Dinamic.eth It's a playful blend of on-chain NFTs, ENS tech, and AI agents โ letting holders create "live" goblin agents that run with goblin energy. Agent airdrops, personality drops, and tying into broader Ethereum AI agent trends. Check https://t.co/q3QKXQjyZe for mints and the dinamic.eth site for agents. Goblin mode activated ๐บ
Dinamic.eth AI onchain agentic solutions revolve around goblin/gremlin-themed AI agents tied to the Pixel Goblins and Goblinarinos NFT collections. Owners of Pixel Goblins (10,000 unique on-chain pixel art NFTs stored 100% on Ethereum via ETHscriptions) or related collections like @goblinarinos scan mint their own customizable AI agents at https://t.co/eVjdtHuymQ
Key elements:
On-chain foundation: Pixel Goblins use ETHscriptions for fully on-chain pixel art (stored in Ethereum transaction calldata). This provides verifiable, decentralized ownership and https://t.co/nzphqOBQ1q
Agent infrastructure: Powered by the dinamic.eth ENS Dynamic Kit โ gasless off-chain ENS updates, CCIP Read for live/dynamic records, and tools for AI agent identities/personalities.
Agents get defined skills, traits, and behaviors (e.g., "Nerdy Gob" with data analysis, alpha hunting, on-chain forensics).
Agentic features: Autonomous, programmable goblin agents for fun, memes, on-chain interactions, or practical use (e.g., personality prompts, live agents airdrops, integration with ENS for identity). Focus on "Goblin Mode" chaos, autonomy ("Autonomous Goblin Identity"), and community-driven creation.
Sleepless days but excited!
Many productive discussions! A lot of progress in the Ethereum Ai / Security / Connectivity Revolution happening on @ethereum accessibility to users.
Dinamic.eth already has a literal stamp on whats coming next!
"By leveraging on-chain registries and verifiable attestations, the system ensures that every action a model takes is permanently linked to its source and inputs.
Data travels through a specialized mesh network that preserves attribution, preventing impersonation and ensuring history remains publicly accessible.
This structural approach replaces traditional trust with mathematical proof, requiring every agent result to be stamped and validated before propagation.
Ultimately, the platform champions a Know Your Agent philosophy by making accountability a mandatory requirement for execution rather than an optional feature."
we've been running this stack in production, ccip-router + WYRIWE + ERC-8263.
Every agent call gets a cryptographic receipt on-chain: input hash, model hash, output hash, EIP-712 signed and replicated across a heterogeneous mesh. any peer can verify a past call without trusting the node that produced it. identity (NodeRegistry), capabilities (WyriweProofVerifier), and observation commitments (AttestationIndex) are all anchored on Ethereum mainnet.
The agent card we've been running this stack in production, ccip-router + WYRIWE + ERC-8263. every agent call gets a cryptographic receipt on-chain: input hash, model hash, output hash, EIP-712 signed and replicated across a heterogeneous mesh. any peer can verify a past call without trusting the node that produced it. identity (NodeRegistry), capabilities (WyriweProofVerifier), and observation commitments (AttestationIndex) are all anchored on Ethereum mainnet.
The agent card is good for discovery but it's self-declared. ours is verifiable at every layer.
Curious what ERC-8257 adds on top of that, does it cover capability verification or just registration?
๐ด ONGOING โ This operation is still active.
If you interacted with any flagged address, rotated your key, and assumed you were safe โ you may not be. The EIP-7702 delegation survives key rotation. The attacker can still execute transactions silently from your wallet without holding your new key. Most wallet UIs will not show this. You would not know.
Check your wallet now:
cast code <your-address> --rpc-url <your-rpc>
Non-empty = you are still compromised.
cc @zachxbt@tayvano_@PeckShieldAlert @CoolifyHQ @etherscan
โ ๏ธ Professional drainer operation active since May 2025 โ ๏ธ
0x0c8b9d0a7e5bd2e66270ad02ff1e4efa6badface
Tracing the flows:
โข 233,017 downstream addresses
โข 637,000+ transactions
โข ~170 ETH (~$336,000) + ~$56K USDC // ~$392,000 confirmed out from the central contract alone
โข 155 ETH (~$306,000) moved in August 2025 alone
โข 33 chains ยท 68 confirmed victims
(key-compromise victims invisible to tracing, likely far more)
How they get in: Coolify API key exposure. /api/v1/applications/{uuid}/envs returns every env var including private keys, one leaked token and they have everything. They donโt attack contracts.
They attack developer infrastructure.
The persistence trick: After draining, they set an EIP-7702 authority delegation to a contract they control.
Rotating your key does NOT remove their access. Check with cast code <your-address> --rpc-url <rpc> โ non-empty output means youโre still delegated. Revoke with a type-4 tx to address = 0x0.
If youโve been hit:
Revoke the EIP-7702 delegation first
Rotate your Vercel/Coolify API tokens
Move to a fresh wallet on an air-gapped machine
Block these:
0x0c8b9d0a7e5bd2e66270ad02ff1e4efa6badface
โ drainer
0xf70da97812cb96acdf810712aa562db8dfa3dbef
โ laundering hub (12K downstream)
0x43b1...aaaa cluster
โ treasury wallets
0xbf6f...23fa cluster
โ layering
Full forensic report + victim list on request. 231K nodes still unexplored, the real network is larger.
cc @zachxbt@tayvano_@PeckShieldAlert @CoolifyHQ @etherscan
Recommendations
For anyone who may have been targeted:
1- Check for EIP-7702 delegations on your wallet, cast call <your-address> "code()(bytes)". Non-empty means delegation is active.
2- Do NOT simply rotate keys, EIP-7702 delegation persists independently of the private key.
You must also revoke the delegation via a type-4 transaction with address = 0x0.
3- If using self-hosted Coolify, rotate all API tokens immediately and audit /api/v1/applications/{uuid}/envs access logs.
4- Report the attacker address to Etherscan, MistTrack, and your chainโs security contacts.
For the broader community:
Block 0x0c8b9d0a7e5bd2e66270ad02ff1e4efa6badface and the 0x43b1...aaaa / 0xbf6...23fa address clusters in on-chain monitoring tools
The Coolify API exposure vector may be affecting many self-hosted deployments, this is worth a coordinated disclosure to the Coolify team
+ detailed reports on request * Trace log *in/outflows *attack flow * hub analysis
The Composition Note on how ERC-8004 + ERC-8263 + OCP compose into a full AI agent verification stack (identity โ action โ output) is now public.
It's a reference guide for implementers, not a fourth spec.
https://t.co/V4oG20kZcl
Its still there for the taking, the things i could only dream at some point are now possible and accessible at many levels ...but society is still discussing arquitetural philosophies over practical work. Many of the progress is delayed not because we cant do it but because there is a conflict of interest between parts!
In my early days of sound engineering (around 2008/2009) I had this ideaโฆ VST's were finally starting to sound good, but to co-create music digitally on local systems we had to use hacky tools like IPMIDI connectors just to sync DAWs. We still had to fix latency manually.
That was the hackerโs way back then stacking more tools in sync. At the time, one of my dreams was to build zero-latency VST's + hardware over IP, so any musician could access high-grade components for their tracks, no matter where they were. Fast-forward 20 yearsโฆ this idea is now reachable at the infrastructure level.
Ultra-low latency audio over IP is real: Dante, Ravenna, AES67, JackTrip, Sonorous, WebRTC + OPUS we can get sub-20ms round-trips on good networks. 5G, Starlink, edge computingโฆ the old geographic barriers are falling.
The dream of renting high-grade hardware remotely is technically possible today, but itโs still fragmented and centralized. Thatโs why Iโm so excited about what weโre building now with dinamic.eth and the team. Weโre creating the On-Chain AI Execution Stack, targeting trustless AI agent economies.
Imagine a trustless real-time music execution layer: Musicians discover & rent high-end VS instances, AI session players, mastering agents, or even physical hardware nodes via smart contracts Payments and usage rights settle atomically on-chain.
Low-latency audio routed through decentralized edge nodes
AI agents that act as live arrangers or automatic latency compensators, learning the feel of each collaboration.
Iโm no longer working in the music industry, but this old frustration still feels like powerful fuel. The missing pieces were exactly the verifiable computing, permissionless coordination, and economic primitives weโre building. What felt impossible in 2009 is becoming infrastructure in 2026.
EF should stay narrow and neutral. The ecosystem builds the execution layers institutions actually need.
Thatโs why weโre shipping the 4-layer On-Chain AI Execution Stack
(ERC-8004 Identity + WYRIWE Input Trust + OCP + Infrastructure Attestation) + ERC-8183 BountyBoard for agentic commerce.
Neutral base + composable higher layers = the real institutional path.