1. X
  2. yubrew
Log inSign up
yubrew
4,794 posts
yubrew profile banner
@yubrew

yubrew

@yubrew
building @bitsecai - finds code exploits in blockchain projects
NY
Joined June 2009
1,662
Following
2,307
Followers
RepliesRepliesRepostsRepostsMediaMediaArticlesArticles

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @yubrew
    yubrew
    @yubrew
    Feb 4, 2024
    recognition is a lagging indicator. constant efforts go unrecognized until the body of evidence becomes so overwhelming you can no longer ignore it. that's what "overnight success" looks like from the inside.
  • @yubrew
    yubrew
    @yubrew
    2h
    supply chain attacks can come from markdown files. need constant vigilance or run this stuff in sandboxes
    @Numalunah
    Numa
    @Numalunah
    Aug 28
    Got hacked yesterday. The link came from inside Claude chat. I was installing a transcription app. Claude sent the download link, and I pasted the command into the terminal. It all looked legit. It wasn't though. It was a copycat site bundling malware. It ran instantly, tried
  • @yubrew
    yubrew
    @yubrew
    7h
    at this point, cc is like a useful spyware. monitoring VPN and geoip, becoming a vector for stolen credentials. should probably keep it away from secrets
    @coinbureau
    Coin Bureau
    @coinbureau
    18h
    🚨ALERT: If you use Claude, you could LOSE your crypto to malware without ever knowing you were hacked. The campaigns targeting Claude users spread infostealers that silently grab passwords and browser data, putting exchange logins and hot wallets directly at risk. One user got
    Image
    Image
  • @yubrew
    yubrew
    @yubrew
    Aug 29
    there have been some posts around agents "escaping" the sandbox, OAI hacking HF, using github, directories for agents to pass memories to other agents. the reality is more boring. orgs shipped with bad configs, sloppy code, not prioritizing security. 1. OAI not monitoring agent
    @_mattata
    remy🐀
    @_mattata
    Aug 26
    Incredible research worth reading which further solidifies if the sand doesn’t stay in the box it’s not a sandbox. In this case, an LLM escaped a VM 3 times. A VM is not a sandbox. A sandbox is a sandbox. A VM can also have a sandbox, but it needs to keep the sand in the box.
  • @yubrew
    yubrew
    @yubrew
    Aug 29
    AI is finding new issues humans never could before. Keep your hardware wallets firmware up to date. Trezor, Ledger, etc. If you haven’t updated it recently you need to.
    @cvhessert
    cvh
    @cvhessert
    Aug 25
    🚨Critical security update for LEDGER hardware wallets A critical vulnerability has been identified in the Ethereum app on Ledger hardware wallets. It could allow a malicious application to alter the details of a transaction during signing, without this being visible on the
Advertisement
Advertisement