Time for a personal update: I have started a new company, @firstset_, with the goal of contributing to the onchain economy, as builders and node operators.
It’s only been a couple of months, and we’ve already made progress on several fronts. More on that below… 👇
@guywuolletjr More generally, vaults are the correct abstraction to allow unsophisticated capital to participate in sophisticated protocols in a non-custodial way
Meta reported a decline in daily active users across its family of apps for the first time ever.
They called out internet disruptions in Iran and WhatsApp restrictions in Russia as the reason for the slight decline
I've been trying to do this with every single new Claude model release and Opus 4.7 is the first one that's managed to do it on Canvas.
It might be doable with GPT-5.5, but Three.js doesn't load within ChatGPT and I've just been lazy to try it on Codex
The OFTScan website is deployed as a smart contract on Ethereum mainnet via ERC-4804 and ERC-5219
0 dependencies, 0 downtime, just onchain HTML
@DefiLlama API used for asset pricing but not required
Use OFTScan: 0x000000f7f90708c034c854efd1d5bfe8e9079e32.1.w3link dot io
@CarlKVogel Better Opsec is part of it, but we need protocol designers to be less naive and more paranoid about what can go wrong https://t.co/m8rEXsRPqN
DeFi exploits are no longer about code vulnerabilities.
The $600M lost in the last 30 days all occurred due to a combination of:
- reckless governance setups
- naive protocol design
- improper OpSec standards and procedures
Protocols need to start thinking harder about stuff like wider councils with higher thresholds, timelocks, rate limits, throttling, and dedicated signers.
Your 6-fig audit won't save your ass if you are naive about how you can get rekt.
Anything else I am missing?
DeFi exploits are no longer about code vulnerabilities.
The $600M lost in the last 30 days all occurred due to a combination of:
- reckless governance setups
- naive protocol design
- improper OpSec standards and procedures
Protocols need to start thinking harder about stuff like wider councils with higher thresholds, timelocks, rate limits, throttling, and dedicated signers.
Your 6-fig audit won't save your ass if you are naive about how you can get rekt.
Anything else I am missing?
DeFi exploits are no longer about code vulnerabilities.
The $600M lost in the last 30 days all occurred due to a combination of:
- reckless governance setups
- naive protocol design
- improper OpSec standards and procedures
Protocols need to start thinking harder about stuff like wider councils with higher thresholds, timelocks, rate limits, throttling, and dedicated signers.
Your 6-fig audit won't save your ass if you are naive about how you can get rekt.
Anything else I am missing?
@banteg@definikola LZ got compromised and they are sweeping it under the rug.
The fact they haven’t explained how the RPC list was obtained and which RPCs got compromised is pretty damning.
> Rather, the attacker was able to gain access to the list of RPCs our DVN uses, compromise two of them – which were independent nodes running on separate clusters without direct connection to each other – and swap out binaries running the op-geth nodes.
Concerning that the post doesn't address:
1. How was access to the RPC list obtained?
2. Which entities were responsible for operating the poisoned RPC nodes?
> Rather, the attacker was able to gain access to the list of RPCs our DVN uses, compromise two of them – which were independent nodes running on separate clusters without direct connection to each other – and swap out binaries running the op-geth nodes.
Concerning that the post doesn't address:
1. How was access to the RPC list obtained?
2. Which entities were responsible for operating the poisoned RPC nodes?
Introducing the USDC Bridge.
A direct way to move USDC crosschain.
Built and operated by Circle, USDC Bridge gives you a predictable, transparent way to move USDC between chains:
→ Native burn-and-mint transfers
→ Clear fees upfront, with live status and progress
→ No route selection. No bridge complexity.
→ Destination gas handled automatically
Move USDC. That’s it.
https://t.co/PpWmUG18o8