Eric Hegnes

40 posts

Eric Hegnes banner
Eric Hegnes

Eric Hegnes

@0xHEGNES

fp proselytizer ∘ bare-metal enjoyer ∘ 3-coloring expert Software Engineer @union_build

Katılım Nisan 2025
23 Takip Edilen582 Takipçiler
Eric Hegnes
Eric Hegnes@0xHEGNES·
Every Christmas we get each other ornaments. This year, I got a whaleshark. 0____0
Eric Hegnes tweet media
English
1
0
8
986
cor
cor@corcoder·
If you are serious about secure TypeScript dependency management (you should be!) then use PNPM. It is the best in terms of workspace dependency management. PNPM accurately simulates a true content-addressed directed acyclic graph, preventing doppelganger attacks. (1/3)
English
19
2
87
7K
cor
cor@corcoder·
Union is NOT at risk from the massive industry-wide NPM supply chain attack. We use @nixos_org for fully reproducible builds. This means that we know byte-for-byte exactly what will be included in our builds. The Nix level sha256 of our NPM dependencies has not been altered in the past 5 days, which predates the date of the attack. Even if you built our app after the malicious packages were published, you would not be compromised. In addition to Nix, we also pin all (transitive) workspace dependencies in a pnpm-lock.yaml. Just to be sure, we also analyzed that lockfile to ensure that it does not include any compromised packages. After thorough analysis we confirm that at no point in time compromised packages were included in Union's builds. However, when interacting with Union's services, you are likely using a wallet. For this, I echo @P3b7_ 's recommendation: If you use a hardware wallet, pay attention to every transaction before signing and you're safe. If you don’t use a hardware wallet, refrain from making any on-chain transactions for now. This is an ongoing situation which we will continue to monitor closely. Stay vigilant.
Charles Guillemet@P3b7_

🚨 There’s a large-scale supply chain attack in progress: the NPM account of a reputable developer has been compromised. The affected packages have already been downloaded over 1 billion times, meaning the entire JavaScript ecosystem may be at risk. The malicious payload works by silently swapping crypto addresses on the fly to steal funds. If you use a hardware wallet, pay attention to every transaction before signing and you're safe. If you don’t use a hardware wallet, refrain from making any on-chain transactions for now. It’s still unclear whether the attacker is also stealing seeds from software wallets directly at this stage. Excellent report here: jdstaerk.substack.com/p/we-just-foun…

English
122
17
212
35K
Eric Hegnes retweetledi
Union
Union@union_build·
The day is here. The wait is over. It's time. The future of zk interop has arrived. Union mainnet is live 🔥
English
648
178
978
533.1K
Arnab D. Saha
Arnab D. Saha@TheArnabSaha·
What package manager do you use ? 1. npm 2. pnpm 3. yarn 4. bun
English
441
8
664
53.1K
Eric Hegnes retweetledi
Union
Union@union_build·
Union is adding support for @base 🟦 Access the Base onchain economy with Union 🧵
English
1K
432
2.4K
196.7K
Eric Hegnes
Eric Hegnes@0xHEGNES·
@syaifudin_kingQ @luknyb There is already search for asset on the bottom right 🔍. We will add search for chain in the future.
Eric Hegnes tweet media
English
2
0
6
152
Eric Hegnes retweetledi
cor
cor@corcoder·
App V4 is now live! It is a complete rewrite of the TypeScript SDK and transfer submission flow by @0xHEGNES . Way faster and more stable. This also fully integrates BTC edition into the app, getting us ready for public mainnet. Most importantly: it prepares for U
Union@union_build

App v3 and the BTC App are no more. There is only App v4. Testnet and mainnet transfers in a single app, plus all the preparations needed for Union's public mainnet.

English
382
107
791
56K
Eric Hegnes retweetledi
cor
cor@corcoder·
- 49.458 LoC - 331 files - 5 codeowners - 1 poem zkgm @0xHEGNES
cor tweet media
English
193
26
413
17.1K
cor
cor@corcoder·
zkgm TokenOrderV2 ngmi if you are not Inspectable and Pipeable
cor tweet media
English
204
28
454
36.1K
cor
cor@corcoder·
@Nifaribs imagine claiming to be heterosexual while composing functions
cor tweet media
English
9
0
8
945