Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ

7.1K posts

Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ banner
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ

Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ

@CryptonautB

Blockchain Project Advisor Creative Strategist @doodles #2786 @LazyLionsNFT #39, 50, 2544, 2545 #LazyLions #ROAR ๐Ÿ‘‘๐Ÿฆ DMs Open

Metaverse ๊ฐ€์ž…์ผ Mayฤฑs 2021
3.5K ํŒ”๋กœ์ž‰5.4K ํŒ”๋กœ์›Œ
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ ๋ฆฌํŠธ์œ—ํ•จ
Keystone Hardware Wallet
Keystone Hardware Wallet@KeystoneWalletยท
๐Ÿšจ If you ran npm install in the last 24 hours, read this. Axios, the most popular JS library with 100M weekly downloads, was backdoored on npm yesterday. Versions axios@1.14.1 and axios@0.30.4 installed a RAT silently, phoned home within seconds, then deleted all evidence. Who's at risk: โ†’ Crypto devs with keys or seeds anywhere near their dev environment โ†’ AI engineers with API keys and cloud credentials in .env files โ†’ Any CI/CD pipeline that ran npm install yesterday Check now: โ†’ npm list axios | grep "1.14.1|0.30.4" โ†’ If found, rotate every secret on any affected system โ†’ Downgrade to axios@1.14.0 โ†’ Run npm ci --ignore-scripts in CI from today And the lesson that never changes: โ†’ Private keys don't belong on internet-connected machines โ†’ Cold storage exists for exactly this reason The only keys a RAT can't access are those on a hardware wallet. Stay secure ๐Ÿ”
Feross@feross

๐Ÿšจ CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: โ€ขย Deobfuscates embedded payloads and operational strings at runtime โ€ขย Dynamically loads fs, os, and execSync to evade static analysis โ€ขย Executes decoded shell commands โ€ขย Stages and copies payload files into OS temp and Windows ProgramData directories โ€ขย Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
3
6
29
4.7K
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ
@grebby @artgobblers It would be nice to see NFTs hold such a status again. I do think the inevitable future comes from a low to no entry cost into monetized ecosystems. NFTs likely will return as authentication tokens of some sort under a different name.
English
0
0
0
42
greb
greb@grebbyยท
how long do i have to wait for someone to make this happen again?
greb tweet media
English
52
2
133
6.7K
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ ๋ฆฌํŠธ์œ—ํ•จ
The Kobeissi Letter
The Kobeissi Letter@KobeissiLetterยท
At 4:11 PM ET, President Trump extended his โ€œpauseโ€ of US strikes on Iranian power plants and oil prices fell -6%. 40 minutes later, that entire decline was erased. Markets are becoming numb to the headlines.
The Kobeissi Letter tweet media
English
412
1.1K
7.2K
782K
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ ๋ฆฌํŠธ์œ—ํ•จ
Watcher.Guru
Watcher.Guru@WatcherGuruยท
JUST IN: ๐Ÿ‡บ๐Ÿ‡ธ US dollar bills to be printed with President Trump's signature, removing Treasurer signature for the first time.
Watcher.Guru tweet mediaWatcher.Guru tweet media
English
2.3K
3.1K
19K
2.4M
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ ๋ฆฌํŠธ์œ—ํ•จ
Keystone Hardware Wallet
Keystone Hardware Wallet@KeystoneWalletยท
๐Ÿ”” Attention Kaspians ๐คŠ Check out what we've built for the $KAS community ๐Ÿ‘‡ Drop your feedback below and tell your circle: "Keystone support is coming!"
Keystone Hardware Wallet tweet mediaKeystone Hardware Wallet tweet mediaKeystone Hardware Wallet tweet mediaKeystone Hardware Wallet tweet media
English
29
88
259
15.4K
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ ๋ฆฌํŠธ์œ—ํ•จ
Keystone Hardware Wallet
Keystone Hardware Wallet@KeystoneWalletยท
๐Ÿšจ Daily Security Reminders: #1: Old token approvals are STILL draining wallets - Revoke them. #2: Expired domains get snatched and injected with malware - Check your bookmarks. #3: Browser extensions get sold to scammers - Audit yours monthly. Always verify everything you sign because your wallet depends on it ๐Ÿ’ก
burn the bridge@econoalchemist

๐Ÿšจ PSA: a scammer has taken control of the samouraiwallet.com domain. Do not be fooled into downloading malicious software. How ironic that the FBI seizes control over the domain only for it to fall into the hands of actual criminals.

English
2
5
18
1.4K
REDMAGIC
REDMAGIC@redmagicgamingยท
Trace vs Prism Which REDMAGIC 11 Air are you taking?
REDMAGIC tweet mediaREDMAGIC tweet media
English
58
38
488
331.3K
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ ๋ฆฌํŠธ์œ—ํ•จ
Keystone Hardware Wallet
Keystone Hardware Wallet@KeystoneWalletยท
That $149 Keystone hardware wallet collecting dust? Useless until you actually set it up. Let's fix that today & bookmark this tweet for reference. 5 Steps to Set Up Your Keystone: 1๏ธโƒฃ Prep ๐Ÿ“ฆ Unbox, charge, grab your SD card & cable 2๏ธโƒฃ Verify โœ… Check device authenticity 3๏ธโƒฃ Update ๐Ÿ”„ Install latest firmware 4๏ธโƒฃ Create ๐Ÿ”‘ Generate seed phrase (offline only!) 5๏ธโƒฃ Connect ๐Ÿš€ Pair with your wallet app You're done. Your crypto is in your control. Security basics: Don't: - Import seed phrases from online wallets (already compromised) - Create seeds on phones or computers - Click random links or connect to sketchy dApps - Sign transactions without checking Do: - Generate seeds on hardware wallets only - Backup on stainless steel plates (paper deteriorates) - Use separate wallets for savings, DeFi & daily spending Take control. Stay secure. Sleep better. ๐Ÿ˜Œ Set it up today. It only takes 15 minutes. RT if this helped ๐Ÿ” Want a custom-designed Keystone like @FugzOfficial for your community? DM us ๐Ÿ™Œ
armosR๐Ÿ•๏ธ@armosrenatox

The custom designed @FugzOfficial X @KeystoneWallet has finally arrived, Iโ€™ve been waiting to get my hands on it ๐Ÿ™Œ I even made a completely amateur unboxing and uploaded it to YouTube you can find it at the link below ๐Ÿ‘‡ youtu.be/IZZiFVKN2j8?siโ€ฆ

English
7
10
38
2.3K
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ ๋ฆฌํŠธ์œ—ํ•จ
Keystone Hardware Wallet
Keystone Hardware Wallet@KeystoneWalletยท
Every day, users lose millions to blind-signed transactions. Asking a user to blind sign a txn is equivalent to urging them to gamble with their money. In both cases, the chance of loss is high. That's why we've always advocated against blind-signing and have been making conscious efforts to make users comfortable with txn verification and signing. Here's what sets Keystone apart: When you're making a transfer, Keystone decodes the txn and displays the details clearly: + From & To Address + Value + Nonce + Method + Calldata, etc If the contract involved is unknown or a secondary contract is involved, you can check the complete RawData ipo an incomplete call data, helping you verify everything before signing your txns. The bottom line? Signing ETH transactions on Keystone is becoming smarter and safer with clearer parsing. Big thanks to @PatrickAlphaC and everyone whose feedback guided us to do better ๐Ÿ™ Got suggestions on how we can make txn signing even safer? Drop them below ๐Ÿค
Keystone Hardware Wallet tweet mediaKeystone Hardware Wallet tweet media
Patrick Collins@PatrickAlphaC

All blockchain hardware wallets are worthless unless either: 1. You spend 20 minutes per transaction verifying your calldata 2. All hardware wallets adopt a transaction legibility standard "oh but my hardware wallet is EAL6+ rated with a secure element and a MCU made from minerals mined from pluto's ultra secure crust that-" - It doesn't matter. If you do not check calldata, you're essentially saying "I trust 100% that this website has not been hacked, because I trust whatever data they send to my wallet". It doesn't matter if your wallet is the most badass piece of security tech that's ever been, because you're letting hackers send whatever they want to your wallet, and you'll blindly sign! We've seen websites hacked all the time. @Compound_xyz was hacked just last week!! Reference: x.com/Compound_xyz/sโ€ฆ And we've seen MASSIVE losses from these hacks across both retail and enterprise use. - Bybit ($1.4B) - Radiant Capital ($50M) - WazirX ($200M) Some wallets have done a great job of getting the ball rolling on their own like @gridplus and @KeystoneWallet who both offer calldata decoding at the device level. @Ledger and @Keycard_ offer EIP-712 digests for signatures which are easier to verify than EIP-712 structs. @MetaMask snaps allow me to build my own custom AI bots and custom decoders to read calldata easier. But it's not enough. Calldata is still very annoying to read, and decoding it can be more confusing. Not enough wallets support EIP-712 digests. The good news... Is that transaction legibility is finally coming... Once we have a standard in place for human-readable transactions, it will be unacceptable to use a hardware wallet that does not have such a feature. And we can FINALLY use hardware wallets the correct way! I'M QUITE EXCITED.

English
3
7
34
2.7K
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ ๋ฆฌํŠธ์œ—ํ•จ
Keystone Hardware Wallet
Keystone Hardware Wallet@KeystoneWalletยท
๐Ÿšจ A UK man's wife just stole 2,323 Bitcoin worth $172M using their home security camera. The man claims that she used their own CCTV system to capture his 24-word recovery phrase as he typed it. One small misstep, and $172M gone forever. Your "smart" home is the dumbest place to access crypto: - Security cameras record everything - Smart TVs have built-in cameras - Alexa is always listening - Baby monitors stream 24/7 - Even your doorbell is watching You bought a hardware wallet to protect against hackers. But every IoT device in your house is a potential witness to your seed phrase. Your hardware wallet has no idea it's being watched. The 3-minute security sweep: โœ… Turn off the cameras before entering seed phrases โœ… Disable smart assistants during crypto access โœ… Use a dedicated offline room with no IoT devices โœ… Never type seeds where devices can "see" or "hear" โœ… Assume every smart device is compromised Your connected home is someone else's security camera feed. Disconnect to protect your crypto ๐Ÿ”Œ Source: @CoinDesk
Keystone Hardware Wallet tweet media
English
15
16
80
5.5K
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ ๋ฆฌํŠธ์œ—ํ•จ
Keystone Hardware Wallet
Keystone Hardware Wallet@KeystoneWalletยท
1/ Everyone declared Solana dead. Twice. From a $260 ATH to $8: blamed, buried, written off overnight. But Solana holders? They didn't flinch. Neither did we. Here's how we grew with one of crypto's most resilient communities ๐Ÿ‘‡
Keystone Hardware Wallet tweet media
English
2
3
18
7.6K
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ@CryptonautBยท
@redmagicgaming I would love a review sample to compare with my Red Magic 7. Show people that the older devices have had no issues lasting years, and compare them side by side.
English
0
0
0
118
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ ๋ฆฌํŠธ์œ—ํ•จ
REDMAGIC
REDMAGIC@redmagicgamingยท
โš ๏ธ CHALLENGER APPROACHING โš ๏ธ REDMAGIC 11 Air: TRACE Edition joins the roster with Silver chassis and Orange accents. Pre-order on March 30th.
English
17
33
272
12.5K
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ ๋ฆฌํŠธ์œ—ํ•จ
Keystone Hardware Wallet
Keystone Hardware Wallet@KeystoneWalletยท
๐Ÿšจ CRITICAL: Millions of Android phones have a processor flaw that exposes crypto keys. The MediaTek Dimensity 7300 chip was recently exposed by @DonjonLedger, revealing a critical vulnerability that enables seed phrase extraction in MINUTES. What attackers can steal with brief physical access: - Seed phrases - Private keys - Wallet PINs - Full bypass of Android secure boot This is why hot wallets aren't enough. One processor vulnerability + brief physical access = your funds are gone. Smartphones prioritize convenience over security. HOW TO STAY SAFE: โœ… Stop storing everything on hot wallets โœ… Use an air-gapped hardware wallet like Keystone โœ… Treat your phone like it's already compromised โœ… Secure elements > smartphone processors for crypto storage MediaTek patched it, but the lesson remains: your phone wasn't designed to protect crypto. Huge respect to @DonjonLedger for responsible disclosure and making the ecosystem safer ๐Ÿค TAG your friends still trusting hot wallets ๐Ÿ‘‡ RT if you value security ๐Ÿ”
Charles Guillemet@P3b7_

๐Ÿšจ @DonjonLedger has struck again discovering a MediaTek vulnerability potentially impacting millions of Android phones. Another reminder that smartphones arenโ€™t built for security. Even when powered off, user data - including pins & seeds - can be extracted in under a minute.

English
2
20
66
6.9K
Cryptonaut Bob ๐Ÿ‘‘๐Ÿฆ ๋ฆฌํŠธ์œ—ํ•จ
The Spectator Index
The Spectator Index@spectatorindexยท
BREAKING: Oil prices up 7%, with crude oil at $94 and brent crude at $99.
English
124
639
4.6K
271.7K