org's dependency tree is mostly code your team has never read, maintained by strangers, and executed on installation. The supply chain threat vector is a risk for the whole org, and it needs serious attention
2
1
11
653
Usman retweeted
I have a hot take about Clarity that I'm surprised I'm not seeing on the timeline. In the last election, the industry was left with two very bad choices. The Dems were politicizing all things crypto at the behest of Warren/Gensler and unfairly targeting them for god knows what reason -- a political power play? Being paid by China to ensure the US is no longer at the frontier of tech and finance? Only God knows. In comes Trump, promising to be The Crypto President, promising the crypto community that if they vote for him, he will get rid of Gensler, create a bitcoin stockpile, protect self-custody, etc. But come on, how many people didn't know, based on his track record, that this would be a deal with the devil? And if they didn't know it then, then how many people still didn't know it after he launched a memecoin during the Crypto Ball and became the Max Extractor in Chief? (Also, let's not forget about solana:FUAfBo2jgks6gB4Z4LfZkqSZgzNucisEHqnNebaRxM1P.) The fact is that if the President and his family hadn't done so much crypto self-dealing during this administration, then Clarity would have had much better odds of passing. In fact, I would dare say it likely would have passed. The last time Kristin Smith was on my show, she said at this point, all the details about crypto had been worked out, and the main issues left to negotiate had to do with ethics. Basically, the remaining issues had to do with the president, and not crypto or Clarity itself. So, did the crypto industry shoot itself in the foot by throwing its lot in with Trump? I'm not saying that Kamala would have for sure been the better choice, but I do think it's worth asking this question.
185
57
678
99,936
SEAL weekly stats, 8-14 Sep: 61 incidents we dealt with. Reported losses by category: Seed compromise $9.39M Protocol compromise $3.94M DPRK intrusion $2.9M Escrow scam $1.68M Malware $960k Social engineering $192k Plus 132.5 ETH lost - distributed across all categories.
1
8
34
3,018
Usman retweeted
Day 14/30 Just 10 minutes can help you check one of the oldest attack paths for any org: spoofed emails. Email is a threat vector that can cause massive hacks, like the Revolut hack this week. theregister.com/cyber-crime/…
2
2
3
481
Usman retweeted
We’re always hiring for top tier talent at Blend! Anything from: > Head of Compliance > Head of Institutional Sales > CMO > Customer Success > Head of Capital Markets > Product Lead > Fintech Partnerships > Smart Contract Engineer If you want to help build Blend into a $1B company, drop a one liner below on why we should hire you!
76
7
298
19,144