🚨SOLANA CO-FOUNDER WARNS ON ETHEREUM L2 SECURITY
Solana Labs co-founder Anatoly Yakovenko says Ethereum Layer 2 networks are not quantum-safe and added, “abandon all hope.”
Product update: Account verification on Immunefi
We've expanded how security researchers can verify their accounts on Immunefi, so the system works for everyone, not just those with NFC-enabled passports/IDs.
Why this matters:
Spam accounts and fake reports have become a real problem across the industry. They waste protocol resources, slow down triage, and ultimately hurt the legitimate security researchers doing serious work.
To address this, we introduced a proof of humanity system with ZKPassport, a Sybil-resistant approach that keeps identity self-sovereign and privacy-preserving, without storing sensitive documents.
But ZKPassport doesn't work for everyone. Not all researchers have passports or ID cards with NFC chips, and the app itself has had bugs. Some researchers were locked out as a result. That was our mistake, and we've been working to fix it.
Three ways you can now verify:
Security researchers now have three options:
1. ZKPassport: works for researchers with an NFC-enabled passport or ID card.
2. Human Passport (new, primary method): verification based on a Unique Humanity Score built from your web3 activity, social accounts, and identity-tied credentials. Hit the threshold, and you're verified.
3. Pay to verify (experimental): currently rolled out to ~10% of users. If the first two methods don't work, researchers can pay a fee to prove they're human.
The goal is simple: every security researcher should have a fair shot at hunting bounties on Immunefi. If you were locked out before, give it another try, and let us know if you hit any issues.
To learn more about Human Passport, check out the Help Center article:
https://t.co/v9cl6qK2Mh
April 2026 is truly brutal
25 hacks in 29 days with $629M+ stolen
Just now: SweatEconomy drained $3.46M (65% of supply) in only 30 seconds
One exploit every 27 hours
The month isn’t even over yet
Three audits. No bug bounty. AI-powered security scanner.
vs.
One audit. $500K active bounty. No AI tools.
The second protocol is safer. Not even close.
AI scanners find what they were trained on. Bug bounties incentivize people to find what nobody has thought of yet.
You cannot train a model on the vulnerability that hasn't been discovered yet. You can pay a researcher to find it.
⚡️QUANTUM COMPUTER BREAKS ECC KEY IN BITCOIN-RELATED TEST
A researcher used public quantum hardware to break a 15-bit elliptic curve key, winning Project Eleven’s 1 BTC Q-Day Prize.
The test does not threaten Bitcoin’s 256-bit security yet, but highlights growing urgency around post-quantum upgrades, with ~6.9M BTC sitting in addresses with exposed public keys.
Alphabet to Invest Up to $40B in Anthropic, Supplying 5GW Computing Power
Alphabet has announced plans to invest as much as $40 billion in the generative AI company Anthropic.
The deal includes providing Anthropic with 5GW of computing power to support its research and development.
The move is expected to intensify competition in the AI sector, particularly with rivals such as OpenAI.
The Arbitrum Security Council has taken emergency action to freeze the 30,766 ETH being held in the address on Arbitrum One that is connected to the KelpDAO exploit. The Security Council acted with input from law enforcement as to the exploiter’s identity, and, at all times, weighed its commitment to the security and integrity of the Arbitrum community without impacting any Arbitrum users or applications.
After significant technical diligence and deliberation, the Security Council identified and executed a technical approach to move funds to safety without affecting any other chain state or Arbitrum users.
As of April 20 11:26pm ET the funds have been successfully transferred to an intermediary frozen wallet. They are no longer accessible to the address that originally held the funds, and can only be moved by further action by Arbitrum governance, which will be coordinated with relevant parties.
@arbitrum With this, I will never use Arbitrum again. It was a good ride. Thank you.
I am happy for the users affected, but L2s are a dead end long term.
Back to basics. BTC and ETH L1 only going forward.
https://t.co/03LoFSQ8kM
@arbitrum This exposes Arbitrum as a multisign wallet that can unilaterally freeze and steal funds though.
Which tbh may be a good option, lets accept bitcoin is the only real descentralized chain, the rest are centralized but without KYC.
Why is KelpDAO blaming LayerZero?
"KelpDAO's leaked memo says it relied on LayerZero's documentation, default configurations, and team guidance when setting up the bridge."
"LayerZero is saying KelpDAO should have used a more secure configuration."
Andy's take: "That is not what you want to see as a user."
🚨 $292M stolen from KelpDAO in 46 minutes.
No smart contract bug. No private key leak. Every on-chain check passed cleanly.
The attacker broke the verification layer not the code.
Here's exactly how it happened 🧵
CT in the last 24 hours
1) @KelpDAO got exploited for $292M via a LayerZero bridge attack
Attacker used the stolen rsETH as collateral on Aave to borrow ETH
Caused $AAVE dropped 10%. Aave froze rsETH markets
2) @PumpFun Instagram got hacked
Hacker is demanding Alon pay out the $PUMP airdrop
Threatening to doxx him via a token launch on PumpFun
3) @GrantCardone real estate billionaire wants to launch a memecoin
To prove you can make money without a Stanford degree
Will hold 20% for developers, and presale
4) $ASTEROID up 70,000% in 24 hours
Elon replied to a post about a 15-year-old who died of cancer and designed the SpaceX zero-g mascot
TL;DR - One trader turned 1 ETH into $474K in 3 hours
$600M stolen from DeFi in 2 weeks
One man pumping a grief token to half a million
Another man threatening to doxx someone on their own platform
Only in crypto