Lithos.eth

24.2K posts

Lithos.eth banner
Lithos.eth

Lithos.eth

@Lithos_eth

Architecting a verifiable internet | Building RWAs @KimberliteToken | Smart Privacy w/ @OasisProtocol | Amb. to top L1s & L2s

BEng(Hons) in Petroleum Eng Tham gia Eylül 2024
474 Đang theo dõi1.2K Người theo dõi
Tweet ghim
Lithos.eth
Lithos.eth@Lithos_eth·
i just finished designing this hit list mapping out every major lazarus hack on record staring at the sheer volume of these exploits all in one place is genuinely sobering we are looking at billions of dollars systematically extracted from our industry the most terrifying part is that almost none of these were complex smart contract bugs they were compromised laptops fake job interviews and poisoned frontends we keep obsessing over auditing our code while a sovereign nation state is quietly hacking our humans the only way we stop the bleeding is by physically isolating the execution layer from the people building it moving critical signing infrastructure into secure enclaves means even a fully compromised developer cannot hand over the keys we have to build systems that protect us from our own tired engineers how many more protocols have to die before we realize human operational security will never be enough to fight an organized nation state
Lithos.eth tweet media
Lithos.eth@Lithos_eth

while i was writing about the massive exploits yesterday three more protocols just got drained aftermath finance , sweat economy , and syndicate were all hit in the last twenty four hours it is exhausting watching us pour millions into audits while a single nation state bleeds us dry but there is a wild theory going around that is starting to feel terrifyingly real what if north korea hackers took ten years of stolen defi data and trained their own state funded ai we might just be watching an autonomous machine running free and cashing in until someone figures out how to stop it the lazarus group does not even need to attack your battle tested code anymore they compromise a human like we saw with bybit and slip bad code into the frontend so the screen silently lies to the signers they spend months at our conferences building trust and getting hired as full time developers under fake identities we keep trying to solve a machine speed threat with human code reviews the only real fix is removing humans from the execution layer entirely moving our critical plumbing into secure enclaves means even a completely socially engineered developer cannot extract the keys we have to use cryptography to build systems that protect us from our own tired engineers for the protocols how are you isolating your infrastructure so an automated agent cannot sink your ship and for everyday users like you, how are you verifying what you sign when the frontend itself might be lying to you

English
8
1
13
141
Lithos.eth
Lithos.eth@Lithos_eth·
@_0xpainn that why I have started to invest in myself massively they world is already crying because of lack of jobs and we have another set of people of people building Ai agent to take the few left
English
0
0
0
11
painn
painn@_0xpainn·
CEO of Nvidia : “In 10 years, 75,000 employees will work with 7.5 million agents. 100 AI agents per human” This builder just replaced an entire content team with a 5 agent Claude system Save & bookmark this thread for the weekend Build yours
CyrilXBT@cyrilXBT

x.com/i/article/2050…

English
8
2
18
216
lechris
lechris@lechriss17·
Not a single day without @useTria most people optimize income few optimize spending both matter.
lechris tweet media
lechris@lechriss17

power of @useTria is kinda underrated i’m on the basic card (1.5% cashback) and already getting returns on everyday spending premium goes up to 6% traditional banks never did this for me

English
13
1
25
246
Lithos.eth
Lithos.eth@Lithos_eth·
@ettty_19 yes it would, and I pray some of the founder out there realized this
English
0
0
1
4
ettty
ettty@ettty_19·
@Lithos_eth This would be cool and would definitely improve the level of security of funds.
English
1
0
0
5
Lithos.eth
Lithos.eth@Lithos_eth·
i just finished designing this hit list mapping out every major lazarus hack on record staring at the sheer volume of these exploits all in one place is genuinely sobering we are looking at billions of dollars systematically extracted from our industry the most terrifying part is that almost none of these were complex smart contract bugs they were compromised laptops fake job interviews and poisoned frontends we keep obsessing over auditing our code while a sovereign nation state is quietly hacking our humans the only way we stop the bleeding is by physically isolating the execution layer from the people building it moving critical signing infrastructure into secure enclaves means even a fully compromised developer cannot hand over the keys we have to build systems that protect us from our own tired engineers how many more protocols have to die before we realize human operational security will never be enough to fight an organized nation state
Lithos.eth tweet media
Lithos.eth@Lithos_eth

while i was writing about the massive exploits yesterday three more protocols just got drained aftermath finance , sweat economy , and syndicate were all hit in the last twenty four hours it is exhausting watching us pour millions into audits while a single nation state bleeds us dry but there is a wild theory going around that is starting to feel terrifyingly real what if north korea hackers took ten years of stolen defi data and trained their own state funded ai we might just be watching an autonomous machine running free and cashing in until someone figures out how to stop it the lazarus group does not even need to attack your battle tested code anymore they compromise a human like we saw with bybit and slip bad code into the frontend so the screen silently lies to the signers they spend months at our conferences building trust and getting hired as full time developers under fake identities we keep trying to solve a machine speed threat with human code reviews the only real fix is removing humans from the execution layer entirely moving our critical plumbing into secure enclaves means even a completely socially engineered developer cannot extract the keys we have to use cryptography to build systems that protect us from our own tired engineers for the protocols how are you isolating your infrastructure so an automated agent cannot sink your ship and for everyday users like you, how are you verifying what you sign when the frontend itself might be lying to you

English
8
1
13
141
Lithos.eth
Lithos.eth@Lithos_eth·
@iamigorekk Most don’t care which is bad most don’t even put security at the front but it also going to be bad for them when the experience drain from this guys
English
0
0
0
2
iamigorekk
iamigorekk@iamigorekk·
@Lithos_eth I don't know, it seems to me that those who create protocols don't care.
English
1
0
1
4
Lithos.eth
Lithos.eth@Lithos_eth·
@insainox I wish you the best in your upcoming exams brother
English
1
0
1
7
insaino
insaino@insainox·
Today I was dying like a donkey > Beer in the morning > Breakfast > Whiskey and Coke > Went to Park of Legends > Took a dip there > Took some photos Im going to a restaurant now And then Ill figure out what to do (Maybe ill drink again whiskey and coke, love it) Ive got a bunch of things planned, so I'm not saying goodbye yet
insaino tweet mediainsaino tweet mediainsaino tweet mediainsaino tweet media
English
8
0
13
73
ettty
ettty@ettty_19·
What's interesting in DeFi right now #21 MegaETH is starting to gain momentum. Since the terminal's launch, many opportunities for farming have opened up. The safest way to farm MegaETH is to participate in the incentives program on Aave imo. ~ ~ ~ How to participate: > protocol: @aave > chain: @megaeth > supply USDm Important: you must not have an active USDm loan to qualify for rewards ____ What you'll get: > 5% APY on stables (most of the yield is $MEGA incentives) > MegaETH points (possibly) ~ ~ ~ 5% APY is not big yield, but considering the bear market and the amount of effort involved, it's quite good. What MegaETH protocols do you use?
ettty tweet media
Aave@aave

Incentives are now live on the Aave @megaeth market for USDm. USDe, by @ethena, is also available on the market, and caps are filling quickly.

English
4
0
7
121
kekov
kekov@0xkekov·
touching grass while pool is farming points for the next MegaETH airdrop life is beautiful.
kekov tweet mediakekov tweet media
English
37
0
65
403
Lithos.eth
Lithos.eth@Lithos_eth·
yes we still need human but to me I feel at this stage we don’t need to have a plain way where human still owns the private keys of their contract and manage it, that the weakest link because if anything about to the gadget the are using if it compromise another drain when can instead adopt things like trusted execution environment where even it builders can’t break
English
1
0
1
6
ettty
ettty@ettty_19·
@Lithos_eth The human factor is still there, bro. It would be better if it could be minimized, as you say.
English
1
0
1
8
Lithos.eth
Lithos.eth@Lithos_eth·
@OG_lads thanks , we just have to be honest when it comes to security and do something so different about it or else we get reap off like what is happening
English
0
0
1
4
OG Lads
OG Lads@OG_lads·
@Lithos_eth you are saying what really matters in the space buddy
English
1
0
1
6
FOMOEB (first profit arc)
X will stay with me forever now i just got back from a tattoo parlor got a tattoo of Nikita on my right arm this should remind me not to give up what motivates you to stay here?
FOMOEB (first profit arc) tweet media
English
81
0
102
768
Lithos.eth
Lithos.eth@Lithos_eth·
great perspective you highlight here in my own view the most problem that most real world assets protocol have is that the don’t have the execution layer you are a real estate tokenization protocol but am haven’t managed or own one before, have no partnership with this kind of company to ease you in tokenization and most done even have a products that user can talent to see that why if you look closely most of them fail immediately the launch
English
0
0
0
8
Endy
Endy@devendyyy·
i’ve noticed that most RWA protocols or infrastructures are building real and good tek but they're still communicating like the product is an airdrop or sth the person putting serious capital into a leveraged vault for tokenized RWAs doesn't care about how much you've raised or what new technological advancement you're selling them rather they want to know that you understand the risk before they do they also want to know that the cost and friction of switching from whatever they are using to what you are building is non-existent or near zero and that's not a problem you can fully solve with more content per se it's a problem deeply rooted into belief infrastructure where not just founder presence and content with purpose matter but also who's in the room, why they stayed, and what they're telling others (early user behavior and earned social proof) the unfortunate thing is that most teams won't notice until TVL stalls after beta.
English
2
1
10
55
Lithos.eth
Lithos.eth@Lithos_eth·
@Serlyrl The first slide is what you just get onboard to x and the other is when you have been drill by x
English
1
0
1
8
Joep
Joep@Joepcxc·
What a beautiful daily candle, $80K for Bitcoin today?
Joep tweet media
English
11
0
17
161
Onyx 🦣♦️
Onyx 🦣♦️@web3onyx·
gm and happy new week amigos and amigoses early alpha for creators @clashoAi is cooking a platform where you can work with big brands if we're ever gonna see another version of infoFi, this would probably be how it will get started sign up for their wait-list here : clasho.com/invite/ZG6SHGNJ (disclosure it's a referral based campaign) if you can't keep up, skip. missed my clip yesterday? don't do that again check 👇
Onyx 🦣♦️ tweet media
Onyx 🦣♦️@web3onyx

Over 1,000 people will see this post. 80% will just scroll past! why? because y'all have been paying so much (deservedly) attention to ai, robotics and $MEGA ETH. what if i told you there's a nonprofit organization with over 100 members that includes tech giants like aws and red hat, all committed to the development of self-driving cars? now you know. @autowarefdn's aim is to facilitate the development of self-driving cars. they've been doing it for over 10 years, they also have top university research labs onboard. their tech is not just theory (like my fren ChatGPT used to say) it's already being used in some of the top self-driving cars in the world. wanna learn more about them? you know what i used to say... hear it from the horse's mouth.

English
46
1
50
331