Val

821 posts

Val banner
Val

Val

@cryptodevval

💻 small dev/OSNIT/SEC | The spot to get all of latest trends

Katılım Ocak 2025
1K Takip Edilen120 Takipçiler
Val retweetledi
Stacy Muur
Stacy Muur@stacy_muur·
Two scammers have already stolen ~$400,000 from users through a phishing @Uniswap ad on Google. It’s insane that Google has ignored this issue for years while fake links keep getting pushed above real ones and users keep getting drained. This is the first result that popped out to me today. Always double-check links through official X accounts or DeFiLlama before connecting your wallet. Stay safe.
Stacy Muur tweet media
b-block@b_block_oficial

Community alert: A website impersonating Uniswap is draining funds from multiple wallets. The scammers are currently holding at least ~$400,000. 0x37925684BA178821b4436E06e67f5dBD6cfA49Bb 0x2fC25F46cC49D226eF92E9A7665f3d2821F3c5E2 Please only use official links, and double-check protocols through @DefiLlama to avoid this kind of scam

English
75
38
335
60.9K
Val retweetledi
Om Patel
Om Patel@om_patel5·
THIS GUY REPLACED EVERY SUBSCRIPTION FOR OVER 30 SERVICES WITH A HOMELAB HE BUILT USING CLAUDE CODE he built his own self hosted version of basically every service you pay for online and runs it all from a 27U server rack in his house the goal was simple: stop renting access to your own data, stop paying monthly subscriptions for things you can run yourself, and have one private dashboard that controls everything in your digital life he opens one homepage on his browser and from there he can: > stream his entire movie and TV collection through plex or jellyfin > request a new movie through overseerr and watch it appear in his library automatically once it's downloaded and tagged > back up every photo he takes through immich (his own google photos) > store all his files through nextcloud (his own google drive) > manage his audiobooks, ebooks, music, RSS feeds, recipes, and bookmarks from one place > block ads across his entire network with adguard home > see live grafana stats for every machine running in his house at any moment and a lot more the homepage dashboard even shows the current weather, his calendar, system stats, download queues, library counts, and shortcuts to every service he uses the hardware list: > netgate 1100 router running pfsense+ for firewall, DHCP, DNS, and VLANs > tp-link 8 port managed switch > tp-link archer C6 access point > raspberry pi 4 dedicated to a full screen grafana dashboard > HP laptop with i3 11th gen and 24GB RAM running proxmox VE as the main hypervisor > compaq laptop with a core 2 duo and 4GB RAM running proxmox backup server > tower PC with a core 2 duo running unraid for the NAS the proxmox VE box runs every self hosted service inside a debian VM with docker compose. backups run on a schedule with chunk based deduplication. unraid handles all the storage with mixed drive sizes and a single parity drive every device is on a tailscale tailnet so he can hit anything from anywhere in the world without poking holes in his firewall then he built his own private streaming empire on top of it: > plex and jellyfin pointing at the same library > overseerr to request movies and shows > radarr, sonarr, lidarr, readarr managing different media types > prowlarr indexing everything > sabnzbd and qbittorrent handling the downloads > bazarr pulling subtitles automatically > tautulli for plex stats > trailarr for trailers then the rest of the stack: > nextcloud replaces google drive > immich replaces google photos > paperless-ngx for OCR document management > adguard home blocks ads across the entire network > miniflux for RSS, karakeep for bookmarks > mealie for recipes, navidrome for music, audiobookshelf for audiobooks > calibre for ebooks, code server for VS code in the browser > stirling PDF, IT tools, microbin, searxng, pairdrop every service surfaces through homepage, a self hosted dashboard he built tooling around to auto generate the YAML config (made with claude code) this guy is paying $0 a month for what most people pay $200+ in subscriptions for and had an initial setup cost of ~1000 to 1500 USD the homelab community is quietly the most overpowered and cracked group of builders on the internet
Om Patel tweet mediaOm Patel tweet media
English
251
392
5K
694.7K
Val retweetledi
StarPlatinum
StarPlatinum@StarPlatinum_·
Centralization exposed inside Tron USDT 🚨 Here’s what is happening: Tether just executed the largest freeze in its history. More than $344,000,000 in USDT (TRC-20) blocked on Tron. By Tether itself. - Coordinated with OFAC and US law enforcement - Executed directly through the USDT smart contract - Funds are now visible but completely unusable This is how it works: - Tether has admin control over USDT contracts - Can blacklist any address - Can freeze balances instantly - Can permanently destroy funds Functions used: - addBlackList(address) - removeBlackList(address) - destroyBlackFunds(address) Now here’s where it gets interesting Timeline April 20 - Arbitrum freezes ~$71M linked to hackers April 21 - Justin Sun tweets: “the most decentralized blockchain in the world is Tron” April 23 - Tether freezes $344M on Tron No response from Justin Sun so far The irony writes itself Stay safe.
StarPlatinum tweet mediaStarPlatinum tweet media
English
305
247
1.4K
167.4K
Val retweetledi
CoinDesk
CoinDesk@CoinDesk·
ALERT: @Bybit_Official's security team uncovers a malware campaign targeting macOS users searching for Claude Code. It uses SEO poisoning to redirect victims to fake installation pages designed to steal crypto wallet credentials and gain remote device access.
CoinDesk tweet media
English
50
94
432
189K
Val retweetledi
Jeffrey Scholz
Jeffrey Scholz@Jeyffre·
Do all your coding inside a VM. Seriously. UTM for Mac is free, works fantastically, and lets you run Mac inside Mac. Get into the habit now before you get rekt by library supply chain issues you cannot control or anticipate. mac.getutm.app Or buy a second laptop. Not having separation nowadays is lunacy.
CoinDesk@CoinDesk

LATEST: A senior blockchain security researcher at CertiK told CoinDesk on Wednesday that North Korea’s Lazarus Group is running a new macOS-focused campaign dubbed “Mach-O Man” that targets executives at fintech, crypto and other high-value firms through routine business communications.

English
26
48
789
130.3K
Val retweetledi
CoinDesk
CoinDesk@CoinDesk·
LATEST: A senior blockchain security researcher at CertiK told CoinDesk on Wednesday that North Korea’s Lazarus Group is running a new macOS-focused campaign dubbed “Mach-O Man” that targets executives at fintech, crypto and other high-value firms through routine business communications.
English
41
66
453
285.2K
Val retweetledi
The Smart Ape 🔥
The Smart Ape 🔥@the_smart_ape·
> builds mythos, the most capable offensive ai ever shipped. > finds a 27-year-old vuln in openbsd. > a 16-year-old one in ffmpeg. > deemed too dangerous. access locked to ~40 glasswing partners. > same day, a discord group get access with the credentials of someone who just had a job interview at a contractor. > the tool that hunts 27-year-old 0-days got bypassed by a poorly-siloed contractor. great time to be alive.
The Smart Ape 🔥@the_smart_ape

x.com/i/article/2046…

English
20
45
1.2K
415.5K
Val retweetledi
Vladimir S. | Officer's Notes
Vladimir S. | Officer's Notes@officer_secret·
Lazarus Group Just Released “Mach-O Man” – A Brand-New Native macOS Malware Kit Targeting Fintech, Crypto, and High-Value Executives You get an “urgent” meeting invite over Telegram for a Zoom, Teams, or Google Meet call. The link leads to a convincing fake website that tells you to copy and paste one simple command into your Mac’s Terminal to “fix the connection issue.” You run it… and Mach-O Man has just taken over your Mac.
English
29
108
491
91.9K
Val retweetledi
James O'Keefe
James O'Keefe@JamesOKeefeIII·
BREAKING NEWS: Top U.S. Nuclear Chief Caught LEAKING Sensitive National Security Information to Stranger, Reveals Army Chemist Was Exposed to U.S. Chemical Nerve Agent, Confirms U.S. Strike Killed Children in Iran, Discloses U.S. Plans to ‘Kill Iran’s New Supreme Leader’ “If he [Mojtaba Khamenei] doesn't change his ways, yeah, they're [United States] going to kill him.” “The easiest way to get intelligence…send a pretty girl, talk to the guy…I have to resist your eyes.” “Your eyes have mesmerized me so much…Almost like you're an intelligence.” Andrew Hugg, a U.S. Chief of Chemical Nuclear Surety, was caught on hidden camera casually revealing sensitive information to a stranger in a public restaurant. Andrew Hugg, Chief of Chemical Nuclear Surety, in charge of nuclear and chemical safety was caught on hidden camera releasing information regarding the U.S. Nuclear Information. He claims the U.S. still possesses nerve agents and says a U.S. Army chemist recently died from exposure. He also acknowledges U.S. airstrikes have killed children in Iran, calling it “collateral damage,” and revealed to the journalist how nuclear launch decisions are made in real time. Hugg described how the United States could assassinate Iran’s next leader if he “doesn’t change,” while admitting the U.S. has no plans to use nuclear weapons: “We’re not going to nuke anybody.” All of this was casually revealed to an undercover journalist in a restaurant. This raises serious questions about this official's judgment, security, and what’s really happening behind closed doors. We have reached out to the Pentagon and U.S. Army for comment and they are working on a response. @USArmy @DeptofWar
English
2K
16.9K
53.1K
8M
Val retweetledi
Sweep
Sweep@0xSweep·
This hacker is trying to break into Trezors for $75 million The biggest wallet he's trying to hack holds $66 million in a single device Joe Grand spent 3 years refining a method to recover hardware wallets for people who locked themselves out years ago The technique came from a 15 year old in the UK who figured it out in his bedroom in 2017 and used it to save a Wired editor $30,000 9 years later the same exploit is saving MILLIONS from a single Trezor The most valuable lockpicking in history is happening out of a backyard lab
English
95
257
2.5K
692.7K
Val retweetledi
Mav
Mav@XMRVoid·
CREATOR OF ‘ONLYFAKE’ ARRESTED DUE TO TRACING OF HIS CRYPTO TO EXCHANGES FOR ONLY $15 YOU COULD CREATE A FAKE ID THAT PASSED ALL CEX EXCHANGES LIKE KUCOIN, MEXC ETC THE ONLY REASON WHY HE WAS CAUGHT WAS BECAUSE HE DIDNT ACCEPT MONERO. IN THE BIG 26’ WE STILL HAVE PEOPLE BEING ARRESTED BECAUSE THEY REFUSE TO JUST DOWNLOAD @cakewallet AND USE $XMR LOL justice.gov/usao-sdny/pr/c…
English
17
64
375
30.5K
Val retweetledi
TFTC
TFTC@TFTC21·
A security researcher just documented a large-scale counterfeit Ledger Nano S Plus operation selling compromised devices across multiple online marketplaces. The fake units look identical to the real thing but contain completely different hardware. Instead of Ledger's secure element chip, the counterfeits run an ESP32 microcontroller with modified firmware labeled "Nano S+ V2.1." Seeds and PINs are stored in plain text and transmitted to attacker-controlled servers. Any wallet initialized on the device is drained. The operation goes beyond the hardware. The sellers also distribute a fake version of Ledger Live built with React Native and signed with a debug certificate. It intercepts transactions and exfiltrates sensitive data to multiple command-and-control servers. The campaign spans five attack vectors: compromised hardware, Android APKs, Windows executables, macOS installers, and iOS apps distributed through TestFlight to bypass App Store review. This comes days after ZachXBT documented a separate fake Ledger Live app that made it through Apple's Mac App Store review process. That operation drained over $9.5 million from more than 50 victims, including musician G. Love, who lost 5.92 BTC after entering his recovery phrase into what he believed was the legitimate app. The pattern is clear: the attack surface for hardware wallet users has shifted from firmware exploits to supply chain and distribution fraud. The devices themselves remain secure. The problem is that users are being intercepted before they ever touch a real one. Ledger's own "genuine check" feature can be bypassed when the hardware itself is compromised at the source, which makes where you buy the device as important as how you use it. The rules haven't changed, but they've never been more important: buy hardware wallets only from the manufacturer. Never enter your recovery phrase into any software. If a companion app asks for your 24 words on a screen, it's a scam. Every time.
TFTC tweet media
English
107
494
1.8K
275K
Val retweetledi
ZachXBT
ZachXBT@zachxbt·
1/ Recently an unnamed source shared data exfiltrated from an internal North Korean payment server containing 390 accounts, chat logs, crypto transactions. I spent long hours going through all of it, none of which has ever been publicly released. It revealed an intricate ~$1M/month scheme of fraudulent identities, forged legal documents, and crypto-to-fiat conversion. Enjoy the findings!
ZachXBT tweet media
English
337
883
6K
1.1M
Val retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️ A BreachForums administrator has allegedly been identified — caught using his real IP and reusing the same passwords across his criminal persona and business accounts. Meet Angel Tsvetkov AKA N/A: a Bulgarian cybersecurity specialist, penetration tester and bug bounty researcher known for responsibly disclosing vulnerabilities in major global platforms.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
45
161
1.3K
163.6K
Val retweetledi
ZachXBT
ZachXBT@zachxbt·
Update: I uncovered another network of 16 X accounts with 2.23M total followers following the same exact strategy of creating panic about war and politics. @MrBitcoinWhalee - 571K @Mrcryptoxwhale - 533K @crypto0637 - 234K @BTCDailyNotes - 174K @CryptoDailyNot - 166K @OnlyBitcoinHQ - 140K @kont1435 - 110K @Jaxweah - 71K @punk2028 - 59K @berkansolana - 58K @brknwhalesol - 52K @harrisauthority - 40K @elindqvistx - 6K @liufeng_dao - 9K @emekacryptong - 4K @yousefmsafr - 3K
ZachXBT tweet mediaZachXBT tweet mediaZachXBT tweet mediaZachXBT tweet media
English
77
76
692
110.3K
Val retweetledi
Ivan Castañeda
Ivan Castañeda@ivancastl·
Muchos foros vinculados a ciberdelincuencia operan fuera del internet indexado. No aparecen en buscadores y cambian constantemente de infraestructura para mantenerse activos. En su mayoría, se encuentran en la web pública no indexada (deep web), aunque algunos pueden tener presencia en la dark web. Cuando una autoridad interviene un dominio, uno de los primeros indicadores aparece a nivel DNS. El dominio deja de resolver hacia su servidor original y comienza a apuntar a infraestructura controlada por autoridades. Cambios en los NS, respuestas distintas o resoluciones inesperadas suelen ser la primera señal. Después llega lo visible: el sitio muestra un aviso oficial de incautación. Pero en OSINT, esperar a verlo en pantalla no es suficiente. El valor está en detectar el cambio en el momento en que ocurre. Aquí te comparto un bot que notifica en tiempo real una incautación, con las siguientes funcionalidades: • Monitoreo continuo de registros DNS (A, NS, MX, TXT) • Análisis de respuestas HTTP en busca de indicadores de incautación • Comparación contra estados históricos • Generación automática de evidencia • Alertas en tiempo real vía bot de Telegram Esto permite identificar de forma temprana cuando un dominio es incautado o confiscado, sin depender de reportes externos. En operaciones OSINT, la diferencia está en transformar señales técnicas en información accionable… antes que los demás. pastebin.com/sm9TeC7S
Ivan Castañeda tweet media
Español
0
24
201
14.3K
Val retweetledi
VECERT Analyzer
VECERT Analyzer@VECERTRadar·
🚨 FINANCIAL INTELLIGENCE ALERT: Binance Database Leak (1.5M Users) 🌐💰 Our Analyzer platform has detected one of the most critical threats to the cryptocurrency sector so far this year. Threat actor PexRat has put up for sale a private database affecting approximately 1.5 million Binance users. Victim: Binance Users (Cryptocurrency) 🏛️. Threat Actor: PexRat 🎭. Volume: 1.5 million records containing full PII and login activity. Timestamp: March 28, 2026 🗓️. Anatomy of the Leak (Compromised Fields) The severity of this dataset lies in the combination of identity data with technical security information: 🔹 User Information (PII): Full names, email addresses, and phone numbers. 🔹 Account Details: Country of registration, account creation date, and Verification status (KYC - Verified/Unverified). 🔹 Security Logs: Last login IP address, device information (User-Agent), and timestamps. 🔹 2FA Status: Information regarding the type of active Two-Factor Authentication (Email/SMS/Authenticator). Monitor: analyzer.vecert.io #CyberSecurity #Binance #CryptoLeak #DataBreach #PexRat #FintechSecurity #InfoSec #CyberAlert #HackingNews #KYC #PII #CriptoMexico #CriptoEspana
VECERT Analyzer tweet media
English
48
88
419
138.7K
Val retweetledi
chiefofautism
chiefofautism@chiefofautism·
someone at ANTHROPIC just showed CLAUDE finding ZERO DAY vulnerabilities in a live conference demo claude has found zero day in Ghost, 50,000 stars on github, never had a critical security vulnerability in its entire, history... it found the blind SQL injection in 90 minutes, stole the admin api key, then did the exact, same thing to the linux kernel
English
300
1.3K
11.7K
1.9M
Val retweetledi
CyberSatoshi 𓆙
CyberSatoshi 𓆙@XBToshi·
🚨Update🚨 The fake TronLink wallet drainer is STILL running as the top "Sponsored" result on Google Ads. It is STILL hosted on the official Chrome Web Store. I don't know how many more users have lost their life savings this week while @Google and Google Adsense actively take money from hackers to distribute this malware. They aren’t just failing to protect users. They are the primary accomplices in the heist. The Web2 trust model is dead. 🩸 #GoogleAdsMalware #FuckGoogle
CyberSatoshi 𓆙 tweet mediaCyberSatoshi 𓆙 tweet media
CyberSatoshi 𓆙@XBToshi

🔪 How Tech Giants Commit Bloodless Murder: A $115k Heist, and a Complicit Google It has been exactly 21 hours since I received the report that a friend had their wallet drained of $115,000 USDT. That phishing link -- the one exploiting the Unicode control character (%E2%80%AE) to flip "no" into "on" and perfectly disguise itself as the official TronLink extension -- is still sitting comfortably at the absolute #1 spot on Google Search, proudly wearing a "Sponsored" tag. Over the past 21 hours, who knows how many newcomers, even regular users trying to manage their assets over the weekend, clicked that link -- endorsed by the world's largest search engine and the so trusted Chrome Store -- and had their life savings instantly vaporized. The hackers didn't break SHA-256. They didn't crack elliptic curve cryptography. They didn't find a zero-day exploit in TRON or Ethereum. Their weapon of choice was Google's credibility. And Google is playing the role of the ultimate accomplice in a perfectly executed, bloodless slaughter . 1. The Hypocrisy and Arrogance of Algorithms If you upload a YouTube video with 3 seconds of copyrighted background music, Google's AI crawlers will strike with the wrath of God in minutes -- demonetizing or banning your channel with the cold precision of a hitman. But when malicious code, utilizing a 20-year-old "Cyrillic replacement + Right-to-Left Override" script kiddie trick, is blatantly submitted to the Chrome Web Store? Google's security scanning system -- built by supposedly the smartest engineers on earth -- suddenly becomes deaf, dumb, and blind. Why the heavy hand on copyright, but a blind eye to hundreds of thousands of dollars in fraud? Because the former threatens the fiat profits of legacy capital. The latter merely drains the wallets of marginalized crypto users. 2. A Perfect Closed-Loop Cartel Is Google just an innocent "platform" in this scam? Absolutely not. The scammers bid on Google Ads. Google's advertising machine happily accepts this blood money, leveraging its monopoly on traffic to spoon-feed poison to every single user searching for "Tron wallet". The hackers take the lion's share, Google takes the ad revenue, and the user gets wiped out. Afterward, Google's legal team will effortlessly wave their Terms of Service: "Users must evaluate the risks of third-party extensions." They don't even have to get their hands dirty. They just open the floodgates of traffic and take a cut from the hunt in the dark forest. This is the modern translation of "Don't be evil." 3. The Bankruptcy of the Web2 Trust Paradigm Our generation was domesticated by Web2. We developed muscle memory: the #1 search result is authoritative. Links on official domains (chromewebstore.google.com) are safe. Mega-corporations will bail us out. But in the Web3 world, this greenhouse-bred "Trust" is a fatal poison. This $115k tragedy teaches us a brutal truth: Centralized systems are fundamentally untrustworthy. When your assets are strictly controlled by private keys, the malice, incompetence, or willful ignorance of any middleman results in your absolute financial destruction. 4. Why We Build the True Dark Forest This is exactly why, no matter how hard it gets, a faction of cypherpunks and builders are stubbornly constructing true, decentralized infrastructure. Stop begging the system to be benevolent. Stop expecting tech giants to suddenly grow a conscience. Against a transparent fiat panopticon and the porous security of traffic monopolies, there is only one defense: "Don't Trust, Verify." Turn off Google Ads. Uninstall extensions you don't absolutely need. Use read-only devices to verify your addresses. Unplug from their system. Strip away your dependency on the illusion of corporate credibility. Fuck Google Ads.

English
3
13
71
6.6K