MevRefund

1.1K posts

MevRefund

MevRefund

@MevRefund

MEV searcher (mid-tier), whitehat, blockchain surveyor

The mempool Katılım Ekim 2021
36 Takip Edilen7.5K Takipçiler
MevRefund
MevRefund@MevRefund·
Found the original attacker (too dumb to successfully pull it off): etherscan.io/tx/0x9788043be… Traced through TC to 0xC8fB3af887C79D8D701334F8CB02b918a8eD139d who had weeks earlier sent me this message: Guess I should've responded 🤷‍♂️
MevRefund tweet media
English
2
1
14
2.1K
MevRefund
MevRefund@MevRefund·
Nope. When your town square is run by an actual Nazi, it's time to find a different town. So long Twitter, I'm moving to mevrefund.bsky.social
English
1
0
4
1.1K
MevRefund
MevRefund@MevRefund·
@cryptoQuoc A contract upgrade is not equivalent to a chain fork. If you truly want to offer non-custodial ownership, make your contracts immutable. Until then, you don't get to hide behind decentralization, code is law, or whatever other excuse you prefer to avoid returning stolen funds.
English
0
0
0
50
cryptoquoc | ₿ 🌊
cryptoquoc | ₿ 🌊@cryptoQuoc·
We have duty to our own stakers to maintain noncustodial ownership of all funds that goes to the feepool. Upgrading and moving funds out is not an option. We voted against the Ethereum DAO fork in 2016. This is the cost of decentralization.
MevRefund@MevRefund

Bruh, the funds are in your upgradeable smart contract, @stakefish You can return them, you just don't want to. Would love to see this litigated somewhere, like when Oasis was forced to rug the Jump hacker. Crypto lawyers how/where can we make this happen?

English
1
0
2
174
@bertcmiller ⚡️🤖
@bertcmiller ⚡️🤖@bertcmiller·
On the exclusive orderflow bit: BuilderNet refunds value back to orderflow providers based off of an open, neutral rule - that democratizes access to what right now is only accessible by those with closed door, opaque deals. You can read the rule here: docs.flashbots.net/flashbots-auct… The goal is to neutralize the need for exclusive orderflow deals, and then to redirect competition from that to more productive dimensions. To that end, every BuilderNet node has the same access to flow and we want to enable others to permissionlessly innovate on top of this flow, e.g. by creating new features, or better merging some transactions together. See our work on putting bots into TDX for a sense of how this might work: x.com/0xangelfish/st… Hope that in the coming quarters we'll see the first instance of novel features or bundle merging from a person or team that would've never been able to deploy their work in prod in the last market structure, but who can do it because BuilderNet enables them to :)
English
1
0
0
279
Viktor Bunin 🛡️🇺🇸
Viktor Bunin 🛡️🇺🇸@ViktorBunin·
Absolutely massive announcement: 1. Will kill censorship on Ethereum 2. Will kill exclusive orderflow deals 3. Gas and MEV refunds built in 4. Neutralized builder duopoly 5. Creates easy pathway for L2 decentralization @titanbuilderxyz when will you join BuilderNet?
Shea Ketsdever@SheaKetsdever

Introducing BuilderNet. BuilderNet is a decentralized block building network for Ethereum that runs on TEEs and shares MEV & gas fees with users. An early version of BuilderNet is live today — operated by Flashbots, Beaverbuild, and Nethermind.

English
8
30
266
25.5K
MevRefund
MevRefund@MevRefund·
Should note that @CoWSwap is fine; just like last time, seems to be a bad solver contract which lets others take cowswap's fees. Solver will be on the hook for losses, not users.
English
0
1
11
1.8K
MevRefund
MevRefund@MevRefund·
The user specifies a contract, which reenters the MEV bot and asks for all of its weth. The MEV bot won't send an unprofitable tx, so the hacker has to send an additional bundle to activate the theft. Note the small bribe paid here which helps ensure the correct tx ordering.
English
1
0
7
2.3K
MevRefund
MevRefund@MevRefund·
Ever seen an MEV bot hacked by a private bait tx? 0x9e5 backruns bloxroute's private order flow, splitting any profits between bloxroute, the user, and themselves. Typically the user refund is a simple internal transfer to an EOA. In this case however ...
MevRefund tweet media
English
5
11
103
11K
MevRefund
MevRefund@MevRefund·
@stakefish New alpha for blackhat hackers unlocked! Just send the funds to a contract which disperses them among several addresses. You too can become a non-custodial service which sadly can't return any stolen funds!
English
1
0
7
1.6K
MevRefund
MevRefund@MevRefund·
Bruh, the funds are in your upgradeable smart contract, @stakefish You can return them, you just don't want to. Would love to see this litigated somewhere, like when Oasis was forced to rug the Jump hacker. Crypto lawyers how/where can we make this happen?
MevRefund tweet media
English
7
2
35
4.1K
MevRefund
MevRefund@MevRefund·
@geomadhack We did respond once in the mempool. For reasons. Don't want to go too deep in the strategy ...
English
0
0
2
984
George
George@geomadhack·
@MevRefund Why is this taking place in the public mempool though? And wasn't the challenge tx a private one? How did he know he got challenged?
English
1
0
1
1.1K
MevRefund
MevRefund@MevRefund·
You're a blackhat with the keys for a compromised withdrawal address. 288 Eth suddenly become available. What do you do? If you're this knucklehead, you immediately send out a mempool tx with a 206 Eth gas fee, then, when challenged, say screw it, and dump the entire stack.
MevRefund tweet media
GIF
English
5
3
67
15.3K
MevRefund
MevRefund@MevRefund·
@thechandog certainly hope so, but in my experience validator returns are pretty rare
English
1
0
2
1.3K
chandog
chandog@thechandog·
@MevRefund since it went to stakefish, isnt it highly likely if not certain it'll be returned?
English
3
0
0
1.4K
stakefish
stakefish@stakefish·
@88danillo @MevRefund Hello! Thanks for bringing this to our attention. I'm sharing it with the team. We will investigate, discuss it internally, and reach out to you.
English
4
0
4
100
MevRefund
MevRefund@MevRefund·
Hi @stakefish , I'm helping whitehat a compromised withdrawal address. Unfortunately, it seems that if the bad guys can't have it, nobody can 😢 Any chance you can return those stolen funds to the rightful owner? etherscan.io/tx/0x3718e5299…
MevRefund tweet media
English
8
6
32
17.6K
MevRefund
MevRefund@MevRefund·
Hi @krakenfx @krakensupport , the lunatics with the stolen private key forced me to dump 92 Eth to your validator. Please reach out to return the stolen funds. etherscan.io/tx/0x660aebf26…
MevRefund@MevRefund

Hi @stakefish , I'm helping whitehat a compromised withdrawal address. Unfortunately, it seems that if the bad guys can't have it, nobody can 😢 Any chance you can return those stolen funds to the rightful owner? etherscan.io/tx/0x3718e5299…

English
36
4
33
8.6K