Morph🧬

307 posts

Morph🧬

Morph🧬

@0xMorph

Everyday @SpearbitDAO @Cantinaxyz

GMT+8 Katılım Nisan 2020
780 Takip Edilen473 Takipçiler
Morph🧬 retweetledi
Eric Vishria
Eric Vishria@ericvishria·
I’m so fucking proud of this team. They took an extraordinarily difficult technical swing with wafer-scale and connected on the first try. Then they spent years grinding through packaging, cooling, compilers, frameworks, early customers, and everything else required to turn a technical breakthrough into a real company — swinging and missing and learning and trying again. Most importantly, they stayed clear-eyed about what they had (a technical marvel) and what they didn’t (enough advantage in training), saw the opportunity emerging in inference, and adapted. That kind of persistence — not to be confused with stubbornness — is incredibly hard to describe, but absolutely essential in the unstable substrate of AI. The requirements of AI today will not be the requirements of AI tomorrow. But this team will keep figuring it out. And I’m here for it.
Eric Vishria tweet mediaEric Vishria tweet mediaEric Vishria tweet mediaEric Vishria tweet media
English
73
26
584
81.4K
Morph🧬 retweetledi
banteg
banteg@banteg·
excuse me, but how is cumrag called rekt news related to securing ethereum? it's long been replaced with an llm that writes snarky "wow hacked again" articles.
banteg tweet media
English
16
8
204
25.8K
Pyro
Pyro@0x3b33·
Contests are dead, cantina killed them
Pyro tweet media
English
20
10
242
15K
Morph🧬 retweetledi
Hari
Hari@hrkrshnn·
Great work by the @Ripple team on responding quickly to our disclosure, alerting the validators who promptly voted down the upgrade that was scheduled to go live on March 5. Our autonomous bug hunter Apex found this critical bug. Had this been exploited, it would have been the largest security hack by dollar value in the world, with nearly $80B at direct risk.
Hari tweet media
XRP Ledger Foundation@XRPLF

We released a full report on the Batch amendment issue from last week. The bug revolved around the signature validation logic of the Batch amendment. It was caught before the amendment was activated by the autonomous AI agent Apex at @cantinaxyz. Thank you to all validators and community members for the collaboration and swift response. More details in the blog post here: xrpl.org/blog/2026/vuln…

English
13
15
116
14.4K
Morph🧬 retweetledi
Cantina 🪐
Cantina 🪐@cantinasecurity·
2026 accelerates the digital economy beyond the standards used to evaluate it. Institutions need a way to evaluate DeFi risk. Teams need a path to institutional adoption. Web3SOC is the institutional due diligence framework, built on a consistent, evidence based methodology.
English
26
37
116
751.9K
Morph🧬
Morph🧬@0xMorph·
@hrkrshnn Sounds insane but I was there to witness it
English
0
0
3
259
Hari
Hari@hrkrshnn·
Our autonomous bug hunter has already saved 11 figures' worth of funds at risk.
English
16
6
65
24.8K
Morph🧬 retweetledi
Cantina 🪐
Cantina 🪐@cantinasecurity·
The AI security tool we’re building surfaced a high-severity vulnerability in Cosmos’ bug bounty, confirmed on HackerOne. We’re designing it for signal > noise so organizations can prioritize real risk. The waitlist is now open.
Cantina 🪐 tweet media
English
2
11
65
28.3K
Morph🧬 retweetledi
Morph🧬 retweetledi
/director
/director@fullyallocated·
I’m starting to think there’s one or more entities out there that have developed strategies with AI assistance to find & exploit old protocols. The bar to build, sample, test, exploit strategies has never been lower. Protocol age used to be a sign of security but in this specific period of time I think old protocols with lots of dead money are probably getting targeted now that capabilities have improved. My prediction is that the next 2-5 years are going to be extremely painful for DeFi as builders try to figure out how to navigate the new environment. Highly complex protocols will be locked down with so much control that they are indistinguishable from centralized incumbents. Permissionless systems will need to be designed in ways that can be formally verified. I feel like we are all frogs in a pot rn. The water is starting to boil but none of us seem to recognize the temperature change. People are acting like the security environment is the same as it was this time last year. Newsflash: it’s not. It’s not even close to what it was 3 weeks ago. The rate at which AI tooling is improving should really make us all stop think about the implications of what that means in attacker’s hands. I’m not talking about someone prompting “find me a hack” or some bs. I’m talking about already sophisticated and highly intelligent people or groups having access a toolset that can 100x their ability to construct and test possible exploit paths, quickly scaffold infrastructure for identifying potential vulnerabilities, etc.
Weilin (William) Li@hklst4r

The latest @ribbonfinance attack appears to be a oracle configuration fault. 6 days ago, the owners updated the oracle pricer which uses 18 decimals price for stETH, PAXG, LINK and AAVE. However, other assets like USDC price still at 8 decimals. creation of OToken is not a root cause because everything is LEGAL. The underlying tokens need to be whitelisted before they are used in an OToken as collateral/strike asset. The attack flow: (1) create new option market (e.g., LINK/USDC option market) that will expire in several minutes. (2) deposit LINK as collateral and buy LINK call option. (3) wait for expiry and execute the option to profit.

English
6
11
72
14.7K
Morph🧬 retweetledi
The Book of Ethereum 📘
The Book of Ethereum 📘@Bookof_Eth·
In the Book of Ethereum, 2025 will be remembered as the year the protocol learned to fortify itself while scaling to meet the world. Cantina's piece captures it well: two great movements - Pectra and Fusaka - advancing Ethereum’l's account design, validator operations, data handling, and cryptographic foundations… all while pairing those changes with rigorous, open security work. This is what real infrastructure looks like: decentralized, upgraded in the open, stress-tested across clients, and strengthened by hundreds of independent researchers. A network doesn't become global money, global settlement, and global coordination by accident. It becomes so through the kind of engineering, humility, and discipline described here. Ethereum's scaling roadmap is not only advancing - it is maturing. And for those building on it, the message is simple: 📖 The foundation grows stronger beneath your feet.
English
8
8
24
212
Morph🧬 retweetledi
Cantina 🪐
Cantina 🪐@cantinasecurity·
In Web3, every second counts. @Hypernativelabs alerts teams to the threat. Cantina neutralizes it. Together, we’re redefining Managed Detection and Response (MDR) for organizations. Read more: cantina.review/8a7c62
English
4
12
40
5.7K
phil
phil@philbugcatcher·
> Baby says “papa” > I look at baby > Baby makes a funny face and laughs I swear there’s no better feeling
English
8
2
139
3.7K
Morph🧬 retweetledi
Kevin 🇺🇦
Kevin 🇺🇦@dj_d_sol·
Really disturbing when I ask ChatGPT about an area I know well and it gives me a completely wrong answer Luckily this never happens with topics I don’t know well
English
4
8
103
6.1K
Morph🧬 retweetledi
m4rio
m4rio@m4rio_eth·
Duck db also compromised! We are full war right now with exploiters attacking npm packages so they can supply chain attack them! Please, i urge everyone to take the following actions: Go to your npm projects and use pinned dependencies, e.g. if you use dep: “^1.0.0” change it to dep: “1.0.0” which means to remove the caret ^. This will pin your dependency on a trusted version, not allowing u to pull a malicious dependency. The attackers are using patch versions which easily gets pulled by npm because the caret ‘^’ is allowing that. So next time when u do a npm install and you removed the lock file, the malicious dependency gets pulled. Do not trust your lock files. If you read this and you don’t what i i wrote above, dm me!
Socket@SocketSecurity

🚨 BREAKING: The DuckDB npm account was compromised. Malicious versions of duckdb, duckdb-wasm, and more were published early this morning with the same wallet-drainer malware seen in yesterday’s supply-chain attack. Check your dependencies! socket.dev/blog/duckdb-np… #NodeJS

English
3
6
42
5.9K
Morph🧬 retweetledi
RareSkills
RareSkills@RareSkills_io·
RareWeek -- where lead auditors at tier-1 firms study.
RareSkills tweet media
English
13
13
136
30.9K
z80.wei 👌☀️👌
hey @grok which two of my mutuals are most likely to be secretly in love with each other
English
2
0
8
1.7K
Han
Han@hanstmy·
🎉 GIVEAWAY! 🎉 We're giving away 5 @MalaysiaBCW tickers to lucky winners! 🎁 To enter: 1️⃣ Follow me, @SuperteamMY 2️⃣ Like & RT this post 3️⃣ Share your thoughts on how you think Malaysia's Solana ecosystem is evolving! Winners will be chosen after 24 hours! Don’t miss out! 🙌
English
13
14
29
2.2K