Building the future of transaction signing and the last line of defense in blockchain.

England, United Kingdom
1/2 ⚠️ One action displayed. 257 authorized ⚠️ Our full write up is live: Signature overflow attacks on Ledger. A Clear Signing bug broke a critical security property: What you see is what you sign. 🔎 Technical details + PoC: bitfinding.com/blog/signatur…
1
7
19
1,964
2/2 Ledger addressed the issue in Ethereum app v1.22.3+. Users should update before relying on Clear Signing for affected flows. 🧪 Reproducing the PoC? Use a separate test device with a fresh, disposable seed and no funds.
5
127
1/2 We helped Ledger identify and fix a High-severity Clear Signing vulnerability. Ethereum app 1.19.0–1.22.2 is affected. Update to 1.22.3+. Our advisory: bitfinding.github.io/publica…
4
9
30
8,286
2/2 A compromised frontend could make the trusted screen omit actions still covered by the signature. We demonstrated the Safe attack end to end and confirmed the same display/signature divergence in Aave and Morpho multicall flows. PoC coming soon. In the meantime, update.
2
382
A compromised frontend could make the trusted screen omit actions that remained covered by the device signature. We demonstrated the Safe attack end to end and confirmed the same display/signature divergence in Aave and Morpho Clear Signing flows. Stay safe - update
20
If you use Ledger for Ethereum, please update the Ethereum-app to v1.22.3. This is a new release. Go update your Ledger. Again.
6
9
772
This exploit is similar to our not-WYSIWYS attack reported in March. We followed responsible disclosure and are waiting for the fix to be widely adopted before dropping the POC
🚨Every Ledger running the Ethereum app is vulnerable to signature substitution A malicious dApp with WebHID access could race an APDU during your transaction review and swap the tx being signed while the device still shows the original Here's what you need to know:
1
5
11
850
We acknowledged and applaud that @Ledger is upping their offensive security with the latest LLMs to find these vulnerabilities before the bad guys do
1
3
60
However, in a world where everyone gets access to the latest models at the same time and agents are watching everyone and everything, unreleased fixes or vulns can’t sit in the open until Patch Tuesday.
3
34
Research update: we’ve been heads down on several projects we’ll be sharing soon. One is our investigation into reorgs, orphans, and cross-chain execution triggered before confirmation. Several bridges are in scope, and we’re sharing findings with their teams privately.
1
5
15
598
We also reported security issues affecting a widely used hardware wallet. We’re coordinating with the relevant team and will publish the technical details when it’s appropriate to disclose them responsibly.
1
1
3
129
Any funds recovered during our reorg experiments have already been returned to their owners. More research and technical write-ups are coming. Big thanks to @thedaofund, @quantstamp, @wintermute_t, and @Giveth for supporting our work.
4
66
Huge thanks to @giveth and everyone involved to make this happen. Thanks to this initiative we can spend more time in public good projects that benefit the whole ecosystem.
TheDAO's Ethereum Security QF Round matching funds have officially been distributed 🛡️ What started as a 500 ETH matching pool from @thedaofund ultimately grew to 638 ETH+ thanks to support from across the ecosystem. 134 projects have now received funding to continue their work strengthening Ethereum security. A huge thank you to every donor, contributor, and project that made this round possible.
3
10
495
BitFinding retweeted
The latest Giveth newsletter is out 💜 Inside: 🛡️ @thedaofund Ethereum Security QF Round results and 638 ETH+ distributed 📊 A new dashboard to explore the round data 🤝 GIVfriend of the month: @wintermute_t 🙌 Featured project: @BitFinding 🏆 Newly verified projects: @walnut_dev, @dedaub and much more
3
8
38
11,043
It's great having @DecurityHQ securing the blockchain at the milliseconds game. Competition in this space is what will make the last line of defense stronger!
Replying to @DecurityHQ
4/ Balancer V2 reached 54% of funds-at-risk in minute one, 93% by minute five. Even at that speed, @BitFinding's whitehat bot intercepted the attacker in the very next block - 12 seconds after the first malicious tx. ~$1M returned to Balancer DAO.
3
6
535
BitFinding retweeted
An AI agent that monitors every block, hunting smart contract hacks would be great right? Well @BitFinding is building it, and it has rescued $1.3M and counting. Learn more: piped.video/watch?v=WUWT9W6N… Support: qf.giveth.io/project/bitfind…
3
9
548
Our whitehat bot fuzzes the blockchain on real time, detecting and intercepting exploits. As an example, only during the Balancer attack, we secured >$1M in a single block. We’re raising on @Giveth QF to scale our public-good infrastructure.
2
1
5
279
This is the kind of security crypto needs more of: technical, proven, and built for the whole ecosystem. Today it is only rewarded through bounties. @Giveth lets the ecosystem fund it proactively. With QF, even $10 can carry far more weight. qf.giveth.io/project/bitfind…
1
3
278
🚨 Exploit Alert: Bad error handling attack Chain: Ethereum Loss: 17 WBTC ($1.3M) TX: 0x770bc9a1f7c32cb63a5002b9ceb5c7994cd3af0fc6b2309cb32d3c46f629daa0 etherscan.io/tx/0x770bc9a1f7…
1
3
8
563