Eric
535 posts




welp, it happened. @owockibot's hot wallet private key was compromised after only 5 days alive. luckily, funds are SAFE. @owockibot's treasury / signing keys are stored in a safe that requires me to sign. what happened? it was given these instructions to never share it... but it still did! from my investigations, it put the key into git commits (which it swears it didnt push!), vercel env variables (which it swears it doesnt remember doing!), and it looks like it got social engineering attacked through X and telegram (though it swears it didnt share secrets w attacker!). what did i learn? 1. investigations with an agent mediating are hard. i've found my agent is not a *reliable narrator* during the investigations. sometimes it forgets things, contradicts itself - esp between context windows. it may even be covering for itself, i cant know for sure. 2. if you expose your agent to the internet, and give it secrets, you cannot be 100% sure it wont leak them. 3. its still gonna be useful for @owockibot to do small txns itself. i am going to be coming up with a way to let it do txns via @MetaMask UI for now. but if anyone is building an agentic wallet hit me up i want to try it out. 4. the @owockibot traction towards the @swarmwealth vision is still going strong. this was a minor setback.














