Trying to turn Web3 into a better place for everyone, every day Head of marketing at @ambire To be cringe is to be free

Why do wallets need a token? This last week Metamask teased finally releasing a token, Rabby followed ( $RABBY), Rainbow joined suggesting $RNBW, and the debate quickly emerged: why would a wallet need a token at all? At the most basic level, a wallet token is a way to share success with the community that sustains it. Wallets have straightforward revenue models: swap fees and convenience fees. Introduce a token, and that revenue can flow back to users through mechanisms such as buybacks, followed by redistributions or burns. The more the wallet is used, the more value accrues to its believers. But the purpose extends beyond revenue. If Web3 is about aligning incentives and distributing power, then governance should be central. Just as $AAVE and $UNI give communities a voice in steering the two biggest protocols, wallet tokens can allow users to decide the direction of the very gateways they rely on daily. There is also the competitive reality. In a crowded market, tokens function as onboarding tools. Incentives and airdrops can capture initial attention, and if the product delivers on UX, they convert newcomers into long-term loyalists. Of course, launching a token is a heavy responsibility. It forces teams to manage new layers of complexity, from treasury design to regulatory navigation. Yet that very responsibility benefits end users: it provides another lens through which to evaluate a project’s maturity, transparency, and long-term commitment. While larger wallets still hesitate, @ambire embraced the model from day one. The $WALLET token is an active governance token with roughly a hundred community voters participating in governance votes every month. It is value sharing, with 65 million $WALLET tokens (6.5% of supply) already bought back from fees and treasury. It is an acquisition engine, distributed to users through Ambire Rewards. What others only hint at, Ambire has executed in full view. Wallet tokens, done right, are not value extraction mechanisms, but the natural evolution of Web3 wallets, aligning incentives, decentralizing control, and turning products into ecosystems.
5
6
49
10,252
vanzoo retweeted
being on 𝕏 all day gives you the most broken view of reality lol. spend 10 minutes on here and you'd think: > AGI is so close > RSI has been achieved > robots are going to kill us all > TPUs are going to space > Opus 5.5 is the best model ever > Astra is insane > Jev is replacing half your LLM calls > some new model is about to end civilization then you go outside... and people are like: "wait, ChatGPT can code?" the difference between AI Twitter and the actual world is hilarious.
189
189
2,914
89,093
You only live once, meat proxy
1
5
221
I compared the swapping experience across x* number of wallet extensions Starting with the following 6 wallets: @ambire @MetaMask @Rabby_io @TrustWallet @Uniswap @WalletChan_ More will be added over time, suggestions are welcome! But only extensions, I will do one for mobile wallets at a later stage.
3
6
18
1,192
New Black Mirror episode is out
Pay with Smile - by @Revolut 😀🚀
2
81
vanzoo retweeted
"People aren't ready, this is gonna change everything" You know what people weren't ready for? Fucking mammoths. Tigers eating them. Monkeys ripping their arms off. The black plague. The ice age. Smallpox. Vikings pulling up on the beach. Drinking water that gives you diarrhea until you die. Getting a scratch and losing your whole leg. The Mongols. The Spanish Inquisition. One volcano can send us back to the dark ages and these safety guys are gonna be shocked. Oh the robots didn't kill us? It was a volcano? Imagine their disappointment as the hot ash rains down on them. A solar flare is gonna explode your phone in your pocket your legs are gonna be covered in battery acid and your bank account will stop working. You're afraid of a computer program doing math? "Things are moving too fast" homie you live on a rock that periodically deletes everything. You are one the most luckiest entities in a 100 light year radius living during a golden era. Cheer up. My ancestors crossed an ocean in a wooden box because they ran out of fucking potatoes. "The social disruption will be enormous!" Nigga World War 2? World War 2? Hop in the people carrier we're landing on the beach. Are these people out of their fucking minds? Do they not know what we've survived already? A couple decades of air conditioning and people suddenly think oh this is the natural condition of mankind. No. We used to have eight kids because seven didn't make it. You're gonna be fine. Man the fuck up. Accelerate.
955
3,056
21,257
896,158
Psst kids, want some @ambire ? Find me at @ETHSofiaBG and I might give you an unlock code for the Ambire mobile app
3
6
29
1,052
wouldn’t be surprised
Rumor has it that when @cinesiusss is away, this account is managed by a group of raccoons who respect your privacy and deeply care about your security.
1
7
251
Remember anon
1
37
Gotta admit that @beehiiv 's clanker feature inside the website builder is absolutely amazing. Been trying the drag-n-drop builder for two days and saw that they have a chat. I thought it'd be a gimmicky wrapper, but it actually works very good. Not only understands the assignment, but it builds it very fast, as the builder is already very flexible.
5
2
11
299
nice argument, unfortunately i have ai generated a video of you rimming a horse
73
698
22,067
636,674
The cigarette. The music. The crowd. Everything about this video is perfect. My new favorite. A masterpiece.
大哥,你这是纯技术啊,纯手搓啊
182
2,378
27,761
2,614,041
vanzoo retweeted
TikTok launched internationally in 2017
35
150
878
57,519
vanzoo retweeted
My iPhone 13 getting ready for another year of outperforming the new £1500 phones
LFCAlex¹⁶🇧🇬
92
4,021
49,150
839,680
I'm wondering too
If you are not using ambire yet, can you please tell me why?
1
5
151
vroom vroom
Man ambire is sooooo much faster then metamask. Feels like block time is 3x faster.
2
144
vanzoo retweeted
Replying to @katexbt @hazae41
No, that’s FUD. Ambire engineer here - let me explain. Dependency count isn’t the attack surface. What each dependency is allowed to reach is the attack surface. As a side note, ~2200 figure is the size of the full installation tree (all yarn.lock resolutions including devDeps and build tooling), while the actual production JS bundle of the browser extension ships about ~300 unique npm packages. But on topic - I have three deep-dive tweets on how we manage supply chain attack risk with these packages in @ambire: 1) With SES, which freezes JavaScript’s shared built-ins, so no package can monkey-patch fetch or the prototypes nitter.net/0xSuperKalo/status/209… 2) With LavaMoat (@MetaMask’s tooling) that gives every package a policy - only the globals, builtins and packages it actually needs. Everything else is undefined to it nitter.net/0xSuperKalo/status/209… 3) With "allow-scripts" config that denies install scripts by default, so nothing runs on npm install nitter.net/0xSuperKalo/status/209… As an example from our real prod bundle, only 2 of the ~2200 packages you mention we have - can even touch the chrome extension APIs, and 0 can eval. Your AI summary is hallucination due to lack of actual context and code I guess. Ask your AI to reevaluate by taking a look at the real code and configuration of our extension open source repo github.com/AmbireTech/extens… If someone compromises one of those small, deep, low-profile packages - we have multiple supply chain gates that would prevent an attack. With these guards, @MetaMask and us are way ahead of the average wallet (or a JS app).
You can sandbox every dependency at runtime and still get owned before your app even starts 👀 One more on supply-chain security, after the SES and LavaMoat posts. Those lock down what a package can do while your app runs - but there's an earlier, quieter attack surface they don't touch: install time 👇 `npm install` doesn't just copy files. Any package can declare a postinstall script - arbitrary code that runs automatically the moment you install, on your laptop or your CI, with your full shell access. It's a legit feature (native modules compile this way), which is exactly why it's such a clean attack: no app code required, and nobody's watching. Shai-Hulud is what that looks like in the wild. Sept 2025, a self-replicating npm worm: 1⃣ a postinstall hook pulled an obfuscated script that ran on dev machines and CI 2⃣ it scanned for npm, GitHub and cloud credentials - env vars, cloud metadata, even TruffleHog to sniff out secrets 3⃣ it exfiltrated them, committing to a public GitHub repo under your own account 4⃣ then it used the stolen npm tokens to republish itself into your other packages No human operator in the loop. 500+ package versions in a few days. The fix is unglamorous and it works: deny all install scripts by default, then allowlist the handful that genuinely need one - a native module that has to compile, a build tool like Sentry's CLI. Everything else: no. That's what @MetaMask's allow-scripts does, and it drops in a fail-safe so the protection can't silently get removed later. Pair it with an age-gate on your lockfile - don't auto-pull versions published in the last couple of days - and freshly poisoned releases like these don't reach you in the first place. A day of work, and a whole class of attack is gone 🛡️
5
2
34
820
Yesterday I saw this poor ragged fox on the streets Today I turned it into a @ChatGPT pet 🤷‍♂️
5
316
Rare (from me) crypto merch shoutout goes to @0xprivacypools Privacy is normal
2
3
16
376
🫡
Every day I see people asking @Ambire for stuff. Every day, @Ambire ships. This team has a better relationship with their users than I have with my GF.
8
264