FAMILY, CHECK YOUR PORTFOLIOS 👀
Your welcome bonus is waiting. Check your balance and see when it unlocks.
A little something from us to get you started.
https://t.co/wCWZV0Ia9x
@blok_cap is like a pro money manager for your crypto, but you're still in control of your funds.
You just need to follow on-chain strategies or managers whose track record lives on-chain and watch your portfolio (your Garden) grow while everything stays in your wallet.
#BLOKC
In 7+ minutes, I will show you how to:
→ Create a Safe (@safe) wallet
→ Fund it
→ Make a transaction with it, and
→ Verify that transaction is correct before you sign it using @cyfrin's abi decoder tool.
That last part applies to any transaction you sign with any wallet.
Meet Savora.
An onchain community savings platform built on @Stacks
A familiar way to save, rebuilt with blockchain for greater transparency, automation and trust.
Save together. Grow together.
#Ajoonchain
I know you must have heard of @MySpenda, the fastest crypto to cash app there is with good rates.
Now @Savora_HQ is coming, a platform where you can save with friends and family, onchain.
So you use Spenda to get the money and spend, you use Savora to save for future.
Win win.
What if losing your private key didn't mean losing your wallet?
For years, that has simply been accepted as part of using crypto.
Social recovery wallets challenge that assumption.
Here is how they work. 🧵
Wallet compromises are now the single biggest source of financial losses in Web3.
For years, smart contract bugs dominated the conversation.
That is no longer where the biggest losses are coming from.
The attack surface shifted. 🧵
I will tell you for free, the findings that get invalidated are rarely wrong.
They are just incomplete.
Before you submit anything:
→ Identify who can trigger it
→ Map the exact call sequence
→ State the realistic worst case
→ Write the PoC that proves it
@CyfrinUpdraft's security course teaches you how to build that last one properly.
A vulnerability without proof is a hypothesis. No one accepts hypotheses.
When a protocol gets exploited, the root cause is often the same:
Some property of the system that should have remained true no longer does.
That property is called an invariant.
Understanding it changes how you think about security. 🧵
Bybit lost $1.5 billion in February 2025.
WazirX lost $235 million in July 2024.
Neither started with a bug in the smart contract.
Both started with someone signing something they could not read. 🧵
The first thing that breaks when an EVM developer touches Solana:
The assumption that a program owns its own state.
It does not. State lives in accounts. The program is stateless.
That shift changes how you read code, think about access control, and reason about vulnerabilities.
I’ve been untangling that mental model gap through the Solana course on @CyfrinUpdraft
I own a GARDEN where I plant CROPS to get fresh veggies.
My garden stopped thriving.
Back to back classes.
Coming home exhausted.
I had no time to tend to my plants.
So I hired a GARDENER.
Signatures control assets in Web3.
→ Permit functions.
→ Meta-transactions.
→ Multi-sigs.
→ Off-chain approvals.
Most developers use them. Few understand where they break.
This thread will fix that. 🧵
Last Saturday, Lazarus (DPRK) hit KelpDAO for $292M.
Two weeks before that, Drift for $285M.
That is $577M in 18 days. Two attacks. Same group.
This is a state-funded operation with no signs of stopping.
How long will this continue?
Last week of class at @shefiorg, and @maggielove_ is taking us on a special AI class.
She's primarily showing us how we can use AI to do what we'd normally take hours and a lot of brain work to do in minutes, using prompts with context.
So many things to relearn in this class.
The argument is that vibe-coding speeds up shipping.
It does.
It also speeds up shipping vulnerable code when the person prompting has no idea what secure code looks like.
You cannot review what you cannot recognize.
Firing your senior devs to cut costs while keeping the AI that learned from them is not a strategy.
It is a countdown.
Databases like @SoloditOfficial exist because humans spent years recognizing and documenting what bad code looks like.
That institutional knowledge is not replaceable. It is the baseline everything else is built on.