We’re excited to announce @zoodotfun, the launchpad for fun!
Zoo will launch on day 1 of @AbstractChain, the consumer chain. It’s a jungle in the trenches and it’s time to see the animals run wild.
Join the TG below to get ready for the launch!
@HackingButLegal This is what happens when you're so obsessed with your hair that you won't let your makeup person get near it because you don't pay them $70k a year to keep the single strand of hair looking like a toupee.
I'm one of those people who's face has subtitles, but the subs were written by someone who doesn't speak the language and gets easily distracted by shiny objects and kittens.
Introducing Basecamp, a tool to launch @base coins directly on Uniswap
No initial liquidity needed, only Base gas fees. Uniswap liquidity locked on launch. Creators earn ⅔ of LP fees and keep 5% of supply.
Launch a coin or see what has been launched: https://t.co/ABRoN1c6G5
This shows exactly what I mean when I say, "It is okay to NOT have an opinion about every single thing." 2020 people felt compelled to weigh in on a topic when they didn't know what they were talking about. Get curious before you get outraged. 🤦♂️
Trying to create custom GPTs feels a lot like training a cat. It's capable of doing what you need. You can tell it exactly what to do and it probably understands exactly what you're saying. But most of the time it'll just do it's own thing and not say why.
JS/TS devs (npm users) if you're like me you have a LOT of projects. It can really eat your drive space. To nuke all your node_modules browse to the dir with all your projects and run the following: `find ./ -name 'node_modules' -type d -prune -exec rm -rf {} +`
TLDR; A former team member who still had access to the code was phished.
The attacker published malicious code to the official npmjs repository.
Any site built with the malicious code would expose their users to the exploit.
Sites built with the bad code are still vulnerable.
FINAL TIMELINE AND UPDATE TO CUSTOMERS:
4:49pm CET:
Ledger Connect Kit genuine version 1.1.8 is being propagated now automatically. We recommend waiting 24 hours until using the Ledger Connect Kit again.
The investigation continues, here is the timeline of what we know about the exploit at this moment:
- This morning CET, a former Ledger Employee fell victim to a phishing attack that gained access to their NPMJS account.
- The attacker published a malicious version of the Ledger Connect Kit (affecting versions 1.1.5, 1.1.6, and 1.1.7). The malicious code used a rogue WalletConnect project to reroute funds to a hacker wallet.
- Ledger’s technology and security teams were alerted and a fix was deployed within 40 minutes of Ledger becoming aware. The malicious file was live for around 5 hours, however we believe the window where funds were drained was limited to a period of less than two hours.
- Ledger coordinated with @WalletConnect who quickly disabled the the rogue project.
- The genuine and verified Ledger Connect Kit version 1.1.8 is now propagating and is safe to use.
- For builders who are developing and interacting with the Ledger Connect Kit code: connect-kit development team on the NPM project are now read-only and can’t directly push the NPM package for safety reasons.
- We have internally rotated the secrets to publish on Ledger’s GitHub.
- Developers, please check again that you’re using the latest version, 1.1.8.
- Ledger, along with @Walletconnect and our partners, have reported the bad actor’s wallet address. The address is now visible on @chainalysis. @tether has frozen the bad actor’s USDT.
- We remind you to always Clear Sign with your Ledger. What you see on the Ledger screen is what you actually sign. If you still need to blind sign, use an additional Ledger mint wallet or parse your transaction manually.
- We are actively talking with customers whose funds might have been affected, and working proactively to help those individuals at this time.
- We are filing a complaint and working with law enforcement on the investigation to find the attacker.
- We’re studying the exploit in order to avoid further attacks. We believe the attacker’s address where the funds were drained is here: 0x658729879fca881d9526480b82ae00efc54b5c2d
Thank you to @WalletConnect, @Tether_io, @Chainalysis, @zachxbt, and the whole community that helped us and continue to help us identify and solve this attack.
Security will always prevail with the help of the whole ecosystem.
@SenatorSinema The war crimes Israel has committed, in the open, without dispute must be responded to by removing all aid to the govt. Redirect any humanitarian funds through reputable NGOs.
Continued support of Israel's govt is to be complicit in crimes against humanity.
@VP The war crimes Israel has committed, in the open, without dispute must be responded to by removing all aid packages to the govt. Redirect any humanitarian funds through reputable NGOs.
Continued support of Israel's govt is to be complicit in crimes against humanity.
@POTUS The war crimes Israel has committed, in the open, without dispute must be responded to by removing all aid packages to the govt. Redirect any humanitarian funds through reputable NGOs.
Continued support of Israel's govt is to be complicit in crimes against humanity.
@Levels On step 2 when it is asking about the CGM plan, why would I pay $199/mo when there is a $199 once option? Is $199 for a single CGM and you get one per billing frequency?
@SamCorcos A number of comments in the interview triggered my neurodivergent radar. I've been struggling with tracking things like where my time goes and was wondering; what sort of scaffolding do you use to help yourself stay accountable to adding items to your calendar?