𝐖𝐨𝐫𝐤𝐢𝐧𝐠 𝐨𝐧 𝐰𝐡𝐚𝐭'𝐬 𝐧𝐞𝐱𝐭. ꟼGꟼ: 063E 966C 93AB 4356 492F E032 7C3B 4B4B 7725 111F

w021d
We, the Ethereum Cypherpunks, act on principles. We fucking care about privacy. We fucking care about security. We fucking care about censorship resistance. And we will always fucking defend these core principles. I wrote the Ethereum Cypherpunk Manifesto because this shit matters. If you're butthurt, go touch some grass and get a reality check. We, the Ethereum Cypherpunks, stand united in our pursuit of a more private, secure, and censorship-resistant future. Like it or not. hackmd.io/@pcaversaccio/the-…
What Ethereum needs is a lot of young blood who shared the cypherpunk vision. All OGs are jaded. It’s on the next generation now.
385
514
2,734
701,536
lol nah, privacy is _not_ dead, we've just built the wrong defaults so far. any kind of privacy must be part of the _runtime_ (can be an execution layer, can be a browser, etc.), not something users have to configure. that's why i've been saying for years: we must ship _L1 enshrined unconditional_ privacy. if the default tx is private by default, you scale privacy and you win. i won't stop until i can replace my xmr txs with eth txs. build the right system defaults, and you win. ethereum enshrined privacy will win.
the main thing i think about is how dead privacy is from here on forward
36
34
257
13,732
sudo rm -rf --no-preserve-root / retweeted
636606729769440499166579950236036751749912014371509557713570027508971809534551913252252094954941974952859310861988904737359709200557919 is a factor of RSA-896 saweis.net/posts/rsa-896.htm…
225
990
9,510
3,901,384
if you're building a self-custodial _software_ wallet, add _max_ friction to creating hot wallets & push users toward hardware wallets. idgaf if it hurts onboarding. your main job is keeping users' funds safe and in a world full of malware, making hot wallets the easy default is fucking _reckless_.
29
10
109
12,470
so remember when certain DPRK groups stored their C2 infra details (often base64-encoded & XOR-encrypted) in smart contracts? it was called EtherHiding. well, our PolinRider "friends" (and other groups) have gotten a bit more "creative". they now use a new pattern called "NullReceiver": simply put, they send a zero-value tx with zero calldata, while hiding the C2 IP address directly in the `to` address lol. let's take real-world example: - tx hash: `0x910d35c6620bea357c867bd93b291dc6feb1990bb57a0a063fa652cd29d096b2` - `to` address: `0xa658863ea658863e68656c6c6f6970626f742121` this will lead to - a658863e -> 166[.]88[.]134[.]62 - a658863e -> repetition of the above IP - the rest (68656c6c6f6970626f742121) is some string "helloipbot!!"
20
39
350
23,641
sudo rm -rf --no-preserve-root / retweeted
Vyper is taking part in @thedaofund’s ETHSecurity Initiatives to fund the full formal verification of the compiler. Help us build a future where every smart contract can be proven correct, all the way down to bytecode! Donate!
Onchain security is everyone’s problem and nobody’s job. ETHSecurity Initiatives is how we are changing that. Propose the work. Fund the work. Build the work. initiatives.thedao.fund/
1
8
28
15,182
sudo rm -rf --no-preserve-root / retweeted
Onchain security is everyone’s problem and nobody’s job. ETHSecurity Initiatives is how we are changing that. Propose the work. Fund the work. Build the work. initiatives.thedao.fund/
40
109
392
195,133
KYC = Kill Your Customer
‼️ BREAKING: Revolut handed over customers’ passport copies, verification selfies and full transaction histories to a malicious actor. The actor sent lawful government information-demand emails using a genuine government domain that passed domain authentication. Revolut later concluded they were not authentic. Affected customers were notified on Friday. What may have been disclosed ranges from name, date of birth and home address to account statements, withdrawal records and complete Bitcoin transaction history. The company says it has alerted the agency to the unauthorised mailbox on its domain, blocked the address and begun notifying regulators. It has not named the agency, explained how someone obtained a mailbox there, or given a number of affected customers. ZachXBT, who circulated the notices, believes the incident was limited in size and aimed at high-net-worth users.
11
54
434
23,963
so some "good" news - the malicious (i.e. the current ui deployment steals notes) tornado[.]cash domain is now finally on "clientHold" status; in simple terms the registrar (TLD Registrar Solutions Ltd.) has told the registry (Binky Moon, LLC) _not_ to publish/activate the domain's dns. so i sincerely hope this will prevent further losses and my personal wish is that the domain can be returned eventually to Roman (after expiration).
5
6
58
7,994
hmmmm
ok wtf is going on - 10mins after my first tweet ICANN changed the status again to "active". this is gonna be an interesting Friday.
2
950
ok wtf is going on - 10mins after my first tweet ICANN changed the status again to "active". this is gonna be an interesting Friday.
so some "good" news - the malicious (i.e. the current ui deployment steals notes) tornado[.]cash domain is now finally on "clientHold" status; in simple terms the registrar (TLD Registrar Solutions Ltd.) has told the registry (Binky Moon, LLC) _not_ to publish/activate the domain's dns. so i sincerely hope this will prevent further losses and my personal wish is that the domain can be returned eventually to Roman (after expiration).
6
20
5,131
sudo rm -rf --no-preserve-root / retweeted
Replying to @MetaMask
i'm so happy you have time for corporate rebranding bullshit while your product(s) suck ass; says a lot about priorities
10
3
213
11,493
it's great seeing blockstream following the standard security practice so white hats can easily reach out, well guess, nooooot looool
3,400 BTC just returned to the liquid federation. Looks like ~600 BTC stayed behind.
5
1
42
5,927
how it should look like
1
10
1,081
sudo rm -rf --no-preserve-root / retweeted
i keep repeating myself: fake identities (incl. burner addresses) is what protects you from retarded govs & corps.
Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought. Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed. All affected customers have been emailed directly. If you didn’t receive an email, then you are not affected. Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems. Trezor systems were not compromised, and your device is secure. But please be alert for fake emails, phone calls, fraudulent letters, and potential risks to physical security. NEVER share your wallet backup with anyone or type it into a website. We’re terribly sorry to everyone affected. We take this matter very seriously and are working to ship anonymous delivery ASAP, so you can protect your personal information when placing an order. For more information, visit our blog: trezor.io/blog/news/recent-c…
7
18
237
14,336
i believe long-term any hard-fork-related client (el & cl) changes must be formally verified. i asked this q yesterday in the Eth R&D discord server and already got some valuable feedback. pls share your feedback, ideas, past experiences, and thoughts on how we can get there on the new thread created here: ethresear.ch/t/formal-verifi… ultimately, before an upgrade goes live, we should be able to provide a mathematical proof that its implementation correctly realises the _specified_ (this is part of the convo btw, _what_ spec) state transition and consensus rules. look, code can fail, processes can fail, and people can make mistakes. math gives us a stronger foundation for securing what we do on ethereum.
6
5
57
4,273
sudo rm -rf --no-preserve-root / retweeted
One thing before I start: everything in this post is public information from my own docket. None of it is new, and I'm not revealing anything you can't already find in the court filings yourself. The retrial just got pushed to April 26, 2027. The order came down today (Dkt. 300). My acquittal motion is still sitting there, undecided. I honestly don't know when this ends. Prosecutors are supposed to protect American interests and go after people who broke the law. A jury deadlocked on the two most serious counts against me. And still SDNY won't stop, because this case was never just about me. It's about setting an example. Don't take my word for it. Tara La Morte, the chief of SDNY's Illicit Finance and Money Laundering Unit, said it herself at a New York City Bar Association event (Law360, Feb. 23, 2024; filed on my docket as Doc. 25-2): "We want the industry to take notice." "What we're trying to do is sort of bring the industry into compliance, and I think Tornado Cash is an example of that." An example. Out of a developer who wrote code. At that same event, her deputy praised the government's blockchain-tracing partner, Chainalysis. Here is what they didn't tell the audience. All of it is from the public docket in my case. According to the trial transcripts, Chainalysis was running its OWN Tornado Cash relayer, and earning fees on the transactions flowing through it. - Chainalysis's own lawyers admitted to "a relayer node that Chainalysis operated"; my subpoena sought documents on Tornado Cash relayer(s) "used from March to August 2022." (Dkt. 211) - In open court, the prosecutor said it plainly: "I think the parties agree as to that part of the testimony, that the Chainalysis relayer earned fees." Same hearing: "there's zero evidence that the defendant was in any way aware that Chainalysis was running a relayer." (Dkt. 259, July 25, 2025) So the company that helped trace my "criminal" transactions was itself profiting from Tornado Cash transactions, while I was prosecuted over software I helped create. And when my lawyers subpoenaed them to testify? - Chainalysis moved to quash. (Dkt. 211) - The government backed them: "Your Honor, we agree with the position outlined in the motion." (Dkt. 255) - The night before, prosecutors called Chainalysis's counsel. The judge asked point-blank: "Did you let them know that they were potentially subject to investigation or prosecution?" The answer: "We have discussed at a high level some of the issues surrounding the relayer with Chainalysis." (Dkt. 259) - The Chainalysis witness took the Fifth. My lawyers learned about that call only afterward, from Chainalysis's own lawyer. (Dkt. 263) The jury never heard any of it. This spring, at the Bitcoin 2026 conference in Las Vegas, something happened that I still can't quite believe. The Acting Attorney General, Todd Blanche, and the FBI Director, Kash Patel, sat on a panel called "Code is Free Speech." Think about that. The two top law enforcement officials in the country. Blanche told thousands of developers: if you're a coder and you're not the one committing the crime, "you are not going to be investigated and not going to be charged." He said the last administration's crypto cases were "outrageous attacks on the industry." Patel praised "the Chainalysises of the world" as FBI partners. And when the moderator pointed at the elephant in the room, my case, Tornado Cash, Roman Storm, the Acting Attorney General called it a "lingering case" they are "continuing to deal with." So here is my hypothetical question. If code is free speech, why am I still being prosecuted for writing it? And if the Chainalysises of the world are the partners, the same Chainalysis that ran its own Tornado Cash relayer and earned fees from Tornado Cash users, while I never did, why is it off the hook? They made an example out of a developer for writing code. Their own vendor ran the same infrastructure, pocketed the fees, and got a phone call instead of a prosecution. Sources 👇👇👇
73
422
1,686
391,062
the ultimate end goal of ethereum must be to give every individual the ability to become _ungovernable_.
31
37
290
12,352
i keep repeating myself: no governance is best governance
Defimon detected an exploit on Term Finance @term_labs that drained ~$8.5M on Ethereum Attacker cheaply acquired a majority of a sparsely-held DAO governance token, then passed malicious proposals to seize control of Term's vaults. Tx #1: etherscan.io/tx/0xd354a15b15… Tx #2: etherscan.io/tx/0x9f273f9a5a… Attackers: etherscan.io/address/0xa908b… etherscan.io/address/0x68645…
8
2
77
7,781