Powered by ApeCoin - Security Awareness Public Good for Web3/NFTs and beyond We provide free classes, security awareness, and track scam/hack trends in Web3.

shop.boringsecurity.com
August is here, and so is our new class lineup. We have several ApeChain partner classes starting with @mutant_cartel on the 11th and 19th, and @archieapes_ on the 25th. Back by popular demand, we end the month with Sleuthing and DeFi Safety and Security. P.S. We remain on the lookout for more community partners. Send us a DM or file a Partner Ticket in our Discord. All classes are free.
5
10
35
6,510
Boring Security retweeted
Claim site is live. If I was able to save your NFTs, you can now reclaim them. You will have to revoke the PaymentProcessor approval first, if you haven't already. You may also opt to donate as part of your transaction. nftsaresafu.xyz/
256
392
1,900
175,721
Boring Security retweeted
At 9AM EST today somebody abused a bug in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives. It wasn't until over 12 hours later that somebody reported it to me, and upon digging in I realized that a great many NFTs were subject to the same exploit. I got in touch with the team over at LimitBreak and they quickly paused Payment Processor V3, which was subject to the same exploit. Unfortunately, V2 was not pausable, so the only path towards protecting affected assets was to run a whitehat operation. Similarly, V3 on ApeChain is temporarily in a state where it cannot be paused, so ApeChain assets approved to V3 needed to be saved as well. All in all, we rescued 23,155 NFTs worth north of $5.7M USD. We later discovered that a similar exploit could be used in reverse to steal WETH. 660 WETH was at risk, which we unfortunately were not fast enough to recover. Apologies to those affected. Shout out to @Boomskite for flagging the initial exploit tx to me, and @coffeedev @0xjustadev and @whiteoakkong for acting quickly and assisting with the recovery. All NFTs are safely relocated. Soon, owners will be able claim them back after revoking the exploitable approvals. Addresses to revoke below.
652
634
3,172
417,200
Boring Security retweeted
REVOKE APPROVALS TO THESE ASAP: Payment Processor V2 on Ethereum: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 Payment Processor V3 on ApeChain: 0x9a1D00000000fC540e2000560054812452eB5366 use revoke.cash or similar.
259
740
2,238
546,099
Boring Security retweeted
exploit discovered a few hrs ago, Quit is in the pocket rn white hat rescue of affected assets, everything safu, more info soon.
Replying to @CirrusNFT
hey ya this is a whitehat and everything in 0x71cF3f5724bD2B72Ef6464992aCd26216DE7fe33 is safe and will be returned once they are no longer at risk
57
67
434
36,908
We're hosting our second class with @mutant_cartel. Join us on August 19th at 8 pm to learn the basics of Web 3 security. Slots are still open, sign-up in the Discord.
6
3
21
2,100
We're two months out of @Giveth's TheDAO round, and we wanted to provide updates on our progress so far 1. Brand New Learning Experience You've seen our posts. You've seen the hype. Boring Security is headed to the Otherside. We've listened to past feedback from communities re hosting classes within Discord. With Otherside, we're providing a neutral online space where we can gather and learn about security. Expect some future classes in the metaverse. ICYMI, all our alumni can claim the BSec avatar, playable right now. 2. Class Refreshers We've been updating our classes to provide you all with up-to-date info in the space. Starting this August and beyond, you'll see new material in the classes and quizzes. 3. New Security Content We've drafted new material for our website and X. These will serve as long-form, more permanent content that people can reference. We've already made some progress, but still have a long way to go. Thank you to @thedaofund and @wintermute_t for helping us continue our mission.
4
4
23
1,264
Hands up if you're headed to ApeFest this year 🙋
4
11
885
Happy Friday, GM! What's one Web3 security lesson that you wish you did not learn the hard way?
7
12
914
Let's welcome the StonkBrokers from @ClutchMarkets as our latest community partner. We're working together to ensure their community is secured and locked down. 📍Join us on July 27, 8 pm EST with instructors Dreww and KFX. Thanks to @the_alpha_dgn for setting this up. Sign-up links are in our Discord (pinned in our bio).
11
21
70
3,796
Just spotted our special edition Ledger. There are still a few of these bad boys available, with a special discount for our Alumni. Grab it here: boringsecurity.myshopify.com…
It’s official. My first Ape related swag has arrived!All courtesy of @WelcomeApes with their welcome package 🎁 Shoutout @lawofthesaw & @0xdort for putting this initiative together 🦍🦾 If you bought your @BoredApeYC this year, make sure you tap with the WelcomeApes team. Sadly for me, my wife has instantly claimed the @ApeChainHUB bag 😂 but she did agree to let me borrow it for events 😅
3
14
1,110
I think the Zachxbt post about hardware wallets is being taken wildly out of context. Using a jailbroken airgapped smart phone can have its benefits as a daily driver wallet, but the audience in which he said that in probably also wasn’t meant to be picked up by numerous news outlets and consumed by the masses. Although the discourse caused by this may be valuable, this has opened our eyes to just how many people have sworn off hardware wallets due to missteps with the handling of customer data by wallet providers. Rather unfortunate. Fundamentally we disagree because we still deal with users day in and day out with compromised seed phrases, and bespoke solutions don’t scale well. Proper Hardware wallets are still the strongest form of self custody that we have today that is accessible and will documented, especially now with clear text initiatives and hardware wallets with large screens. Your security stack and behaviors aren’t about perfect or “doing what the pros do”, because we’ve dealt with developers and security professionals who have been hacked as well. Often. It should protect yourself from yourself, as well as reducing your overall attack surface. Also, there is value in subscribing to a shared security model across the space that is proven, accessible, and easy to use. The amount of flexing like “never been hacked, just don’t click weird links dummy” we’ve seen on the timeline as a result of this debacle is maddening, but overall I am eager to see this conversation unfold, because it’s an important one. We are team hardware wallet. Solidly on the team that “doesn’t want to have to trust a phone manufacturer with a million competing priorities to not accidentally leak my notes app logs in some SIRI AI training data when a rogue model erroneously sweeps a few thousand wallets for some Skynet, type shit.
5
4
24
1,691
Just kicking back in the @OthersideMeta after a long day of buidling. Soon. 😉
2
15
988
Check out our July Web3 security class calendar! We're kicking off the month with a Web3 101 class by @wiimee and @SimonartOnline later today. Expect a refreshed set of quizzes and insights from our instructors. P.S. We're on the lookout for communities to partner with for classes. All classes are free; just send us a DM or Discord ticket.
3
14
35
2,000
GM. First day of the new month! 🌞 Great to see so many new apes over the past few days. We invite all new apes to hop in our Discord and avail of our free crypto security education. We're here to ensure you keep those apes secured and locked down. Our July class calendar will be out in a few days. Join our Discord to sign up for classes (link in our bio).
6
3
22
1,101
Are you a BSec Alumni? Then come fly with us in the Otherside! Our new Avatar is now available for anyone who has claimed ANY Boring Security Badge! Big shout out to @RidazLp2 and @imjameshall for making it possible. Higher!
31
37
140
5,023
Leveling up your knowledge in the @OthersideMeta. 🔜
6
15
55
1,834
We're hosting our first community partner class today with @Tabcorp_HR @TaborRobak. Learn the essentials of Web 3 Security 101: 🗓️ June 16, 3pm EST 🔗 Boring Security Discord We still have a few slots left. Sign up on our Discord (link in bio).
1
2
16
622
Your Discord 2FA is probably weaker than you think. Let's rank your Discord 2FA options from terrible to unbreakable: ❌ 1. SMS 2FA (The Worst Option) If you are still receiving 6-digit codes via text message, you are vulnerable. SIM-swapping is incredibly common, and hackers can easily trick cell carriers into redirecting your texts to their phones. ⚠️ 2. Authenticator Apps (Better, but watch out for Cloud Sync) Apps like Google Authenticator or Authy are a massive step up. However, many of them now default to "Cloud Sync." If you use an app, disable cloud sync or keep it locked behind biometric security. 🛡️ 3. Passkeys & Physical Devices (The Gold Standard) Discord supports Passkeys, which are completely phishing-resistant. Because they tie a cryptographic key directly to your hardware, a fake login website cannot trick you into giving up your credentials. 🚨The absolute most important step: YOUR BACKUP CODES None of this matters if you lose your phone or security key. Go to your Discord Settings > My Account > View Backup Codes. Write them down on paper and hide them offline. If you get locked out of your account and don't have these codes, Discord Support cannot bypass 2FA to recover your account. Take 2 minutes to do this today. Interested in learning how to secure your Discord server? Stop by our Discord > Open a Ticket > BSEC Services > Discord Audit (link in our bio).
3
13
828
Would you attend a Boring Security class here? 👀
43
16
151
9,630