PIL program initiative is out!
Dive into our 🎡 plan to drive the most value to the @LiquityProtocol ecosystem and lock-in ~10% ETH-denominated yields on @ipor_io
Check out the vault here: https://t.co/wf3VCgQFQT
The UFO / UAP docs dropped today
i couldn’t leave them sitting in random PDFs
so i turned them into a searchable archive:
all records, maps, timeline, photos, videos, and page-cited answers
reply with a query, i’ll post the best hit or try it yourself at
https://t.co/M0dwpi6xJn
@DrNickA @yieldchad @chud_eth The project can keep running keeping the treasury corresponding to the holders that don't redeem.
You can buy tokens and ensure part of the treasury is kept.
Matchday: UCL & Copa Libertadores today.
Make your calls and get CLOUT, no 💸 involved here
https://t.co/C74GPAm3oA
1⃣ Live game stats and predictions
2⃣ Custom calls
3⃣ Participate on each game, earn Clout and climb the leaderborad
This means that CURATED is expanding, moving from being a crypto and token-focused fundraising platform into a crypto-powered generalized investing platform.
CURATED is now targetting to be the place where investors can find attractive opportunities in any sector, including: Robotics, AI, Biotech, Hardware, and (of course) crypto.
Something big is coming to CURATED 😏
We're working with a partner to open up equity deals on our platform! Enabling access to pre-seed to growth rounds, secondary deals, and Pre-IPO companies.
curl | bash isn't a meme anymore. It's how most dev tools ship now. Which means every command you paste from ChatGPT, a README, or a Discord DM is a supply-chain decision you're making without realizing it.
Attackers realized. They've scraped millions of LLM responses, collected the package names GPT, Claude, and Copilot hallucinate, and quietly registered them on npm, PyPI, crates, etc.
It has a name now: slopsquatting. USENIX researchers tested 16 LLMs on 576,000 code samples. 58% of the hallucinated packages repeated across runs, Attackers farm them, register, and wait
Your terminal doesn't know the difference. Your lockfile captures the hash of whatever you ran, malicious or not. The CVE lands a week later. By then, Team PCP, UNC1069, and Shai-Hulud already have your GitHub token, your AWS keys, and a fresh public repo named after you.
This is the supply-chain version of the homograph attack. Same idea. New surface.
I built tirith to catch the curl version two months ago. v0.3.0 catches the install version:
Signed Threat DB cross-referenced before the install runs. Malicious-package intel from @openssf and @datadoghq. IOC/blocklists from @abuse_ch. Tor exit coverage via @torproject. Live OSV and deps lookup via @GoogleOSS.
Still local. Still no telemetry. Still free and Open Source
https://t.co/sRZ5n5IZ69
It is comforting to know that the 3/4 multisig is also protected by a 9/12 multisig
I think Arbitrum made a tough and correct choice today, if you have the power it is your responsibility to use it
@arbitrum