Billions Network TGE is approaching.
In light of community feedback, the Billions team is offering community round contributors three options ahead of TGE:
- A: 100% refund
- B: Full allocation + 25% bonus, 6-month lock
- C: Full allocation + 50% bonus, 12-month lock
Selection window: Apr 27, 12pm UTC → May 18, 12pm UTC
Options B and C are for contributors who want to stay aligned with Billions over the longer term.
Refunds will be processed after the selection window closes and handled in the order in which they are received, subject to the stated processing period.
Selections will be final once submitted.
Only original contributing wallets will be eligible to make a selection. Contributors who do not select an option before the deadline will default to a full refund.
Submit here: https://t.co/Axra3I9EyR
@benfielding@aksff124 At some point we need just stop it and let the team do what they see fit anyways markets are crap 🥲 just hope the product they built works
I guess most of the CT users often use fonrtun pro extension or xhunt extension (specially in the chinese community this is very popular), people see open source on github and just trust it.
so today, I checked both xhunt and frontrun to see what is really going on under the hood and tbh some of this stuff is wild.
xhunt is open source, it is true but being open source doesn't always mean safe. their README says "local-only data storage, no sensitive information uploads" which is a straight up lie.
i checked the actual code and every single API call sends your real IP address, physical city, ISP and even persistent device fingerprint using FingerprintJS and the full url of every single page you visit on twitter, all going to their server at kb(.)xhunt(.)ai. they hit 4 different IP geolocation services [ipapi(.)co, ip-api(.)com, ipinfo(.)io, ipify(.)org] just to figure out where you are.
even worse, they deliberately use RC4 encryption and String.fromCharCode arrays to hide header names like "authorization" and "x-user-id" and "x-window-location-href" from anyone reviewing the code. tbh legit developers don't do that.
they also have a completely unrestricted HTTP proxy in the background script (EXECUTE_REQUEST handler) with zero URL validation, means any code can tell your browser to fetch literally anything, your local network, cloud metadata, whatever. and there is an empty wallet injection function already wired up with world:MAIN access just sitting there waiting to be activated. their remote config runs on Alibaba Nacos so they can push changes server-side in minutes without any chrome store review.
frontrun is a lil bit different. it hooks into 12 𝕏 GraphQL endpoints : your feed, followers, following, searches, community posts, all of it and monkey-patches fetch, XHR, and WebSocket on 8+ crypto platforms.
the intercepted API data from 𝕏 and crypto platforms stays in your browser for the overlay, but every time you open a crypto site, frontrun pings Amplitude with the platform name, when you log in it sends your email and name to Amplitude and on errors it uploads logs with your device ID and user agent to their own server at loadbalance(.)frontrun(.)pro
but the key difference is that intercepted data mostly stays local in your browser for the overlay UI. it's not being sent to their servers the way xhunt does it.
it worth noting that frontrun also uses GrowthBook for remote feature flags so they can change extension behavior server-side without a chrome store update too. but overall, frontrun is much less shady than xHunt in practice.
neither extension is stealing your keys or draining wallets today. but the infrastructure is there in the case of xhunt. remote config systems that can push silent changes, aggressive permissions, and in xhunt's case deliberate code obfuscation to hide what they are doing. just be aware of what you are installing.
🚨‼️ BREAKING: Crunchyroll breached through outsourcing partner in India.
A threat actor exfiltrated data from Crunchyroll's ticketing system and also managed to pull 100 GB of personally identifiable customer analytics data.
We've analyzed sample data and it includes IP addresses, email addresses, credit card details, and more.
An employee of their outsourcing partner Telus had executed malware on his system, which gave a threat actor access to Crunchyroll's environment.