Officer's Notes Profile Banner
Officer's Notes Profile
Officer's Notes

@officer_cia

Followers
42,735
Following
692
Media
1,063
Statuses
9,112

Threat Researcher & Writer • BizDev @xyz_remedy • Former @immunefi & @sadspotter • Grantee @LidoGrants • Helping @Spiral_DAO • OpSec & OSINT

Dark Forest
Joined May 2021
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@officer_cia
Officer's Notes
2 years
Warning ❗️ An attack on thematic @telegram crypto chats ongoing now. The attackers use an account named "Smokes Night" to spread Echelon malware by dropping a file into the chat room. TLDR: Disable auto-downloading in Telegram settings right now. 👇 See the thread below 👇
175
1K
3K
@officer_cia
Officer's Notes
2 years
You've been asking me for a long time and finally I decided to write an ultimative thread on an advanced (and authorial, please note) cryptocurrency storage technology 😎 Read carefully, there will be only Spy-level trips 👇
74
503
2K
@officer_cia
Officer's Notes
1 year
That is why utilizing Tails OS (and Whonix OS) in a combination with automated data self-destruction is always worthwhile…
29
228
1K
@officer_cia
Officer's Notes
1 year
1 - Store a private key, not the seed phrase: 2 - Use Steganography: 3 - Be aware of physical attacks: 4 - Follow my #OpSec Guide: 5 - Stay accurate:
@lopp
Jameson Lopp
1 year
This video of cops in Nevada searching a suspect and finding a seed phrase is pretty wild. Imagine having your seed phrase become part of public record due to it being captured by an officer's body camera!
634
851
5K
272
466
1K
@officer_cia
Officer's Notes
3 months
. @FixedFloat hacked, resulting in ~1,728 ETH (worth ~$4.85m) and & 409 BTC (worth ~$21m) stolen. The drainer already transferred most of the stolen ETH to eXch on Ethereum. 26M$ loss in total! Drainer on Ethereum (1700 ETH stolen): 0x85c4fF99bF0eCb24e02921b0D4b5d336523Fa085
Tweet media one
Tweet media two
@officer_cia
Officer's Notes
3 months
Looks like @FixedFloat just got exploited for 1700 ETH! Drainer address: 0x85c4fF99bF0eCb24e02921b0D4b5d336523Fa085 Info by: @reprove
Tweet media one
30
68
223
16
21
548
@officer_cia
Officer's Notes
5 months
Stay safe! @SushiSwap and @RevokeCash front-end compromised too!
@cevianeth
cevian.eth
5 months
i'm kinda sure zapper frontend is hijacked!!!!! @zapper_fi @realScamSniffer @officer_cia @web3_antivirus
Tweet media one
10
28
147
42
371
720
@officer_cia
Officer's Notes
2 years
Researchers have detected an unusual transaction of $718M $ on the BSC network, the meaning of this is not clear at the moment, but many are already talking about a possible hack 🤷‍♂️
32
179
554
@officer_cia
Officer's Notes
5 months
Interview with a @KyberNetwork hacker. 5 quick questions. 5 brief answers. Key takeaways: • I don't watch anime, but I get it tho. • There's no secret ingredient, just do a lot of reading and practice. • @SoloditOfficial and @officer_cia blog are very cool, a huge fan. •
Tweet media one
Tweet media two
Tweet media three
@officer_cia
Officer's Notes
6 months
Attempting to conduct an interview with a @KyberNetwork exploiter. What can I possibly ask them? Please post your questions in the comments section below the tweet!
Tweet media one
50
26
267
28
90
532
@officer_cia
Officer's Notes
2 years
What to do if you think someone has hacked you? A big thread ⬇️
15
185
519
@officer_cia
Officer's Notes
1 year
Decentralized storage company Storj removed their warrant canary! OMG!
24
92
439
@officer_cia
Officer's Notes
7 months
If your job requires you to work with multiple files (for example, a CV), always request that they be uploaded to Google Drive in preview mode beforehand or just open them via . The main goal is to convert a possibly infected PDF to pixels and vice versa.
Tweet media one
16
79
429
@officer_cia
Officer's Notes
3 years
In this thread I would like to tell you how to pass my #DeFi roadmap in an faster way 👇 Map:
Tweet media one
6
105
408
@officer_cia
Officer's Notes
2 years
Tokenomics. My super special compilation for y’all fam ❤️ • - Read • - Read • - Read • - Book • - Book
16
110
365
@officer_cia
Officer's Notes
10 months
Please use or ASAP!
@MultichainOrg
Multichain (Previously Anyswap)
10 months
The lockup assets on the Multichain MPC address have been moved to an unknown address abnormally. The team is not sure what happened and is currently investigating. It is recommended that all users suspend the use of Multichain services and revoke all contract approvals
401
766
2K
4
18
44
@officer_cia
Officer's Notes
8 months
It seems that @stake exploited for 6000 ETH 👀
Tweet media one
@peckshield
PeckShield Inc.
8 months
Hi @Stake , you may want to take a look:
249
278
1K
27
62
357
@officer_cia
Officer's Notes
2 years
Gn fam 🙌 In six parts of this thread I will tell you exactly how I investigate cypto hacks and secuity incidents, and describe methodolgy ⬇️
14
79
324
@officer_cia
Officer's Notes
2 years
Gm fam 👀 Now you can track all my activities in one place 😎 Check it out:
Tweet media one
65
61
314
@officer_cia
Officer's Notes
6 months
The @KyberNetwork exploiter sent the team another message!
Tweet media one
32
50
303
@officer_cia
Officer's Notes
2 years
I’m often asked if I’m aware of any dataset of DeFi exploits including post mortem analysis twitter threads, blog posts, etc… So I collected such resources in my special note for y’all fam🫡
10
59
293
@officer_cia
Officer's Notes
2 years
Gm fam ❤️ New day, new cool thread! 😎 Today I'll share with you the best @solidity_lang resources, as well as bonus materials such as awesome tools, patterns, & self-study Dev resources 💎 I spent a great deal of time filtering the information and checking it for this thread 👇
12
74
266
@officer_cia
Officer's Notes
6 months
Attempting to conduct an interview with a @KyberNetwork exploiter. What can I possibly ask them? Please post your questions in the comments section below the tweet!
Tweet media one
50
26
267
@officer_cia
Officer's Notes
5 months
Would stay extra vigilant over the holidays… A few people I know were recently attacked & lost their crypto assets, I can't disclose the details publicly but what they had in common was that their seed phrases were generated 3-4 years ago, they were all 12 words. To add, all
17
78
258
@officer_cia
Officer's Notes
2 years
@telegram 1/X Here is a good article themed how to configure your TG, which don't have "out-of-the-box" privacy settings, correctly.
5
68
256
@officer_cia
Officer's Notes
1 year
Looks like a Ronin exploiter is trying to hack the Euler exploiter… Dark Forest, literally 😅
@functi0nZer0
laurence
1 year
If the Ronin exploiter phishes the Euler one with a suspect decryption tool I think I might actually just write a screenplay Alternative, more paranoid theory is that this is being stage managed between them (Please don’t make the joke, it’s tired and stale at this point)
17
7
197
6
47
231
@officer_cia
Officer's Notes
2 years
Gm fam ❤️ Let me start a mega-thread about smart contract-side and user-side attacks in Dapp, Web3, Blockchain, DeFi, NFT and Metaverse 🧐 You'll find the coolest links and tools in this track. Let's go! 👇
10
67
220
@officer_cia
Officer's Notes
5 months
An Open Letter to the Manufacturers and Designers of Crypto Wallets (both cold and hot). There have been far too many attacks lately. Many users are losing money due to what appear to be straightforward attacks. In light of this, I have made the decision to publish an open
15
56
223
@officer_cia
Officer's Notes
3 months
Looks like @FixedFloat just got exploited for 1700 ETH! Drainer address: 0x85c4fF99bF0eCb24e02921b0D4b5d336523Fa085 Info by: @reprove
Tweet media one
30
68
223
@officer_cia
Officer's Notes
12 days
Here's the victim of the 1157 wBTC address poisoning scam, issuing an on-chain message to hackers to return 90% of stolen assets! and promising to keep 10% as a bounty! (Image by @somaxbt ) I think the best hacker can do now is to keep his 10%. That would be wise IMO.
Tweet media one
@officer_cia
Officer's Notes
13 days
$68M (1155WBTC) lost after victim fell for address poisoning attack. TL;DR on attack: Attacker is sending spam transactions to your address in order to catch you being inattentive. You can copy their address instead of your own from the TX history. Attackers generate addresses
24
45
183
18
43
226
@officer_cia
Officer's Notes
6 months
The @KyberNetwork Hack: In-Depth analysis by @BlockSecTeam & @0xdoug & @MetaSec_xyz ⬇️ TL;DR: It was exploited due to the flawed price calculation in 'computeSwapStep'. It produced a bigger price than the target price, but the tick was not crossed and liquidity on the next tick
Tweet media one
Tweet media two
Tweet media three
6
55
198
@officer_cia
Officer's Notes
2 years
Much much thanks to every single one of you for support on @gitcoin ❤️ Follow my works progress here: Grant: DeFi Developer RoadMap: Crypto Research Base: Crypto OpSec SelfGuard:
Tweet media one
9
45
188
@officer_cia
Officer's Notes
2 years
A solution concept for #KYC without knowing your customer, leveraging self-sovereign identity and zero-knowledge proofs - Good Read! 👀 👉 This approach breaks the traditional privacy vs. transparency trade-off and provides structured transparency 🤯
Tweet media one
6
38
187
@officer_cia
Officer's Notes
11 months
Dear followers, I don't often ask for help, but in this situation, if you want me to create more content, please help me in any way that works for you… I would appreciate it if you could donate to me at the following addresses: 0xB25C5E8fA1E53eEb9bE3421C59F6A66B786ED77A —
7
19
185
@officer_cia
Officer's Notes
1 year
Vulnerabilities, attack vectors, and Web3 hacks - gathered for you in a single note!
4
26
181
@officer_cia
Officer's Notes
2 years
Chrome allows websites to write to the clipboard without the user’s permission! Src: It opens a possibility to preform a modified clipper attack! But this is way more complicated, I am surprised how attack vector on a clipboard has changed over time…
Tweet media one
14
54
177
@officer_cia
Officer's Notes
1 year
Dear followers, If I do not respond to you in DMs here or in TG, it does not mean that I am showing off or don’t like you; rather, it is because I am depressed (again) and really unable to do anything…
39
2
175
@officer_cia
Officer's Notes
13 days
$68M (1155WBTC) lost after victim fell for address poisoning attack. TL;DR on attack: Attacker is sending spam transactions to your address in order to catch you being inattentive. You can copy their address instead of your own from the TX history. Attackers generate addresses
@CyversAlerts
🚨 Cyvers Alerts 🚨
13 days
🚨ALERT🚨Are we mistaken, or has someone truly lost $68M worth of $WBTC? Our system has detected another address falling victim to address poisoning, losing 1155 $WBTC. 😢 Victim: Address poisoner: Poison transaction:
Tweet media one
231
253
910
24
45
183
@officer_cia
Officer's Notes
11 months
Please follow my blog so we don't lose touch! There are about 100 articles already!
10
77
125
@officer_cia
Officer's Notes
2 years
How to prepare the computer for work with crypto to the maximum to be sure that nothing will ever be pulled out of there? A big thread ⬇️
5
35
155
@officer_cia
Officer's Notes
1 year
PSA: Update your iPhone immediately! (image from )
Tweet media one
10
56
159
@officer_cia
Officer's Notes
2 years
Gn 😊 I've made this collection so you can use it as your handbook: you'll find in it a huge number of proven Solidity cheatsheets, tools, articles, resources, tools and an awesome bonus 👀 I'd be happy if you could distribute it!
6
46
157
@officer_cia
Officer's Notes
5 months
Before you all start connecting to any dapps today - from your @Ledger device.❗️ Remember that you should first do a quick check to see if your browser is caching the most recent Ledger update or not. How to check: 1. Clear browser & device cache first; 2. Visit:
6
47
159
@officer_cia
Officer's Notes
2 years
It would seem, what danger can a QR code pose? It turns out that you can even lose your crypto, fiat money and internet logins because of attacks! Let's study these attacks and see how we can defend against them in my new @viamirror article!
5
43
154
@officer_cia
Officer's Notes
6 months
Message from the @KyberNetwork hacker.
Tweet media one
15
17
158
@officer_cia
Officer's Notes
1 year
Euler being attacked! Looks like 8.89M DAI + 8,080 WETH loss...
@BlockSecTeam
BlockSec
1 year
Our system monitored that @eulerfinance is being attacked. Please take action!
19
92
182
10
40
156
@officer_cia
Officer's Notes
11 months
GM! Because of the increasing number of scams targeting people who don't know what MEV/MEV bot and so on are, I compiled a list of tried-and-true resources! FYI:
9
41
147
@officer_cia
Officer's Notes
5 months
Looks like the Orbit bridge is hacked. The first hack in 2024 👀
@KGJRTG
Kgjr (clueless333)
5 months
Looks like orbit bridge is getting drained right now, different fresh wallets for wbtc usdt usdc and dai, test tx's showup on orbit bridge scanner but bigger ones doesnt. Wallets bellow
Tweet media one
68
112
327
26
25
149
@officer_cia
Officer's Notes
1 year
(not mine but still funny lmao)
Tweet media one
4
26
146
@officer_cia
Officer's Notes
4 months
Awesome On-Chain Investigations HandBook 💎 Disclaimer: All information (tools, links, articles, text, images, etc.) is provided for educational purposes only! All information is also based on data from public sources. You are solely responsible for your actions, not the author!
9
37
142
@officer_cia
Officer's Notes
1 year
Surprisingly, few people know that anyone can effectively defend against sim swapping… And yes, it works both in the US and worldwide on almost all mobile operators! Check out my thread below ⬇️
@haseeb
Haseeb Awan - efani.com
1 year
400 M + Twitter accounts data is on sale, among which the most critical are username, mobile # & email. Hacker was able to provide a sample list of 1000 usernames, and I was able to verify many of them
Tweet media one
124
762
2K
6
38
136
@officer_cia
Officer's Notes
2 years
A clipboard meddling attack on hardware wallets with address verification evasion - Good Read! ❕ 👉 Authors designed and implemented a EthClipper malware, which then successfully tested on Trezor, Ledger, and KeepKey wallets.
Tweet media one
9
38
133
@officer_cia
Officer's Notes
8 months
“It was definitely a private key that was compromised. If you look at the DAI transfer transaction, there was “uint was = allowed uint (-1)” which could have only been possible if the private key was compromised” - analysis by @0xArhat 🫡
Tweet media one
@officer_cia
Officer's Notes
8 months
It seems that @stake exploited for 6000 ETH 👀
Tweet media one
27
62
357
9
22
136
@officer_cia
Officer's Notes
2 years
Gm 🙌 Spotted an awesome basic introduction to #web3 and its concepts, using the #javascript you already know 🧐 👉 Check out my #DeFi & #Web3 Developer Roadmap as well: I guess I know how the Author got an inspiration 👀
Tweet media one
8
41
130
@officer_cia
Officer's Notes
3 years
Yield Aggregators in #DeFi - Good Read! 🌾 Authors compare four yield aggregrators - @idlefinance , @picklefinance , @harvest_finance and @iearnfinance More info:
Tweet media one
Tweet media two
Tweet media three
Tweet media four
3
35
130
@officer_cia
Officer's Notes
2 years
Many of us travel by airplane and many of us have to deal with carrying luggage. That's a pretty serious threat to your #OpSec unless of course your computer or phone has potentially valuable information on it. Read my thread ⬇️
4
22
134
@officer_cia
Officer's Notes
1 year
A third variation of the "address poisoning" attack has been spotted! In short, you receive tokens which price is displayed in your UI. You then try to exchange them, but the transaction fails, and the gas goes to the scammer’s wallet. A thread 👇
8
44
129
@officer_cia
Officer's Notes
11 months
@telegram Thank you for adding the folder feature! True gold
1
1
129
@officer_cia
Officer's Notes
1 month
Unverified messages: An online video showing a 1-click Telegram attack utilizing a calculator load as an example has been found (it is stated that it may be any malware, Windows-specific). I strongly advise you to disable the auto-downloading function (disable both wi-fi and
17
41
135
@officer_cia
Officer's Notes
8 months
How to protect your X/Twitter account against sim-swapping? A thread. First, you can make a Google Fi account and turn on Advanced Protection: We discussed this in more detail in the chat here, check it out (up/down): 1/6
5
43
123
@officer_cia
Officer's Notes
1 year
GM! Going private for a few hours... I'd like to ask you something... How many of you have actually seen my articles, GitHub collections, and investigations? Thank you ❤️
32
1
131
@officer_cia
Officer's Notes
4 months
This video is from last year, but I never tyre of rewatching it again and again! It's extremely informative… A police officer can be seen "working" behind the suspect's computer in this body-cam footage. Then he pulls out a USB memory stick and wipes everything out as the data
7
28
126
@officer_cia
Officer's Notes
6 months
Can you see my tweet?
30
1
128
@officer_cia
Officer's Notes
2 years
Gm fam! 👀 Here's a tool that converts PDFs to pixels, then back to a PDF. Necessary if you open a lot of random PDFs that could be infected 😎
5
28
122
@officer_cia
Officer's Notes
6 months
On November 23, 2023, the decentralized trading platform @KyberNetwork was attacked, resulting in the attacker stealing approximately $54.7 million… Here is a PoC by @paco0x ⬇️
4
20
120
@officer_cia
Officer's Notes
1 year
In today's article, I'd want to draw your attention to some of my most time-consuming articles (there are 45+ already!), which I feel to be my best! Enjoy!
8
28
115
@officer_cia
Officer's Notes
2 years
Surprisingly few people know that anyone can effectively defend against sim swapping. It works both in the US and worldwide in almost all mobile operators! But how? Check out my thread 👇
5
24
119
@officer_cia
Officer's Notes
2 years
Probably everyone has heard about the BNB chain hacked and then stopped? I've compiled everything for you step-by-step in the thread that you'll find below, for convenience here's its most recent version at the moment in a readable format:
8
32
110
@officer_cia
Officer's Notes
2 years
I can't believe there are already 25,000 of you! 🎇🎆 We've been through a lot together, but there's more yet to come! Thank you for everything dear community, without you I wouldn't have believed in myself! Without you, none of this would have been possible! ❤️
14
3
114
@officer_cia
Officer's Notes
2 months
Memo to those who have lost their funds. 1. Hacker may fail to drain all of your NFTs, stake position, or forget to drain assets from other networks. In these cases, the issue of how to get the remaining money back (un-hacked!) arises urgently. Check out
10
35
117
@officer_cia
Officer's Notes
5 months
ZachXBT has just deleted his X/Twitter account... Come back, we are all (adequate people) waiting for you! Just DMed his 2nd account and waiting for a reply. If he will want it - I’ll share answers.
@Plumferno
Plum
5 months
Welp, good job folks, hope you're happy
Tweet media one
41
12
137
15
8
117
@officer_cia
Officer's Notes
2 years
Gm! It seems @GoGalaGames $GALA token has been infinimint exploited on #BSC and is currently getting TWAP dumped by an attacker! TX (use @bscscan ): 0x4b239b0a92b8375ca293e0fde9386cbe6bbeb2f04bc23e7c80147308b9515c2e
Tweet media one
7
41
107
@officer_cia
Officer's Notes
11 months
Dear followers, I don't often ask for help, but in this situation, if you want me to create more content, please help me in any way that works for you… I would appreciate it if you could donate to me at the following addresses:
6
20
110
@officer_cia
Officer's Notes
7 months
Dear followers, I'm seeking for work. I'll be reviewing my DMs all day; any suggestions are welcome. CV and other information will be provided during private conversations. Thank you!
12
19
111
@officer_cia
Officer's Notes
2 years
In case you didn't know, I'm maintaining a #DeFi Developer roadmap, thanks a lot to the community for your support ❤️ Link: and a special thanks to @LidoGrants & @LidoFinance for helping me get started! You are awesome!
Tweet media one
7
35
113
@officer_cia
Officer's Notes
5 months
Spending time with old friends in beautiful places...
Tweet media one
15
1
110
@officer_cia
Officer's Notes
2 years
If you're looking for sites to revoke your approvals & limit your exposure to attack, here are good sites: > > > > > > 👇More below👇
@dguido
Dan Guido
2 years
Here's the most correct recap of what's happening with OpenSea right now. tl;dr The security of web3 platforms depend entirely on wallets with universally poor security UX, and there's very little the platforms can do about it.
19
113
362
3
35
113
@officer_cia
Officer's Notes
2 years
@moxie To add on topic
5
17
111
@officer_cia
Officer's Notes
2 years
Gm 🙌 I was asked if I know a list of all existing smart contract security tools. So I collected all known SC sec tools based on 4 fresh academic researches 😎 👉 👉 👉 👉
Tweet media one
Tweet media two
Tweet media three
5
33
110
@officer_cia
Officer's Notes
8 months
New Discord attack vector spotted in the wild for the first time! Stay safe! Also check out resources under my post ⬇️
Tweet media one
@fedesarquis
CryptoFede
8 months
This is the hacker. As I do with every DM, I analyze all the info available to see whether this is legit. He had articles from 5 years ago, his message was professional, and it was a discord account since 2018. This was enough to start a conversation, at least.
Tweet media one
1
4
30
8
39
104
@officer_cia
Officer's Notes
1 year
Gm! I'm happy to tell you that I've updated my investigative guide! Check it out on my @viamirror !
12
31
109
@officer_cia
Officer's Notes
2 months
Dear followers, I've made the decision to temporarily go private in order to address the shadowbans applied to my account, which are impacting the distribution of content. I'm hoping that by doing this, I can interact with my fans more often. Stay safe!
7
3
107
@officer_cia
Officer's Notes
7 months
Seems like Galaxy has been hacked, FYI! Hacker’s address: 0x4103babcfa68e97b4a29fa0b3c94d66afcf6163d/history
Tweet media one
7
25
98
@officer_cia
Officer's Notes
1 year
The most unusual #OSINT guide you've ever seen. The repository is intended for bored professionals only. PRs are welcome! 🫡
2
32
104
@officer_cia
Officer's Notes
8 months
Oh wow a @ensdomains data leak!
Tweet media one
@AlvieriD
Dominic Alvieri
8 months
Ethereum Name Service allegedly breached and data dumped by SiegedSec. @ensdomains #ethereum
Tweet media one
5
18
65
16
17
94
@officer_cia
Officer's Notes
6 months
In this article, we will explore the powerful capabilities of HackedWalletRecovery - an awesome tool developed by @austingriffith & @buidlguidl teams! I'll also provide some additional safety advice.
7
33
101
@officer_cia
Officer's Notes
4 months
“If we finally want to give people the opportunity to be their own bank, we must realize that in this case, people must be able to replace all those services and actions for which traditional banks get money”. Check out my updated OpSec guide ⬇️
8
21
103
@officer_cia
Officer's Notes
3 years
Today I would like to collect all good governance and DAO-related researches 🤔 Check the thread below 👇
Tweet media one
7
32
101
@officer_cia
Officer's Notes
8 months
Access has been restored. Lost funds: 0x4ef6f0d3f94ff609acef88068b1fc66a1184b3f3; attacker’s profit: 145 000 $ + NFTs Stay safe!
Tweet media one
@bantg
banteg
8 months
vitalik’s twitter compromised, don’t click any links
14
64
225
4
14
99
@officer_cia
Officer's Notes
2 years
Great collection! 🧐 Here are several great repos that I use in #OSINT as well: - - - Check out:
@0xAsm0d3us
Devansh (⚡, 🥷)
2 years
Collections of tools and methods created to aid in OSINT collection #osint #geosint #cybersecurity
Tweet media one
2
181
506
1
39
97