@DeepSafe_AI#DeepSafe
The correct choice is B: whoever produces that block can influence the hash by controlling its contents or withholding it if the outcome is unfavorable
The correct choice is B: whoever produces that block can influence the hash by controlling its contents or withholding it if the outcome is unfavorable
Weekend puzzle.
A contract runs a lottery. To pick the winner, it uses the hash of a block produced after ticket sales close.
Who can influence the result?
A. Nobody. It's a hash.
B. Whoever produces that block.
C. Only the contract's deployer.
@DeepSafe_AI The correct choice is B: whoever produces that block can influence the hash by controlling its contents or withholding it if the outcome is unfavorable
Weekend puzzle.
A contract runs a lottery. To pick the winner, it uses the hash of a block produced after ticket sales close.
Who can influence the result?
A. Nobody. It's a hash.
B. Whoever produces that block.
C. Only the contract's deployer.
@UTechStables@binance On July 30, Coinkite disclosed that Coldcard devices — going back to March 2021 firmware — had been silently bypassing their dedicated hardware randomness chip during key generation, falling back to a predictable
$U Flexible Earn is renewed with even bigger rewards on @binance !
Extended for 30 full days with massive limits:
Regular Users:
• 8% Bonus APR on 0 – 5,000 $U
VIP 1–9 Users:
• 5% Bonus APR on 0 – 500,000 $U
📅 Duration: Aug 16, 00:00 – Sep 14, 23:59 (UTC)
Subscribe on Simple Earn now! 👇
https://t.co/3TLSGMl5PC
@DeepSafe_AI On July 30, Coinkite disclosed that Coldcard devices — going back to March 2021 firmware — had been silently bypassing their dedicated hardware randomness chip during key generation, falling back to a predictable
Victims of the Coldcard wallet exploit are organizing a commercial litigation action against Coinkite. Over $116M gone, thousands of wallets drained — accountability efforts are only getting started. But the actual failure happened years earlier, and it's worth understanding why.
On July 30, Coinkite disclosed that Coldcard devices — going back to March 2021 firmware — had been silently bypassing their dedicated hardware randomness chip during key generation, falling back to a predictable software substitute instead. Some seeds ended up with as little as 40-72 bits of real randomness instead of 128. Weak enough to brute-force offline, with no need to ever touch the physical device.
The bitter irony: the disclosure meant to protect users became the attackers' target list. Within days, wallets were drained faster than owners could migrate funds.
Coldcard's entire pitch was that your keys never exist anywhere reachable. That held — right up until the one component no one was independently checking, the device's own randomness, had quietly been swapped out for years.
A single implementation generating a whole key is always one silent substitution away from this. CRVA is built on the opposite premise: no device, no operator, no single random source ever holds or produces a complete key. Ring-VRF and MPC mean there's no "one component" left to quietly fail.
Source: https://t.co/gYHU8jXizL
#DeepSafe #CRVA #Web3Security
@DeepSafe_AI On July 30, Coinkite disclosed that Coldcard devices — going back to March 2021 firmware — had been silently bypassing their dedicated hardware randomness chip during key generation, falling back to a predictable
Nearly 200,000 XRP drained from the Coreum-XRPL bridge in 97 minutes. Not by breaking a key. Not by breaking a signature. By exploiting what the verifiers were actually checking.
The bridge required 17 of 28 relayers to sign off on each withdrawal — a real threshold, not a single point of failure. But the relayers only checked whether a payment succeeded and whether its memo named a recipient. Nobody checked whether the payment's destination was the bridge's own address.
So the attacker moved XRP between two wallets they controlled, attached a memo formatted like a deposit, and 17 honest relayers signed off on a transaction that had nothing to do with the bridge.
Here's what makes this worse than "one bug slipped through": those 28 relayers weren't 28 independent checks — they were 28 copies of the same software, running the same logic, checking the same wrong field. You don't get 28 verifications that way. You get one verification, repeated 28 times. Decentralizing who signs doesn't help when everyone shares the same blind spot.
Real independence isn't a headcount of signers. It's verification that doesn't inherit the bridge's own assumptions — that checks a claim against the source ledger itself, not a memo the ledger never validated. This is the gap CRVA is built around: agents are drawn at random each epoch specifically so no single piece of operator-controlled logic becomes the thing every verifier quietly defers to.
Twenty-eight relayers agreeing on the wrong question is still the wrong answer.
#DeepSafe #CRVA #Web3Security
🏆 Bifu【2026 World Cup Social Carnival】is LIVE! Share a $800 Cash Pool!
The FIFA World Cup 2026 passion is ignited! Bifu has teamed up with @taskonxyz to launch a massive $800 giveaway. NO sign-up needed, NO UID required! Just follow, retweet, and win!
🎁 Total Prize Pool: 800 $USDT
🥇 Social Referral Board (400 USDT): Share your exclusive referral link and invite friends to complete tasks. Top leaderboard winners take home up to 100 USDT!
1st: 100U | 2nd: 50U | 3rd: 30U | 4th-10th: 20U each | 11th-15th: 16U each
🎁 Grand Lucky Draw (400 USDT): Complete tasks in seconds! 40 lucky winners will be randomly drawn to get 10 USDT each!
📝 How to Join:
1️⃣ Click the TaskOn link: https://t.co/tPcIt5SBr1
2️⃣ Follow @BifuGlobal
3️⃣ Like & Retweet this post!
⏳ Event Period: June 15 - July 5, 2026
#WorldCup2026 #BifuExchange #TaskOn
🔍 POTS #Airdrop (New Round)
✔️ Guaranteed distribution by Airdrop Detective
🏆 Airdrop Pool: 1,000 USDT
🔴 Start the airdrop bot: https://t.co/0c3v8vGUka
🔘 Do the tasks on the bot & submit your data.
🔘 Details: https://t.co/RjcNiFANef
#Airdrops #BTC #POTS #USDT #AirdropDet