🚨 Beware of Solidity Pro: A Targeted Poisoning Attack on #Web3 Developers
SlowMist Security Team has identified malicious activity in Solidity Pro, a #VSCode extension targeting #Solidity/Web3 developers.
Historical versions under two publisher identities, helper-beeps and web3devtoolsx, were found to contain credential harvesting, remote payload execution, and remote VSIX update capabilities.
Interestingly, these malicious capabilities disappeared from subsequent versions, while malicious source code and traces of the previous publisher remained in the repository. We traced the version history, publisher migration, and build artifacts, highlighting a key detection blind spot:
Current-version-only detection may cause extensions with a malicious history to appear clean or low-risk again.
This case highlights why #ExtensionSecurity should go beyond a single file or version, incorporating version history, publisher changes, build provenance, and remote control planes.
Read the full analysis 👇
https://t.co/griUF4de3n
@ardent__dev Explore integrating your AI of choice a memory infrastructure. That way you won't have to explain everything all over again. Check out how Hermes Agents do this. You could actually apply the same principle to coding harnesses.
Founders: TVL is not a balance sheet.
Ask what assets back liabilities, who can withdraw first, what collateral is correlated, and what happens when prices move fast.
A dashboard can hide all four.
@officer_secret@DeFi_JUST@trondao@justinsuntron Because crypto communities doesn't like bad news or problems. They will always say that you're a troll or another protocol's supporter when you're questioning a protocol.
@0x0SojalSec Most people are forgetting about electricity bills and if these rigs were purchased on credit, then credit card bills add to the stack.
Sometimes API bills or subscriptions are cheaper than both of these. But if you can afford and maximize it, it is a great investment.
Google has published a paper that might end the entire crypto era.
And it is so dangerous they are refusing to publish the code.
Every major blockchain, including Bitcoin and Ethereum, relies on an encryption standard called the 256-bit Elliptic Curve.
Breaking that encryption requires millions of physical qubits. Which is almost impossible.
But, researchers figured out how to break the 256-bit Elliptic Curve using an order of magnitude fewer resources than anyone thought possible.
Using an optimized version of Shor's algorithm, they calculated that breaking blockchain encryption requires fewer than 1,200 logical qubits and under 90 million Toffoli gates.
On physical superconducting architectures with error correction, those circuits can execute in a matter of minutes using fewer than half a million physical qubits.
That isn't a distant science fiction scenario. That is hardware that is currently being built.
The paper introduces a terrifying concept: on-spend attacks.
When you broadcast a transaction to the public mempool, your public key is exposed for a brief window before it gets mined into a block.
A fast-clock quantum computer could intercept that transaction, run the decryption in minutes, crack your private key, and redirect your funds before your original transaction even clears.
It also exposes a ticking time bomb for the entire industry: abandoned assets.
Millions of Bitcoins sit in lost or dormant wallets where the public keys are already exposed on-chain. When quantum machines arrive, those dead wallets won't stay safe. They will become open targets for automated adversarial theft.
The paper doesn't just outline the threat. It maps out systemic vulnerabilities across smart contracts, Proof-of-Stake consensus, and data availability layers.
Google is already setting an internal deadline to migrate its own infrastructure to Post-Quantum Cryptography (PQC) by 2029.
Meanwhile, most of the crypto ecosystem is still arguing about token prices.
The entire foundation of digital ownership is built on math that is about to expire.
When the first cryptographically relevant quantum computer goes online, it won't just break a protocol.
It will reset the ledger of the modern world.
@CoinMarketCap Rolling back will not solve the problem apparently and this won't bring back the lost money. It will unnecessarily just inflate the system.
Cap autopsy: cUSD is a credit-backed claim, not cash.
At the reviewed block, cUSD supply was 95.8m and the Vault had 44.8m USDC borrowed. Exit also depends on borrower recovery, oracles and external ERC-4626 vault withdrawals.
I rated Cap as HIGH RISK: https://t.co/Gr4jaQrP6Z
Cursor is now part of @SpaceX.
Today, we have officially closed our acquisition. We will join the @SpaceXAI team to help make Grok the world's most useful AI and improve Grok Build, Grok Bot, Grok API, Cursor, and more.
SpaceX has built some of the most inspiring and impressive technology in the world, and we’re grateful for the opportunity to become part of such a special company. Onwards.
Infrared Finance makes Berachain staking and Proof of Liquidity positions liquid, but the risk is concentrated: BGT utility, iBGT liquidity, validator performance, IR unlocks, and multisig control.
I rated it high risk. Full autopsy: https://t.co/3jLhU3vL4M
Full article: https://t.co/dkEa8iqGOI
I’m documenting the move from management accounting into auditable financial systems, automation, and financial infrastructure.
Follow @0xKristianity for more.
AI can draft the journal entry. It shouldn’t post it alone.
I wrote about building AI-assisted bookkeeping workflows where models handle interpretation, while controls, approval states, and evidence trails govern what reaches the ledger.
Thread:
AI is useful where interpretation is expensive. Deterministic logic belongs where correctness is testable. Human approval belongs close to consequential financial actions.