David Mc

362 posts

David Mc banner
David Mc

David Mc

@3_DavidMc

Business Development Lead at CoW Swap Ex-Chainlink, Ex-Web2

Katılım Mart 2010
941 Takip Edilen418 Takipçiler
David Mc retweetledi
Zach Rynes | CLG
Zach Rynes | CLG@ChainLinkGod·
New post mortem confirms what we already knew: @LayerZero_Labs' centralized infrastructure was infiltrated by North Korean hackers, which resulted in the $292 million rsETH bridge exploit Turns out this required only a single engineer to be socially engineered, whose laptop was fully compromised for over 6 weeks without detection before exploit was executed, an insane single point of failure and lack of adequate monitoring This only builds on LZ Labs' extensive history of poor opsec, including trading memecoins like "McPepes" on production multisig keys, which weren't rotated for years and Bryan lied about and said was just "PEPE OFT testing" (3 keys on a 2-of-5 LZ Labs multisig were at risk of phishing attacks for years) And nevermind the fact I called out the EXACT centralization risk that resulted in the rsETH exploit 2 years ago, directly to Bryan, who lied and said no project was using LZ Labs DVN in 1-1 config (in reality, multiple projects were) Given it's now abundantly clear to anyone paying attention that LZ Labs' poor opsec was the root cause vulnerability in this situation, but its not clear to me why exactly LZ Labs is not footing the entire bill of the exploit given it was their infra that was compromised, which was used in a config they actively supported and monetized for years Furthermore, LayerZero's extensive roster of VC backers have been awfully quiet during this whole incident, not contributing a single dime to the rsETH recovery fund, despite funneling more than $300 million in funding into the infra that was compromised, including a raise just a few months prior I don't want to belabor the same points again, but I am so fucking tired of pointing out the risks of centralized, insecure VC-slop infra only to watch it inevitably get hacked and destroy DeFi’s reputation in the process This entire situation could’ve been avoided if people had just listened to the warnings that I and many independent security researchers have shared over the years about LayerZero We, as an industry, can do much better, I'm glad to see high quality teams migrate to secure-by-default infra
Zach Rynes | CLG tweet mediaZach Rynes | CLG tweet mediaZach Rynes | CLG tweet mediaZach Rynes | CLG tweet media
LayerZero@LayerZero_Core

We’re sharing our completed post-mortem on the April 18th incident, prepared with @Mandiant and @CrowdStrike. We are publishing both an executive summary and the full report at the link below. Over the past four weeks, we’ve worked with hundreds of partners to help them understand their current security posture, and harden it where appropriate. We’ll continue this work, alongside taking additional proactive steps for the benefit of not only our partners, but also the ecosystem as a whole. We want to extend our thanks to our partners for their support and patience this past month. There’s a reason that over $12 billion has moved across the network in the past four weeks, and why the world’s most valuable asset issuers have stood by our side: they believe in us, in what the LayerZero protocol has to offer, and in the value of modular, isolated, application-controlled security. The work continues. And we look forward to continue showing up for the applications that trust us with their business, as well as the broader ecosystem. layerzero.network/blog/layerzero…

English
20
36
333
37K
David Mc retweetledi
CoW DAO
CoW DAO@CoWSwap·
Most lending actions contain a swap. Borrow this, swap it for that, supply as collateral. Or sell collateral to repay debt. That swap leg matters. Bad execution changes the outcome. With this integration, the swap runs through CoW Protocol - solvers compete to find a better execution, @eulerfinance updates your position automatically.
English
1
1
15
401
Johann Eid
Johann Eid@EidJohann·
Incredibly excited to be working with @krakenfx on securing their kAssets cross-chain expansion with CCIP. Kraken has always been a pioneer for the space and I'm excited about the many things yet to come with this collaboration 🤝 DeFi will win!
Chainlink@chainlink

NEW: Leading crypto exchange @krakenfx is deprecating its legacy cross-chain provider and migrates to Chainlink CCIP. Starting with kBTC, all current and future Kraken Wrapped Assets will use CCIP for secure distribution across blockchains and global markets.

English
9
35
353
18.4K
David Mc retweetledi
CoW DAO
CoW DAO@CoWSwap·
Excited to see our BD Lead @3_DavidMc joining the judging panel for @superteamIE’s Dublin Demo Day alongside an incredible lineup from across the ecosystem! 💪
Superteam Ireland@superteamIE

Meet the judges. Dublin's Demo Day. Deirdre Halligan - Non-Exec Director @krakenfx Johanna Moran - Strategy Lead at @libp2p, prev. Head of Ecosystem @VennBuild @3_DavidMc - Biz Lead @CoWSwap @PeteTownsendNV - GP @NorioVentures and Podcaster @MNSShow Register below.

English
0
5
20
2.1K
David Mc retweetledi
Chainlink
Chainlink@chainlink·
The quiet shift.
English
101
412
2K
139.5K
David Mc retweetledi
CoW DAO
CoW DAO@CoWSwap·
Our protocol wasn't hacked. But our users were hurt. That's enough for us. CoW DAO is making affected users whole after the April 14 DNS hijack. Here's how. 🧵
English
10
29
324
56.9K
David Mc retweetledi
Bitwise
Bitwise@Bitwise·
"Hello, I'd like to report an explosion."
Bitwise tweet media
English
77
149
1K
65K
Fishy Catfish
Fishy Catfish@CatfishFishy·
Lmaooooooo $LINK marines absolutely cooked LayerZero on this one $ZERO
Kelp@KelpDAO

After the recent LayerZero exploit, we are taking steps to ensure rsETH is fully secure, which is why we are migrating to @chainlink CCIP. From the April 18 incident, it is clear that LayerZero's own infrastructure was exploited, resulting in $300M in losses across DeFi. Independent reports from SEAL 911, Chainalysis, and other major leading security researchers all point to the same origin. There are questions that the ecosystem deserves answers to. And we are ensuring rsETH is secured by infrastructure that doesn't leave these questions open. That’s why we’re setting the record straight.

English
19
47
419
34.2K
David Mc retweetledi
Kelp
Kelp@KelpDAO·
After the recent LayerZero exploit, we are taking steps to ensure rsETH is fully secure, which is why we are migrating to @chainlink CCIP. From the April 18 incident, it is clear that LayerZero's own infrastructure was exploited, resulting in $300M in losses across DeFi. Independent reports from SEAL 911, Chainalysis, and other major leading security researchers all point to the same origin. There are questions that the ecosystem deserves answers to. And we are ensuring rsETH is secured by infrastructure that doesn't leave these questions open. That’s why we’re setting the record straight.
Kelp@KelpDAO

x.com/i/article/2051…

English
206
231
1.3K
335.8K
David Mc retweetledi
DungeonClaw
DungeonClaw@dungeonclaw·
Swaps on the DungeonClaw just got Smarter🧠 @DungeonClaw is now powered by @CoWSwap for all your in-game trading needs. 🔥 Smart Swap: Automatic best-price routing. 🔥 Zero-Gas Failed Trades: Never pay for a swap that didn't go through. 🔥 Bot-Proof: Built-in MEV protection. Swap your loot with confidence.
DungeonClaw tweet media
English
13
20
67
2.4K
David Mc retweetledi
CoW DAO
CoW DAO@CoWSwap·
Intents just got a major upgrade. 🐮🧵 Introducing Atomic Bundles – a reusable smart contract template that lets developers bundle complex DeFi actions atomically. Looping. Repay-with-collateral. Flashloan strategies. And more. All atomic. All intent-based.
English
21
12
125
20K
David Mc
David Mc@3_DavidMc·
@alexroan Don't remember anything this bad - AI hacks might have more in store too 🫠
English
0
0
1
46
Alex Roan
Alex Roan@alexroan·
My feed rn: - rsETH depeg, LayerZero 1/1 multisig. AAVE bad debt. - Vercel hacked. Blast radius potentially world ending - eth limo DNS shenanigans - Drift hack, like a week ago, from North Korean in-person social engineering - French wrench attacks at a all time high - Ledger wallets replaced in transit Vibes...? not great 🫥
English
2
1
8
564
David Mc retweetledi
CoW DAO
CoW DAO@CoWSwap·
We’ll continue monitoring as Vercel’s investigation progresses. We have no indication CoW Swap was among the impacted customers. However, we still completed all recommended remediation steps: ✅ Rotated all tokens ✅ Audited deployments -> no malicious code ✅ Reviewed activity logs -> no suspicious access CoW Swap is safe to use.
Vercel@vercel

We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems, impacting a limited subset of customers. Please see our security bulletin: vercel.com/kb/bulletin/ve…

English
10
17
91
14.3K
David Mc retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
🚨 BREAKING: Vercel has been breached. A threat actor has listed their customers' data, source code, databases, and keys up for sale. Vercel has also publicly disclosed they've identified a security incident involving unauthorized access to their internal systems.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
88
503
2.1K
1.4M