Ethnical

1.4K posts

Ethnical banner
Ethnical

Ethnical

@EthnicalInfo

Sec Engineer at @OPLabsPBC 🔴

MemPool Katılım Haziran 2014
586 Takip Edilen1.4K Takipçiler
Ethnical retweetledi
banteg
banteg@banteg·
it's really crazy that layerzero doesn't have some redundant sanity check and allows to bridge 116,500 rseth from a chain with a supply of 49 anyway here is my investigation gist.github.com/banteg/705d028…
English
44
119
1K
199.3K
nasm
nasm@nasm_re·
@d0llcorps3 Mais sinon ce qui m'avait motivé à commencer youtube à l'époque ce sont les vidéos de @EthnicalInfo
Français
2
0
2
48
.maddie⚝₊ ⊹
.maddie⚝₊ ⊹@d0llcorps3·
hello vous avez des bonne chaine IT FR ( low level architecture RE etc... ) sur youtube à conseillez ? je trouve rien de cool sur le youtube fr
Français
16
6
105
25.6K
Ethnical
Ethnical@EthnicalInfo·
@Montyly Just tried and found 2 0day in 7 seconds in solidity compiler thank you for sharing this! 🚀
English
0
0
1
181
Josselin Feist
Josselin Feist@Montyly·
Today I am releasing IsItVulnerable: a new tool I’ve been working on for the past several months: github.com/montyly/isItVu… It builds on recent LLM progress and over a decade of experience building security tools. I developed a new technique that combines abstract interpretation with machine learning The key insight is that this method abstracts the intelligence away entirely. I call it Abstract Intelligence, or AI The result is a major breakthrough in program analysis: IsItVulnerable finds all bugs with 100% recall Yes, all bugs. Fully guaranteed I have tested it extensively, and it has never failed. The results are honestly incredible April 1, 2026 marks a turning point for security, and the industry will never be the same My DMs are open for investors. Entry ticket starts at $500k.
English
32
21
209
13.1K
Ethnical retweetledi
Optimist Prime
Optimist Prime@jinglejamOP·
We are extremely excited to announce Vision Chain in collaboration with Bitpanda - A regulated European exchange with 7 million users, powered by the OP Stack!
English
30
40
265
66.9K
Ethnical retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
🚨‼️ We're in contact with the actor behind the Trivy and LiteLLM hack. They told us they are currently extorting several multi-billion-dollar companies from which they've exfiltrated data. They've obtained 300 GB of compressed credentials and are working their way through them as we speak. The LiteLLM compromise alone led to half a million stolen credentials, according to the threat actor. Their message to the world: "TeamPCP is here to stay. Long live the supply chain." They've sent us their new logo (see image) and also teamed up with several threat actors, including Xploiters and Vect.
International Cyber Digest tweet media
English
50
257
1.4K
164.6K
Ethnical retweetledi
Andrej Karpathy
Andrej Karpathy@karpathy·
Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
Daniel Hnyk@hnykda

LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below

English
1.4K
5.4K
28.1K
66.4M
RKM
RKM@rkmtimes·
JUST IN🇺🇸🇮🇷🇨🇳 China deploying Liao Wang- (818A) electronic Reconnaissance Giant to damage American aerial weapon’s accuracy against Iranian Soil. 🚨China plans to protect Tehran’s Sovereignty with high tech weapons or Type 055 destroyers.
English
825
2K
11.1K
1.4M
Aurélien Taché
Aurélien Taché@Aurelientache·
La première ministre japonaise raciste et négationniste, persiste dans l'escalade militaire. Quelle différence avec les missiles que Kroutchev voulait installer à Cuba ́? Aucune mais lui avait finit par renoncer. La France doit dénoncer ces provocations. lefigaro.fr/international/…
Français
352
40
282
633.8K
JosepBove 🔴🦇🔊
JosepBove 🔴🦇🔊@josepbove·
Finally a conference where some people discovered how funny I am when I am talking Spanish :)
English
1
0
2
131
Ethnical retweetledi
Barchart
Barchart@Barchart·
BREAKING 🚨: Commercial Real Estate Office CMBS Delinquency Rate jumps to 11.8%, the highest level in history 👀
Barchart tweet media
English
134
896
4.8K
711.2K
Ethnical
Ethnical@EthnicalInfo·
Nothing more to add here, keep building lads!
Optimist Prime@jinglejamOP

Is crypto dead? It feels dead. It felt dead in 2014 when Mt. Gox happened and I was already the “weird bitcoin person” on campus. But it didn’t die, legit companies like Coinbase got formed. It felt dead in 2017 after getting pilled on the world computer, only to see the most horrible scams as the first wave of adoption. But it didn’t die, it tripled the talent market in crypto. It felt dead in 2021, because technology didn’t matter when the casino ruled all. But it didn’t die, it flooded the ecosystem with capital. Now it’s 2025. With every hype cycle there’s been a comedown. It weeded people out, and provided the necessary focus to prepare the infrastructure for the next wave of adoption. Global finance will settle on crypto rails. The world computer is effortlessly handling trillions in value and the OP Stack processes more than half a billion transactions every month. I’ve returned to OP Labs as the CEO to take us into this new chapter. We have made a ton of changes - both bittersweet and exciting. For years, we've operated as a fragmented ecosystem, crippling our ability to move quickly. Now, we are re-unifying our GTM and Engineering teams under one roof. Our Foundation remains focused on decentralization. And, after 3 years in Mexico City, my cofounders and I have finally returned to the US and we've opened up a new office in NYC. We’re rounding out year 7 of scaling Ethereum. None of us are going anywhere. This isn’t the last storm we’ll weather, and we’re still fighting like hell. And you know what, Crypto isn’t going anywhere. Stop taking so much adderall and buying extra strength Zyns, it’s making everything feel worse. Go to the gym, drink some water, and I’ll meet you back at the office. We’ve been cooking & I can’t wait to share more with y’all.

English
0
0
0
203
Ethnical
Ethnical@EthnicalInfo·
@0x_anti @glassnode Kinda of crazy times.. multiples indices at all time high but capitulations around the corners for some sectors..
English
0
0
1
52
AntiFragile
AntiFragile@anti_fragile·
When we look at the Net Unrealized Profit/Loss (NUPL) across sectors, we can clearly see why altcoin holders are suffering. Virtually every sector except BTC and ETH is in capitulation territory
AntiFragile tweet media
English
3
1
5
931
sudo rm -rf --no-preserve-root /
no - `owners` is a linked list in Safe and if the hashmap points to something non-zero it's considered an owner. You can directly write owners like that into storage without appearing in the `getOwners` linked list (this can be done via delegatecall). Thus it's called shadow owners.
sudo rm -rf --no-preserve-root / tweet media
English
3
3
21
2.4K
engn33r
engn33r@bl4ckb1rd71·
In honor of multisig security month, I'm happy to present a new tool that analyzes the security of a Safe multisig's configuration. 🛠️ Not every Safe is safe! Test it out on the example multisig addresses 👇
engn33r tweet media
English
19
22
132
24.1K