saeta.eth
468 posts


A critical vulnerability I found in code forked from @1inch could have drained ~650k COVE tokens from @cove_fi contracts. Here's how the attack worked and how it was responsibly disclosed 🧵
Cove@cove_fi
On June 12, 2025, a critical reentrancy vulnerability was identified by @adrianromero @yAuditDAO @electisec in Cove’s liquidity mining program and promptly neutralized. No user funds were lost, and 652,565 non-transferable COVE tokens were secured as a precaution. The vulnerability was introduced in @1inch token-plugins@1.0.0, and was integrated by Cove. This variant was never deployed within @1inch infrastructure.
English

If I was Vercel’s CEO I would be spending all my time supporting my customers and community in patching a security vulnerability that:
- Vercel sat on for days
- Dishonestly tried to spin into a marketing event
- Silently changed their logs
- Still haven’t provided clarity for customers
But what is he doing?
Calling me a liar for pointing out the obvious that Nextjs is primarily made to run on Vercel.
Any external provider or anyone self-hosting would attest to the pain, money, and time it takes.




English
saeta.eth retweetledi

@OfframpXYZ Hey, can you please take a look at ticket #2649? It’s been a while since Paul last replied.
English

Gm 💜
We wish you all a happy new year as 2024 comes to a close. It's been a wild ride this year and we've barely taken a breather, but we're excited to get back to building Offramp as soon as the holidays are over! 🔥
During the month while migration was ongoing, we realized that needed more firepower to push out fixes and improvements faster for everyone. We dropped the ball for some of you, and we were overwhelmed with tickets and support requests.
We've doubled both our engineering and customer support teams to help support the much larger customer base we have.
Expect a drastically improved product, and much faster turnaround times for technical issues from 2nd Jan where we'll have 24/7 customer support available.
You'll see the effect of this increased headcount very soon. Thank you for continuing to back us - we'll keep pushing 💪
Happy holidays from Team Offramp 💜
English

Hey @SlowMist_Team, it's a little alarming that you did ZERO due diligence/research and displayed on your website that I lost $110,000 on ApeChain.
You didn't even look to see if the transaction was real...
pop-punk.ape... cmon guys. Not a good look for an auditing firm.

English
saeta.eth retweetledi

We are happy to announce that we have donated 1 million dollars to the @UBAonline (public university of Buenos Aires) to create a research center in cryptography.
Half of the money will be used for scholarships for students and the other half for professors.


English

@bal7hazar @OpenZeppelin no plans, just traveling through Japan
English

yesterday was my last day at @OpenZeppelin after 7 years
I'm very grateful and proud of my work there. I don't know where else I could have been given the opportunity to work on security, product, marketing, and open source, all while doing very impactful work
thanks y'all
English

@eugenioclrc @TheSecureum @GalloDaSballo @neumoXX are there two buttpluggies there or am i wrong? oneee twooo, yes two
English

Feeling happy after last @TheSecureum RACE by @GalloDaSballo , i guess is difficult to beat this goats :D GG again @neumoXX

English
saeta.eth retweetledi

Blobs are coming .oO
Dencun is scheduled for mainnet activation at epoch 29696, occurring March 13 at 13:55 UTC. See the announcement below for client release versions and other useful info about the upgrade 🤖
blog.ethereum.org/2024/02/27/den…
English

Maybe related to github.com/foundry-rs/fou…? if you remove the --chain-id param, it works :)
English

This is pretty interesting, the same command with other networks works
anvil --chain-id 42161 --fork-url arbitrum.llamarpc.com
cast balance 0xf39Fd6e51aad88F6F4ce6aB8827279cffFb92266 --rpc-url http://localhost:8545
Error: (code:-32603, message: Required data unavailable...
English
saeta.eth retweetledi

economic security flippening
⬛⬛⬛⬛⬛⬛⬛ 700%
Ethereum
• 29.9M ETH staked
• $2,525 per ETH
→ $75B of economic security
Bitcoin
• 600M TH of hashrate*
• $17.5 per TH**
→ $10.5B of economic security
*Expressing hashrate in TH is a common abuse of notation—the correct unit is TH/s.
**Bitmain sold the S21 in bulk at $14 per TH/s. The energy efficiency of the air-cooled S21 is 17.5J per TH. With a setup cost of $200K per MW of air-cooled datacenter there's an additional datacenter setup cost of $3.5 per TH/s, for a total cost of $17.5 per TH/s.
$17.5 per TH/s should be a conservative upper bound. The S21 can be overclocked to reduce the dominant nominal rig cost of $14 per TH/s. Should Bitmain itself deploy the hashrate the sticker price can be discounted by Bitmain's profit margin. Manufacturing billions of dollars of S21s will lead to economies of scale and better pricing from suppliers like TSMC as well as assemblers. Manufacturing and installing state-of-the-art S21s is one of many strategies to deploy hashrate. For example, old hardware acquired at a significant discount can cover some of the hashrate, especially post-halving. Datacenter costs can be partially recouped by reselling capacity at discount pricing, e.g. at $100K per MW to AI farms. Rig costs can also be partially recouped by reselling PSUs and scrap metal.
English





