Web3 Security
All things security focused - breaking news, exploitation breakdowns, and tips for staying safe while going full degen.
Colin Charles pfp

@bytebot

Is self-custody the only way? How many wallets of people you know have been drained by malware? For some reason, threat actors always find a way. 7.4 BTC stolen. ZachXBT managed to freeze ~15k on a centralised service. Again, I am questioning our ultimate freedoms, much like Udi is. the story: https://x.com/Bitcoin4Jimmy/status/1950617736373006823 Udi: https://x.com/udiwertheimer/status/1950744316462170491?s=46&t=iLSaYO2O7t6yPdmEXeqMdA
3 replies
0 recast
4 reactions

Colin Charles pfp

@bytebot

Farcaster fam, I have finally regained access to my X account. It has been a harrowing few days (imagine waking up ~7am on a Sunday morning to see your X account is gone). There are 2 people that likely helped move things along - an engineer at X (former GSoC student - I was once a program admin+mentor too for many years at MySQL and MariaDB), and a public policy person. They helped get those tickets moving. I revoked access to all apps - this believe app thing - happened while I was asleep. And there shouldn't be anything weird about the Twitter for iPhone access (one is via 5G, the other is via home WiFi. Believe stands out like a sore thumb there. How did this likely happen? You can ask for 2FA reset - https://help.x.com/en/forms/account-access/regain-access/2fa-problem And as long as you know an email address AND/OR a phone number - you can also get a password reset. If this information is public (e.g. in WHOIS records), you're hosed! Hacker did not use Grok. Looks like it was just to launch coin
3 replies
0 recast
4 reactions

Ryan J. Shaw pfp

@rjs

Confused Deputy strikes again! “Zoom” is the name of the app but also the name of the participant. The user sees the dialog and thinks it’s the system asking if the app can access the screen. But it’s actually the app asking if the participant can access the screen. https://blog.trailofbits.com/2025/04/17/mitigating-elusive-comet-zoom-remote-control-attacks/
0 reply
0 recast
7 reactions

Officer’s Notes pfp

@officercia

- I was thinking to get apple watch & make a shortcut when I say for example 'macaroni' for it to send a message to all my close people, etc to know im under attack… Do you guys know anything similiar to this I can buy or I have to make something of my own? - Of course! Different variations of "panic button", “canary letter”, “deadman’s switch” and "logic gates" are put into practice and you can do exactly the same things yourself. Check out the screenshots, and also the articles I'll drop below (Apple automation as example). Alternatively, Android + Tasker + miBand!
1 reply
1 recast
1 reaction

Officer’s Notes pfp

@officercia

Safeguard Your OpSec with These Vital Tips https://officercia.mirror.xyz/S2ZQ6kkRVUfZzJx9Pv72ZWvVf5EaZPjr2yjiHbRDaZk
0 reply
1 recast
11 reactions

WiiMee.eth pfp

@wiimee

Time to dust off this account.
1 reply
0 recast
3 reactions

hartej 🇺🇦 pfp

@hartej

Solodit has merged our pull request, making over 1,200 of Zokyo's detailed findings from 92+ audits available to you How to Access: - Visit Solodit (The Home to Web3 Security) - Select "Zokyo" from the Source dropdown - Click 'Search' and start learning
0 reply
0 recast
2 reactions

Reeeny pfp

@reeeny

It always comes down to allowing no one access to your seed phrase....in whatever form. https://x.com/the_smart_ape/status/1833437549643370795?t=Owbt0csSxsyf8TWeuzajcA&s=19
0 reply
0 recast
0 reaction

hartej 🇺🇦 pfp

@hartej

why penetration testing is essential for mobile and browser extension crypto wallets and what the process involves https://zokyo.io/blog/unlocking-security-the-power-of-penetration-testing/
0 reply
0 recast
0 reaction

WiiMee.eth pfp

@wiimee

This got 9! votes on my Twitter with almost 9k following. I need farcaster to crush that. Would you rather watch an educational video with a Loom style facecam than a faceless one? ✅ Yes ❌ No ✍🏻 Doesn't matter if good
1 reply
0 recast
0 reaction

willywonka ⌐◨-◨ pfp

@willywonka.eth

Email this morning that CoinGecko data for 2M users was leaked 😔
5 replies
0 recast
0 reaction

Osker pfp

@skerskerr.eth

Self-custody and security remain the highest priorities for @privy! Feel free to give this piece @henri wrote a read 🤝
0 reply
0 recast
3 reactions

Preston pfp

@ptonewreckin

Have identified several teams using Helius that have failed to protect their API keys. Takes 30 seconds 🫡 https://t.co/zYpYTB7WCq
0 reply
0 recast
3 reactions

maxgrok pfp

@maxgrok

If anyone needs solidity security researchers to perform an audit, got some rare availability. Dm me and mention farcaster for a good deal!
0 reply
0 recast
1 reaction

Officer’s Notes pfp

@officercia

Weekend reading: Top 30 articles officercia.mirror.xyz
2 replies
1 recast
7 reactions