Cofounder & CEO @FoundationHQ. Building Human Authority Hardware for Bitcoin and agentic computing. Mechanical engineer, MBA dropout. Also tweets about health.

Boston, MA
Foundation was using Gusto and Deel, really did not like the experience, @warpdotco has been awesome.
We’ve raised $85M for this moment. Introducing Warp 2.0: The first AI Head of HR. Every company is building AI to replace jobs. Warp is building AI to do the jobs no human should have to: If you work in HR, I want you to spend time with the manager who needs help or building company culture people actually want to work at. If you’re a founder, I want you to focus on signing clients or spending time with your family. You shouldn’t have to figure out how to register state tax in California. You shouldn’t have to pay outrageous penalties because you don't know what a DE 9C is. I want to make HR human again. Today, this is finally possible with the Warp Agent. I’d love for you to see it in action: warp.co/agent
3
1
10
1,068
Zach Herbert 🇺🇸 retweeted
Your login codes shouldn't have to live on your phone. Passport Prime keeps your 2FA codes offline, on dedicated hardware you control. With KeyOS 1.4.0, there are more ways to bring your existing accounts across, including bulk imports from Google, Aegis and Proton Authenticator. Import your accounts, then generate the codes you need directly on Passport Prime, without an internet connection. Your email, work accounts and digital identity deserve protection, too.
1
4
19
1,290
This is why smartphones and computers can never serve as a root of trust for AI security & human authority. Tens of millions of lines of code. No formal verification. Each time a frontier model is released, it will be whack-a-mole to fix newfound vulnerabilities.
Urgent security advisory for iOS users! Install the latest iOS update immediately. Security researchers report that financially motivated attackers are now using a complete, in-the-wild exploit chain that can quietly steal cryptocurrency private keys and mnemonic seed phrases from iPhones. The reported attack begins when a target is socially engineered into opening a malicious page in Safari. That page is said to abuse a memory-corruption flaw in WebKit / JavaScriptCore to gain arbitrary read/write access from JavaScript, then bypass Pointer Authentication Codes (PAC) to run native code, break out of the WebContent sandbox, and escalate to kernel/root privileges. With that access, attackers can pull data from the device Keychain and from local crypto wallet apps. The claimed impact range is iOS 13 through iOS 26.5; that range has not been independently confirmed in full. Until more is known, treat any unpatched device as potentially exposed and update as soon as a newer build is available. Also avoid untrusted links in Safari, especially if you keep wallet keys or seed phrases on the phone.
3
3
28
3,745
Zach Herbert 🇺🇸 retweeted
Verify v1.0 is now available for Passport Prime. Check SHA-256/SHA-512 hashes and OpenPGP release signatures fully offline before using a download. Open source and ready to install on any Passport Prime running KeyOS v1.4 WHAT WILL YOU BUILD? foundation.xyz/app-showcase/…
2
11
55
1,975
Zach Herbert 🇺🇸 retweeted
Envoy v2.3.4 is now available for download. This maintenance release includes bug fixes and reliability improvements for Tor, Magic Backup and Passport Prime updates. Full release notes below👇
3
4
27
2,044
Zach Herbert 🇺🇸 retweeted
It's time for a new foundation. Not a new start. Legacy Mode is live on Passport, keep every account you already have, on code anyone can inspect. Switch to open source hardware and software while keeping your existing accounts for supported assets. Here’s how. 🧵
13
18
99
22,184
Ledger users: it's time to switch to open source. Introducing Legacy Mode by @FoundationHQ
8
8
61
8,858
If anyone guesses what we are announcing tomorrow I will send you a complimentary Passport Prime by @FoundationHQ!
Switch to open source. It's time for a new foundation. 09.15 | 10AM ET foundation.xyz/switch
59
5
61
10,554
It pains me to see a large percent of all Bitcoin & digital assets stored on closed source hardware. Tomorrow we are making it easier than ever to switch to open source.
Switch to open source. It's time for a new foundation. 09.15 | 10AM ET foundation.xyz/switch
4
5
86
6,134
Zach Herbert 🇺🇸 retweeted
New hardware for the PocketJS lab: a beautifully compact Passport Prime, kindly sponsored by @FoundationHQ. Thanks @OwenKemeys for making it happen! We love bringing PocketJS to new kinds of hardware. Hardware makers, feel free to reach out 😛
4
9
163
10,083
Zach Herbert 🇺🇸 retweeted
I'm really digging my new Passport Prime from @FoundationHQ .
4
3
22
4,972
Zach Herbert 🇺🇸 retweeted
I'm disgusted by many of the replies. People saying "code is law, so it's fair game to steal 600 bitcoin" are amoral weirdos. If their home had a lock w/ buggy firmware that allowed thieves to loot it, then the thieves returned some of their possessions after they begged, but kept a lot of their property, I bet your ass these goofballs wouldn't be like "Hurr derr, code is law, so it's my fault thugs used a code bug to get into my house and steal my stuff. They aren't criminals, they're 'whitehats' I must respect and thank for returning some of my things after I begged them". Get the f*ck out of here, you spineless, morally bankrupt goofballs. Thieves deserve to be hunted, beaten, and made an example of, not lauded as noble actors.
To those responsible for the theft of bitcoin from the Liquid Network: Blockstream will not pay a ransom for the return of stolen funds. Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft. We have engaged in good faith in an effort to secure the return of stolen user funds and protect the broader Bitcoin community. That effort should not be mistaken for acceptance of the actions taken nor of the terms being demanded. We will not be a party to the precedent that open-source software developed for the good of the Bitcoin community should subject its developers to paying a ransom that far exceeds their economic participation. Bitcoin is hard money and can’t be minted without costs, Bitcoin doesn’t haircut users to pay a ransom. To the Bitcoin community: We are fighting for what we believe in, for the users whose funds were taken, and for the principles on which Bitcoin was built. The community has demonstrated incredible resolve with teams of people dedicating their time in support of each other to identify and patch vulnerabilities in each other's products and systems. We are all driven by the mission that Bitcoin is the single best asset, for every person, company, and institution on the planet to invest, use, and build on. The world is a different place with the advancements of AI, and the Bitcoin community has responded with force to combat that threat. Damage has been done, battles have been lost, but on the whole the Bitcoin community is gaining ground in the war with bad actors. We want to thank the community for those efforts, for your support in hardening the network, helping users recover funds, and for your support in our assertion that crime does not deserve rewards. To those holding the stolen bitcoin: There is still an opportunity to resolve this responsibly. The bitcoin can be returned and we can revert to the standard of white-hat principals. However, if the funds are not returned, we will pursue every lawful avenue available to us. We will work with law enforcement, exchanges, service providers, forensic specialists, and other relevant parties to trace and recover the assets and identify those responsible. More importantly, Bitcoin is transparent by design and the community is made up of the most sophisticated engineers, cryptographers, and white-hat hackers globally. Transactions do not disappear, and neither does the evidence they leave behind. We will not pay for the return of stolen property. We will not abandon our users. The Bitcoin community will not stop pursuing the funds. Return the bitcoin.
64
8
120
13,505
Zach Herbert 🇺🇸 retweeted
Something is coming. Built for those ready to make the switch. No starting over. No looking back. September 15.
Made with AI
4
3
49
3,124
Something big coming from @FoundationHQ next week. Our stated goal since 2020 is to build the open source hardware & software foundation for the entire industry. It's time to switch.
Switch to open source. It's time for a new foundation. 09.15 | 10AM ET foundation.xyz/switch
2
1
44
2,493
Zach Herbert 🇺🇸 retweeted
Switch to open source. It's time for a new foundation. 09.15 | 10AM ET foundation.xyz/switch
7
15
67
33,584
Does this mean we will have room temperature superconductors by Sunday?
Replying to @anabology
you know what let's try
7
1,445
Zach Herbert 🇺🇸 retweeted
As AI changes the speed and accessibility of vulnerability research, responsible disclosure has never been more important. We’re working alongside researchers and other industry leaders to support coordinated disclosure, responsible communication, and sufficient time for vulnerabilities to be fixed before they are made public. 🤝 Protecting users must remain the priority.
📌 AI made finding bugs cheap, but it didn’t make responsible disclosure optional. Finding and exploiting vulnerabilities has never been easier. A few hours of prompting now does what used to take a skilled researcher weeks. Unfortunately, defenders no longer enjoy the asymmetry they relied on. Security is still a cat-and-mouse game, but with many more cats, the user suffers. Which is exactly why the process around disclosure matters more than ever. How it works, and it is not complicated: ➤ A researcher finds a bug and contacts the vendor privately. ➤ The vendor reproduces, acknowledges, and both sides agree on a timeline. 90 days is the common default, more or less depending on severity, capacity to fix... ➤ During that window both sides keep it secret while the vendor fixes and ships. ➤ Once users are protected, both sides publish. The ecosystem learns. The researcher usually gets paid. The issue now is the barrier is so low that anyone can surface a finding with no security background, and some skip straight to the audience: ❗Presenting a reproduction of an already-fixed bug as a live compromise. ❗Full disclosure of a bug that is not fixed yet. ❗"Critical vulnerability found" teasers, dripping details for engagement. Call it what it is: attention farming with someone else's risk. When the bug sits between a user and their funds, this is reckless. Especially in crypto, where there is no chargeback. But the damage doesn't require live funds to be at stake. Manufactured panic causes harm of its own, because it drives people away from self-custody, and that damages the whole ecosystem. So I have three asks: 1️⃣ For users: software and hardware have bugs, always. The single most effective thing you can do is stay updated and follow basic security hygiene. That has never mattered more than today. The time between releases and malicious actors exploiting the vulnerabilities have shrunk dramatically due to LLMs and that one can't afford to be passive and postpone security updates any more 2️⃣ For new researchers with a fresh model and a real, validated finding: welcome, we need you. Use the vendor's disclosure process. That is not bureaucracy. It is the difference between making the ecosystem safer and putting users in the crosshairs for a few likes. Remember that security communication must be accurate and proportionate. State the severity, affected versions, and fix status in the first sentence, not the tenth. 3️⃣ And to everyone building in this industry, vendors and researchers alike: let's make coordinated disclosure the norm we defend out loud, not the fine print. Reward the researchers who do it right. Refuse to amplify the ones who trade user safety for reach. This is how we win, together. Some of the actors already support the initiative. @Ledger @Trezor @FoundationHQ @AnchorWatch @_SEAL_Org and others Spread the message.
3
4
32
4,581
This is 95% of all Bitcoin on Liquid
It looks like ~4,000 BTC just moved from the Liquid Network bridge all at once with an OP Return saying, "we are whitehats. contact us on chain". TXID: c103de95817b43f2df635ec6f35ff126ca26a7c6d20570c4b01866b2b3e69a19
19
18
247
24,799
Zach Herbert 🇺🇸 retweeted
In case you missed how thoroughly open source Passport Prime is, here's a link to the machining drawing of the chassis for no reason github.com/Foundation-Device…
Replying to @FoundationHQ
KeyOS was built to be a platform. You can now sideload third-party apps directly from Settings > Apps. The new Allowed Publishers model lets you choose who to trust, with control over permissions for sensitive operations.
2
4
27
5,714
Apps have finally arrived to KeyOS! Our biggest release yet.
KeyOS 1.4.0 is now available for Passport Prime! This major release brings a redesigned launcher, third-party app sideloading, new wallet connections, easier 2FA imports and extensive security hardening. We recommend updating promptly. 🧵
5
4
42
4,119