独钓蓑笠翁
3K posts


0/ Today, the Ethereum Foundation completed a bilateral swap of ~21,269 aWETH to wstETH, coordinated with @LidoFinance and @mellowprotocol as part of their ongoing deleveraging work.

Introducing Pharos RealFi Access Program: The $PROS Public Sale A structured, Pharos-hosted framework designed to provide compliant and broad access to the Pharos ecosystem ⚓ Identity verification, eligibility checks, and secure settlement are powered by Sonar of @echodotxyz 🧵 Thread for details:


Update on rsETH incident: @LlamaRisk has published a report outlining the rsETH incident, the immediate actions taken, its impact on Aave, and potential paths forward. All service providers have been working to assess the two potential bad debt scenarios on the Aave protocol. Aave DAO service providers are also leading an effort with ecosystem participants to address any bad debt. This effort already has several indicative commitments from various parties and we are grateful for the strong support we have received so far. We will share further updates as we have them. In the meantime, the full report can be read here: governance.aave.com/t/rseth-incide…


The Arbitrum Security Council has taken emergency action to freeze the 30,766 ETH being held in the address on Arbitrum One that is connected to the KelpDAO exploit. The Security Council acted with input from law enforcement as to the exploiter’s identity, and, at all times, weighed its commitment to the security and integrity of the Arbitrum community without impacting any Arbitrum users or applications. After significant technical diligence and deliberation, the Security Council identified and executed a technical approach to move funds to safety without affecting any other chain state or Arbitrum users. As of April 20 11:26pm ET the funds have been successfully transferred to an intermediary frozen wallet. They are no longer accessible to the address that originally held the funds, and can only be moved by further action by Arbitrum governance, which will be coordinated with relevant parties.

关于BTC的抗量子计算的问题,有人把问题聚焦在算法问题,或者是FUD。 其实,算法从来不是核心问题,技术方案也不是问题,也从来不是FUD的问题,也不是皇帝不急太监急的问题。 问题只有一个: 如何处理暴露公钥地址资金的问题。 是冻结/烧毁?还是谁拿走算谁的? 这里涉及到较大比例BTC的处理:大约25-33%的BTC(大约600-700万枚处于量子暴露状态,包括中本聪的100万,以及其它永久丢失的BTC。 冻结或烧毁会违反BTC社区一直以来的原则:不可干涉,不可篡改。 如果无须冻结这些BTC,谁拿走算谁的。 那么,600-700万枚BTC会被人拿走,假如当时BTC已涨至30万美元一枚,这意味着,这部分总价值在1.8万亿-2.1万亿美元。 这么大规模的BTC流入市场,难以想象,最终的市场会变成什么样子? 现在BTC的量子防护路线,最大的难点,从来不在于技术,而在于治理困境:如何达成社区共识的问题。 其实有个建议: 可以把暴露公钥地址代币纳入到未来的挖矿安全预算。 等未来一天,矿挖完了,这些可以做安全预算的补贴。 同时解决BTC的两座大山:量子计算+安全预算。一举两得。 当然,大概率不会被BTC社区采纳,会遭遇不干预派的激烈反对。


又是一次攻击事件 1 小时前黑客在以太坊主网增发 10 亿枚 $DOT 并抛售,所幸该网络的流动性较差,损失目前看来是可控的,但还需要进一步排查攻击原因 增发地址 👉 etherscan.io/tx/0x240aeb9a8… 但受此影响,DOT 在主网上的市值变成了天文数字,而胆子大的正在抄底搏命,把 DOT 玩成 Memecoin 了…😅

Update: The @DriftProtocol exploiter has now swapped all stolen assets ($270M+) into 129,066 $ETH($273M). intel.arkm.com/explorer/entit… x.com/lookonchain/st…


🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.



Agent 支付赛道卷起来了 估值 1590 亿美金的支付巨头 Stripe, 孵化的 Tempo 公链主网正式启动,同时上线了【机器支付协议】(Machine Payments Protocol,MPP),AI Agent 现在可以像人类刷卡一样,自主完成支付——零注册、零 API Key、按请求付费 和x402最大的区别是, MPP一开始就集成了信用卡支付 , 且 Stripe 有 500 万商户,如果这个阶段的购买决策还是人来做出,则在真实世界的用例里面有更多优势









