sean retweetledi
sean
299 posts


⛔️ Why you should completely abandon browser extension wallets (and why we're preparing to release a XRAY/Vault solution that solves this problem):
1. Browser extension wallets have extensive access to the web pages you view, including sensitive elements such as the clipboard. This access allows malicious extensions to inject scripts that can steal sensitive and any other information, directly from the page or clipboard, as well as perform any functions. Have you checked your browser extensions and what access levels (permissions) they have?
2. Browser extensions often rely on numerous JavaScript libraries and dependencies. Each dependency represents a potential vulnerability and if any of these libraries are compromised, it can lead to security breaches in the extension itself. The most recent event was with the Polyfill library, which is used by tens of thousands of websites and apps.
3. Expands on the first and second points: you may be spied on (although there's still no way to hide the sending of the transaction — some server or node must accept it).
We've added two screenshots to this post to give you an idea of what's going on. The first is a disclaimer on the Chrome store for Eternl Wallet, the second is the Yoroi dependency tree. And also attached a few related links.
Links:
— Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies: @alex.birsan/dependency-confusion-4a5d60fec610" target="_blank" rel="nofollow noopener">medium.com/@alex.birsan/d…
— Polyfill Supply Chain Attack: thehackernews.com/2024/06/over-1…
— Hundreds of articles about billions of dollars a year stolen because users are unable to understand where they are and how things work.
Dependency tree visualizer:
— Yoroi dependecy checker (1881 dependencies): npmgraph.js.org/?q=https%3A%2F…
— Daedalus dependecy checker (2781 dependencies; not a browser extension, but still): #deps=devDependencies" target="_blank" rel="nofollow noopener">npmgraph.js.org/?q=https%3A%2F…
So potentially between two thousand and three thousand NPM dependencies and therefore developers have access to your browser window if you use the Yoroi/Eternl/Nami/NameItAsYouWant extensions.
XRAY/Vault will eliminate some of these security concerns and make Cardano's online experience more UX-friendly. Fully compatible with CIP-0030, and without dependencies. Works like HW, but without the HW.
How? You'll see soon ™ :)
#cardano #ada

English

@Trainwreckstv Same to you and the fam.
Max in coming today. I can feel it.
English

Happy Holidays to you Mr. @cz_binance. Thanks for everything you've done and continue to do.
English

⚽️Yokaiswap World Cup Football⚽️
🌟Second semi final🌟
🇫🇷France Vs Morocco🇲🇦
Rules: @yokaiswap/yokaiswap-world-cup-football-da0b478577c2" target="_blank" rel="nofollow noopener">medium.com/@yokaiswap/yok…
✅Retweet & Like.
✅tag your friends & challenge them in prediction.
Prize: 20000 $YOK😱
👇Comment your predictions (be specific in case of a tie result) below👇

English

@OCDinsomnia @Arthium @Trainwreckstv Damn thanks for the explanation. I'd definitely cash out then. Extra 200k aint worth the lost it all risk.
English

@Arthium @Trainwreckstv 4 way multi bet, so the multiplier stacks higher. He's won on 3, and just needs to win the last one. He can cash out now for 1.3m, or wait till the last bet finishes and cash out full 1.5m. But if last bet loses, he loses the whole bet.
English
sean retweetledi

@PokerPepes Bro if you need help developing the dApp im all in till there is success damn :(
English

@yokaiswap 23K CKB was lost during the transfer and what should I do now !!?
English

Hi Yokai Family.
The YOK-CKB Liquidity pool migration is going to take place tomorrow at 8AM UTC.
Please follow @yokaiswap/8273dbad7ec" target="_blank" rel="nofollow noopener">medium.com/@yokaiswap/827… to get started.
Hope you are all ready to begin farming on Yokaiswap v1 🌟💫

English















