tinyxiong.eth

837 posts

tinyxiong.eth

tinyxiong.eth

@tinyxiong_eth

Build things for builders | 登链社区 @UpchainDAO Initiator | Co-Founder of @DeCertme

Katılım Mayıs 2009
891 Takip Edilen2.5K Takipçiler
tinyxiong.eth retweetledi
登链社区
登链社区@UpchainDAO·
Solana 2026开发者训练营 Season 2 开始报名啦 这一期主要是项目实践,内容包含: ​🫱视频课:Solana Bootcamp 2026 中文版 + Solana Mobile 开发 ​🫱Solana 技术栈 + AI 开发 ​🫱Solana 生态中的头部项目分享领域经验、产品开发及更深入的技术理解 有兴趣的小伙伴不要错过哦😎
Solar (Solana中文社群)@Solana_zh

👨‍💻新一期2026 Solana开发者训练营S2开启招募! Solana开发者训练营S2由Solar和 @solana @solana_devs 共同举办,@0xProject @Titan_Exchange @magicblock 支持,联合华语区头部的22家开发者社区和21个高校区块链协会,为华语区开发者量身打造为期六个月的三季开发课程,由易至难覆盖全阶段开发者,助Solana开发者熟练掌握从0到1产品设计和项目开发,就业Solana生态项目开发岗位。 S2:生态分赛道区块链项目实战(线上+线下) 🗓️3月31日-4月30日 现在报名👉luma.com/6ou80u5n 🟣Solana生态头部项目将分享领域经验、产品开发及更深入的技术理解; 🟣代表华语区提交四月Colosseum全球黑客松的毕业生将获得 @SafePal 与Solana联名硬件钱包、NFT毕业认证、Solana工作机会优先权,及丰厚开发者支持奖学金

中文
0
1
2
606
tinyxiong.eth
tinyxiong.eth@tinyxiong_eth·
作者利用 GPT-5.4 反编译以太坊字节码, 不仅还原代码,还能结合Etherscan、函数签名、运行时字符串等链上上下文,逐步揭示合约行为。 文章分析了一个钓鱼合约和 Balancer V2 攻击者的合约, 逐步推理背后的攻击逻辑。 #区块链 #智能合约 #AI安全 -全文翻译:learnblockchain.cn/article/24469
Kalis@jaczkal

x.com/i/article/2023…

中文
5
13
115
31.8K
tinyxiong.eth retweetledi
Wey Gu 古思为
Wey Gu 古思为@wey_gu·
chrome 速度可以的,正式版 146 已经包含了这个允许把一个浏览会话暴露成 MCP 的能力了,skills 已经有了。 感谢 chrome 团队和社区,在事实标准的浏览器层面努力协作把这些信息流通、降噪,并快速做到 好时代🫡
Petr Baudis@xpasky

It took another two months but Chrome 146 is out since yesterday! And *that* means: with a single toggle, you can expose your current live browsing session via MCP and have your CLI agent do things in it. Aaand I have been waiting to deal with my LI connects until this moment.

中文
4
8
110
25.9K
tinyxiong.eth
tinyxiong.eth@tinyxiong_eth·
以太坊基金会阐述新使命,把以太坊定位成『避风港技术』,并强调CROPS(抗审查、开源、隐私、安全 的首字母缩写) 这并不是新鲜口号,而是对区块链核心精神的深度提炼和再确认。所谓『避风港』,就是建立一个真正由技术保障的、无惧任何强制或垄断的数字空间,为每个人提供一个在网络世界中保有自主权的『逃生舱』。它意味着我们不是要与现有体系对抗,而是要提供一个更稳健、更自由、更去中心化的替代方案。 EF在协议层关注去中心化、可验证性、安全,在应用层则力求打造无需依赖中间商、极致保障用户自主权和隐私的『零选项』体验。 看到EF不局限于以太坊本身,而是将自己视为更广泛『避风港技术社区』的一部分,格局👍 -全文翻译:learnblockchain.cn/article/24421
vitalik.eth@VitalikButerin

This is the new EF Mandate. For many of you, the contents should be no surprise, and a clarification along the lines that we have been going and thinking for the past few months. But the clarification is nevertheless worth making. Ethereum is a unique object and has a unique role in the world. Its role is to be a sanctuary technology, to preserve technological self-sovereignty, to enable cooperation without coercion, domination or rugpulling, and to provide an escape hatch, to ensure that no single person, organization or ideology's victory in cyberspace can be total. The Ethereum Foundation is a steward of Ethereum - the original steward, and today, the steward specifically dedicated to preserving and expanding the above aspects of Ethereum. This means a heavy emphasis on CROPS (censorship and capture resistance, open source, privacy, security), both at the protocol layer, and at the access layer, user-facing applications and tools that we create or contribute to. There are things that we do in Ethereum because we believe that they are valuable for the underlying goals that we have for Ethereum. There are things that we do not do because from the perspective of our values we find them uninteresting (or worse, harmful). But there are also things that we do not do because while they are useful, they are not our role. At the Ethereum protocol layer, we focus on decentralization, verifiability, inclusion guarantees, protocol liveness, security and privacy first and foremost. We also value capabilities (eg. L1 scale, account abstraction, perhaps some forms of in-protocol aggregation), particularly because improvements in these capabilities better enable users to properly benefit from Ethereum's CROPS properties and displace the need for higher-layer intermediaries that might weaken the extent to which Ethereum's properties carry over into the full stack. We also believe that the Ethereum protocol must strive to pass the walkaway test. "We do X to specialize to serve the use cases of today, if more use cases appear later, we will continue to keep adding more EIPs for them later" is logic fit for many other blockchains whose names you hear often on this forum, but we do not believe it is logic fit for a decentralization-first blockchain like Ethereum. At the application layer, we focus on making "the zero option" - user experience that goes hard on ensuring security and privacy, avoiding dependence on intermediaries, and respecting the user's agency - as high quality as possible. We see this as complementary to work in the Ethereum ecosystem that "goes broad", starting from the world that it exists, and brings it onchain and improves its properties over time. Such work has its natural home outside the EF. We intend to be supportive of such efforts. We believe that the two are complementary: tools that are developed within the EF can be adopted by anyone, including partially, and even partial adoption that improves people's security, privacy and agency is a good thing. But the form of user experience that is more heavily insistent on CROPS properties is where we want the EF to develop its center of expertise. This does not mean shrinking from the hard questions. We believe in a vision of self-sovereignty that protects users, and does not leave users in the cold to face environments where they lose their life savings if they make a mistake, and click "yes" on a confirmation screen by accident two seconds after. But such protection must be designed based on a philosophical baseline of empowering the user, not empowering centralized organizations that claim to act in the user's name. This quadrant of design space - caring about users' (including non-experts') well-being and safety, and yet insistent on doing this in a way compatible with their agency and freedom, is underserved (not just in crypto, but in the world). We wish to use Ethereum as a platform to build out and showcase this quadrant, and ideally work with others to expand its reach over time. This is also a new chapter in how we see our position in the world. We must see ourselves not just as the Ethereum community, but also as maintainers of the Ethereum tool within what you might call the CROPS community or the sanctuary tech community, or a dozen of other words that have for a long time been used by people with similar values to us but far outside Ethereum. This means open-mindedness to new conceptions of what things in the world are our natural allies. Ethereum is not the world. Ethereum is a specific object in the world that is here to have specific properties. The Ethereum Foundation is a specific organization within Ethereum - one steward, not the sole one. I encourage all to read the mandate in detail; it includes concrete examples of how we intend to deal with the challenges and nuances of these ideas. We are doubling down on Ethereum and are excited about its next chapter.

中文
0
0
1
440
tinyxiong.eth
tinyxiong.eth@tinyxiong_eth·
第一性原理看以太坊 1. 数据可用性 = 全球公共布告栏。这是去中心化协作的基石,比智能合约更原始 2. 支付 = 抗垃圾邮件/女巫攻击。ETH不仅是货币,更是构建无需许可、抗审查系统的“经济屏障”。 3. 智能合约 = 便利且互操作的编程层。虽然ZKP+布告栏能做很多事,但智能合约提供标准化和互操作性,是DeFi等复杂应用爆发的关键。 V同时提醒,现在以太坊费用已大幅降低,扩容路径明确。是时候重新审视那些曾因成本搁置的创新了。我们不能只盯着既有应用,更要从技术本源出发,思考这片“全球共享内存”还能承载怎样的未来。 #以太坊 #Web3 -全文翻译:learnblockchain.cn/article/24397
vitalik.eth@VitalikButerin

I was recently at Real World Crypto (that's crypto as in cryptography) and the associated side events, and one thing that struck me was that it was a clarifying experience in terms of understanding *what blockchains are for*. We blockchain people (myself included) often have a tendency to start off from the perspective that we are Ethereum, and therefore we need to go around and find use cases for Ethereum - and generate arguments for why sticking Ethereum into all kinds of places is beneficial. But recently I have been thinking from a different perspective. For a moment, let us forget that we are "the Ethereum community". Rather, we are maintainers of the Ethereum tool, and members of the {CROPS (censorship-resistant, open-source, private, secure) tech | sanctuary tech | non-corposlop tech | d/acc | ...} community. Going in with zero attachment to Ethereum specifically, and entering a context (like RWC) where there are people with in-principle aligned values but no blockchain baggage, can we re-derive from zero in what places Ethereum adds the most value? From attending the events, the first answer that comes up is actually not what you think. It's not smart contracts, it's not even payments. It's what cryptographers call a "public bulletin board". See, lots of cryptographic protocols - including secure online voting, secure software and website version control, certificate revocation... - all require some publicly writable and readable place where people can post blobs of data. This does not require any computation functionality. In fact, it does not directly require money - though it does _indirectly_ require money, because if you want permissionless anti-spam it has to be economic. The only thing it _fundamentally_ requires is data availability. And it just so happened that Ethereum recently did an upgrade (PeerDAS) to increase the amount of data availability it provides by 2.3x, with a path to going another 10-100x higher! Next, payments. Many protocols require payments for many reasons. Some things need to be charged for to reduce spam. Other things because they are services provided by someone who expends resources and needs to be compensated. If you want a permissionless API that does not get spammed to death, you need payments. And Ethereum + ZK payment channels (eg. ethresear.ch/t/zk-api-usage… ) is one of the best payment systems for APIs you can come up with. If you are making a private and secure application (eg. a messenger, or many other things), and you do not want to let people to spam the system by creating a million accounts and then uploading a gigabyte-sized video on each one, you need sybil resistance, and if you care about security and privacy, you really should care about permissionless participation (ie. don't have mandatory phone number dependency). ETH payment as anti-sybil tool is a natural backstop in such use cases. Finally, smart contracts. One major use case is _security deposits_: ETH put into lockboxes that provably get destroyed if a proof is submitted that the owner violated some protocol rule. Another is actually implementing things like ZK payment channels. A third is making it easy to have pointers to "digital objects" that represent some socially defined external entity (not necessarily an RWA!), and for those pointers to interact with each other. *Technically*, for every use case other than use cases handling ETH itself, the smart contracts are "just a convenience": you could just use the chain as a bulletin board, and use ZK-SNARKs to provide the results of any computations over it. But in practice, standardizing such things is hard, and you get the most interoperability if you just take the same mechanism that enables programs to control ETH, and let other digital objects use it too. And from here, we start getting into a huge number of potential applications, including all of the things happening in defi. --- So yes, Ethereum has a lot of value, that you can see from first principles if you take a step back and see it purely as a technical tool: global shared memory. I suspect that a big bottleneck to seeing more of this kind of usage is that the world has not yet updated to the fact that we are no longer in 2020-22, fees are now extremely low, and we have a much stronger scaling roadmap to make sure that they will continue to stay low, even if much higher levels of usage return. Infrastructure for not exposing fee volatility to users is much more mature (eg. one way to do this for many use cases is to just operate a blob publisher). Ethereum blobs as a bulletin board, ETH as an asset and universal-backup means of payment, and Ethereum smart contracts as a shared programming layer, all make total sense as part of a decentralized, private and secure open source software stack. But we should continue to improve the Ethereum protocol and infrastructure so that it's actually effective in all of these situations.

中文
1
1
11
2.1K
tinyxiong.eth
tinyxiong.eth@tinyxiong_eth·
Oz 的这篇文章非常及时地提醒我们“传统”IT安全问题正在成为加密世界的新战场,过去我们总盯着重入攻击、整数溢出,现在最大的漏洞和损失,却越来越多地出现在链下运营基础设施。例如:私钥管理、多签被盗,到供应链攻击等 -全文翻译:learnblockchain.cn/article/24383
OpenZeppelin@OpenZeppelin

Defense in depth means securing the people, processes, and infrastructure around your code 🔒 We wrote about what that looks like in practice ↓ openzeppelin.com/news/introduci…

中文
0
0
2
372
tinyxiong.eth
tinyxiong.eth@tinyxiong_eth·
认真讨论帖,最近越来越多的声音表示,区块链是为 AI 准备的,Agent 间的支付将 N 倍于人类支付,于是有了 ERC8004,ERC8183 等 但我对 Agent 间相互雇佣这个未来表示怀疑,人类会将很多工作外包给其他人完成,是因为人类太弱了,自己搞不定,但是大模型会越来越强大,他会趋向于自己完成(如果他有意识)。 如果 Agent 没意识,而是服务于人这个主体, 可能更多的时候,还是使用现在的订阅支付,因为路径依赖很难摆脱,加密支付并没有很大的优势 作为从业者,肯定希望加密支付能被应用在 Agent 上,但是目前看不懂,大家怎么看,有朋友一起讨论一下么?
中文
2
0
4
685