This is what I tell all new builders.
Build a presence - contribute to open learning.
Be a ferocious learner. Then, show off and teach what you’ve learned and built.
Another week, another major wallet draining exploit. 🚨If you’re a user of @AtomicWallet move your assets before the attacker moves them for you🚨
Both users and devs are imperfect so we need to move beyond Seed Phrase wallets as a single point of failure. Multisig everything!
Storing keys from your hardware wallet on servers (albeit encrypted) is a bad idea.
However, I’m shocked how many people thought that seeds never left HW wallets. Your seed phrase is always available to the firmware for display.
Let’s stop treating HW wallets as bulletproof 💀
I understand that I'm 1 of like 5 people on this hellish bird app that has written Ledger device code
I am still surprised at how many people thought it produced signatures via ✨ magic ✨ secure enclave technology
We need your help in order to really nail it down! If you’re a victim of an unexpected crypto theft within the last year, please fill out the secure form at:
https://t.co/6AsjIpv4e0
It’s anon friendly and all fields are optional.
🚨🚨 OFFICIAL PUBLIC RELEASE 🚨🚨
Victims urged to come forward!!
We've just published a new writeup @viamirror -
"Uncovering a Sophisticated Multi-vector Crypto-Asset Theft Scheme"
Which serves to detail the elaborate posts already made by @tayvano_
We've had a number of contacts reach out wanting to know if they are at risk from the wallet draining activity reported by @tayvano_ - below is our perspective, stepping through the risk factors.
https://t.co/LSf8ZLHKg3
⚠️PSA⚠️ courtesy of @tayvano_
🙏PLEASE DON'T KEEP ALL YOUR ASSETS IN A SINGLE KEY OR SECRET PHRASE FOR YEARS 🔑
Use @safe multisig and rotate to fresh keys regularly.
‼️We can’t stress this enough - If you have all your crypto under a single Seed Phrase / Private Key, please be safe - migrate now 🙏
We recommend a @safe multisig with at least two separate keys that you control. Then rotate each key at least once a year 🔑
Hear the journey that led @paulsalis to create @everlasting_io in the latest episode from @BlockchainNZ 🎧 From starting out in crypto & smart contract auditing, through to securing wealth beyond lifetimes 🔑
https://t.co/MVbddzGabx
Good analysis of the trust assumptions you are making when you delegate to services like Lido to stake ETH.
It’s why I’m bullish on Distributed Validator Technologies like @ObolNetwork as it can shift control away from validator services when used in a setup with your own nodes.
Circle's Cross-Chain Transfer Protocol (CCTP) is getting closer to launch. Such an important piece of infrastructure that can help foster more scalable, efficient, secure and user friendly apps built on USDC. https://t.co/zP7fgZrL10
We’re joining @safe in supporting the #TakeBackOwnership movement.
Make 2023 the year that you secure your crypto wealth to be passed on to loved ones!
Your keys, your coins, your legacy
🫵🔑,🫵🪙,🫵👑
226 Smart contracts on Cookbook! 🤯
If you are interested in smart contract development you need to checkout @cookbook_dev 👩🍳 It's a free repo of solidity smart contracts where you directly view all the details + simply deploy as well!
https://t.co/btWlmXQkrf
Not everyone on CT is interested in esoteric knowledge about MEV. However, if you are building *anything* on Ethereum in the next few years, you should read this. Explicit and Negative MEV are likely to become the norm, so make sure to allow for it when designing contracts & UX
I can see this becoming more common for responsible disclosures in both web3 and web2 👀⏳🔒
Project teams won’t be able to delay fixes or negotiate down bug bounty payments if the clock is ticking on the public being able to decrypt the vuln disclosure details.
Happy 2023 everybody 🎉 This is a reminder that the Solidity Developer Survey 2022 is only open for 5 more days and will close on Jan 7! If you are a Solidity developer and did not respond to it yet, please take a moment and do so.
📊: https://t.co/dR4wKUAm4S #xp