Tripathi
122 posts

Tripathi
@0xTripathi
building @tradehotstuff | Security Researcher | prev @iitroorkee

gm @EchoProtocol_ may be hacked on @monad Someone minted 1k ebtc out of nowhere, max borrowed wbtc against it on @Curvance, bridged, and tornado away








Introducing Hotstuff Invest 24/7 spot markets for Tokenized Stocks, ETFs & Crypto, powered by @xstocksFi Built on a Hybrid RFQ + order-book model with @bebop_dex as our 1st RFQ venue and more venues being integrated over time The $147T equity market is coming on-chain.

Introducing Hotstuff Invest 24/7 spot markets for Tokenized Stocks, ETFs & Crypto, powered by @xstocksFi Built on a Hybrid RFQ + order-book model with @bebop_dex as our 1st RFQ venue and more venues being integrated over time The $147T equity market is coming on-chain.


From a first glance at gasolina‑aws, only 3 fields actually drive the DVN's RPC behavior. - srcChainName - srcTxHash - blockConfirmation None of them can produce a verifiable proof of packet execution on the source chain. srcTxHash, only helps fetch the receipt + logs and blockConfirmation is fully RPC‑dependent If the configured RPC is malicious or compromised, it can return forged logs and the DVN signs them without any cryptographic check but It would be naive to use single RPC, or multiple RPCs from the same upstream provider but there could be other failures like signing‑key compromise, a compromised S3 bucket repointing providers.json, or a compromised gasolina host ::(



it's really crazy that layerzero doesn't have some redundant sanity check and allows to bridge 116,500 rseth from a chain with a supply of 49 anyway here is my investigation gist.github.com/banteg/705d028…




Introducing aWETH Redemption Protocol With ETH utilization at 100% on Aave, many lenders are currently unable to withdraw and face increasing risk if markets move. aWETH Redemption Protocol allows ETH lenders to: • Exit into wstETH or weETH • Regain immediate liquidity • Reduce exposure to liquidation risk If you’re just lending ETH — you can fully exit. If you have ETH collateral and another debt — your collateral is seamlessly swapped into wstETH or weETH while your debt remains the same. We’re working alongside @LidoFinance , @ether_fi, @0xProject, @1inch, @KyberNetwork, and other ecosystem partners to: • Reduce systemic risk in DeFi • Ease utilization pressure • Support a healthier DeFi market Our goal is simple: protect users while reinforcing the foundations of DeFi. Capacity is initially limited to $1B in ETH. fluid.io/lite/aave-v3/e…






