security
Discussion on all things web3 security and auditing
simon pfp

@sa

Microsoft continues to suck... https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer/
0 reply
0 recast
3 reactions

Shaya pfp

@shaya

I don’t know who needs to hear this but Coinbase support, Apple support, or anyone from support is NEVER going to call you out of the blue about an incident. Hackers mostly go after the low-hanging fruit. Don’t get fooled. Share for awareness and stay vigilant.
0 reply
5 recasts
22 reactions

simon pfp

@sa

https://interestingengineering.com/ai-robotics/anthropic-project-glasswing-10000-software-vulnerabilities
0 reply
0 recast
3 reactions

simon pfp

@sa

https://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330
2 replies
1 recast
5 reactions

Darryl Yeo 🛠️ pfp

@darrylyeo

TL;DW – if you use a Visa card as your Express Transit card in Apple Wallet, switch to a different card or disable the Express Transit feature altogether. https://youtu.be/PPJ6NJkmDAo
2 replies
3 recasts
16 reactions

DepressiveHacks pfp

@depressivehacks

Great article from @revokecash (@wiimee) about recovery scams: https://revoke.cash/learn/security/crypto-recovery-scams
0 reply
0 recast
1 reaction

DepressiveHacks pfp

@depressivehacks

Another day, another breach. Last couple have been on SUI, but the rate at which these are coming has to have everyone concerned. https://x.com/i/status/2048384340049215835
1 reply
0 recast
3 reactions

DCG 201 pfp

@dcg201

https://www.bleepingcomputer.com/news/security/trust-wallet-links-85-million-crypto-theft-to-shai-hulud-npm-attack/ @trustwalletapp @officercia $TWT
1 reply
0 recast
3 reactions

DCG 201 pfp

@dcg201

BOOTSTRAP 🥾: SUCCESSFUL DEPENDENCIES 💾: INSTALLED NETWORK 📡 : CONNECTED CONTENT 👨🏾‍💻: █████████████████▒▒▒▒ 89% IMPORTANT & EXCITING #DCG201 ANNOUNCEMENTS LATER TODAY $XMR @tbsocialist @zachxbt @officercia
0 reply
0 recast
2 reactions

Icetoad 🍕 🎩 🐈 pfp

@icetoad.eth

The widespread use of door locks makes it safe for you to not use a door lock lol
1 reply
0 recast
9 reactions

Kamilla pfp

@pianokamilla

Taking care of my cyber security today I suggest you invest time and money to make sure you’re as protected as possible
0 reply
0 recast
8 reactions

DCG 201 pfp

@dcg201

The @ledgerofficial white hat team discovered a flaw in Tangem cards that makes brute force attacks possible by exploiting vulnerabilities in their secure channel implementation leveraging a “tearing” technique. This allows attackers to bypass the card’s security delay mechanism after failed authentication attempts. The vulnerabilities cannot be patched on existing cards because they’re not upgradable. It is important to note that this attack requires physical access to a Tangem card. https://www.ledger.com/blog-brute-force-attack-tangem @officercia
0 reply
1 recast
2 reactions

Josh Ellithorpe pfp

@quest

If you happen to use PureVPN, they have an IPv6 leak. https://anagogistis.com/posts/purevpn-ipv6-leak/
2 replies
0 recast
5 reactions

DCG 201 pfp

@dcg201

On September 2, 2025, the $Bunni V2 protocol suffered a major exploit resulting in the loss of $2.4M on Ethereum and $5.9M on UniChain. The attack targeted flaws in the liquidity accounting mechanisms of BunniHook, specifically exploiting a precision error by performing multiple carefully sized swaps that yielded more tokenOut than intended. https://www.quillaudits.com/blog/hack-analysis/bunni-v2-exploit @uniswap @officercia @zachxbt
0 reply
0 recast
2 reactions

Peter pfp

@silencedogood.eth

When a Valid Critical Goes Nowhere: Lessons from 14 Weeks in ImmuneFi Limbo https://medium.com/@sillencedogood/when-a-valid-critical-goes-nowhere-lessons-from-14-weeks-in-immunefi-limbo-7764039316a2
0 reply
0 recast
1 reaction