Deniz Mert Edincik

2.1K posts

Deniz Mert Edincik banner
Deniz Mert Edincik

Deniz Mert Edincik

@bluesign

Reverse Engineer / Developer / Mostly Harmless

Katılım Şubat 2007
804 Takip Edilen968 Takipçiler
Deniz Mert Edincik
Deniz Mert Edincik@bluesign·
@rrrkren @bz_bbclub Yeah I think @bz_bbclub was thinking about sending fake usdc with the exact same amounts from different address attacks. ( You send some dust from random, flood history, then send the fake one )
English
0
0
1
39
bz
bz@bz_bbclub·
resource-oriented programming eliminates this by default. no global token ledger to pollute, no permissionless transferFrom to emit phantom events, no deposit without the receiver’s vault capability. there’s no mechanism to spray fake history on flow thanks to cadence; the attack vector doesn’t exist at the language level
etherscan.eth@etherscan

x.com/i/article/2031…

English
3
5
27
7.7K
Deniz Mert Edincik
Deniz Mert Edincik@bluesign·
@rrrkren @bz_bbclub Yeah but then you are trading time for money. Attack becomes cheaper, but takes too long. Better would be birthday paradox approach, but still not feasible. ( Anology would be sending spam email for 100$ per receipent, or sending spam email 1 receipent per a week )
English
0
0
0
35
Eric Ren
Eric Ren@rrrkren·
@bluesign @bz_bbclub Actually iirc since flow’s addresses are deterministically enumerable, it might not be hard to predict when similar addresses appear. This limits the attack surface but it’s likely much much less effort than billions of transactions
English
1
0
0
66
Deniz Mert Edincik
Deniz Mert Edincik@bluesign·
0x73e4a1094d0bcab6 for example is my address. - Block explorers wallets etc can show full address as it it short. Let's say you still try to poison: - To poison you need maybe 0x73e4 xxxxxxxx cab6 kind of address. - You need to create account to have an address. ( which has cost ) - for prefix + suffix only 2 bytes ( by fixing 4 bytes ). 4 bytes free. I think you need to generate like billion+ addresses.
English
1
0
1
82
Deniz Mert Edincik
Deniz Mert Edincik@bluesign·
@idaykan Central park ve besiktas zaten tezat degil mi. Besiktas nufus yogunlugun en dusuk oldugu ilcelerden biri.
Türkçe
0
0
0
148
aykan
aykan@idaykan·
Yapay Zeka’ya Beşiktaş stadını ve Süzer Plazayı kaldır ve New York Central park gibi düzenleme yap dedim ve sonuç…
aykan tweet mediaaykan tweet mediaaykan tweet mediaaykan tweet media
Türkçe
248
88
2.6K
697.2K
Deniz Mert Edincik
Deniz Mert Edincik@bluesign·
@prot0071 @drmervekaratas Kdv sizi hic etkilemiyor. 100 liralik hizmeti 120ye satiyorsunuz. Kdv 0 also ( musteri geri alamasa devletten 20yi ) hizmeti sizden 100e alacak zaten.
Türkçe
1
0
0
15
Prot
Prot@prot0071·
@drmervekaratas Aynı şey hizmet sektöründeki herkesi kapsıyor. Proje çiziyorum fatura kesiyorum %20 KDV otamatikmen giriyor cunku şirketime mahsup edebileceğim bir emtia girmiyor+ %20 gelir vergisi? Emtia girişi olmadığı için kazancın tamamı kar gözüküyor. Bu duruma bir düzenleme şart!!!
Türkçe
1
0
3
540
Merve Karataş
Merve Karataş@drmervekaratas·
Genç Yazılımcı: Yurt dışına freelance iş yaptım, 500 dolar kazandım. Bu parayı çekip harcamak istiyorum. ​PayPal/Stripe: Tamam, paranı hesabına aktarıyoruz. ​D*vlet: Dur orada. O şirketlerin sunucusu benim ülkemde değil, onları yasakladım. Ayrıca o gelen paradan gelir vergisi, stopaj vermen lazım. Şirket kurup Bağ-Kur ödemezsen banka hesaplarına bloke koyarım. ​Genç Yazılımcı: E ama 3 kuruş kazanıyorum, şirket masrafı kazancımdan fazla? O zaman işi bırakıyorum ya da yurt dışına kaçıyorum. ​- Sonuç: Beyin göçü rekor kırdı, ülke teknoloji çöplüğüne döndü, herkes ev genci. - ​Ulusalak dangalak: Emperyalist sermayeye veri güvenliğimizi yedirmeyiz! Yaşasın tam bağımsız yerli-milli intranet! 🤡🤡🤡
Türkçe
169
761
8.3K
746.1K
Deniz Mert Edincik
Deniz Mert Edincik@bluesign·
@grkn Olmasi gereken de biraz bu aslinda. Yoksa sistem calismiyor.
Türkçe
0
0
1
158
Gurkan Oluc
Gurkan Oluc@grkn·
Henüz oylanmamış ama, bu fikirler nereden geliyor acaba? “Bir süredir gözlemliyoruz; orta sınıf parasını bankada tutmamaya başladı. Kriptoya, index fund’lara giriyor; iyi kötü getirilerle biraz birikimini büyüttü. Finansal bağımsızlıktan falan bahsediyorlar. Ne münasebet… Çok büyümeden, ümüklerini sıkalım” gibi bir yerden mi geliyor? Avrupa ve UK'de yaşım ilerledikçe ve gelirim arttıkça farkediyorum ki, sistem aslında sizin çok da kazanmanızı ve biriktirmenizi istemiyor. Sadece her ay sürekli gerekli / gereksiz ihtiyaçlarınız için harcayıp, aydan aya yaşamanızı ve çalışmaya mahkum kalıp, önünüze konan şartlara "he" demenizi daha çok tercih ediyor gibi.
Alex Recouso@recouso

NEW: DUTCH UNREALIZED GAINS TAX 🇳🇱 The Netherlands just voted to overhaul annual income tax filings with a new tax of up to 36% for unrealized capital gains, starting in 2028. Assets like Bitcoin on bitcoin, stocks, and bonds will trigger tax liabilities each year based on changes in value, even if nothing has been sold. I've been warning you: asset seizures are coming to Europe.

Türkçe
2
0
23
5.2K
Deniz Mert Edincik retweetledi
roham
roham@roham·
We bet big on Flow. All of our products – from NBA Top Shot, NFL ALL DAY, Disney Pinnacle, and CryptoKitties to our new slate of apps starting with @PeakMoney_ – are built on @flow_blockchain. This weekend, our bet was tested in public with a serious security incident. An attacker exploited a vulnerability in the execution layer to extract millions of dollars before being stopped thanks to coordinated action across the Flow ecosystem. What happened next is most important. Validators worked together to halt the network within 30 minutes. The exploit itself was identified and fixed rapidly by the Flow core development team, working with community developers (shoutout @bluesign). Over the following 48 hours, the Foundation, bridge operators, exchanges, and ecosystem builders worked toward consensus on remediation. Partners pushed back on early proposals. The approach evolved with input. No single entity could force the outcome. As of this morning, the network is fully operational on the Cadence environment with 99.9% of accounts fully restored and the rest being verified as we speak. Why does this matter? The entire thesis of Flow is safer rails for consumer finance: institutional-grade products accessible to people who shouldn't need a crypto education to not get wrecked. Security and process aren't features of that mission. They're core to the product. This weekend tested whether that's real or marketing. Consumer accounts were protected, the architecture isolated the damage, and the decentralized process held under genuine pressure. The foundation is stronger for having been tested—and the products that actually deliver Consumer DeFi to mainstream users haven't even shipped yet. Flow is live. Dapper users were secure throughout. Now the real work begins.
English
74
38
226
32.1K
Deniz Mert Edincik retweetledi
Dieter Shirley 🌊
Dieter Shirley 🌊@dete73·
I just had a hell of a morning, but I couldn’t be prouder of our community and foundation team addressing this quickly. Special thanks to @bluesign who had a tl;dr of the multi-step contortion comprising the hack by the time the caffeine hit my system. Much ❤️❤️❤️, my friend!
Find Labs@findlabs

FLOW NETWORK INCIDENT: Forensic Fund Tracking Report FindLabs is publishing the following analysis in collaboration with the Flow Foundation's security and engineering teams, who conducted the primary forensic investigation. • INCIDENT CONFIRMATION On December 27, 2025, an attacker exploited a vulnerability in Flow's execution layer. The attacker then moved assets off-network — primarily through bridges to Ethereum — before validators executed a coordinated network halt. Confirmed funds exited to date total approximately $3.9M, with forensic analysis ongoing. Critically, this exploit did not access or affect existing user balances. All user deposits remain intact. The vulnerability has been identified and isolated. A full technical post-mortem will be published within 72 hours. • ATTACKER WALLET (ETHEREUM) 0x2e7C4b71397f10c93dC0C2ba6f8f179a47F994e1 All confirmed exit transactions route through this address. Freeze requests have been submitted to exchanges and stablecoin issuers. • CONFIRMED EXIT TRANSACTIONS The following exit paths have been identified and verified. Confirmed funds exited to date: ~$3.9M USD equivalent. Forensic analysis is ongoing and this report will be updated as additional transactions are identified. CELER BRIDGE — 297.69 ETH - 74.422 ETH — etherscan.io/tx/0xbf3f95b0f… - 74.422 ETH — etherscan.io/tx/0xe6f55f204… - 74.422 ETH — etherscan.io/tx/0x106b8db43… - 74.422 ETH — etherscan.io/tx/0x9d6684f6f… DEBRIDGE — 479.35 ETH (includes USDC conversions) - 49.359 ETH — etherscan.io/tx/0x2d347295a… - 151.781 ETH — etherscan.io/tx/0x1eae85eed… - 123.30 ETH — etherscan.io/tx/0x3b5671861… - 14.932 ETH — etherscan.io/tx/0x9d6684f6f… - [+ 10 additional transactions ranging 11-17 ETH each] DIRECT WITHDRAWALS — 109.19 ETH - 90.299 ETH (Binance) — etherscan.io/tx/0xcf20b2c7f… - 18.89 ETH (Binance) — etherscan.io/tx/0x6e5b6fb95… RELAY BRIDGE — 39.44 ETH - 39.44 ETH — etherscan.io/tx/0x6bc988300… STARGATE — 9.98 ETH - 4.99 ETH — etherscan.io/tx/0x22a55360d… - 4.99 ETH — etherscan.io/tx/0x4378c6988… WBTC — 9.8 WBTC (~$930K) - 4.9 WBTC — etherscan.io/tx/0xe00dee9da… - 4.9 WBTC — #tokentxns" target="_blank" rel="nofollow noopener">etherscan.io/address/0x2e7c… PYUSD — 339K PYUSD (converted to ~261 ETH) - 279K PYUSD — etherscan.io/tx/0x52580ac81… - 60K PYUSD — etherscan.io/tx/0xeb3f5cf06… • ACTIVE LAUNDERING DETECTED The attacker is actively attempting to launder funds through privacy-preserving protocols: THORCHAIN (ETH → BTC conversion) - 250 ETH — etherscan.io/txs?a=0x2e7c4b… - 248 ETH — etherscan.io/tx/0x83099b48a… - 287 ETH — etherscan.io/tx/0x82276037a… CHAINFLIP (ETH → BTC conversion) - 50.6 ETH — etherscan.io/tx/0x74330ac39… - 258.14 ETH — etherscan.io/tx/0x6d250dc07… - 258.82 ETH — etherscan.io/tx/0x3c18a6daf… • CONTAINMENT STATUS ✅ Flow network halted — no further unauthorized activity possible ✅ Exit transactions identified to date mapped above ✅ Freeze requests submitted to Circle, Tether, Binance, Coinbase, Kraken ✅ Forensic partners and law enforcement engaged ✅ User funds unaffected — exploit did not access existing balances • NEXT STEPS The protocol fix has been developed and is entering final validation. → Target restart: Within 4-6 hours, pending successful testnet validation → Next status update from Flow Foundation: Within 2 hours → Full technical post-mortem: Within 72 hours This report will be updated as fund movement continues.

English
13
7
61
10K
Deniz Mert Edincik retweetledi
roham
roham@roham·
There was a security incident on Flow this morning. About $3.9M exited before validators worked together to halt the network. User balances and assets are not affected. Your Top Shot moments, Pinnacle pins, and NFL All Day collectibles are safe. Products are paused during the halt, but everything is intact. I helped start Flow and our products run entirely on it. This one is personal. The Foundation flagged the incident at 4:40 AM and we are working with the Dapper and Flow teams to resolve the situation in the safest and most expeditious manner possible. The Foundation is targeting a restart within 4-6 hours, with updates every 2 hours. Follow @flow_blockchain for the official timeline and details. Special thank you to @bluesign for helping find and lock down the source of the exploit in collaboration with the Foundation.
Dapper Labs@dapperlabs

Following this update from Flow, we want to make it clear that no Dapper Labs user balances or assets are impacted. Including the Dapper Labs treasury. Dapper Platforms will be back online when the Flow network resumes normal operations, currently expected to happen in ~6 hours.

English
51
17
139
31.2K
Arthur Camara
Arthur Camara@arthcmr·
@bluesign @KellyMorrisonMN well, she was talking about a specific person and saying there's no such thing as preventative imaging (which is incorrect). Sure, there's the potential argument that preventative MRIs are more harmful for the general population than useful, but that's a different discussion.
English
1
0
0
46
Kelly Morrison
Kelly Morrison@KellyMorrisonMN·
Doctor here 👋 There's no such thing as a "preventative MRI."
English
6.8K
2.2K
15.6K
4.9M
fatih kadir akın
fatih kadir akın@fkadev·
@aokocax Milletin herhangi bir şeyi abartma seviyesi can sıkıcı ya. Ben de seviyorum Alperen’i de öncesinde de NBA izleniyordu yani.
Türkçe
2
0
2
896
Deniz Mert Edincik retweetledi
Brian Doyle 🌊
Brian Doyle 🌊@random_entropy·
Great new tutorial by the Flow Tools team that shows how to run a fork of mainnet in the emulator. It's so much easier to build DeFi apps this way. You can use real contracts and impersonate any account without risking funds! developers.flow.com/blockchain-dev…
English
2
2
15
929
Deniz Mert Edincik
Deniz Mert Edincik@bluesign·
@arthcmr @KellyMorrisonMN People often mistake statements about the "general population" vs "individuals" Like antibiotics are bad for the general population because of the increase of antibiotic resistance, but ofc beneficial for the individual.
English
1
0
0
25
fatih kadir akın
fatih kadir akın@fkadev·
hatalı denmiş ama bana hala "queens of the ai" daha mantıklı geliyor çünkü bahsedilen AI artık kavramsal olan AI değil, mevcut dünyada var olan AI olmuş oluyor. bu nedenle "the AI" kullanmak mantıklı bence. bu arada İngilizlerin/Amerikalıların hiç umurunda olan bir şey değil.
Türkçe
14
0
42
25.4K
lazlo tooth
lazlo tooth@lazlototh67·
@jakubwiech Hi Jakub. I'm happy to see Poland thriving with per capita GDP $45k. My state, NY, is at about $116. Even with income inequalities this amount enables my very poorly run state to redistribute income so the poorest have more than many middle class Poles, but I wish you luck.
English
12
0
5
571
Jakub Wiech
Jakub Wiech@jakubwiech·
Hi, I’m from Poland, and I recently read in the US National Security Strategy about Europe’s supposed “civilizational erasure.” So I’d like to tell you a bit about European civilization. 🇪🇺We have a more modest GDP, yet we still run a trade surplus with the United States, employ 2.5 times more industrial workers, have a higher export share in GDP, and maintain lower income inequality. 🇪🇺We don’t have a heavily privatized healthcare system, yet our life expectancy at birth is about three years higher, and infant mortality is nearly half that of the US. 🇪🇺We don’t have universal and unconditional access to firearms, yet European cities are far safer: we have clearly lower rates of homicide, violent crime, and car theft. 🇪🇺We don’t design our entire spatial order around a single mode of transport; instead, we build transport systems with a strong role for public transit, including rail. 🇪🇺We don’t have tech giants pumping up stock-market valuations, but we do equip ordinary workers with things like paid monthly vacations, paid sick leave, paid parental leave, and contracts that prevent sudden dismissal. So let’s ask ourselves: which of these things truly reflects the kind of civilization we want to pursue? PS In the photo I’m sitting and waiting for some delicious food, did I mention that Europe is superior in this as well, because we have regulations that limit the use of harmful food additives?
Jakub Wiech tweet media
English
1.4K
4.8K
26.1K
1.1M
BPT
BPT@bpthaber·
Grok, Norveç'te bir kişinin hayatını kurtardı. — 49 yaşındaki hasta, şiddetli karın ağrısı şikayetiyle hastaneye gitti. — Doktorların kontrolünün ardından asit engelleyici ilaç yazılarak eve gönderilen hasta, ağrılarının geçmemesi üzerine Grok'a durumu anlattı. — Grok, ülser delinmesi veya atipik apandisit olabileceğini söyleyerek, acilen hastaneye geri dönüp bilgisayarlı tomografi çektirmesi gerektiğini söyledi. — Hastaneye geri dönen hasta, Grok'un yazdığı mesajı göstererek "Sanırım bende bundan var, bilgisayarlı tomografiye girmek istiyorum" dedi. — Tomografide hastanın apandisitinin neredeyse yırtılmak üzere olduğu görüldü ve acilen ameliyata alındı. — 6 saatlik ameliyatın ardından apandisit alındı ve hastanın ağrısı tamamen geçti. — Ölümden dönen hasta: "Hayattayım ve iyileştim çünkü doktorların gözünden kaçan durumu bir yapay zeka fark etti."
BPT tweet mediaBPT tweet media
Türkçe
694
754
26.9K
5.6M
Deniz Mert Edincik
Deniz Mert Edincik@bluesign·
from my layman understanding, to make 1.3 HF, I need to borrow $17400 ( buy & hold 0.6 BTC ). At end of the year I will have 1.6 BTC - USD interest ( let's say 10% $1740 ) which brings me to $72350.32 ( 1.56 BTC )
English
0
0
0
182