0xFoX ⟠ retweeted
It's an increasingly common take that AI hacking means cybersecurity is doomed.
I disagree. I think cybersecurity is naturally defense-favoring once people get their shit together. And anyone who continues to hold cryptocurrency (including me, ~90% of my net worth) is implicitly making that bet.
Here's why I am making that bet.
First, the oversimplified punchy one-line statement:
If AI can prove Navier-Stokes and FLT, then AI can prove the statement "this program is secure" as a mathematical theorem. Even if the program is very complicated.
Now, the nuance:
(See also: vitalik.eth.limo/general/202… )
The word "secure" is hiding all kinds of skeletons in the closet in terms of what it actually means. What does it mean for Signal (the encrypted messenger) to be "secure"?
The most basic definition you might think of is: no one who doesn't hold the recipient's secret key can read the contents of the message.
But:
* Did you remember to include _other_ critical forms of security? Can the adversary forge messages? Can the attacker prevent messages from reaching the recipient? Can they cause your client to crash by sending malformed messages?
* Have you made sure that your model of the adversary includes attackers that interfere with the protocol actively and not just passively? And attackers that interfere by replaying messages to you or the recipient that either of you sent over the wire at any point earlier?
* What if the adversary hacked (or _is_) the Signal server?
* How did you learn which public key belongs to the recipient in the first place? What if that process was tampered with?
* What if your device gets hacked at some point in the past or future - is your message still safe then?
* What if your key leaks because of a bug in your operating system? Or because you got a bugged version of the Signal client? Or what if the database is corrupted?
* Or the libraries, interpreter or compiler of the programming language you wrote it in?
* What if your key leaks because tiny perturbations in perceptible signals generated by the hardware leak mathematical relationships that can extract the key a few hundredths of a bit at a time?
* Are you hiding the *size* of the payload? Does that matter?
* You're definitely not hiding the identity of the sender and the recipient, and the exact time each message was sent (think: not just time-of-day, but also time deltas between one message and the next). Is that not enough to deduce a lot of important facts about what relationships you have, and what *kinds* of conversations you are having?
So ... even definitions can be over a thousand lines of code, and need deep careful thought to figure them out.
Working on making definitions more human-readable is of extreme importance - it's perhaps the only "high-level language" that matters right now.
But even still, even despite all of the above, for security-critical components, the definition is a much smaller attack surface than the implementation. Verifying that the definition is adequate is a much more tractable task than scanning over the code directly - and can become even more tractable with better tooling.
Definitions are also _additive_: if two groups have two different definitions A and B, then, well, you can just prove that the program satisfies both A and B. Code is not additive in this way: if a program is A + B, a bug in A _or_ B can sink the whole thing. Definitions are additive. And if you can't satisfy A and B at the same time, you've isolated the most important philosophical issue for your project to spend its next few weeks grappling with.
Sometimes, definitions are not much smaller than the implementation - UI components might be one example. But for many of the most critical components - message-passing protocols, sandboxes, cryptography like SNARKs and FHE - the asymmetry is real.
Historically, a large class of failures with this approach have come from people only verifying a small portion of their code, that they self-declared to be the security-critical portion, and ignoring the rest - and it turns out that something in the rest of the code is security-critical too.
This was reasonable back when verification was difficult and scarce. The solution today: sorry, you have to verify over literally your entire program, including database, networking, any caching layers, everything. Modern AI can do it.
So it's not about "the good guys find all the vulnerabilities before the bad guys do" - that could maybe work too, after all a finite program only has a finite number of vulns, but it's riskier - it's specifically an asymmetric strategy of making code that is much more resilient in the first place.
This is the kind of direction that Ethereum is going in for the next few years. There is no future for blockchains - especially blockchains with scalability and privacy - without doing this. We need to make software actually secure. And we have already made a lot of progress.
I ve spent years in security and crypto. Im tired of seeing people drained over basic self custody mistakes nobody taught them to avoid.
So Im starting a security series.
First lesson: a browser profile holding your hot wallet should contain only the wallet extension.
🤖 Made with AI
ALT Infographic explaining browser-extension supply-chain attacks against crypto hot wallets. It shows a trusted extension receiving a silent auto-update and remote C2 payload, then hijacking a dApp and draining EVM, Solana or TRON wallets. Recommended setup: a dedicated crypto profile containing only the wallet extension.
● Extensions bought and then weaponized:
· Enable Right Click & Copy: Smart Unlock + OCR
· RapidLens: Google Lens for Screen Search & Images
· QuickLens: Search Screen with Google Lens
· Password Protect PDF
· Allow Copy: Select & Enable Right Click, Edge
● Extensions created by the attacker:
· PixelCheck
· Creative Library: Ad Spy Tool
· Website Traffic Checker: MirrorSphere SEO Stats
· Site Signal: Website Traffic & SEO Checker
· SEO Pulse Pro: Website Traffic & SEO Analyzer
· Private Crypto News Reader
· Blockfolio: Address Monitor
· Crypto Rates & Fiat Converter
· Crypto Alerter: Price Alarms & Volatility Warnings
· DeFi Pulse Tracker
· Crypto Price Badge: Quick Glance
· Multi-Chain Explorer
· LedgerLook: Wallet Checker
· Meta & Facebook Ad Library Spy: Save Ads, Finder, Downloader | FeedX-Ray
●A security tool can reduce one risk while adding supply-chain risk.
On a hot-wallet profile, minimize code, permissions and trust.
Self custody is freedom, but only if you learn the basics.
If this can save one person from a drain, share it.
Sources and complete IOC and extension-ID list:
socket.dev/blog/chrome-edge-…
0xFoX ⟠ retweeted
🚨Every Ledger running the Ethereum app is vulnerable to signature substitution
A malicious dApp with WebHID access could race an APDU during your transaction review and swap the tx being signed while the device still shows the original
Here's what you need to know:
New method, apparently: no more KYC or “source of wealth” checks that drag on for months.
On the Crypto.com exchange, all it takes is to say theres an SMS problem or ignore the issue and blame the users carrier for not receiving the code.
Because with email and an authenticator, it would be much harder to keep people stuck by claiming “the email never arrived” or “your authenticator isnt synchronized”
Nice new method to keep peoples funds effectively hostage when they try to move their liquidity off the EXCHANGE.
At this point, if this keeps happening, people are naturally going to start asking a much more serious question: is the liquidity actually there? @cryptocom @Cryptocom_Exch
0xFoX ⟠ retweeted
Going to bed late is associated with a higher IQ.
Researchers at the London School of Economics analyzed thousands of individuals to map the relationship between circadian rhythms and cognitive ability.
People with higher IQs are significantly more likely to be night owls.
The data breaks it down by sleep schedules:
• Very Dull (IQ < 75): Sleep by 11:41 PM
• Normal (IQ 90–110): Sleep by 12:10 AM
• Very Bright (IQ > 125): Sleep by 1:44 AM (and sleep in past 11:00 AM on weekends)
Why? Evolutionary psychology.
For 99% of human history, night was for sleeping. Artificial light didn't exist. Staying up late chasing complex thoughts, building projects, or solving problems is an "evolutionarily novel preference."
People with higher general intelligence are more equipped to override ancestral instincts, break away from the traditional sun-up-sun-down routine, and adapt to a modern, 24/7 world.
The early bird might get the worm.
But the night owl gets the higher IQ score.
0xFoX ⟠ retweeted
CNC marble processing machine operating 24 hours a day in Italy completed the giant Tyche statue in about 15 days.
0xFoX ⟠ retweeted
Yesterday has a good chance of being referenced by later historians as “the day that the existence of ASI became obvious to those paying attention.”
Solving 4+ Fields-worthy open problems in one go is so far beyond the pale that even the most absurd goal post movers are silent.
Ledger is not affected by the recently published Coldcard Mk3 advisory.
Ledger devices use a certified True Random Number Generator (TRNG) built directly into our Secure Element chip, generating full 256 bits of entropy for every 24-word Secret Recovery Phrase. Please refer to this article for more information: support.ledger.com/article/4…
Coinkite has published a security advisory regarding certain Coldcard Mk3 firmware versions - you can read their notice here: blog.coinkite.com/coldcard-m…
0xFoX ⟠ retweeted
1/ Uniswap's fee switch is on across the board and the question an LP asks next is: where is the best place to LP now?
We measured it: same $10k synthetic position, five pools on Uniswapv3, Pancakeswap and Aerodrome, different ranges, 90 days, 30 days, 14 days.
Results below:
0xFoX ⟠ retweeted
V4 fees are additive.
V3 fees are not.
Volume follows fees.
So the difference is naught.
Tons of FUD and misunderstanding around the v4 fee switch:
"LP fees are getting reduced" - False. Protocol fees are additive, not subtractive. LPs earning 30bp per swap still earn 30bp
"The protocol is taking 25% of LP profits" - Made-up math. On a 30bp pool the protocol fee is 5bp. That's 5/35 = ~14% of total swap fees and 0% of what LPs were already earning
"The cut is too high" - CEXs charge 100–200bp per swap. 5bp on a 30bp tier is 20–40x cheaper, for the deepest distribution in DeFi
And to the fork that talks about Uniswap more than its own product, takes 100% of swap fees, and "compensates" LPs with uneven token inflation set by token votes: lol
People still dont understand that even if “Robinhood Chain” is generating all this volume, it is still an Ethereum Layer 2. I wonder why they chose Ethereum in the first place.
The fact that the main chain earns relatively little right now is completely intentional. It is the same strategy used by AI companies and by Netflix in the early days of password sharing: first you acquire the users, then you raise the prices.
There are way too many newcomers here who still dont understand a damn thing.
This bullshit where my DeFi address gets flagged as “medium risk” by some AML checking website, simply because every time I make a transaction I receive another transaction from a phishing address with the same first and last characters as mine, needs to stop.
What the fuck am I supposed to do about it? I move huge amounts of money through DeFi, so scammers constantly target me with address-poisoning attacks. WHAT am I supposed to do, change my address every two days?
Can someone come up with a proper way to block this shit? @VitalikButerin @LefterisJP @banteg @ethereumJoseph @ethereum @ethcforg .....
0xFoX ⟠ retweeted
Robinhood's Ethereum L2 is one week old and already doing nearly 1/3 of Solana’s spot DEX volume.
The funniest part?
It’s just one of dozens of $ETH L2s.
NEW: @RobinhoodApp's Ethereum L2 records 193,000 daily active addresses and ~$563M in DEX volume in its first week, driven almost entirely by meme coin trading.
0xFoX ⟠ retweeted
Erik Voorhees: A new kind of inequality is coming, and it has nothing to do with money.
"If you really understand how to use agents and models, you become kind of like a demigod."
Erik's prediction:
A stratification of society based on capability, not wealth.
Those far up the AI curve advance faster and faster.
FT @RaoulGMI @ErikVoorhees @RealVision.