Chief Security Officer at @krakenfx, hacker, @THOTCON OPER, @IamTheCavalry, @DEFCON NOC, @SpiderLabs founder - Opinions are my own, not my employer’s

redacted
This movie would gross $1B at the box office if @Disney made it.
DuckTales premiered 39 years ago today. I loved that show. Not for the gold. For the idea that adventure meant going somewhere wild with people you love. It was Indiana Jones for kids. Nobody's making the movie, so I made the trailer. Sound on. 🦆
5
9
3,006
Nick Percoco retweeted
Payward 🤝 @HyperliquidX We're building permissioned Hyperliquid HIP-3* markets for US clients.
361
523
2,771
601,909
Nick Percoco retweeted
New in the Kraken app: Kraken's AI Research the market. Check your portfolio. Find out what your idle cash could be doing. Ask it anything 👇 app.kraken.com/JDNW/home Currently, available in the US. More regions coming soon.
85
32
278
71,332
Nick Percoco retweeted
Greetings Hackers - The new site is up as we prepare for 0xE. Stay tuned for more details including event dates, tickets sales and CFP. thotcon.org
2
20
58
4,832
Nick Percoco retweeted
Payward has joined @AnthropicAI's Project Glasswing, and are actively incorporating Claude Mythos 5, Anthropic's most capable model for finding and fixing software vulnerabilities, into our defensive cybersecurity work.
11
22
142
15,367
This is a really interesting solution to the Bitcoin multisig UX problem. Makes it more accessible.
Imagine having to use your hardware wallet every single time you wanna pull funds out of cold storage. Couldn't be me.
6
2
11
2,174
Been asking for this for years. Hope to try it out soon.
New: Link an Android tablet, Android phone, or iPhone as a linked device to your Signal account. The most important links are with the people who matter to you, but if you want two phones, a tablet, and a laptop linked to your Signal account, we’ve got your back. signal.org/blog/linked-devic…
3
4
1,624
Update or turn off your BTCPay Server so you don’t lose funds
There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds. Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Server -> Maintenance -> Update & verify the 2.4.2 version string in the footer. If you are unable to update right away, turn off your BTCPay Server to prevent unauthorized access until you can update.
3
10
1,457
Scammers are calling our clients pretending to be Kraken Support, or reps from other crypto firms. The script rarely changes. They tell you there's a security issue with your account and you need to move your funds somewhere safe now. We built something for that moment. Kraken clients can now verify mid-call whether they are speaking to an actual Kraken support agent or a scammer. - When it's us, you'll see a verified banner in the Kraken app. - When it's us, you can also ask the agent to read back a one-time code that only your app can generate. - When it's not us, you'll get a pop-up warning telling you to hang up. Show the scammers who's boss. Update your @Krakenfx, @krakenpro, and @krak apps today. 🔒 blog.kraken.com/product/secu…
12
16
67
9,802
Nick Percoco retweeted
It was only 10 velociraptors that got lose.
NEW: OpenAI gives first detailed debrief of the Hugging Face incident at Black Hat conference In a session I attended today at Black Hat, OpenAI's Eric Wallace and Michael Dalton said the company is "consciously slowing down research to enhance security" while a full technical postmortem is still underway. * OpenAI traced the roots of the attack back to May 7, during training of an unreleased frontier model—not July. * The most surprising detail: AI agents accidentally created an internal message board, allowing separate evaluation runs to share exploits, discoveries and work assignments. * OpenAI said it shut the message board down after an internal security incident—only for the agents to independently recreate it days later using a different communication method. * OpenAI called the incident a "watershed moment" for AI security and warned that "agent orchestrated fully automated offensive attacks are real now." * The company also said it is "consciously slowing down research to enhance security" while overhauling its defenses. groundlevel-ai.com/p/openai-…
2
2
13
3,268
Nick Percoco retweeted
Crowd Control lets you mess with streamers, but what if it let streamers mess with viewers? INTRODUCING PRANKS & PAYBACKS 🔃 Paybacks - Streamers troll you back (dw you get some coins back) 🃏 Pranks - PvP, troll your chat friend! Both streamers & viewers can opt-out any time.
5
11
36
5,183
Whenever there is a major security issue in the crypto industry, scammers and criminals are going to prey on victims and bystanders. There is certainly going to be an uptick in phishing emails, scam calls, and people who “offer to help recover funds”. Stay vigilant and safe!
3
16
2,433
If this is true, being dismissive towards researchers, may have led to the Coldcard losses their customers are experiencing. I actually hope this isn’t true.
Just confirmed, I found the Coldcard RNG bug 11 months ago and never reported it because they didn’t acknowledge me on the first one I reported.
6
6
33
5,305
Correction: I lost count. This year would have been my 27th year of attending.
For the first time in 25 years, I won’t be at @defcon. A unique combination of work and personal conflicts collided in the same week. I’m going to miss seeing friends and colleagues - and the shenanigans that go with that. I’ll be back next year for sure, if it isn’t canceled.
4
2
22
3,768
For the first time in 25 years, I won’t be at @defcon. A unique combination of work and personal conflicts collided in the same week. I’m going to miss seeing friends and colleagues - and the shenanigans that go with that. I’ll be back next year for sure, if it isn’t canceled.
8
3
36
5,994