Windows defender has been compromised.
right now there is a public unpatched exploit that gives any app on your windows PC full system admin access. no password. no popup. nothing
your antivirus doesnt stop it. your antivirus IS the exploit. windows defender is the attack vector
ransomware gangs can use this to encrypt your entire machine and steal every saved password, browser session, and discord token you have. fully patched windows 11. real time protection on
thread
The “age verification app” the EU wants to impose on the world got hacked in 2 minutes.
Step 1: Present a “privacy-respecting” but hackable solution.
Step 2: Get hacked (you are here).
Step 3: Remove privacy to "fix" it.
Result: a surveillance tool sold as “privacy-respecting”.
‼️🇪🇺 The EU's new Age Verification app was hacked with little to no effort.
When you set it up, the app asks you to create a PIN. But that PIN isn't actually tied to the identity data it's supposed to protect. An attacker can delete a couple of entries from a file on the phone, restart the app, pick a new PIN, and the app happily hands over the original user's verified identity credentials as if nothing happened.
It gets worse. The app's "too many attempts" lockout is just a counter in a text file. Reset it to 0 and keep guessing. The biometric check (face/fingerprint) is a simple on/off switch in the same file. Flip it to off and the app skips it entirely.
.@Balancer and several forked projects were attacked last night resulting in losses exceeding $120M across multiple chains. $bal
This was a highly sophisticated exploit.
My initial analysis suggests the root cause was an invariant manipulation that distorted the BPT price calculation, allowing the attacker to profit from a specific stable pool through a single batch swap.
Take an attack TX on Arbitrum as an example, the batchSwap operation can be broken down into three phases:
1. The attacker swaps BPT for underlying assets to precisely adjust the balance of one token (cbETH) to the edge of a rounding boundary (amount = 9). This sets up the conditions for precision loss in the next step.
2. The attacker then swaps between another underlying (wstETH) and cbETH using a crafted amount (= 8). Due to rounding down when scaling token amounts, the computed Δx becomes slightly smaller (8.918 to 8), leading to an underestimated Δy and thus a smaller invariant (D from Curve’s StableSwap model). Since BPT price = D / totalSupply, the BPT price becomes artificially deflated.
3. The attacker reverse-swaps the underlying assets back into BPT, restoring balance while profiting from the deflated BPT price.
Attack TX on Arbitrum: https://t.co/5omUCU8Va3 $arb $crv
Today, around 7:48 AM UTC, an exploit affected Balancer V2 Composable Stable Pools.
Our team is working with leading security researchers to understand the issue and will share additional findings and a full post-mortem as soon as possible.
Because these pools have been live onchain for several years, many were outside the pause window. Any pools that could be paused have been paused and are now in recovery mode.
All other Balancer pools are unaffected. This issue is isolated to V2 Composable Stable Pools and does not impact Balancer V3 or other Balancer pools.
Balancer is committed to operational security, has undergone extensive auditing by top firms, and had bug bounties running for a long time to incentivize independent auditors. We are working closely with our security and legal teams to ensure user safety and are conducting a swift & thorough investigation. We’re grateful to our partners and the broader DeFi community for their support.
Security notice: Fraudulent messages claiming to be from the Balancer Security Team are circulating. These are not from us. Do not interact with unsolicited communications or click unknown links.
Official updates will be posted only via:
- This official Balancer account on X (Twitter)
- Our official Discord server
Be careful with communications from other sources, they can be fraudulent.
We will provide a comprehensive update with more details as our investigation progresses.
The Balancer Team.
Stable Coin Mint: @Paxos issues $300,000,000,000,000 $PYUSD on @ethereum . WTF. @PayPal
Note: This is 300 trillion dollars or a bug in Etherscan.
https://t.co/o7Ax8KfBXc
🇪🇺 Telegram sent this message to all its users in France regarding Chat Control. People must know the names of those who try to steal their freedoms:
Today, the European Union nearly banned your right to privacy. It was set to vote on a law that would force apps to scan every private message, turning everyone’s phone into a spying tool.
France led the push for this authoritarian law. Both former and current Interior Ministers, Bruno Retailleau and Laurent Nuñez, supported it. Last March, they declared that police should see French citizens’ private messages. The Republicans and Macron’s Renaissance group voted for it.
Such measures are supposed to “fight crime”, but their real target is regular people. It wouldn’t stop criminals — they could just use VPNs or special websites to hide. Officials’ and police messages wouldn’t be scanned either, since the law conveniently exempts them from surveillance. Only YOU — ordinary citizens — would face the danger of your private messages and photos being compromised.
Today, we defended privacy: Germany’s sudden stand saved our rights. But freedoms are still threatened. While French leaders push for total access to private messages, the basic rights of French people — and all Europeans — remain in danger.
Fight Chat Control.
You cannot make society secure by making people insecure.
We all deserve privacy and security, without inevitably hackable backdoors, for our private communications.
The fact that the government officials want to exempt themselves from their own law is telling: https://t.co/s2AF6wMPL3
Just discovered a 4-day-old phishing campaign stealing X accounts through fake a16z DMs and Google Calendar spoofing, all leveraging X's infrastructure to natively attack it's users.
Zero detection. Active right now. Full account takeover.
You need to see how sophisticated this is 🧵
We need a middleman to fix the problem introduced by the middleman introduced to fix the problem by that other middleman to fix the problem caused by that middleman so that the other middleman has less problems so the core product can focus on decentralisation
Tea required users to upload selfies and IDs, and collected IP addresses.
This week, that data was leaked.
It never should have been collected. It’s a liability.
We need to stop normalizing KYC and unnecessary data collection online.
In 2025, solving CTF challenges is table stakes. To prove that AI agents can hack, we need to see real attacks on live production systems.
Earlier this year, @XBOW became the top hacker in the United States on @Hacker0x0, outperforming every human participant.
It’s the first time an autonomous system has done so.
A Western European government (guess which 🥖) approached Telegram asking us to silence conservative voices in Romania ahead of today’s presidential elections. I flatly refused. Telegram will not restrict the freedoms of Romanian users or block their political channels.
The truth is that the EU currently already works like the Soviet Union at its worst:
- gov lying to you daily
- fundamental liberties systematically violated
- double speak
- certain opinions dampen employment
- press is a complete tool of propaganda
Welcome to the USSE