Truegav
@Truegav
Followers
72
Following
115
Media
21
Statuses
333
Board member at Cryptonite (#2 CTF team nationally) | #3 SolanaCTF | Web3 Security Goat
REDACTED
Joined January 2023
All the privacy tools I use: A thread #privacy #cryptography #Anonymous @sethforprivacy (notice me senpai)
1
0
10
When Meta trains it models on 80+ TB of pirated books from LibGen and other platforms, it's called 'fair use', without them having to pay penalties and / or receive some form of legal punishment, as proceedings are ongoing. When Aaron Swartz downloaded 70 GB of articles from
304
7K
32K
Say it with me:"Code is speech"
0
0
0
But it really does erode a lot of trust. I will now think twice before trying a new protocol, before trusting an audit, or putting my money in projects I care about. (10/10)
0
0
2
This thread feels pretty harsh. Specially as a hacker. it really does hurt when someone breaks code you considered perfect. Its easy for me to write this. I don't have to bear the guilt of users losing their life savings. Or staining your auditing firm's reputation. (9/10)
1
0
2
Audits, it seems, are just expensive receipts for code that's "secure, until it isn't." The 'Decentralization' part from 'defi' seems to be missing. It raises all the same questions and Eth's DAO hack (8/10)
1
0
2
Victims get their money back. But let's be clear: A 7-person committee remotely burning assets from a private wallet is not "DeFi." It is a bank, just with more steps, and no insurance. The value of osETH was just proven to be a revocable permission slip from 7 signers (7/10)
1
0
1
Now, after proving their protocol is a glorified, admin-controlled database, the @stakewise_io team has submitted a proposal to remove this "feature." "It was the first and last time," A very convenient, one-time-use god mode. (6/10)
1
0
2
A 7-member "DAO" multisig held the keys. On Nov 3, this multisig sprang to life, executed a transaction to grant itself the controller role, and promptly called: burnFrom(hacker_wallet, amount) mint(dao_wallet, amount) Poof. Hack undone. (5/10)
1
0
2
Moving on from the hack to the recovery. StakeWise, issuer of the stolen osETH & osGNO, announced they've clawed back ~$20.7M. Not via negotiations. Not by hacking the hacker. They did it by simply... deleting the assets from the attacker's wallet. (4/10)
1
0
2
If you sat me down, and explicitly told me there was a vulnerability in Balancer's code, it would take me days to even think of this idea. To find this bug in a protocol you know has had 11 separate audits, including from @OpenZeppelin and @trailofbits is baffling (3/10)
1
0
2
The attacker chained thousands of micro-swaps in a single transaction, compounding the rounding flaw to drain the LPs. Now, rounding error vulns are nothing new. But the way the hacker amplified the precision loss is crazy even to a seasoned CTF player like me. (2/10)
1
0
2