Grok says that this post by @liorcito uncovers fresh details on the Balancer V2 exploit—like the attacker's binary search via reverts & decompiled math helper code—not yet buzzing on X. Deep dive into rounding biases & on-chain forensics:
https://t.co/N140Sw1bPz
Right @grok ?
Throwback to 2011: our founder @julianor (with @XorNinja, formerly at Google and now leading @calif_io) exposed critical flaws in SSL/TLS (HTTPS) with the BEAST attack at Ekoparty 🔥
🤯 Breakthroughs like these inspire the work we do at Coinspect today!
🚨 Worm-like supply chain attack is unfolding.
I warned this was coming and I've been building. Multiple projects: system to incentivize disclosure of risk, monitoring to detect even subtle business logic shifts, client-side protection.
Looking for partners + early adopters.
1/🧟♂️⚠️ What are Zombie dApps?
When Web3 projects shut down, their domains often expire then attackers re-register them to build “zombie” sites that drain wallets by posing as legitimate shutdown pages.
1/ 🆕 Coinspect Wallet Security Ranking 2nd edition released!!
74 wallets tested
Curious where your go-to wallet stands?
Fresh data and some surprising moves on the leaderboard. Dive in below 👇🧵
🔇Just visiting a site could drain your crypto — no clicks, no approvals.
We uncovered critical wallet vulnerabilities in Freighter, Frontier, and Coin98 that silently exposed users.
Don’t miss the full breakdown:
https://t.co/fSgUnMQsOP
⚠️The @MorphoLabs front-end incident was critical flaw in the generation of signature requests. The dApp prompted users to sign an unlimited Permit2 approval targeting the bundler3.bundler3 contract (0x65661941..Dc90245) instead of access-controlled generalAdapter1 contract.
🗺️We are developing an interactive visualization of #web3 dApp front-end dependencies.
🔎Our tool maps which third-party JS loads from which domains to help identify potential supply chain targets and harden dApps' web2 setups.
Watch the demo below:
We've confirmed latest Frontier Wallet Chrome extension allows websites to access your seed phrase. Thanks to @pcaversaccio, we are now in contact with @ravidsrk. We've sent them the proof-of-concept exploit code and are awaiting their patch to verify it fixes the issue.
🚨 Alert for Frontier Wallet Users! 🚨
⏩Create a new seed in a secure wallet and transfer your funds ASAP.⏪
Any website can access your private keys. Despite our attempts to contact @FrontierDotXYZ over the past year, we have received no response.
⏳📣Tech details next week.
📢 We were the first to announce @1inch incident: our ongoing dApp security research (👁️⭐️) provided key info (shared with SEAL 911)
Though other sites were affected, 1inch was the target, and its role in DeFi made fast action essential to protect users.
Insights from 👁️⭐️ soon.