Michael Lewellen retweeted
Turnkey now supports Solana V1 Transactions! Execute larger, more complex operations up to 4,096 bytes as one atomic transaction all within Turnkey's secure signing infrastructure.
Replying to @solana
Transactions V1 is now live on Solana, increasing max transaction sizes from 1,232 to 4,096 bytes. Complex operations like ZK proofs, large multisigs, and confidential transfers that required multiple transactions now fit in one. Full details from @anza_xyz: nitter.net/anza_xyz/status/209966…
1
1
8
724
Michael Lewellen retweeted
Shielded Bitcoin vs Zcash: Shielded Bitcoin is pretty clever tech given the constraints, but there’s a big gap that Zcash provides. - Zcash: zk-proof of shielded transaction is validated by the miner at block inclusion. Invalid proofs are not included in the block, therefore you know any proof onchain is valid. - Shielded Bitcoin: zk-proof is just stored on Bitcoin without checking for validity. A separate network is needed to determine if the proofs are valid and reconstruct the Sheilded transaction state. You can’t use the Shielded pool with Bitcoin Consensus alone, very much how most L2s function. Interestingly, this seems to be a massive technical improvement over the Lightning Network! Am unclear on how or why the secondary network would function without PoW rewards. An important detail is left to research, which is how the lock/unlock of L1 transparent BTC will work in practice. Look forward to seeing what they find here.
JUST IN: Researchers propose framework for private transfers on Bitcoin without a need for a soft fork 👀
8
10
76
16,951
So you’re telling me Flock’s surveillance honeypot not only violates our privacy, but also moonlights as Russian spyware when cops leave their accounts unsecured? 🤡
Cybersecurity researcher: I found that Flock did not require their clients to use multi-factor authentication. This led me to find Flock law enforcement accounts for sale by a Russian vendor on a dark web marketplace. In addition to this, we found insufficiently protected sensitive information stored on Flock cameras, including photos, license plate data, logs, API keys, passwords, and communications.
3
3
23
1,048
Michael Lewellen retweeted
The main problem with massive money printing - it doesn't work if the rest of the world doesn't want your debt. In 1929, the Great Depression was triggered from a sudden deflationary event. For years, credit became extremely overextended due to private lending and banking greed. Back then, the primary vehicle of investment for the general public was the stock market, so on the heels of a WWI victory, Americans borrowed aggressively and plowed capital into the stock market. Eventually, the bubble burst and euphoria turned into fear overnight. Simultaneously, Smoot-Hawley imposed a strict regime of US isolationist tariffs, which intensified the deflationary reset. It took two decades to recover, but it was a necessary reset that enabled a renaissance of economic prosperity in our great nation. Sadly, it was a war that focused American productivity, greased the economy with spending, and ultimately reset global conditions. Today, credit is once again deeply in extreme overextension, except this time it is both private and public credit. We are imposing strict, isolationist tariffs. And now, we are participating in a war that to most, is seemingly coming out of nowhere. In a crumbling fiat regime, war is the eventuality, the result, of an overburdened empire built on decades of credit extension. Play this out with game theory. Many think that the US will print its way out of it. Certainly, printing will occur, but the effects of the printing are diminishing quickly. Printing only works if there is someone on the other side willing to extend you fair terms, and the rest of the world has signaled that US debt is no longer a primary interest. 3 years of failed long-term UST auctions, K shaped economic maturation, and as of last year, gold has replaced USTs and became the highest reserve asset among all central banks globally. The tides have quickly shifted. It is only a matter of time before macro data gets worse, which is already becoming untrustworthy as for two consecutive years, jobs data has been revised down by 1 million each year. Printing will stimulate, but I believe this is the last time the US can play this card before a major monetary regime change. We are on track to double our already enormous debt load within 8 years. Ask yourself this - there is $1.2 Quadrillion of "value" stored among the four major pillars of equities, bonds, real estate, and commodities. Yet, there is only $120 Trillion of fiat in existence. What happens when even one of these pillars attempts to liquidate into cash. There is simply not enough cash to support the existing fractional banking system. The data is there. The signs are there. It is not difficult to reach a logical conclusion at this point. Get to BTC and gold as quickly as you can.
3
5
39
21,926
Michael Lewellen retweeted
In new brief, Lewellen argues that DOJ enforcement discretion cannot replace clear legal protection for non-custodial developers coincenter.org/a-thin-doj-po…
8
22
5,774
Michael Lewellen retweeted
@LewellenMichael submitted a reply brief on Monday against the DOJ, arguing that the district court prematurely dismissed his challenge to the DOJ’s interpretation of 18 U.S.C. § 1960 and that the DOJ’s interpretation of § 1960 exposes him to a credible threat of prosecution if he publishes and operates a non-custodial cryptocurrency software. @coincenter’s blog discusses his arguments and the road ahead: coincenter.org/a-thin-doj-po…
2
9
20
3,371
Michael Lewellen retweeted
Idiocracy vibes. Next up, watering the plants with Gatorade.
110
78
1,327
47,283
Michael Lewellen retweeted
We're proud to work with @Compound_xyz, one of DeFi's most established lending protocols, to protect its community from phishing and impersonation across the web. Fake domains and fraudulent Medium articles made up nearly two-thirds of all threats blocked, followed by impersonation accounts on X at 24%. Capital moves fast. So do we.
2
19
40
1,787
Michael Lewellen retweeted
First episode of Builders Room in the books! I sat down with @LewellenMichael to chat & demo Swaps & Earn on Turnkey, unlocking new revenue streams for any platform. Head over to the Builders Room to request to be featured on future episodes: turnkey.com/builders-room
5
2
15
953
Huge congrats to the OpenZeppelin team! I'm proud to have been part of the early story watching the security standard the team set become the rails S&P Global wants to build on is a hell of a validation. Well earned!
Today we are announcing that S&P Global has entered an agreement to acquire OpenZeppelin. Onchain finance is growing from an emerging market into core financial infrastructure, and the standards and rails our team and community built are becoming the rails of global finance. OpenZeppelin smart contracts facilitated over $37 trillion in value transferred, with the vast majority of the largest DeFi protocols, blockchain networks, stablecoins and tokenized funds relying on them. With S&P Global, we expect to accelerate the impact of onchain finance, backed by more than a century of trust in global markets, benchmarks, and risk frameworks. To our clients and to all the users of OpenZeppelin open source tools: • OpenZeppelin Contracts and all our open source applications and tools remain open source, free, and publicly maintained on GitHub. Building open source standards stays a core priority. • Audits, engineering work, and ecosystem programs continue with the same team, brand, quality, and customer experience, with what will be the added benefit of S&P Global's research capacity, market data, and institutional reach. For the last decade, OpenZeppelin has set the security standard for onchain finance. Today begins a new chapter for that mission, together with one of the most trusted names in global markets. Read the full announcement: openzeppelin.com/news/spglob…
3
1
66
2,136
turns out “give the agent your password, API keys, TOTP seed, and a tiny prayer” isn’t a great auth strategy 😅 we’re building the better version at @turnkeyhq with scoped access, programmable policies, approvals when needed, and credentials that stay out of the model’s hands if your agents actually do stuff, come build with us and stay safu: turnkey.com/agent-auth-beta
new thing we’ve been building at @turnkeyhq: agent auth.  agents need credentials to do useful work. right now this means giving them passwords, api keys, oauth tokens, even totp seeds. this gives the agent far more access than the action actually requires  for years, turnkey has secured millions of private keys using verifiable TEE infrastructure. underneath that is a generic system for credentials, auth and policies, with human and machine authenticators, consensus, temporary and revocable access, and a full audit trail  now we are opening up these primitives for agent builders. 

the end user keeps sovereignty over their credentials while giving builders a way to easily grant scoped access based on the action it needs to take. 

a lot of agent builders are not thinking about security yet, but we think this becomes a critical product differentiator very soon. we want to make doing it correctly the easy path.  many of the pieces are already live:  •agents can retrieve encrypted secrets under programmable policies, including consensus and temporary or revocable access •they can sign git commits and authenticate over ssh without holding the underlying private keys •and of course if you want your agent to pay for things over crypto rails, turnkey already secures the wallets and enforces the policies for that too what’s next: we’re looking for agent builders who want to help shape what comes next. reach out or sign up below turnkey.com/agent-auth-beta
4
1
28
915
Michael Lewellen retweeted
“Who’s a good boy?!” Hackers just dumped the contents of a Flock camera. They found: 🔴Software explicitly detecting people, not just plates 🔴1.6 million images logged in 21 days 🔴Key to decrypt files stored on the device itself. Finds directly contradict Flock, which claims someone with physical access can't access images. Making it worse,@GainSec warned about the physical access issue more than a year ago & Flock downplayed it. And yeah, the Flock camera logged “Who’s a good boy?!” about every 2 minutes, all while plagued with errors, crashes & reboots. By @dmehro & @josephfcox wired.com/story/hackers-floc…
195
7,587
24,979
875,721
Michael Lewellen retweeted
Join us this Thursday, Sept. 17th, to kickoff the first episode of Builders Room! Turnkey’s Head of Solutions Engineering @LewellenMichael is demoing our newest product: Swaps & Earn. 🗓️ Sept. 17 | 11AM ET Register here: turnkey.com/builders-room?ut…
2
3
24
2,164
Michael Lewellen retweeted
Doesn't matter what side you're on, this much red for v4 hooks is diabolical.
A malicious hook doesn't need a UI to scam you. 👉 It just needs to look like the best quote. After analyzing over 84,000 v4 hooks, we determined only 19% of hooks to be safe. It's time to get real about hooks.
Article

Uniswap v4 hooks were a mistake

It’s time to get real about hooks. This year 0x has routed 81.92 million trades and $42.67 billion in volume, with roughly ~70% of transactions touching Uniswap liquidity. And we field dozens of

15
4
106
12,848
Michael Lewellen retweeted
.@1Password's FLAWED report says AI models produce a clean security fix only 26% of the time. Defenders shouldn't take that number seriously. • The six vulnerabilities were handpicked because their fixes were complex. Clean-fix rates ran from 3% to 60% depending on the bug, and the report averaged them together. • Agents set up to fail were counted in the headline figure. Two of 1Password's prompts instructed the agent to apply the wrong fix. Those trials make up 22% of the data. One evaluation mode prevented the agent from compiling or running any code, and it accounts for 36% of the data. • The report ran two models, GPT-5.5 at medium effort and Opus 4.8 at high. Neither was tested at its highest available setting, so the report says nothing about how more effort or stronger models change the results. • Several instruction and grading errors further undercut the headline, and are elaborated upon in the attached blog. We've spent four months submitting hundreds of AI-authored patches to widely adopted open-source projects as part of Patch the Planet. Our experience didn't match 1Password's report, so we did a full analysis across 186 AI-authored pull requests and 33,500 subsequent commits, benchmarked against 2,265 human-authored patches we graded across years of security engagements. blog.trailofbits.com/2026/09…
24
49
266
556,021
Michael Lewellen retweeted
I agree that you should not route to arbitrary hooks! But this is an oversimplification of the problem. 1. Uni v4 hooks fragment liquidity by creating a trade-off between fast coverage of new tokens and security. Fragmented liquidity is obviously bad for users. Though I will say it isn’t impossible, just very difficult, to have both fast token coverage and security. We spent a lot of time iterating on our design to get to this point. To put things in perspective, the official Uniswap allowlist supports 115 hooks. 0x supports ~17,000 verified hooks. 2. Hooks make quotes less trustworthy, and users can’t tell the difference until it’s too late. Most aggregators do route to at least some malicious pools (I’m not aware of any others that don’t), resulting in inflated quotes that aren’t easily detected through simulation. Meta-aggregation is such a big part of the market structure that aggregators that integrate malicious hooks are actually rewarded with more volume. Users have no way of telling the difference and end up getting rekt. This is why you often see F-tier aggregators with the highest volume share on meta-aggregators with poor quality controls.
This should be titled "0x routing made a mistake" If you're an aggregator, you can't just route to arbitrary hooks! It's why Uniswap's own router has an approval process developers.uniswap.org/hook-…
7
9
80
5,596
spicy and correct take
A malicious hook doesn't need a UI to scam you. 👉 It just needs to look like the best quote. After analyzing over 84,000 v4 hooks, we determined only 19% of hooks to be safe. It's time to get real about hooks.
Article

Uniswap v4 hooks were a mistake

It’s time to get real about hooks. This year 0x has routed 81.92 million trades and $42.67 billion in volume, with roughly ~70% of transactions touching Uniswap liquidity. And we field dozens of

4
3
24
2,375
Michael Lewellen retweeted
@coincenter’s stance on the newly revised BRCA is that it would provide important protections for non-controlling blockchain developers under the BSA, but it removes the BRCA’s explicit protection against criminal liability under 18 U.S.C. § 1960, leaving this incredibly important matter to the courts. This makes @LewellenMichael’s lawsuit against the DOJ even more important. Read more: coincenter.org/the-proposed-…
1
8
27
4,583