Things which could help against NPM supply chain attacks similar to one which happened today:
- prefer specific pkg versions instead of ranges (2.0.0 not ^2.0.0)
- prefer rare dep updates (once per 3mo or so)
For pkg authors:
- publish from github ci
- do not store npm tokens on a dev machine
- while publishing from...
5
9
54
Releasing ESPLR - a local ETH block explorer.
Big problem of ecosystem is reliance on 3rd party RPCs (infura, alchemy, quicknode). Also reliance on 3rd party explorers (etherscan). They track users: it makes system one big panopticon.
Local nodes can make the situation better!
PC with an archive node only costs $40/...
24
70
272
New vulnerability in elliptic.js allows attackers to extract private keys from signatures.
This happened because fully deterministic signatures are not your friends. Check out my latest blog post describing the bug and prevention methods:
2
8
40
There are challenges in upgrading blockchains to be post-quantum safe, however, some of them seem easy.
Most keys these days are generated from BIP39 mnemonics. Bip39 is pq-safe. We freeze all balances. To unfreeze, we ask users to generate a STARK proof which shows seedphrase is related to their address. After that f...
6
10
67
noble-ciphers got audited, while curves got their third audit. Thanks to OpenSats for funding & Cure53 for the work! PDF in repo.
Contact me if you’re:
- auditor (paid / unpaid) willing to review new open-source goods
- willing to fund auditors
1
2
23
Ethereum $130B staking contract was created using Tornado Cash.
Torn has mostly been used for legit on-chain privacy. An example is the transaction by anon dev, deploying the contract.
The repo rebuilds it using modern tech. Great for ZK education!
0
5
20
New release of JS eth-signer is out. A lot of new features have been added:
- EIP-7702 AA transactions
- EIP-4844 KZG implementation in pure JS
- EIP-712 / EIP-191 message signing
- EIP-7495 SSZ stable container
2
11
44




