Philip Martin

209 posts

Philip Martin

Philip Martin

@SecurityGuyPhil

CSO @ Coinbase. Army Veteran. Maker of delicious smoked meats and baked goods.

San Francisco, CA Beigetreten Ekim 2014
330 Folgt5.9K Follower
Philip Martin
Philip Martin@SecurityGuyPhil·
The latest quantum papers from Google and Caltech are an important signal for the industry. Timelines are still debated, but the time to act is now. The good news: post-quantum cryptography exists. This is a solvable problem, and many chains already have roadmaps. Bitcoin needs to catch up though. The bad news: post-quantum cryptography is relatively new and it would be fairly easy to create new security risks if implementation is rushed. The industry needs to align on what happens to wallets that fail to migrate before a CRQC appears. At Coinbase, we’ve been working on this for a while, auditing and upgrading our internal infrastructure, researching post-quantum cryptography and establishing a Quantum Advisory Council. It’s clear Bitcoin needs to make some fast progress here, so Coinbase is taking the role of rallying the troops and getting the right people in the room - Bitcoin core devs and the broader community - so they can start tackling this. But no one developer or company can do this alone. Real progress will require coordinated action across the ecosystem. If you’re working on post-quantum approaches for Bitcoin, we want to support you, and connect you with others that are working on it too. Please DM me directly and I’ll get you added to the working group. Bitcoin can and will upgrade, but it will take the entire community working together.
English
41
46
425
366.3K
Philip Martin
Philip Martin@SecurityGuyPhil·
Thanks for flagging. I can confirm this is an isolated issue due to a change we made with one of our corporate DEX wallets, which led to unauthorized transfers. No customer funds were impacted. We’re revoking token allowances and are moving funds to a new corporate wallet. Big thanks to members of the security community who jumped in to offer a hand.
English
5
2
38
3.1K
deebeez
deebeez@deeberiroz·
Looks like @coinbase was recently drained of ~$300,000 after using @0xProject swapper incorrectly. They approved all the tokens accrued as fees to their router, getting drained immediately by MEV bots 🧵
deebeez tweet media
English
69
59
596
103.4K
Philip Martin
Philip Martin@SecurityGuyPhil·
Thanks for flagging. I can confirm this is an isolated issue due to a change we made with one of our corporate DEX wallets, which led to unauthorized transfers. No customer funds were impacted. We’re revoking token allowances and are moving funds to a new corporate wallet. Big thanks to members of the security community who jumped in to offer a hand.
English
1
0
2
353
Michael D. Sproto - Classic
Michael D. Sproto - Classic@solumsursum·
@coinbase was just hacked The shadowy supercode coomers added vapid scamcoin USELESS to their roadmap and are ignoring the People’s $BITCOIN Dump all $COIN stock, $BRETT, $ZORA, and any other Coinbase/Base adjacent assets at risk of contagion as they are at risk of facing VIOLENT sell pressure and cascading liquidations. The safest thing to do right now is to go ALL-IN on the People’s $BITCOIN ASAP! #HarryPotterObamaSonic10inu
English
2
0
3
1.7K
Philip Martin
Philip Martin@SecurityGuyPhil·
@zachxbt Thanks for the thread, I know you’ve chatted with the team some already and we’re looking forward to engaging more with you and anyone else seeking to make crypto safer for all.
English
4
0
8
435
ZachXBT
ZachXBT@zachxbt·
1/ Over the past few months I imagine you have seen many Coinbase users complain on X about their accounts suddenly being restricted. This is the result of aggressive risk models and Coinbase’s failure to stop its users losing $300M+ per year to social engineering scams.
ZachXBT tweet mediaZachXBT tweet media
English
559
1.3K
9.3K
2.4M
Philip Martin retweetet
Charles Henderson
Charles Henderson@angus_tx·
My team is hiring! I’ve just opened 8 new roles, including for application security testers and red teaming & adversary emulation. If you have a passion for securing the world’s most important organizations and want to be a part of a team with amazing culture, great benefits, and opportunity for growth, here is the link to apply: jobs.lever.co/coalfire?depar…
English
11
43
95
25.4K
Philip Martin
Philip Martin@SecurityGuyPhil·
Scams are a scourge, and education is one of the most important tools we have. Maybe *you* already know everything there is to know about scams, but do your friends and family? My ask: share this video with at least one person in your life that might be vulnerable.
Coinbase 🛡️@coinbase

We’re proud to announce the Tech Against Scams coalition. Scams are a tech-wide issue and require an industry-wide response. Together with industry leaders, we're committed to protecting and educating users. Learn More→ coinbase.com/blog/announcin…

English
11
5
29
5.3K
Philip Martin
Philip Martin@SecurityGuyPhil·
hey @GaryGensler and @SECGov, serious offer: as a crypto exchange we've had a lot of experience with security protocols around social media, and as a veteran and patriot I love to help my country. If you'd like any suggestions feel free to reach out.
U.S. Securities and Exchange Commission@SECGov

The @SECGov X account was compromised, and an unauthorized post was posted. The SEC has not approved the listing and trading of spot bitcoin exchange-traded products.

English
27
74
917
208.2K
Philip Martin
Philip Martin@SecurityGuyPhil·
Check out a new in depth look at the Euler exploit coming out of our Unit 0x team. Part one (looking at the exploit) is below, part two coming early next week! coinbase.com/blog/euler-com…
English
0
5
16
3.1K
Philip Martin
Philip Martin@SecurityGuyPhil·
@TalBeerySec @ZenGo @CoinbaseWallet Hey @TalBeerySec, I lead security at Coinbase. We appreciate security researchers from around the world working with us to keep Coinbase products and customers safe. That message doesn't reflect how we want to engage with the security research community. 1/
English
6
7
207
47K
Tal Be'ery
Tal Be'ery@TalBeerySec·
Yikes! Tomorrow @ZenGo will publish about a vulnerability we had found in @CoinbaseWallet and others. We had responsibly disclosed to CB many weeks ago, they fixed and awarded us multiple bug bounties. Today we informed them we are going to publish. This is the reaction we got:
Tal Be'ery tweet media
English
57
133
727
410.3K
Philip Martin
Philip Martin@SecurityGuyPhil·
10/ They may also cherry pick cold storage addresses and ask us to restore those if they didn’t see enough cold storage activity in a given period…but you all tend to keep us busy enough that we haven’t needed to go there.
English
0
0
12
0
Philip Martin
Philip Martin@SecurityGuyPhil·
9/ Come audit time, the auditors verify the controls are functioning as intended, verify the signed messages and review cold restores over the audit period to make sure we moved enough funds over time to provide appropriate assurance.
English
1
0
5
0
Philip Martin
Philip Martin@SecurityGuyPhil·
1/ I don't have inside knowledge of what is happening inside @binance. That said, their on-chain movement of funds for audit purposes isn’t out of the norm and @coinbase did something similar many years ago when we first started 3rd party auditor review of custodial assets. 🧵
English
4
16
134
0