Diep Pham
215 posts



Wormable Substack XSS: blog.calif.io/p/wormable-sub… It must have been years since the last time a wormable XSS was found in a major social media website. This beautiful type confusion XSS attack vector is a gift that keeps on giving. But most of all, @samykamkar is our hero!

Type confusion attacks in ProseMirror editors blog.calif.io/p/type-confusi…






In the past month, KyberSwap has faced unprecedented challenges due to the Elastic exploit. Despite this, I am grateful to say that our core business, including the Aggregator and Limit Order functions, remains robust. Moreover, we will soon be launching our Zap API, an innovative development that will enable dApps, wallets, and other projects to become the most convenient gateways for their users to access DeFi liquidity protocols. This development underscores our commitment to not only sustaining our platform, but also to continuing to contribute to the wider DeFi ecosystem. However, due to the Elastic exploit, in a move to stand by affected users, we implemented the KyberSwap Elastic Exploit Treasury Grant Program to cover up to 100% of users’ losses. We have also made significant changes in our business operations to ensure we are well positioned to continue on a sustainable path forward, including temporarily pausing our liquidity protocol initiatives and KyberAI project. Regrettably, we have also reduced our workforce by 50%. The past few days have been among the most challenging in my journey as an entrepreneur. The decision to part ways with so many of our team members was heart-wrenching. Each individual is not only highly skilled, but also deeply committed to advancing DeFi and bringing tangible value to end-users. Their unwavering dedication during these tough times has shown great character and passion for the industry. Such talent and integrity are rare in our fast-paced, profit-driven industry. To support our departing team members, we are creating a voluntary database to connect them with potential opportunities in the web3 space. I highly recommend that fellow web3 founders consider these exceptional individuals for their teams. They are not only capable, but also bring a level of commitment and integrity that is invaluable. @KyberNetwork


@DzLe77 Last twelve hours measurement in HN. As usual, the culprit is biomass burning around HN.

Calif Inc: Privilege escalation in AWS Elastic Kubernetes Service blog.calif.io/p/privilege-es…



Now I’m building my own businesses, I realize how absurd it is for an “idea” guy to get 90% equity of a new tech startup.

Success! ToChim was able to exploit a permissive list of allowed inputs against the Samsung Galaxy S23. They earn $25,000 and 5 Master of Pwn points. #Pwn2Own






