
22k real time provable TPS has been achieved internally 22k signatures 22k orders 1 second Now let’s double it
Rahul | Aerius Labs
4.3K posts

@Rahul__Ghangas
Utility maxxing 🔧, Stressed Dictator - @AeriusLabs, prev - @CelestiaOrg, @renprotocol | Building @Trade_VEX @FluxePay

22k real time provable TPS has been achieved internally 22k signatures 22k orders 1 second Now let’s double it



Please take 1 minute and watch this clip from Andreas Antonopoulos at ETHDenver 2019 The exact moment Andreas is warning about, where moloch tries to turn Ethereum into corposlop, is here We need the courage to resist it


ai layoffs are getting out of hands so I built “I GOT FIRED” button 🚨 one click, and it makes entire company codebase public, pushes .env secrets to public repo, drops staging db and finally notifies my lawyer 🙂 I hope I never need it but it’s ready 👍🏻


Thank you. The important part is zeroing out taxes on the bottom half. Best way to put money in someone’s pocket is to not take it out in the first place. Bottom half is only 3% of total tax revenue. But it’s very meaningful to that person. Zero it out.



This morning, THORChain was drained of roughly $10.8m Node operators have freezed the network for nearly 13 hours. The full analysis isn't out yet, but according to @jpthor, this could be a MPC exploit. ECDSA and TSS is hard. THORChain's vaults rely on TSS, a flavor of MPC where a quorum of nodes jointly produces a signature without ever reconstructing the private key. Clean for Schnorr or EdDSA; painful for ECDSA, which Bitcoin and Ethereum require. That's why we saw plenty of protocol attempts (Lindell17, GG18, GG20, CMP, CGGMP21, DKLS, KU23...), each patching flaws in the previous one. GG20 has a track record. THORChain's TSS uses GG20, on a fork of Binance's tss-lib. GG20 has shipped two well-publicized critical bugs: CVE-2023-33241 and TSSHOCK. CGGMP21, now cggmp24, are the latest protocols, but GG20 is still widely deployed. I often hear a misconception when I hear about MPC setup: "The key is split across many nodes, so any single co-signer doesn't really matter". In every published GG18/GG20 attack, one malicious or compromised co-signer is enough to extract everyone else's shard and reconstruct the full key. AI changes the threat model. Compromising a full software node, complex Go stack, exposed P2P, custom signing daemons, a churn protocol that admits new participants on a schedule, has always been difficult and acted as a barrier. With LLM-driven vulnerability discovery and exploit synthesis, the bar to compromise one of N validators is dropping fast. Here, it's a plausible TSSHOCK-style playbook: - compromise one operator - wait for it to churn into an active Asgard vault - send malformed proofs during keygen or signing - reconstruct the key offline - sweep in a single transaction It's unclear yet if the attacker used a known-unpatched GG20 weakness, or a fresh cryptographic flaw. But, in all cases, MPC and TSS are not a substitute for hardening every co-signer. They sit on top of co-signers that must each be treated as critical infrastructure, hardware-isolated enclaves, minimally exposed, continuously audited, and running protocol with security proofs. While the investigation progresses, be careful in your interactions onchain. These TSS setup are used in various protocols.




A sovereign state just anchored its official archives to @ethereum . Türkiye's Presidential Communications Directorate has moved 130 institutional publications onto IPFS, with cryptographic proofs settled on Ethereum mainnet — making Türkiye the first state to transition official institutional records to verifiable proof on a public, permissionless L1. The authenticity and integrity of these records can now be independently verified by anyone. This is what state-level endorsement of decentralized infrastructure actually looks like.