Nicolas Christin's Avatar

Nicolas Christin

@nc2y.bsky.social

Prof. at Carnegie Mellon University. Computer security, online crime, and assorted online seediness. Reformed(?) hacker. Economic migrant. πŸ“ Pittsburgh, PA, mostly πŸ•ΈοΈ https://www.andrew.cmu.edu/user/nicolasc

512 Followers  |  217 Following  |  124 Posts  |  Joined: 29.04.2023  |  1.8361

Latest posts by nc2y.bsky.social on Bluesky

Preview
HTTPS by default One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable β€œAlways Use Secu...

HTTPS by default security.googleblog.com/2025/10/http...

28.10.2025 21:15 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Last week my student Ally Nisenoff published "Exploiting the Shared Storage API" at @acm_ccs: www.andrew.cmu.edu/user/nicolas...

3 days later, Google announced they're abandoning Shared Storage:
privacysandbox.com/news/update-...

(Correlation doesn't imply causation. Interesting, though.)

20.10.2025 19:13 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Advances in Financial Technologies

We're hosting the 7th intl' conf. on Advances in Financial Technologies (AFT'25) at Carnegie Mellon on Oct. 8-10. Join us to hear about the latest exciting developments in crypto research. Registration closes on Sept 16!
advfintech.org/aft25/attend...
(Program: advfintech.org/aft25/progra...)

11.09.2025 19:34 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Toxin Tagger (T-T) on X: "🚨Warning🚨: There was a surge in the number of poisoning attacks on Ethereum, potentially due to the lower transaction fees. Figures: Daily number of poisoning transfers in August 2025 for Ethereum and BSC. https://t.co/jorxvN3hv3" / X 🚨Warning🚨: There was a surge in the number of poisoning attacks on Ethereum, potentially due to the lower transaction fees. Figures: Daily number of poisoning transfers in August 2025 for Ethereum and BSC. https://t.co/jorxvN3hv3

This is concerning, it seems like lower fees on Ethereum are facilitating address poisoning attacks…

x.com/toxin_tagger...

03.09.2025 17:30 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

That’s a wrap for me at #usesec25
Conferences should really consider reusing the tag holders, the amount of wasted plastic is staggering

15.08.2025 18:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

β€œCanadian pharmacist helps run notorious deepfake porn site.”

The online crime jokes write themselves.

15.08.2025 16:37 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Ah true but I should try again today then

14.08.2025 19:14 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Poster for our paper "How Researchers De-Identify Data in Practice"

Poster for our paper "How Researchers De-Identify Data in Practice"

I'm presenting my USENIX paper "How Researchers De-Identify Data in Practice" at 9am this Thursday. Kudos to my co-authors Paige Pepitone, @adamaviv.bsky.social, and @mmazurek.bsky.social. Come say hiβ€”I am on the academic job market!

Here's the paper: www.usenix.org/conference/u...
#usesec25

13.08.2025 16:40 β€” πŸ‘ 6    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

Taro just presented this at #usesec25, and will be manning the poster shortly. If you are around we would love to hear from you.

13.08.2025 20:30 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

I’m not sure there is a more clichΓ©ed Seattle experience than having a latte at a local coffee shop with some salmon on toast while they’re blaring Soundgarden’s β€œOutshined.”

13.08.2025 15:26 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

My student Jenny Tang (coadvised with @lujobauer.bsky.social) is making friends at SOUPS with our paper on looking at 10 years of SOUPS papers and reviewing how solid the stats were. Basically: not great, not great at all. (And that includes my own work.)
Paper: www.andrew.cmu.edu/user/nicolas...

12.08.2025 22:18 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Blockchain Address Poisoning In many blockchains, e.g., Ethereum, Binance Smart Chain (BSC), the primary representation used for wallet addresses is a hardly memorable 40-digit hexadecimal string. As a result, users often select ...

TLDR: Address poisoning is a thing.
Paper: arxiv.org/abs/2501.16681
Real-time website: cryptotrade.cylab.cmu.edu/poisoning/
Real-time twitter bot:
x.com/toxin_tagger
(no BlueSky bot yet, sorry, soon I hope)
(7/7 end)

21.07.2025 17:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

We simulated the lookalike address generation process across various software- and hardware-based implementations. One large attacker group appears to use GPUs for this attack! The paper also discusses some defenses. (6/7)

21.07.2025 17:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

We discovered a few large attack entities using clustering techniques. Larger groups are vastly profitable and win against smaller attack groups. We uncovered some attack strategies, such as populations they target, success conditions, and cross-chain attacks. (5/7)

21.07.2025 17:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

We developed a detection system and performed measurements on two years of ETH and BSC. We identified 13x the number of attack attempts reported previouslyβ€”in all, 270M on-chain attacks targeting 17M victims. 6,633 incidents have caused at least 83.8M USD in losses. (4/7)

21.07.2025 17:10 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

The attacker generates β€œlookalike” addresses that resemble the victim’s recipient’s address, engages with the victim to β€œpoison” the transaction history, and fools the victim into sending their assets to the attacker by mistake. (3/7)

21.07.2025 17:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Background: Crypto wallet addresses are usually impossible to memorize. As a result, users often select addresses from their recent transaction history, which facilitates phishing-like attacks: blockchain address poisoning. (2/7)

21.07.2025 17:10 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Blockchain Address Poisoning In many blockchains, e.g., Ethereum, Binance Smart Chain (BSC), the primary representation used for wallet addresses is a hardly memorable 40-digit hexadecimal string. As a result, users often select ...

New research alert 🚨 from my group, β€œBlockchain Address Poisoning” (Tsuchiya et al.), to appear at USENIX Security 2025 (arxiv.org/abs/2501.16681)! As a follow-up, we also developed a real-time detection system: cryptotrade.cylab.cmu.edu/poisoning/ and x.com/toxin_tagger (1/7)

21.07.2025 17:10 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 1    πŸ“Œ 1
Preview
CMU's "Tartan Federer" Team Sweeps All Four Tracks at International AI Privacy Challenge - Software and Societal Systems Department - School of Computer Science - Carnegie Mellon University Carnegie Mellon University's "Tartan Federer" team, led by S3D’s Zhiwei Steven Wu, achieved a clean sweep at the 2025 Vector Institute MIDST Challenge, winning all four competition tracks. Their innov...

CMU S3D’s β€œTartan Federer” swept all 4 MIDST tracks, revealing privacy gaps in diffusion models.

Its loss-feature attack was the only entry to beat random guessing in the white-box multi-table test.

Details: s3d.cmu.edu/news/2025/0501-midst.html

#AIPrivacy #CMU #AI #ML!

19.06.2025 20:01 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Just because your prof didn't file an academic dishonesty report does not mean that they don't know you cheated.

Knowing you did it and proving it to the hearing board are two different thresholds.

17.06.2025 00:46 β€” πŸ‘ 31    πŸ” 5    πŸ’¬ 2    πŸ“Œ 0

Details: it's likely that there are some symbol mismatches between some homebrew libraries linked against old OpenGL libs and the new OpenGL shipping with Sequoia. This drove me nuts. So I'm posting this here in hopes people don't waste their time. Oh, and don't ask an LLM, they're clueless.

16.06.2025 22:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

PSA: If you're using homebrew, and discovered that MAME crashes w/ a Bus Error upon startup after upgrading to Sequoia, 1) update mame.ini so that the line containing gl_lib points to /System/Library/Frameworks/OpenGL.framework/Libraries/libGLVMPlugin.dylib 2) launch w/ DYLD_LIBRARY_PATH="" mame

16.06.2025 22:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

🧡 about a new paper by my amazing students and collaborators. To appear this week at SIGMETRICS. πŸ‘‡

09.06.2025 22:39 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
CMU Researchers Build Personalized Models To Advance Precision Cancer Care Researchers from Carnegie Mellon University’s School of Computer Science developed a new approach to bridge this gap between available data and actionable insight, creating personalized models to help...

CMU researchers are using personalized models to decode how cancer behaves in individual patients, one of medicine's toughest challenges.

Through individualized data and insights, their work revealed hidden #cancer subtypes that could inform treatment and improve survival predictions.

#Research

06.06.2025 13:32 β€” πŸ‘ 8    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Advances in Financial Technologies

Looking for a home for your great scientific result in fintech that is almost all written up and ready to go? The AFT deadline is in less than 24 hours…

aftconf.github.io/aft25/index....

28.05.2025 11:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Jokes aside yeah it seems like this could work.

25.05.2025 14:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Do you live in England, by any chance?

25.05.2025 14:10 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Possible? Yes. Putting the contents of a can of sardines in a yoghurt is also possible, from a physics standpoint.

25.05.2025 13:26 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Pasta sauce cookie is something you should only attempt after you’ve gotten your second Michelin star.

Like, David Chang, I’d eat his pasta sauce cookie no questions. Doing it myself because the teevee told me to, yeah, no.

25.05.2025 04:24 β€” πŸ‘ 26    πŸ” 7    πŸ’¬ 0    πŸ“Œ 1

In NYC, a man was tortured for two weeks for Bitcoin. He escaped. Alice Hutchings @message4bob.bsky.social and colleagues tell us it's happening around the world.

Conference paper: "Investigating Wrench Attacks: Physical Attacks: Targeting Cryptocurrency Users"
drops.dagstuhl.de/storage/00li...

24.05.2025 21:00 β€” πŸ‘ 12    πŸ” 5    πŸ’¬ 1    πŸ“Œ 0

@nc2y is following 20 prominent accounts