A bug that sat in Zcash's Orchard circuit for four years was found by an AI, days after the model shipped.
In Part 4, @rabizzzy breaks down how a researcher's purpose-built AI harness caught it.
Welcome to Taler Finance | The curated vault era is here, but infrastructure still lags behind traditional asset management.
Taler closes that gap.
We build and scale tailored vault infrastructure for institutions and ecosystems. A thread 🧵
Security updates you should know from June: what got hit, and why the biggest loss never touched a smart contract.
TLDR;
• $75.32M lost across 32 web3 incidents (vs May's $59.52M)
• One targeted social-engineering operation was 42% of the total
Happening offchain this month:
• Miasma: an npm worm that hijacked Red Hat's packages, now stealing GCP & Azure cloud identities and shipping releases with valid provenance
• Oracle PeopleSoft: a zero-day exploited for 2 weeks before the advisory
Transparency should lower your cost of doing business.
Introducing Verified D&O: issuers who prove their identity and collateral now qualify for D&O underwriting built for digital assets.
A collaboration with @blupryntco.
The Zcash Orchard bug was patched, but nobody can prove it was never exploited.
In Part 3, @rabizzzy breaks down why privacy makes an exploit invisible and the trade-off against supply integrity 👇
The Zcash orchard pool bug came down to a single missing constraint in a zero-knowledge circuit.
In Part 2 of our miniseries, @rabizzzy breaks down how Zcash proves a payment it can't see, and whether the same bug could be hiding in projects far beyond Zcash 👇
The Zcash orchard pool bug came down to a single missing constraint in a zero-knowledge circuit.
In Part 2 of our miniseries, @rabizzzy breaks down how Zcash proves a payment it can't see, and whether the same bug could be hiding in projects far beyond Zcash 👇
One of the best parts of running an open funding round is being able to learn in the open.
The @thedaofund Ethereum Security QF Round retrospective is now live!!
Inside you'll find what worked, what didn't, and the improvements we're already thinking about for future rounds.
I’m excited to announce our $40M Series B, led by @AmplifyPartners with @kleinerperkins, and @Theoryvc.
After knowing each other for 10 years and meeting in our freshman year in college, Cheng Han and I came together in 2021 to solve the massive problem with blockchains - the
A double-spend bug sat in Zcash's Orchard pool since 2022, through multiple audits and expert reviews.
In Part 1, @rabizzzy breaks down what the bug actually was, how it surfaced, and why a counterfeiting flaw in a privacy coin is harder to assess than an exchange hack 👇
As social engineering attacks rise, OPSEC matters more than ever.
Excited to have Roman, Incident Lead @Quantstamp, at @ETHCincoDeMayo sharing practical ways to lock down your devices, laptops, and accounts!
A new speaker joins Ethereum Security Day CDMX on July 8th! Roman, Incident Lead from @Quantstamp will give a practical workshop:
🛡️ OPSEC: Practical Methods to Improve the Security of Our Devices, Laptops, and Accounts.
Let's secure @ethereum, register: luma.com/kbkipite