Joined October 2022
247 Photos and videos
有没有大佬可以教教我怎么挖链上合约的漏洞啊,挖到一个确定的肯定的无容置疑的不可否认的会被接受的漏洞真的太难了…
20
43
16,984
Jun 14
经过一段时间的摸索与实践,我发现了适合我早睡早起的方法 那就是十点以后就尽量不要再工作了 当然,工不工,这可能是身不由己的事情 但是,我的朋友,如果你可以选择的话,不妨尝试一下 把结束工作的时间尽量提前,然后出去公园走走,人多的地方待一会。取代掉晚上完成工作后(或者实在干不动了)报复性玩手机直至深夜久久不想入睡的习惯 留点时间给自己做一些低强度的活动(强度一高就升皮质醇了就睡不着了),活动活动,转换一下心情和状态。 相信你也可以在12点前感觉到微微的无聊和强烈的困意,该上床睡觉了。 「写于凌晨1:30 ,刚结束工作」
13
983
Jun 13
In addition to high-end chips, they’ve now begun imposing a blockade on advanced AI models from other countries. Man, what can I say? We can only hope that domestic models catch up as soon as possible, so we won’t have to live at the mercy of others.
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Claude models is not affected. We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible. Read our full statement: anthropic.com/news/fable-myt…
1
570
Jun 12
NiceNiceNice 🤗 cant wait to try it!
🌘 Kimi-K2.7-Code, our latest coding model, is now released and open-sourced! 🔷 Improved coding & agent performance over K2.6: 21.8% on Kimi Code Bench v2, 11.0% on Program Bench, and 31.5% on MLS Bench Lite. 🔷 Reasoning efficiency: Less overthinking, with 30% lower reasoning-token usage compared to K2.6. 🔷 Long-horizon coding: Improved instruction following, higher end-to-end coding task success rates. ⚡️ 6x High-Speed Mode coming soon! 🔌 Available today via Kimi API and Kimi Code. 🔗 Kimi Code: kimi.com/code 🔗 API: platform.moonshot.ai
1
1
567
Jun 12
Thats cool😎
Jun 11
Been wanting this to exist for a while, so I built it. ProofOfRep, a reputation board for bug bounty programs and contests. Report your unfair or dishonest experiences, with proof, and I'll manually review everything. Hope it helps SRs focus on projects that actually take security seriously. Still early. Let me know if this sucks or if it's useful. All feedback welcome. proofofrep.xyz/
482
ACai retweeted
Jun 9
Today, @LlamaRisk proposed a new standardized Risk Framework for assets on Aave V3, V4, and Aave Horizon. As Aave powers new financial applications and expands into new types of markets, best-in-class standards for evaluating asset risk will support that growth.
LlamaRisk has published an ARFC proposing a new standardized Risk Framework that governs all assets on @Aave V3, V4, and Aave Horizon. The framework establishes standards for evaluating asset, bridge, and chain-level risk criteria, and for monitoring and automated risk management systems.
23
108
230
17,568
Jun 8
# Zcash Ironwood 更新 针对这个“无法确认是否在 Orchard 池内发生了增发”的问题,Zcash 项目方给出了一个名为“Ironwood”的更新方案:x.com/zodl_co/status/2063262… 计划在 2026 年 7 月下旬会创建一个名为 Ironwood 的新隐私池,资金可以从现有的 Orchard 往 Ironwood 进行迁移。 和以往的隐私池迁移不一样,这次的迁移增加了一个 turnstile 角色,作为两个池子资金流通的“闸门”,任何人都可以通过它来审查迁移的资金量。 目前 Orchard 将停止接受新的存款和内部交易,Orchard 中的资金只能通过 turnstile 转入 Ironwood 系统。通过这个方法确保确保流通中的 ZEC 数量始终保持在正确范围内。 从主动披露漏洞到提出解决方案🧐Zcash 团队的响应还是挺积极的,团队是真的在做事情。
Jun 6
了解了一下 Zcash 纰漏的漏洞情况: Orchard 的 Halo 2 电路实现存在约束缺失。 攻击场景分析 攻击者可以利用 Halo 2 电路约束缺陷,可以提交一个由虚假 Note 构成的 Action 来通过 Halo2 的验证,得到新的输出 Note。 由于链上只能验证哪些 Nullifier 被使用了,无法验证被使用 Note 的来源,再加上链上的资金流向不可追踪且历史供应量无法全量统计,所以无法确认漏洞是否被利用来增发代币。 为什么 Orchard 的历史供应量无法全量统计? 因为 Orchard 的历史供应量来自一下三个渠道: 1. 透明池转入 [公开]:用户从 t-address 向 z-address 转账 2. 挖矿奖励 [不公开]:矿工可以选择将区块奖励直接发到 z-address 3. 旧池迁移 [不公开]:Sprout → Sapling → Orchard 的池间迁移 所以即使你精确统计了历史上所有透明转入的金额,也只能得到了一个理论下限,无法得到准确的金额。而且,对于增发来说,得到一个下限是没有意义的。
7
1,292
Jun 8
After selling 32 BTC, which sparked heated discussion, MicroStrategy bought back 1550 BTC. 🤨The fact that Saylor publicly announced his purchase plan suggests he still cares about his influence on the crypto market and MicroStrategy.
Strategy has acquired 1,550 BTC for $101 million to increase our $BTC Reserve to ₿845,256. We have also increased our USD Reserve by $100 million to $1.0 billion. $MSTR $STRC strategy.com/press/strategy-…
1
365
Jun 8
🫡
FloorProtocol V2攻击事件分析:伪造 NFT ID 触发双重下溢 hackmd.io/@spdadi/BkyJaZN-Gg
3
938
Jun 8
Yet another cross-chain bridge security incident.🫣
Preliminary Postmortem: Syscoin Bridge Incident We want to provide the community with a preliminary update regarding the recent Syscoin bridge incident involving approximately 5B SYS. The Syscoin bridge is currently paused while the team investigates, finalizes the fix, and works on rectifying the unauthorized SYS output created through the affected bridge path. Summary An attacker exploited a validation issue in the bridge flow that resulted in an unauthorized SYS output being created on the UTXO side. The affected funds were moved and split after reaching the UTXO chain. We are actively tracing those funds and coordinating with exchanges and ecosystem partners to prevent the tainted outputs from being deposited, traded, or further distributed. What happened Based on our current investigation, the incident involved the bridge relay path incorrectly accepting or interpreting a transaction proof. This caused the bridge system to treat the transaction as valid and create an unauthorized SYS output of approximately 5B SYS through the UTXO bridge path. The funds were first sent to: sys1qgaelv690g7wwp2xchfdh0enf5uewzq5sm9wvcw They were then spent and split into additional outputs. The current large tainted balances appear to be associated with: sys1q2k482wnachkgky4lw60973p4vcf7xlh9kzpv33 — approximately 4B SYS sys1qx6jjkq89sdaxftfgre3m0nv7vjfd4jeakg5t38 — approximately 1B SYS Relevant transactions Initial UTXO transaction: explorer-blockbook.syscoin.o… Subsequent spend: explorer-blockbook.syscoin.o… Split transaction: explorer-blockbook.syscoin.o… Actions taken - The bridge has been paused. - We have contacted exchanges and relevant partners and asked them to blacklist, freeze, or closely monitor any SYS deposits connected to the tainted UTXO trail and all descendant spends. - We are continuing to trace the affected funds and coordinate with infrastructure providers and ecosystem partners. Remediation The team has identified the affected validation path and has a fix in place. Our priority now is to complete implementation and review of the fix, while also determining the correct process to rectify the unauthorized SYS output and neutralize its impact on the network. We will provide further updates once the remediation path has been finalized. User Guidance Users should not interact with the bridge while it remains paused. We understand the seriousness of this incident and are treating it as the highest priority. We will continue to share updates as the investigation and remediation progress.
505
Jun 8
来吧来吧,有什么更新快端上来吧 目前看kimi算是国内做生态比较积极的AI厂商了,kimi claw,kimi code,还有 GUI kimi work 等主流的工作模式都安排上了原厂支持。还有🤔下一款模型什么时候发布?
Hello world!
1
449
Jun 7
# Orchard 介绍 Orchard 本质上是一套加密的 UTXO 系统,只不过是把 UTXO 替换为了一种叫 “Note” 的加密凭证。Note 的明文存于本地,链上只存在 Note 对应的密文与凭证。 当用户需要转账时,遍历每个区块,采用观察密钥逐个解密其中的 Note 密文。如果解密成功,则证明这个 Note 属于该用户,可以使用该 Note 构造转账。 通过构造 Action(1-in-1-out 的原子单元)进行转账,和 UTXO 一样,可以一次性捆绑多个 Action 作为一个 Bundle 输入。通过 Halo 2 对 Action 生成零知识证明,向链上证明这个 Action 的合法性。 然后用户采用 RedPallas 签名方案,使用一次性的**随机化签名密钥(Randomized Signing Keys)**对 Bundle 的哈希进行签名,确保 Action 的内容不会被篡改。 Action 在被验证使用后,已消费 Note 的 Nullifier(唯一指纹)被永久记入全局集合防止双花,新 Note 的承诺则被追加到 Note Commitment Tree 中,使其进入可消费状态。
Jun 6
了解了一下 Zcash 纰漏的漏洞情况: Orchard 的 Halo 2 电路实现存在约束缺失。 攻击场景分析 攻击者可以利用 Halo 2 电路约束缺陷,可以提交一个由虚假 Note 构成的 Action 来通过 Halo2 的验证,得到新的输出 Note。 由于链上只能验证哪些 Nullifier 被使用了,无法验证被使用 Note 的来源,再加上链上的资金流向不可追踪且历史供应量无法全量统计,所以无法确认漏洞是否被利用来增发代币。 为什么 Orchard 的历史供应量无法全量统计? 因为 Orchard 的历史供应量来自一下三个渠道: 1. 透明池转入 [公开]:用户从 t-address 向 z-address 转账 2. 挖矿奖励 [不公开]:矿工可以选择将区块奖励直接发到 z-address 3. 旧池迁移 [不公开]:Sprout → Sapling → Orchard 的池间迁移 所以即使你精确统计了历史上所有透明转入的金额,也只能得到了一个理论下限,无法得到准确的金额。而且,对于增发来说,得到一个下限是没有意义的。
2
4
15
2,867
Jun 6
了解了一下 Zcash 纰漏的漏洞情况: Orchard 的 Halo 2 电路实现存在约束缺失。 攻击场景分析 攻击者可以利用 Halo 2 电路约束缺陷,可以提交一个由虚假 Note 构成的 Action 来通过 Halo2 的验证,得到新的输出 Note。 由于链上只能验证哪些 Nullifier 被使用了,无法验证被使用 Note 的来源,再加上链上的资金流向不可追踪且历史供应量无法全量统计,所以无法确认漏洞是否被利用来增发代币。 为什么 Orchard 的历史供应量无法全量统计? 因为 Orchard 的历史供应量来自一下三个渠道: 1. 透明池转入 [公开]:用户从 t-address 向 z-address 转账 2. 挖矿奖励 [不公开]:矿工可以选择将区块奖励直接发到 z-address 3. 旧池迁移 [不公开]:Sprout → Sapling → Orchard 的池间迁移 所以即使你精确统计了历史上所有透明转入的金额,也只能得到了一个理论下限,无法得到准确的金额。而且,对于增发来说,得到一个下限是没有意义的。
1
1
7
6,079
Jun 5
The long-awaited Pashov audit skill v3 has been released.🫡 I've had a preliminary look at the project information preprocessing part (called x-ray) and found that concepts like entry-point and invariant align with my thinking (these concepts are important). I will further explore and learn about the implementation philosophy of this skill.
Jun 4
🤯An AI security tool has 1st-place performance on security contests from just 1yr ago. Solidity-auditor v3 is out, FREE & Open Source. Thousands of Solidity developers are using the tool already. Upgrade your security baseline, use the tool🫡 pashov.com/solidity-auditor-…
1
24
3,638
Jun 3
期待🫡
Jun 3
Replying to @pashov
solidity-auditor v3 is launching tomorrow. ~100 people have already tested it and have been reporting valid vulnerabilities on bug bounty platforms. Use with caution. github.com/pashov/skills
1
389
Jun 2
梳理了一下 @Polymarket 最近关于“Strategy 到底有没有在 5.31前卖出 BTC”的争议情况🫣以及后续走向的分析。 这类在市场规定时间外,且在争议期内发生结果逆转的情况,还需要订一个明确的规则。即使再次发生都依赖投票决议来解决,但是这类争议再次出现时,是否也会导致默契票的产生🤔?
1
1
450
Jun 1
在工作中使用了 AI 以后产生的其中一个问题就是要阅读的文档内容越来越长了,信息密度越来越低了。 在人工手写文档的时候,目的只是把事情表达清楚。人是有惰性的,事情“表达清楚”了,就不会再继续添加内容了。 但是 AI 介入写文档以后就不一样了,猛猛写,都写上。 当文档涉及到分点列举时,可以列出五六七个点,即使最重要最关键的点只有一个或者两个。 同一个流程文字描述一遍,伪代码展示一遍,mermaid 图再画一遍,生成 html 再展示一遍。 很多内容不是说不对,而是“不够重要”,读文档的人“他不关心”。因为人也是有注意力窗口的,甚至 context 大小要远远小于当前的 AI。你文档一股脑的塞下这么多东西,人是很难读得下来的。 所以有时候拿到文档的第一件事是做什么:找 AI 让他帮我总结一下这份文档的内容是什么... 这何尝又不是一种 harness 呢,只不过服务的主体是我这个 context 不足的碳基生物罢了。
2
1
12
1,850