"The problem is that clicking on the link to that web page is enough to trigger a cross-site WebSocket hijacking attack because OpenClaw's server doesn't validate the WebSocket origin header."
thehackernews.com/2026/02/open...
@ad403.bsky.social
Share my learning journey in the field of Blockchain, Crypto and Web3. Security Engineer at taurushq.com See my blog https://rya-sge.github.io/access-denied
"The problem is that clicking on the link to that web page is enough to trigger a cross-site WebSocket hijacking attack because OpenClaw's server doesn't validate the WebSocket origin header."
thehackernews.com/2026/02/open...
Prompt injection and RCE in Qodo Merge, an open-source AI code review tool. Great write-up!
kudelskisecurity.com/research/qod...
"The attack involved infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org. The incident began from June 2025 until December"
Recommend version: v8.9.1
notepad-plus-plus.org/news/hijacke...
"The North Korean threat actor known as Konni has been observed using PowerShell malware generated using artificial intelligence (AI) tools to target developers and engineering teams in the blockchain sector."
thehackernews.com/2026/01/konn...
Using only natural language instructions, researchers were able to bypass Google Gemini's defenses against malicious prompt injectionΒ and create misleading events to leak private Calendar data.
20.01.2026 12:50 β π 12 π 4 π¬ 1 π 0ERC-1643, part of ERC-1400, is one of the oldest tokenization related standard on Ethereum (2018) developed by PolymathNetwork.
It allows to manage on-chain document which is very useful for tokenization and RWA. More information on the Ethereum magician forum: ethereum-magicians.org/t/erc-1643-d...
The latest release of CMTAT Solidity (v3.1.0), a security token framework for on-chain RWA, includes now Chainlink CCIP support for seamless cross-chain transfers. Available on GitHub
19.12.2025 13:13 β π 0 π 0 π¬ 0 π 0How do you tokenize RWAs on Solana?
CMTA just released a new specification leveraging the Token Extensions Program (Token-2022).
Now available on GitHub: github.com/CMTA/CMTAT-S...
Glad to have contributed through my work at Taurus
Tracking the latest NPM supply-chain attack (βShai Huludβ):
β’ Socket: socket.dev/blog/shai-hu...
β’ Aikido: www.aikido.dev/blog/shai-hu...
Quarkslab engineers Robin David, Mihail Kirov and Kaname just completed the first public security audit of Bitcoin Core, led by
@ostifofficial.bsky.social and funded by Brink.dev
Details on the blog post:
blog.quarkslab.com/bitcoin-core...
Congrats to developers for such software masterpiece !
Great YouTube playlist to learn more about Hash-Based quantum-safe signature schemes (LMS, XMSS and
SPHINCS+). www.youtube.com/watch?v=pt5W...
#cryptography
Bluesky seems to work, unlike X/Twitter x)
18.11.2025 13:27 β π 1 π 0 π¬ 1 π 0Coinbase Security series: what is MPC and how to use it for Key Management: youtu.be/qdhM3syDkxM
#cryptography
Breaking server SGX via DRAM bus: wiretap.fail
01.10.2025 10:47 β π 2 π 0 π¬ 0 π 0See also www.aikido.dev/blog/npm-deb... and www.securityalliance.org/news/2025-09...
09.09.2025 06:09 β π 1 π 0 π¬ 0 π 0"The malware did more than just steal SSH keys, npm tokens, and .gitconfig files - it weaponized AI CLI tools (including Claude, Gemini) to aid in reconnaissance and data" www.stepsecurity.io/blog/supply-...
28.08.2025 18:00 β π 0 π 0 π¬ 0 π 0Algebraic intermediate Representation (AIR) for Blake Hash youtu.be/INtBA-9vJpU?... hackmd.io/@starkware-h...
13.07.2025 12:53 β π 0 π 0 π¬ 0 π 0Coinbase MPC wallet library presentation at EthCC m.youtube.com/live/ppeyz_J...
01.07.2025 19:43 β π 2 π 1 π¬ 0 π 0My last article about ERC-20 ConditionalTransfer is available on Taurus blog: www.taurushq.com/blog/tokeniz...
Based on CMTAT, an open-source project: github.com/CMTA/CMTAT
#solidity
Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised.
27.04.2025 14:21 β π 3 π 1 π¬ 0 π 0MITRE Vice President Yosry Barsoum has warned that U.S. government funding for the Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE) programs expires today, which could leadΒ to widespread disruption acrossΒ the global cybersecurity industry.
16.04.2025 02:16 β π 12 π 9 π¬ 0 π 1NFTs are used to represent unique items on the blockchain. As you may know, the most known standard on Ethereum is ERC-721. Since its creation, several other standards (ERC-1155, ERC-2981, ERC-4907,...) have emerged to meet various use cases. More details here: rya-sge.github.io/access-denie...
02.04.2025 05:58 β π 3 π 0 π¬ 0 π 0Ledger's article on the security and integrity of the Trezor Safe 3 crypto wallet firmware is a great read to better understand how the new Trezor models (Safe Family) work (Secure Element, firmware integrity, chips used)
www.ledger.com/why-secure-e...
blog.trezor.io/trezors-mult...
How to tokenize on Ethereum and EVM based blockchain? My last article on Taurus blog is a deep dive into ERC-1400, one of the oldest tokenization standards (2018). www.taurushq.com/blog/erc-140...
25.03.2025 11:15 β π 0 π 0 π¬ 0 π 0A cascading supply chain attack that began with the compromise of the "reviewdog/action-setup@v1" GitHub Action is believed to have led to the recent breach of "tj-actions/changed-files" that leaked CI/CD secrets.
18.03.2025 16:04 β π 3 π 5 π¬ 0 π 0A couple weeks ago we published our monthly release of ZK Mesh: the February 2025 Recap.
Wondering which articles/threads are the most popular amongst our #ZKMesh readers so far?
ZK Mesh Feb 2025 Top 5, here we go
π§΅ π
open.substack.com/pub/zkmesh/p...
damn this halo2 book is soooo goooood halo2.zksecurity.xyz/intro/
14.03.2025 15:53 β π 0 π 1 π¬ 0 π 0A large-scale Coinbase phishing attack poses as a mandatory wallet migration, tricking recipients into setting up a new wallet with a pre-generated recovery phrase controlled by attackers.
14.03.2025 18:35 β π 7 π 6 π¬ 0 π 0Sepolia Pectra fork incident recap:
"we quickly realized that, because the deposit contract is token gated, an ERC-20 transfer event was emitted whenever a deposit was processed.
mariusvanderwijden.github.io/blog/2025/03...
Bybit hack deep dive by ncc group www.nccgroup.com/us/research-...
12.03.2025 07:53 β π 0 π 0 π¬ 0 π 0