quik

780 posts

quik banner
quik

quik

@itsmequik

Katılım Şubat 2011
406 Takip Edilen52 Takipçiler
quik retweetledi
quik retweetledi
Zach Rynes | CLG
Zach Rynes | CLG@ChainLinkGod·
You are ignoring the elephant in the room LayerZero Labs’ centralized infrastructure was infiltrated by North Korea, which resulted in a $292 million bridge exploit How did this massive security failure, which occurred on your infrastructure, take place exactly? Rather than throwing Kelp under the bus, again, maybe you can address some of these points: 1. How exactly did North Korea (DPRK) gain access to your core node & RPC servers on your supposedly hardened infrastructure? What was their initial access? 2. How did your endpoint detection (EDR) and cloud monitoring not detect this intrusion? Were these not running in these critical systems? 3. How long did the DPRK have persistence on the LayerZero infrastructure without being detected? 4. What other systems, data, code, and internal sensitive customer information did they access? If they were on your cloud infra, it stands to reason they also had access to your internal tools (GDrive, Email, Slack, etc). 5. Will you or LayerZero Labs take responsibility for these security failures or has your legal counsel advised you not to comment to avoid accepting liability?
English
11
31
451
24.4K
quik retweetledi
Kelp
Kelp@KelpDAO·
After the recent LayerZero exploit, we are taking steps to ensure rsETH is fully secure, which is why we are migrating to @chainlink CCIP. From the April 18 incident, it is clear that LayerZero's own infrastructure was exploited, resulting in $300M in losses across DeFi. Independent reports from SEAL 911, Chainalysis, and other major leading security researchers all point to the same origin. There are questions that the ecosystem deserves answers to. And we are ensuring rsETH is secured by infrastructure that doesn't leave these questions open. That’s why we’re setting the record straight.
Kelp@KelpDAO

x.com/i/article/2051…

English
206
234
1.3K
336.1K
quik retweetledi
Mikko Ohtamaa
Mikko Ohtamaa@moo9000·
Narrator: Most of the LayerZero configs were 1/1. It should not come as a "surprise" for the LayerZero foundation CEO. Multiple security researchers have warned about this for years. LayerZero did not just ignore warnings; it actively shot the messengers. Here: x.com/donnoh_eth/sta… Here: x.com/banteg/status/… Here: x.com/_prestwich/sta… Here: uniswap.notion.site/Bridge-Assessm… etc. In LayerZero, the zero stands for zero spine and 100% bullshit.
Bryan Pellegrino (臭企鹅)@PrimordialAA

I’ve been asking myself why has it taken me so long to write this? Ultimately I still carry a huge amount of cognitive dissonance here. In my mind LayerZero the protocol was like Gnosis Safe and the application was setting their config, and who the )@(!$ would secure billions in TVL on a 1/1? I even tweeted about it, literally 0, I would have bet almost anything on that because almost every major application we helped setup their configs. Someone then going and manually changing that to a 1/1 was outside of the realm of possibility for me. I was wrong. It’s easy to sit back and say ‘it’s just a protocol we have no control over how people use it’ but we have the opportunity to be better. There was a conversation this week speaking to a customer and they just… screamed at me, at the top of their lungs, and swore for a solid ~3-5 minutes straight. We had implemented additional security measures of forcing a more stringent RPC quorum and forcing every chain to provide multiple RPCs and we had done it without telling them and it !)@$d with their business, which frankly is a deadly sin. We had messed with their business and they said communication wise we were completely blowing this. They were completely right. This is something I care about a ton, it is both the result of a huge portion of my life and something that I fundamentally believe in. I literally gifted a copy of Unreasonable Hospitality to every single manager in the company. The entire point of what we’ve built is to enable others to build on top of it, it is to provide a protocol and a platform for people to build on, and we’ve been failing some of our largest customers. The past two weeks have been unbelievably miserable. I’m incredibly grateful for all of the applications who have worked with us over the past 2 weeks, for @zeroshadow_io who has spent endless cycles with us tracking and seizing millions in attacker funds which will be returned to the rsETH team, and for all of the parties who brought together DefiUnited. Particularly @aave for leading and @MikeSilagadze for pushing everyone to get their !@)($ together and sort things out as quickly as possible, and putting himself in the frontline of acquisition talks and everything else to try to get to a solution quickly. @LayerZero_Core is one of the most critical pieces of infrastructure in the industry, the LayerZero protocol has earned the trust of the largest and most important asset issuers in the space. We will do better and we will make the industry better for it. My entire focus over the past 2 weeks has singularly been working with applications to harden their setup, building tooling to assist in tracking and freezing hacker funds, and the rsETH recovery efforts. That is going to shift now to where LayerZero Labs spends it's time and effort. The only thing this company will spend time on is how we can better serve our asset issuers and the upcoming launch of Zero.

English
14
17
211
13.3K
quik retweetledi
Zach Rynes | CLG
Zach Rynes | CLG@ChainLinkGod·
Rather than provide additional info on how and why LayerZero Labs' centralized infrastructure was infiltrated by North Korean (DPRK) hackers, which resulted in the $292M rsETH bridge exploit Bryan decides throwing the user under the bus the first time wasn't good enough, they just had to do it again for good measure! All for the crime of trusting the LayerZero Labs team and their infra, using a 1/1 config that ~50% of LZ OApps use (per @Dune), that the LZ Labs DVN supported (until it was blocked), and that the LZ Labs team monetized (DVN fees) Why take responsibility, and therefore legal liability, over the exploit when finger pointing is just as good 👆👉👇👈 And nevermind the fact that there are multiple chains in the LZ docs where the LZ Labs DVN is the only one listed, and therefore the only possible config ! Why did the LZ Labs DVN support a 1/1 config up until now if it was such an obviously dangerous thing? Why isn't this config blocked at the protocol level if its always been so obviously bad? People have been pointing out the massive centralization problem in the LayerZero ecosystem for YEARS now, including the 2/2 multisig Stargate bridge run by the LZ Labs team (does anyone genuinely think a 2/2 multisig bridge setup is really all that much better than 1/1?) But only after the $292M bridge hack is such centralization now such an obvious risk, give me a break Why should anyone integrate LayerZero, knowing they're going to be thrown under the bus as disposable meat the moment the LZ Labs fucks up and gets hacked by North Korea?
Zach Rynes | CLG tweet media
Bryan Pellegrino (臭企鹅)@PrimordialAA

I’ve been asking myself why has it taken me so long to write this? Ultimately I still carry a huge amount of cognitive dissonance here. In my mind LayerZero the protocol was like Gnosis Safe and the application was setting their config, and who the )@(!$ would secure billions in TVL on a 1/1? I even tweeted about it, literally 0, I would have bet almost anything on that because almost every major application we helped setup their configs. Someone then going and manually changing that to a 1/1 was outside of the realm of possibility for me. I was wrong. It’s easy to sit back and say ‘it’s just a protocol we have no control over how people use it’ but we have the opportunity to be better. There was a conversation this week speaking to a customer and they just… screamed at me, at the top of their lungs, and swore for a solid ~3-5 minutes straight. We had implemented additional security measures of forcing a more stringent RPC quorum and forcing every chain to provide multiple RPCs and we had done it without telling them and it !)@$d with their business, which frankly is a deadly sin. We had messed with their business and they said communication wise we were completely blowing this. They were completely right. This is something I care about a ton, it is both the result of a huge portion of my life and something that I fundamentally believe in. I literally gifted a copy of Unreasonable Hospitality to every single manager in the company. The entire point of what we’ve built is to enable others to build on top of it, it is to provide a protocol and a platform for people to build on, and we’ve been failing some of our largest customers. The past two weeks have been unbelievably miserable. I’m incredibly grateful for all of the applications who have worked with us over the past 2 weeks, for @zeroshadow_io who has spent endless cycles with us tracking and seizing millions in attacker funds which will be returned to the rsETH team, and for all of the parties who brought together DefiUnited. Particularly @aave for leading and @MikeSilagadze for pushing everyone to get their !@)($ together and sort things out as quickly as possible, and putting himself in the frontline of acquisition talks and everything else to try to get to a solution quickly. @LayerZero_Core is one of the most critical pieces of infrastructure in the industry, the LayerZero protocol has earned the trust of the largest and most important asset issuers in the space. We will do better and we will make the industry better for it. My entire focus over the past 2 weeks has singularly been working with applications to harden their setup, building tooling to assist in tracking and freezing hacker funds, and the rsETH recovery efforts. That is going to shift now to where LayerZero Labs spends it's time and effort. The only thing this company will spend time on is how we can better serve our asset issuers and the upcoming launch of Zero.

English
19
50
371
31.1K
quik retweetledi
Wilson
Wilson@Wilson19947653·
>get seeded from SBF and Alameda >run infra from moms basement >play poker with every industry player insisting infra is decentralized >fast forward 4 years, LZ underpins a good segment of crypto >North Korea exploits LZ infra and $300M is poofed away >gaslight and ask for pity
Bryan Pellegrino (臭企鹅)@PrimordialAA

I’ve been asking myself why has it taken me so long to write this? Ultimately I still carry a huge amount of cognitive dissonance here. In my mind LayerZero the protocol was like Gnosis Safe and the application was setting their config, and who the )@(!$ would secure billions in TVL on a 1/1? I even tweeted about it, literally 0, I would have bet almost anything on that because almost every major application we helped setup their configs. Someone then going and manually changing that to a 1/1 was outside of the realm of possibility for me. I was wrong. It’s easy to sit back and say ‘it’s just a protocol we have no control over how people use it’ but we have the opportunity to be better. There was a conversation this week speaking to a customer and they just… screamed at me, at the top of their lungs, and swore for a solid ~3-5 minutes straight. We had implemented additional security measures of forcing a more stringent RPC quorum and forcing every chain to provide multiple RPCs and we had done it without telling them and it !)@$d with their business, which frankly is a deadly sin. We had messed with their business and they said communication wise we were completely blowing this. They were completely right. This is something I care about a ton, it is both the result of a huge portion of my life and something that I fundamentally believe in. I literally gifted a copy of Unreasonable Hospitality to every single manager in the company. The entire point of what we’ve built is to enable others to build on top of it, it is to provide a protocol and a platform for people to build on, and we’ve been failing some of our largest customers. The past two weeks have been unbelievably miserable. I’m incredibly grateful for all of the applications who have worked with us over the past 2 weeks, for @zeroshadow_io who has spent endless cycles with us tracking and seizing millions in attacker funds which will be returned to the rsETH team, and for all of the parties who brought together DefiUnited. Particularly @aave for leading and @MikeSilagadze for pushing everyone to get their !@)($ together and sort things out as quickly as possible, and putting himself in the frontline of acquisition talks and everything else to try to get to a solution quickly. @LayerZero_Core is one of the most critical pieces of infrastructure in the industry, the LayerZero protocol has earned the trust of the largest and most important asset issuers in the space. We will do better and we will make the industry better for it. My entire focus over the past 2 weeks has singularly been working with applications to harden their setup, building tooling to assist in tracking and freezing hacker funds, and the rsETH recovery efforts. That is going to shift now to where LayerZero Labs spends it's time and effort. The only thing this company will spend time on is how we can better serve our asset issuers and the upcoming launch of Zero.

English
6
8
171
14.1K
quik retweetledi
SilverSwap
SilverSwap@SilverSwapDex·
Seems like @SiloFinance is failing its community airdrop allocations still unpaid, oracle issues surfacing repeatedly, and instead of transparency, anyone asking questions gets removed from Discord. Where is the accountability here? @SonicLabs openly having a partnership with these guys. @michaelfkong @AndreCronjeTech - will you address these concerns, or remain silent while this continues? Lack of communication and accountability only erodes trust further. Does trust even remain ? Or hey just throw out some metrics and the "people" will be happy #DeFi #Crypto #Airdrop #Transparency #Web3 #CryptoCommunity #DeFiAccountability #Blockchain #Trust #DoBetter
SilverSwap tweet media
English
6
7
45
3.1K
quik retweetledi
SilverSwap
SilverSwap@SilverSwapDex·
Dear @SiloFinance, Will we ever receive the airdrop we earned, or was the plan just to ban us from Discord and ignore your own commitments? 🤔 We staked over 500,000 S with your platform in good faith and in return, we’ve received nothing. No transparency, no communication, just silence. 🚫 This isn’t how you treat your community. Do better. ⚠️ Guess the reasons why @SonicLabs is partnering with them because the thought process aligns . #Crypto #DeFi #Airdrop #Transparency #Web3 #CryptoCommunity
SilverSwap tweet media
English
10
5
63
5.4K
quik
quik@itsmequik·
@LayerZero_Core So what is L0's contribution? Any details at all?
English
1
0
19
4.4K
LayerZero
LayerZero@LayerZero_Core·
As part of an industry-wide recovery initiative, LayerZero's proposed contribution would go towards the best path forward to restoring rsETH backing. We have been closely coordinating with Aave and all other parties like EtherFi, Ethena, Arbitrum, and Kelp who have been working tirelessly to ensure the best possible outcome for crypto.
LayerZero tweet media
English
136
132
657
245.8K
quik retweetledi
ZachXBT
ZachXBT@zachxbt·
Did you really just accidentally say that Thorchain was centralized for all of those years while DPRK laundered hundred of millions while raking in millions of fees with an admin key you held in your possession?. Cannot wait until your post shows up in an court indictment one day.
English
61
53
1.1K
119.8K
quik retweetledi
Zach Rynes | CLG
Zach Rynes | CLG@ChainLinkGod·
To be clear: North Korean hackers infiltrated LayerZero Labs’ centralized infrastructure and stole $290M Rather than explain how that happened, LZ put out a statement carefully worded by lawyers to minimize their liability and threw KelpDAO under the bus for trusting them
English
43
96
1.1K
63.5K
Pokerbots
Pokerbots@Pokerbots1·
Ok so this has been up for nearly 2days and not one public response from @CoinPoker_OFF or their ambassadors Specifically @padspoker made some public commitments back in 2024 attached in screenshots @ToddWitteles @mariomosboeck @CaitlinComeskey @BlaiseBourgeois @Charlie_Carrel
Pokerbots tweet mediaPokerbots tweet mediaPokerbots tweet mediaPokerbots tweet media
Pokerbots@Pokerbots1

1/6 COINPOKER WHO REALLY CONTROLS YOUR MONEY ? @mariomosboeck @padspoker @CaitlinComeskey @BlaiseBourgeois @ToddWitteles @junglemandan @Nick_Palma1010 @TomDwan @KatieStonePoker @RealKidPoker @Charlie_Carrel @BobbyJamesPoker

English
3
1
6
7.3K
Benoit Dubosson
Benoit Dubosson@beniduboss·
Somebody could make a good business by making a privacy focused, no data kept, business that analyses people’s DNA and offers a full comprehensive report on it The machine is 5k, which still would make sense for people like me, but is too high of a barrier for most Keep no logs, work with an established lab or find a way to do it yourself, automate full report to share to customers Could do this in 2 days working with 3rd party labs in Switzerland Once you scale you could offer to create custom pills for each patient needs One of you should do this
Seth Howes@SethSHowes

I’ve wanted to do this for a decade. But I never did - I refuse to give any company my DNA. It is me. So this week I sequenced my genome entirely at home. Literally on my kitchen table. I never exposed my DNA sequence to the internet. Not at any point. I used a MinION to do the sequencing (it’s smaller + weighs less than an iPhone). I used open-source DNA models for the analysis (Evo2 and AlphaGenome) running locally on a DGX Spark and Mac Studio. I traced mechanisms behind my family’s multigenerational autoimmune conditions that no clinician has been able to understand. When I set out to do this I didn’t know if it would actually work. It does. Your genome is the most private data you will ever have. You probably shouldn’t let it leave your house.

English
18
5
119
27.1K