Hexidethmal retweeted
Replying to @dcinvestor
Wouldn’t it be cool if you could revoke all in one txn. Or if all approvals were ephemeral? Guess what EIP I’m about to shill
7
1
54
5,771
Hexidethmal retweeted
Reminder: you can now sync an ethereum node within half a day and with aggressive settings the space it takes up on disk can be under half a terabyte. EIP-4444 and hard work by client teams on optimizing snap sync has improved things *a lot*. Glamsterdam will improve the sync situation further still (eg. Nimbus's new sync protocol uses it)
120
78
719
110,499
Hexidethmal retweeted
Americans are violating the privacy rights of the government’s surveillance devices.
Flock Safety has issued a legal demand seeking the removal of a public map showing the locations of approximately 300,000 of its surveillance devices across the United States.
37
522
3,279
93,166
Hester Peirce: mass KYC collection builds honeypots that get crypto holders phished, hacked, and physically attacked. Her answer: zero-knowledge proofs - verify without exposing anyone. Meanwhile, SDNY is retrying Roman Storm in April 2027 - on the theory that he committed a crime by NOT building one of those honeypots. The government's own expert, AnChain.AI's Philip Werlau, told the jury Tornado Cash needed a "user registry": a list of authorized users, with logins "like Gmail, Spotify." On cross he admitted it "could have collected personal identifying information." When the defense asked whether hackers target exactly such databases, prosecutors objected. Sustained. The jury never heard the answer. Surveillance is privacy. Free Roman Storm. Study the case. Read the docket. See for yourself how bad this precedent is. Make some noise. This case is a threat to every developer and every user who values privacy. The more people know, the harder it is to get away with.
JUST IN: 🇺🇸 SEC Commissioner Hester Peirce calls to end mass KYC data collection, warning it puts crypto holders at risk of phishing and physical attacks. Pierce says the current KYC/AML system creates massive databases of sensitive information that can be hacked, leaked, or exploited. She's pushing for zero-knowledge proofs (ZK proofs) that could verify users meet regulatory requirements without exposing their personal information.
19
71
394
24,576
Hexidethmal retweeted
Fully locally decoded @CoWSwap transaction! On PQ1, you see exactly what you are signing on Cow Swap! Plus it’s fully open source!
5
14
48
1,183
Hexidethmal retweeted
Amazing!
The first purpose-made hardware wallet to be a @safe signer! Check out this video where I show you how signing Safe txs is made secure, using local decoding and verification on the PQ1!
1
2
5
451
Hexidethmal retweeted
HABEMUS TESTNET — DAISUGI v0.1 A post-quantum Ethereum testnet using hash-based SPHINCS signatures with non-native account abstraction. Big thanks to @riva_labs and @GiulioRebuffo. Coming next: • Frame Transactions • Signature aggregation via LeanSPHINCS Believe in somETHing. Link ⬇️
27
44
245
60,233
Hexidethmal retweeted
Many claimes by L2s turned out to be false. Now we are putting privacy protocols under similar scrutiny. Just because they say they provide you with Privacy, this may mean widely different things. Don't trust, verify
Every privacy protocol says "private." But the question is: private from whom? We just shipped a new feature on L2BEAT that answers that for every protocol we track, against 5 different adversaries.
9
9
94
6,578
Hexidethmal retweeted
Cybersecurity researcher: I found that Flock did not require their clients to use multi-factor authentication. This led me to find Flock law enforcement accounts for sale by a Russian vendor on a dark web marketplace. In addition to this, we found insufficiently protected sensitive information stored on Flock cameras, including photos, license plate data, logs, API keys, passwords, and communications.
84
2,968
9,775
447,280
Hexidethmal retweeted
The first purpose-made hardware wallet to be a @safe signer! Check out this video where I show you how signing Safe txs is made secure, using local decoding and verification on the PQ1!
5
9
37
2,965
Tempo guys stay on brand
4
88
Hexidethmal retweeted
This is a pretty big deal: a new bill in Congress would let US courts order VPNs and DNS resolvers to block websites. VPNs are explicitly named in a US site-blocking bill for the first time. It’s being sold as an anti-piracy measure but once the legal machinery for blocking websites exists, the obvious question is where it goes from there. And we’ve already seen how badly this can go. Spain’s anti-piracy blocking has swept up legitimate sites along with the targets...
65
781
1,906
63,678
Hexidethmal retweeted
Amazing engineering and it has a clear purpose: scaling Ethereum without fragmentation!
Arithmetic-friendly hashes have long been one of the weakest pieces of prover cryptography. With ZisK v1.3.0, we removed Poseidon entirely and moved to BLAKE3. What surprised us is that we got the same performance — or even better. After many optimizations elsewhere in the prover, hashing had become one of the most time-consuming parts of proof generation. BLAKE3 is more than an order of magnitude faster, making this cost almost disappear and largely compensating for the increased complexity of the recursion circuit. Getting there required a lot of re-engineering: circuit sizes, prover scheduling, and architecture all had to be reconsidered around the new trade-offs that BLAKE3 gives us. The final result surprised even us. There is a lot of focus today on binary-field proving. Binary fields attack the hash-proving bottleneck from a different direction, but introduce different trade-offs when proving regular arithmetic. There is a huge amount of research happening here, and at ZisK we are following it very closely. I'm genuinely curious to see whether binary-field architectures will outperform what we can achieve with the current approach — and how long it will take. So I like to think of v1.3.0 as setting a new target. 🎯 To everyone working on binary fields — and to all of us trying to make provers faster: let's see if we can beat it :) And we still have a few optimizations in the basket.
4
11
133
7,566
Hexidethmal retweeted
First ever USDC on Base transfer using post-quantum wallet! We have a little update for PQ1, we now have the working e2e devices. Here is a little demo :)
28
19
143
29,319
Hexidethmal retweeted
Zero-day remote code execution vulnerability in iPhone Safari. Click a link, and your crypto, passwords and everything else on your iPhone are gone. Exploited in the wild by "DarkSword" malware. "The DarkSword attack program has leaked, with its core capability being: extracting forensic-level data from iOS devices via HTTP interfaces. In actual attacks, attackers can combine social engineering or watering hole attacks to lure users into falling victim, thereby stealing data from iPhone / iPad devices and uploading it to servers controlled by the attackers." Update iPhones immediately. Apple originally patched this, but rumours suggest even the latest versions are vulnerable, “pending confirmation,” across a wider range than the original 18.4–18.7 window. From a Chinese security researcher, SlowMist CISO, @im23pds nitter.net/im23pds/status/2101265…
Urgent security advisory for iOS users! Install the latest iOS update immediately. Security researchers report that financially motivated attackers are now using a complete, in-the-wild exploit chain that can quietly steal cryptocurrency private keys and mnemonic seed phrases from iPhones. The reported attack begins when a target is socially engineered into opening a malicious page in Safari. That page is said to abuse a memory-corruption flaw in WebKit / JavaScriptCore to gain arbitrary read/write access from JavaScript, then bypass Pointer Authentication Codes (PAC) to run native code, break out of the WebContent sandbox, and escalate to kernel/root privileges. With that access, attackers can pull data from the device Keychain and from local crypto wallet apps. The claimed impact range is iOS 13 through iOS 26.5; that range has not been independently confirmed in full. Until more is known, treat any unpatched device as potentially exposed and update as soon as a newer build is available. Also avoid untrusted links in Safari, especially if you keep wallet keys or seed phrases on the phone.
36
157
1,215
343,628
Hexidethmal retweeted
🔍没想到 一语言中,iOS 用户抓紧升级 黑灰产已实现: 1.点击链接提取私钥、助记词 2.用户使用Safari 访问网页,WebKit/JSC 内存损坏拿到 JS 层 read/write 3.绕过 PAC 拿到 native call 能力 4.逃出 WebContent 沙箱 5.内核提权拿root权限,拖走 Keychain + 钱包数据 🔍 受影响的版本 iOS 13至 26.5 (待定)
🔥所有用户请及时更新iOS 系统 DarkSword 攻击程序已经泄漏,其核心能力为:通过 HTTP 接口从 iOS 设备中提取取证级数据。 在实际攻击中,攻击者可结合社工或水坑攻击诱导用户中招,进而窃取 iPhone / iPad 内数据,并上传至攻击者控制的服务器。
15
42
284
166,414
1. Kevin O'Leary on Tornado Cash, Aug 2022: “It’s okay to arrest that guy. He’s messing with the primal forces of regulation.” “If we have to sacrifice him, that’s okay.” “I’m tired of this crypto cowboy crap.” The crime, in his telling: building software institutions didn’t like. 2. Kevin O'Leary on SBF, Nov 2022, after FTX collapsed and customer money vanished: Would he invest in Bankman-Fried again? “The answer would be yes.” “One of the most brilliant traders in the crypto universe.” He was a paid FTX spokesman. Deal worth about $15 million. Then he asked for a second chance for the guy who ran it.
Questioner: Would you back SBF [of FTX] again? Kevin O'Leary: "He was one of the most brilliant traders in the crypto Universe... the answer would be, yes."
7
10
89
6,475
Again, this will be official legal guidance that can be referred to in court Just a single speech from Hinman for years tied the hands and plagued Warren and Gensler’s attempt to illegally use the @SECGov to kill the industry and inhibit orderly capital formation in new markets
3
107
Hexidethmal retweeted
Important Notice We have detected abnormal asset transfers involving the DCENT App Wallet and are currently conducting an urgent investigation. Based on our initial findings, the issue appears to be limited to the DCENT App Wallet. If either of the following applies to you, we strongly recommend transferring your assets as soon as possible to a secure hardware wallet or another trusted wallet address: • You hold any assets, regardless of amount, in the DCENT App Wallet. • You use the same mnemonic phrase for both the DCENT App Wallet and a hardware wallet. ⚠️ Please be alert for scams. Do not send assets to any wallet address provided through DMs or unofficial channels, and do not click links or follow transfer instructions from unverified sources. We will provide further updates through this official account as soon as we confirm the cause, scope of impact, and necessary response measures. Official X accounts: @DCENTWALLETS @DCENTWALLETS_KR @DCENTWALLETS_JP Customer Support: dcentwallet.zendesk.com/hc/e…
155
271
635
347,048