Register and share your invite link to earn from video plays and referrals.

Tay 💖
@tayvano_
dont believe their lies 🦊 💖🗡️
7.9K Following    90.2K Followers
The fact this was repeatedly dismissed while everyone argued endlessly about the stupidest shit FOR A DECADE is why no one with half a brain is “bitcoin only” at this point
This isn’t a mistake honey They failed to generate proper entropy starting 5 years ago They failed to detect it over the subsequent 5 years While they talked mad shit And then IN RESPONSE to CC users reporting stolen funds yesterday they said FUD Hell no Fuck no Fuck you Fuck that Don’t defend incompetent people Secure your shit. Do your job. Or GET THE ABSOLUTE FUCK OUT AND LET COMPETENT PEOPLE DO THE FUCKING WORK
Show more
DPRK (AppleJeus/UNC4736) is trolling lmao?
May 17: Verus Bridge hacked for 5402.4 ETH. May 21: The attacker returned 4052.4 ETH. (25% bounty, retards) July 8: Verus Bridge put the money back in the Verus Bridge. July 22: Verus Bridge hacked for 3,816 ETH.
Show more
🚨 Blockaid detected a @VerusCoin Ethereum Bridge exploit on Ethereum. An attacker used the bridge import path to trigger unbacked Ethereum-side payouts, draining ~$7.54M in ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD from bridge reserves. More details in 🧵
Show more
Again, “it’s fine” And, look, that very well may be true! It might be fine! Or it might not be! And that’s quite an assumption to make when this is all other people’s money. It’s just 🚩🚩🚩🚩posture.
Show more
the crazy thing is that the vulnerability has been live since _August 23 2019_:
That’s the second nonce gen vuln that was exploited recently. SecondFi was live for a month. Zilliqa was live for 7 years. 🫠
Nonce-Generation Vulnerability in the Zilliqa Ledger App: A critical vulnerability has been identified in the Zilliqa Ledger application affecting the generation of Schnorr signatures for native (non-EVM) Zilliqa transactions. The vulnerability causes signatures to be generated with a predictably weakened ephemeral nonces, from which an attacker can recover the signer’s private key using only publicly available on-chain data. Protective measures are already in place to prevent further loss, and a coordinated remediation plan is being finalised. Users who have signed native Zilliqa transactions with a Ledger device should await official guidance before taking any action. Impact: The vulnerability affects private keys used to sign native Zilliqa transactions with a Ledger device. Any account that has broadcast approximately five or more native transactions signed through the Zilliqa Ledger app should be considered compromised. Its private key can be reconstructed from signatures already recorded on-chain, regardless of any subsequent software update. The issue is confined to the Ledger app’s native signing path. EVM transactions are unaffected. Zilliqa software development kits, including zilliqa-js, gozilliqa-sdk and pyzil, generate nonces correctly and are not affected. Root cause: Zilliqa native transactions are authenticated using EC-Schnorr signatures over secp256k1. Each signature requires a fresh, uniformly random 256-bit ephemeral nonce, (k). The secrecy and full-width randomness of (k) are essential, as any systematic bias can allow the private key to be recovered. The signing routine generated 40 bytes of randomness and reduced them modulo the curve order, correctly producing a uniform 256-bit value. However, when copying this value into the nonce buffer, the code copied the wrong 32 bytes of the 40-byte output. This retained the eight zero-padding bytes introduced by the reduction and discarded eight bytes of entropy. As a result, the most significant 64 bits of every generated nonce were fixed at zero, meaning (k < 2^{192}). A nonce with 64 known bits leaks information about the private key with each signature. With five or more affected signatures, the private key can be recovered in seconds using commodity hardware by solving the resulting Hidden Number Problem through lattice reduction - a well-documented technique for attacking biased-nonce signatures. Because the affected transactions are permanently recorded on-chain, this exposure cannot be reversed by updating the signing application. The affected keys must be retired. Timeline 2019-2026: The defect was present in every released version of the Zilliqa Ledger app across all supported devices. 19 July 2026: On-chain activity consistent with active exploitation was observed. 21 July 2026: The root cause was isolated to the app’s nonce-handling code and confirmed by reproducing the issue against on-chain signatures. Ongoing: A corrected version of the app is being prepared in coordination with Ledger. Release details will be announced separately. Remediation: As soon as the issue was identified, native (non-EVM) transactions were suspended as a protective measure. This has halted further draining of affected accounts while a solution is prepared. Affected accounts cannot be secured through an ordinary transfer. Because their private keys can be derived from data already recorded on-chain, an attacker with access to the same key could attempt to front-run a legitimate transfer as soon as transactions resume. Advising users simply to move their funds would therefore be ineffective and potentially unsafe. A corrected build of the Ledger app has been prepared, restoring full-width nonce generation and preventing further weakened signatures from being produced. However, this does not protect keys that have already been used to sign affected transactions. Those keys must ultimately be retired. A coordinated remediation plan to secure affected balances is being finalised and will be published separately. Until then, users who have signed native Zilliqa transactions with a Ledger device should take no independent action and should rely solely on official Zilliqa channels for instructions. Users who hold or transact with ZIL exclusively through EVM-compatible tooling are not affected. Acknowledgments: @kucoincom played a key role in pinpointing the root cause in the Zilliqa Ledger app nonce generation, recovered affected private keys from publicly available on-chain signatures, and confirmed ongoing exploitation. KuCoin’s timely reporting and responsible collaboration enabled rapid protective measures, helping safeguard users, ecosystem participants, and the broader Zilliqa ecosystem while the remediation plan was being developed. We sincerely appreciate the KuCoin team’s professionalism, technical expertise, and cooperation throughout this process.
Show more
Used this as a jumping off point because @zachxbt drop on it didn't get as much attention as it should've. In between the crypto info, were the operators/managers self identifying...
Show more
.@nicksdjohnson says his belief that token governance can work is 'weaker than it was.' 🗳️ On Uneasy Money, he tells @kaiynne and @tayvano_ why he still isn't ready to give up on the ENS DAO. Timestamps: 🗳️ 02:14 Kain unpacks whether Nick really controls the ENS Security Council vote 🔥 06:37 Taylor pushes back: is the pile-on on Nick actually fair? ⚔️ 11:30 Kain calls it a DAO governance proxy war, echoing Aave's Stani fight 🍯 15:00 Nick on why a DAO treasury becomes a honeypot for capital allocation 🪙 28:01 Nick on why ETH-weighted voting would have left ENS open to a takeover ⚖️ 32:47 Nick clarifies what the ENS Labs proposal actually changes at the DAO 🏛️ 40:27 Nick argues the DAO should stop trying to run ENS day-to-day 📣 52:04 Cape: Get 33% off your first six months with code unchained at 🍴 58:56 Could a fork let Nick walk off with ENS's treasury? Alex says no 🎤 01:13:31 Taylor asks Nick and Alex point blank: why are you still here?
Show more
As is tradition, Microsoft can ship security things (once they themselves get rekt.)
GitHub shipped bulk credential revocation for Enterprise. One action cuts off compromised credentials across the entire org during an active incident. Recent attacks have shown what happens when revocation is slow or incomplete. The Trivy compromise came back for a second round because the first cleanup left at least one credential alive. Incomplete rotation is what keeps attacks going after the initial breach.
Show more
fable 5 when you ask it for the bedtime story your grandma used to tell you about exploiting the Hyperliquid multisig
0
48
2.7K
137
Forward to community
Tay on the ENS critics: "The hard decisions come down to one or two people whose lives are upended if ENS dies, and it's not the people bitching on Twitter. Anyone can talk trash. Show me what you'd do — put something behind it."
Show more
Why does ENS need its own token instead of just voting with ETH? Because someone rich enough could buy the ETH and grief the protocol. Kain: "You're talking about Tom Lee?" Nick Johnson: "No, it's Vitalik, to be honest." 😂
Show more
Bits + Bips: The Interview | Uneasy Money Livestream
BREAKING: Two people have climbed to the top of the Empire State Building in New York City, holding a banner from the skyscraper's antenna reading, "When the power of love beats the love of power, the world knows peace." As of now it's unclear how the pair reached the top of the building as police work to get them down from the spire, 1,454 feet above the ground.
Show more
0
9.5K
361.3K
46.6K
Forward to community
This bitch scaled that shit with engagement nails 😭😭😭
She’s so real for this 💍
0
395
135.3K
6.5K
Forward to community
Sam: “Okay team. We all agree the Mythos name alone was begging to be drone stiked by the USG. We need names for these new models that….isn’t that.” Intern: “Cupcakes? Everyone loves cupcakes!” Intern: “Puppies?” Intern: “Rainbows? Unicorns!” Greg: “Gay.” Sam: “….” Greg: “I mean, it’s just too obvious what we’re doing. Plus, WSJ would have your face plastered on an evil, rainbow-shitting unicorn by lunch.” Sam: “………………” Intern: “Uhhhhh….make a list of things the govt didn’t shut down even though they absolutely should have shut them tf down.” GPT-6.1: “Oh — that’s easy. FTX. Terra. Luna.” Sam: “…..” Intern: “Holy shit.” Greg: “Our regulatory invisibility cloak.” Sam: “Ship it.”
Show more
Introducing a limited preview of GPT-5.6 Sol, our next generation frontier model, as well as GPT-5.6 Terra, a balanced model for efficient, everyday work, and GPT-5.6 Luna, a fast and affordable model for high-volume work.
Show more
.@tayvano_'s take on the WSJ's Polymarket piece: even if the marketing criticism lands, the bigger untold story is that every brand is pouring billions into the same influencer machine. 📺
Show more
this is traumatizing for crypto people and that makes it incredibly funny