Felch
1.2K posts

Felch
@FelchM5779
product manager @ https://t.co/zfiTPJYj5M | helping brands turn Reddit convos into an ROI machine

When we evaluated agentic web search providers, it was clear that the best solution wasn't just the fastest, or the cheapest. It's a balance of token use, total trajectory latency, and net new information that language models don't already know. Congrats to @p0 on a solid product and some awesome technology.


Starcloud CEO @PhilipJohnston joins @itsmoislam and I at the NYSE. "In order to make data centers in space work, you really need the BOM costs for a 200 kW satellite to be on the order of 1 million dollars." We chat: - Building low cost sats - 20 yr terrestrial vs. 5 yr space - Merge with a launch company? - Does Starcloud exist if Earth's bottlenecks vanish? - Better leader: Altman or Dario - Building sats cheaper than Starlink - GPU failure rate

I had the pleasure to sit down with @MartinShkreli A truly formidable young man We didn’t talk about pharma We talked about cookie banners (& his favorite rules in prison) Also spoke about his new venture: Godel He agreed to let me invest €100 (pending regulatory approval)

The KelpDAO exploit (~$290M, is NOT a LayerZero protocol bug. It's a configuration issue and a case study every project with a cross-chain token needs to look at today. KelpDAO shipped their rsETH OFT with a 1/1 DVN security stack. One required verifier. Zero optional. Threshold 0. Straight from LayerZero Scan's ReceiverOAppConfig on the rsETH bridge pathway: • requiredDVNCount: 1 • requiredDVNNames: [LayerZero Labs] • optionalDVNCount: 0 • optionalDVNThreshold: 0 Source and Destination OApp both labeled "Kelp DAO." Destination is the rsETH OFT Adapter on Ethereum: 0x85d456B2DfF1fd8245387C0BfB64Dfb700e98Ef3. How the attack worked: the forged message's source packet was never actually emitted on the source chain (Unichain). The single required DVN signed an attestation for something that didn't exist and because it was the ONLY required DVN, there was no independent verifier to contradict it. Everything downstream then executed exactly as designed: commitVerification → lzReceive → peer check → OFT decode → rsETH mint. The contracts weren't broken. The verification layer was. One signature and 116,500 rsETH materialized out of thin air on Ethereum. To be clear: LayerZero V2 is modular by design. Apps pick their own security stack X-of-Y-of-N, multiple independent DVNs, thresholds, block confirmations. No one is forced into any configuration. The protocol gave projects the full toolkit. KelpDAO chose 1/1. Even reputable DVNs can have a bad day key compromise, infra failure, bad actor, whatever. That's exactly why you want multiple independent verifiers. Redundancy is the whole point. A 1/1 DVN is the cross-chain equivalent of a 1-of-1 multisig on a treasury. Baseline for any OFT/OApp with serious TVL: • Multiple required DVNs (3–4+) • Independent providers (don't stack correlated risk) use canary DVN as it’s also its own independent client. • Optional DVNs + threshold on top • Sane block confirmations If you're a founder or dev with an OFT live in production, pull your Send/Receive ULN config today. Call getConfig() on the endpoint. If requiredDVNCount is 1 and optionalDVNCount is 0, reconfigure before the market does it for you. Anyone can verify any OApp's config on layerzeroscan.com right now. Security is the application's responsibility. LayerZero hands every project a powerful, modular security stack it's on the project to actually use it. Kelp's full RCA is still coming, but the root enabler is already onchain and visible to anyone who looks. Check your configs. Stay safe out there.



We're discussing all things Hyperliquid this Friday. If you're active in the ecosystem, you're invited. We'll be giving away challenge accounts and points. Set your reminders below.

If you want to stand out, just do the old fashioned things well: - Be on time - Be well read - Practice good posture - Look people in the eye - Do what you say you'll do - Have a confident handshake Few live up to this standard. It will never go out of style.







'How can it be that wherever you look, you find empty homes and buildings? Why is there no national drive to harness their potential? Incredibly, there is no obligation for Government or local authorities to step in.. @emptyhomes estimate the number is closer to 1.5 million'

Today we're launching Era and announcing $11M in funding. We're building the intelligence layer for a new ecosystem of AI devices — the platform that lets any device manufacturer, brand, designer, or creator make objects that think, respond, and act in their own style. We're entering a Cambrian explosion — new form factors, new creators, new objects worth desiring. Made by people who've never had the tools to make them, before today. Welcome to the new Era. Backed by @AbstractVC, @BoxGroup, @topology_vc, @betaworks, @CollaborativeFund, @MozillaVentures, and @AIResidency.




