theredguild

117 posts

theredguild banner
theredguild

theredguild

@theredguild

A guild of security researchers, educators and advocates working for the public benefit of the Ethereum ecosystem.

Katılım Temmuz 2022
0 Takip Edilen3.5K Takipçiler
theredguild
theredguild@theredguild·
Our own @tinchoabbate and @mattaereal have been selected for the first batch of top Ethereum Security Researchers. After working for more than three years together, fully dedicated to public goods - even when there is no runway (like now) - this type of recognition is motivating
thedao.fund@thedaofund

Who qualifies? Not just auditors & white hats. We’re looking across the entire security space: zk, formal verification, AI, opsec, infra, web2, generalists and more. What matters? Real work, real impact, and a deep understanding of what Ethereum needs to do to be safe enough to become the backbone of the world’s financial infrastructure.

English
0
2
8
681
theredguild retweetledi
Franco Victorio
Franco Victorio@fvictorio_nan·
Thinking about stealing this disclaimer from @theredguild's blog
Franco Victorio tweet media
English
1
1
4
209
theredguild retweetledi
Paul Kuryłowicz
Paul Kuryłowicz@wh01s7·
Hard to disagree with @mattaereal; public/open goods are undervalued, leading to builder burnout as written in latest @theredguild article Imagine incident response without @_SEAL_Org, static analysis without slither from @trailofbits, or learning security basics without @PatrickAlphaC videos. When @drdr_zz and I were creating SCSVS, many people were eager to use it, treating it as a checklist or reference. Many things were created on top of it. However, few people actively contributed. This is partly due to the lack of desire to build someone's brand (which is understandable), but it is not the only reason, as we see in many joint and non-branded initiatives that also have similar struggles. Without the support of sponsors or super high motivation, it's difficult to actively develop such projects. With the New Year slowly approaching, why not make a change? One project that deserves way more attention is Security Frameworks. It offers quick, actionable insights across a massive range of security topics. The sad part? When I send it to clients, most are hearing about it for the first time. Reply below with an underrated initiative, project, or tool that you think needs more eyes on it. 👇
English
2
7
15
1.3K
Rahul Saxena
Rahul Saxena@saxenism·
Building the TEE Security Handbook has been one of the most rewarding things I've done. However, as I move this project along, I'm realising just how difficult it is to bankroll an open-source public good. To keep the handbook high-quality, accurate, and expanding, I need to bring in more research engineers. That means paying people fairly, giving them time, and making sure the project doesn't bottleneck on me. This handbook will always be a non-profit, public good. But even non-profits need sustainability. Open-source funding has always been a tricky problem… so I’m opening this up to my frens: If you have experience with grants, ecosystem sponsorships, or sustainable models for public goods, I’d love to hear your thoughts. I really want this handbook to become a long-term asset for the entire TEE ecosystem and not something that dies because the contributors couldn't be funded properly. Any advice is appreciated. The TEE Security Handbook is in the quoted tweet. Thank you :)
Rahul Saxena@saxenism

The TEE security handbook is live now. This document covers: + Defining TEEs + TEE attacks categorisation + Deep dive of TEE platforms + Threat modelling around TEEs + Security layers for TEE protocols + Best practices for engineers & protocols Here: docs.bluethroatlabs.com

English
5
1
33
3.5K
theredguild retweetledi
Jeff Security
Jeff Security@jeffsecurity·
EIP-7702 is an auditor's minefield💀 "Sticky Storage" means dirty slots persist on your EOA between delegates, potentially bricking wallets. Plus massive init front-running risks. Mandatory watch from @theredguild: youtube.com/watch?v=ZFN2bY…
YouTube video
YouTube
English
2
14
80
7.1K
theredguild retweetledi
World Ethical Data Forum
World Ethical Data Forum@WEDF_forum·
For years, the public has known @WEDF_foundation mainly through our research, policy work, and the World Ethical Data Forum — our paywall free, open, privacy-advancing meeting ground for those who build, study, govern, and live inside digital systems. What’s been less visible is the work we’ve done quietly at the intersection of digital rights, networked infrastructure, and security. Much of that has involved pro bono defence for NGOs, human-rights organisations, and civil-society groups facing surveillance, censorship, infrastructure compromise, and targeted attack. We spoke little about this because the work demanded discretion. That background is why, during @EFDevcon in Buenos Aires, @_jdmarshall was invited by @ethereumfndn to join security engineers from across Ethereum — @TheRedGuild, @mattaereal, @samczsun, @fredrik0x, @_SEAL_Org, @0xRajeev and others — at @TheTrustX by @TheSecureum to examine Ethereum's security posture and the responsibilities that come with its maturation into critical open digital infrastructure. Matta’s excellent recap of the 1TS technical working groups captures the day's substance — and explores not only the outcomes but also the many paradoxes and challenges involved in the defence of public goods. And in defence *as* a public good. For anyone interested in @ethereum's future, its security assumptions, public-goods coordination, or the broader landscape of freedoms-tech, this is essential reading from one of Ethereum’s hardest-working whitehats: blog.theredguild.org/off-chain-laye… As 2026 approaches, we’ll be sharing more about the public-goods work we’ve been doing off-radar. This feels like the right place to begin.
English
1
51
51
2.4K
theredguild
theredguild@theredguild·
New article just dropped, part of our passing by many, many events, primarily focused on our awareness campaign around @EFDevcon. Featuring EthCon, DSS, Aleph, 1TS, Convergence, and more! Come by, and see what we were up to! blog.theredguild.org/against-all-od…
English
2
5
26
3.5K
theredguild retweetledi
Patrick Collins
Patrick Collins@PatrickAlphaC·
If you have a @theredguild pin, shirt, or other apparel, that is a signal that you’re legit af
English
8
3
78
5.6K
theredguild
theredguild@theredguild·
Amidst chaos, we almost forgot to announce that we have launched Phishing Dojo's public beta! Find more information directly on the platform. More stable, new challenges, new trainings! blog.theredguild.org/the-phishing-d…
English
0
7
12
2.1K
matta ⚡🪷
matta ⚡🪷@mattaereal·
Commitment means not having funding for the past 40 days, yet still working at 3 am, doing my best to change people's lives through our awareness and education initiatives. I am confident people will notice all the effort and love that @tinchoabbate and I have dedicated to this.
English
6
0
40
2.3K
theredguild
theredguild@theredguild·
Most articles on the npm worm did not provide tangible practices or a clear course of action for preventing future attacks. We know because we studied more than 20 articles on the subject 😮‍💨 Here's our take on what to do, a collab with @alcuadrado 🫡 blog.theredguild.org/how-to-npm-and…
English
1
18
39
4.8K
theredguild retweetledi
Nodo Serrano
Nodo Serrano@NodoSerrano·
Que lindo cuando hay ganas de ensuciarse las manos y aprender cosas nuevas! ¡Ethereum Essentials Vol.1 fue un éxito! @EFDevcon @theredguild
Nodo Serrano tweet mediaNodo Serrano tweet mediaNodo Serrano tweet mediaNodo Serrano tweet media
Español
0
1
6
495