Pinned Tweet
The people I know who've never been scammed in crypto all pretty much have these habits: 1. They use a separate laptop or phone to interact with crypto sites 2. They don't keep all their tokens in one wallet (or on multiple wallets with the same seedphrase) 3. They have stronger security for their most valuable wallets than their day to day trading wallets Often, that's using hardware wallets or it's multisig/MPC wallets 4. They bookmark their favorite crypto sites instead of relying on Google to find them 5. They never trust an email or DM. They go directly to the source when they need to do something, not externally presented links 6. They revoke their approvals on EVM chains using tools like Revoke Cash or Etherscan 6. They do their own research on protocols and don't blindly deposit funds into untested protocols 7. They double check the addresses they send to, and don't copy/paste wallet addresses from Blockscanners FINALLY, 8. they take their time when transacting and do it when they're at their best. They don't rush, or transact while drinking, or under the influence of drugs or when they're tired. Staying safe in crypto doesn't have to be complicated. You just have to be consistent and do what works.
67
114
742
66,551
Beau retweeted
little dry run period: nftsaresafu.xyz/ check what you have claimable. If you see anything that looks incorrect, please let me know. Will open claims based on the same snapshot after a few more QC runs. 25k NFTs so please be patient.
Claim portal is coming together and should be out within a few hours. Thank you for everybody donating through X Money. If you'd prefer to donate ETH/tokens, I spun up a dedicated address: nftsaresafu.eth In addition to the time spent and yet to spend, last night cost me $7500 in gas, so I appreciate all of the support 🫡
128
102
493
41,788
I agree that freezing stolen NFTs typically just creates a new victim (the unsuspecting buyer) But marketplaces like OS prob have little choice given liability around enabling trading stolen goods
I'm sorry But locking the NFTs after the hacker has already WETH'd all of these assets on your marketplace (or Blur)... doesn't punish the hacker That mfer already has his money I hate the locking of NFTs after the hacker has already sold them
2
20
1,630
Beau retweeted
*SEC STAFF ISSUES FAQS ON CRYPTO ASSET SECURITIES LAWS APPLICATION *SEC STAFF: TOKEN BUYBACKS ON FUNCTIONAL PROTOCOLS DO NOT CONSTITUTE MANAGERIAL EFFORTS *SEC STAFF: LIQUID STAKING TOKENS ARE DIGITAL COMMODITIES OR TOOLS, NOT SECURITIES *SEC STAFF: MAINTENANCE, ENHANCEMENTS, SYSTEM GRANTS NOT CONSIDERED ESSENTIAL MANAGERIAL EFFORTS *SEC STAFF: PROMOTING CRYPTO UTILITY WITHOUT PROFIT CLAIMS GENERALLY NOT AN INVESTMENT CONTRACT
115
252
1,667
369,627
There are also ~400 former Pudgy Penguin holding wallets that granted approvals to the exploited contracts If those wallets ever buy a Penguin again, you can bet it'll instantly be swept by scam bots. If you intend to purchase a NFT, revoke approvals first
We still have A LOT of work to do as a NFT community related to live granted approvals 5% of Pudgy Penguins holders have approvals to lending protocols and pools 8% have approvals to legacy or old smart contracts that are NOT BEING UPDATED OR SECURED 30.2% have at least 1 live approval to any smart contract Go to Revoke Cash and revoke all your NFT approvals, if you're a Pudgy holder you can also currently claim our Cold Storage SBT as a bonus. nitter.net/RevokeCash/status/1971…
10
11
77
5,455
We’re proud to announce that Pudgy Penguins is appearing in the @Walmart holiday catalog. Distributed to over 40 million people, this appearance puts Pudgy Penguins at the center of the holiday shopping season. Billions will Huddle 🐧
195
287
1,513
107,669
We still have A LOT of work to do as a NFT community related to live granted approvals 5% of Pudgy Penguins holders have approvals to lending protocols and pools 8% have approvals to legacy or old smart contracts that are NOT BEING UPDATED OR SECURED 30.2% have at least 1 live approval to any smart contract Go to Revoke Cash and revoke all your NFT approvals, if you're a Pudgy holder you can also currently claim our Cold Storage SBT as a bonus. nitter.net/RevokeCash/status/1971…
Pudgy Penguins x Revoke We've partnered with Pudgy Penguins to bring you the Cold Storage SBT. This SBT is a badge of honor for any Penguin that keeps their valuable NFTs in Cold Storage.
18
17
111
11,970
Beau retweeted
The bulk of the damage is done, but there are still assets that are vulnerable to the exploit. I'm doing what I can to sweep what's left but hundreds of scammers are also doing the same. Whether you're affected or not, if you have open approvals to the addresses below, please revoke them. The open approvals can and will be used against you if affected assets are returned to your wallet while they're still open.
REVOKE APPROVALS TO THESE ASAP: Payment Processor V2 on Ethereum: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 Payment Processor V3 on ApeChain: 0x9a1D00000000fC540e2000560054812452eB5366 use revoke.cash or similar.
136
144
675
71,785
Beau retweeted
Huge thank you to the @pudgypenguins team, specifically @beausecurity for the Cold Storage SBT last year Today’s Magic Eden / Limit Break Payment Processor V2 issue showed exactly why it mattered Old “approve for all” permissions on a 2024 marketplace contract let thousands of NFTs get moved Penguins sitting in hardware wallets with zero token approvals were never in that blast radius. That SBT wasn’t just a badge. It pushed people to actually move their NFTs off hot wallets and revoke everything. Many pudgy fam are safe because of that Appreciate the team making security part of the culture instead of an afterthought 🐧🙌
Pudgy Penguins x Revoke We've partnered with Pudgy Penguins to bring you the Cold Storage SBT. This SBT is a badge of honor for any Penguin that keeps their valuable NFTs in Cold Storage.
5
6
56
2,186
Back in March @nft_dreww and I warned about the risk of Magic Eden smart contract approvals as they began shutting down EVM ops Last night a team of the good guys led by @0xQuit proactively rescued $6 million of NFTs that were at risk due to approvals Talking about security isn’t sexy until something goes wrong. Well guess what? Something really wrong could have and did happen here. If your NFTs were rescued last night it should be a massive wake up call to improve your personal security. Go revoke those approvals, keep your long term holdings in wallets with no approvals whatsoever. When you plan to sell, move each NFT to a specific wallet dedicated for selling to separate your approvals risk from your vault And while I have your attention, hardware wallets and multisigs are still great, keep storing your seed phrases offline too. Security doesn’t need to be scary or difficult, it can be quite simple and work. You just need to own it!
I keep talking about this because it is super important If you ever sold NFTs on ETH or L2s with Magic Eden you need to revoke approvals. Specifically, if you still hold an NFT from a collection you sold on there it may be vulnerable as ME shuts down support for some products.
24
39
213
10,135
One of my wallets was on the list of potential targets of today's Magic Eden / Limit Break Hack. Thanks to @beausecurity's and @nft_dreww's reminders, I revoked old Magic Eden approvals several months ago and was therefore not affected. Even though the majority of the exploit was a whitehat rescue from @0xQuit and the NFTs will be returned once they are no longer at risk, this should be strong reminder to everyone, that safety practices are such an important part of our daily interactions in this space. Always stay safe and make sure you regularly check token approvals and revoke them.
I keep talking about this because it is super important If you ever sold NFTs on ETH or L2s with Magic Eden you need to revoke approvals. Specifically, if you still hold an NFT from a collection you sold on there it may be vulnerable as ME shuts down support for some products.
1
1
9
664
Beau retweeted
At 9AM EST today somebody abused a bug in Payment Processor V2 to steal 10 Meebits, 50 Otherdeeds, 10 WoW, and 235 Desperate Apewives. It wasn't until over 12 hours later that somebody reported it to me, and upon digging in I realized that a great many NFTs were subject to the same exploit. I got in touch with the team over at LimitBreak and they quickly paused Payment Processor V3, which was subject to the same exploit. Unfortunately, V2 was not pausable, so the only path towards protecting affected assets was to run a whitehat operation. Similarly, V3 on ApeChain is temporarily in a state where it cannot be paused, so ApeChain assets approved to V3 needed to be saved as well. All in all, we rescued 23,155 NFTs worth north of $5.7M USD. We later discovered that a similar exploit could be used in reverse to steal WETH. 660 WETH was at risk, which we unfortunately were not fast enough to recover. Apologies to those affected. Shout out to @Boomskite for flagging the initial exploit tx to me, and @coffeedev @0xjustadev and @whiteoakkong for acting quickly and assisting with the recovery. All NFTs are safely relocated. Soon, owners will be able claim them back after revoking the exploitable approvals. Addresses to revoke below.
607
577
2,815
326,542
Beau retweeted
REVOKE APPROVALS TO THESE ASAP: Payment Processor V2 on Ethereum: 0x9A1D00bEd7CD04BCDA516d721A596eb22Aac6834 Payment Processor V3 on ApeChain: 0x9a1D00000000fC540e2000560054812452eB5366 use revoke.cash or similar.
246
711
2,111
465,416
Beau retweeted
BITGET POTENTIALLY HACKED FOR OVER $100M: ONCHAIN
99
161
959
705,313
You get this DM from an X Support account, what are you doing?
22
1
36
2,334
Beau retweeted
your transparent blockchain activity is next to get doxed encrypt, shield, win
Researchers built an AI that doxes any "anonymous" reddit account in under a minutes for $2. eth zurich and anthropic published a terrifying paper proving that "practical anonymity" on the internet is officially dead. they built a fully autonomous ai pipeline that takes your pseudonymous posts, extracts your identity signals, searches the web, and figures out exactly who you are. no human investigator needed. the numbers are actually mindblowing.. - 67% of hacker news users identified correctly - when the system makes a guess, it is right 90% of the time - it even unmasked scientists whose interview transcripts were explicitly redacted for privacy the scariest part? even time doesn't protect you.. they tested users who took a full year break and changed their interests. the ai still matched their old and new profiles with 90% precision. it sees through your persona changes like they aren't even there. there is no defense against this. the agent splits the work into tiny, benign tasks like "summarizing a profile" or "ranking candidates." no api safety guardrail is going to flag it because no single step looks malicious.. every throwaway account. every "nobody will connect this to me" comment. it’s all just searchable micro-data now.
Community note
Paper shows LLM agents re-ID 67% of tested HN users (LinkedIn-linked then stripped) at 90% precision for $1-4 in minutes. Authors note these easier than typical pseudonymous accounts; lower for careful/Reddit users. Not "any" account. arxiv.org/abs/2602.16800 decrypt.co/379228/ai-can-…
80
59
547
70,384
friend of mine who only ever talks crypto with me during bull markets just told me he’s long XRP again he couldn’t believe I didn’t own any
23
53
2,286
Beau retweeted
New PFP
62
30
411
25,141
Have seen several posts about farming bot fees by launching tokens from old wallets with legit history Tbh I see 0 problem with this. The snipers and bot traders are a plague, go extract from them.
Free money alert if you ever used Farcaster (doesn't need to be an active wallet, mine sure isn't) Farcaster app -> Settings - > Advanced -> Advanced recovery options -> Show WALLET recovery phrase -> Import this into Rabby Launch a shitter on ponsfamily.com with 4% creator tax (5% total) make sure its something funny like a cat/dog, have description filled out, name, ticker, etc Collect $200-300+ Thank me later.
14
62
21,385
Beau retweeted
Could it be solana:2zMMhcVQEXDtdE6vsFS7S7D5oUodfJHE8vd1gnBouauv szn?
53
58
404
97,799
I had Muse doing a task for me and it paused because it hit a “click to prove you’re human” pop up It then asked me if I wanted it to click it myself or have it do it Of course I told it to do it Hysterically weak anti-bot measures these days
10
1
31
2,627