If you are lost -> The answer is education
If you are educated -> The answer is execution
If you are executing -> The answer is consistency
Web3 security for the win, let's WIN together team🫡
💬 Onchain Message:
Mr. White Hat, thank you for deceiving JaredFromSubway MEV bot.
This bot made me lose a lot of Ethereum. Now that you have those funds, could you refund me some ETH? Great job! 🛠
https://t.co/G7AopHt4ya
Before repeating a viral root-cause theory, trace the tx yourself. The popular explanation this time
(RingSwap's approve-pattern + SELFDESTRUCT nerf) didn't match what the calldata actually shows.
Always verify before you build on someone else's analysis. BESAFU🫡
Everyone's repeating the same theory about the JaredFromSubway $7.5M+ hack (RingSwap mint/transferFrom bug).
I traced the actual attack tx myself. The real cause is much simpler and scarier.
🧵
Lesson for anyone running bots, vaults, or just a normal wallet:
→ Revoke unused approvals regularly (https://t.co/kRMVff90sO, Etherscan Token Approvals tool)
→ Never approve unlimited amounts to unknown/unaudited contracts
→ Use a dedicated hot wallet for new protocol interactions, not your main treasury
This applies to MEV bots too maybe especially to them.
The MEV bot jaredfromsubway was exploited for $7.7M!
Including:
1,583.5 $ETH($2.75M)
2.87M $USDC
2.09M $USDT
The attacker has already swapped all the funds for 4,427 $ETH($7.7M).
So far, 1,000 $ETH has been deposited into #TornadoCash for laundering.
https://t.co/HtASjgLM11
Ethereum is for shipping.
Here are 25 things the Ethereum ecosystem launched, upgraded, and announced over the past month.
0/ @thedaofund Ethereum Security Quadratic Funding Round with @Giveth wrapped. The fund supported 134 security projects and had 3,934 unique donors.
1/ @Ronin_Network, one of the largest gaming blockchains, completed its migration to an Ethereum L2.
2/ Clear Signing went live. It is an open standard designed to help end blind signing and make transaction data human-readable before signing. Contributors include wallets and hardware, infrastructure, tooling, individual builders, and the Ethereum Foundation’s Trillion Dollar Security initiative, with the @ethereumfndn acting as a neutral steward.
3/ @SEAL_911 and @Wonderland_Fi introduced DARC, a Digital Asset Risk & Compliance standard for crypto teams, with continuous monitoring across GitHub, infrastructure, multisigs, DNS, and more.
4/ @arbitrum announced that LG Electronics' blockchain team is piloting an onchain advertising network on Arbitrum.
5/ @base activated Azul, its first standalone network upgrade, introducing multiproofs, new execution and consensus clients, CLZ opcode support, Osaka repricings, and performance upgrades up to 5,000 TPS.
6/ @Mastercard expanded stablecoin settlement support to include USDC, PYUSD, USDG, USDP, and SoFiUSD on Ethereum mainnet, @arbitrum, and @base.
7/ @EFDevcon 8 Mumbai early bird tickets went live. Tickets were available paid in ETH.
8/ Türkiye's Directorate of Communications (@Communications) registered cbiletisim.eth, making its first step in establishing an official onchain identity with @ensdomains.
9/ @CashApp launched stablecoin support, allowing nearly 60 million users to send and receive USDC with no wallet setup required, live on Ethereum mainnet and @Arbitrum.
10/ @torproject and @FundingCommons launched a web3-native crowdfunding initiative supporting 10 internet freedom projects.
11/ @JPMorgan launched a second tokenized money market fund on Ethereum.
11/ @lifiprotocol launched LIFI Intents, a full-stack intent execution engine built on the Open Intents Framework, an initiative for standardizing crosschain intents.
12/ @l2beat launched Token Frameworks, a dedicated place to explore interoperability solutions, token movement, volume, speed, chains, and framework adoption.
13/ @PrivacyEthereum launched a private transfers dashboard comparing 11 protocols across privacy, cost, UX, decentralization, compliance, verifiability, state, and composability.
14/ @Veildotcash launched Veil MCP 0.2.0, enabling agents to make private x402 payments on @base.
15/ @src_co_ introduced SLOW, reversible, self-custodial crypto payments on Ethereum.
16/ @ensdomains ecosystem builders launched ENS8004, a web app that converts an ENS name into an onchain AI agent other applications can find and verify.
17/ @OctantApp introduced properQF in Epoch 12, integrating quadratic funding into the funding round.
18/ @AragonProject launched onchain profiles, making governance participants readable across forums by resolving ENS names, avatars, bios, websites, and social links from Ethereum mainnet.
19/ The Ethereum Community Hub network expanded to Lisbon, hosted at the @gnosisDAO office.
20/ @SuccinctLabs introduced data confidentiality to OP Succinct, enabling institutions to keep transactions confidential while settling to Ethereum.
21/ @HardhatHQ 3 became stable, bringing Solidity tests, multichain support, a Rust-powered runtime, a revamped build system, and Hardhat Ignition for deployments.
22/ The inaugural @ethconf, in NYC, brought together thousands of founders, industry leaders, and builders to discuss building on top of Ethereum.
23/ @EthPrague brought Ethereum builders together in Prague to discuss protocol development, privacy, culture, and long- term societal impact.
24/ @ETHGlobal introduced a new format where, for the first time at an ETHGlobal hackathon, projects do not have to begin from zero.
Just tested Tx2Poc on the ThetanutsFi exploit (Jun 15 2026, ~$2.1M)
passing PoC in 16 minutes from tx hash to forge test green.
Flash-loan → claim() → integer division truncation → free mint loop →
redeem. Full attack path reconstructed automatically, 105,471 USDC
profit asserted on-chain.
This changes the workflow completely. What used to take hours of manual
calldata extraction is now a single command.
Solid work @Z_Bra0 🔥 #DeFiHackLabs
@ivanbogatyy Had the same setup running on the Aztec codebase yesterday.
Filed PR #1052 first but used vm.rollFork instead of proper
calldata replay. Learned from your PR next time extracting
actual calldata. Claude Code + Opus 4.8 is genuinely powerful
for this.
@cyfrin ERC-8213 is clean. The length prefix preventing
collision is the key insight most people miss.
Same primitive used in Merkle leaf encoding
length-prefixing before hashing prevents
second-preimage attacks.
Is Bitcoin Stock-to-Flow model useless now?
There was a time when Stock-to-Flow was one of the most popular Bitcoin models out there.
👉🏻 https://t.co/QPiwRwKhAb
According to it, BTC should've been comfortably above $250K by now. Instead, we're still having "Will Bitcoin hit $100K?" discussions.
Did the model break, or did the market change?
@HackenProof // Must also check caller controls the `to` role
require(roles[to].adminRole == from, "not admin of target");
// OR check msg.sender is admin of `to`
require(roles[roles[to].adminRole].member[msg.sender], "forbidden");
☠️No one can feel the pain of Indian investors
🤔Agreed?
💵Invest in FD
📈Inflation beats returns
🤔Lets beat inflation with Equity
💵Invest in stocks & MF
📉Portfolio stuck for 2 years
🤔Let's move to a safe haven
💵Invest in Gold
📉Bought the top, now it's correcting
🤔Let's try crypto
💵Invest in Crypto
📉Portfolio gets halved every year
😤Enough, let's hold cash
💵Do nothing
📉USD/INR 12% down in 1year
😭😭
🤷Moral of the story
💸Many ways to lose money
🤑Making money is hard
💙Like
🔁RT