NanakNihal Profile Banner
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬› Profile
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›

@NanakNihal

Followers
842
Following
3K
Media
54
Statuses
1K

Protocol Architecture | Security | ZK | Occasional Posts About Neuroscience. Founder @0xHolonym building tools for privacy, civic infrastructure, & onboarding

Joined November 2021
Don't wanna be here? Send us removal request.
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
@xkcd the real question is do you go the path that minimizes walking or try to predict where the passenger street crossing signs will be in your favor to minimize wait time.
1
0
158
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
Humanity Protocol just raised at $1.1b. They claim to use ZK and other privacy enhancing technology to keep biometrics secure. So I looked through their privacy policy and holy shit it's WILD:. First off, all personal data by default is stored on their servers.
Tweet media one
14
16
85
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
There is a name for this and it’s BLIND SIGNING. Please please please stop using hardware wallets and multisigs and thinking you are safe. Here’s how it happened and most importantly how to prevent it:.
@Bybit_Official
Bybit
3 months
Bybit detected unauthorized activity involving one of our ETH cold wallets. The incident occurred when our ETH multisig cold wallet executed a transfer to our warm wallet. Unfortunately, this transaction was manipulated through a sophisticated attack that masked the signing.
9
7
62
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
I found a way to copy private keys from Friend Tech with two user clicks, making it as easy as prompting toπŸ“‹paste to steal wallets. @friendtech and @privy_io teams fixed it in hours. FT gave a bounty despite not having a bounty program. Major kudos for taking security seriously!
13
10
56
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 months
It's not about using a TEE, it's about how you use it. Most TEEs are *mostly* useless. And most ways projects use TEEs are *mostly* useless. Spicy opinions on TEEs:.
8
3
57
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
After the recent blind signing attack we decided to launch Human Wallet in alpha mode. What is our radical security fix?. Allowing you to see transactions on your hardware wallet in a human-readable way.
Tweet media one
3
10
37
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
fighting for privacy with @0xHolonym team at the @0xbowio event. the privacy / compliance protocols seem to really like knife fighting. GG @jhscheufen @ameensol. Fuck North Korea
Tweet media one
Tweet media two
5
3
39
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
9 months
I am thrilled to announce that we have raised $5.5 million to build human keys.
@0xHolonym
human.tech by Holonym
9 months
1/ πŸš€ Big news! Holonym Foundation has secured $5.5M in seed funding to advance global digital personhood through ✨Human Keys✨ . Led by @FinalityCap & @Papervc and .
Tweet media one
5
1
33
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
1 month
People are wrong. Crypto and cryptography have tons of use cases. Just not where investors and developers live.
Tweet media one
1
4
35
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
7 months
Here’s why ZK matters in developing countries:.
1
2
31
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
@Bybit_Official This type of attack is called blind signing and is increasingly common. Here is how to prevent it.
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
There is a name for this and it’s BLIND SIGNING. Please please please stop using hardware wallets and multisigs and thinking you are safe. Here’s how it happened and most importantly how to prevent it:.
0
0
11
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
FYI: the @magic_labs team still hasn't paid me three months after I disclosed a critical vulnerability which saved their users millions of dollars in their official bounty program. They even publicly bragged they fixed it, yet are ghosting me. How can we hold them accountable?.
3
8
28
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
6 months
Ranking Bangkok side events for coolness based on how willing attendees were to get our temporary tattoos:.1. @FundingCommons clear winner. tattoos, tramp stamps everywhere, no fear to represent bringing digital human rights to everyone through cryptography.
5
3
27
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 months
We haven’t spoken loudly our metrics because we haven’t felt a huge need. But when worldcoin thinks they’re bigger than you, I think it’s time to clarify:.
@DCbuild3r
dcbuilder.eth βšͺ️
2 months
@NanakNihal @Rahul__Ghangas @HumnPassport I mean you can, but it's always a question of how many people use that solution or provide a good app experience using that tool. Nothing comes close to the distribution and UX of World App and World ID.
1
5
28
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
DO NOT BUY THIS COIN. This is without a doubt one of the most supremely evil people in the world. First reason not to buy, he and his government is sanctioned. More reasons:.
@ascom_pmbjs
Min Aung Hlaing
3 months
The Government of Myanmar will launch the first national coin today at 8:00 AM UTC. We welcome all to participate in this historic step of Myanmar`s digital economy.
3
4
25
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
eliminating blind signing attacks has been achieved internally.
2
5
25
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
Here are two critical vulnerabilities I found in Magic Link to steal users’ entire wallet balances. They’ve been publicly implying these didn’t exist and never paying me for a bug bounty. After months of waiting, @magic_labs finished fixing them yesterday so I can now share 🧡.
3
6
23
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
We’re literally the biggest now by most metrics. And no eyeball scanners (though I love the excellent research for privacy technology worldcoin has done 😘). Still feels like day 1 at @0xHolonym.
3
2
22
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 years
@Iinux No thanks I only fork after commit.
0
2
18
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
We are working on having this live tomorrow or Tuesday. Not for full treasuries or serious funds. But to *pilot the first practical/convenient solution to blind signing*. There couldn’t be a better time to make this so we are focusing full effort ASAP. If you / your company is
Tweet media one
4
0
20
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
6 months
Thanks for this well-thought-out blog post on wallets, Vitalik. Here are my thoughts:.
@VitalikButerin
vitalik.eth
6 months
What I would love to see in a wallet:.
1
1
20
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
8 months
While most people know Myanmar is in turmoil, the extent of it is shocking and not reported often:.
3
2
17
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
Sad to see when the attack you have been warning about happens…it’s frustrating that so few people cared. But at least now people do.
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
10 months
Multisigs can have many signers but the frontend is still a weakly guarded point of failure.
3
2
19
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
@LefterisJP @Bybit_Official @pcaversaccio You should probably use more than just that tool. Verification is great but not if device is compromised. You need separate device just for signing, ideally with Qubes or if not something like Windows secure sandbox mode.
2
0
1
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
7 months
holonym forever
Tweet media one
3
1
18
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
Working on something in response to the $1.5bn hack.@Ledger @safe hmu
Tweet media one
2
2
17
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
23 days
privacy is a right and when it’s eroded slowly we don’t notice. But a world without privacy is pretty scary.
@0xHolonym
human.tech by Holonym
23 days
digital privacy isn’t a luxury β€” it’s a human right. the case for a private-by-default world, and why it’s time to wake up:.
Tweet media one
1
2
18
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
the one question that haunts zk engineers
Tweet media one
0
2
17
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
Vitalik is right on 99% of everything he says. Which is why it’s so surprising he would have maximalist opinions like this about MPC vs. AA. I think most ppl knowledgeable about AA and MPC would not hesitate disagree with him here.
@VitalikButerin
vitalik.eth
2 years
@yugacohler MPC-based EOAs are fundamentally flawed because they cannot revoke keys (and no, re-sharing doesn't count; the old holders can still recover the key). Smart contract wallets are the only option.
1
1
15
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
8 months
I know this will come as a shock, but I think this is the time to announce it: I’m not Satoshi Nakamoto.
2
2
12
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
So happy to have this absolute legend on our team now @0xHolonym!.
@kbw
Kyle | human.tech | Passport | kbw.Ξth
4 months
What once started as an internal project to prevent Sybil attacks in the @gitcoin Grants program, has now evolved into one of the largest user generated identity credential solutions in web3. So excited to be joining Holonym to further sovereign digital identity. Learn more πŸ‘‡.
0
1
14
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
craziest thing at eth denver was that a bunch of people whose first time it was at any crypto conference said β€œthe people are so cool”. WHAT HAPPENED. HOW ARE WE COOL NOW.
5
0
14
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
7 months
Here’s the issue. Everyone says best practice is β€œuse a multisig”, β€œuse hardware wallets”, etc. Yet we have seen two high profile attacks in recent years following them. What is wrong with these ideas, and what should we do instead?.
@bantg
banteg
7 months
this level of attack is really scary. to my knowledge, the compromised signers have followed the best practices. they also used different combinations of os, software and hardware wallets, as well as simulated every transaction. where do we go from here? magical amulets?.
1
3
14
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
i have no words at this point. i don't think anything else needs to be said.
1
0
14
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
It was great speaking with @tomerweller @marek_ and @lucycoulden about how crypto not only can be but *is* used to provide access to digital rights and prosperity. Even in our space, most people don’t know that crypto already is super useful beyond speculation. Thanks for.
@EthereumDenver
ETHDenver πŸ”πŸ¦¬πŸ¦„
3 months
The Human Algorithm: Building the Soul of Crypto .- @tomerweller from @StellarOrg.- @NanakNihal from @0xHolonym.- @marek_ from @Celo.- @lucycoulden from @Polkadot . How do we ensure technology serves human flourishing?. Full video below πŸ‘‡πŸ§΅
0
0
14
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
29 days
Culture shapes technology. More important than building tech is building culture.
@FundingCommons
Funding The Commons ➑️ Berlin, June 10-11
29 days
"We need a refresh of the culture around technologyβ€”something transcultural, rooted in our shared humanity.". In our open conversation with by @0xHolonym, @hebbianloop and @NanakNihal explored how to build privacy-first infrastructure that centers people.
1
1
14
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
This is an incredible improvement. The asynchronicity, weighted shares, and permissionless joining and exiting are make it way more robust and practical.
@dWalletLabs
dWallet Labs
3 months
1/ Introducing 2PC-MPC V2. We’ve introduced significant improvements to the 2PC-MPC framework, which now supports not only threshold ECDSA but also Schnorr (and EdDSA) signatures. This thread details what has changed compared to the previous version.
0
3
13
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
Again, thanks @friendtech and @privy_io for having a quick response, and FT for awarding a bounty despite not having a bounty program. This encourages whitehats. As frontends are controlling wallets now, it's not just smart contracts where this type of security mindset is needed.
0
0
12
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
But they only disclose personal data to their employees, contractors, marketing partners, AI model training, the Chinese government, other governments, and to anyone they want if it would "prevent financial loss"
Tweet media one
1
0
13
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
11 months
Yes, ZK can actually make consumer lives easier and safer.
@madhavanmalolan
Madhavan (Maddy)
11 months
App Presentation at @NanakNihal from @0xHolonym (Silk App)
Tweet media one
0
1
13
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
This is the best time to be building real use cases of crypto: stable coin payments, remittances, high yield, financial infra for developing counties, etc. When everyone is skeptical of anything other than memes, yet infra has caught up to the point where real uses are possible.
1
0
10
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
8 months
@ma1fan You can add it here if things don’t get better (or maybe even if they do)
0
0
12
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
Just arrived in Denver, it’s a little cold but I’m so excited to network with everyone!
Tweet media one
0
0
11
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
7 months
the goat @Muzzamil_01 at a rare time he needs to eat instead of constantly shipping @silkysignon
Tweet media one
0
1
10
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 months
Burmese friend sent me this. If you’re wondering how to help you can donate here. It took like 30s to donate. It’s a small org and money goes a long way
Tweet media one
Tweet media two
1
1
11
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
ethdenver this year is great β€” despite the complaints on CT, it’s a super small group of committed people who work in a bear. this is so much better than bull markets….
0
0
12
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
See you πŸ”œ let’s talk about 2PC-MPC.
@GrootKkw
ubergeek.sui γ€ŒπŸ¦‘γ€
3 months
Gentle reminder tonight I will host a space with as guest speaker, @NanakNihal from the @0xHolonym team. Nightly β˜•οΈ at 8PM US Central time. They been building on @ikadotxyz . Go check them out and get your questions ready to be asked.
2
2
11
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 months
this was an incredible day of talks.
@0xHolonym
human.tech by Holonym
2 months
Live with Restream, March 14
0
2
11
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
Friendtech fixed this by setting X-Frame-Options to DENY, preventing malicious dapps from embedding their wallets. This is something every project with a dapp-specific wallet should begin to put in their headers. Yet most don't developers don’t know they should add those headers.
1
1
11
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
it's fun when you're building a wallet and check to see how other wallets have implemented basic security features and it turns out they haven't at all oops lol.
4
0
10
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 years
Excited to be building on Keelung.
@BTQ_Tech
BTQ Technologies
3 years
Hello, Keelung! Our team has been working on a zero-knowledge cryptography development toolkit for fast, private and secure applications. Learn more:
Tweet media one
5
4
10
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 months
running your code nitro enclave doesn't automatically make it secure. enclaves can't handle persistence, so you need to store data somewhere, encrypted to a key outside an enclave. If you use KMS, you're storing it in a centralized way a cloud account can access!.
1
0
11
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 months
So should we use SGX instead because it's less centralized / not in the "cloud"? Definitely not. SGX and any other TEE still struggles when it comes to persistence. TEEs don't have persistent storage.
2
0
10
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
In our space it’s rare to find organizations where everyone cares about building meaningful technology. Funding the Commons is one of the few spaces where people come together to focus on crypto for good. It’s easily the top quality event in crypto.
@FundingCommons
Funding The Commons ➑️ Berlin, June 10-11
4 months
Identity shouldn’t be a barrier to financial access or basic rights. πŸ”. @hebbianloop and @NanakNihal, the co-founder of by @0xHolonym, explore how zero-knowledge identity proofs are securing privacy and autonomy where institutions fail.
0
0
10
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
9 months
For what it’s worth: we have never experienced any request or pressure from the to send the @eigenlayer team tokens. They have been professional in every interaction with them.
2
0
10
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
To try it out, go to and add your hardware wallet as the 2FA method in Privacy & Security settings:
Tweet media one
1
0
8
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
UPDATE: ITS LIVE on chrome webstore. No need for walletconnect.
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
After the recent blind signing attack we decided to launch Human Wallet in alpha mode. What is our radical security fix?. Allowing you to see transactions on your hardware wallet in a human-readable way.
Tweet media one
1
0
10
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
They use your biometric palm print, name, social media, content viewing habits, etc. for marketing
Tweet media one
1
0
10
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
Also big thanks to @samczsun and the Paradigm team for helping coordinate everything so quickly.
1
0
8
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
Again, this is a $1.1b company and have been claiming ZK and privacy as one of their largest value props:.
1
0
10
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 months
The most fun part about having company treasury onchain is the accidentally finding $100k on some random chain.
2
0
10
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
7 months
we are proud to be building privacy preserving civic infrastructure @0xHolonym. This is one of many uses cryptography can have in real life.
0
0
8
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
1 month
Crypto adoption will likely come from cypherpunk value props as these are the primary value props crypto has. These can only be enforced via the infra layer, but infra alone is insufficient without also focusing on adoption.
@owocki
Kev.Ξth
1 month
cypherpunk 🀝 adoption. (thanks @post_polar_ & others for the dialogue)
Tweet media one
2
3
7
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
1 year
We started this as a hackathon project. Really cool to see our relayer is now often #1 gas spender on @Optimism, and we're grateful to be part of this ecosystem that values public goods funding.
@0xHolonym
human.tech by Holonym
1 year
πŸ•΅οΈβ€β™‚οΈwhere’s Holonym?. πŸ”Žhint: we’re just a hop over . πŸ™ thanks to OP badge holders for voting us #155/643 . ZK verifications place us as one of the largest gas guzzlers on OP. These fees go straight back to public goods 🫦.
1
0
9
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
looks absolutely gorgeous.
@0xHolonym
human.tech by Holonym
4 months
something big is coming
0
0
9
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
7 months
ZK prevents this liability. If no one holds sensitive data, no one can hand it over to hostile governments.
1
0
9
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
8 months
sad news for everyone involved. wonder if fidelity has heard of zk.
@WatcherGuru
Watcher.Guru
8 months
JUST IN: $5.4 trillion asset manager Fidelity confirms 77,000+ customer records were hacked, including license, social security numbers, and personal information.
0
0
8
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
24 days
Hard to use this app when half of the timeline is anti-woman, anti-black, and anti-Indian. Not even well reasoned arguments just hatred. Does this happen to everyone / ppl people twitter thinks are right wing because of crypto? Or is this just a me thing.
5
0
9
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
1 month
Arrived in London and the Burger King is playing slow classic Hindi songs. I love this city.
1
0
9
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
And they're a chinese company
Tweet media one
2
0
9
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 months
Human ID has issued over 34M credentials. Last time I checked, that’s more than World.
1
0
9
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
7 months
Refugees need identities (like everyone else). But they have not trusted orgs to give them identities.
1
0
9
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
The attack worked because for some reason, most webservers typically do not set X-Frame-Options leaving websites vulnerable to clickjacking by default.
1
0
7
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 months
@DCbuild3r @Rahul__Ghangas @HumnPassport dude you need an orb to verify and it’s broken half the timeβ€” wdym nothing comes close to your UX? And ppl refuse to use an orb bc they feel like it’s selling the windows of their soul to our AI overlord. Not ideal UX. With passport you only need a browser, no orbs. We have.
1
0
8
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
NOTHING LIKE A 4AM DEBUGGING SESSION TO GET YOU IN THE ZONE.
2
1
7
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
What the fuck @magic_labs .- has bounty program of $3k max.- critical bug that can steal whole wallet.- pays $1k and refuses to create a timeline to fix it.- another report of same severity.- ignores it after I mention it ~8x.- fixes, brags about fix, never pays, ghosts.- posts:.
@magic_labs
Magic Labs
2 years
πŸ” At Magic, we prioritize product security through proactive measures and collaboration with ethical hackers via @Hacker0x01. Our goal? Strengthen security and safeguard user data & digital assets through community-driven bug bounties. πŸš€#BugBounty.
0
2
8
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
6 months
when your founders are 2/3 vegan but marketing team isn't πŸ˜….
2
0
8
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
6 months
i'm noticing that scaling a company should be done with education, not processes. aligned teams that understand vision, mission, and execution and can then be autonomous >>> teams with clear instructions. it takes time to onboard but allows the team to be wayyy more productive.
0
0
7
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
10 months
Crowdstrike is old news. But what does it mean for your crypto?.It’s actually really bad:.
1
1
8
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
Catch us tonight at the antalpha hacker house if you’d like a deep dive on how Holonym works and how to incorporate privacy into your dapp with ZK about how ZK works.
0
3
8
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
7 months
feeling Silky @silkysignon
Tweet media one
0
1
8
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
I think we have caused a flawed mental model by echoing the classic advice that startups solve problems, and phrasing every pitch in terms of solving a problem. There are so many great companies that don't clearly solve a problem.
1
0
6
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
9 months
Highly recommend longhash accelerator for any early stage founder!.
@LongHashX
LongHashX Accelerator
9 months
Excited to share that.@0xHolonym., an alumni of LongHashX Accelerator Cohort 9, has closed their seed round! It's been incredible to have worked closely with @NanakNihal, @hebbianloop and the rest of the team through - . β€’ Weekly problem-solving sessions with a dedicated.
1
1
8
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
7 months
So what should you do?.There are two answers. One option is use a dedicated device and.OS (e.g. Qubes, tails, grapheneOS). The other is use 2PC (such as @silkysignon or @ZenGo) where even if your device is compromised tx sim is done remotely as well.
1
0
8
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
7 months
warning for those in Thailand: google translate for English->Thai automatically shows the translation of β€˜I love you’ when you type β€˜I’. This just caused a very funny circumstance.
0
0
6
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
waking up to tornado cash being legal vibes ✨.
0
0
7
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
8 months
I love this spicy tweet. Have always wanted a wallet security ranking, so I will check it out. sad for the victim, tweets like this will fix it in the long term.
@coinspect
Coinspect Security
8 months
IT IS WEB3 WALLET'S FAULT.We believe many wallets are phishing traps putting users at risk. Since we can't prove who's behind them, we've created an objective Wallet Security Ranking to help protect everyone.
0
1
7
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
8 months
- You can get killed for using internet. Internet has become illegal, with starlink as the only option. The military dictatorship has bombed starlink sites, causing new internet hotspots to be made with bomb.shelters.
2
0
7
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
What To Do?.Ask @magic_link and companies in general to change their culture around security, including fixing bugs *before* they are taken to the public, not leaving security researchers unpaid, and being transparent about vulnerability+audit reports ;).
0
0
7
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
For friend tech, a straightforward clickjacking attack doesn't work since it takes three clicks to perform dangerous actions. Parent websites can't track these clicks, so they can't respond sufficiently to attack the user.
1
0
6
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
4 months
the first decentralized oblivious pseudorandom function!.
@HumnNetwork
Human Network, previously Mishti Network
4 months
Big news here:. @0xHolonym's Mishti Network is now live on @symbioticfi.This collaboration marks a major step forward in decentralizing and fortifying Human Key Infrastructure to harden natural digital rights through crypto-economic security.
Tweet media one
0
0
7
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 months
The other class of attacks to be careful of is replay attacks. Enclaves don't have trusted data about the external world, much like the walled gardens of blockchains that require trusted oracles to function. When you restart an enclave, you can replay some or all of the encrypted.
1
1
7
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
8 months
Thanks @Lightshift_xyz for the awesome article and being a stellar investor in @0xHolonym πŸš€.
@Lightshift_xyz
Lightshift
8 months
🧡 Identity is broken. Centralized systems expose users to risks and security breaches. Learn how @0xHolonym is changing this, building a decentralized identity framework that puts users back in control of their data ↓.
1
0
6
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
8 months
Thank you frens from Myanmar who will remain unnamed (for safety) for educating me about this.
0
0
6
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
7 months
@decryptmedia @worldlibertyfi @s_lutz95 The first stablecoin pegged by the ruble.
0
0
7
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
3 months
@basedkarbon bro she literally shot the attacker and you’re saying women have bad opsec. women are statistically more risk-averse in many ways such as finances. this is a wrong take.
2
0
6
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
7 months
I will write more on this but wanted to put this out there. we need a lot more accurate information on how to better secure funds.
0
0
7
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
10 months
Here is a reminder *multisigs aren’t necessarily safe even with hardware wallets*. It’s a tragedy their customers’ funds were lost. The only thing good that can come out of it as an opsec lesson nobody seems to know….
@Mudit__Gupta
Mudit Gupta
10 months
WazirX hacked for over $230m USD (2,000 cr INR). Their safe multisig was compromised and drained. The hackers started practicing the hack onchain at least 8 days ago and finally executed it today. It's a very methodical and organized attack, pointing towards DPRK as the hacker.
Tweet media one
2
1
7
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
1 year
If anyone ever finds the private key to 0x01234567890abcdef01234567890abcdef012345 it’s theirs πŸ˜‚.
@0xHolonym
human.tech by Holonym
1 year
the first ZK NFC verification of an e passport is now immortalized on chain. deep fakes no longer a threat.
0
0
6
@NanakNihal
Nanak Nihal Khalsa πŸ”œπŸˆβ€β¬›
2 years
gm. i protecc. Thanks for the Holonym memes @jeenaeth.
2
1
7