HASHRATE

13.6K posts

HASHRATE banner
HASHRATE

HASHRATE

@Hashratebtc

Bullder - Bitcoin | Lightning | Bitcoin class of 2140

Luis Alves Se unió Temmuz 2015
5.2K Siguiendo1.4K Seguidores
HASHRATE
HASHRATE@Hashratebtc·
@TROPACRYPTO Cara ethereum fez isso em 2016 com DAO hack. Esse tabu já foi quebrado kkkkk o problema é quando fizerem isso com BTC
Português
0
0
2
178
ATROPA CRYPTO
ATROPA CRYPTO@TROPACRYPTO·
A Arbitrum acabou de roubar $71M de volta da Coreia do Norte. A comunidade tá aplaudindo. Mas eu tenho uma pergunta que ninguém tá fazendo...
ATROPA CRYPTO tweet media
Português
11
0
20
2.6K
ASV
ASV@aldovieira1971·
@leonardoscaburi Perdi de realizar lucro nos 126 K por causa dos gurus que ficaram dizendo que ia até 150K l. Parei de tentar acertar onde vai parar ou até onde vai descer. Agora, é só shortando e fazendo parcial, de grão em grão. Já fiz uma merreca até os 77. Se cair, compro de novo.
Português
3
0
1
169
Leonardo Scaburi Reinol
Leonardo Scaburi Reinol@leonardoscaburi·
Quem está certo? Augusto comentou no meu post anterior que o fundo foi 60k e vai para 92k e eu estou achando que é armadilha e mais uma bandeira de baixa. Como o meu índice de acerto está na casa dos 97.6%, acredito que eu esteja certo dessa mais uma vez.
Leonardo Scaburi Reinol tweet media
Português
54
1
71
5.7K
BowTiedMara
BowTiedMara@BowTiedMara·
@RodrigKildysart Sotaque rioplatense é a música mais linda que pode ouvir nessa vida.
Português
4
0
4
3.2K
BowTiedMara
BowTiedMara@BowTiedMara·
Brazilians thought the Argentine lawyer arrested in Rio for “racism” would face public backlash here in Argentina. Instead she became a celebrity and is already doing TikTok restaurant commercials 😂
English
1.1K
246
4.9K
2.3M
Pedro Soyer
Pedro Soyer@PedroSoyer_·
@jsmello_89 @fernandoulrich pois bem, a única função do dinheiro é ser um meio de troca (as outras ''funções'' são meramente acidentais).
Português
3
0
0
156
Fernando Ulrich
Fernando Ulrich@fernandoulrich·
Irã vai exigir pagamento em bitcoin no pedágio de passagem pelo Estreito de Ormuz. De acordo com o Financial Times: "Hamid Hosseini, porta-voz do Sindicato dos Exportadores de Petróleo, Gás e Produtos Petroquímicos’ do Irã, disse ao FT na quarta-feira que o Irã queria cobrar taxas de pedágio de qualquer petroleiro que passasse e avaliar cada navio. “Assim que o e-mail chegar e o Irã concluir sua avaliação, os navios terão alguns segundos para pagar em bitcoin, garantindo que não possam ser rastreados ou confiscados devido a sanções”, acrescentou Hosseini." Quando o dólar é usado como arma geopolítica, o bitcoin é usado como arma de defesa.
Português
89
92
1.3K
77K
HASHRATE retuiteado
Feross
Feross@feross·
🤨 People keep asking how to protect yourself. #1: set min-release-age=7 in .npmrc #2: install Socket for GitHub (it's free!) to protect PRs from bad dependencies: socket.dev/features/github #3: install Socket Firewall (also free!) to protect your laptop: socket.dev/features/firew…
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
58
288
2.4K
342.6K
HASHRATE
HASHRATE@Hashratebtc·
Todo dia isso agora pqp
klöss@kloss_xyz

do you understand what just happened to one of the most used npm packages on the internet? → axios gets downloaded over 100 million times a week and today it got compromised → an attacker hijacked the npm credentials of a lead axios maintainer… changed the account email to an anonymous ProtonMail address… and manually published two poisoned versions → axios@1.14.1 and axios@0.30.4… neither version contains a single line of malicious code inside axios itself. instead they inject a fake dependency called plain-crypto-js that drops a remote access trojan on your machine → the fake dependency was staged 18 hours in advance… three separate payloads were pre-built for macOS, Windows, and Linux… both release branches were hit within 39 minutes. every trace was designed to self-destruct after execution too → there’s no tag in the axios GitHub repo for 1.14.1. it was published outside the normal release process entirely... bypassed CI/CD completely → StepSecurity called it one of the most operationally sophisticated supply chain attacks ever against a top 10 npm package → a routine npm install silently opens a backdoor… no warning… no suspicious code visible in axios itself this is the wake up call all vibe coding bros need to hear right now: → if you installed either version… assume your system is compromised → pin to axios@1.14.0 or axios@0.30.3 → rotate all secrets, API keys, SSH keys, and credentials on affected machines → check network logs for C2 connections → add –ignore-scripts to CI npm installs going forward 100 million weekly downloads and one compromised maintainer account… that’s all it took to wreak absolute havoc and I imagine we see a whole lot more of these… crazy times ahead for cybersecurity and vibe coding be safe out there y’all

Português
0
0
0
69
Anonymous
Anonymous@YourAnonNews·
Director of the FBI, Kash Petel's account hacked. Video leaked online. What does that say about the ability of the current FBI director to not click on phishing emails.
English
1.9K
4.8K
19.3K
2.4M
HASHRATE retuiteado
Andrej Karpathy
Andrej Karpathy@karpathy·
Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
Daniel Hnyk@hnykda

LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below

English
1.4K
5.4K
28K
66.5M
madu
madu@eduardalobatoo·
tô testando o cartão da @amuletslabs aqui no paraguay e tô gostando demais - compras em USD sem spread - sem IOF - sem reporte pede KYC mínimo por conta da bandeira do cartão (VISA) pode usar passaporte pra fazer eu uso com minha cédula paraguaia
madu tweet media
Português
6
2
51
8.9K
Rafaela Romano
Rafaela Romano@hi_disruptivas·
Uma coisa que acho MUITO estranha, quando em um restaurante tem um casal que NÃO conversa. Faz 30 minutos que o casal do meu lado NÃO FALA NADA um com o outro. To quase indo lá sugerir um assunto de tanto constrangimento 😳 Como pode uma coisa dessas????
Português
81
1
207
25.2K
Cururu
Cururu@cururu_azul·
@Samuelsworld A Itália deveria fazer um programa para emigração massiva de argentinos e brasileiros descendentes de italianos. São culturalmente próximos no idioma e na religião. Mas avisem os italianos que se precisarem imigrar em massa para cá novamente, vamos recebê-los.
Português
6
0
10
1.7K
HASHRATE
HASHRATE@Hashratebtc·
@peppipets É só morar lá uai para de drama
Português
0
0
0
110
Raul Sena
Raul Sena@oraulsena·
Consegue citar algum serviço descentralizado e com muita qualidade?
Português
232
2
347
66.2K
The Notorious J.O.V.
The Notorious J.O.V.@whotfisjovana·
there are cathedrals everywhere for those with eyes to see them
English
12
284
5.4K
138.7K
𝕏 Pikapika
𝕏 Pikapika@Pikachunoku·
@R38TAO Erro. Pegaram de algum manual de transferência de BTC e esqueceram de trocar o exemplo do manual pela chave correta.
Português
5
1
108
13.4K
Renato 38 r38tao
Renato 38 r38tao@R38TAO·
Alguém mandou 2.56 BTC para Satoshi no primeiro endereço usado no BTC: 1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa Por que alguém faria uma doação dessas? O primeiro endereço a receber saldos em BTC tem os 50 BTC (não gastáveis do primeiro bloco minerado) e já tem 107 BTC de saldo (57 BTC de envios posteriores).
Renato 38 r38tao tweet mediaRenato 38 r38tao tweet mediaRenato 38 r38tao tweet media
Português
71
20
733
102.6K
HASHRATE retuiteado
AMBOSS ⚡
AMBOSS ⚡@ambosstech·
ANNOUNCING RailsX: The most powerful tool for financial access, advancing Bitcoin's core principles of sovereignty and decentralization. RailsX empowers peer-to-peer (P2P) trading with Lightning, enabling KYC-free, trading P2P in self-custody. Lightning is a now a DEX. ⚡️🧵
GIF
English
14
58
213
46.8K