Joined July 2014
53 Photos and videos
Paulius retweeted
npm finally fights supply chain attacks with v12 (July 2026) blocking install scripts by default. Here's how to adapt early without breaking your CI 🧵 What's changing: • preinstall/install/postinstall scripts → blocked by default • Git dependencies → blocked by default • Remote URL deps → blocked by default The fix is creating a one-time allowlist per repo: 💻 npm install 💻 npm approve-scripts --all 💻 git commit -m "chore: allowlist install scripts" This snapshots exactly what's trusted today and only new unknown scripts are blocked automatically going forward. CI adaptation playbook: 1. Upgrade to npm 11.16.0 2. Run the approve-scripts commands above 3. Add --strict-allow-scripts to your pipeline Now jobs will fail loudly if anything unreviewed tries to run. Source: github.com/orgs/community/di…
1
4
256
Paulius retweeted
Jun 4
🤯An AI security tool has 1st-place performance on security contests from just 1yr ago. Solidity-auditor v3 is out, FREE & Open Source. Thousands of Solidity developers are using the tool already. Upgrade your security baseline, use the tool🫡 pashov.com/solidity-auditor-…
98
127
492
41,044
rant time: people are so fucking obsessed with building more tools, more products, more services, more "security" layers. are you guys all fucking insane?? every single thing you add is more complexity. and complexity is exactly what makes systems _dangerous_. you don't get safer by stacking abstractions on top of abstractions. you just increase the attack surface and pray the whole dependency chain doesn't collapse (hint: it will collapse!!). now you depend on 10, 50, 100 moving parts. all needing updates, all with their own bugs, all potential supply chain failures and we call that "security" like fucking retards. dude, it's the fucking opposite. we're not building safer systems. we're building systems so complex nobody actually understands them anymore. and almost nobody is asking the obvious question: **what can we remove?** everyone wants to add. nobody wants to reduce. that's how you end up in a nightmare system (hint: we're already in that nightmare). not because of one big failure. but because of thousands of tiny dependencies you never should have had in the first place.
34
28
254
13,132
Paulius retweeted
May 20
software engineering in 2026: - your package manager is compromised - your cloud provider blocks your account - github itself is hacked software is solved
160
1,000
12,144
414,076
Paulius retweeted
Apr 30
april 2026 defi hack calendar
Apr 30
april 2026 was the worst month ever in terms of defi exploits ~$635M lost in total, 28 incidents in 30 days: 1) apr 1 - drift - $285m 2) apr 3 - silo v2 - $392k 3) apr 4 - tmm - $1.67m 4) apr 5 - denaria finance - $165k 5) apr 9 - aethir - $423k 6) apr 12 - hyperbridge - $2.5m 7) apr 12 - subquery - $60k 8) apr 13 - dango - $410k 9) apr 13 - mona - $61k 10) apr 14 - zerion - $100k 11) apr 16 - rhea finance - $18.4m 12) apr 16 - grinex - $15m 13) apr 18 - kelp dao - $293m 14) apr 20 - juicebox v3 - $52k 15) apr 20 - thetanuts finance - $50k 16) apr 21 - volo protocol - $3.5m 17) apr 22 - kipseli - $80k 18) apr 23 - giddy finance - $1.3m 19) apr 25 - purrlend - $1.5m 20) apr 26 - scallop - $150k 21) apr 27 - singularity finance - $413k 22) apr 27 - zetachain - $300k 23) apr 28 - judao - $228k 24) apr 28 - quant - $138k 25) apr 29 - aftermath perps - $1.14m 26) apr 29 - sweat foundation - $3.5m 27) apr 29 - syndicate - $330k 28) apr 30 - wasabi protocol - $5m
8
1
55
6,694
Paulius retweeted
Kelp rsETH exploit is terrible due to extensive DeFi integrations. Not sure how big the exposure is yet but: - Aave V3: Markets already frozen - SparkLend: Also froze the rsETH market - Lido Earn via Mellow strategy meta-vault. I think it was a leveraged market - Fluid: Frozen market - Compound - Euler - Upshift: Paused High Growth ETH and Kelp Gain vaults - Pendle PT YT tokens - Some Beefy strategies. Yearn? I suppose LayerZero is probably affected too, as rsETH were bridged from L2s, so I wonder if those rsETH on L2s aren't worthless right now. The situation is still developing, so I don't want to FUD any protocol, but it seems there are not many places to hide in DeFi.
99
78
749
155,787
Paulius retweeted
SEAL is coordinating an active investigation into the ongoing incident involving Kelp DAO along with all relevant stakeholders. If you have information to share or are able to assist in freezing/recovering funds, please reach out at t.me/seal_911_bot
8
22
124
22,135
Paulius retweeted
KelpDAO's rsETH bridge seems to have been exploited for ~$292M. Hacker borrows WETH against stolen rsETH on Aave. Here's what we know.
16
12
80
15,096
Paulius retweeted
Link to site: soliditylang.org/survey-2025… Some highlights: - Stack-too-deep is the number 1 pain point - The majority use AI and 45% don't trust the output - Foundry sees continued market gain as dev framework - 70% have not heard of Core Solidity
1
2
9
738
Paulius retweeted
🆕 Contract Tab Revamp Navigating contract source code used to mean a lot of scrolling. Now you've got a full IDE-style code browser, plus refreshed read/write tabs Here's what's new ⤵️
17
38
243
19,092
Paulius retweeted
21 crypto projects are shutting down if you have assets on any of these, move them out 1. Fantasy top (@fantasy_top_) → Core mode sunset ~mid-June 2. Magic Eden ME Wallet (@MagicEden) → x.com/MagicEden/status/20390… 3. Leap Wallet (@leap_wallet) → x.com/leap_wallet/status/203… 4. Dmail (@Dmailofficial) → x.com/Dmailofficial/status/2… 5. Intergaze (@intergaze_xyz) → x.com/intergaze_xyz/status/2… 6. Yupp ai → (@yupp_ai) x.com/pankaj/status/20390100… 7. Tally (@tallyxyz) → x.com/tallyxyz/status/203391… 8. Fey Protocol (@feyprotocol) → x.com/feyprotocol/status/203… 9. Angle Protocol (@AngleProtocol) → x.com/AngleProtocol/status/2… 10. DataHaven_xyz (@DataHaven_xyz) → x.com/DataHaven_xyz/status/2… 11. Step Finance (@StepFinance_) → x.com/StepFinance/status/202… 12. Parsec Finance (@parsec_finance) → x.com/parsec_finance/status/… 13. ZeroLend (@zerolendxyz) → x.com/zerolendxyz/status/202… 14. PolynomialFi (@PolynomialFi) → x.com/PolynomialFi/status/20… 15. Nifty Gateway → x.com/niftygateway/status/20… 16. SlingshotCrypto (@SlingshotCrypto) → x.com/SlingshotCrypto/status… 17. Runiverse Game (@RuniverseGame) → x.com/RuniverseGame/status/2… 18. Soundxyz (@soundxyz_) → x.com/soundxyz_/status/20013… 19. MilkyWay (@milky_way_zone) → x.com/milky_way_zone/status/… 20. Pixiland Social (@pixilandsocial) → x.com/pixilandsocial/status/… 21. Blocto App (@BloctoApp) → x.com/BloctoApp/status/19993… x.com/0xvietnguyen/status/20…

Leap Wallet: Sunset Notice After careful consideration, we've made the decision to sunset Leap Wallet and its associated products. The products will be sunset on 28th May, 2026, and all users should complete their migration before then. We started Leap in 2022 to redefine what wallet experiences in crypto mean. Over time, that journey expanded across multiple ecosystems and 100 chains. Through every phase, the team approached the work with conviction, care, and a deep sense of responsibility to the users and communities we served. This decision was not made lightly. We continue to believe in the long-term future of crypto and the interchain ecosystem, and we remain supporters of the builders still in the arena. What's being sunset The following products will be sunset after 28th May, 2026: • Leap Wallet (Extension, iOS, Android) • Compass Wallet (Extension, iOS, Android) • Leap WebApp • Swapfast • Leap Cosmos Hub Validator • Leap Cosmos Snaps Until that date, all wallet products listed above will retain their existing core functionality. You will still be able to view balances, send tokens, manage staking positions, and export your recovery phrase and private keys. All other products listed above will likewise retain their existing functionality until 28th May, 2026. What users need to do If you are using one of Leap’s wallet products, we recommend migrating your wallets to another wallet like Keplr, MetaMask, Phantom, or Rabby. Because Leap is a non-custodial wallet, your assets live on the blockchain, not in our apps. As long as you have your recovery phrase, you can continue to access your assets through another compatible wallet by importing that recovery phrase. Your addresses and balances will carry over automatically. If you have ATOM delegated to Leap’s Cosmos Hub validator, please redelegate to another validator to continue earning staking rewards. We encourage doing this as early as possible to account for network unbonding periods. Detailed migration guide and FAQs can be found on the website - leapwallet.io What to expect next After 28th May, 2026, all Leap products will be sunset and will no longer function, including applications already installed in your browser or on your mobile device. Even if you do not migrate from Leap to another wallet before that date, you can still recover access to your assets by importing your recovery phrase into another supported wallet Migration support will be available through our official support channels until 28th May, 2026 at support@leapwallet.io Thank You Thank you to all our users, for letting us serve you through so many market cycles. Thank you to our amazing partners, for helping us build experiences & worlds we never thought possible. Thank you for Leaping with us. 🐸 💚
264
287
1,465
517,420
Paulius retweeted
Mar 31
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
541
4,026
16,169
12,403,856
Paulius retweeted
The @battlechain testnet is now LIVE. Come enter the ultimate red-team platform. Give us feedback so we can launch mainnet very soon, and fix web3 security.
51
80
568
69,076
Web3 companies are posting jobs on jobs.ashbyhq.com Here is how to find them 1. Google "site:jobs.ashbyhq.com defi" 2. Filter by date (last month) Replace "defi" with other keywords Positions I found gist.github.com/t4sk/faed549… Good luck
10
20
301
18,752
Paulius retweeted
Source Code Intelligence is now live in EVM Chronicle. Variables are now inline-clickable in source view, so you can inspect live storage instantly. Functions are now simulatable directly from code, with inputs and execution traces in one flow. From source → state → execution, without leaving the page.
4
6
393
Paulius retweeted
Keeping up with Web3 hacks is chaotic You need to monitor: - @CertiKAlert - @SlowMist_Team - @realScamSniffer - @CyversAlerts - @Phalcon_xyz - @HypernativeLabs - @guardrailai - @blockthreat - @RektHQ - dozens of security researchers on X Everything is scattered. So we built QuillMonitor. An AI agent that tracks security alerts across the ecosystem and pushes real-time hack alerts into one feed. Each alert includes: • exploit summary • impacted contracts • mitigation notes • links to the original researchers / alert sources All discoveries are credited to the original researchers. QuillMonitor simply aggregates signals into one place. 🚨 t.me/QuillMonitor / @ QuillMonitor
3
4
41
3,939
A few words about my condition, my health, and how my treatment is going. The initial diagnosis of a brain tumor was not confirmed (although benign cysts were found), but I am continuing treatment for POTS, asthma, lymphadenitis, tachycardia attacks, and hypertension. I have already spent almost $50,000 on treatment, which is almost all of my savings. I am also waiting for another MRI to double-check my brains. I would like to share my story, hoping to find people with similar symptoms and learn a little more about treatment so I can ask my doctor about it. I'll start with the fact that on June 24, 2024, I suddenly started to suffocate (air hunger) and feel oxygen deprivation. It was terrible. I thought I was going to die. My palms were cold, my heart was racing (up to 160 bpm), and my stomach hurt. I managed to call an ambulance, and when they arrived, they did an ECG and measured my oxygen saturation. They said that I apparently had vegetative-vascular dystonia and a panic attack. They recommended that I take glycine. They also took me to the hospital, where I had a CT scan of my lungs, and then they sent me home. After that, I went to see a neurologist, who diagnosed me with somatoform disorder. Then I developed a terrible feeling of anxiety that still haunts me to this day. I developed restless legs syndrome, I am very afraid for the future, and I am very afraid that I will suffocate again. Anyway... I went to other private doctors, a cardiologist, a pulmonologist, an endocrinologist... They found asthma, gastritis, and some other problems that, in theory, couldn't cause such symptoms. I spent a huge amount of money on all the doctors and had a CT scan of my lungs, an ultrasound of my heart and neck vessels, and a huge number of tests... It's just awful... I should mention that I'm only 27 years old and was 26 when these symptoms started. Since I had recently had COVID-19, I thought I might have a blood clot or POTS... So I had an X-ray and other tests done. Cardiologist tested me and determined that my resting heart rate was 65-70, but when I stand up, it reaches 110-120. So, I was diagnosed with POTS. However, as treatment, they prescribed cytoflavin and meldonium which has no scientific evidence of its effectiveness. I think my doctor doesn't really believe in this diagnosis, so he sent me to a psychiatrist when he heard from me that I was afraid of forgetting how to breathe and similar things. I went to the psychiatrist and he prescribed me escitalopram and diagnosed me with depression and CPTSD. He also advised me to do EMDR, which I have just started. On June 23, 2024, I was a perfectly healthy 26-year-old guy, but by June 25, I felt like I had lost almost all of my health. It was just awful. I want to do a few more tests to find out for sure whether there are any blood clots in my lungs (although the CT scan showed that there aren't any) using rarer diagnostic methods such as lung scintigraphy through inhalation of radioactive gas. But anyway, time is passing... And the anxiety remains. If you have acquaintances who have experienced similar symptoms, or if you yourself have encountered them, please DM me... perhaps I am overlooking something. Also, if you would like to help me with a donation, I would be very grateful and will return all the money once I finally overcome my illness, whatever it may be. I hope to return to my work schedule, write articles, and do more scientific work.
Dear friends, for the past few days I have been suffering from health issues. Please pray for me - it doesn't matter what religion you follow. I hope that I will be able to recover and continue blogging as before. I have a lot of projects planned and I really want to make them happen...
53
31
253
49,793
Paulius retweeted
We are seeing a new BIG wave of Telegram accounts takeovers (thousands hacked daily). We are highly suspicious but can not prove it yet, that this is happening because SMS with auth codes sent by Twilio are being intercepted by multiple threat actors at the Tiers level (as we discovered in march 2025). - In the meanwhile, the way to protect from this is very simple: Settings > Privacy and Security > Two-Step verification: turn it on, write it down and configure a secure email. - If your Telegram account is hacked, you are NOT gonna get it back and also all your contacts and conversations are gone forever (unless you are a high-profile). Stay safe
6
12
43
5,032
Paulius retweeted
Mar 4
🚨Ethereum Developers: you can now install your first AI Auditor in 1 minute - fully autonomous, available 24/7, with multiple sub-agent helpers. Open Source. FREE to use (with your AI model) and already finding vulnerabilities in smart contracts. Link below🫡
177
256
1,434
187,104