Colin Charles
Colin Charles avatar
Colin Charles
@bytebot
Applied AI, open source developer, databases, data, vibe coding (sic.), remote. itinerant businessperson. globalist. Currently building Mitsukeru.
Colin Charles avatar
Pinned
It’s no longer if you’ll get scammed. It’s when. I’m building Mitsukeru, an always-on AI butler that protects against scams, bad contracts, and social engineering. 💸 $1.03T lost to scams in 2024. ⚡ AI is accelerating infiltration. 🛡️ We need proactive defences, not reactive training. Why here? Because this is gra...
Mitsukeru.pdf
drive.google.com
Mitsukeru.pdf
Mitsukeru.ai
docs.google.com
Mitsukeru.ai
Mitsukeru: Technical Roadmap/GTM
docs.google.com
Mitsukeru: Technical Roadmap/GTM
41
108
235
Colin Charles avatar
another one bites the dust 🫡 @alitiknazoglu
We have some difficult news to share: no more orange GIFs. Inflynce is shutting down on April 9th. This wasn't an easy decision, but it's the honest one. We built the first mindshare algorithm on Farcaster. 1.4M+ transactions processed. 7,400+ creators earned $66K+. $40K protocol revenue. Zero funding. After more th
quote image
1
1
6
Colin Charles avatar
absolutely diabolical. explains where we are getting all our scam calls from. 50,000 robocalls, in 50 minutes, via 18,000 phone numbers, which garnered USD$1.2 million in losses to victims.
Man set up devices in Singapore blasting 50,000 scam calls in 50 minutes; victims lost S$1.6 million
channelnewsasia.com
Man set up devices in Singapore blasting 50,000 scam calls in 50 minutes; victims lost S$1.6 million
1
4
Colin Charles avatar
Persian love cake. Working outside while sipping some Persian tea today too. I can’t help but think of our Iranian friends. I hope they’re safe. Today China asked for bitchat to be removed from the AppStore. I love the idea of the AppStore but this is also what centralized control does that is bad. And there’s no s...
Cast image embed
1
7
Colin Charles avatar
Drift protocol update 6 months in the making, and maybe the most interesting bits are: 1. compromise via cloned code repo under the guise of deploying a frontend for their vault 2. TestFlight application, for wallet product (this is probably not a vector - app sandboxing) 3. "For the repository-based vector, one poss...
Drift avatar
Drift
@DriftProtocol
1d
https://t.co/qYBMCup9i6
7
Colin Charles avatar
Curious, what do the base ambassadors really build on base?
Noelle | ACTIV8 | Malaysia Blockchain Week avatar
Noelle | ACTIV8 | Malaysia Blockchain Week
@nonolee97
2d
Work In Progress🔜 在美好的国度@ns 期待与大家在@base Builder Loft相遇 是一个Base Builders 可以放松休息并积极发挥的地方 我们即将展开序幕,太期待了! https://t.co/fdGpWTpOR5
quote image
quote image
quote image
4
2
10
Colin Charles avatar
Someone very wise just told me this amazing quote: "a closed mouth is a closed destiny." I never heard this quote before, and maybe I'd have made some AI image for it on base, but damn, I do like a good quote. Also, very apt for this Saturday - we just had Good Friday, and tomorrow is Easter Sunday. Happiest Holy W...
1
1
16
Colin Charles avatar
Awaken tax was hacked on April 1. If you used it, take note of what will come next. @duca used to be active here, now only on X, but has been silent for a few days. Aviate, Navigate, Communicate - it’s what pilots do. Silence in this case isn’t golden. You know why France has a lot of wrench attacks? Well… imag...
2
13
Colin Charles avatar
I am very excited by Gemma 4. You can even ask it to describe what it sees, i.e. a video tool call. Lowest I have been able to test it on so far? Late 2019 Intel MacBook Pro (16GB RAM/1.5GB Intel UHD Graphics 630 + 4GB AMD Radeon Pro 5500M). It works. 3.8GB stored in Chrome cache. We love transformers.js! And we ...
Cast image embed
1
8
Colin Charles avatar
Drift sends the thieves an Onchain message. lol. The co-founder of drift… is Malaysian. Her very first job? She was writing for my ex-girlfriend’s fashion site ;) Yeah, what a twisted fate of irony.
It's crazy what happened to Drift. $210-270m drained in seconds is truly nuts. "The attack involved unauthorized or misrepresented transaction approvals obtained prior to execution, likely facilitated through durable nonce mechanisms and sophisticated social engineering" "Compromise of multiple multisig signers’ app
Drift avatar
Drift
@DriftProtocol
3d
Critical information of parties related to the exploit have been identified. Drift is now sending an on-chain message from 0x0934faC45f2883dd5906d09aCfFdb5D18aAdC105 to the ETH Wallets that holds the stolen funds. Wallet 1: 0xAa843eD65C1f061F111B5289169731351c5e57C1 (Timestamp
1
3
Colin Charles avatar
This post from Base. Base killed the browser officially and now it’s just built in. But the ui overlaps… gosh. What are they doing to this app? Rapidly iterating I get, but communicate and work with the users. Also who in their right mind will create a tradable coin and pay for it? Pay to post is quite ridiculous
Cast image embed
7
Colin Charles avatar
It's crazy what happened to Drift. $210-270m drained in seconds is truly nuts. "The attack involved unauthorized or misrepresented transaction approvals obtained prior to execution, likely facilitated through durable nonce mechanisms and sophisticated social engineering" "Compromise of multiple multisig signers’ app...
Drift avatar
Drift
@DriftProtocol
4d
Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Drift’s Security Council administrative powers. This was a highly sophisticated operation that appears to have involved
2
8
Colin Charles avatar
Most supply chain attacks now come to basically be ways to give you some kind of crypto stealer. The motivations are clear, but you can see the costs associated and an added reason why people dislike crypto
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack | Google Cloud Blog
cloud.google.com
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack | Google Cloud Blog
Mitsukeru LERG protects (on Windows and macOS) against this particular supply chain attack. But you're probably not running it yet... so... if you want to check if you're affected on Linux or macOS: find ~ -name "package.json" -not -path "*/node_modules/*" -exec grep -l '"axios"' {} \; | while read f; do echo "=== $
6
Colin Charles avatar
Mitsukeru LERG protects (on Windows and macOS) against this particular supply chain attack. But you're probably not running it yet... so... if you want to check if you're affected on Linux or macOS: find ~ -name "package.json" -not -path "*/node_modules/*" -exec grep -l '"axios"' {} \; | while read f; do echo "=== $...
Feross avatar
Feross
@feross
6d
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios
5
9
Colin Charles avatar
Top of the morning folk! Mitsukeru LERG update. What Apple is doing is *great*. We've been doing similarly too on macOS and Windows. And a quick update on Windows - we actually now use WinUI 3, after a bit of experimentation - and it looks so much better than Windows Presentation Foundation (WPF). WinUI 3 is the li...
Cast image embedCast image embed
Ferdous Saljooki avatar
Ferdous Saljooki
@malwarezoo
10d
In macOS Tahoe 26.4 Apple added a new security feature to Terminal that warns users of potentially malicious pastes with a "Possible malware, Paste blocked" prompt. Here how it actually works 🧵 https://t.co/8ts5tt93jW
quote image
3
8