I have created a donation page to support my work: donate.joinstr.xyz/ This would help me continue to work on joinstr and other projects.
8
11
76
44,275
floppy.md retweeted
I will never understand the appeal of conferences. We know, Bitcoin is good. We get it.
15
2
48
1,596
floppy.md retweeted
4
6
2,677
floppy.md retweeted
People remember much less of what you say and much more about how you make them feel.
1
2
60
1,323
floppy.md retweeted
Coldcard was NOT an LLM enabled attack, people created seeds with weak entropy and had their weak seeds brute forced. Brute forcing is older attack than bitcoin itself. Don't allow yourself to be gaslit by this narcissist.
32
71
683
20,305
floppy.md retweeted
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
616
658
3,679
1,950,349
floppy.md retweeted
While I deeply respect the cryptographic research that @nemothenoone and the @allocinitxyz team are pursuing to enable covenants on Bitcoin without a soft fork, it’s worth emphasizing that the cryptography underlying this approach is still highly experimental, and its security assumptions are far from established. It will likely take years of research and scrutiny before there is enough confidence in these constructions for use in Bitcoin applications — and realistically, that confidence may never materialize. I love the boldness of their vision and I’m impressed by the progress so far. At the same time, I think it’s important that the community has a clear understanding of where the research currently stands and how uncertain its practical viability remains from a cryptographic perspective.
Shielded Bitcoin: Private Transfers on Bitcoin L1
30
47
364
26,207
floppy.md retweeted
Replying to @MrHodl
It’s just this meme coming over and over again
1
3
10
537
You don't need a team of larps. You just need a subscription for using AI models and a brain.
5
456
floppy.md retweeted
An on-chain analysis and wallet labeling tool for individuals. 🏠 Self-hosted, powered by Bitcoin & Electrum 🔗 Transaction flow, 3D graph and scanning 🏷️ Wallet analysis, review, and annotation tools Soon...
1
3
7
458
floppy.md retweeted
Replying to @januszg_
people in this space love to lie in their marketing
1
1
4
367
All WordPress users need to update their WordPress installations immediately 💯 There is a 9.2 CVE that discloses a remote code execution vulnerability that affects versions all the way back to 2016 😬 Here's the official notice github.com/WordPress/wordpre…
33
211
868
144,005
floppy.md retweeted
Zero-day remote code execution vulnerability in iPhone Safari. Click a link, and your crypto, passwords and everything else on your iPhone are gone. Exploited in the wild by "DarkSword" malware. "The DarkSword attack program has leaked, with its core capability being: extracting forensic-level data from iOS devices via HTTP interfaces. In actual attacks, attackers can combine social engineering or watering hole attacks to lure users into falling victim, thereby stealing data from iPhone / iPad devices and uploading it to servers controlled by the attackers." Update iPhones immediately. Apple originally patched this, but rumours suggest even the latest versions are vulnerable, “pending confirmation,” across a wider range than the original 18.4–18.7 window. From a Chinese security researcher, SlowMist CISO, @im23pds nitter.net/im23pds/status/2101265…
Urgent security advisory for iOS users! Install the latest iOS update immediately. Security researchers report that financially motivated attackers are now using a complete, in-the-wild exploit chain that can quietly steal cryptocurrency private keys and mnemonic seed phrases from iPhones. The reported attack begins when a target is socially engineered into opening a malicious page in Safari. That page is said to abuse a memory-corruption flaw in WebKit / JavaScriptCore to gain arbitrary read/write access from JavaScript, then bypass Pointer Authentication Codes (PAC) to run native code, break out of the WebContent sandbox, and escalate to kernel/root privileges. With that access, attackers can pull data from the device Keychain and from local crypto wallet apps. The claimed impact range is iOS 13 through iOS 26.5; that range has not been independently confirmed in full. Until more is known, treat any unpatched device as potentially exposed and update as soon as a newer build is available. Also avoid untrusted links in Safari, especially if you keep wallet keys or seed phrases on the phone.
36
157
1,215
343,761
floppy.md retweeted
I am very pleased to announce the official author team for the 7th edition of Gray Hat Hacking through @MHEducation. The book will be published in mid-2027. Join me in welcoming: @chompie1337, @natashenka, @zodiacon, @ale_sp_brazil, @gf_256 to the team, along with 6th ed. authors @mosesrenegade & @htejeda! A big thanks to @allenharper for carrying the book since the First Edition, as well as all authors across all editions. Note: This is a mock up cover
13
33
178
26,300
Unauthenticated CPU exhaustion DoS in Wasabi: uncensoredtech.substack.com/…
1
6
697
floppy.md retweeted
We've paused Blink services while we investigate a security incident. An attacker accessed a limited number of custodial accounts and withdrew funds. The large majority of funds are secure. Non-custodial wallets are not affected.
54
200
549
152,765