anticapture

303 posts

anticapture banner
anticapture

anticapture

@anticapture

Accelerating DAO governance capture resistance | By @blockful_io

Katılım Ocak 2025
29 Takip Edilen586 Takipçiler
Sabitlenmiş Tweet
anticapture
anticapture@anticapture·
🗳️ With @tallyxyz winding down, delegates and token holders need reliable places to participate. Multiple independent frontends aren't just nice to have, they reduce single points of failure. 🔗 Anticapture is now available as a governance interface: anticapture.com
English
1
8
41
7.1K
anticapture retweetledi
blockful.eth
blockful.eth@blockful_io·
The wasabideployer.eth address was compromised and it was the only wallet holding the ADMIN role in the @wasabi_protocol. Once compromised, the attacker used it to grant the ADMIN role to a contract under their control. This allowed them to call the strategyDeposit function across 7 vaults, move funds into the attacker's contract, replace the vault logic through a UUPS upgrade, and drain the full balances via a drain() call. The attack unfolded across 4 different chains, hitting multiple vaults, and was fully executed in just 3 minutes. This brought April's total to 30+ exploits and roughly $630M stolen: making it one of the worst months in DeFi history. A significant share of these incidents stemmed from poor access control management across protocols: - No timelocks on granting sensitive roles like ADMIN, leaving no window to detect or stop a malicious action. - No limits on fund withdrawaltas or protocol-level fund movements. - In Wasabi's case, not even a multisig controlled the sole ADMIN address - it was just a bare EOA. These safeguards would have prevented attacks like Resolv (March 2026), Drift, Wasabi, and others that followed the same pattern. As an industry, we need to align on stronger access control standards and make the protocols holding billions of dollars of user funds genuinely harder to take over with a single compromised key.
blockful.eth tweet media
ZachXBT@zachxbt

@wasabi_protocol Why did a single EOA seemingly have so much control without basic safeguards? Seems your runway was burned on KOL grifters like Kook….

English
0
5
23
3.2K
anticapture retweetledi
blockful.eth
blockful.eth@blockful_io·
1/ Lido is discussing replacing its current mechanism for pausing protocol contracts. Currently, Lido has the GateSeal: an emergency button capable of pausing certain contracts. Control over this button is shared among different Lido committees, and the permissions for each "button" are approved through governance. They can pause anything from the contract used to withdraw stETH from validators to receive ETH to the stVaults contracts. The goal is for it to act as a safeguard not only for the DAO, but for the protocol as a whole. The problem is that maintaining the GateSeal is too cumbersome. Every GateSeal expires after one year, meaning new permissions must be granted annually so contracts can keep pausing specific Lido contracts. On top of that, each GateSeal controls a fixed number of contracts: if one contract is paused but the GateSeal controls ten, it becomes unable to pause the remaining nine unless a new governance proposal renews its powers.
blockful.eth tweet media
English
4
6
45
9.9K
anticapture retweetledi
anticapture retweetledi
blockful.eth
blockful.eth@blockful_io·
Erin Koen (@eek637), Gov Lead at @Uniswap, submitted a proposal to withdraw 12.5M delegated $UNI from the @UniswapFND and other governance members, such as @Anode_GG, @kpk_io, and @AxiaNetwork0x. The delegations come from the Uniswap DAO treasury. The rationale is the increase in delegations from $UNI holders following the creation of its DUNA at the end of 2025. As a result, they now have delegates with skin in the game and no longer depend on delegates whose voting power comes from the DAO treasury. But is that actually true? The data shows that it is, but with some nuances. 🧵
blockful.eth tweet media
English
1
4
24
2K
anticapture retweetledi
blockful.eth
blockful.eth@blockful_io·
A governance attack attempt happened over the past few weeks. Its goal: steal every dollar deposited in the protocol, $40M. Here's how Lazy Summer identified and blocked an attack that would have been capable of draining every user's balance. 🧵
blockful.eth tweet media
English
2
9
28
1.9K
anticapture retweetledi
zeugh.eth
zeugh.eth@theZeugh·
For you donations to count for matching on the Ethereum Security QF, you have to donate at least 1 USD worth to each project. I see a lot of donations on @anticapture are bellow that value. We appreciate your support, but it'd go a long way if you could come again and leave a WHOLE dollar for us to get matched :)
zeugh.eth tweet media
English
3
6
33
1.9K
anticapture retweetledi
DeFiScan
DeFiScan@defiscan_info·
This past month, we have never seen as much demand for risk infrastructure and decentralization assessments in DeFi. @DeFiScan is building it along the amazing teams @l2beat, @walletbeat, and @anticapture. Please consider donating to us!
DeFiScan tweet media
English
1
5
27
2.6K
anticapture retweetledi
netto.eth
netto.eth@alextnetto·
Just donated to a few projects that push for security in different front and are underfunded IMO @anticapture - preventing access control attacks (disclosure: my project) @walletbeat - UX, security for users @defiscan_info - Holding DeFi to better standards @cyfrin - A lot of security public goods @zachxbt - no comments needed
Giveth@Giveth

If you’re tired of watching exploits dominate the timeline, this is your moment to act. The Ethereum Security QF Round is LIVE! Support the people and projects securing Ethereum and its L2s. 500 ETH (~$1M+) in matching from @thedaofund. Explore & donate: qf.giveth.io/qf/ethereum-se…

English
9
9
47
3.3K
anticapture retweetledi
blockful.eth
blockful.eth@blockful_io·
Our work on @anticapture has protected over $150 M so far. We are live on @thedaofund Ethereum Security Round on @Giveth It's a great chance to multiply any donation you make to support projects that you believe are important for security. giveth.io/project/antica…
Giveth@Giveth

If you’re tired of watching exploits dominate the timeline, this is your moment to act. The Ethereum Security QF Round is LIVE! Support the people and projects securing Ethereum and its L2s. 500 ETH (~$1M+) in matching from @thedaofund. Explore & donate: qf.giveth.io/qf/ethereum-se…

English
3
10
25
3.2K