Cos(余弦)😶‍🌫️

9.2K posts

Cos(余弦)😶‍🌫️ banner
Cos(余弦)😶‍🌫️

Cos(余弦)😶‍🌫️

@evilcos

Founder of @SlowMist_Team // 分身一号/捉虫大师/救火运动员 // 🕖灾备频道 https://t.co/bMGdsBkYwM

HACKING Katılım Kasım 2008
1.5K Takip Edilen123.6K Takipçiler
Sabitlenmiş Tweet
Cos(余弦)😶‍🌫️
这行业割韭菜的行为越多,诈骗越多,跑路越多,黑客事件只会越多,一些有能力的黑客决不允许在“聪明”赚钱这块输过这般人。
中文
467
20
576
205.9K
Cos(余弦)😶‍🌫️
@luoyonghao 许多韭菜就是冲着这个热劲来,疯的很,最好的方式是完全忽略,没有注意力也就没有炒作话题或角度
中文
1
0
2
1.1K
罗永浩
罗永浩@luoyonghao·
我为了防止人们上当公开辟谣,结果还能涨得更狠?那不是说明那些傻韭菜就是活该吗?我靠。。。
hao shan@haoshan888

@luoyonghao @cz_binance 罗老师,你越提涨的越狠,无视就好了,不懂可以问AI

中文
240
2
133
51K
Cos(余弦)😶‍🌫️
@zaochih 因为 26 的几个小版本也存在相关漏洞,我们捕获的样本,能触发的不在你列的这个常见范围内。还有目前看样本也不一定是 DarkSword。黑产会拿来大规模水坑的几乎都是这些老洞。所以,有安全更新,更新就对了。
中文
1
0
3
392
草纸
草纸@zaochih·
@evilcos 怎么都光说“旧版”不提多旧,原来是 18.4-18.7(
中文
1
0
0
433
Cos(余弦)😶‍🌫️
已经拿到一些在野攻击样本了,目前可以肯定的这是针对旧版 iOS 的 iPhone,Safari 浏览器,有加密货币钱包的用户群体。 有假冒色情直播、波场能量站、退款流程、漏洞预警等等的网页,如果旧版本 iPhone 用户的 Safari 浏览器打开了这种网页,没有关闭的情况下,此时解锁钱包 App 准备使用,明文私钥就可能会被这种网页里的恶意 JavaScript 利用代码给盗走。 系统更新要重视,尤其看到有安全漏洞修复有关的更新。否则你的那些钱包怎么被盗的你都知道。 细节我们会看情况再决定披露。
23pds (山哥)@im23pds

🔥所有用户请及时更新iOS 系统 DarkSword 攻击程序已经泄漏,其核心能力为:通过 HTTP 接口从 iOS 设备中提取取证级数据。 在实际攻击中,攻击者可结合社工或水坑攻击诱导用户中招,进而窃取 iPhone / iPad 内数据,并上传至攻击者控制的服务器。

中文
5
14
108
46.4K
Cos(余弦)😶‍🌫️
@7jdg 还是有不少,许多人懒人的老设备拿来当所谓“冷钱包”(不用时飞行模式),一个没注意,收到一封看去有关系的邮件,然后点开,接着继续使用钱包 App,然后中招
中文
0
0
0
471
Cos(余弦)😶‍🌫️
😏其实方法论我们 @TycheKong 已经公开过,参考 PPT 的“AI 能否在攻击发生后独立完成根因分析?”章节。 至于实践吧,得独立完成,这个确实需要不少背景知识。
Cos(余弦)😶‍🌫️@evilcos

Hacking Time - 我们在代码审计(尤其智能合约有关的安全审计及攻击分析)方向,使用 AI 的经验及案例分享: @TycheKong @SlowMist_Team github.com/slowmist/Hacki…

中文
1
0
6
8.2K
Cos(余弦)😶‍🌫️
经过半个月每天真实的链上攻击验证,我用 Hermes Agent 分别与 DeepSeek V4 Pro/GLM 5.1/GPT 5.5 组合,加上 SlowMist.AI 的 Harness 经验,打造了 3 个完全独立的 Agents,效果都挺不错了。 链上分析工作实现初级自由😊 我的心得是:目前 Harness 经验最关键,其次是不错的模型,再次是不错的框架。 继续折腾,将相关工作先一个个实现初级自由。
Cos(余弦)😶‍🌫️@evilcos

在 Hermes Agent 上配套 DeepSeek V4 Pro 模型,链上安全分析能力已经很令我满意了…三笔近期的攻击,复杂度从中等到普通到简单。mark 下。

中文
13
16
199
49.5K
Cos(余弦)😶‍🌫️
Transit 这次被盗是其 2022 年安全事故的历史遗留问题所致,其波场早期发布的旧版本智能合约存在历史遗留问题,虽然该旧版本合约于 2022 年停止使用,但近期被攻击者利用🤔 顺便说下,Transit 当前在运行的智能合约不受影响。
Cos(余弦)😶‍🌫️ tweet mediaCos(余弦)😶‍🌫️ tweet media
Cos(余弦)😶‍🌫️@evilcos

Transit Swap 这次安全事故不是个简单的坑… 主要原因在于 Transit Swap 协议在进行代币兑换时并未对用户传入的数据进行严格检查,导致了任意外部调用的问题。攻击者利用此任意外部调用问题窃取了用户对 Transit Swap 授权的代币。 多说无益,尽力追踪。

中文
3
4
36
16.3K
Hansen 🦞
Hansen 🦞@Hansen1018·
这是什么情况?OpenClaw安全放弃维护了? @evilcos
Hansen 🦞 tweet media
中文
1
0
0
4K
Cos(余弦)😶‍🌫️
EF 牵头的 Clear signing 是来解决盲签问题的,不过看来了下需要目标智能合约协议按规范(ERC-7730)来完成注册,如,已经有一批了: github.com/ethereum/clear… 然后支持 ERC-7730 的钱包及相关工具就可以很好解析展示。 现在合约一大堆,没按规范来的怎么办?看看已有钱包的工作,比如 @Rabby_io 等实际上在“盲签”及“签名可读性”上已经做了巨量沉淀,这些工作在没有 ERC-7730 时已经做的不错,也许当下 ERC-7730 可以做个补充,还不是主导。 不管怎样,是个不错的工作。
Ethereum Foundation@ethereumfndn

0/ Clear signing is now live. An open standard to end blind signing, making human-readable transactions default. This effort brings a major UX and Security upgrade to transaction signing on Ethereum.

中文
4
1
39
27.6K
Cos(余弦)😶‍🌫️
江湖规矩,黑我可以,但禁止用 rm -rf 做破坏🌚🌚🌚
蓝点网@landiantech

用心极其险恶!#TanStack 供应链攻击中黑客预留死人开关,检测到开发者吊销令牌后执行 rm -rf ~/ 命令。相关恶意脚本位于~/.local/bin/ 目录,里面的检测脚本会每 60 秒查询 1 次窃取的 GitHub 令牌,如果令牌被撤销就会触发死人开关,从而执行 rm 命令删除开发者的所有文件:ourl.co/112916

中文
5
0
67
24.9K
Cos(余弦)😶‍🌫️ retweetledi
宝玉
宝玉@dotey·
吴恩达老师观点:所谓“AI 会引发大规模失业”,纯粹是一种不负责任的恐慌故事。 软件工程师都快被 AI 工具折腾死了吧?可现实却是工程师招聘市场依旧火爆,美国失业率稳稳地停在 4.3%,没半点要崩的样子。每一波技术浪潮,最终创造出来的新岗位远比被干掉的多得多,这次也不会例外。 “AI 抢饭碗”这个故事为啥这么流行背后的三股推动力: 一是前沿 AI 公司特愿意把自己技术吹得越神越好。一项技术能干掉一个年薪十万的员工,那卖你一万美元的订阅费是不是就显得便宜了? 二是企业自己也爱把裁员说成是“AI 提效”,毕竟比承认“疫情期间招人招过头了”听着体面多了。 三是媒体天然就偏爱恐慌故事。“AI 会让人类灭绝”,这标题点击率总比“AI 会改变你的工作内容”高出几个数量级。 他举了些历史上类似的群体恐慌故事:比如公众对核电站安全的过度焦虑,直接导致核电发展停滞几十年;60年代“人口炸弹”的恐惧,让很多国家祭出了严厉的人口控制政策;再比如对脂肪的恐惧,导致政府推广了几十年的高糖低脂饮食。这些听起来有点荒唐,但当年每一个故事都非常流行,并实实在在影响了无数人的生活。 AI 不会带来失业末日(jobpocalypse),而会带来一场就业狂欢(jobapalooza)。大量 AI 工程师的岗位即将诞生,而且还不止是在传统科技公司里。其他非 AI 岗位的技能需求也会发生重大变化。对普通人来说,现在正是进入 AI 行业、或者掌握 AI 工具的最佳时机。
Andrew Ng@AndrewYNg

There will be no AI jobpocalypse. The story that AI will lead to massive unemployment is stoking unnecessary fear. AI — like any other technology — does affect jobs, but telling overblown stories of large-scale unemployment is irresponsible and damaging. Let’s put a stop to it. I’ve expressed skepticism about the jobpocalypse in previous posts. I’m glad to see that the popular press is now pushing back on this narrative. The image below features some recent headlines. Software engineering is the sector most affected by AI tools, as coding agents race ahead. Yet hiring of software engineers remains strong! So while there are examples of AI taking away jobs, the trends strongly suggest the net job creation is vastly greater than the job destruction — just like earlier waves of technology. Further, despite all the exciting progress in AI, the U.S. unemployment rate remains a healthy 4.3%. Why is the AI jobpocalypse narrative so popular? For one thing, frontier AI labs have a strong incentive to tell stories that make AI technology sound more powerful. At their most extreme, they promote science-fiction scenarios of AI “taking over” and causing human extinction. If a technology can replace many employees, surely that technology must be very valuable! Also, a lot of SaaS software companies charge around $100-$1000 per user/year. But if an AI company can replace an employee who makes $100,000 — or make them 50% more productive — then charging even $10,000 starts to look reasonable. By anchoring not to typical SaaS prices but to salaries of employees, AI companies can charge a lot more. Additionally, businesses have a strong incentive to talk about layoffs as if they were caused by AI. After all, talking about how they’re using AI to be far more productive with fewer staff makes them look smart. This is a better message than admitting they overhired during the pandemic when capital was abundant due to low interest rates and a massive government financial stimulus. To be clear, I recognize that AI is causing a lot of people’s work to change. This is hard. This is stressful. (And to some, it can be fun.) I empathize with everyone affected. At the same time, this is very different from predicting a collapse of the job market. Societies are capable of telling themselves stories for years that have little basis in reality and lead to poor society-wide decision making. For example, fears over nuclear plant safety led to under-investment in nuclear power. Fears of the “population bomb” in the 1960s led countries to implement harsh policies to reduce their populations. And worries about dietary fat led governments to promote unhealthy high-sugar diets for decades. Now that mainstream media is openly skeptical about the jobpocalypse, I hope these stories will start to lose their teeth (much like fears of AI-driven human extinction have). Contrary to the predictions of an AI jobpocalypse, I predict the opposite: There will be an AI jobapalooza! AI will lead to a lot more good AI engineering jobs, and I’m also optimistic about the future of the overall job market. What AI engineers do will be different from traditional software engineering, and many of these jobs will be in businesses other than traditional large employers of developers. In non-AI roles, too, the skills needed will change because of AI. That makes this a good time to encourage more people to become proficient in AI, and make sure they’re ready for the different but plentiful jobs of the future! [Original text in The Batch newsletter.]

中文
87
36
238
172.5K
Cos(余弦)😶‍🌫️ retweetledi
SlowMist
SlowMist@SlowMist_Team·
🚨SlowMist TI Alert🚨 💸 @Aurellion_Labs Loss: 455,003 USDC (~$455,003) 🔍 Root Cause: Unprotected initialize(address varg0) in SafeOwnable Facet. Diamond set owner via non-initialize path without updating _initialized version slot (bytes 0-7 of 0xf0c57e...) from 0, allowing re-init by attacker to overwrite owner, call diamondCut to inject malicious facet with pullERC20, and drain approved USDC. 📌 Victim Contract: 0x0adc63e71b035d5c7fdb1b4593999fa1f296f1b2 📌 Vulnerable Facet: 0x3ca79c1cf29b8d19f7c643bb6e6bc9c49762e70f 📌 Attacker EOA: 0x9f49591a3bf95b49cd8d9477b4481ce9da68d5ca Attacker seized Diamond ownership and drained USDC from approved victims including 0x2e933518..., 0xa90714a1..., 0xeced2d37.... arbiscan.io/tx/0x19cbafae5… Powered by #SlowMist.AI
English
2
11
37
22.7K
Yishi
Yishi@ohyishi·
OneKey Anzen 安全实验室的研究已被 Black Hat USA 主会收录。 我们将演示如何从一个内存损坏漏洞出发,成功 Hack 一些市面上的主流硬件钱包。 即使它们有安全芯片、OTP/fuses、key sharding 和 defense-in-depth 等多层安全设计,攻击链仍然可以一路推进,直到最终破解出助记词。 这个漏洞并不是钱包厂商自己的业务代码,而是一个被广泛复用的 SoC 厂商 USB reference SDK,属于供应链级的风险。POS 终端、读卡器、可信嵌入式设备,只要建立在类似 SDK 之上,都可能暴露在同一类攻击面里。 我们在做这项研究时还有个很有意思的点,即,在没有 JTAG、没有 SWD、没有任何硬件调试接口的前提下,深度使用特定 LLM 模型参与了 memory leak 分析、firmware memory layout 推断、payload 迭代、权限提升,直到最终破解出助记词。AI 在压缩真实漏洞研究和利用开发的周期,意味着硬件安全也必须上强度。 Anzen 团队已向相关团队负责任披露,待受影响的厂商完成修复后,我们会分享更多研究细节。 #from-8-bytes-to-full-compromise-ai-assisted-exploitation-of-a-widespread-usb-flaw-in-a-dual-se-hardware-wallet-52311" target="_blank" rel="nofollow noopener">blackhat.com/us-26/briefing…
Yishi tweet media
中文
11
9
98
12.6K
郭宇 guoyu.eth
郭宇 guoyu.eth@turingou·
我做一回大善人,好心推广下这些说我做的都是垃圾套壳项目的吊毛做的东西
郭宇 guoyu.eth tweet media郭宇 guoyu.eth tweet media郭宇 guoyu.eth tweet media郭宇 guoyu.eth tweet media
中文
40
3
284
89.5K
aiiii.sol
aiiii.sol@xiaolinnihao·
@evilcos 老师可以试试gemini3.1-flash-lite,做主agent,然后开多个sub-agent调用那些模型接任务,lite 的gemini又快又强适合下发
中文
1
0
3
1.2K
Cos(余弦)😶‍🌫️ retweetledi
SlowMist
SlowMist@SlowMist_Team·
🚨 MistEye Security Gate Officially Released|Building Frontline Security Detection for AI Agents SlowMist has officially released MistEye Security Gate, a pre-execution security gateway Skill that provides security detection capabilities for dependency installation and domain access for mainstream #AI coding agents such as @claudeai , @cursor_ai , and @OpenAI GPT. 👉github.com/slowmist/miste… MistEye Security Gate enables: 🔹 Supply chain package risk detection (npm/pypi/go etc.) 🔹 Real-time scanning of domains/URLs/IPs/emails 🔹 File hash & malicious Skill/MCP identification 🔹 Hard blocking mechanism + daily automated inspections Core Scenarios Covered: - Dependency installation checks (requirements.txt, package.json, etc.) - External link / domain threat validation - Continuous security inspection of installed Skills How to Deploy: 1️⃣ GitHub Repo: github.com/slowmist/miste… 2️⃣ Get free API Key: app.misteye.io/api-keys 3️⃣ Set MISTEYE_API_KEY (env var preferred, or config file with 600 permission) 🛡️ Why It Matters: It cuts off #AIAgent supply chain and external interaction risks at the source, strengthening the frontline defense. Ready to make your AI Agents run more securely? Welcome to integrate MistEye Security Gate! 🔗 Full article: slowmist.medium.com/misteye-securi…
SlowMist tweet mediaSlowMist tweet mediaSlowMist tweet mediaSlowMist tweet media
English
0
8
26
7.4K