0xCarl

3.7K posts

0xCarl banner
0xCarl

0xCarl

@lccarllee

Rujira,RUNE本位主义者

1光年 Katılım Kasım 2016
744 Takip Edilen479 Takipçiler
Sabitlenmiş Tweet
0xCarl
0xCarl@lccarllee·
比特币:私钥即产权 门罗币:隐私即自由 RUNE+RUJI:无审查即市场 产权,自由,市场, 共同构建人类历史的加密时代。
中文
0
0
2
81
0xCarl retweetledi
THORChain
THORChain@THORChain·
THORChain incident update #2 We have become aware of multiple fake accounts and false information circulating regarding “refunds”, “airdrops”, compensation claims, and other alleged initiatives. To be absolutely clear: - Initial findings indicate that no user funds were lost in the incident - THORChain is currently conducting no refund, airdrop, or compensation program - Any account claiming otherwise is impersonating THORChain or spreading misinformation. Please rely only on official THORChain communication channels for updates. THORChain contributors are still actively investigating the recent incident alongside THORSec and external security partners. More information will be shared as the investigation progresses.
English
17
43
212
12.9K
0xCarl retweetledi
C. ₿utt 📵
C. ₿utt 📵@ctbutt114·
@Airdrops_one For external matters, does Ethereum Foundation halt Ethereum? Why is it only a concern when Thorchain acts neutral? Meanwhile, protocol exploit requires immediate action. Are you suggesting they should've sat back and let more be taken? Apples to oranges comparison.
English
1
1
12
291
0xCarl retweetledi
Rujira
Rujira@RujiraNetwork·
Earlier today, one of @THORChain's Asgard Vaults was compromised, resulting in a loss of approximately $10.7m worth of assets, followed by the halting of THORChain. As the App Layer on top of THORChain, this also impacts Rujira and our Secured Assets, and for now the chain and its products are halted until the bug has been resolved and a plan is in place. Once we have more information to share about the next steps, we will share it with the community. If you would like to follow the discussion or have any questions, we advise you to join the Rujira Telegram chat and the THORChain Dev Discord. We want to emphasize that, no matter what, we are not going anywhere. The vision of omnichain DeFi is still very much alive, just as it was yesterday, and we firmly believe both THORChain and Rujira will come out of this stronger.
THORChain@THORChain

Important Announcement Trading on THORChain is currently halted after a vault was compromised. Initial indications are user funds are safe and only protocol owned funds are affected. The network automatically detected abnormal behavior and halted signing activity, which alerted the broader community and prevented further outbound transactions. The investigation is still ongoing to determine the root cause. Contributors are actively working on the issue and we will report updates as we progress toward a solution. What we currently know: * One of the six Asgard vaults appears to have been compromised. * Current estimates place the loss at approximately $10.7m USD * The network automatically detected the abnormal behavior and halted signing activity, preventing further outbound activity. * Nodes securing the vault were subject to their bonded RUNE being slashed as a result of the unauthorized outbound transactions. * Churn activity has been paused while the investigation and remediation efforts are ongoing. * Onboarding additional chains and operations requiring churns will be delayed until the network is stabilized. * Initial indications show no individual user swaps were affected. We are asking all node operators to immediately review their infrastructure, hosts, key management systems, and operational security for any signs of compromise or abnormal behavior, and to report anything suspicious in Discord. Node operators participating in the affected vault are requested to securely provide Bifrost logs to the dev team for analysis using 'make relay' .

English
6
9
113
6.4K
0xCarl retweetledi
Vini B |「 thecoding 」
Vini B |「 thecoding 」@vinibarbosabr·
THORChain had ~$10M drained from one of its vaults Let's take a look at what happened, the exploit, and the interesting timeline of another vault churn/migration security issue discussed in @THORChain's gitlab that I discovered earlier today and posted below THORChain is one of the most used decentralized cross-chain networks, which makes these events super relevant to the entire ecosystem! According to @theoblivionsage's analysis, the attacker was able to get `_vaultAllowance` over a THORChain vault during what looked like a legit ERC20 vault migration Allowance was given via an Ethereum transaction caling the `transferAllowance()` function, allowing the attacker to sign outbound transactions from this THORChain vault they now control Think of it like a company that has a bank account this account has a password that allows to move the money out of the account, according to the company's needs the password is owned by one manager at a time, but it might change hands from time to time for security reasons or the company's protocol what happened here is that a thief managed to convince the company to make him the manager, getting access to the password during a routine migration -- and VUSH! they drained the account Interestingly, the attacker operated the vault as a legit validator for 2 days before executing the drain @banteg points the exploit to a commit (af46db22) from 6 days ago in the thornode repository by THORChain on gitlab: fix(common): sign full ObservedTx wrapper to prevent proposer forgery the rest is history (check my quoted post below) I really hope the THORChain devs can come out stronger from this hack (and I believe they will) as the chain and thorchain:native are really important to crypto's decentralization as a living ecosystem, in general I'll keep monitoring the situation and posting about it Make sure to follow me on X and subscribe for free to [en] thecoding.substack or [pt-br] codigoaberto.substack See ya!
Vini B |「 thecoding 」@vinibarbosabr

interesting timeline here in THORChain's repo an old issue related to vault churn/migrations has been reactivated in the context of a vault `transferAllowance()` exploit on @THORChain + security issue raised in Jan 2023 by Mr. Smith + Son of Odin closes the issue in Jul 2023 + Jack Zampolim proposes reopening it in Aug 2024 + a few discussions follow the reopening for a month + radio silence until 2 months ago + Son of Odin added a `priority` flag in Feb 2026 + THORChain gets hacked on May 15, 2026 for ~$10M + Mr. Smith adds a note a few hours after the attack: > "In light of recent events related to Thorchain vaults being exploited, will monitor and update this thread/issue with any relevant content, and be available for discussion of this if required." a video is coming discussing the hack and this thread before speculations begin: the issue described in this thread doesn't seen to be directly related to today's exploit on thorchain:native (and i'm not sure it's patch would have prevented what happened today), but it indeed addresses the broader attack surface that is vault churn/migration, which makes it relevant following recent events and worth working on THORChain devs have my support during these difficult times and i'm sure they will come out stronger from it -- i also respect a lot revisiting old, related issues

English
5
12
58
5.8K
0xCarl retweetledi
Oblivion Sage
Oblivion Sage@theoblivionsage·
@eridanus_dev @PeckShieldAlert @THORChain you're right, vault addrs come from TSS keygen. updated the writeup after reviewing patch af46db22. actual vector was proposer forgery, bifrost only signed inner Tx not the ObservedTx wrapper, inbound bit wasn't signed so a proposer could forge observations during churn.
English
0
1
4
150
PeckShieldAlert
PeckShieldAlert@PeckShieldAlert·
#PeckShieldAlert @THORChain has been exploited for ~$10M worth of crypto, including 36.75 $BTC ($3M) and ~$7M worth of assets from #BNBChain, #Ethereum, and #Base. The stolen funds mainly sit in: bc1ql4u94klk265lnfur2ujk9p6uh52f2a8jhf6f37 0xd477b69551f49C0519F9B18c55030676138890Bd
PeckShieldAlert tweet media
English
22
45
170
54.6K
0xCarl
0xCarl@lccarllee·
@jpthor truly become the necessary tokens to access that ecosystem, thereby driving genuine growth in usage demand. Furthermore, it would be best if the two tokens — RUNE and RUJI — could eventually merge into one.
English
0
0
0
25
0xCarl
0xCarl@lccarllee·
@jpthor who want to become nodes. The real untapped demand that needs to be developed is usage demand. This requires promoting the growth of the application layer on top of the Rujira ecosystem. Only when there is a thriving app ecosystem built on the Rujira platform can RUNE and RUJI
English
1
0
0
26
JP
JP@jpthor·
$XMR live on chainnet. 4-node testing network but real funds. we continue testing...
JP tweet media
English
24
35
320
45.6K
JewBiz
JewBiz@JewBizLogic·
你什么时候意识到自己没见过世面? 去泰国之前,我以为自己见过一些东西。 去了之后才知道,我什么都没见过。 那些橱窗里密密麻麻的肉体,上千人的酒池肉林,街角躺在地上飞翔的白种人,还有他们身边醉生梦死的泰国女孩。 我突然理解了一件事—— 在很多地方,很多人,是连选择的机会都没有的。 不是不努力,不是不想改变。 是从生下来那一刻,路就已经被定死了。 印度的贱民是这样。泰国贫苦家庭的女儿也是这样。 那一刻我第一次觉得,能有得选,本身就是一种奢侈。
中文
52
16
267
77.9K
Cindy胖迪🥰
Cindy胖迪🥰@CindyCreation·
可怕的 #优绩主义者,连结婚都要标上自己的学校和学位。 这群人是不是除了学历没有什么拿得出手的? 我想问左上角那个是没有学历吗?为什么不给别人标呢?是觉得人学校不够好吗? 恨不得每天都说自己是清北上交的这这种人一般没两把刷子。
Cindy胖迪🥰 tweet media
中文
68
0
39
8.7K
0xCarl
0xCarl@lccarllee·
@BTCBruce1 multicoin之前吸筹完毕现在拉盘出货呢
中文
0
0
0
431
Bruce J
Bruce J@BTCBruce1·
$ZEC 连涨10天 虽挖,仍百思不得其解 于是问了几个矿友 他们说CZ案后 有相当一部分人觉得比特币原来不靠谱 还能被没收? 于是把目光转向了隐私币 门罗是刘禅 ZEC更像孙权 园区本无国界 铁丝网不认护照 电棍不在乎你说什么语言 KPI对全人类一视同仁 所以 $ZEC = $BTC ?
Bruce J tweet mediaBruce J tweet media
中文
125
8
107
49.6K
0xCarl retweetledi
fincontrarian
fincontrarian@fincontrarian·
Coinbase was down for 5+ hours today because of AWS infrastructure problems. 😬 Think about that for a second. One overheated data center… And one of the biggest crypto exchanges on earth stops working. 🚨 No trading. No access. No “financial freedom.” That’s the weakness of centralized infrastructure. Meanwhile, @THORChain keeps swapping billions in native assets through a decentralized network of independent nodes spread globally. ⚡️ No single server. No AWS dependency. No CEO pressing pause. No company office you can unplug. That’s why THORChain is becoming the DEX of DEXes. 🧠 While CEXs: • freeze • halt withdrawals • go offline during volatility • rely on cloud providers THORChain keeps doing what crypto was supposed to do from day one: Permissionless liquidity. Native asset settlement. 24/7 unstoppable markets. 🔥 BTC ↔ ETH ETH ↔ ATOM LTC ↔ DOGE Soon: ZEC ↔ XMR ↔ DASH 👀 No bridges. No wrappers. No custodians. The irony? People call THORChain “dangerous” while centralized exchanges can literally disappear for hours because a server room got too hot. 😭 That’s the difference between: “crypto company” and actual decentralized infrastructure. $RUNE #THORChain
English
2
9
18
538
0xCarl retweetledi
0xCarl
0xCarl@lccarllee·
RUNE和RUJI是人类历史上第一次真正意义上构建了无审查的金融市场。 把BTC的“私钥即产权”,XMR的“隐私即自由”等理念真正的融合在了一起。
fincontrarian@fincontrarian

Funny how every cycle people say privacy coins are dead… and then suddenly $XMR, $ZEC and $DASH start ripping again. 👀 Delisted, attacked, ignored for years — yet they’re still here. Because there will always be demand for privacy and permissionless money. And now they finally have a place where they can all connect together: @THORChain ⚡️ No bridges. No wrapped versions. No asking anyone for permission. Just native cross-chain swaps powered by $RUNE. Honestly feels like the market is slowly realizing what’s coming: $XMR + $ZEC + $DASH liquidity all flowing through the same decentralized protocol. 🔥 The most hated coins connecting to the most hated protocol was inevitable. $RUNE isn’t competing with them. It’s becoming the unifier for all of them. 🟠

中文
0
0
2
57
0xCarl
0xCarl@lccarllee·
@lianyanshe 高周转率是原因?不,高周转率是结果,原因是品牌信任建立起来的巨大客流量。
中文
0
0
1
79
链研社|AI First🔶💧
今天去路过了永辉超市,看到胖改店把永辉超市给坑惨了。胖东来把成功归结于真诚和爱这是商业上最大的谎言,永辉超市学了这套还真是被忽悠瘸了。永辉客流少的可怜,还学什么提供品质服务,只增加成本而没有办法回收。 胖东来的本质是一个拥有极高商品周转率、极低损耗率、且具备局部垄断定价权的非典型零售综合体。它的成功从来不是因为温情。 传统商超综合毛利率通常在20%左右。胖东来账面毛利率并没有大幅甩开行业平均水平。真正让它赚到大钱的,是远超同行的资金效率。 靠的高周转和低库存,零售业的本质是资金效率游戏。传统超市标品在货架上躺30到45天才能卖出,资金占用成本极高。胖东来凭借巨大客流,商品周转天数极短,很多爆款按天甚至按小时周转。 假设两者毛利率都是20%,永辉某笔资金一年周转6次,胖东来一年周转20次。同一笔本金,胖东来一年滚出400%毛利总额,同行只能滚出120%。有庞大现金流的来源,现金直采压低价格。 高周转→低进货价→高薪酬→高服务→更多客流 胖东来的DL系列,精酿啤酒、烘焙糕点、果汁。贡献了30%的销售额,却远不止30%的利润。砍掉中间商,加上信任溢价,这些自有品牌的毛利率高于 20 %。 所以它的商业逻辑从来不是真诚换市场,而是信任=溢价+高周转=资金效率碾压。 永辉为什么学不会 2025年永辉亏损25.5亿元,五年累计亏损逼近120亿元,资产负债率88.96%。它不是不努力,调改了284家门店,关了381家,力度不可谓不大。 但再怎么样都没办法用菜市场的毛利,去硬扛奢侈品的服务成本。 一线城市核心商圈的租金是许昌的5到8倍,胖东来是自持物业,客流量远没有胖东来的密度,两者仅这点成本就差了 10 倍,达到盈亏平衡线的要求也提高 10 倍。周转一慢,生鲜损耗就上去;损耗上去,净利润就被吃掉。永辉在慢周转+高损耗+高店租的泥潭里。 更残酷的是,它学的是表——高薪酬、缩短营业时间、无理由退换。 却没学到里,三线城市的低地租+超高客流带来的极速周转+信任溢价支撑的自有品牌定价权。抛开财务模型强行增加人工和服务成本,现金流必然瞬间枯竭。 永辉的困境,也不是不够真诚,从财务模型从根本上就不兼容。
链研社|AI First🔶💧 tweet media
中文
70
26
206
90.9K
0xCarl
0xCarl@lccarllee·
God bless everyone that love liberty.
Haily Copper 🚁@HailyCopper

It’s wild they gave @stablekwon 15 years. Look, I was a heavy investor in $Luna terra-luna:native in the early days, buying well below 50 cents and riding it all the way up past a $100. I believed in the vision letting regular people like all of us act as our own central bank instead of feeding a selected few. Station, Anchor, Mirror, plus more all of it was light years ahead in UI and growing like crazy. They didn’t take him down because he was a fraud. They crushed him because it was working too well and growning way too fast. Do Kwon himself always said he was a heavy investor in THORChain, and now you can clearly see why. His project ultimately failed, and they made an example out of him. But this right here is our second chance, and I genuinely believe it’s where people can actually benefit this time. @THORChain , built by @jpthor and @CBarraford Over 90 fully decentralized nodes and growing! staying true to that pure Bitcoin ethos no single point of failure, no one in control. You can swap native $BTC for native $ETH or any other crypto, straight from your wallet, no wrapping, no bridges, no middleman. Liquidity providers earn real yield from real trading fees. It’s survived every crash and come out stronger. Now @RujiraNetwork $Ruji is on top, bringing collateralized lending, arbitrage, on chain orderbooks, and even a Bitcoin backed stablecoin in the works. Everything fully decentralized, all in your own control. This isn’t just another fake defi play. This is the real shot for normal people to win in a new financial system. The elites got their scapegoat from @stablekwon. They’re not getting this one. God bless @dokwon and his family. We know what his true intentions were. If you’ve been waiting for the right moment, this is it. Don’t sleep on THORChain $Rune and Rujira $Ruji. I see this as the nextbig chance we the people have. God bless 🙏

English
0
0
1
28
0xCarl retweetledi
AstroBoy🔮⚡️
AstroBoy🔮⚡️@fevrdad·
I don’t hold any altcoins anymore, BUT, I need to admit that the $RUNE ecosystem is the most battle-tested and resilient in the space. Both $RUNE and $RUJI have survived black swan events and follow Satoshi’s vision closely. They’re the last standing in a space full of scams and greed. That’s why I hope they win. If you support privacy and TRUE DeFi, you should support them. @jpthor @markfromdenmar_
AstroBoy🔮⚡️ tweet media
English
8
56
280
12.6K