Founder & Viceroy of The Holy Trinity BTC • ETH • USD | "Do Not Cast Your Pearls Before Swine"

Clown City™ The Graveyard of Rekt™ Yeah, just roll back the chain bros. Projects should just host an Excel Sheet on AWS. It's faster and more secure. For transactions, everybody just DMs the team, who then updates the Excel Sheet as required. It's exact the same thing.
1
2
438
Zano deleted the original post. They now refer to it as muh network upgrade:
Security update and coordinated upgrade: The core team has identified a vulnerability in public Gateway Addresses that affects asset issuance, including fUSD. Transaction privacy is unaffected, and no spend keys or wallets are compromised. We will coordinate a network upgrade asap. It requires majority consensus to activate, so we ask node operators, pools, and exchanges to be ready to update. No action is needed from ordinary users beyond upgrading when the release is published. A full technical write-up will follow after the upgrade is in place.
23
> "hold X shitcoin, earn Y stock" So what is the point of the shitcoin intermediary? Why wouldn't you just purchase the actual stock if you wanted it? I'm not talking about the IOU stock either. > "it's a meme, but paired with a stock" If you pair your shitcoin with an IOU stock, your shitcoin will be sold down for the IOU stock.
1
145
>Muh black swan Your username alludes to sucking dick. Crypto Dick Sucker
1
3
780
Black Hats know you can't survive a Second Strike. You'll be put out of business with the next attack. Bitget is at even HIGHER risk now, not less. They'll be determined to refill their Rekt Fund™ ASAP, and the best method is to liquidate their own users. Also, lol
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
5
1,307
Skill Issue. Pareto is amoral, and crypto is maximum PVP. The Crypto Industry in a Nutshell: 1. Get Rekt™ 2. Cope 3. Release Postmortem™ (bonus points for muh phoenix recovery or some profound lesson learned) 4. Get Rekt™ again
Bitget Wallets Suspected of Security Breach, Over $170M in Assets Moved and Swapped to ETH Breaking: MLM monitoring indicates that Bitget may be experiencing an ongoing wallet security incident, with three hot wallets and one cold wallet suspected to have been compromised. More than $170 million worth of assets have reportedly been moved out and swapped into ETH, with activity linked to 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee. The affected wallets are said to still hold about $530 million in assets. The attack vector and total losses remain unconfirmed, and Bitget has not yet publicly responded.
1
3
1,509
You're quite arrogant for using F-Tier exchanges like @bitget thinking you won't get smoked. You're objectively a weaker investor. Even "Tier 1" CEXs aren't safe, but unironically, I can argue Threshold Retardation warrants Tier 1 Custody--that's another post, another day.
1
2
82
$350M
At 18:31 UTC on September 24, 2026, Bitget’s security systems identified unauthorized transfers involving a limited number of hot wallets. Our security team immediately activated emergency response procedures and began a full investigation. Based on our current assessment, approximately $351.6 million in assets were affected. Bitget’s cold wallets and the overwhelming majority of platform assets remain secure and unaffected. Most importantly, user funds remain protected. The incident falls within the coverage of Bitget’s User Protection Fund, which currently holds more than $464 million. Customer account balances remain accurate, and deposits and trading continue to operate normally. As a precaution, withdrawals have been temporarily suspended while our teams complete a comprehensive security review. We have identified and flagged the relevant transfer addresses and have formally engaged law enforcement agencies and leading on-chain security partners. We are working around the clock to restore withdrawal services as soon as it is safe to do so. Bitget will provide further updates through our official channels. We will not speculate on the attack vector while the investigation remains ongoing. Our focus is on protecting users, securing all systems, and delivering complete transparency throughout this process.
70
you are under attack retard
Introducing Finality: Chargebacks for Stablecoins Trillions of dollars are transacted today without a way to dispute a single payment. Finality is the first to give enterprises dispute resolution to their customers without reversing blockchain transactions. We're inviting payment providers, LPs, and arbitrators to help shape the network ahead of broader access.
1
3
405
The Graveyard of Rekt™ It's ironic considering your thesis was onchain clawbacks with a middleman--you can't even clawback your own funds in this exploit. I will give the benefit of the doubt that it was not an inside job.
Today at 4:21 UTC Payy’s bridge contract on Ethereum was exploited and drained of its full balance. Investigation is ongoing and we are following incident response guidelines. While we investigate, all Payy Network transactions are paused including deposits, withdrawals, transfers and card transactions. We will continue to communicate updates here.
75
You mean like, legacy banking? Since you WANT a centralized blockchain, it's faster and more secure to host a database on AWS. Blockchain sucks. It's not the right technology. You only need a blockchain if somebody is trying to censor your transaction. Stablecoins are Trust Me Bro x Trust Me Bro Then you add middlemen like Visa/Mastercard, neobanks, custodians, regulators, a freeze function, enhanced KYC, and what's the point? You already have cryptoC U R R E N C Y live today. Bitcoin & Ether can be used without permission or freeze risk. But people don't care about that. People are in cryptocurrency to get rich. "Selling" crypto for goods and services is BEARISH. You do not sell $GOOG to pay your invoices. If you want "consumer protection", use a normie credit card.
there's a billion dollar opportunity in crypto that no one is building: a blockchain where stablecoin payments can be disputed, chargebacked, or reversed. everyone talks about stablecoins replacing Visa because they’re instant, cheaper, and global. but a huge part of Visa’s value is the system that protects buyers and merchants when something goes wrong: > chargebacks > refunds + returns > fraud protection > dispute resolution > buyer protection > merchant protection stablecoin payments don’t have any of that. once you send the money, the transaction is final and irreversible. if the merchant never ships, sends the wrong product, or scams you, there’s no dispute process to get your money back. that’s one of the biggest things holding stablecoins back from being adopted in everyday commerce. someone needs to build a payment network specifically around this problem: > consumers pay merchants in stablecoins > buyers can file disputes if something goes wrong > merchants can respond to those claims > a governing layer decides when funds should be returned you still get instant, cheap, global payments, but now with the consumer protections people already expect from card networks like Visa.
1
300
This will be confusing for Burgers due to your misleading picture. Marktplaats is the leading Netherlands' classified Ads website; ahead of both Craigslist and Facebook Marketplace. These are not Rolex Authorized Dealers, but regular folk sell items peer-to-peer. There is no store. Scammer message sellers, and they agree to meet-up and settle payment in cryptocurrency. They social engineer and likely distract the seller, before sending fake EURC tokens hoping the buyer does not verify. Scammer quickly makes up an excuse to leave and exit with the Rolex. Not a clever scam at all, just don't be retarded.
🇳🇱 Des escrocs ont réussi à acheter de VRAIES ROLEX… avec de la FAUSSES crypto. Aux Pays-Bas, deux hommes de 24 et 45 ans sont soupçonnés d’avoir ciblé des vendeurs de Rolex sur Marktplaats. Le paiement devait être effectué en EURC, le stablecoin euro émis par Circle. Mais selon la police, les vendeurs recevaient en réalité des tokens contrefaits conçus pour ressembler au véritable EURC. À première vue, le paiement semblait donc avoir été effectué… alors que les tokens n’avaient pas la valeur attendue. L’affaire remonte à plusieurs signalements reçus en août 2025. Les deux suspects ont finalement été arrêtés le 9 septembre 2026. Lors de la perquisition au domicile du suspect de 24 ans, la police affirme également avoir découvert des armes à feu et de la drogue. C’est une arnaque particulièrement intéressante parce qu’elle exploite une confusion fréquente en crypto. Voir « EURC » dans un wallet ne suffit pas à prouver que l’on possède le véritable stablecoin, et non une copie ressemblante crée sur une autre blockchain.
4
368
*records screen* ???
Today, we’re releasing Kalypta, the first app to block AI notetakers in your meetings. Granola? Wisprflow? Cluely? No more. With Kalypta, you become inaudible to AI. Your call continues normally.
158
Since that @zachxbt post: Apple patched 87 security holes with unique CVEs in iOS. And every update unveils new destruction. Most people don't own an iPhone 17 (MIE support), so it's even worse advice. A hardware wallet is far more secure, full stop. Any grievances are strictly a matter of skill, truly. "Crypto" is never far from The Graveyard of Rekt™
Since this @zachxbt post: • Coldcard - a Bitcoin hardware wallet, was hacked for $40 million. • Trezor - one of the largest cold wallets, experienced a major data leak. • SafePal - one of the largest cold wallets, experienced a major data leak. Incredible timing.
7
2
51
16,521
[Update]
Come post your brilliant ideas in the comments, you arrogant plonkers. Apple patched another ~30 security holes in iOS 26.6.1 with a particularly nasty one: "Processing an image may lead to arbitrary code execution" (CVE-2026-65346) You're going to get GODSTOMPED by the many men who are NOT good. Tons of iOS exploits were abused for YEARS before the "good guys" ever caught wind. Some of the flaws they were exploiting had been sitting there for DECADES. Your "security" is contingent upon the GOODWILL of other men. That is a horrible game plan. And when you lose all your money for being cute with your OPSEC, don't cry too loud. Skill Issue. The vulnerable code behind iOS CVE-2026-20700 predates the 2007 iPhone itself, having been inherited from macOS, with roots reaching back to NeXTSTEP. It was not patched until 2026. Yes, really. It was actively exploited "in the wild" by multiple threat actors, and chained together with other security holes. @tayvano_ "DARKSWORD" And before DARKSWORD, iOS was getting cucked by "CORUNA", an iOS exploit that achieves FULL DEVICE COMPROMISE. I'll repost some others (non-exhaustive) since you people glossed over them: KISMET - NSO Group FORCEDENTRY - NSO Group FINDMYPWN - NSO Group PWNYOURHOME - NSO Group ENDOFDAYS - QuaDream BLASTPASS - NSO Group OPERATION TRIANGULATION - Unknown GRAPHITE - Paragon Solutions What else is there to say? ∙ North Korea IS capable of zero-days, and chaining zero-days, but they don't need any of that to annihilate the crypto industry. They're operating at a fraction of their true power, like DragonBall Z. They send you guys poisoned PDFs, phishing links, Zoom links, and your dead bodies float down the river. It's a Graveyard of Rekt™ What battle? What defence? It's a slaughter and butcher. When "normies" clown crypto, it's accurate. It's a joke industry. There's Bitcoin, there's Ether, and there's the USD. That's it. Everything else must invent a reason to exist, in an attempt to acquire: more Bitcoin, Ether, and USD. People have been trying to "make moves" for 17 years, only to get bodied by tokenized fiat currency. KEK North Korea is a third world threat actor, not even close to being the top elite. But they don't need to elite to manhandle the crypto industry. And despite the Rekt City™ that takes place daily, the crypto industry displays the greatest hubris by far. Projects communicate through postmortems as if some profound lesson was absorbed, only to get killshotted the very next day, by some other exploit they never saw coming. You have mountains of evidence, security researchers stating the contrary, but y'all triple down that an iPhone is more secure than a Hardware Wallet. Millions of lines of code on a multimedia entertainment device vs A compact codebase on dedicated hardware that has one job Not even Apple engineers would agree with you. DONKEY. ∙ @vidya_no68665 thinks he's clever with: >"You're suppose to set the Iphone aside and only interact with it when needed not fucking daily drive it, I thought this was fucking obvious." You are grossly overestimating the security of stock iOS with absolutely nothing on it. The attack surface is MASSIVE. On iOS, your PRIVATE KEY is exposed in RAM, you retard. The Secure Enclave cannot do secp256k1 so your wallet has no choice but to decrypt and sign in memory. You are naked, AND in the AFU State which is the most vulnerable state for an iPhone. Compare that to a proper hardware wallet where the private key remains inside the Secure Element. (Do not mention Coldcard, I have a specialty dunk thread for those noob investors already, who are full of arrogance). @__noided Further, run Wireshark on a separate device and see how busy your "clean iphone" is with hundreds of connections happening in the background. It's not "quiet". Your iPhone is never idle, and it's constantly parsing untrusted data: iMessage, WebKit, ImageIO, fonts... which IS the attack surface. @n13 -- Airplane Mode is a software toggle, not a hardware kill switch. Wi-Fi/Bluetooth/Cellular/NFC/UWB run their own firmware and remain connected to the main processor. Some use DMA to access restricted regions of host memory. Now, Apple does constrain this access but they don't eliminate it. Find My literally still works against a powered off iPhone using reserve power. It broadcasts a Bluetooth Low Energy beacon that other Apple devices can pick up and relay through the Find My network. Your iPhone is still transmitting even when "off". If people want to get cute with muh "QR Codes", come on now. The iPhone can still parse attacker-controlled input, AND memory corruption bugs in image-processing code have led to RCE already. CVE-2026-65346 is a recent example, patched this week. You can presume there are others that the "good guys" haven't found yet. Why would they be notified? ∙ History Lesson: Exploit after exploit, Apple was brought to their knees. In desperation, you know what Apple did in response? They sued the NSO Group. lol lmao even "PLS STOP HACKING US, PLSSSS" And then? Apple walked away from their own lawsuit because discovery would have forced them to disclose sensitive intel that other bad actors would have weaponized against them. NSO Group aside, there's an entire black market and grey market for iOS zero days. And these upstanding scholars are not buying exploits to report them to Apple. They are going to use them to destroy you, for as long as possible until they're patched, if ever. If they're lucky, they can use it for YEARS. "In the wild" simply means "the good guys finally noticed bro". Great plan, everyone. Good work. Guess who discovers tons of iOS zero-days? Google Citizen Lab Amnesty Kaspersky Numerous independent researchers Anonymous reports Often, it's not even Apple themselves. Your goodwill is stacked on top of goodwill from people who have zero obligation to Apple. Y'all have no clue if it was exploited or not because not everyone is reporting they got Rekt™. And, you have no idea if you were exploited when it concerns zero-days. It can execute and persist, without you noticing. @SatoshiSideho -- Apple has been getting Rekt™ for years @bch_gangster -- Zach does great work and I'm not knocking that. But he's a self-taught on-chain investigator, not a cryptographer, and he's never claimed otherwise. He has social reach, and you're citing him on something outside his expertise. People can be wrong, you know? ∙ The amusing thing is I dunk on hardware wallets all the time, targeting their actual weaknesses unrelated to noob skill issues. Go read them. I've been citing iPhones & Pixels well before Zach's post, and well before any KOL reacted to "timeline news". Y'all have this notion that I don't have a plethora of tools at my disposal and have reached a sound conclusion based on hard evidence, and BATTLE EXPERIENCE. I don't need a job, your job, or any referral links. I can speak with the most freedom, uninhibited by bias. Meanwhile, dudes clinging onto their sole iPhone are looking for confirmation bias.
1
39
You think you're clever huh
Flawless Victory. I demand stronger opponents: nitter.net/HalesFall/status/20904… [@im23pds is the @SlowMist_Team CISO] -- not that that matters because there was never a debate to begin with. Some of you only read if it's spoonfed to you from within "Web 3".
15
Come post your brilliant ideas in the comments, you arrogant plonkers. Apple patched another ~30 security holes in iOS 26.6.1 with a particularly nasty one: "Processing an image may lead to arbitrary code execution" (CVE-2026-65346) You're going to get GODSTOMPED by the many men who are NOT good. Tons of iOS exploits were abused for YEARS before the "good guys" ever caught wind. Some of the flaws they were exploiting had been sitting there for DECADES. Your "security" is contingent upon the GOODWILL of other men. That is a horrible game plan. And when you lose all your money for being cute with your OPSEC, don't cry too loud. Skill Issue. The vulnerable code behind iOS CVE-2026-20700 predates the 2007 iPhone itself, having been inherited from macOS, with roots reaching back to NeXTSTEP. It was not patched until 2026. Yes, really. It was actively exploited "in the wild" by multiple threat actors, and chained together with other security holes. @tayvano_ "DARKSWORD" And before DARKSWORD, iOS was getting cucked by "CORUNA", an iOS exploit that achieves FULL DEVICE COMPROMISE. I'll repost some others (non-exhaustive) since you people glossed over them: KISMET - NSO Group FORCEDENTRY - NSO Group FINDMYPWN - NSO Group PWNYOURHOME - NSO Group ENDOFDAYS - QuaDream BLASTPASS - NSO Group OPERATION TRIANGULATION - Unknown GRAPHITE - Paragon Solutions What else is there to say? ∙ North Korea IS capable of zero-days, and chaining zero-days, but they don't need any of that to annihilate the crypto industry. They're operating at a fraction of their true power, like DragonBall Z. They send you guys poisoned PDFs, phishing links, Zoom links, and your dead bodies float down the river. It's a Graveyard of Rekt™ What battle? What defence? It's a slaughter and butcher. When "normies" clown crypto, it's accurate. It's a joke industry. There's Bitcoin, there's Ether, and there's the USD. That's it. Everything else must invent a reason to exist, in an attempt to acquire: more Bitcoin, Ether, and USD. People have been trying to "make moves" for 17 years, only to get bodied by tokenized fiat currency. KEK North Korea is a third world threat actor, not even close to being the top elite. But they don't need to elite to manhandle the crypto industry. And despite the Rekt City™ that takes place daily, the crypto industry displays the greatest hubris by far. Projects communicate through postmortems as if some profound lesson was absorbed, only to get killshotted the very next day, by some other exploit they never saw coming. You have mountains of evidence, security researchers stating the contrary, but y'all triple down that an iPhone is more secure than a Hardware Wallet. Millions of lines of code on a multimedia entertainment device vs A compact codebase on dedicated hardware that has one job Not even Apple engineers would agree with you. DONKEY. ∙ @vidya_no68665 thinks he's clever with: >"You're suppose to set the Iphone aside and only interact with it when needed not fucking daily drive it, I thought this was fucking obvious." You are grossly overestimating the security of stock iOS with absolutely nothing on it. The attack surface is MASSIVE. On iOS, your PRIVATE KEY is exposed in RAM, you retard. The Secure Enclave cannot do secp256k1 so your wallet has no choice but to decrypt and sign in memory. You are naked, AND in the AFU State which is the most vulnerable state for an iPhone. Compare that to a proper hardware wallet where the private key remains inside the Secure Element. (Do not mention Coldcard, I have a specialty dunk thread for those noob investors already, who are full of arrogance). @__noided Further, run Wireshark on a separate device and see how busy your "clean iphone" is with hundreds of connections happening in the background. It's not "quiet". Your iPhone is never idle, and it's constantly parsing untrusted data: iMessage, WebKit, ImageIO, fonts... which IS the attack surface. @n13 -- Airplane Mode is a software toggle, not a hardware kill switch. Wi-Fi/Bluetooth/Cellular/NFC/UWB run their own firmware and remain connected to the main processor. Some use DMA to access restricted regions of host memory. Now, Apple does constrain this access but they don't eliminate it. Find My literally still works against a powered off iPhone using reserve power. It broadcasts a Bluetooth Low Energy beacon that other Apple devices can pick up and relay through the Find My network. Your iPhone is still transmitting even when "off". If people want to get cute with muh "QR Codes", come on now. The iPhone can still parse attacker-controlled input, AND memory corruption bugs in image-processing code have led to RCE already. CVE-2026-65346 is a recent example, patched this week. You can presume there are others that the "good guys" haven't found yet. Why would they be notified? ∙ History Lesson: Exploit after exploit, Apple was brought to their knees. In desperation, you know what Apple did in response? They sued the NSO Group. lol lmao even "PLS STOP HACKING US, PLSSSS" And then? Apple walked away from their own lawsuit because discovery would have forced them to disclose sensitive intel that other bad actors would have weaponized against them. NSO Group aside, there's an entire black market and grey market for iOS zero days. And these upstanding scholars are not buying exploits to report them to Apple. They are going to use them to destroy you, for as long as possible until they're patched, if ever. If they're lucky, they can use it for YEARS. "In the wild" simply means "the good guys finally noticed bro". Great plan, everyone. Good work. Guess who discovers tons of iOS zero-days? Google Citizen Lab Amnesty Kaspersky Numerous independent researchers Anonymous reports Often, it's not even Apple themselves. Your goodwill is stacked on top of goodwill from people who have zero obligation to Apple. Y'all have no clue if it was exploited or not because not everyone is reporting they got Rekt™. And, you have no idea if you were exploited when it concerns zero-days. It can execute and persist, without you noticing. @SatoshiSideho -- Apple has been getting Rekt™ for years @bch_gangster -- Zach does great work and I'm not knocking that. But he's a self-taught on-chain investigator, not a cryptographer, and he's never claimed otherwise. He has social reach, and you're citing him on something outside his expertise. People can be wrong, you know? ∙ The amusing thing is I dunk on hardware wallets all the time, targeting their actual weaknesses unrelated to noob skill issues. Go read them. I've been citing iPhones & Pixels well before Zach's post, and well before any KOL reacted to "timeline news". Y'all have this notion that I don't have a plethora of tools at my disposal and have reached a sound conclusion based on hard evidence, and BATTLE EXPERIENCE. I don't need a job, your job, or any referral links. I can speak with the most freedom, uninhibited by bias. Meanwhile, dudes clinging onto their sole iPhone are looking for confirmation bias.
Since that @zachxbt post: Apple patched 87 security holes with unique CVEs in iOS. And every update unveils new destruction. Most people don't own an iPhone 17 (MIE support), so it's even worse advice. A hardware wallet is far more secure, full stop. Any grievances are strictly a matter of skill, truly. "Crypto" is never far from The Graveyard of Rekt™
6
11
5,304
You're STILL going to get destroyed: @stacy_muur @MedusaOnchain @oxtochi @Obesepotato_hl @Jampzey ...and anybody else who's trying to get "cute" with their OPSEC. nitter.net/HalesFall/status/20782…
❌ WRONG. DONKEY ADVICE. ZachXBT is a brilliant investigator, brilliant OSINT researcher. But he's NOT a security engineer. Crypto is the WORST INDUSTRY to consult on security anything. Getting Rekt™ is the Standard Operating Procedure. Not a day goes by where crypto isn't exploited. And everybody reads the post mortem as if some lesson was learned, only to get exploited again by another exploit they never saw coming. What does that tell you? ARROGANCE. The smartest people working on security are in Web2, not Web3. That is where I defer. Google Project Zero, for example, saved your ass more times than you can count. You just never hear about it. They disclose numerous iOS zero-days that you know nothing of. Do not compare Google Project Zero to your neighbourhood Web3 firm. It's a Porsche to a Unicycle. I have read all your comments. Crypto has an arrogance problem. What business does a KOL have speaking on this subject? 1. Memory Integrity Enforcement (MIE) Nobody mentioned that the iPhone 17 is unique among ALL iPhones. Why? The iPhone 17 has Memory Integrity Enforcement (MIE). Always on. Synchronous mode. HARDWARE level, not software. ALL OTHER IPHONES ARE INFERIOR. You and your donkey ass "muh old iphone", muh lockdown mode, muh just use it to sign, muh muh muh. ENOUGH. Software cannot patch in what the silicon doesn't have. And before you reply muh iPhone 17 is safe, NO! MIE raises the COST of exploitation. It does not remove the attack surface. Apple says this themselves. "Operation Triangulation" already bypassed a hardware mitigation in the wild, through undocumented chip registers nobody outside Apple knew existed. The iPhone 17 is the Minimum Viable Donkey. It is NOT a hardware wallet. 2. PHYSICAL ATTACKS Nobody mentioned Before First Unlock (BFU) vs After First Unlock (AFU). iPhones (and Pixels) have state-of-the-art Secure Elements, stronger than off-the-shelf chips found in hardware wallets. This is true, but it's not the reality. It's only true if the iPhone is in BFU state with data at rest. ...But to sign a transaction you have to UNLOCK the phone. Congrats, you're now in the vulnerable AFU state. Widely available forensic tools (your local police station has them) extract data from iPhones and Pixels TODAY, yes even the latest models in their AFU state. When was the last time you turned off your phone? Exactly. 99.99% of people are running the AFU state. Contrast that to a hardware wallet whose keys never leave the signing boundary. Unlocked or not. The safest state for a phone is OFF, which is useless to you as you need to sign. 3. REMOTE ATTACKS This is where you will get utterly destroyed and cry on Twitter after losing all your money. You have NO defence against zero-click exploits (with many more to come): KISMET - NSO Group FORCEDENTRY - NSO Group FINDMYPWN - NSO Group PWNYOURHOME - NSO Group ENDOFDAYS - QuaDream BLASTPASS - NSO Group OPERATION TRIANGULATION - Unknown GRAPHITE - Paragon Solutions Muh dedicated device, muh one app. DONKEY. The attack surface is the whole ass phone. Next, the following run independent firmware alongside iOS, each with their own attack surface. You can't "harden" these: Baseband/Modem WiFi Chipset Bluetooth SIM Card eSIM NFC UWB inb4 muh sandboxed. Exploits chain over boundaries. A hardware wallet gives you a TRUSTED DISPLAY. You verify the transaction on a separate device from the compromised host. Muh Phone = Host and signer are the SAME device. If it's cucked, the attacker controls what you SEE and what you SIGN. You're going to lose all your money. The list of zero-click exploits documented against iPhones keeps growing, many of which are hoarded. Every iOS update patches numerous security holes you knew nothing of. There have been ZERO documented cases of funds being remotely extracted from a hardware wallet's secure element. ZERO >inb4 muh Ledger bluetooth. The security model already assumes it's hostile. >inb4 muh Ledger Connect Kit, muh Ledger NPM. Both attacks hit the HOST. Software wallets have no defence, and your iPhone wallet IS a software wallet. Ledger users needed to BLIND SIGN. The device told them it couldn't verify the transaction and they signed anyway. >inb4 muh Secure Enclave. An exploited iPhone will lie to you, or just yoink your funds with no action required from you. The Secure Enclave only supports NIST P-256. Bitcoin and Ethereum use secp256k1. Your wallet's signing keys CANNOT live inside it. They live in app memory where the exploit is. You're not ready for that conversation though.
1
170
Arrogant Plonkers, indeed.
Flawless Victory. I demand stronger opponents: nitter.net/HalesFall/status/20904… [@im23pds is the @SlowMist_Team CISO] -- not that that matters because there was never a debate to begin with. Some of you only read if it's spoonfed to you from within "Web 3".
37
Flawless Victory. I demand stronger opponents: nitter.net/HalesFall/status/20904… [@im23pds is the @SlowMist_Team CISO] -- not that that matters because there was never a debate to begin with. Some of you only read if it's spoonfed to you from within "Web 3".
🔍没想到 一语言中,iOS 用户抓紧升级 黑灰产已实现: 1.点击链接提取私钥、助记词 2.用户使用Safari 访问网页,WebKit/JSC 内存损坏拿到 JS 层 read/write 3.绕过 PAC 拿到 native call 能力 4.逃出 WebContent 沙箱 5.内核提权拿root权限,拖走 Keychain + 钱包数据 🔍 受影响的版本 iOS 13至 26.5 (待定)
1
5
405
ARC will coast to irrelevance. Structurally, it's even weaker than Robinhood L2. Many are unaware that "Stablecoin as Native Gas" was already done, with far stronger price narrative, pedigree, and the proving ground on multiple fronts: POA NETWORK TOKENBRIDGE BLOCKSCOUT NIFTY WALLET MAKERDAO XDAI STAKE $STAKE "BURNER" WALLET POA ---> POSDAO DARK FOREST (ZKSNARK) 1HIVE ARAGON REDDIT MOONS GNOSIS CHAIN [CURRENT] How do I know? Whale, whale, whale. Further, a few things you should never trust: - Muh institutional money™ - Muh chinese money™ - Muh dubai oil money™ For what matters (to you), is price up. And there's 101 better things to be positioned in.
Arc Mainnet is live. Arc launches as the Economic OS for the internet: an open platform for global markets, real-time value movement, tokenized assets, and agentic economic activity. Arc is more than a blockchain. It launches as a full-stack financial platform with assets, applications, interoperability, developer infrastructure, and Circle platform services live from day one. Arc delivers USDC as native gas, deterministic sub-second finality, EVM compatibility, and institutional validators. It integrates with Arc Studio, App Kits, Arc Portal, Circle Agent Stack, CCTP, Gateway, CPN, and StableFX. A complete economic platform at genesis. Arc launches with infrastructure for: → Agentic economic workflows → Lending and borrowing → Trading and liquidity → Onchain FX → Payments and settlement → Tokenized assets → Exchanges, wallets, custody, compliance, data, and developer tooling 190+ institutional and ecosystem builders are building across Arc.
2
5
464
Launch day is your opportunity to market the very best ARC has to offer. Instead, the ARC team would rather pump & dump meme slop.
the duke of @arc has entered the chat I hear it's @jerallaire dog
1
1
119
Out-of-touch boomers disconnected from reality. They're the ones to triple down on "hype events" a la @SphereVegas , @cryptocomarena naming rights, endless "conferences", all while their price chart nukes to oblivion.
Tonight, 850 drones will illuminate the San Francisco skyline to tell the story of Arc and what comes next: up to $1M for eligible teams building on Arc. Live on X at 9:30 PM PT.
1
42
The next time @Blockstream @Liquid_BTC get hacked, nothing will be returned. You Crypto Corps stomped on "White Hats" for years, rewarding them peanuts, ignoring them, closing their issues as "duplicates" with half-assed reasons. The industry should prepare for the rise of Grey Hats. They will hack you and then dictate terms. You will say "yes sir" and beg. And no, you're not smarter than them because YOU got exploited. Release the chat logs. An agreement must have been made for them to return 3400 BTC (85% of the funds). The alternative was 0 BTC. You'd be screaming right now. Now, you label it "theft" which to me signals a renege on agreed terms. We can't know until you release that information. Your shitchain got annihilated, let's not forget the source of the Rekt. You were fortunate a Black Hat didn't get you first. I also cannot discount an inside job. But I extend the benefit of the doubt. You'll be writing "Dear Hacker" letters into the void. Sophisticated people who were intelligent enough to exploit you, the REALLY GOOD ONES, will not be caught. People think @chainalysis @trmlabs @elliptic are some magic wand, as if tracing and enforcement are the same thing. You can literally stare at an exploiter's address and watch in futility as funds are laundered successfully. >Muh law enforcement No country is going to war with another country over a theft or hack. Rival intelligence agencies hack each other all the time under "fair game". Crypto is a literal who.
To those responsible for the theft of bitcoin from the Liquid Network: Blockstream will not pay a ransom for the return of stolen funds. Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft. We have engaged in good faith in an effort to secure the return of stolen user funds and protect the broader Bitcoin community. That effort should not be mistaken for acceptance of the actions taken nor of the terms being demanded. We will not be a party to the precedent that open-source software developed for the good of the Bitcoin community should subject its developers to paying a ransom that far exceeds their economic participation. Bitcoin is hard money and can’t be minted without costs, Bitcoin doesn’t haircut users to pay a ransom. To the Bitcoin community: We are fighting for what we believe in, for the users whose funds were taken, and for the principles on which Bitcoin was built. The community has demonstrated incredible resolve with teams of people dedicating their time in support of each other to identify and patch vulnerabilities in each other's products and systems. We are all driven by the mission that Bitcoin is the single best asset, for every person, company, and institution on the planet to invest, use, and build on. The world is a different place with the advancements of AI, and the Bitcoin community has responded with force to combat that threat. Damage has been done, battles have been lost, but on the whole the Bitcoin community is gaining ground in the war with bad actors. We want to thank the community for those efforts, for your support in hardening the network, helping users recover funds, and for your support in our assertion that crime does not deserve rewards. To those holding the stolen bitcoin: There is still an opportunity to resolve this responsibly. The bitcoin can be returned and we can revert to the standard of white-hat principals. However, if the funds are not returned, we will pursue every lawful avenue available to us. We will work with law enforcement, exchanges, service providers, forensic specialists, and other relevant parties to trace and recover the assets and identify those responsible. More importantly, Bitcoin is transparent by design and the community is made up of the most sophisticated engineers, cryptographers, and white-hat hackers globally. Transactions do not disappear, and neither does the evidence they leave behind. We will not pay for the return of stolen property. We will not abandon our users. The Bitcoin community will not stop pursuing the funds. Return the bitcoin.
4
535