The best kind of meetup: When the audience creates as much value as the speakers. Over the course of last night's meetup, audience members kept both speakers going with sharp technical questions on address reuse, 2FA vs on-chain keys, and co-signers vs custodians. 🎤 @_benkaufman built a live 2-of-3 Bitcoin multisig with a Ledger, Trezor and Jade: xpubs, descriptors, on-device address checks, a PSBT signed by two keys. His rule: back up the descriptor, or two keys won't be enough to spend. 🎤 @boazeb took it to mobile. After a recent iOS zero-day leaked seeds from phones, he asked if multisig is inevitable for consumer wallets. His @summocash wallet runs 2-of-3 with a policy-checking co-signer and guardian recovery. See you at the next one!
1
1
5
248
Can your crypto survive a $5 wrench attack? After next Wednesday, yes. 82 documented attacks in 2025, about double the prior peak. @boazeb and @_benkaufman will cover multisig at the meetup. 📆 Next Wednesday, 23/9, 18:00 📍 @sncentral_ luma.com/o6gh384v
NEXT MEETUP IN TEL AVIV 1. @_benkaufman workshops multisig with @SparrowWallet. 2. @boazeb on building @summocash, his 2-of-3 multisig app. 🗓️ Wednesday - 23/9/2026 📍@sncentral_ (28 Lilienblum St.) Learn to keep your crypto safe: luma.com/o6gh384v
1
1
4
786
NEXT MEETUP IN TEL AVIV 1. @_benkaufman workshops multisig with @SparrowWallet. 2. @boazeb on building @summocash, his 2-of-3 multisig app. 🗓️ Wednesday - 23/9/2026 📍@sncentral_ (28 Lilienblum St.) Learn to keep your crypto safe: luma.com/o6gh384v
2
6
12
1,381
Open-Kritt passed 1,000 GitHub stars in just two weeks. TOMORROW, Gabriel Balko takes apart the AI agent behind it → the one that found a $250,000 bug. Speaker: - Gabriel Balko (@ControlZ_1337), Security Researcher & Founder, ControlZ / Kritt. #18 all-time on Immunefi. What he is covering: - how the agents are scoped, one per entry point - how duplicate findings get merged and ranked - what the agents reliably miss Second half is live Q&A. Bring questions. 📅 Wednesday, August 19 🕐 10:00 EDT · 16:00 CET · 17:00 IDT 📍 luma.com/eo69kght?tk=kIt76F
1
2
120
A Bitcoin seed should take billions of years to guess. COLDCARD seeds made after 2021 took just 15 minutes to crack on a consumer laptop. @AvishaiY, @boazeb, and @SHAP0W discuss the catastrophic consequences on The Underground.
2
1
5
269
Did you know that @TomerAshur and @3miLabs did the research that led to it?
Goodbye, Poseidon! An epic 8-year, 8-figure rabbit hole in post-quantum cryptography reaches its dream conclusion. The Ethereum Foundation is abandoning Poseidon for L1, pivoting to SHA or BLAKE. This milestone unlocks ultimate security for lean Ethereum and foreshadows a golden era of hash-based cryptography. Since 2018, the Ethereum Foundation has invested in magic cryptographic bricks, so-called "SNARK-friendly hashes". In 2019, Poseidon was born. It held strong and became the dominant SNARK-friendly hash, securing billions via zkrollups and zkVMs. In a stunning reversal, breakthrough SNARK designs show that SNARK-friendly hashes aren't necessary after all. Off-the-shelf traditional hash functions like SHA2 and BLAKE2s can now match Poseidon in a SNARK. In hindsight the key was not SNARK-friendly hashes, but hash-friendly SNARKs. The secret is doing maths over the smallest prime number: 2. So-called "binary fields" natively speak the language of bits, aligning with the boolean operations inside traditional hashes. This is a stark departure from "prime fields", where awkward large-prime arithmetic makes bit manipulation painfully expensive. We're talking sci-fi cryptography. 1M traditional hash calls proven per second, on a laptop. Just 100x overhead vs native CPU boolean compute. Nobody predicted such performance, not even the handful of binary-field visionaries. Hat tip to the research geniuses: Jim and Ben with Binius in 2023; Ron, Benedikt and William with Flock in June. With SHA2, the lean aesthetic of minimal assumptions reaches its climax. The EF's principled stance on pure hash-based cryptography has aged like fine wine. We now enjoy foundations the world can trust for decades and centuries, foundations worthy of the dream of an internet of value. Speed of deployment is a secondary win. There's no longer a need to wait years for Poseidon cryptanalysis to bake. Emile and Thomas from the EF post-quantum team are moving at breakneck speed with binary fields. The strawmap now points to a production-grade leanVM in 2027, with CL, DL, EL deployments in 2028. As AI becomes exceptional at cryptanalysis, the contrarian bet to avoid riskier structures like lattices and isogenies is visibly paying off. The past weeks have been brutal. Lattice-based "HAWK" and isogeny-based "SQIsign", both signature schemes in NIST's Round 3, have suffered blows. Sources I trust say more blood is coming. On AI, the open autoresearch trend kicked off by ECDSA[.]fail is spreading fast, with amazing outcomes from zk[.]golf and SNARK[.]fast. Days ago SNARK[.]fast crossed 1.8M BLAKE3/sec proven on an M3 Max. Stay tuned for fresh autoresearch challenges dropping tomorrow. Also tomorrow: Ethproofs call #10, dedicated to binary fields. Possibly the most noteworthy Ethproofs call yet. Experts leading the charge will present the future of hash-based SNARKs at 2pm UTC. What an incredible time to be alive. To witness history, DM me for a calendar invite :) Today I can confidently claim that hash-based cryptography has won out for blockchain post-quantum signatures. SNARK succinctness compresses arbitrarily many signatures into one small proof per block. SNARK flexibility yields k-of-n threshold signatures, complex multisigs, and more. Ultimate security. Uncompromising performance. Full programmability. Believe in something. Believe in hashes.
2
124
Gabriel Balko (@ControlZ_1337) open-sourced his AI agent that found a $250,000 bug, and it has already passed 1,000 GitHub stars and secured hundreds of thousands of dollars. Next week on the Underground, he'll show you how it works: 📅 Wednesday, August 19 🕐 10:00 EDT · 16:00 CET · 17:00 IDT 📍 Live on YouTube Register here: luma.com/eo69kght?tk=kIt76F
1
1
7
315
Web3 Devs Underground retweeted
Big love to @Web3_Devs 🖤 Israel's largest developer-led Web3 community is joining Common S3nse as a Community Partner — bringing their builders straight to the stage in Amsterdam. Privacy • Security • DeFi 📍 Amsterdam 📅 September 4-5 (during Cypherpunk Week) 🦦 Privacy is Common S3nse 👉 commons3nse.cryptocanal.org/ 🐈‍⬛ Cypherpunk Week 👉 cypherpunkweek.com/
1
3
5
264
🚨 Emergency session THIS WEDNESDAY. A build error from March 2021 made COLDCARD wallets generate seeds from software instead of the hardware RNG. The seeds ended up with just 40 bits of entropy instead of 128. Attackers have now taken around 1,816 BTC (~$114M) from ~5,294 addresses. Speakers: - @AvishaiY, Co-Founder & CEO at @sodabubblelabs - @boazeb, ex. @Citi, ex-CEO Blocktrail/BTC.com - @SHAP0W, Managing Partner at @MasterkeyVC On the agenda: - what exactly went wrong - how to check if your wallet is affected, and what to do next - why nobody caught it for five years 📅 Wed, Aug 5 🕐 12:00 EDT · 18:00 CET · 19:00 IDT 📍 Live on X, YouTube & LinkedIn: luma.com/web3devs-nc1e
1
5
7
343
Recap 👇 A startup got paid in full on a $1M deal and lost ₪400K to the exchange rate. FX hedging with @AltshulerShaham, a ₪1B Innovation Authority fast track, and on-chain hedging with @OfirEliasi. First LIVE session (in Hebrew 🇮🇱) at our new home, @sncentral_. piped.video/watch?v=J3wv1dlC…
2
4
205
Web3 Devs Underground retweeted
A simplified explanation of the Coldcard issue. When you set up your Coldcard it generates a secret - the words it tells you to copy and keep safely. Turns out it was choosing those words in an easily predictable way (instead of randomly), meaning it’s easy to guess which words a Coldcard would choose. Since it’s easy to guess your secret, anyone can know it. This secret is the key to your Bitcoin - meaning anyone who guesses the secret has as much ownership of the Bitcoin as you do, and can steal it to a wallet they control.
1
5
47
3,067