ETHSecurity Community
This is the farcaster instantiation of the great and lindy ETHSecurity community which exists on Telegram and elsewhere.
Officer’s Notes pfp

@officercia

Essential Security Tactics to Implement After the Bybit Hack https://paragraph.com/@officercia/essential-security-tactics-to-implement-after-the-bybit-hack
0 reply
0 recast
1 reaction

Officer’s Notes pfp

@officercia

Come listen to me explaining OpSec stuff on Rekt News voice room! https://twitter.com/i/spaces/1YqxolrQqNQKv
0 reply
1 recast
0 reaction

horsefacts pfp

@horsefacts.eth

stay noided https://x.com/_seal_org/status/1999953423672971318
0 reply
4 recasts
28 reactions

Officer’s Notes pfp

@officercia

Come to listen to my voice on Wednesday, December 17th: https://x.com/rekthq/status/1999158122926022661?s=46
0 reply
2 recasts
8 reactions

Officer’s Notes pfp

@officercia

Keystone 3 vs. GridPlus Lattice: Two Hardware Wallets That Actually Make Sense https://paragraph.com/@officercia/keystone-3-vs-gridplus-lattice-two-hardware-wallets-that-actually-make-sense
0 reply
1 recast
2 reactions

horsefacts pfp

@horsefacts.eth

clever clever https://x.com/j222ad/status/1995816859254296636
3 replies
5 recasts
29 reactions

Officer’s Notes pfp

@officercia

Staying Private in Crypto & Web3: Simple, Practical Tips That Actually Work https://paragraph.com/@officercia/staying-private-in-crypto-and-web3-simple-practical-tips-that-actually-work
0 reply
1 recast
3 reactions

horsefacts pfp

@horsefacts.eth

There is another pretty bad Shai Hulud supply chain attack going on today. This time it hit a number of ENS related packages. Check your dependencies and stay safe out there! https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
3 replies
2 recasts
14 reactions

Royal pfp

@royalaid.eth

Final postmortem from Balancer https://x.com/Balancer/status/1990856260988670132
0 reply
0 recast
0 reaction

Officer’s Notes pfp

@officercia

Harnessing OSINT: Empowering Personal Defense and Everyday Decision-Making https://officercia.mirror.xyz/nvXWIhc9XzYH585JKt1J-EsqdZwdZE_P98ht9zkeLUA
0 reply
2 recasts
2 reactions

Officer’s Notes pfp

@officercia

Dear followers, I have a few spots available for OpSec audits and training! In this audit, we will explore secure methods for managing crypto, identify the right tools to use, and understand how to work with delegation software and multisig setups. We will specifically focus on how to mitigate emerging threats and recognize the most common attack vectors. Please DM!
1 reply
0 recast
4 reactions

Officer’s Notes pfp

@officercia

Be careful of a fake Hyperliquid app on the Google Play Store. None of these platforms seem to do a good job of filtering these scams out. Theft address 0x8c12C21C394D9174c3b1a086A97d2C5523ABb8F5
1 reply
2 recasts
11 reactions

Royal pfp

@royalaid.eth

Balancer initial postmortem, boiled down to a rounding issue where the contract rounded in favor of the user and not the protocol. Classic bug on the EVM. Anytime any kind of truncation of decimals happens or you round you HAVE TO be in favor of the protocol because of flash loan style looping contracts that can amplify fractions of pennies into a protocol disrupting draining attack https://x.com/Balancer/status/1986104426667401241?t=w-h1GSu6AfuHnxoqU3TxcQ&s=09
2 replies
1 recast
15 reactions

Julie pfp

@bbjubjub.eth

Inflating severity is one thing LLMs do better than human auditors iykyk
0 reply
0 recast
0 reaction

Officer’s Notes pfp

@officercia

Protecting Yourself from Address Poisoning Attacks https://officercia.mirror.xyz/OfprXWY1n5ixX1UKomyGGGA48RuxZ_59M7vNvanHErc
0 reply
0 recast
2 reactions