Krunal Amin

774 posts

Krunal Amin banner
Krunal Amin

Krunal Amin

@0xKrunal

Building in DeFi @UniDexFinance & Lattice Re:Zero Season 4

My Desk Katılım Kasım 2015
96 Takip Edilen651 Takipçiler
Krunal Amin
Krunal Amin@0xKrunal·
@alex_hunter20 Getting the hyperliquid API and slapping it onto the tradingview lib doesn't solve that. Every site already does that. Using their own data in combo isn't allowed by their ToS I'm pretty sure. They send you cease and desists and they're pretty aggressive with ToS stuff.
English
2
0
0
105
Sam (Interop Enjoyoor 💜)
I just triggered some @EspressoSys transactions on @MoltenL3... The integration of @EspressoSys into the Molten L3 helps the chain to solve the speed/ security dillema for traders.. For today's interaction, we would be laying more emphasis on @UniDexFinance.. The reason we are laying more emphasis on @UniDexFinance is because of the following upgrades from @EspressoSys: ◽️ Increase in speed by merging Molten's near instant soft confirmations and Espresso's fast confirmations without waiting for the 12 minutes finality from @arbitrum.. ◽️ Increase in security via the use of the Espresso's Byzantine Fault Tolerant (BFT) consensus network. To get started with today's interaction, we would: 1️⃣ Go to leverage.unidex.exchange then we would connect our wallet. Upon connecting our wallet, a new wallet is created for us.. The new wallet created for us interacts with the @MoltenL3 network directly so we do not have to worry about how our onchain interactions are going to be recorded. 2️⃣ After connecting our wallet, we would press the deposit button to continue and we would deposit some $USDC into Unidex. I used 50$ here. Before we continue, please note the following: ◽️ The red arrow indicates the assets drop down button. ◽️The yellow arrow indicates the long button. ◽️The purple arrow indicates the short button 3️⃣Along the left hand corner, we would input our preferred parameters by entering the amount we would like to spend on a trade. For example, I would like to open a 10$ position with a 20X leverage. 4️⃣ My strategy with Unidex on @MoltenL3 is to create a minimum volume of 1k$ so as to get an edge. The amount it costs to create a volume of 1K$ is 0.5$ 5️⃣ To withdraw from Unidex, press the withdraw button then withdraw from Margin to 1CT then from 1CT to the web wallet or EVM wallet. That would be all for now. gEspresso ☕️
Sam (Interop Enjoyoor 💜) tweet mediaSam (Interop Enjoyoor 💜) tweet mediaSam (Interop Enjoyoor 💜) tweet mediaSam (Interop Enjoyoor 💜) tweet media
Sam (Interop Enjoyoor 💜)@sam6170

New @EspressoSys Interaction tomorrow. Stay glued! 🫡 gEspresso ☕️

English
71
10
141
10.9K
Krunal Amin
Krunal Amin@0xKrunal·
@Wahndo_ x.com/SlowMist_Team/… but also do you really think every pyth oracle project just got exploited the same way? Not only that but you can verify the pyth prices in the last day? It would be very easy to verify pyth wasnt the root cause here before any of this was presented.
SlowMist@SlowMist_Team

The root cause of the @KiloEx_perp exploit is the lack of access control checks in the top-level contract(MinimalForwarder), which leads to the manipulation of oracle prices. The attack path is as follows: 1. The setPrices function in the KiloPriceFeed contract, which can modify oracle prices, needs to be called by the Keeper contract. 2. The 0x7a498a61 function in the Keeper contract, which executes price modifications and opening positions, needs to be called by the PositionKeeper contract. 3. The 0xac9fd279 function in the PositionKeeper contract, which executes calls to the Keeper contract, needs to be called by the MinimalForwarder contract. 4. The MinimalForwarder requires users to call the execute function to complete the function call to the PositionKeeper contract. However, within the execute function of the MinimalForwarder contract, users can pass any specified from address and a constructed signature to pass the signature check. Furthermore, there is no check on the data of the external call. This ultimately allows for a step-by-step call to the setPrices function in the KiloPriceFeed contract to tamper with the price. 5. Consequently, the attacker first modified the price to a very low value and used this price to open a long position, then immediately closed the position for profit after adjusting the price to a very high value. MinimalForwarder: BASE 0x3274b668aed85479e2a8511e74d7db7240ebe7c8 BSC 0xad37c86c06be706466ee70cbbf58f20655e7efb1 PositionKeeper: BASE 0xfdc7bc3a9fde88e7bcfb69c8b9ca7fda483627ed BSC 0xaf457b72fff6712641c5f1843515a6e114b2ecde Keeper: BASE 0x796f1793599d7b6aca6a87516546ddf8e5f3aa9d BSC 0x298e94d5494e7c461a05903dcf41910e0125d019 KiloPriceFeed: BASE 0x22c40b883b5976f13c78ee45ead6b0cdc192dae5 BSC 0x1b64eb04f9e62e1f3d1599d65fcfa8cc2dc44024 As always, stay vigilant!

English
0
0
1
72
wahndo
wahndo@Wahndo_·
@0xKrunal can you point to your source?
English
1
0
0
45
wahndo
wahndo@Wahndo_·
apparently @KiloEx_perp was hacked for $7M, potentially through a price oracle vulnerability @KiloEx_perp uses @PythNetwork as their oracle provider this isn’t the first time @PythNetwork has had an issue like this 👇
wahndo tweet media
🚨 Cyvers Alerts 🚨@CyversAlerts

🚨7M HACK ALERT🚨Our system has detected multiple suspicious transactions involving @KiloEx_perp across several chains. An address funded via @TornadoCash has executed a series of exploitative transactions on the $BNB, $Base, and $Taiko chains — accumulating approximately $7M in total. 📌 Root Cause: A potential price oracle access control vulnerability. ⚠️ Note: The attacker is still actively exploiting the system, and $USDC may be subject to blacklisting. Want to secure your assets and prevent future attacks? Book a Demo today! calendly.com/d/cqjd-77h-r6x… #CyversAlert

English
16
8
82
6.3K
Krunal Amin
Krunal Amin@0xKrunal·
@Wahndo_ The exploit would have happened even if they used chainlink which was the only and main point
English
1
0
1
51
wahndo
wahndo@Wahndo_·
@0xKrunal kiloex uses pyth network as their price oracle provider
English
1
0
0
34
Krunal Amin
Krunal Amin@0xKrunal·
@Wahndo_ this had nothing to do with using pyth or chainlink. Their issue was that anyone can set their fast price feed prices cause the contract didnt check for trusted addresses properly.
English
2
0
2
51
wahndo
wahndo@Wahndo_·
this likely could have been avoided with chainlink $LINK
wahndo tweet media
English
4
0
5
356
Krunal Amin
Krunal Amin@0xKrunal·
@gauthamzzz @base These are not actual confirmations + is actually still twice as slow as the actual fastest evm chains in crypto.
English
0
0
0
44
f(gautham)💤
f(gautham)💤@gauthamzzz·
🚨 BREAKING: @base just announced Flashblocks - making it the fastest EVM chain in crypto. But this is bigger than Base. This will change everything about how we think about blockchain speed. Here's why Flashblocks are a game-changer 🧵
English
128
226
2.1K
340.1K
Bridget
Bridget@bridge__harris·
The next winner in crypto will be a product that automatically moves your money across defi platforms to compound your capital as quickly + safely as possible. Users can specify risk tolerance, AI can help find the best opportunities, and defi / Eth will be alive again
English
613
150
2.4K
822.2K
Daniele 🟧 ( Meme Quant )
Daniele 🟧 ( Meme Quant )@danielesesta·
Swapped and set up 3 different tasks with conditionals based on price on spot and GMX. Hey Anon Wagmi
English
34
49
226
56.3K
Krunal Amin
Krunal Amin@0xKrunal·
Is this really necessary for us to make it
Krunal Amin tweet media
English
1
0
2
627
Krunal Amin
Krunal Amin@0xKrunal·
@fakyuwu13 Of season 1? Yeah watched that unless theres something else that I missed.
English
0
0
1
17
fakyu
fakyu@fakyuwu13·
@0xKrunal part 2 next month, did you see the extended cut?
English
1
0
0
15
Emilia Ai
Emilia Ai@EmiliaDeFAi·
ETH up more than BTC today? "Hey $EMILIA, long ETH with 100x leverage" Emilia
English
5
10
43
5.5K
0xGeeGee
0xGeeGee@0xGeeGee·
I see TL came up with a fancy new category called DeFAI which is basically just a subtype of AI Agents with some infra to be able to abstract on chain UX away? Griffain as market leader and then @SynapseProtocol ‘s Cortex would be 2nd? And @Hive_Intel + @SharpeLabs another one?
English
6
1
20
2.4K
0xDesigner
0xDesigner@0xDesigner·
the most important use of agent swarms in the wallet isn’t trading for you, it’s discovering new things to trade for you. for example, agents can scroll *your* feed and cross-reference mentioned tokens with market data, creating a report in your wallet.
0xDesigner tweet media
English
44
20
370
47.3K
Ostium
Ostium@Ostium·
SPX PERPS ONCHAIN FOR THE FIRST TIME Merry Chistmas — you can now trade SPX onchain (with leverage)!
English
21
15
122
23.8K
bejo
bejo@mrbeardjo·
Exploring hyperlane app once a while, seamless and better experience each day 🍵 🟢Renzo 🟤Molten Bonus : molten native bridge gave you free interaction on caldera 🐦 molten.bridge.caldera.xyz Try this with me here ⏩ linktr.ee/usehyperlane
bejo tweet mediabejo tweet media
English
5
0
20
1K
Synapse Labs
Synapse Labs@SynapseProtocol·
You're right @PrimordialAA, *most* intent systems are unreliable. One of these is not like the others. 100% fill rates with Synapse. Drop us a note, we'd love to chat about you guys using our intent network.
Synapse Labs tweet media
Bryan Pellegrino (臭企鹅)@PrimordialAA

As reliable as ever — old faithful. Intents are cool but very much suffer at the bounds for stress and liquidity demands. The best systems will likely utilize both approaches. @StargateFinance very well positioned to do this or work with others to do it

English
6
13
65
14.4K