Daniel Von Fange

3.6K posts

Daniel Von Fange banner
Daniel Von Fange

Daniel Von Fange

@danielvf

Skilled Professional (most days). Defends against the bad guys.

East Coast Katılım Eylül 2006
1.2K Takip Edilen12.2K Takipçiler
Sabitlenmiş Tweet
Daniel Von Fange
Daniel Von Fange@danielvf·
This exact string of bytecode has been deployed more than 40 million times, averaging more than 25 times per unique contract on ethereum. It makes up 8.16% of all code on Ethereum. What is up with this? Thread... 1/4
Daniel Von Fange tweet media
English
14
26
238
39.6K
elyx0
elyx0@elyx0·
@danielvf Depends if the 10% reqs assembly{} shenanigans no one will grasp
English
1
0
0
45
Daniel Von Fange
Daniel Von Fange@danielvf·
If you had the option of making all new solidity contracts 10% smaller, but cost 15 gas more to call, would you do it?
English
4
0
2
867
Daniel Von Fange
Daniel Von Fange@danielvf·
@sferik @nikitabier In a non-gamed case, it's because you're both adding value (your own opinion), and it's higher signal (you are putting in some work in response). Elon is basically gaming it though. Things that work on average can be gamed.
English
0
0
0
15
Erik Berlin
Erik Berlin@sferik·
@nikitabier Why does Elon always repost with a “comment” (typically a single word or emoji) versus just reposting. Presumably the algorithm rewards the former, but he/you could change the algorithm. The comments don’t add value; they’re just noise.
Erik Berlin tweet media
English
1
1
1
160
Daniel Von Fange
Daniel Von Fange@danielvf·
@puntium Also, you can completely remove a lot of risks at the architecture stage, before any code gets written.
English
0
0
1
115
Daniel Von Fange
Daniel Von Fange@danielvf·
@puntium Internal code review, both early/informal, and full/deep before code goes to external parties for review.
English
1
0
3
265
Ken Deeter (puntium.eth) 🦇🔊
The 2026 DeFi security stack: - Audits (human, agentic) - Formal Verification - Guarded Launches - Rate limits, settlement gates with emergency overrides - Bug bounties - First loss junior capital tranches - Multisig opsec review - Gsuite/slack/telegram/X opsec review - DNS / package dependencies / Web2 stack security audit - Collateral asset review and disclosure (market, operational, oracle) - Infra dependency risk (bridges, pools, oracles, etc.) - Realtime monitoring - Incident response run-books - Periodic reviews to catch drift in any of the above - Review depth and sophistication that scales with value at risk What am I missing?
English
16
12
89
7.7K
Mitchell Amador
Mitchell Amador@MitchellAmador·
You would be surprised to understand which ecosystems are really the safest, and what drives that. It's not what you think.
English
5
0
22
1.8K
pashov
pashov@pashov·
The reasonable man adapts himself to the world, while the unreasonable man persists in adapting the world to himself. Therefore all progress depends on the unreasonable man. Have a beautiful Saturday🌸
English
5
4
59
3.4K
Daniel Von Fange
Daniel Von Fange@danielvf·
@functi0nZer0 I just learned that if someone is behaving super badly in UK parliament they kick them out for a few days as punishment.... ..... by saying their full name
English
0
0
1
229
Daniel Von Fange
Daniel Von Fange@danielvf·
The lesson from this weekend is: 1. Do not build a system like this 2. If you have built a system like this, fix it 3. If you depend on someone who depends on something like this, be scared, don't trust as much.
Daniel Von Fange tweet media
English
5
17
138
20.6K
Daniel Von Fange
Daniel Von Fange@danielvf·
@hrkrshnn Some of the happiest days in my life have been when I no longer needed to do a thing, for the thing to be done.
English
0
0
16
945
Hari
Hari@hrkrshnn·
If you spent 10 years of your life becoming a cancer specialist and all of a sudden a pharma company is going to drop a cancer vaccine that cures 90% of cancer, how will you react?
English
18
3
46
8.8K
Tay 💖
Tay 💖@tayvano_·
Yeah, they will do whatever and learn whatever to execute a hack. They're very good at learning. But I guess sitting there and trying to find a vulnerability is just not something they spend their time on. It might also be the sheer number of people, especially ones who aren't necessarily the best devs but who can send messages and socially engineer the fuck out of any company in the space.
English
1
0
1
151
Daniel Von Fange
Daniel Von Fange@danielvf·
They used to be clueless on the smart contract side, but that's not the case any more. The big hacks were not because of smart contract vulnerabilities, but often employ contracts to do some clever things. Bybit for example, upgraded a gnosis safe to a custom dprk implementation, and stole with it.
English
6
0
2
250
MilliΞ
MilliΞ@llamaonthebrink·
@tayvano_ @wagmiAlexander Yeah I personally think because they don’t have the savvy They repurpose spy tools for nation state cyber war to target low hanging opsec marks
English
2
0
13
737
fofr
fofr@fofrAI·
gpt-image-2 is pretty good. > show me a screenshot of a mac desktop, large terminal window visible, doing something in the terminal with an expressive TUI layout related to a world sim
fofr tweet media
English
30
43
1.3K
241.2K
Daniel Von Fange
Daniel Von Fange@danielvf·
A scary amount of people do use that phrase to mean "an Act of God beyond the control of mortals". Compromising infra and replacing geth so it faked information to a particular IP, is both 1. A sophisticated attack 2. Something that you should have designed your system to handle.
English
1
0
5
378
WhiteHatMage
WhiteHatMage@WhiteHatMage·
In the shadowed veils of antiquity, such world-shaking calamities were simply called ~magic~. Yet in this flickering age, mortals name them ~sophisticated attacks~. Both spring from the same ancient root: the ever-hungry void of knowledge.
English
1
1
23
1.2K
Daniel Von Fange
Daniel Von Fange@danielvf·
I think many non-pure onchain projects may have something like this buried inside. For example, a large restaking protocol might build a cron job that loads in the total amount staked over RPC, and then updates the onchain token's assets and distributes yeield with the results.
English
1
0
5
1K
Daniel Von Fange
Daniel Von Fange@danielvf·
To add nuance, there's some aspect of this in any bridge. But trust should not be binary - you can't build a system like this on pure trust of the component before it.
English
1
0
6
1.2K