Guys, ASC is now on pip:
pip install droidasc
Optimize global xrefs with bytes.translate → ~30% faster.
Friends already using it to mass-scan big vendors and finding one-click bugs. Even my bug from yesterday got duped…
Not sure open-sourcing this was a good idea😂
#BugBounty
On Telegram, anyone can utilize AI bots to easily develop, launch and manage their own bot – with no coding required. #TelegramTips
More information for developers is available here:
https://t.co/xBsBGCc664
Telegram for macOS can render spoiler text as pseudo braille.
Screenshots or screen shares can allow the hidden text to be recovered.
Spoilers ≠ security.
Treat them like blur, not encryption.
Try it here: https://t.co/mfqGTcGnJZ
Big news! 🔥
Yesterday I left my role at Clerk to go all-in on Shaders, a brand new way to bring creative effects to frontend frameworks!
🚀 Early access it right around the corner. Join the waitlist today at https://t.co/Jq8h3jH3GR and let me know what you think!
Here’s the first look 👇
From context engineering to embeddings, chunking might be the most underrated part of the pipeline.
It has more of an impact on performance than most people think 👀
Chunking is the pre-processing step of splitting texts into smaller pieces - the "chunks" that become the actual units stored in your vector database. Each chunk gets vectorized and determines what information gets retrieved when you search.
Top 𝗰𝗵𝘂𝗻𝗸𝗶𝗻𝗴 𝘀𝘁𝗿𝗮𝘁𝗲𝗴𝗶𝗲𝘀 you should know:
📏 𝗙𝗶𝘅𝗲𝗱-𝘀𝗶𝘇𝗲 𝗰𝗵𝘂𝗻𝗸𝗶𝗻𝗴: The simplest approach - split text into chunks of consistent size (e.g., 100 words, 200 characters). Easy to implement but might break sentences awkwardly.
🔄 𝗥𝗲𝗰𝘂𝗿𝘀𝗶𝘃𝗲 𝗰𝗵𝘂𝗻𝗸𝗶𝗻𝗴: Hierarchically splits documents, preserving structure while creating manageable chunks. Great for maintaining context across different levels of detail.
📄 𝗗𝗼𝗰𝘂𝗺𝗲𝗻𝘁-𝗯𝗮𝘀𝗲𝗱 𝗰𝗵𝘂𝗻𝗸𝗶𝗻𝗴: Uses natural document markers like paragraphs, sections, or chapters as boundaries. Keeps related information together but can create wildly different chunk sizes.
🧠 𝗦𝗲𝗺𝗮𝗻𝘁𝗶𝗰 𝗰𝗵𝘂𝗻𝗸𝗶𝗻𝗴: Variable-size chunks based on meaning rather than arbitrary markers. More sophisticated but computationally intensive.
⏰ 𝗟𝗮𝘁𝗲 𝗰𝗵𝘂𝗻𝗸𝗶𝗻𝗴: Embeds first, then chunks - preserving more contextual information in the vectors themselves.
There's really no one-size-fits-all strategy, like most things, it depends on your data. Your chunking approach directly impacts both information retrieval AND the contextual information provided to your LLM, and is definitely part of this new world of context engineering.
My recommendation: start with fixed-size chunks of ~200-500 tokens with some overlap, then experiment based on your specific use case. Document structure matters - technical documentation might benefit from section-based chunking while narrative text might work better with semantic approaches.
Check out this page for a deep dive into setting up chunking: https://t.co/PFIp5hTlr9
or this ebook for more deep dives into advanced RAG strategies: https://t.co/r4liiopeGS
Generating PDFs is hard. Including puppeteer in your app bundle is error-prone outside of Javascript apps.
Use Cloudflare's Browser Rendering API. You can add auth, deploy it, and use it to render PDFs across projects.
https://t.co/J5Qc0pgLGk
🥳 It's an exciting day! 🥳
Thanks to @Webflow GSAP is now 100% FREE - including ALL of the bonus plugins like SplitText, MorphSVG, and all the others that were exclusively available to Club GSAP members.
We can't wait to see what you make!
16,582 OpenAI keys - all active as of this post, with credit deposited on the account for this project.
Y'all have my authorization to go crazy in this environment. Good luck, and please be kind to my wallet 🙏
https://t.co/Hz62zcTfVi
TL;DR: A dev machine of Safe was compromised. This allowed access to AWS and their S3 bucket. A malicious JavaScript was pushed to the bucket and eventually distributed. The malicious JS code targeted specifically the Bybit contract address. The JS code changes the content of the transaction during the signing process.
Bybit shared to investigation reports here: https://t.co/2E9KCeOKPf
So, this is how lazarus drained 1.5 Billion
1) malicious JS injected into Safe{Wallet} at https://t.co/s8gAO3DM4d (because apparently, one of the nk devs just casually pushed it to production 🤡)
2) the JS modified executeTransaction() only if the signer was in a predefined list (Bybit’s multisig owners).
3) modified transaction now sets operation: 1 (delegatecall) to attacker address instead of a normal call.
4) delegatecall hits the attacker contract, which changed Safe contract's first storage slot which is masterCopy to a another attacker contract.
5) new masterCopy contract contained sweepETH() & sweepERC20(), draining $1.5B