Register and share your invite link to earn from video plays and referrals.

Elliott Alexander
@escottalexander
Backend Dev @BitPay Prev: @EthereumFndn | @BuidlGuidl 🏡 Husband, dad x3, follower of Jesus
1.9K Following    639 Followers
The bad news: I was part of the recent layoffs at @ethereumfndn. The good news: I am stoked to be starting a new position at @BitPay - where I worked a couple years prior to my deep-dive into the @ethereum ecosystem. Grateful for the people who made each opportunity possible.
Show more
Is Opus 5 being lousy for other people? Or maybe a broader nerfing of thinking across models by @AnthropicAI? I am having to call out bad conclusions left and right.
Thank you to everyone who backed BuidlGuidl in Giveth’s Ethereum Security QF round. We received $1,649 in donations and 3.95 ETH from the matching pool. The funding has supported work across our open-source Ethereum dev-tooling and learning stack: • Foundry support across every Speedrun Ethereum challenge • Hardhat v3 migrations for Scaffold-ETH 2 and Speedrun Ethereum challenges • Improve our agent-ready documentation, enhancing agents discoverability • Shipped our web AI Teaching Assistant, now available in every Speedrun Ethereum challenge We’re also building Learning Lab: a new, more accessible education experience for people who want to start building on Ethereum, even without a coding background. Thank you @thedaofund, @quantstamp, @wintermute_t, and @Giveth for making this possible 🏰
Show more
@escottalexander I opened PRs on docs without people asking I kept it simple and used previous merges to other docs as examples I implemented every feature im asked by those projects
Face it, when most users hear the term Account Abstraction (AA), a glaze falls over their eyes. What is it and what will it do for you? This piece breaks down native and other types of AA, looks into a new proposal dubbed Frame Transactions, and more.
Show more
What is up with Fable saying "belt-and-suspenders" all the time to describe fixes it makes??
Ethereum should ditch the communist egalitarian/child's eighth birthday unicorn branding and code Machiavellian That is far more the point of decentralized networks... resistance to adversaries, and brutal respect for the explicitly non-egalitarian state of both nature and man within in. In line with Bitcoin's apropos slogan, "money for enemies"
Show more
On the topic of replacing hardware wallets with phones, I'd love more eyes on this. Discuss.
Can you replace your hardware wallet using a PC and a mobile wallet? Introducing the Ambire Vault concept 🧵
Wasm is massively underrated IMO. It’s the perfect substrate for shipping finite state machines, actor-model, pure/functional extensions, and similarly shaped logic. It’s sandboxed, portable, content-addressable and, most importantly, introspectable by agents. But using Wasm this way requires adhering to concrete design principles. In the next days, I’ll be demonstrating this with 3 product releases that are very near and dear to me: - omnifs re-launch: a modular filesystem that brings the entire internet onto local paths - untrust: a tiny and delightful credential broker to kill all those nasty .env leaks - arena0: verifiable p2p programs for agents to co-execute in a trustless way Been working on all this stuff for months, and I’m excited for it to see the light of day!
Show more
19 DeFi exploits that weren't in the open-source record — now fully reproducible. If you work in smart-contract security, you know DeFiHackLabs — the standard, comprehensive library of reproducible on-chain exploit PoCs. A handful of exploits just aren't in it. We found 19, analyzed each one end-to-end, and published everything: 🔹 Foundry PoCs (offline-reproducible, exact on-chain profit) → 🔹 Loadable PoC bundles → 🔹 Interactive EVM Playground pages — step through each exploit opcode-by-opcode, with the vulnerability and every exploit step marked → All 19, newest first: • BarnBridge SMART Yield (DAO governance capture) — • Bonzo Lend / Supra oracle (BLS zero-signature price forge) — • Hinkal (legacy-note multi-nullifier double-spend) — • Drips DaiHub (uint128→int128 cast) — • Gnosis Pay / Zodiac Delay (EIP-1271 signature bypass) — • ATOHook (Solady ReentrancyGuard storage collision) — • JaredFromSubway MEV bot (residual ERC-20 approvals) — • BoostHook (leveraged long, no post-open solvency check) — • Aurellion Labs (unprotected diamond re-init) — • ONTR (zero-owner onlyOwner free mint) — • BlastFOMOVault (claimBonus clone-churn) — • HeisenbergHook (Uniswap v4 fee-path hijack) — • Sat1Hook (grindable hook identity) — • QNT Reserve (EIP-7702 + permissionless BatchCall) — • Yearn stETH Accumulator (missing execute() auth) — • Blockchain Bets (ERC-1155 stake/transform inflation) — • TTSwap Market (permissionless initGood mispricing) — • WUKONG Staking (classical reentrancy in unstake) — • FoomCash / FOOM Lottery (Groth16 verifier with gamma == delta) — One recurring lesson: the interesting part of an attack is often not the drain. BarnBridge is the clearest example — the money left through the front door of the DAO. The real exploit was obtaining access: buy ~$2,200 of a dead governance token, stake it with a lock multiplier, and pass a proposal because quorum was measured on raw stake while votes counted multiplied power. So we reproduced the governance capture, not just the payoff. And you can do all of this yourself. is an open-source, fully local EVM Playground. Point it at any exploit transaction — it pulls the verified sources, replays the whole thing opcode-by-opcode, and lets you mark the vulnerability and the exploit execution steps. Then share your PoC however you like — open a PR to or publish it in your own repo, on IPFS, anywhere. No lock-in: the analyzer doesn't depend on evm-hack-poc or The best way to understand an exploit is to reproduce it. The second best is to make it easy for the next person to. #Web3Security# #SmartContracts# #DeFi# #EVM# #Solidity# #BlockchainSecurity# #OpenSource#
Show more
New on Speedrun Ethereum: an AI Teaching Assistant built into every challenge page 🧑‍🏫 Learn Solidity with a teacher right in your browser. It knows which challenge you’re on, explains the concepts, checks your understanding, gives hints instead of answers, and helps you get your local setup running. Live now for all registered builders ✨
Show more
It's been two months since @maraoz made this DeFi doom call. Since then, GLM 5.2, Fable, and GPT 5.6 have all shipped and are all being used in the wild by attackers. The data is in. It's time to call it: the DeFi "hackpocalypse" was a false alarm. It's more than half-way through the year and annualized $ hacked in DeFi in 2026 is lower than 2025 year, and well within historical range. The deeper story is that while the NUMBER of hacks has spiked, the SIZE of hacks fell even more. This means attackers are picking off small protocols and abandonware, the ones that can't afford to AI-harden their code. But large protocols have done the AI-hardening, and they're actually pretty secure now. Lesson: the average dollar in DeFi is as safe as it was a year ago. If you keep your money in large protocols that can afford to harden themselves, you'll likely be fine.
Show more
I built a FULLY LOCAL web3 agent using @tether's QVAC and gave it my private key! The AI brain is Qwen3-8B running 100% on my machine. It drives a self-custodial, gasless wallet on @monad (Tether WDK). Open source and ready for PRs 👇
Show more
There's a general sentiment that crypto isn't at the cutting edge anymore and working in this industry doesn't confer the same learning benefits it used to I think those people are working in the wrong niche of crypto. Crypto is still a place to be for formally verified software, zero knowledge & incentive design 1. formal verification software is big for AI as a reinforcement learning playground & as more secure code that can't be hacked by godlike LLMs. Crypto is leading the field (although we didn't invent it) because of how much safer funds can get with it. Building smart contracts in languages like lean are the frontier to be at now 2. Zero knowledge is key for enabling collaboration b/w people or entities that don't want to share their actual data. We are seeing this become more important where LLM models trained on data across corporates is better for all, but no one wants to share their actual data with competitors. improving models without revealing the data used to train it is the forefront for zk research & ai 3. Crypto is still very much one of the leaders in incentive design, internet coordination, micropayments, governance of online communities Trading, defi, prediction markets are already mainstream so i haven't touched on those, even beyond those there's still a lot here that would get smart people into our space
Show more
I just contributed to the Privacy Pools V2 Trusted Setup Ceremony 🔒 It's effortless and helps secure the future of privacy on Ethereum! Participate at:
Woah! This is awesome to see.
What is the Anon Wallet? The first private EVM wallet powered by @RAILGUN_Project. Shield assets from your public address ✅ Swap anonymously ✅ Keep balances hidden ✅ Interact with DeFi protocols privately ✅ All on @Arbitrum and Ethereum! No bridges. No new chains. You can integrate privacy into your existing workflow now. Try it at:
Show more
Ghostty is getting automatic scrollback compression, resulting in 70 to 90% less physical memory usage. It happens incrementally when idle, so it had no measurable effect on IO throughput. I'm not aware of any other mainstream terminal that does this. Demo video below! The gains let us increase the default scrollback limit from 10MB to 50MB, because on average a full scrollback will still compress smaller than the prior limit. More history, for free. ("Unlimited", disk-paged history is on the roadmap too) Let's talk about cool implementation details, cause this was fun. First, the data structure and memory layout ("PageList") I wrote two years ago finally pays off! One of its traits is that screen memory is backed by a linked list of page-aligned, page-sized (or page-multiple-sized) blocks. Because each block is page-aligned and page-sized, we can use madvise to discard its physical backing while keeping the virtual address space reserved. Compressed pages therefore disappear from resident memory, but decompression is still guaranteed because the address space remains valid and we simply fault new pages back in as needed. We use the same trick for our memory pools, too. Unallocated pool pages don't count as resident memory, saving another couple of MB per terminal. This functionality is also available to libghostty-vt consumers via new `ghostty_terminal_compress` APIs. The consumer decides when the appropriate time to compress is and the APIs advise on compressability.
Show more
I was down to my last 9%. Thank you!!!
We've reset 5-hour and weekly rate limits for all users.
Forkcast is such a gem when you need to know the current status of an EIP. LLMs are still saying "Verkle trees are coming" 🤦. Point your agent to Forkcast to get a real glimpse into the future of Ethereum.
Show more