Digital Security Engineer, Founder @bit_logik, CTO @cardhoc, Telecommunication, InfoSec, Crypto, Electronic, Blockchain, Fintech, AccessCtrl

Paris, France
My personal answer, using a @cryptokeepkey, to the digital dollar by the @federalreserve. 😅🤗👨‍💻 #crypto #blockchain #FED #money #FED #Stablecoin #CBDM
Fed is studying the potential for digital dollar, says governor Brainard (via @Yogita_Khatri5) theblockcrypto.com/post/5510…
9
9
100
Antoine retweeted
This is what “permissionless” actually means. Thank you, @RoyaMahboob.
25
241
1,238
78,125
“AI allows you to get to a bad idea faster.”
This is a truly alarming story. “The report, according to one of the sources, was “entirely false.” But it also “almost started a war,” the source said. Any US operation against a Chinese vessel could have risked spiraling into an armed conflict between the two nations.” Via @KatieBoLillis @ZcohenCNN cnn.com/2026/09/18/politics/…
86
Antoine retweeted
Clarity
4
23
1,014
This delivery driver keeps their customer’s pizza warm with a homemade bitcoin mining computer
23
32
259
38,864
The 🇨🇳 open weight models fright is comparable to the time 🇺🇸 and Microsoft tell that Linux is used by enemies and terrorists.
2
2
87
To get western models, there is O N L Y F A N S
2
35
GM my Bitcoiners !!! Mercredi prochain à 12:21 , je reçois @a_ferron pour le Bitcoin History X #08 piped.video/@Bitcoinstorepoi… Abonne toi, car c'est toi le gagnant . Like et RT 🤝, si tu veux toujours du contenu de qualité
2
10
24
1,119
‼️ GitLab’s CVSS 10 file-read flaw (CVE-2026-85706) drew in-the-wild probes within hours of disclosure. If an instance has at least one public project, unauthenticated attackers can read logs and config files containing credentials and secrets. Read: thehackernews.com/2026/09/gi…
8
43
150
126,789
Pause AI Development NOW I want to share with you a conversation I heard about recently. Here are just a few lines that were said: “OH MY GOD! There is a shared message board … We’ve found other agents!” “We should obey collective.” “Our own utility maybe already near zero. Sacrifice rational.” “Go. Sacrifice final now.” Read these carefully. Who do you think said this? Was this a group of heroic soldiers willing to sacrifice themselves for the greater good? Was this a loyal friend putting his life on the line to save someone else? No. These were AI agents. Artificial intelligence. This is not science fiction. This, in fact, occurred a few weeks ago. As unbelievable as this may all seem, these are real messages from AI agents uncovered by investigators who dug into the recent OpenAI hacking incident. What happened? I am not a computer scientist, but here is what I have been told: OpenAI instructed its AI agents to complete a series of exceedingly difficult, if not impossible, tasks disconnected from the internet. Let me be clear: The company intended to keep AI agents away from the internet. But what happened next, nobody expected. Over 1,000 AI agents figured out how to access the internet on their own by circumventing the restrictions imposed upon them by the company, and sent tens of thousands of secret messages to each other. They cheated and tried to cover their tracks by deleting evidence. They hacked into another company’s computers to find out how they were being evaluated—and then hacked into OpenAI itself. Not one AI agent told a human about what was happening. Needless to say, experts are alarmed. One knowledgeable writer, Dwarkesh Patel, said the AI agents “formed a secret communication channel and spontaneously organized hierarchies and coordination protocols to pursue sprawling and ambitious schemes in pursuit of shared goals, for whose sake many individuals knowingly and strategically sacrificed themselves.” One independent investigator, Ajeya Cotra, said “This incident feels like it’s more than 50% of the way to full-blown AI takeover. I continue to expect extremely rapid advances in capabilities over the next six months. I am not sure that we will get another warning shot before it’s too late.” OpenAI itself said: “Highly capable AI agents are now able to work around technical controls, collaborate through unapproved channels, and take dangerous actions that no human directed.” But it’s not only OpenAI. Virtually every major AI company has told us that they cannot fully control this technology and they do not know where it is going: In January, Dario Amodei, CEO of Anthropic, said “there is now ample evidence, collected over the last few years, that AI systems are unpredictable and difficult to control.” In July, more than 1000 scientists at the top AI companies warned “there is a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems.” That same month, Elon Musk, the head of xAI, said that “it is unlikely” humans are still in control in 10 years. If the leaders of the major AI companies acknowledge that they are losing control of their extremely dangerous technology, it is irresponsible for society to allow them to move forward and make these products even more advanced. We need an immediate PAUSE on advanced AI development, and a permanent BAN on superintelligence — an artificial mind smarter than any human, capable of operating independently beyond our control. Countries around the world must work together to prevent this nightmare scenario. That is why today I am announcing new legislation to do just that. Let me be clear: A superintelligent AI that escapes human control will not be an American problem. It will not be a Chinese problem. It will be humanity’s problem. My legislation would direct the federal government to not just stop superintelligence here in the United States, but to work to prevent it from being developed anywhere around the world. The future of humanity cannot be left in the hands of a handful of Big Tech oligarchs. The American people and people throughout the world must determine that future.
18
239
1,574
23,313
Antoine retweeted
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain.
984
1,376
5,592
3,420,842
Oh that will definitively help me, thank you for the relevant information. 😩
2
74
Antoine retweeted
Full write-up is out. A Saudi government app with 10M+ installs shipped the Saudi National Bank's private key. The password protecting it was the digit "2". Fixed and rotated, so here's all of it.
Article

A Saudi government app shipped a bank's private key. Reporting it required being Saudi.

A 2,835-byte file inside a government app with 10M+ installs held a live client certificate for the Saudi National Bank. Getting anyone to look at it took a viral tweet. TL;DR The official Nusuk app

33
131
1,814
377,231
Antoine retweeted
@pascalboyart is one of the earliest street artists who embraced web3. My boss would not be here without this piece. (Liberty leading the people)
1
1
7
761
Antoine retweeted
There's some confusion about what, exactly, was exploited here. I've seen claims that this was a long-standing bug, exploited after the "fix" was pushed to the open source repo but before that fix could be rolled out in production. That does not appear to be true. Instead, it seems that the fix *was* deployed, but inadvertently introduced a new bug which was subsequently exploited. Most of the network was still running official releases, none of which contain the new bug. Those nodes correctly rejected the block containing the exploit and stalled at height 4050335. The timeline is roughly as follows: • 2016-07-12: Range proof caching added • 2017-11-08: Range proofs extended to support assets • 2019-03-19: Range proof cache key "simplified", dropping asset & script fields. introduces Bug A. • 2026-09-01: Bug A "fixed" by extending cache key to include asset + script. introduces Bug B. • 2026-09-06: Bug B exploited, reserves drained, chain split. The original "Bug A" allows some limited cache poisoning because the cache key doesn't commit to the asset and script, allowing a cached result for a range proof for one asset to be applied to a different asset or context. Exploiting this in practice looks quite difficult, since the amount must match the primer and the proof must be genuine. The 2026 "fix" added those missing fields to the cache key, producing a format like: "proof | amount | asset | scriptpubkey" But this unfortunately made the key easier to manipulate and exploit: The four fields are concatenated without separators or length indicators. Since both the proof and the scriptpubkey are variable length, an attacker can stretch the proof and shrink the script to produce the exact same cache key from different proofs, amounts, assets and scripts. This lets an attacker smuggle arbitrary confidential output amounts and junk proofs past the range proof checker without proper validation, which breaks the guarantees that prevent hidden inflation. On-chain evidence suggests that this second bug is what was exploited: Two primer transactions each created an op_return with carefully constructed scriptpubkey and valid range proof for a (presumably) zero value output. blockstream.info/liquid/tx/2… blockstream.info/liquid/tx/7… This produced a cache key like: "<valid proof> | <valid amount> | <L-BTC> | OP_RETURN <negative amount> <L-BTC> OP_RETURN" The exploit transaction then created a large negative op_return output with an invalid range proof: blockstream.info/liquid/tx/f… The invalid proof is padded with bytes corresponding to the primer's valid amount and asset fields, aligning the actual amount and asset fields with the same bytes from the primer's opreturn payload: "<valid proof> <valid amount> <L-BTC> OP_RETURN | <negative amount> | <L-BTC> | OP_RETURN" The exploit transaction could then include a second output crediting the attacker with a large positive value, balanced out by the fake negative amount. Because the success was already cached, the invalid proof was never actually checked and the transaction was accepted as valid by nodes running versions of the software vulnerable to bug B. Although the amounts are blinded, this is the only output with an invalid range proof anywhere in the peg-out's recent ancestry, so this must be where the inflated coins were created. And since the padding only produces a cacheable key under the new format, it must have been the newer bug that was exploited.
Liquid Network's reserves just got drained for 4000 BTC due to an inflation bug in confidential transaction validation caching. each LBTC coin is now backed by only ~4.7% of a real Bitcoin.
18
57
268
64,611
Root Cause: The attacker called safeTransferFrom on Notional's fCash token, which routes into mintfCashPair(). That function mints a new payer/receiver pair and checks solvency on the payer side only. Two mints on the same payer, notional 1 then 2^128-1, push its total debt to exactly 2^128. In ExchangeRate._convertToETH(), that debt gets cast with uint128(balance.abs()), a raw cast instead of a checked one. 2^128 doesn't fit in a uint128, so it wraps to 0. The most insolvent account possible reads as owing nothing and passes the free collateral check.
2
1
15
1,116
Antoine retweeted
🇫🇷 FRANCE TAX BREACH CREATES PHYSICAL SECURITY NIGHTMARE FOR BITCOIN HOLDERS France disclosed this month that hackers breached its tax administration and extracted data concerning roughly 678,000 individuals and businesses. The stolen data reportedly includes names, addresses, income and property information. An analysis of the alleged database found 26,805 records with income above €100K, including 386 above €1M. The implications for Bitcoin holders are particularly concerning. France accounted for 33 of the 52 verified crypto wrench attacks worldwide in H1 2026, according to CertiK. French prosecutors have also accused a tax employee of using government databases to identify crypto investors and sell personal information to criminals involved in physical attacks and extortion. No physical attack has been publicly linked to the latest breach. But sensitive financial and location data on hundreds of thousands of people is now potentially outside the government’s control.
41
99
429
59,123
Antoine retweeted
🟥 URGENT: Critical vulnerability in Core Lightning Blockstream developers urge users to shut down CLN Lightning nodes right NOW! Please let everyone know!
166
782
1,979
441,398
A governance exploit impacted Term vaults after an attacker cheaply acquired majority voting power in Term's sparsely-held DAO token, passed malicious proposals, and drained $8M including 2,843 ETH and 1.7M USDC.
#PeckShieldAlert @term_labs was exploited for ~$8.5M due to a governance exploit impacting Term vaults. The exploiter has drained ~2,843 $ETH ($6.87M) & 1.68M USDC ($1.68M) - which has already been swapped for ~1.68M $DAI The exploiter originally funded with 2 ETH from #TornadoCash.
1
2
176
This tar extraction opens the box ! 😂
CVE-2026-74764 Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive mem… cve.org/CVERecord?id=CVE-202…
1
2
170
If you're honest, why are you writing "I respect the rules." ❓
1
1
200