patrick.algo
6.3K posts

patrick.algo
@patrickbennett
CEO/Co-Founder of @txnlab Inc, creators of Haystack @haydotapp, NFDs @nfdomains, use-wallet, and Réti open pooling for #Algorand


SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.





We experienced an outage at Coinbase last night, which is never acceptable. The root cause was a room overheating in an AWS datacenter when multiple chillers failed. We design our services to be redundant to downtime in any one AWS Availability Zone (AZ), and most of our systems worked this way last night, but not all. Our centralized exchange did not. Exchanges have unique architectures that optimize for latency and co-location of clients. It is possible to make exchanges resistant to AZ failures, but this can introduce latency delays that are not desirable along with breaking customer co-location. Given this incident, we'll revisit these tradeoffs to ensure we're giving you the best possible venue to trade. At a minimum, the duration of an outage should be able to be reduced considerably when an AZ move is needed. Thank you to the AWS and Coinbase teams for working through the night to mitigate the issue. We’ll share the detailed technical summary once it's ready.















Algorand 💚 EVM Wallets Yesterday we debuted our first rollout of xChain Account abstraction on @alphaarcade This lets users bring their EVM wallets to Algorand with full self custody Here's what you can do 🧵


The EVM ecosystem has over 30 million monthly active wallet users. Until today, none of them could access Algorand dApps without creating a new wallet. That changes now with xChain Accounts. xChain Accounts launches today with @alphaarcade, one of the top prediction markets in crypto by transaction volume. Connect with supported EVM-compatible wallets like MetaMask, Rabby, Coinbase Wallet, or any other EVM wallet. No new wallet or seed phrase required.



@toly @TrustlessState If I need a large CPU with several cores and an FPU to compute a signature, I'm not sure I can make this secure... Actually, I know I can't ;)












