Today we’re releasing Unlukey🎲 a free, public tool to identify wallet addresses generated from weak seed phrases.
The goal is simple: help users detect vulnerable wallets before attackers do. 🧵
Coinspect’s latest Wallet Security Ranking has a new Top 5 👇
🥇 @MetaMask
🥈 @OneKeyHQ
🥉 @ambire
4️⃣ @phantom
5️⃣ @Coinbase
MetaMask leads with 85.5, while OneKey and Ambire complete a new podium.
Explore the leaderboard: https://t.co/do5RjzwWRF
Huge congrats to @ambire for breaking into the Top 3 of our latest Wallet Security Ranking! 🏆
You’re doing a phenomenal job. The progress is clear, the improvements really show, and this result is well deserved.
Congrats to the whole team! 👏
Today we’re releasing Unlukey🎲 a free, public tool to identify wallet addresses generated from weak seed phrases.
The goal is simple: help users detect vulnerable wallets before attackers do. 🧵
Today we are publishing the first Ill Bloom findings: affected-address checker + on-chain analysis to help users identify exposed addresses and protect their assets.
🔗 https://t.co/NLod0LR3cd
⚠️ We will never ask for seed phrases, private keys, signatures, or approvals, or ask users to send funds to "recover" or protect a wallet.
Hey @exodus 👋 @coinspect testing team here, doing an address-poisoning security review for our ranking. Is recipient-address detection on your roadmap? Also saw some balance-loading issues while testing, known problem right now?
Multiple software wallets are adding address poisoning protection, so we just merged a change to our Wallet Security Ranking checklist: https://t.co/EiFG1G75qI
Stay tuned for the next testing round 🗣️
I present TAINT.
A bug bounty pays for a report that someone must review. TAINT pays for a demonstration.
Software is built from thousands of components written by strangers.
TAINT asks: Can someone get arbitrary bytes into the artifact I trust?
Since October 2024, we’ve followed responsible disclosure giving wallet teams time to review findings and improve security.
🔥 In 2026, Wallet Security Ranking enters its next phase: fully open.
New on Learn EVM Attacks: 4 new real DeFi exploits reproduced with write-ups, runnable Solidity PoCs, and more:
• Futureswap fee bug
• 1inch calldata corruption
• Bunni rounding drift
• LyraDepositWrapper validation flaw
Explore, run the code, learn to defend. 🔎👇
I just published Zeroshot-14B, a small model finetuned with 10,000+ public CVE findings, to increase its ability to find bugs in C/C++/JavaScript code.
Why? Because big models are too expensive and slow. This one is fast, and free. Link in thread...⬇️
Grok says that this post by @liorcito uncovers fresh details on the Balancer V2 exploit—like the attacker's binary search via reverts & decompiled math helper code—not yet buzzing on X. Deep dive into rounding biases & on-chain forensics:
https://t.co/N140Sw1bPz
Right @grok ?
Ladies and gentlemen, the decentralized web👇
This is not:
* just a privacy issue
* about "hacking Google"
It is about phishing and insecure dynamic third-party code as the initial vector for wallet drainers.
Open🧵for more examples
Evolving NPM Supply Chain Attacks
Protect your development and CI/CD environments:
❌ npm i → may pull infected dependencies
✅ npm ci → installs from lockfile, reproducible & safe
🚀 Missed our launch? The Learn EVM Attacks Explorer is live!
Experiment with real #DeFi exploits across #Ethereum, Polygon, BNB Chain & more
🪄with one-click (2?) reproducibility, search, and shareable case studies.
Explore, learn, and help build safer protocols👇
1/🧟♂️⚠️ What are Zombie dApps?
When Web3 projects shut down, their domains often expire then attackers re-register them to build “zombie” sites that drain wallets by posing as legitimate shutdown pages.