🤝 We’re thrilled to partner with @Aptos_Labs to release Revela Decompiler - the first ever open-source tool to decompile Move bytecode back to its original source code.
Revela is made open-source, find it at Verichains GitHub: https://t.co/0aqXVOgzgi
Revela is also available as an online tool at https://t.co/9zGzLd9rGk
The Move decompiler developed in collaboration by @Verichains and @AptosLabs is a game changer for the security on the @Aptos network. It allows to convert any bytecode deployed on chain back to source code. Only possible with Move!
https://t.co/T6hzdyX5FU
FAST malware analysis with binary emulation! @asoni taught me a ton of sweet stuff going through a Qakbot sample, Cobalt Strike and more using emulation frameworks like Unicorn and Qiling... seriously super cool, huge thanks to Anuj for showcasing! https://t.co/PhYxUxaMm9
2/ This remind me of the response from CEO of #Multichain after we reported critical #MPC#vulnerabilities. It was later found out that all MPC 'trusted nodes' were actually run under the his personal cloud account and the #bridge got #hacked eventually! https://t.co/4apCYJBJtY
3/ Reporting bugs directly to vendor or via #bugbounty are both painful. For example, #THORChain stopped responding to our emails after receiving full POC & paper. Even though they had halted the chain globally due to our report https://t.co/Ch36IysEI2
4/ We've now opted to directly inform the public about the potential #risks instead. It's also important to remember that ##MPC and #ZKP are relatively new and complex protocols, making them susceptible to #vulnerabilities. Stay tuned for more MPC/ZKP #bugs releases from us!
1/ After #TSSHOCK#MPC mass pwned, it's now #ZKP's turn. We've reported a Critical Proof Forgery Attack, allows anyone with access to an aggregator, to steal funds from a top #zkEVM Layer-2. Unsurprisingly, vendor's reply: '..not exploitable by anyone due to centralization'!!?
Just In!
Our TSSHOCK paper acceptance into @BlackHatEvents, the premier cybersecurity conference!
#BHUSA Join our researchers in Vegas this August, as we will share in this briefing our critical 0-day attacks on MPC vaults and wallets.
Brief notice here: https://t.co/1xb8tf93OX
I've put together a new blog post! This one re-treads @bl4sty's earlier AMLogic research but takes my own approach to exploit development, with an 'alternative' vulnerability and an emulator. Just for fun!
https://t.co/ZjNFniOjz9
I have published a tutorial on writing an emulator using the @unicorn_engine for security testing custom radio protocols on @NordicTweets SoCs.
https://t.co/XtYyJBxFBq
video: https://t.co/gfcLl6rFWj
#IIoT#security#nrf52840