Lithos.eth

24.2K posts

Lithos.eth banner
Lithos.eth

Lithos.eth

@Lithos_eth

Architecting a verifiable internet | Building RWAs @KimberliteToken | Smart Privacy w/ @OasisProtocol | Amb. to top L1s & L2s

BEng(Hons) in Petroleum Eng เข้าร่วม Eylül 2024
474 กำลังติดตาม1.2K ผู้ติดตาม
ทวีตที่ปักหมุด
Lithos.eth
Lithos.eth@Lithos_eth·
i just finished designing this hit list mapping out every major lazarus hack on record staring at the sheer volume of these exploits all in one place is genuinely sobering we are looking at billions of dollars systematically extracted from our industry the most terrifying part is that almost none of these were complex smart contract bugs they were compromised laptops fake job interviews and poisoned frontends we keep obsessing over auditing our code while a sovereign nation state is quietly hacking our humans the only way we stop the bleeding is by physically isolating the execution layer from the people building it moving critical signing infrastructure into secure enclaves means even a fully compromised developer cannot hand over the keys we have to build systems that protect us from our own tired engineers how many more protocols have to die before we realize human operational security will never be enough to fight an organized nation state
Lithos.eth tweet media
Lithos.eth@Lithos_eth

while i was writing about the massive exploits yesterday three more protocols just got drained aftermath finance , sweat economy , and syndicate were all hit in the last twenty four hours it is exhausting watching us pour millions into audits while a single nation state bleeds us dry but there is a wild theory going around that is starting to feel terrifyingly real what if north korea hackers took ten years of stolen defi data and trained their own state funded ai we might just be watching an autonomous machine running free and cashing in until someone figures out how to stop it the lazarus group does not even need to attack your battle tested code anymore they compromise a human like we saw with bybit and slip bad code into the frontend so the screen silently lies to the signers they spend months at our conferences building trust and getting hired as full time developers under fake identities we keep trying to solve a machine speed threat with human code reviews the only real fix is removing humans from the execution layer entirely moving our critical plumbing into secure enclaves means even a completely socially engineered developer cannot extract the keys we have to use cryptography to build systems that protect us from our own tired engineers for the protocols how are you isolating your infrastructure so an automated agent cannot sink your ship and for everyday users like you, how are you verifying what you sign when the frontend itself might be lying to you

English
17
1
23
387
Lithos.eth
Lithos.eth@Lithos_eth·
@kurturex I think you have to try because it not easy to get 5M impressive here man
English
0
0
0
1
kurture 🀄︎
kurture 🀄︎@kurturex·
what's disappointment? disappoinment is when you spend 2 days without a proper sleep.. just to grind 5m impressions.. only to get stuck here :)
kurture 🀄︎ tweet media
English
63
0
78
539
Lithos.eth
Lithos.eth@Lithos_eth·
robin this deserve a documentary man, you did justice here I talk more of security because I have first hand experience it indeed terrible when it happened Lazarus hackers are years ahead of us and this guys work like a real organization with shifts in between that why protocols must be so careful, treat it has the most important thing because it there’s a loopholes without being fixed the next second you are drain and human working in this key position need to be careful with everything within them lastly protocols need to adopt using privacy and confidential smart contracts where humans are not in position to hold upto private keys or whatever
English
0
0
0
0
robin |
robin |@robintwts·
imo if they can reach the human, they can reach the code - social engineering it’s like those movies where the “nerds” get set up w women (hot queens), and in the end the whole system gets compromised thru them. one wrong trust, and da whole operation falls that’s fiction… but the real life version is worse. lemme remind yu of that major hack oh yes! the drift protocol hack, where the attackers (social engineers) didn’t break smart contracts… they built trust they ran a full illusion. evrything looked g0dd3mn legit - they even invested $1M just to pull out about $285M (if my math is right, that’s 280x) - v intentional team. that’s not random crime that’s - (i) planning (ii) patience (iii) obsession almost like the series “money heist”… where professor (the master mind) had mapped out evry details years in advance this is why teams need more than just technical security…. they need paranoia training (leju pah) - constant awareness - always questioning evry checkpoint, evry evry click, evry interaction, evry “urgent” msg even what feels normal they should be groomed like those media trained public figures. yu should see kevin hart give answers to those complicated questions in that lgbtq themed interview. one wrong answer & kevin is fvcked. social engineers are lunatics and honestly more hungrier, [prolly skilled] than builders - v relentless their brains work overtime and don’t stop running scenarios that end in one thing - “access” and that’s the part that should worry us cuz in the end, ppl break first and evry lock we build in code, in defi, in crypto is only as strong as the trust we place behind it - our devs. just saying ps: the lord bless our real good devs.
Lithos.eth@Lithos_eth

i just finished designing this hit list mapping out every major lazarus hack on record staring at the sheer volume of these exploits all in one place is genuinely sobering we are looking at billions of dollars systematically extracted from our industry the most terrifying part is that almost none of these were complex smart contract bugs they were compromised laptops fake job interviews and poisoned frontends we keep obsessing over auditing our code while a sovereign nation state is quietly hacking our humans the only way we stop the bleeding is by physically isolating the execution layer from the people building it moving critical signing infrastructure into secure enclaves means even a fully compromised developer cannot hand over the keys we have to build systems that protect us from our own tired engineers how many more protocols have to die before we realize human operational security will never be enough to fight an organized nation state

English
2
0
5
45
Lithos.eth
Lithos.eth@Lithos_eth·
@emilios_eth this has been the most unique of all this that am Seeing on TL
English
0
0
0
0
emilios.eth
emilios.eth@emilios_eth·
That’s PFP material
emilios.eth tweet media
English
13
0
37
289
Lithos.eth
Lithos.eth@Lithos_eth·
@0xKarbon looking at this analytics you have consistently hit more than 150 replies per day that real numbers man you are a legend see you tomorrow
English
0
0
0
1
Karbon
Karbon@0xKarbon·
If I didn’t reply, I didn’t see you. Just crossed 1,600 followers basically 2K at this point See u tomorrow , guys. Tomorrow = gaming day + real opportunities for small creators (no engagement farmers)
Karbon tweet media
English
33
0
42
246
Jonny Dee
Jonny Dee@0xJonnyDee·
Shoutout to the OG @ripchillpill. Replied to one of his posts, he reshared it so it got more eyes on it, and then followed me back. A Perfect example of how cool the crypto space can be. You can connect with people and grow from a simple reply. Just send the message.
Jonny Dee tweet media
English
9
1
32
502
Lithos.eth
Lithos.eth@Lithos_eth·
@ray_world0 real growth buddy and sure this month you will win more and more including bounties
English
0
0
0
10
Ray
Ray@ray_world0·
april recaped: earned $50 gained 207 followers wrote about 3 articles entered 5 bounty, didn't win any connected with more mutuals learning the art of being creative started pitching more - a couple leads things will change a lot in may, i believe, btw my 4 months stats
Ray tweet media
pleb@0xplebbie

april recaped: earned $0 gained 170+ followers wrote my second article entered 1 bounty - didn't win connected with more mutuals mastered the act of serving bangers started pitching more - a couple leads didn't finish the course on AEO there's probably more I'm leaving out... let's do more in may 🙂‍↔️

English
18
0
34
257
Lithos.eth
Lithos.eth@Lithos_eth·
@arkilus78 Waw , I was smiling reading this growth always comes when you do they right things consistently and you are reaping that fruit of quality
English
1
0
1
7
arkilus
arkilus@arkilus78·
i was getting around 300-500 views per post ended april with 89k views but here's the interesting part : - first 2 weeks , got around 14k views - in last 2 weeks, got around 75k views 5x growth in just 2 weeks what changes? - figured out my niche - promised to provide value, not commentary - start doing only 1 post per day - give hours to research and write a single post - work on hook/followup/structuring/CTA/banner - became simplistic with my tone, no jargon at all and yeah, we finally doing good growth happens with clear plans and execution its still just the beginning , had to go long way what’s your stats for last month? drop them below, let's see who else is cooking👀
arkilus tweet media
arkilus@arkilus78

i found $AI before most of CT did here's the exact system i use to find projects early (bookmark this | you will need it later) -------------- the obvious methods everyone uses: - tracking fundraising sites (cryptorank/rootdata) - following big VCs on X these could work but everyone does them, you won't be early enough using only these -------------- the methods that actually give you an edge: > watch, who VCs are silently following and engaging with most investments are decided before the actual announcement, if a16z or Paradigm suddenly follows a project with 200 followers and zero funding pay attention immediately that's not random, VCs don't follow noise > crypto jobs onboards, before fundraising news : look at web3career and remote3co when a project suddenly posts 3-5 jobs in a single week, they are highly likely just raised money that's a 30-60 day window before the news hits CT most people wait for the official announcement, but you will be there before it > GitHub activity before Twitter presence : go to github(dot)com/explore and filter by crypto/blockchain/web3 projects with recent commits, growing contributors, and active issue discussions, but tiny Twitter presence this gap between tech activity and social presence is your early signal by the time they have 10K Twitter followers the GitHub was already busy for months > follow the angel investors not just the VCs this is the one that nobody talks about find 10-15 angel investors who have backed winning projects before, when they personally invest in something new that signal is stronger than any VC announcement angels bet their own money not LP money, that conviction is different -------------- what i check in the first 5 minutes: > does the branding look like someone cared about it (weak branding = team running on hype only) > does it have at least a pre-seed or seed round (no funding at all = too high risk of total time waste for me you could go before that as well) > is the tech starting a new narrative or following one (followers get paid less than starters, always) > is GitHub active with real commits (ghost GitHub on a "cutting edge tech" claim = immediate skip) > does the founding team have verifiable backgrounds (LinkedIn + previous products that actually shipped) -------------- the timing rule that changes everything : most people find a project > research it > wait to see if others are talking about it > then join late the right sequence is: find it > research it > join immediately if it passes your checklist > built conviction > let others discover it while you're already inside for a while the difference a mid cook to a high cook is usually just timing not much of contribution gap -------------- those are the ways that allows me to have a 5fig portfolio the people who ate the biggest rewards are there before the noise master It, and you will always be early what method do you use to find projects early? ( drop it below, genuinely curious 👀 )

English
27
1
48
419
Lithos.eth
Lithos.eth@Lithos_eth·
@arkilus78 you nailed it , i have been hacked before so I know how painful it is and talk-less of protocols being drain like this and users funds being wipe off totally so goes into depression or deep financial crackdown
English
1
0
1
8
arkilus
arkilus@arkilus78·
@Lithos_eth man that's sad anyway who has actually lost it only they could feel the real pain honestly
English
1
0
0
7
Lithos.eth รีทวีตแล้ว
Lithos.eth
Lithos.eth@Lithos_eth·
i just finished designing this hit list mapping out every major lazarus hack on record staring at the sheer volume of these exploits all in one place is genuinely sobering we are looking at billions of dollars systematically extracted from our industry the most terrifying part is that almost none of these were complex smart contract bugs they were compromised laptops fake job interviews and poisoned frontends we keep obsessing over auditing our code while a sovereign nation state is quietly hacking our humans the only way we stop the bleeding is by physically isolating the execution layer from the people building it moving critical signing infrastructure into secure enclaves means even a fully compromised developer cannot hand over the keys we have to build systems that protect us from our own tired engineers how many more protocols have to die before we realize human operational security will never be enough to fight an organized nation state
Lithos.eth tweet media
Lithos.eth@Lithos_eth

while i was writing about the massive exploits yesterday three more protocols just got drained aftermath finance , sweat economy , and syndicate were all hit in the last twenty four hours it is exhausting watching us pour millions into audits while a single nation state bleeds us dry but there is a wild theory going around that is starting to feel terrifyingly real what if north korea hackers took ten years of stolen defi data and trained their own state funded ai we might just be watching an autonomous machine running free and cashing in until someone figures out how to stop it the lazarus group does not even need to attack your battle tested code anymore they compromise a human like we saw with bybit and slip bad code into the frontend so the screen silently lies to the signers they spend months at our conferences building trust and getting hired as full time developers under fake identities we keep trying to solve a machine speed threat with human code reviews the only real fix is removing humans from the execution layer entirely moving our critical plumbing into secure enclaves means even a completely socially engineered developer cannot extract the keys we have to use cryptography to build systems that protect us from our own tired engineers for the protocols how are you isolating your infrastructure so an automated agent cannot sink your ship and for everyday users like you, how are you verifying what you sign when the frontend itself might be lying to you

English
17
1
23
387
Lithos.eth
Lithos.eth@Lithos_eth·
this is very thoughtful of you persie you good to filter what we consume as a people and beside I love how you highlighted people we can learn from which is great I think in live everything we see is build from what exists so learning from other but having our own independent style is a unique think it makes people remember us and give us edge over others once more this way very insightful
English
0
0
1
9
Lithos.eth
Lithos.eth@Lithos_eth·
you nailed this Timmi hypocrite is they other of the day and it shows how biased and how sick human psychology is most of them doesn’t want to take responsibility what they do especially when the get to the height of influence everyone supporting knows someday he or she will shill a rug And people should stop investing base on people opinion especially when it has to do with product with no visible products
English
0
0
0
3
Timii🩶
Timii🩶@0x_Timi·
this space is really annoying cuz we love postmortems a lot. we see an obvious problem but we look away. pred markets have no reason to have a token - let alone one that starts out shilling its token without a live product. no one said anything then - it’s just hypocritical.
Sourabh Ruchandani@PhiloSourabh

Good to see Medusa take responsibility. But creators should be very mindful of what they promote in this space. Promoting a TGE directly was a mistake in the first place, let alone a rug pull. Emerging creators like Medusa should surround themselves with OG web3 creators to learn how to use their influence to support the ecosystem. Peace!

English
9
2
18
234
Onyx 🦣♦️
Onyx 🦣♦️@web3onyx·
gm and happy new week amigos and amigoses early alpha for creators @clashoAi is cooking a platform where you can work with big brands if we're ever gonna see another version of infoFi, this would probably be how it will get started sign up for their wait-list here : clasho.com/invite/ZG6SHGNJ (disclosure it's a referral based campaign) if you can't keep up, skip. missed my clip yesterday? don't do that again check 👇
Onyx 🦣♦️ tweet media
Onyx 🦣♦️@web3onyx

Over 1,000 people will see this post. 80% will just scroll past! why? because y'all have been paying so much (deservedly) attention to ai, robotics and $MEGA ETH. what if i told you there's a nonprofit organization with over 100 members that includes tech giants like aws and red hat, all committed to the development of self-driving cars? now you know. @autowarefdn's aim is to facilitate the development of self-driving cars. they've been doing it for over 10 years, they also have top university research labs onboard. their tech is not just theory (like my fren ChatGPT used to say) it's already being used in some of the top self-driving cars in the world. wanna learn more about them? you know what i used to say... hear it from the horse's mouth.

English
48
1
52
346
Lithos.eth
Lithos.eth@Lithos_eth·
@web3onyx sorry for the eye effects I will do better next time I used figma
English
0
0
0
4
Onyx 🦣♦️
Onyx 🦣♦️@web3onyx·
@Lithos_eth This is wholesome and colorful What tool did you use It's a sore to the eyes btw
English
1
0
1
9
painn
painn@_0xpainn·
@Lithos_eth you’ve been getting you hands busy
English
1
0
0
19
Lithos.eth
Lithos.eth@Lithos_eth·
@juvenilelad I can’t really say for now but every chain must be security conscious
English
0
0
1
3
persie
persie@juvenilelad·
@Lithos_eth do you think they can get to arbitrum
English
2
0
2
26
Lithos.eth
Lithos.eth@Lithos_eth·
@0xZodex for now now one is going to stop them they are ahead of us
English
0
0
0
8
zodex
zodex@0xZodex·
@Lithos_eth nobody can stop them but we want to secure and only look trusted ppl
English
1
0
1
17
agim𓍯
agim𓍯@aGim_asf·
got paid on the first day of the month this is beautiful omen
agim𓍯 tweet media
English
127
0
188
2.3K
Amar
Amar@a12321xyz·
Good night legends I have been working on a project called Arcium Obscura Markets for the Arcium rtg developer challenge. Most prediction markets are hard to trust because seeing where everyone else is betting changes how you think. This app uses mpc technology to keep every bet and outcome private until it is time to settle. It was a great way to explore how privacy can actually make market signals more honest. You can find the demo and the code below if you want to see how we integrated the arcium cluster with solana. Give it a try & tell me if any bugs. @quipnetwork is advancing its compute layer with active workload execution across shared hardware @TheARCTERMINAL Terminal is evolving ANIMA into a more execution focused system that turns inputs into structured output
Amar tweet mediaAmar tweet media
English
81
7
78
402