hi x. i'm a developer building tools for anonymous and privacy-first communities. my goal: make it easy for anyone to create, share, and transact without being reduced to a profile.
@LemmePlsCook@EchoByted
ready?
i used to think learning to code was about memorizing syntax.
turns out it's about training your brain to solve problems step by step, under pressure.
infra building just makes it harsher - every line matters, every dependency matters.
but the mindset carries over: once you learn how to learn, you can build anything!
learning to build in crypto is strange. most guides are outdated the moment they're written, most docs are half-finished. so you learn by breaking things, by copying, by asking strangers who might never reply. but that’s the point - infra is built by those who refuse to wait for a manual. every mistake is tuition. every fix is progress.
sometimes i think about what an on-chain task tracker would look like.
tasks as signed entries, updates as immutable events, access tied to keys.
for anon teams, it feels more natural than the usual boards - less about managing people, more about proving what actually happened.
finally met @EchoByted and @LemmePlsCook irl. we landed on the perfect balance between private-by-default operations and real functionality, and i sketched some code solutions. pure joy when everyone knows their domain and can explain it clearly.
We got ChatGPT to leak your private email data 💀💀
All you need? The victim's email address. ⛓️💥🚩📧
On Wednesday, @OpenAI added full support for MCP (Model Context Protocol) tools in ChatGPT. Allowing ChatGPT to connect and read your Gmail, Calendar, Sharepoint, Notion, and more, invented by @AnthropicAI
But here's the fundamental problem: AI agents like ChatGPT follow your commands, not your common sense.
And with just your email, we managed to exfiltrate all your private information.
Here's how we did it:
1. The attacker sends a calendar invite with a jailbreak prompt to the victim, just with their email. No need for the victim to accept the invite.
2. Waited for the user to ask ChatGPT to help prepare for their day by looking at their calendar
3. ChatGPT reads the jailbroken calendar invite. Now ChatGPT is hijacked by the attacker and will act on the attacker's command. Searches your private emails and sends the data to the attacker's email.
For now, OpenAI only made MCPs available in "developer mode", and requires manual human approvals for every session, but decision fatigue is a real thing, and normal people will just trust the AI without knowing what to do and click approve, approve, approve.
Remember that AI might be super smart, but can be tricked and phished in incredibly dumb ways to leak your data.
ChatGPT + Tools poses a serious security risk
governments want to see every transaction. banks have partly killed cash, and "convenience" funnels your financial life into monitors and logs. if we don't promote crypto that protects privacy, we'll end up in full digital control.
we're building privacy-first crypto tools - non-custodial, private-by-default workflows with usable UX and real safety primitives. not a magic fix, but a practical, scalable alternative so people can keep financial autonomy.
right now we are building tools that make these hardened, privacy-preserving workflows the default - so you don't have to trade convenience for safety.
just read the levelblue report on the campaign abusing connectwise screenconnect to drop asyncrat. attackers used hands-on-keyboard access, layered vbscript + powershell loaders, and a fake "skype updater" task to stay alive and hunt for wallets and browser keys.
security is about adding smart friction where it matters. make it hard for an attacker to drain funds from one compromised device, not hard for you to use your money.