Orion

4.7K posts

Orion banner
Orion

Orion

@BasedOrion_

eng @SquadsLabs | building blocks @ParagonStaking | passkeys @getbunkr

Katılım Ağustos 2014
940 Takip Edilen2K Takipçiler
Sabitlenmiş Tweet
Orion
Orion@BasedOrion_·
Milestone: Running a Node ✅ Super proud to say that @BGuillaumat_ and I are running a validator (@ParagonStaking) together ❤️ Supporting the network I use 24/7 feels like such a full circle moment 🙌 Feel free to follow or stake while we work towards our leader slot 🫂
English
16
8
72
12.3K
febo
febo@0x_febo·
p-token is live!
febo tweet media
English
137
111
582
173.6K
Orion retweetledi
Squads
Squads@multisig·
Announcing Solana Multisig Tools Three new open-source tools for Squads Protocol v4. All three are small, self-hostable, and built with minimal dependencies. We're actively engaging with STRIDE to help strengthen multisig management practices on Solana. This is the first step towards multiple independent frontends and access points to v4. multisig-cli A focused Rust CLI for reviewing, simulating, signing, and executing multisig proposals. It parses multisig accounts and instructions directly instead of pulling in a large dependency tree. The result is a binary that's easy to audit and well suited for high-trust operational workflows. If you're using an older CLI, we recommend switching to this multisig-cli which has minimal dependencies. multisig-verifier A static, zero-backend browser UI. Reads multisigs state directly from Solana RPCs, decodes proposals, tracks approvals, and lets members approve or reject from their own wallet. No secrets leave the browser. Strict CSP rules by default. multisig-monitor Real-time visibility into multisig activity. Watches configured multisigs, decodes actions, and emits notifications when members create, vote on, execute, or modify configuration. Treasury and governance events surface as they happen. The pattern across all three: inspect before signing, verify before approving, monitor after execution. Smaller dependency surfaces reduce supply-chain risk. Direct decoding reduces blind signing. Open implementations are reviewable end-to-end. Monitoring closes the loop. We strongly encourage every team to verify what they're signing through more than one interface. Don't rely solely on any single frontend. Cross-check with a CLI, an independent verifier, or a second client before approving anything that matters. We're working with a number of security teams who will host their own versions of the multisig-verifier. You can self-host today. Soon teams will also be able to access independently operated instances run by parties with no affiliation to Squads. Link to the repo in the post below.
English
26
47
307
90.9K
LE◎ - sol/acc
LE◎ - sol/acc@L0STE_·
I'm about to do some dirty things to a program...
English
4
1
39
1.1K
jon wong
jon wong@jnwng·
after four long years, last week was my final one @SolanaFndn. along the way, i've been witness to the growth of one of the strongest ecosystems in all of technology (let alone crypto) and i'm deeply appreciative of having played a small part in where @solana is today there are too many stories to recount and too many people to thank so i won't begin to try, but i'm forever a fan of the entire Solana ecosystem and always hope to count myself as part of the family as for what's next: i seek to fulfill a decade-long vision quest to build the last company i ever work for with my friend @nkumar23. across both of our many interdisciplinary experiences throughout our careers, we've seen the value of being glue, of mixing-and-matching skillsets, and of building powerhouse teams to tackle hairy problems. this all-around mindset is embodied by the rare achievement of getting a 5x5 in basketball: at least five points, assists, rebounds, steals and blocks in a single game. only 15 players have done it, ever. we will take this approach to heart with the next step of our journey. this creative technology lab slash product studio slash members collective will have both highly experimental and entirely practical outputs, which we'll explore with software, writing, events, & art. we'd love for you to follow along as we figure it out: 5x5.studio // @5x5_collective
English
154
16
542
44.4K
Orion retweetledi
Stepan | squads.xyz
Stepan | squads.xyz@SimkinStepan·
An update on what we're focusing on with @multisig in light of the Drift incident last week. What we're building now: 1. A proxy program for v4 that lets you opt in to killing durable nonces for a specific signer. This removes the ability for pre-signed transactions to sit indefinitely waiting to be executed. 2. A dedicated protocol management multisig program with configurable template policies and a UI you can run locally. Built for teams that need tighter governance controls over admin operations. 3. Exploring clear signing with intents so signers can verify exactly what a transaction does before approving it (cc @Redacted_Noah). What's already available on v4 and can be set up by your team today: – Timelocks. You can set these up in Settings. They create a mandatory delay between proposal approval and execution. – Signer permissions. You can assign Propose, Vote, and Execute rights separately, so not every signer has the same level of access. – Multisig nesting. You can set up configurations where eg two separate multisigs are signers on a third. Adding a layer of operational separation. -Minimal UI. An interface on top of v4 that you can run locally (github.com/Squads-Protoco…). If you're unsure about your current setup or want guidance on how to configure any of this, DM us.
Squads@multisig

Our investigation into the @DriftProtocol incident remains ongoing. Early evidence points to two compromised signers on Drift's admin multisig, which were used to execute a transaction modifying Drift's program configuration. Squads programs were not compromised. We have also found no evidence of compromise to Squads infrastructure, though we are actively investigating to confirm this with full confidence. We will share further findings as they become available. Best Practices for Operationally Critical Multisigs Thresholds: Any multisig with operational or administrative control over a program should have a signing threshold of 3 or above. This requires an attacker to concurrently compromise multiple independent signers, significantly raising the difficulty of this type of attack. Where possible, signers should also be geographically and organizationally dispersed. Signers sharing the same location, devices, or org structure introduce correlated risk. Timelocks: Multisigs with program-level control should implement a timelock (can be set up in Settings of your Squads multisig). It won't prevent a malicious transaction from being proposed, but it creates a window to detect and reject it before execution. The tradeoff: timelocks also slow down legitimate emergency responses to bugs or active exploits, so teams should factor this into their operational setup. Alerts & Monitoring: We encourage all operationally critical multisigs to set up monitoring and alerts through our security partner @RangeSecurity. Range provides two key things: an alternative interface for independently verifying transaction content outside of the Squads UI, and proactive Slack alerts so signers are notified before a proposal moves forward. If you want help getting set up, reach out and we'll connect you directly. A high threshold, a timelock, and monitoring are the foundation for any multisig with program-level control. Signing Process: Signers should use dedicated devices and hardware wallets, never a general-purpose machine. Additionally, signatures are only valid for approximately 2 minutes each, so introduce at least a 2 minute delay between each signer taking actions to ensure signatures cannot be collected & bundled by an attacker. Always verify transaction content independently across all three available sources: the Squads UI, Range's alternative interface, and Solana Explorer or Solscan On Durable Nonces 
The Drift attack exploited durable nonces to collect signatures without time pressure, bypassing the 2-minute transaction expiry that would otherwise limit this type of attack. We are actively exploring ways to block durable nonce usage across all of our programs, both at the program level and through other enforcement mechanisms, to ensure this protection extends to our immutable programs V3, V4, and our current Smart Account Program. Beyond this, the broader Solana ecosystem is taking steps to address this at the protocol level, with a new transaction format that drops durable nonces as a feature entirely. We will follow up with more information on this soon.

Beyond Multisig, Operational Security Technical controls only go so far. Most high-profile compromises lately have been social engineering attacks targeting the people behind the keys, not the contracts themselves. If you are running mission-critical protocol operations, invest in your internal opsec processes and team culture accordingly, how proposals are initiated, communicated, and approved all matter. We recommend engaging dedicated security advisors. @zeroshadow_io and @0xGroomLake are trusted starting points, and we are happy to connect you directly.

English
18
35
214
34.2K
Orion
Orion@BasedOrion_·
In essence I thinks its rooted in the right idea, but under all the current wallet standards/offerings, the clear intent signing advantage would only apply to CLI + "hot" wallet signing. Ledgers etc still rely on showing you hashes rather than the actually "clear" tx or message underneath. So at least for mission critical actions people take with custodians & ledgers etc, jobs not finished 🥲
English
1
0
1
28
Orion
Orion@BasedOrion_·
Super cool to see this kind of stuff being spun up 🙌 Kudos @gumsays 🫶
English
0
0
1
175
Orion
Orion@BasedOrion_·
@gumsays If you ever need help parsing or anything of the sort, DM 🫡
English
0
0
3
279
trent.sol
trent.sol@trentdotsol·
I just signed the solana mandate with myself: no durable nonces no address lookup tables no precompiles
English
13
5
108
10K
toly 🇺🇸
toly 🇺🇸@toly·
The cold storage signer should ideally have allow list templates in the trust zone. @SimkinStepan seems doable as a constraint on chain, right? But also, the hw signers that are members of the quorum should also each maintain an allow list, then the durable nonce would have never leaked.
English
2
0
3
288
Dana
Dana@TheSoftwareJedi·
i missed the fact that these drift related squads txs had durable nonces... that changes things. perhaps all my wallet security rants are misapplied here. the drift admins may not have completely exposed their keys. just signed a rogue tx sometime in the last 10 days / 2 days respectively. theres no way to tell when it was signed, just sometime in the window. so if thats the case, perhaps proper wallet security was in place - but they were somehow tricked into signing something without knowing. a key thing to look at here would be a fake squads page, since it seems like those wallets were signing legit squads txs during the window. wallet1: solscan.io/account/39JyWr… nonce1: solscan.io/account/7s7s6s… nonce1 used in attack: solscan.io/tx/2HvMSgDEfKh… wallet2: solscan.io/account/6UJbu9… nonce2: solscan.io/account/EmYEry… nonce2 used in attack: solscan.io/tx/4BKBmAJn6Td…
English
9
5
81
32.5K
Orion retweetledi
Altitude
Altitude@altitude·
SWIFT transfers are live. Pay any bank account, anywhere in the world. Directly from your Altitude account. 200 countries. 11,000 banks. 1 balance.
English
55
60
507
155.4K
Orion
Orion@BasedOrion_·
IBRL’ing on the mountain
Orion tweet media
English
1
4
20
2K
Orion
Orion@BasedOrion_·
@alessandrod Granted would probably be a better look to land settlement faster by adding tiny prio fee & budget ixn….
English
0
0
1
36
Orion
Orion@BasedOrion_·
@alessandrod Make raw transactions great again
Orion tweet media
English
1
0
2
97
Orion
Orion@BasedOrion_·
@redacted_noah Just to feel something every once in a while
English
0
0
1
51
Orion
Orion@BasedOrion_·
@heymike777 @multisig Paying transaction fees natively from the vault sadly isn’t possible due to how Solana works. What exactly are you trying to achieve?
English
0
0
1
23
beeman 📱
beeman 📱@beeman_nl·
Gm gm! 😎 What are you working on today? 🧐
beeman 📱 tweet media
English
44
1
115
2.6K
Orion retweetledi
Phil Jacobson
Phil Jacobson@philjacobson·
Stoked to launch Bill Pay on @altitude. Every CFO managing stablecoin-native ops knows bill pay is a mess. Invoices get lost in email. Some payments in fiat, others in stables. Disconnected tools. Manual reconciliation. It's not fun. We built Bill Pay to fix this. One platform for all your payouts, across stables and fiat. Automated. For free. Give it a spin and let me know what you think.
Altitude@altitude

Altitude Bill Pay is live. Pay bills directly from your stablecoin balance. → Email-forwarded bills for auto-ingestion → OCR AI populates every detail → Pay in USDC or via fiat rails your vendor prefers → Payouts from one account make reconciliation simple No more patchwork. One account. All your bills. Closing your books has never been easier.

English
6
5
30
3.1K
Steven (っ♡◡♡)っ
Steven (っ♡◡♡)っ@stevensarmi·
Honestly, this is cool and all but this is just a list of people who are employed by foundation. the real devs who shape Solana every day are the mfers in the trenches grinding glass so their businesses can thrive and raise the tide for everyone. This is def not a complete list, and im sorry for the spam listing you here, but you should follow ever single one of these people. ❤️🫶 @metaproph3t @pileks @metanallok @adamdelphantom @italoacasas @brianlong @WilfredAlmeida_ @SteveCleanBrook @SimkinStepan @BasedOrion_ @callum_codes @allinbitcoin_ @rakka_sol @ArenRendell @junbug_sol @glowburger @kdotcrypto @mxmnci @yrschrade @RealSpaceMonkey @spacemandev @drpeepee @airtightfish @MaxResnick @alessandrod @L0STE_ @deanmlittle @clairefxyz @dhkleung @0xAmol @adhcrypto @candyflipline @armaniferrante @peterpme @beeman_nl @tobeycodes @timahhl @defythepancake @AdrianBrz_ @HypoNyms @cavemanloverboy @niteshnath @metasal @mert @jahris @r0bre @8bitpenis
Mango@mango_

Who is behind @solana? you probably already know toly, raj, lily and vibhu, but many other people shape solana every day: • @lagunacarta: Ecosystem Marketing • @niran7: Head of Owned Media / Marketing • @nickducoff: Head of Institutional Growth • @stevensarmi: Engineering • @therealchaseeb: Founders & Beyond • @jnwng: Vice President of Product • @CaddleMaya: BD Payments • @Pedromiranda: Consumer Growth • @ramzyyalii: DeFi Growth • @AntonioNetoSOL: LATAM Growth • @catgu_: Head of Digital Assets Product • @stokenomic: Recruiter / HR alongside many other legends building solana as we know it today ⚡️

English
25
4
96
10.6K