cvh

593 posts

cvh banner
cvh

cvh

@cvhessert

build, automate, secure, validate, advise, invest & repeat | VP, Security & Smart Contracts @0xPolygonLabs | Re/Tweets are my own | 🇦🇷

Amsterdam, The Netherlands Katılım Aralık 2008
1.1K Takip Edilen663 Takipçiler
Sabitlenmiş Tweet
cvh
cvh@cvhessert·
Security shouldn't be hard nor expensive, you just need to know what's important... Hopefully this helps prevent future loses in this ecosystem in some way... @cvh/w3s" target="_blank" rel="nofollow noopener">hackmd.io/@cvh/w3s
English
2
2
16
2.4K
cvh
cvh@cvhessert·
@pashov I put this together for some friends and projects I advise. Wonder your thoughts on how to address this issue, it’s only going to happen more in the future @cvh/5-dollar-wrench-attacks" target="_blank" rel="nofollow noopener">hackmd.io/@cvh/5-dollar-…
English
1
1
1
69
pashov
pashov@pashov·
At least 7 "wrench attacks" since the start of the month, 5 of which in France. A "$5 wrench attack" shows that your crypto can often be stolen by bad people with malicious intent and just $5 "weapon" like a wrench. Learn personal OpSec. Protect your data and stay safe.
pashov tweet media
English
20
12
158
67.5K
cvh
cvh@cvhessert·
AppSec in the AI era will be less about reviewing code and more about operating systems that: Attack. Triage. Improve. Repeat. AI swarms finding and exploiting weaknesses. AI triage validating impact, killing noise, scoring real risk. Even opening the PR. Continuous. Autonomous. Human-guided.
English
0
0
1
36
cvh
cvh@cvhessert·
Everyone wants an AI red team swarm constantly breaking their own code But that’s not the hard part The real bottleneck is triage If your system generates 500 findings a day and you can’t automatically validate exploitability, dedupe noise, score real business impact, and chain issues into real attack paths, you don’t have security You have alert fatigue Build the triage brain first, thats what I’m focusing on!
English
0
0
4
87
cvh
cvh@cvhessert·
Thank you for 1M context window!
English
0
0
0
24
cvh retweetledi
smartcontracts.eth
smartcontracts.eth@kelvinfichter·
Sleep is just context compaction
English
5
12
79
5.7K
cvh
cvh@cvhessert·
I need a MCP for @TenderlyApp please 🙏
English
0
0
0
36
cvh
cvh@cvhessert·
Who’s building a SKILL.md & AGENT.md marketplace? Seems like a no brainer…
English
0
0
0
131
cvh retweetledi
ZachXBT
ZachXBT@zachxbt·
Community alert: Ledger had another data breach via payment processor Global-e leaking the personal data of customers (name & other contact information). Earlier today customers received the email below.
ZachXBT tweet media
English
1.1K
1K
5.6K
1.2M
cvh
cvh@cvhessert·
@TenderlyApp can you build an @claudeai Agent Skill to build, run and interpret simulations?
English
0
0
0
23
cvh retweetledi
wavey
wavey@wavey0x·
... after three long days with claude code, i have this to share: → SlotScan.info a human readable web ui for evm storage visualization (supports Solidity + Vyper) → Blog post documenting my learnings: wavey.info/posts/2025/rev…
English
6
12
87
15.5K
cvh
cvh@cvhessert·
Basically every CIO out there…
Peter Girnus 🦅@gothburz

Last quarter I rolled out Microsoft Copilot to 4,000 employees. $30 per seat per month. $1.4 million annually. I called it "digital transformation." The board loved that phrase. They approved it in eleven minutes. No one asked what it would actually do. Including me. I told everyone it would "10x productivity." That's not a real number. But it sounds like one. HR asked how we'd measure the 10x. I said we'd "leverage analytics dashboards." They stopped asking. Three months later I checked the usage reports. 47 people had opened it. 12 had used it more than once. One of them was me. I used it to summarize an email I could have read in 30 seconds. It took 45 seconds. Plus the time it took to fix the hallucinations. But I called it a "pilot success." Success means the pilot didn't visibly fail. The CFO asked about ROI. I showed him a graph. The graph went up and to the right. It measured "AI enablement." I made that metric up. He nodded approvingly. We're "AI-enabled" now. I don't know what that means. But it's in our investor deck. A senior developer asked why we didn't use Claude or ChatGPT. I said we needed "enterprise-grade security." He asked what that meant. I said "compliance." He asked which compliance. I said "all of them." He looked skeptical. I scheduled him for a "career development conversation." He stopped asking questions. Microsoft sent a case study team. They wanted to feature us as a success story. I told them we "saved 40,000 hours." I calculated that number by multiplying employees by a number I made up. They didn't verify it. They never do. Now we're on Microsoft's website. "Global enterprise achieves 40,000 hours of productivity gains with Copilot." The CEO shared it on LinkedIn. He got 3,000 likes. He's never used Copilot. None of the executives have. We have an exemption. "Strategic focus requires minimal digital distraction." I wrote that policy. The licenses renew next month. I'm requesting an expansion. 5,000 more seats. We haven't used the first 4,000. But this time we'll "drive adoption." Adoption means mandatory training. Training means a 45-minute webinar no one watches. But completion will be tracked. Completion is a metric. Metrics go in dashboards. Dashboards go in board presentations. Board presentations get me promoted. I'll be SVP by Q3. I still don't know what Copilot does. But I know what it's for. It's for showing we're "investing in AI." Investment means spending. Spending means commitment. Commitment means we're serious about the future. The future is whatever I say it is. As long as the graph goes up and to the right.

English
0
0
0
98
cvh retweetledi
cvh
cvh@cvhessert·
Nice article, to add a bit on the re-audit aspect. The way I plan and think of this is dividing your budget and yearly plans on GROW and MAINTAIN line items. GROW is what most projects normally do, bigger budget for new products, features, etc. They all get audited/pen-tested, ideally more than once. MAINTAIN is a smaller budget, specifically for new audits on existing products/apps. Can be full scope or with a specific one, or targeted to specific objective / goal like a CTF or Red Team engagement. For example, in traditional web2 / SaaS companies, and also as required by various certifications and regulations, yearly network and application Pentest are the norm.
English
0
1
9
790