We reviewed Mina Multisig's FROST integration line by line, not because a scanner exists for this kind of cryptographic code, but because a library's guarantees only hold if every override respects them.
Full case study on @AuditHubDev. @nori_zk
The same tokens got counted twice.
Once as a deposit the protocol owed back. Once as a reward it had earned. Both were withdrawable.
@FormallyJon on how $27M leaves a reward calculation.
Reentrancy was the delivery. The accounting was the bug.
Exploits got cheaper to generate. Patching after launch did not.
@KFerles on where security has to move. Check invariants with humans and AI at the design phase. Then run static analysis and AI scanners on every commit.
Earliest catch is always the cheapest fix.
@RealFinOfficial A dedicated validator set is the interesting call here. Tokenized RWAs bring compliance and settlement expectations most general L1s never had to design for. How are you thinking about validator selection and permissioning at launch?
@ETH_Daily Agree starting early matters. The open question for me is whether big stakers treat quantum-resistant options as a due diligence box to tick before the threat is real, or just wait until it's mandated.
@StarkWareLtd The Falcon-512 tx at ~$0.06 is the detail that matters commercially. PQ security usually means a cost premium that kills adoption. Proving it's economically viable today changes where teams decide to build.
@immunefi@trmlabs Agree the barrier is collapsing. The flip side worth naming: LLMs compress the defender's cycle too. The teams pulling ahead are the ones catching the low-skill, high-volume attempts early, so the real talent only has to hunt the genuinely novel stuff.
@RealFinOfficial Owning your own L1 vs building on a shared chain is a real tradeoff. You get control over gas and network params, but you also carry the full weight of validator trust yourself. The sequencing for testnet is the interesting part.
@aztecnetwork@TactfulCipher Native vs bolted-on privacy changes the whole set of assumptions you're building against, not just the developer experience. Feels like a different mental model at every layer once you actually build both.
@babylonlabs_io Solid roadmap, and the order makes sense. Curious whether the partnership announcements land before or after the tokenomics vote, since one shapes how the other gets read.
@RealFinOfficial Once the asset record itself is the audit trail, due diligence stops meaning "trust the issuer's PDF" and starts meaning "read the state." That's a real shift for institutional buyers.
@RealFinOfficial Three separate firms is smart. Did you have each one focus on a different layer, or run them all against the full codebase? The overlap vs. coverage tradeoff is where teams tend to leave gaps.
@ekidenfi Solid milestone. Validating market maker integrations under real activity is a hard thing to fake in a controlled environment. The move to Mainnet reads a lot more credible when you've earned it this way.
@brevis_zk The compliance angle makes this click. You can satisfy a requirement, solvency, eligibility, a KYC threshold, without ever exposing the record. That's a completely different posture than encrypting it and hoping the key never leaks.
@hrkrshnn The hit-and-run framing is the scary part. Traditional incident response assumes hours to triage. When the whole lifecycle fits in 10 seconds, the human is out of the loop before the first alert even fires.
Another $8.5M stolen this morning 🤦♂️
Audited code
Zero exploits
Perfectly legal vote
3rd major DAO attack this year
The attacker started with 2 ETH out of Tornado Cash and bought governance tokens
That was enough to seize 100% voting power in 4 of the 5 USDC vaults and about 91% of the ETH Meta Vault at Term Labs
Then he did exactly what you would expect
Proposed sending himself the money
Voted yes
Executed 😂
2,843 ETH gone about $6.87M and 1.68M USDC swapped to DAI
Can’t have Circle freeze your funds of course
PeckShield and CertiK confirmed it on-chain and the crazy part is that Term Labs' contracts are fine
Audited
Nothing bypassed
No reentrancy
No oracle manipulation
No keys lost
Someone just bought full control of the DAO for 2 ETH…
Governance that requires silence to block is governance that fails open.
Term Finance's vault proposal sat unvetoed for six days. That counted as approval. $8.5M later, the Meta Vaults are permanently shut.
@Ozone_chain The urgency framing is fair, but the near-term risk isn't computers breaking curves today, it's 'harvest now, decrypt later.' Encrypted data captured now gets read once hardware catches up. That turns it from a future problem into a present one.