zkoranges

138 posts

zkoranges banner
zkoranges

zkoranges

@zkoranges

Engineering | Security · DeFi · Cryptography · AI @PhilidorLabs

เข้าร่วม Mayıs 2021
492 กำลังติดตาม382 ผู้ติดตาม
zkoranges รีทวีตแล้ว
Philidor
Philidor@philidorlabs·
More granularity added into our «Asset Composition » risk analysis Having a single asset that dominate vault allocation or using the same underlying asset gives penalties on your risk score 👀 This @SteakhouseFi vault on @Morpho is still considered as a Prime tier
Philidor tweet media
English
1
1
4
147
zkoranges
zkoranges@zkoranges·
Google experimenting with zkPoEX: a reminder that groundbreaking technology doesn’t always find its purpose overnight. Sometimes, even the most powerful innovations take years before the right use case reveals their true value.
K Kulkarni@ks_kulk

Awesome to see @Google using SP1 to generate a ZK proof of the quantum circuit at the heart of their Shor’s algorithm attack on ECDSA. Beyond the landmark quantum result itself, this is a genuinely novel application of ZK, one that we should expect to see a lot more of. ZK lets you prove that you know a protocol is insecure without revealing the underlying attack. This opens up a new paradigm, “ZK disclosure”, whereby frontier labs can surface dangerous vulnerabilities without handing a loaded weapon to the world. Quantum computing is a great first use case, but the same logic applies wherever there is a gap between “proving something is broken” and “responsibly sharing the proof”. This includes AI alignment, zero-day exploits in critical infrastructure, and biosecurity. Exciting times for ZK and cryptography more broadly!

English
0
0
10
794
zkoranges
zkoranges@zkoranges·
At @philidorlabs we’re working on making sure you can understand the yield, and risks involved.
zkoranges tweet media
English
0
1
9
120
zkoranges
zkoranges@zkoranges·
Crypto projects love to advertise TEEs and zero-knowledge proofs, which often makes users assume they’re inherently more secure. But without proper due diligence, there’s a good chance these claims are more marketing than substance.
Wojciech Aleksander Wołoszyn@WAWoloszyn

Spent the weekend auditing TEE-based crypto projects on mainnets. It’s worse than I expected. “Remote attestation” is mostly just theatre. With one exception (Flashbots), users are being sold security properties that simply aren’t there.

English
0
0
6
175
zkoranges รีทวีตแล้ว
Philidor
Philidor@philidorlabs·
Regarding the USR exploit: Philidor Vaults are NOT exposed. In addition, all of the vaults exposed to USR were marked as “Edge” by our transparent risk methodology.
English
1
2
7
522
zkoranges รีทวีตแล้ว
Zdeadex
Zdeadex@Zdeadex·
The problem with promoted “Core” vaults: they’re often Edge in practice Gauntlet USDC Core, marketed as core, shows up as Edge (~4.9/10) on @philidorlabs when you apply a transparent methodology and look at collateral exposure, not the label Don’t trust, Verify
Zdeadex tweet media
Anton Cheng@antonttc

If you have any funds in Gauntlet USDC Core / Smokehouse USDC vaults on Morpho. Withdraw NOW. #overview" target="_blank" rel="nofollow noopener">app.morpho.org/ethereum/vault…

English
1
1
3
433
zkoranges
zkoranges@zkoranges·
So glad I didn't waste my time learning React, now that it doesn't matter anymore
English
1
0
3
38
zkoranges
zkoranges@zkoranges·
@StaniKulechov Interface shouldn't display swaps with such high price impact though...
English
1
0
3
142
Stani
Stani@StaniKulechov·
Earlier today, a user attempted to buy AAVE using $50M USDT through the Aave interface. Given the unusually large size of the single order, the Aave interface, like most trading interfaces, warned the user about extraordinary slippage and required confirmation via a checkbox. The user confirmed the warning on their mobile device and proceeded with the swap, accepting the high slippage, which ultimately resulted in receiving only 324 AAVE in return. The transaction could not be moved forward without the user explicitly accepting the risk through the confirmation checkbox. The CoW Swap routers functioned as intended, and the integration followed standard industry practices. However, while the user was able to proceed with the swap, the final outcome was clearly far from optimal. Events like this do occur in DeFi, but the scale of this transaction was significantly larger than what is typically seen in the space. We sympathize with the user and will try to make a contact with the user and we will return $600K in fees collected from the transaction. The key takeaway is that while DeFi should remain open and permissionless, allowing users to perform transactions freely, there are additional guardrails the industry can build to better protect users. Our team will be investigating ways to improve these safeguards going forward.
English
2.9K
991
11.1K
6.6M
zkoranges
zkoranges@zkoranges·
Can we agree to abolish light mode? My eyes hurt.
English
0
0
5
67
zkoranges รีทวีตแล้ว
Zdeadex
Zdeadex@Zdeadex·
Playing with @philidorlabs skills, soon gonna release more details on how DeFi managers, Institutions and more can use them to allocate in DeFi Start by checking your portfolio philidor portfolio 0xxxxx
Zdeadex tweet media
English
2
1
5
272
Theo
Theo@Theo_Network·
1/ Introducing thUSD: the yield-bearing stablecoin powered by gold.
English
85
2.3K
985
200.9K
zkoranges
zkoranges@zkoranges·
open-source models are the only ones we can reliably trust from here on out: the weights and code can be inspected, audited, and self-hosted (although not cost-efficiently yet). U.S. AI stocks look increasingly fragile: faster-moving chinese model releases raise the competitive bar, while shifting U.S. policy adds real uncertainty to the market.
Balaji@balajis

It’s all open source models from here. American AI companies are simultaneously fighting Democrats (by automating blue jobs), Republicans (by rankling the US military), and China (by fruitlessly combating distillation attacks). Solve for the equilibrium: open source models become the only trusted models. Centralized American AI burns bright, makes a ton of money, but eventually gets outcompeted by the privacy, freedom, and trust of decentralized local AI.

English
0
0
6
119
zkoranges
zkoranges@zkoranges·
@_Akanoa_ Must-have to reduce context usage
English
0
0
1
1.5K
zkoranges
zkoranges@zkoranges·
1/ Most DeFi risk scores are a single number with no explanation. Some are gated behind a pro account. A "7/10" tells you nothing. Is it the collateral? The contracts? The governance? Without decomposition, you're trusting a black box that masks the one dimension that could cause total loss.
zkoranges tweet media
English
2
1
8
412
zkoranges
zkoranges@zkoranges·
7/ We're still working on the fine-tuning of the risk methodology and more updates are coming. If you have any comments or questions, DM or comment. Happy to share ideas.
English
0
0
6
45
zkoranges
zkoranges@zkoranges·
6/ Every weight, threshold, and override rule is published. Same on-chain inputs always produce the same output. No editorial discretion. No "we know the team" adjustments. A risk framework that can't withstand scrutiny is not a framework: it's an opinion. 759 vaults scored, open: analytics.philidor.io/vaults
English
1
0
6
53