Robert Chen retweeted
holllyyyyyyyyyyyyy fffffffffffffffffff
16
5
173
97,103
Txv1 is live, and Anchor 0.30.2, 0.31.2, and 0.32.2 support receiving it. If you're still on old coral-xyz/anchor packages, update to anchor-lang/core and friends Anchor 1.2.1 is coming soon with support for receiving *and* sending Txv1 Thanks @clubby789 for pushing this through!
1
7
30
1,392
I'll be in London speaking at Scale or Die - if you're around, would love to meet! luma.com/scale-or-die-26
2
1
81
2,557
Robert Chen retweeted
We’re disclosing HEIF Heist, a months-long investigation into libheif that allowed us to hack OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more. It was literally xkcd #234, one obscure image library beneath a huge number of apps. 🧵
47
426
3,234
556,505
Robert Chen retweeted
We found some stuff. Actually, quite a lot of stuff. Back in July, our team @rootxharsh, @S1r1u5_, and @iamnoooob managed to compromise multiple OpenAI employees’ ChatGPT accounts. In theory, any ChatGPT connector can be affected. This includes Slack, github, email, and other services. 🧵
7
17
168
8,640
really scary find from @S1r1u5_ and team, hacking into OpenAI's monorepo! great writeup from the @WSJ
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
3
2
84
6,957
Robert Chen retweeted
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
356
1,398
11,858
2,788,356
Anchor v1.2.0 is here, including `lang` and `spl` fixes that missed the last release. What's new: • Better zero-copy support and CPI fixes • Newer Rust toolchain for smaller binaries • And much more... Shoutout to @clubby789 and @madduswaroop for pushing this through!
2
2
33
3,759
Robert Chen retweeted
1/ We found a full collision for the Poseidon1 Collision Prize instance and submitted it on July 31. Two different messages, identical 16-word output after all 28 rounds, verified on the Initiative's official implementation. The technical breakdown and full story ⬇️
1
12
93
9,316
Robert Chen retweeted
Acctual is joining Altitude to bring invoicing into the global operating account, alongside a deeper bill pay experience. We’re bringing more of how businesses get paid, pay bills, move money, and run finance into one connected system. Invoicing, now in your Altitude account.
32
35
217
119,353
Great panel with @claudijd, @_mwc, and @amandatums on how security coordination can help inform smarter policymaking Thanks to @SolanaInstitute for hosting!
3
2
46
2,455
Robert Chen retweeted
I’ve joined @thinkymachines to work on safety & alignment. The default trajectory is that as AI gets more powerful, control over it will concentrate in the hands of a few. I’d rather build safety systems that let control over AI be shared widely. Longer thoughts below.
42
31
962
270,752
Robert Chen retweeted
Solana is the most battle-tested network. Each stress test on Solana has been met with major improvements by the core engineering teams and further improved the network resiliency time over time. Solana's resiliency isn't just about surviving the worst days, but also making ambition for a better future possible. thestreet.com/crypto/innovat…
30
62
274
22,643
Robert Chen retweeted
📌 AI made finding bugs cheap, but it didn’t make responsible disclosure optional. Finding and exploiting vulnerabilities has never been easier. A few hours of prompting now does what used to take a skilled researcher weeks. Unfortunately, defenders no longer enjoy the asymmetry they relied on. Security is still a cat-and-mouse game, but with many more cats, the user suffers. Which is exactly why the process around disclosure matters more than ever. How it works, and it is not complicated: ➤ A researcher finds a bug and contacts the vendor privately. ➤ The vendor reproduces, acknowledges, and both sides agree on a timeline. 90 days is the common default, more or less depending on severity, capacity to fix... ➤ During that window both sides keep it secret while the vendor fixes and ships. ➤ Once users are protected, both sides publish. The ecosystem learns. The researcher usually gets paid. The issue now is the barrier is so low that anyone can surface a finding with no security background, and some skip straight to the audience: ❗Presenting a reproduction of an already-fixed bug as a live compromise. ❗Full disclosure of a bug that is not fixed yet. ❗"Critical vulnerability found" teasers, dripping details for engagement. Call it what it is: attention farming with someone else's risk. When the bug sits between a user and their funds, this is reckless. Especially in crypto, where there is no chargeback. But the damage doesn't require live funds to be at stake. Manufactured panic causes harm of its own, because it drives people away from self-custody, and that damages the whole ecosystem. So I have three asks: 1️⃣ For users: software and hardware have bugs, always. The single most effective thing you can do is stay updated and follow basic security hygiene. That has never mattered more than today. The time between releases and malicious actors exploiting the vulnerabilities have shrunk dramatically due to LLMs and that one can't afford to be passive and postpone security updates any more 2️⃣ For new researchers with a fresh model and a real, validated finding: welcome, we need you. Use the vendor's disclosure process. That is not bureaucracy. It is the difference between making the ecosystem safer and putting users in the crosshairs for a few likes. Remember that security communication must be accurate and proportionate. State the severity, affected versions, and fix status in the first sentence, not the tenth. 3️⃣ And to everyone building in this industry, vendors and researchers alike: let's make coordinated disclosure the norm we defend out loud, not the fine print. Reward the researchers who do it right. Refuse to amplify the ones who trade user safety for reach. This is how we win, together. Some of the actors already support the initiative. @Ledger @Trezor @FoundationHQ @AnchorWatch @_SEAL_Org and others Spread the message.
44
52
225
101,554
Robert Chen retweeted
Replying to @0x10n
@0x10n found a cool thing in v8.
Replying to @QED_Audit
@QED_Audit found CVE-2026-19174, an integer overflow in V8 that gives you arbitrary code execution in Chrome. The bug is one line of constant arithmetic. It survived 3.5 years of fuzzing, manual audit, and LLM-driven review. (1/n)
2
22
2,222
simple fixes go a long way
Was bad prompting responsible for the HuggingFace incident? It turns out the ExploitGym prompt is remarkably bad at explaining intent to agents. I benchmarked how agents respond to broken tasks w/ different prompts and the ExploitGym one was the only prompt that led to cheating!
1
26
2,239
I'll be in DC on the 14th, if you're around come say hi! luma.com/DCSummit
2
79
2,617
we're looking to grow the design team a bit! you'd get to work with @enscribe, super talented at what he does
I'm hiring a fractional designer. Please message me with your portfolio.
1
2
23
2,809
here we go again..
Our team discovered a critical remote code execution vulnerability in Next.js. If you self-host Next.js, update immediately. Vercel managed Next.js hosts are safe! We’ll publish the technical details and proof of concept soon!
1
28
4,155