Coinspect Security

1.9K posts

Coinspect Security banner
Coinspect Security

Coinspect Security

@coinspect

You Build. We Defend. Since 2014 protecting critical decentralized systems: L1 nodes, smart contracts audits, wallets, web3 dApps, exchanges, bridges.

Katılım Temmuz 2014
739 Takip Edilen2.7K Takipçiler
vitalik.eth
vitalik.eth@VitalikButerin·
@donnoh_eth @zklim5389 do oracles too lots of skeletons in the closet there I was fully serious when I said last week that making sure all our oracles are resilience and decentralization-maxxed is more important than stage 1 -> stage 2
English
62
24
296
47K
Coinspect Security retweetledi
Juliano Rizzo
Juliano Rizzo@julianor·
1/ From all the recent writeups, I pick a few to read carefully and enjoy while drinking 🧉 and eating chipa, the way I did before with every (yes) Bugtraq post. This week: Qualys ptrace LPE, CVE-2026-46333 — no AI Linux PDF RCE, CVE-2026-46529 — human+AI Both are worth reading:
English
1
8
62
5.7K
Coinspect Security retweetledi
Juliano Rizzo
Juliano Rizzo@julianor·
🚨GitHub CONFIRMS breach of ~3,800 internal repositories. Root cause: Poisoned VS Code extension on employee device. Exfiltrated: GitHub Actions, Enterprise, Copilot, CodeQL, billing/auth platforms + more. ✅ No customer data impacted Log analysis and secret rotation in progress.
Juliano Rizzo@julianor

TeamPCP post 4 hours ago:

English
0
3
14
5.8K
Coinspect Security retweetledi
GitHub
GitHub@github·
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
English
1.7K
5.4K
25.5K
13.7M
Coinspect Security retweetledi
Giveth
Giveth@Giveth·
The Ethereum Security QF round brought together: • 500 ETH matching pool from @thedaofund • $300K+ in donations • Additional matching pool support from @Quantstamp and @CredShields • Dozens of teams showing up for Ethereum security Really inspiring to see so many parts of the ecosystem come together around supporting Ethereum security. And special thanks to the teams who stepped up with additional support across the round: @Quantstamp, @CertiK, @sigp_io, @Certora, @chain_security, @PashovAuditGrp, @CredShields, @hackenclub, @OpenSea, @yearnfi, @osec_io, @coinspect, @dedaub, @RektHQ, @hexens, @perimeter_sec, @rv_inc, @WeAreTellor, @ECHInstitute Stay tuned for the final results!
GIF
English
10
16
102
3.3K
Coinspect Security retweetledi
Microsoft Threat Intelligence
Microsoft Threat Intelligence@MsftSecIntel·
Microsoft is investigating a new, emerging Mini Shai-Hulud npm supply chain attack targeting antv packages. Attackers compromised an antv maintainer account and published malicious versions of multiple widely used packages (for example, antv/g2). As these packages are widely used as dependencies, the compromise propagated into downstream libraries like echarts-for-react, impacting a much broader set of applications and continuous integration (CI) environments. All compromised packages contain a byte-identical, obfuscated credential-stealing payload delivered via a preinstall hook (Bun). The malware targets high-value secrets including: - GitHub personal access tokens (PATs) and OpenID Connect (OIDC) tokens - npm / Amazon Web Service (AWS) credentials and Security Token Service (STS) sessions - Secure Shell (SSH) keys, kubeconfigs, and .env / .npmrc files - Software-as-a-service (SaaS) tokens (Slack, Stripe, Vault) Exfiltration occurs over HTTPS with Transport Layer Security (TLS) validation disabled. The payload also abuses stolen OIDC tokens to forge Supply-chain Levels for Software Artifacts (SLSA) provenance and propagate malicious releases, exhibiting worm-like behavior across repositories. Malicious files distributed through npm packages are detected by Microsoft Defender as Trojan:AIGen/NPMStealer , "Suspicious Node.js process behavior", or “Credential access attempt”, preventing credential theft and malicious post-install execution. Mitigation: - Audit dependencies for affected antv and related packages; pin or downgrade to known-good versions (pre-2025-05-18). - Revoke and rotate exposed credentials (GitHub, npm, cloud tokens, SSH keys). - Validate integrity of CI pipelines and recent build artifacts. - Network IOC: Stolen credentials are exfiltrated over HTTPS to t.m-kosche[.]com:443. Block at egress and review network logs for outbound connections.
Microsoft Threat Intelligence tweet media
English
35
235
1.3K
173.8K
Bojan
Bojan@bjnpck·
I'm starting to use @ambire more. - Covers everything rabby does - Less tracking
Bojan tweet media
English
8
5
43
2.6K
Coinspect Security
Coinspect Security@coinspect·
Bitcoin Core PoC crash for CVE-2024-52911. ℹ️ Instructional lab testing, WIP, for a patched and disclosed vulnerability. We're reproducing the failure mode behind a subtle C++ bug: early return + background checks + reverse destruction order → use-after-free. Valuable case study given the codebase’s criticality and quality bar.
Coinspect Security tweet media
English
0
6
17
1.8K
Giveth
Giveth@Giveth·
The Ethereum Security QF round is officially closed! Huge thank you to every donor, project, badgeholder, contributor, and community member who showed up to support Ethereum security over the past weeks. More soon 💜
GIF
English
18
16
119
16.6K
Coinspect Security retweetledi
Cotabe.eth
Cotabe.eth@Cotabe_M·
@coinspect is one more team that beyond being an auditing firm is building public goods to make the ecosystem safer. Beyond wallet security ranking, they are working in DappFence and Taint. All public goods for Ethereum security. Tip of the hat to you guys!
Giveth@Giveth

Huge thank you to @coinspect for backing Ethereum security 💜

English
0
4
7
451
Coinspect Security
Coinspect Security@coinspect·
Through @thedaofund on @Giveth, our team supported public goods projects we believe in and we added ~$5k with the Badge (4x) to help amplify support through quadratic funding. But money is the easy part. We'll keep building public goods security projects for Ethereum and supporting other teams with open resources, expertise, and free security services.
English
3
8
20
1.9K
hexens
hexens@hexens·
Three Hexens engineers voted as badge holders in the Ethereum Security QF round, casting their votes for projects they believe in. Hexens contributed $400 per badge-holding team member to back their participation.
English
3
10
42
2.1K
Coinspect Security retweetledi
Patrick Collins
Patrick Collins@PatrickAlphaC·
There are around only 24 hours left to donate to the DAO security fund. I would like to ask you to please donate to Cyfrin Updraft & Tooling. If you know someone who learned security with us, please consider donating! We have been the #1 education platform for onboarding security researchers and developers to Web3 for 3 years straight, 100% for free. qf.giveth.io/project/cyfrin… Some stats: - Averages 8k students a week - Hundreds of thousands of hours of watchtime in aggregate - Millions of views on YouTube (500k on foundry 1 year ago, 600k 2 years ago, ~200k on intro to security, ~25k on assembly and formal verification, etc) - Thousands of stars on security education on GitHub Not to mention @SoloditOfficial, Aderyn, LocalSafe, WiseSigner, ERC-8213, @CodeHawks first flights & AI first flights (competitive audit live trainings) and more. If you don't like our education, we have a tooling page too: qf.giveth.io/project/cyfrin… Thank you for your consideration!
English
23
54
256
14.3K
Coinspect Security retweetledi
souilos
souilos@theSouilos·
Supporting projects like this ⬇️ by @coinspect Talented guys in the industry.
English
1
2
11
299
Coinspect Security
Coinspect Security@coinspect·
Most people choose wallets based on vibes, downloads, or who paid for the biggest sponsorship. Users shouldn’t have to rely on marketing claims when choosing where to keep their assets. We built Wallet Security Ranking We test. You decide.
English
1
3
10
220
Sakata
Sakata@0x_sakata·
these are the best wallets in web3 prove me wrong
Sakata tweet media
English
149
1
206
2.2K
Coinspect Security retweetledi
Juliano Rizzo
Juliano Rizzo@julianor·
Once upon a time, someone noticed "random" numbers repeating. That observation led to one of the most catastrophic crypto bugs ever (Debian’s 2008 OpenSSL RNG flaw)
Adam Gordon Bell 🤓@adamgordonbell

@itseieio This is from this thread btw. So collisions can happen.

English
11
35
1.4K
161.4K