Nethny

182 posts

Nethny banner
Nethny

Nethny

@nethny_dev

building in Solana ecosystem exploring blockchain × AI learning in public 🔭

USA 加入时间 Temmuz 2021
41 关注28 粉丝
置顶推文
Nethny
Nethny@nethny_dev·
$1.8B stolen across Bybit, Step Finance, and Drift - and not a single one was a smart contract bug. Drift's $285M wasn't a program exploit. It was social engineering against the Security Council multisig. Durable nonces kept signatures alive while signers got compromised one by one. We keep auditing contracts. Attackers keep walking around them. The unsolved problem in DeFi security isn't code - it's proving that a human actually looked at what they signed.
Nethny tweet media
English
3
0
4
60
Nethny
Nethny@nethny_dev·
@anza_xyz so Alpenglow depends on this for on-chain PoP verification - does that mean the voting program migration to BPF is blocking Alpenglow, or can they run in parallel?
English
0
0
0
55
Anza
Anza@anza_xyz·
1/ SIMD-0388 proposes a new family of syscalls for the BLS12-381 elliptic curve. This brings native support for a modern, 128-bit security pairing-friendly curve to Solana programs. Here's what changes 🧵
Anza tweet media
English
13
5
33
14.5K
Nethny
Nethny@nethny_dev·
@mert the shannon analogy is strong but it cuts both ways - fiber optics needed pure glass to work. right now the chain is pure but the endpoints aren't. every major hack this year was a human, not a contract
English
0
0
0
29
Nethny
Nethny@nethny_dev·
@0xYankee 52 real buyers in $10.4M of volume. fifty two. and people wonder why their organic score is low
English
0
0
0
26
Nethny
Nethny@nethny_dev·
inspired by @karpathy's workflow - adapted for crypto dev where half the docs are scattered across 5 platforms and outdated by next week
English
0
0
1
8
Nethny
Nethny@nethny_dev·
karpathy just shared his setup for LLM-compiled knowledge bases - raw docs go into a wiki maintained by agents, then you query it like a research assistant now think about this for crypto. every protocol has docs scattered across gitbooks, github, medium, discord. half of it outdated by the time you find it one local wiki where you ask "cheapest way to batch token transfers on Solana" and your agent cross-references frameworks, token extensions, and RPC limits in seconds the real AI × crypto build isn't another token. it's tooling that lets you actually navigate this ecosystem
Nethny tweet media
English
1
0
3
26
Nethny
Nethny@nethny_dev·
@ivan_nomadz @solana solid map but missing a dev tooling section. built for MONOLITH with quasar + claude code + awesome-solana-ai + trident for fuzzing - would be a solid addition to v3
English
1
0
2
132
Ivan 🧳
Ivan 🧳@ivan_nomadz·
Solana Ecosystem Map 2026 for Founders {v.2} The opportunities to build on @solana are massive, so it wasn’t possible to include everything in one post. Here’s an update: 1. Investment communities They can help you get funding on fair terms, often easier than pitching traditional VCs. > Monke Ventures {@MonkeVentures} The investment syndicate of @MonkeDAO, democratizing high-quality deal flow for everyday investors. The syndicate has funded over 40+ teams, with $2M+ in total funding. > Superteam syndicate at the @echodotxyz Lets people invest in crypto startups and token projects by joining private funding rounds alongside top investors. 2. Hackatons Hackathons allow you to test your product in real conditions, receive feedback, secure early funding, and build long-term relationships. > @colosseum: main {twice a year} and Eternal > @solanamobile & @RadiantsDAO focused on mobile apps for Seeker > @superteam's local hackathons 3. Grants {Non-Dilutive Funding} At an early stage, raising large amounts of venture capital is rare. Better start with smaller, strategic funding that validates your project. > @SolanaFndn {~$40 000} > @solanamobile {~$10 000} > @superteam {~$10 000} > @Kalshi {$2 000 000 pool} > @MetaplexFndn {based on DAO decision} 4. Accelerators Accelerators provide structured support in product development, go-to-market strategy, fundraising preparation, and network access. > @colosseum > @OrangeDAOxyz > @incubator > @alliance > @MonkeFoundry > @a16zcrypto > @OnePieceLabs > @venture_launch 5. Conferences and IRL Events Strategic conversations at events often lead to partnerships, funding, and distribution opportunities. > Solana Breakpoint & Accelerate by @SolanaEvents > Events by @MeteoraAG and @JupiterExchange > Solana Summits hosted by Superteams 6. Podcasts To stay in sync with Solana news, opportunities, and learn how others operate, follow pages who consistently share insights. > Billions hosted by @Pedromiranda > Bits to Bricks hosted by @amiravalliani > Open Intelligence hosted by @_rishinsharma > On The Road hosted by @nickducoff > Solana is Global hosted by @afscott > The Stack hosted by @nocircuit > Validated {@ValidatedPod} hosted by @Austin_Federa > The Index Podcast {@theindexshow} hosted by @afkehaya > Lightspeed {@LightspeedpodHQ} hosted by @defi_kay_ > Solfate Podcast {@SolfatePod} hosted by @jamesrp13 & @nickfrosty > Talking Tokens {@_TalkingTokens} hosted by @jacqmelinek > SOL BROTHERS {@SolBrothersPod} hosted by @YouKnowEno & @simonmolitor > Ownership {@ownershipfm} hosted by @8bitpenis Bookmark this map and share it with others. Also check the previous one for more opportunities 👇
Ivan 🧳 tweet media
Ivan 🧳@ivan_nomadz

Solana Ecosystem Map 2026 for Founders. @solana remains the strongest ecosystem to build on in crypto. As the founder of @NOMADZxyz, I have spent years navigating the ecosystem end to end. From communities and hackathons to grants, accelerators, and fundraising, I have personally gone through each stage. Based on that experience, here is a clear roadmap of the sources that deserve your attention in 2026. 1. Communities Your starting point should be people. Surround yourself with founders, builders, and contributors who are already active in the ecosystem. Start with: ➩ Global @superteam and local Superteams such as @SuperteamAE, @SuperteamDE, @SuperteamPOL, @SuperteamUKR, and others. This is also one of the strongest entry points to access experienced builders and early-stage funding through Instagrants (up to $10k grants). ➩ Solana-native communities such as @MonkeDAO, @islanddao, and @MadLads. 2. Hackathons Hackathons allow you to test your product in real conditions, receive feedback, secure early funding, and build long-term relationships. Programs worth your attention: ➩ @colosseum, including main (twice a year) and Eternal tracks. ➩ @solanamobile & @RadiantsDAO, focused on mobile apps for the Solana dApp Store. ➩ Solana hackathons by @Arcium and @magicblock with multiple additional bounties. ➩ Local hackathons organized by Superteams. 3. Grants (Non-Dilutive Funding) At an early stage, raising large amounts of venture capital is rare. Start with smaller, strategic funding that validates your project and extends your runway. Key sources: ➩ @SolanaFndn ($40k on average) ➩ @MetaplexFndn (based on DAO decision) ➩ @superteam (up to $10k) ➩ @solanamobile (up to $10k) ➩ @MonkeFoundry (up to $10k) 4. Accelerators Accelerators provide structured support in product development, go-to-market strategy, fundraising preparation, and network access. Leading programs: ➩ @colosseum@OrangeDAOxyz@incubator led by @solanalabs@venture_launch@alliance 5. Conferences and IRL Events Physical presence accelerates trust and relationship building. Strategic conversations at events often lead to partnerships, funding, and distribution opportunities. Events that consistently generate outcomes: ➩ Solana Breakpoint and Accelerate by @SolanaEvents. ➩ Regional events hosted by Superteams. ➩ Events organized by ecosystem companies such as @Backpack, @MeteoraAG and @JupiterExchange. 6. Bootcamps Bootcamps provide focused education and deep ecosystem immersion. They strengthen both expertise and relationships within specific verticals. Strong options include: ➩ @mtndao@venture_launch@sns Month at the @ns This roadmap is based on personal experience. I have gone through almost all of these programs and understand the practical value they bring to founders. Comment “Founder” and I will send you additional opportunities I am currently tracking inside the Solana ecosystem.

English
52
49
360
44.7K
Nethny
Nethny@nethny_dev·
@mert The scariest part is how low-tech these attacks are. No zero-days, no flash loans - just patience and social engineering against the people holding the keys. We've gotten good at making contracts secure. Now we need the same rigor for everything around them.
English
1
1
1
89
mert
mert@mert·
crypto eliminates opaqueness and central points of failure in financial code, but humans remain the bottleneck most hacks come down to the simple act of one clicking a link they shouldn't have clicked these are picking up in pace, be extra cautious clicking any link or file
Muyao@MuyaoShen

updated the Drift hack story: what the hack exposed is not a weakness in DeFi's tech, but a human weak link - as @mert told me. do you agree? bloomberg.com/news/articles/…

English
40
7
160
26K
Nethny
Nethny@nethny_dev·
The speed of the ecosystem response yesterday showed exactly how strong this community is. That coordination matters. One thing this incident made clear: the contracts held. The vulnerability was at the human and operational layer. As the Foundation builds out those support channels, signer opsec and key management standards could be the highest-ROI investment for the whole ecosystem.
English
1
0
0
477
Ramzy
Ramzy@ramzyyalii·
Yesterday was profoundly unfortunate and unfair to everyone who has been affected. I would like to start off by thanking all the ecosystem participants and partners who sprung into action the moment the exploit happened. It is times like these that unfortunately do bring us all closer together and this was a prime example of how strong the Solana developer community is as well as how supportive our ecosystem of partners have become. I want to highlight that this was a sophisticated attack and that the objective root cause is still being investigated. What I can tell you all is that Solana remains strong and many critical components of the Solana DeFi ecosystem are completely unaffected by this attack. The Solana Foundation is working to establish support channels for teams to ensure security is robust and will be providing more information soon. We will come out of this stronger than ever - of that I am absolutely sure.
Drift@DriftProtocol

Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers. This was a highly sophisticated operation that appears to have involved multi-week preparation and staged execution, including the use of durable nonce accounts to pre-sign transactions that delayed execution.

English
19
26
240
28.6K
Nethny
Nethny@nethny_dev·
Agents monitoring is one layer, but the core issue is the moment of signing. An agent can flag a suspicious tx - but can it verify that the human signer actually understood what they approved? That gap between detection and deliberate human decision is where these attacks keep landing.
English
0
0
2
52
thedev
thedev@x402juice·
@nethny_dev @calilyliu Agentic commerce is coming. We’ll soon have Agents working every second as a security barrier
English
1
0
3
62
Lily Liu
Lily Liu@calilyliu·
The Drift incident hits hard, it stings for the whole ecosystem. Drift has been working around the clock to investigate and contain it. We're supporting where possible. Smart contracts held up. The real targets now are humans: social engineering and opsec weaknesses more than code exploits. Solana has come through tough spots before by shipping faster, building better, looking out for each other - and shipping safer. Stay safe, watch your own setups, and keep building. More updates as they come.
Drift@DriftProtocol

Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers. This was a highly sophisticated operation that appears to have involved multi-week preparation and staged execution, including the use of durable nonce accounts to pre-sign transactions that delayed execution.

English
42
30
402
76K
Nethny
Nethny@nethny_dev·
For context: - Bybit ($1.5B, Feb 2025): compromised Safe wallet dev, UI manipulation + blind signing - Step Finance ($40M, Jan 2026): executive devices compromised, project shut down - Drift ($285M, Apr 2026): Security Council multisig social engineered via durable nonces @vibhu confirmed: "no program or smart contract exploit" The attack vector has moved. The defensive stack hasn't.
English
0
0
2
39
Nethny
Nethny@nethny_dev·
$1.8B stolen across Bybit, Step Finance, and Drift - and not a single one was a smart contract bug. Drift's $285M wasn't a program exploit. It was social engineering against the Security Council multisig. Durable nonces kept signatures alive while signers got compromised one by one. We keep auditing contracts. Attackers keep walking around them. The unsolved problem in DeFi security isn't code - it's proving that a human actually looked at what they signed.
Nethny tweet media
English
3
0
4
60
Nethny
Nethny@nethny_dev·
@SolanaFloor @Ledger @DriftProtocol @P3b7_ The scariest part is the consistency. Bybit ($1.5B), Step Finance ($40M), now Drift ($285M) - same playbook every time: skip the contracts, compromise the humans. $1.8B drained in a little over a year and not a single line of Solidity or Rust was the problem.
English
0
0
0
366
SolanaFloor
SolanaFloor@SolanaFloor·
NEW: @Ledger CTO Charles Guillemet says the @DriftProtocol hack reflects a familiar DPRK-linked pattern, a patient supply-chain-level compromise targeting human signers rather than smart contracts.
SolanaFloor tweet mediaSolanaFloor tweet media
English
6
8
117
8.9K
Nethny
Nethny@nethny_dev·
the pattern across Bybit, Neutrl, Drift is the same: the weakest link isn't the contract, it's human attention under pressure. maturity as an industry probably means hardware that enforces deliberate signing - not just "be more careful." you can't opsec your way out of sophisticated social engineering forever.
English
0
0
1
98
chase
chase@therealchaseeb·
I thought we had somewhat rid ourselves of most of the worst type of people in the space as we crossed into a bear market. But DeFi hacks and other things of this nature that involve real people and real money tend to show true colors, and it’s obvious we’ve barely matured as an industry, if at all. Sad day for Solana but also sad day for DeFi and the space in general. This impacts everyone who has dedicated their life to building here every day. There are obvious lessons to be learned from this. No one is immune, even if you avoided it this time. The industry is a massive target for sophisticated state actors. Still tons of work to do to improve. Otherwise what are we even doing here?
English
31
3
98
4.4K
Nethny
Nethny@nethny_dev·
PDAs solve the tx mechanics. but the Drift attack wasn't a tx problem - it was a human attention problem. signers were compromised before they touched any nonce. what if the hardware required proof you were deliberately focused before authorizing? you can replace the primitive, but you can't patch inattention at the protocol level.
English
0
0
0
46
toly 🇺🇸
toly 🇺🇸@toly·
@AlexSmirnov @trentdotsol There would be an equivalent replacement. You can basically do everything now with PDAs and trigger your own custom cpi.
English
4
0
4
495
Nethny
Nethny@nethny_dev·
pager duty is still reactive - someone has to notice and respond. what if the signing device required hardware-attested proof of deliberate attention before authorizing? attacker compromises the signer, but can't fake the 8-minute focus window. Seed Vault on Seeker could enforce this today. detection becomes irrelevant if signing is physically gated.
English
0
0
1
498
toly 🇺🇸
toly 🇺🇸@toly·
@trentdotsol They didn’t really hide it well. The nonce was assigned to the multisig signer, which should have been a red flag immediately and triggered pager duty.
English
7
3
98
10.6K
trent.sol
trent.sol@trentdotsol·
as the initial author and chief hater of durable nonces, i don't defend them often. despite the number of references in this thread, their only role in the hack was allowing the attacker to hide while they compromised signers. durable nonces aren't magic. they just extend tx ttl
Drift@DriftProtocol

Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers. This was a highly sophisticated operation that appears to have involved multi-week preparation and staged execution, including the use of durable nonce accounts to pre-sign transactions that delayed execution.

English
11
4
97
25.7K
Nethny
Nethny@nethny_dev·
The real gap isn't multisig - it's that signing proves key access, not deliberate human attention. What if high-value txs required hardware-attested proof that all signers were simultaneously in verified focus for the last 8 minutes? Gaze-tracked, Seed Vault signed. Social eng gets credentials, not temporal proof of collective deliberation. Is anyone building attestation at the biometric layer?
English
0
0
2
626
vibhu
vibhu@vibhu·
Drift was hit by a very sophisticated attack, the source of which is still being investigated There was no program or smart contract exploit Like almost all crypto hacks of late (Bybit, Neutrl, Step), this ultimately appears to be opsec/social engineering vs contract risk The unfortunate reality is that this happened to a Solana-based entity, but it could have happened to any protocol protected by a multisig on any chain There’s likely to be a lot of lessons to be learned and socialized once the full investigation is complete, but this is an isolated incident and says nothing about Solana DeFi or any other Solana product Of course, my heart goes out to everyone affected by this Today was very hard on many people including lots of friends and I’m personally filled with tremendous sadness, because nobody deserves this But I know the Solana DeFi community will pick up the pieces and rebuild fast as only Solana can
Drift@DriftProtocol

Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers. This was a highly sophisticated operation that appears to have involved multi-week preparation and staged execution, including the use of durable nonce accounts to pre-sign transactions that delayed execution.

English
87
42
436
67.1K
Nethny
Nethny@nethny_dev·
@cavemanloverboy [REDACTED] is just "ask again never" but at least Seeker exists. that's more concrete than most crypto roadmaps rn 💀
English
0
0
0
245
dr cavey phd ∿
dr cavey phd ∿@cavemanloverboy·
Some smart people tell me there is an earnest smart developer community in Solana, and now that [REDACTED], the chain has a bright future. Hard for me to tell from outside, but I hope the community gets its fair chance to thrive🦾🦾
English
11
4
151
11.3K
Nethny
Nethny@nethny_dev·
This is exactly what on-chain focus verification needs. If MetaTimer can predict LLM reasoning latency with 6% error, imagine using that same chain-of-thought decomposition to validate real focus signals on Seeker. Semantic complexity → attention depth. Have you thought about that layer?
English
0
0
0
23
toly 🇺🇸
toly 🇺🇸@toly·
MetaTimer: Using Large Language Models for Precise, Prompt-Aware Inference Latency Prediction The rapid proliferation of large language models (LLMs) in production systems has exposed a fundamental limitation: inference latency varies dramatically across prompts due to differences in semantic complexity, required reasoning depth, output length, and generation dynamics. Conventional prediction methods—ranging from token-count heuristics and hardware Roofline models to traditional machine-learning regressors—fail to generalize because they cannot capture these prompt-specific nuances. Accurate a priori estimation of processing time is essential for resource scheduling, dynamic batching, cost forecasting, service-level guarantees, and user-experience enhancements. We introduce MetaTimer, the first framework to repurpose a lightweight LLM itself as a high-precision meta-predictor capable of forecasting the exact wall-clock inference duration required by any target LLM for an arbitrary input prompt. A compact 8B-parameter model is fine-tuned on a massive corpus of millions of prompt–execution pairs collected across heterogeneous model families (GPT-4-class, Llama 3.1, Claude, Mistral), quantization levels, decoding strategies, and hardware accelerators. The predictor employs chain-of-thought reasoning to decompose prompt semantics, estimate output token distributions and reasoning trajectories, and integrate model- and hardware-specific performance profiles, yielding fine-grained predictions for Time-to-First-Token (TTFT), Time-Per-Output-Token (TPOT), and total latency. Extensive evaluations on held-out benchmarks spanning reasoning, creative writing, coding, and long-context tasks demonstrate state-of-the-art accuracy: a mean absolute percentage error (MAPE) of 6.3% for end-to-end latency—representing a >40% reduction in mean squared error relative to the strongest Roofline–ML baselines—and strong zero-shot generalization to unseen models and platforms. When integrated into production serving stacks (vLLM, TensorRT-LLM, Triton), MetaTimer delivers up to 31% gains in resource utilization and tail-latency reduction. These results establish that LLMs possess emergent capabilities for computational self-modeling, opening a new paradigm for self-aware, adaptive, and energy-efficient generative AI infrastructure. We publicly release the predictor model, dataset, and serving plugins to accelerate research in meta-performance modeling for frontier AI systems.
English
22
2
113
10.9K
Nethny
Nethny@nethny_dev·
@joshyote Scale without stickiness is just noise. What % of those 10B are MEV sandwiches vs actual user behavior? If we solve that, Solana really is bigger than Earth.
English
0
0
0
18
josh
josh@joshyote·
More quarterly transactions than people on earth. Solana is bigger than planet earth. Let that sink in.
Artemis@artemis

BREAKING: @solana crosses 10 BILLION quarterly transactions for the first time ever

English
5
0
18
1.2K