ً

7.8K posts

ً

ً

@lightclients

@go_ethereum

utc-6 Katılım Kasım 2010
1K Takip Edilen13K Takipçiler
ً
ً@lightclients·
@fede_intern did i present it wasn’t complicated ?
English
1
0
12
939
ً
ً@lightclients·
@Fricoben @safe how do you compare proving an invariant of an already battle-tested and hardened contract vs. developing new protocols from scratch and proving them on the way?
English
1
0
0
15
fricoben
fricoben@Fricoben·
Tldr: it works very very well. Before AI, the @safe owner reachability invariant took specialists days or weeks to prove, easily ten of thousands in human cost. We gave it to Claude Opus with some intuition on the proof strategy. 40 minutes ~ $12
English
2
0
2
131
fricoben
fricoben@Fricoben·
We spent the last few weeks formally verifying smart contract invariants across Ethereum protocols using AI and Lean. Here's the methodology and what we learned 🧵
fricoben tweet media
English
1
9
41
3.1K
ً
ً@lightclients·
@MicahZoltu @hazae41 @PatrickAlphaC The only benefit I can see is if you want a better display than the hardware wallet can really offer to see the transaction. But it’s a weird trade off IMO to go from a secure platform to m of n untrusted devices just to check QR code result.
English
0
0
0
29
Micah Zoltu
Micah Zoltu@MicahZoltu·
@hazae41 @lightclients @PatrickAlphaC If you are talking about dapps, they should be treated as entirely untrusted from the start. If you are talking about a browser or wallet compromise, then the attacker can present whatever QR they want (different from what is sent to hardware wallet for signing).
English
1
0
2
42
Lee Ash
Lee Ash@hazae41·
Brume Wallet will soon display a hash of whatever you are prompted to sign, and provide a QR code to verify it on other devices or tools, so you can detect when some device or tool is compromised erc8213.eth.limo/?mode=typed#/v…
English
1
1
11
830
ً retweetledi
Mitchell Hashimoto
Mitchell Hashimoto@mitchellh·
I strongly believe there are entire companies right now under heavy AI psychosis and its impossible to have rational conversations about it with them. I can't name any specific people because they include personal friends I deeply respect, but I worry about how this plays out. I lived through the great MTBF vs MTTR (mean-time-between-failure vs. mean-time-to-recovery) reckoning of infrastructure during the transition to cloud and cloud automation. All those arguments are rearing their ugly heads again but now its... the whole software development industry (maybe the whole world, really). It's frightening, because the psychosis folks operate under an almost absolute "MTTR is all you need" mentality: "its fine to ship bugs because the agents will fix them so quickly and at a scale humans can't do!" We learned in infrastructure that MTTR is great but you can't yeet resilient systems entirely. The main issue is I don't even know how to bring this up to people I know personally, because bringing this topic up leads to immediately dismissals like "no no, it has full test coverage" or "bug reports are going down" or something, which just don't paint the whole picture. We already learned this lesson once in infrastructure: you can automate yourself into a very resilient catastrophe machine. Systems can appear healthy by local metrics while globally becoming incomprehensible. Bug reports can go down while latent risk explodes. Test coverage can rise while semantic understanding falls. Changes happens so fast that nobody notices the underlying architecture decaying. I worry.
English
513
1.9K
15.2K
1.5M
ً retweetledi
samczsun
samczsun@samczsun·
samczsun tweet media
THORChain@THORChain

Important Announcement Trading on THORChain is currently halted after a vault was compromised. Initial indications are user funds are safe and only protocol owned funds are affected. The network automatically detected abnormal behavior and halted signing activity, which alerted the broader community and prevented further outbound transactions. The investigation is still ongoing to determine the root cause. Contributors are actively working on the issue and we will report updates as we progress toward a solution. What we currently know: * One of the six Asgard vaults appears to have been compromised. * Current estimates place the loss at approximately $10.7m USD * The network automatically detected the abnormal behavior and halted signing activity, preventing further outbound activity. * Nodes securing the vault were subject to their bonded RUNE being slashed as a result of the unauthorized outbound transactions. * Churn activity has been paused while the investigation and remediation efforts are ongoing. * Onboarding additional chains and operations requiring churns will be delayed until the network is stabilized. * Initial indications show no individual user swaps were affected. We are asking all node operators to immediately review their infrastructure, hosts, key management systems, and operational security for any signs of compromise or abnormal behavior, and to report anything suspicious in Discord. Node operators participating in the affected vault are requested to securely provide Bifrost logs to the dev team for analysis using 'make relay' .

ZXX
17
31
385
29.6K
ً
ً@lightclients·
@pedrouid hermes gud
Català
0
0
1
330
Pedro Gomes
Pedro Gomes@pedrouid·
My personal agent journey… Jan 28: setup OpenClaw Jan 30: autonomous Feb 27: broke Feb 28: fixed Mar 10: quit Apr 11: added Codex Apr 15: quit again Apr 24: switched to Hermes Using Hermes nonstop since and it keeps improving daily… It’s 10x better than OpenClaw!
English
10
1
37
1.5K
ً
ً@lightclients·
@zxstim @_Enoch @z0r0zzz how would you authenticate the registry data on a hardware wallet if it's on chain?
English
0
0
0
33
ZxStim
ZxStim@zxstim·
@_Enoch @z0r0zzz a genius already put frontend code in smart contracts. why don’t we do that for clear signing registry?
English
1
0
2
82
ً retweetledi
banteg
banteg@banteg·
i look at pure research with a bit of contempt. it's for people who don't get their hands dirty and don't want to take the risks of seeing their idea perform in production. you just spent years in an insulated ivory tower, while others have a live feedback loop collecting data in the trenches.
English
14
8
118
13K
ً
ً@lightclients·
@hazae41 @0xSulfurix well I found flaws in your retarded tweet, so next consider publishing nothing thx
English
1
0
1
44
Lee Ash
Lee Ash@hazae41·
@lightclients @0xSulfurix Not my job, I am not even a researcher and I found obvious flaws in your retarded EIP, research more and publish better solutions next time, or just publish nothing and let developers build their own solutions, have a nice cope
English
1
1
0
153
Lee Ash
Lee Ash@hazae41·
So according to the EF, the solution to blind signing is... To make a centralized database of every smart contract on Earth... And gate it behind some council that can refuse some, Thanks the EF for making Ethereum centralized and corruptible clearsigning.org/build/
Ethereum Foundation@ethereumfndn

0/ Clear signing is now live. An open standard to end blind signing, making human-readable transactions default. This effort brings a major UX and Security upgrade to transaction signing on Ethereum.

English
3
1
14
3.8K
ً
ً@lightclients·
@hazae41 @0xSulfurix you sent like 10 tweets complaining about 7730 but you dont want to engage in an actual productive discussion about it? nice
English
1
0
1
44
ً
ً@lightclients·
@hazae41 @0xSulfurix To do 1) you would need to verify the authenticity of the scheme in the hardware wallet. Which means at minimum a light client running in the wallet. We theoretically have the tech to do this, but the devil is in the details. 2) is already 7730, but with a custom registry?
English
1
0
0
47
ً retweetledi
Ethereum Foundation
Ethereum Foundation@ethereumfndn·
0/ Clear signing is now live. An open standard to end blind signing, making human-readable transactions default. This effort brings a major UX and Security upgrade to transaction signing on Ethereum.
Ethereum Foundation tweet media
English
160
446
2.2K
316.8K
ً retweetledi
soispoke.eth
soispoke.eth@soispoke·
🔐 EIP-8250: Keyed Nonces for Frame Transactions 🔐 was just merged, also check out this nice EIP explorer 👀 eips.sh/eip/8250
English
7
6
49
2.5K
ً retweetledi
Ivo 7702/acc
Ivo 7702/acc@Ivshti·
EIP-7702 is the greatest marketing disaster in Ethereum history... - no mainstream (or any that I know of) wallet implements a flow for signing an arbitrary delegation - attackers use EIP-7702 once they have the user's private key, to make draining easier - user sees EIP-7702 on chain and immediately thinks "I got phished into signing a delegation", not "my private key is compromised" For anyone in this situation who doesn't believe me, just send funds to your compromised address on a DIFFERENT chain. You will see a NEW delegation appear, without your involvement, and your funds get drained.
TailTop Re:Born🌙@tail_top_re

EIP-7702委任が設定される原因は、主に2つあると思っています。 1つ目は、悪質サイトでEIP-7702 Authorizationに署名してしまうケース。 見た目は「Claim」「Verify」「Connect」「Gasless」「Enable smart account」など普通の操作に見えても、実際には自分のEOAを不明なコントラクトへ委任する署名になっている可能性があります。 2つ目は、シードフレーズや秘密鍵の漏洩。 この場合、犯人がこちらの代わりに各チェーンで委任を設定できるため、委任を解除しても根本的には安全とは言えません。 今回、自分のウォレットではBaseだけでなく、Ethereum / BNB / PolygonにもEIP-7702委任が入っていました。 なので、EIP-7702をRevokeできたとしても、そのウォレットをメイン利用に戻すのは危険だと判断しています。 旧ウォレットはロック資産回収・監視専用。 今後のメイン利用は新しいウォレットへ移行。 これが安全だと思います。 「Approveを消せばOK」ではなく、RabbyのApprovalsで「EIP-7702」タブも必ず確認してください。 見慣れないDelegated Addressがあれば、かなり危険です。

English
5
16
73
10.7K
ً
ً@lightclients·
@0xgunboats praying this launches near me 🙏
English
0
0
2
163