The next era of Web3 infrastructure deserves a brand new type of security review.
For @0xPolygon's Heimdall v2 upgrade, Sherlock is bringing that model to life.
June 15 to July 6.
Sneak peak of the @0xPolygon OMS dashboard. This team is moving faster than I've ever seen to build a best in class global payments platform from the ground up.
🚨 BREAKING: Active supply chain attack across npm, PyPI, and Crates.io.
Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems.
TrapDoor targets #crypto, #DeFi, AI, and security developers, stealing wallets, SSH keys, cloud credentials, GitHub tokens, browser data, env vars, and API keys.
Socket detected releases with a median detection time of 5 minutes, 27 seconds. The fastest detection occurred 58 seconds after publication.
Added some new features to https://t.co/rSBfXf84E6 including this Transaction Report.
Generate a transaction report PDF and download it, it also contains the transaction diagram.
🚨 Supply chain attack on the Laravel Lang organization:
700+ historical versions across multiple community-maintained Laravel Lang packages were compromised with an RCE backdoor, including:
laravel-lang/lang
laravel-lang/http-statuses
laravel-lang/attributes
Laravel-Lang/actions
The payload targets cloud creds, CI/CD secrets, Kubernetes tokens, Vault, browser data, password managers, SSH keys, and more.
Where could we improve Composer 2.5?
We're working on the next model and would love your feedback.
Lots of work to do (our CursorBench evals below) in the coming weeks!
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
Lend, Swap, Deposit, Stake in a single transaction cross-chain with Composable Actions. Build with integrated protocols or add your custom flows.
Composable Actions on Trails, see how:
We shipped Composable Actions in @TrailsHQ 0.15.0. 🚀
Here is a problem they solve. 👇
You spot two good opportunities:
- a Morpho USDT vault on Polygon
- a Aave DAI lending pool on Polygon
You want to invest 1,000 USDT into the Morpho vault and 500 DAI into Aave.
Easy, right?
Except your funds are not there.
You have 2,000 USDC, and it is sitting on Base.
So the actual flow looks more like this:
1. Bridge enough USDC from Base to Polygon.
2. Approve the bridge.
3. Wait for the funds to arrive.
4. Approve USDC for the swap.
5. Swap USDC into 1,000 USDT.
6. Approve USDT for the Morpho vault.
7. Deposit 1,000 USDT into Morpho.
Nice. One deposit done.
But you are only halfway there. 😅
8. Approve USDC again.
9. Swap USDC into 500 DAI.
10. Try to deposit into Aave.
11. Realize you do not have enough native POL for gas.
12. Bridge another token just to get gas.
13. Try again. 😵💫
At some point, the opportunity stops feeling exciting and starts feeling exhausting.
Composable Actions are built for this kind of flow. 🧩
With Trails, you can bundle the whole thing into one intent:
- start with USDC on Base
- bridge to Polygon
- swap into the assets you actually need
- deposit into Morpho
- lend into Aave
- choose how you want to pay fees
- keep self-custody throughout the process, control slippage
One transaction. One signature. Multiple actions.
No manual hopping between chains.
No approval maze.
No stopping halfway because you ran out of gas.
For developers, Composable Actions are typed building blocks for complex DeFi flows.
You can compose actions like swap, lend, deposit, and custom actions into a single user experience across protocols.
For users, it feels simple:
"I have this token over here. I want these positions over there."
Or even:
"I have dollars in my account. I want to put $1,000 into Aave and earn yield."
They should not need to know what chain Aave is on, what token they need, how to bridge, what gas token to hold, or which approvals to sign.
With an embedded wallet, they may not even need to sign anything directly.
The app can turn that simple intent into the right onchain actions behind the scenes.
Trails handles the path in between.
This first version is live now, and it is only a small part of what Composable Actions will make possible.
Use any token, from any supported chain, to bridge, swap, deposit, lend, or compose with multiple protocols in a single flow.
And if the user does not have crypto yet, FIAT can also be plugged in.
Complicated DeFi should not require a complicated user journey.
https://t.co/WRP2UrbhGW
Give your agent a wallet and let it do [ anything ] onchain with the Open Money Stack.
One prompt for smart wallets, embedded onramps, swaps, crosschain bridging, predictions, x402 APIs, onchain identity, & more.
Try it out with the Polygon Agent CLI: https://t.co/Rnzoi7daLU
More institutional-grade privacy options are live with Polygon CDK.
Launch a custom private chain connected to global onchain liquidity, with a new validium configuration powered by @SuccinctLabs.
Private where it matters. Actually connected where it counts.
Another upgrade for the chain. Now up to 140M gas, bringing max TPS to 3,800+
We've increased capacity again to enable even more onchain payments at scale.
Every payment on Polygon just got faster.
We just shipped another upgrade to the chain. Block time has decreased to 1.75s, making it the first reduction since genesis.
14% more payments per second, every second. Accelerate.
More payments. Every second.
Polygon is now pushing 3200+ TPS, with 1.75-second blocks and sub 5-second finality. This follows a 250ms reduction on block time.
14% more payments per second on the chain built for money movement
We're building Trails to bring one-click simplicity into onchain payments.
We just shipped v1.5 to bring composable actions into Trails. Details in the thread.
Introducing Composable Actions - execute N actions cross-chain with virtually any protocol in a single signature. Comes bundled with several DeFi protocols already added with the library or build your own custom flows. @GabiDev98 cooked on the devex.