Tradecraft is live on Base! It's been cooking for several weeks and happy to say that it's finally out.
All the functionalities are there, like the on-chain signal lab (including the backtester) the integrations with messaging apps to detect Base calls and the JavaScript strategies with the AI assistant.
Looking forward to connect with others and learn more about this ecosystem. Anyone that is an advanced trader on Base please do sign up to the beta, you will be whitelisted. The form and screenshots of the site are available at https://t.co/Glv8DfBdKy
@base@jessepollak
It's a ChatGPT-like app, but private. It's not spying on you. Your chat history stays in your browser. It's local, it's encrypted and technically safe.
That's @AskVenice for you.
A security researcher just documented a large-scale counterfeit Ledger Nano S Plus operation selling compromised devices across multiple online marketplaces.
The fake units look identical to the real thing but contain completely different hardware. Instead of Ledger's secure element chip, the counterfeits run an ESP32 microcontroller with modified firmware labeled "Nano S+ V2.1." Seeds and PINs are stored in plain text and transmitted to attacker-controlled servers. Any wallet initialized on the device is drained.
The operation goes beyond the hardware. The sellers also distribute a fake version of Ledger Live built with React Native and signed with a debug certificate. It intercepts transactions and exfiltrates sensitive data to multiple command-and-control servers. The campaign spans five attack vectors: compromised hardware, Android APKs, Windows executables, macOS installers, and iOS apps distributed through TestFlight to bypass App Store review.
This comes days after ZachXBT documented a separate fake Ledger Live app that made it through Apple's Mac App Store review process. That operation drained over $9.5 million from more than 50 victims, including musician G. Love, who lost 5.92 BTC after entering his recovery phrase into what he believed was the legitimate app.
The pattern is clear: the attack surface for hardware wallet users has shifted from firmware exploits to supply chain and distribution fraud. The devices themselves remain secure. The problem is that users are being intercepted before they ever touch a real one.
Ledger's own "genuine check" feature can be bypassed when the hardware itself is compromised at the source, which makes where you buy the device as important as how you use it.
The rules haven't changed, but they've never been more important: buy hardware wallets only from the manufacturer. Never enter your recovery phrase into any software. If a companion app asks for your 24 words on a screen, it's a scam. Every time.
I just joined the World Monitor Pro waitlist — stock monitoring, geopolitical analysis, and AI daily briefings in one platform. Join me: https://t.co/YJK2vfspRm
INTEL: BLOCKAID SAYS ITS SYSTEM IDENTIFIED A FRONT END ATTACK ON COWSWAP, COW[.]FI FLAGGED AS MALICIOUS, USERS WITH CONNECTED WALLETS URGED TO REVOKE APPROVALS AND AVOID INTERACTIONS IMMEDIATELY
🚨🚨
We are currently experiencing an issue with the CoW Swap frontend (https://t.co/GPQ8bBzftU). While we are investigating, please DO NOT use CoW Swap.
@blocmates Does GIZA have any mechanisms in place that protect it from getting scammed, e.g., by a fake stable coin pool offering super attractive APY but being a honey pot?
Proximity is now live on the App Store. If you're an early user, please drop a rating, or even better, a review. It means the world to us.
https://t.co/2vaF1XXRee
@crypto_condom „Age assurance is only required if a user wants to access age-restricted content and features or update the teen-by-default safety settings.“
So we will all be treated teens per default.
Most of the stuff reads like good security practices anyways, but there will be downsides...