🎙️ High-signal Web3 Spaces - Tue 1PM 🧠 200–300 avg listeners, 1K+ peaks | Since 2023 💼 Book guests/sponsors: xspaces@dbcrypt0.com

Everywhere 👀
🔒 12,000+ tuned in to hear founders tackle one of Web3’s biggest threats: Security 🎙️ This is xSpaces — real builders, real talk. ✅ Live every Tue + Fri @ 1PM EST 💼 Sponsors & guests: xspaces@dbcrypt0.com 🎧 Listen + follow if you value real Web3 talk.
5
4
19
4,492
xSpaces retweeted
One person saved 23k NFTs worth ~$6M from a hacker Great to see the NFT community show support and rally around @0xQuit But nobody's asking WHY this keeps happening The answer: EVM/ERC design flaws See you at the next one 😏
2
6
26
1,132
xSpaces retweeted
Largest NFT heist in history And your “security pros” will just tell you to revoke approvals 🤦‍♂️ Some of these so-called security pros got drained themselves too Let them lose everything and then maybe people will wake up
No idea whats going on here but I just watched this wallet drain 3832 NFTs from 100s of different wallets May be a good idea to revoke all NFT permissions if you have any valuables in your wallet Seems to be funded from a wallet possibly linked to @0xQuit so maybe a whitehat?
1
5
22
2,191
xSpaces retweeted
$100M just moved out of Bitget's cold wallet and everyone's screaming hack Except nobody bothered to check what Bitget launched this morning Users started reporting blocked withdrawals and on-chain watchers clocked nine figures leaving a Bitget cold wallet Then CT does what it does best… BeInCrypto broke it but notice they never used the word hacked Their exact wording was that something unusual appears to be happening Now the part nobody's checking Bitget went live on Sygnum Protect today Off-exchange custody where institutional clients hold collateral in a Swiss regulated bank instead of on Bitget's balance sheet Migrating client collateral off your books into a third-party custodian That's a nine-figure cold wallet transfer and on a block explorer it looks identical to theft That doesn't clear them though The withdrawal complaints are real and Bitget hasn't explained them But the two things that would confirm a hack are both missing No security firm has traced funds to an unlabeled wallet and no proof-of-reserves gap has been published Exchange runs start with a screenshot and a guess Wait for the tracing 🤨
2
4
38
5,290
xSpaces retweeted
This is why crypto isn’t ready for mass adoption… So that recruiter who emailed you about your dream job? They could be a North Korean hacker And 7,000 people just learned this the hard way Japan's NPA, the FBI, and German intelligence all dropped the same warning today The operation they're hunting goes by WaterPlum Here's the playbook they ran for seven months: 1️⃣ Pose as a tech recruiter for real company and real role 2️⃣ Set up an interview and they are friendly and professional so you’d take the call 3️⃣ Send a "technical assessment" and ask you to run it at home 4️⃣ You run it and malware lands and credentials gone The damage: 30,000+ devices infected 7,000 crypto accounts drained $10.7M stolen 100+ countries Honestly the $10.7M is boring though because we see that every single day The reach is what should worry everyone 30,000 machines across 100 countries and every single entry point was someone wanting a job We audit contracts for weeks We argue about decentralization Meanwhile the real attack surface is a dev unzipping a file from a recruiter who seemed nice Moral of the story? Crypto is never going mainstream if we don’t tighten security measures across all surfaces The threat of losing everything didn’t exist until we started making money digital
3
4
27
2,474
xSpaces retweeted
Supernova just went LIVE 4 shards running 600ms blocks ~200ms finality The performance is actually insane Find me one chain that outperforms @MultiversX right now. I'll wait.
13
80
319
7,778
xSpaces retweeted
Three stickers this summer were minted exactly once. • Holofoil Color Shift Zoo-F-O Friends. • Holofoil Color Shift Flea "Lucky!" from @Claynosaurz Pioneer Edition. • Neon Toggle Double Trouble from @quirkiesnft Chapter I. All 1-of-1s and none of them are listed. 👀
4
25
1,117
xSpaces retweeted
One satoshi just minted 40.65 Bitcoin out of thin air on @nomicbtc Worst part is the exploit ran for 74 days before anyone noticed 🤯 And your bridge balance might be next Here's what actually happened: Nomic's ibc_deliver handler called mint twice on a single deposit First mint got burned like it should have so all good Second got credited to the destination account as spendable nBTC Problem is nothing checked who was being credited… 40.65060238 nBTC 25 IBC packets one block total fee: 1 satoshi Now look at the date on that block The mint landed June 25th at 21:49:59 UTC, Nomic block 33,137,470. @osmosis froze the pool September 7th 74 days of counterfeit Bitcoin sitting inside Alloyed BTC! Fake nBTC in and real backing out We’ve seen this movie before 😏 Then Axelar and SquidRouter, Noble and CCTP, out to Ethereum, into roughly 671 ETH, straight into Tornado Cash Where that leaves everyone else: 110.57 allBTC in circulation Around 70.73 BTC actually behind it 63.97% backed Depositors will probably be made whole which is good But it took an independent researcher publishing a block height before anyone started counting Every one of those 74 days, somebody deposited real Bitcoin into a pool that was already short This is the future of finance 🙄
8
8
40
3,475
xSpaces retweeted
L2s aren't parasitic? September 3rd: Robinhood Chain fees: $4.5M Arbitrum's cut: $450K Ethereum gets: $398 11,400 to 1 ratio That's the Ultra Sound Money thesis in action 🫠
6
2
46
2,502
xSpaces retweeted
🚨 $319M just left Blockstream's Liquid peg and the only explanation is an OP_RETURN message saying "we are whitehats" 🤯 No statement from Blockstream No explanation from the functionaries Just a note on chain Liquid's federation wallet held roughly 4,200 BTC for months One peg-out moved close to 4,000 of it A follow-up transaction spent about 3,998.5 BTC and carried the whitehat message TXID: c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19 Blockstream's own Liquid explorer now reads 207.275 BTC 🤯 Liquid isn't supposed to work like this To get real bitcoin out, LBTC gets destroyed on the sidechain first Then the functionaries process the withdrawal Mainchain funds require an 11-of-15 federation multisig The Peg-out Authorization Key system restricts payments to approved member wallets only So either 11 of 15 functionaries signed this off, or the whitelist built to prevent exactly this didn't hold Neither answer makes Liquid look good The coins aren't running and they're just sitting on Bitcoin and haven't been mixed That's more consistent with a whitehat extraction than a theft But hours in, Blockstream, Liquid and Adam Back have all said nothing The whole pitch for a federated sidechain was that you don't have to trust any single party We got 15 of them, and we're still reading OP_RETURN messages to find out where $319M went 🤨 Still unconfirmed so let’s see how this plays out…
6
6
48
4,079
xSpaces retweeted
Ten wallets control most of the voting power in 39 of the 48 biggest Ethereum DAOs Convex holds 53% of Curve's governance Aura holds 65% of Balancer's And the average DAO has only 21% of its supply registered to vote at all So where is the D in these DAOs? 🤨
1
2
36
1,399
xSpaces retweeted
The biggest upgrade in MultiversX history drops in 6 days Sub-second finality averaging under 250ms Making it one of the most decentralized and scalable chains in existence And soon? The fastest too 🚀
The Supernova release is out. Validators, please prepare your machines. Activation on September 10.
3
52
222
5,230
xSpaces retweeted
Robinhood Chain just went dark for 14 minutes today No blocks No transactions 2 million tokenized stock holders frozen out And the status page still said operational Tokens couldn't move Contracts couldn't execute Transactions just piled up against the same block number while the entire chain sat dead Cause? Not disclosed Incident notice? Nothing posted in seven days Here's why it happened: The chain runs on a single sequencer 😏 One machine orders every transaction so when it stops, there's no fallback No second validator and nothing to catch it L2BEAT ranks it below Stage 0, their lowest decentralization tier 😂 Partly for that single point of failure but also because the contracts can be upgraded instantly with no delay That’s a MASSIVE reg flag Now look at what's riding on it… Tokenized stockholders doubled from 1 million to 2 million in August and Robinhood Chain leads that entire market This is the infrastructure they're selling to move equities and ETFs onchain Your actual broker has circuit breakers and backups Probably even a phone number that answers when things break Two months after launch, this one couldn't even update its status page Nobody lost money today but they're pitching this as the future of stock settlement And the future went dark for 14 minutes on a Friday morning 🤨
32
31
161
16,802
xSpaces retweeted
Solid start But this L1 is still absurdly undervalued Plenty of room left to run
20
71
323
7,609
xSpaces retweeted
A dead oracle just drained $4.88M from Injective 🫠 Not a sophisticated hack Not a zero-day exploit Just a deactivated price feed that someone forgot to unregister The oracle was called Frontrunner Deactivated months ago Data source emptied Still registered on-chain Still callable by anyone Here's how that became $4.88M: 1️⃣ Attacker spins up 299 binary options markets, all pointed at the dead oracle 2️⃣ No price comes back, so the "no-price refund" path fires 3️⃣ Refund math pays out roughly double what it should 4️⃣ Run it 299 times USDC out, swapped into 1,979.8 ETH, parked in an Ethereum wallet that has never sent a transaction Then Injective stopped producing blocks for 3 hours and 42 minutes On-chain researcher Rarma clocked the halt from block 181,027,006 to 181,027,007 QuickNode's status logs confirm it too Then an emergency patch was deployed, the chain came back online, and there is no rollback The shortfall is apparently covered by the insurance fund No governance vote No post-mortem No word on what the patch actually changed Crazy part is that official accounts kept posting promo content the entire time🤨 And it wasn't the only chain that went dark Ontology paused its mainnet in the same window, before it had even confirmed anything was wrong Since then it confirmed malicious activity and is still down for an emergency upgrade How many chains does that make that have been just switched off this past month now? 🤔 Just another day in the Wild West of Web3
15
19
131
10,461
xSpaces retweeted
Cronos just proved why invitation-only validators are a scam dressed up as security At 14:38 UTC today, the entire network went dark Every user Every app Blocks stopped One lending protocol got hit and 33 hand-picked operators made a call and everyone was shut out Here's what actually happened: @TectonicFi got exploited @CronosNetwork posted: "We identified an exploit in Tectonic. The Cronos Network has been halted and we'll provide updates here." That's the entire statement… No dollar figure No attack vector No restart window Then @TectonicFi followed up telling users not to interact until they confirm it's safe So how does one app shut down an entire L1? Their own docs spell it out Cronos EVM runs proof-of-authority with roughly 33 validators But those validator slots are invitation only and applications are not open So basically 33 hand-picked operators with a group chat consensus mechanism Tectonic held about $121.9M TVL as of Aug 26 per DefiLlama, ranking 22nd among lending protocols CRO was near $0.058 at ~$2.79B market cap when blocks stopped Loss estimates range from $10M to $120M+ but nothing confirmed since neither team has given a number Now to be fair the halt probably saved money When someone's draining a lending market live, killing block production is the fastest move you have But you can't market a permissionless chain and then run the emergency stop out of a group chat Every Cronos user who never touched Tectonic just had their funds frozen by a decision they didn't vote on and can't appeal Nobody put that in the pitch deck I bet
20
16
102
10,928
xSpaces retweeted
🚨 UPDATE: Only a few Singles Packs are left of @quirkiesnft Chapter 1 Gold, Silver and Bronze Packs are officially SOLD OUT. Collect the last few Grails and Holofoils at Digitoys.io
3
14
33
1,576
xSpaces retweeted
~90ms average finality This is what best-in-class tech actually looks like Only on @MultiversX
Guess what's back. See the tech. Taste the tech. telemetry.multiversx.com/
9
68
276
10,179
xSpaces retweeted
17 days out from the biggest upgrade MultiversX has ever seen Supernova drops Sept 10th Same hardware but 10x faster and infinitely scalable This changes everything
3
37
171
5,578
xSpaces retweeted
329 trillion SAND minted in 5 hours @TheSandboxGame called it "minimal” and Korean exchanges shut down before Sandbox even noticed 🤨 Here's exactly what went down: 23:42 UTC: Attacker takes over @LayerZero_Core delegate permissions on Base through approveAndCall The printer goes live 329.24 trillion SAND 703 separate mint events 173 addresses $49 billion face value created from nothing 04:45 UTC: It stops after 5 hours and 3 minutes of unauthorized minting… 05:09 UTC: The multisig finally responds 24 minutes after the attacker was already done Upbit and Bithumb halted trading well before Sandbox halted the attacker 🤦‍♂️ Then comes their official statement: "Less than 0.01% of total SAND token supply." Technically true but what a joke The real damage? $665K drained from the Ethereum OFT adapter So the honest version reads: We lost $665K and printed 73,600x that in counterfeit tokens while nobody was watching The financial outcome was survivable but the 5 hours it took to notice were not It gets worse too This is the third LayerZero OFT delegate hijack of 2026 KelpDAO in April: $292M face value StakeDAO in May: 5.4 trillion vsdCRV Sandbox now: 329 trillion SAND Same attack surface Same "trillions minted, pennies stolen" headline Same brush off Sandbox still hasn't explained how the delegate got compromised too Three protocols hit by the identical failure mode in 5 months and the response is a percentage engineered to sound like a rounding error How many times does the same attack have to work before we stop calling it minimal? Fix the delegate model or stop pretending the number is small!
5
6
23
2,601