Gryphus ☣ Mario

3.7K posts

Gryphus ☣ Mario banner
Gryphus ☣ Mario

Gryphus ☣ Mario

@Grifo

I break things and code stuff to break more

ЕГГОГ! Katılım Mart 2008
468 Takip Edilen428 Takipçiler
Sabitlenmiş Tweet
Gryphus ☣ Mario
Gryphus ☣ Mario@Grifo·
The final part of our State of the Art of Private Key Security in Blockchain Operations series is live! 🔐 [4/4] Approvals & Policies Talking about Approvals (by humans) & Policies (what can be signed): 🔗 nccgroup.com/research-blog/… 🧵 A quick recap of the full series 👇
Gryphus ☣ Mario tweet media
English
4
5
3
426
Gryphus ☣ Mario retweetledi
☠ Dani Martinez ☠
☠ Dani Martinez ☠@dan1t0·
🎣 Just released: GoPhish MCP Server! ✨ Features: 🎯 Campaign management (CRUD + analytics) 👥 Groups, templates, pages, SMTP profiles 📊 Advanced analytics & reporting 🔍 Smart search & utilities github.com/dan1t0/gophish… #GoPhish #MCP #AI
English
1
5
8
810
Gryphus ☣ Mario
Gryphus ☣ Mario@Grifo·
Whether you're worried about the keys on your project, or about managing institutional funds, I hope you can get some (good) ideas from these posts!
English
0
0
0
46
Gryphus ☣ Mario
Gryphus ☣ Mario@Grifo·
The final part of our State of the Art of Private Key Security in Blockchain Operations series is live! 🔐 [4/4] Approvals & Policies Talking about Approvals (by humans) & Policies (what can be signed): 🔗 nccgroup.com/research-blog/… 🧵 A quick recap of the full series 👇
Gryphus ☣ Mario tweet media
English
4
5
3
426
Gryphus ☣ Mario
Gryphus ☣ Mario@Grifo·
[3/4] Private Key Storage & Signing Modules A look into the pieces that actually hold and use private keys. HSMs, Enclaves, and types of storage for operational keys (including where you should never store them) 🔗nccgroup.com/research-blog/…
English
0
0
0
43
Gryphus ☣ Mario
Gryphus ☣ Mario@Grifo·
[2/4] Common Custody Solutions Architectures Showcasing some of the common architecture designs (off-chain centralized, off-chain MPC, on-chain) and their core components 🔗 nccgroup.com/research-blog/…
English
0
0
0
34
Gryphus ☣ Mario
Gryphus ☣ Mario@Grifo·
[1/4] Concepts, Wallet Types & Signing Strategies Foundations of key management: Multisig, MPC, offchain vs onchain, and how these models shape custody design. 🔗 nccgroup.com/research-blog/…
English
0
0
0
34
Gryphus ☣ Mario
Gryphus ☣ Mario@Grifo·
Part 3 of our Private Key Security for Blockchain Operations series is live! This one dives into the heart of custody solutions — the Private Key Storage & Signing Module 🔐 Do's and Don'ts of private key storage! 🔗 nccgroup.com/research-blog/…
Gryphus ☣ Mario tweet media
English
1
0
0
47
Gryphus ☣ Mario retweetledi
deebeez
deebeez@deeberiroz·
We @VennBuild just discovered a critical backdoor on thousands of smart contracts leaving over $10,000,000 at risk for months Along with the help of security researchers @dedaub @pcaversaccio, the seals team @seal_911 and others, we managed to rescue the majority of funds before the attacker could make their move. This is the story of how a sophisticated attacker (cough Lazarus) put backdoors in thousands of contracts and ALMOST got away with it 🧵
English
53
116
784
132.6K
Gryphus ☣ Mario
Gryphus ☣ Mario@Grifo·
@PatrickAlphaC The main issue is when one of the EIP-712 fields is calldata of another contract (like all Safe{Wallet} fields) which will just be a bunch of hex data that your HW wallet won't decode, like this example below:
Gryphus ☣ Mario tweet media
English
0
0
0
18
Patrick Collins
Patrick Collins@PatrickAlphaC·
So... what do we need to see on our wallets? If we have any one of these (all the data, message & domain hash, safeTxHash) that's enough to verify that what we are signing. Ideally, we get the safeTxhash, since it's the easiest to verify (cuz it's just a single hash)
English
2
0
2
183
Patrick Collins
Patrick Collins@PatrickAlphaC·
What should your hardware wallet show you? When you sign a transaction or a message, what is the information you NEED to verify what you're signing is correct? If you don't know, you must watch this, and/or read this thread. 👇
English
14
44
316
16K
Gryphus ☣ Mario retweetledi
Ryan Els
Ryan Els@ryanels·
World's best CSS developer 😂
Ryan Els tweet media
English
59
642
5.8K
218.1K
Gryphus ☣ Mario retweetledi
Lorenz Lehmann
Lorenz Lehmann@LehmannLorenz·
Today, my PC was nearly compromised. With just one click, I installed a malicious @code extension. Luckily, I was saved as my PC doesn't run on Windows. Hackers are getting smarter and aren't just targeting beginners. Here's how they do it and how you can protect your coins!
Lorenz Lehmann tweet mediaLorenz Lehmann tweet mediaLorenz Lehmann tweet media
English
203
1.7K
10.3K
2.5M