Rebuilt from scratch. Scan withyour iPhone to try it on TestFlight
Timeline: - Metamask Validator hack a few days ago - Lubin moves $300m to fresh addresses - Justin Drake tweets the below hearing rumours that OAI / Anthropic math research have gotten further than expected and broken something critical + currently in talks with EF
1/ Today @greenfield_cap published an open letter on the @safe Community Forum explaining why we have filed a supervisory complaint with the Swiss Federal Supervisory Authority for Foundations (ESA) concerning the Safe Ecosystem Foundation. Here is why, and what we are asking for.
Today I call upon the blockchain industry to calmly begin planning for "bunker mode". My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses, i.e. addresses whose pubkeys remain hidden behind a hash. Holders, starting with large and sophisticated ones, should consider moving the bulk of their funds to addresses that have never signed a transaction. And when they do sign one, they should also move remaining funds to a new address (possibly generated from the same seed phrase). Don't rush. While I believe there is cause for action a rushed migration would do more harm than good. Don't panic either. Moving assets to protected addresses is a simple, preventative step which does not require new cryptography or new wallets. IMO it is now reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years. By "break" I mean fast private key recovery (e.g. in one week) on available hardware (e.g. a large GPU cluster). Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen. This includes the n log(n) bound for integer multiplication and the 3SUM conjecture. In hindsight, May's unexpected disproof of the Erdős unit distance conjecture was our warning shot. Yesterday's OpenAI drop made it clear that mathematical superintelligence is upon us. They say there are weeks where decades happen. We are about to live through weeks where centuries of mathematical progress happen. Could our magic 64-byte ECDSA signatures be too good to be true? Was it just security through obscurity all this time? Elliptic curves feel especially vulnerable to superintelligence. Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimise algebraic structure.) Separately, as Ewin Tang can attest, an efficient quantum algorithm sometimes foreshadows an efficient classical one. We should be open to the possibility of a classical counterpart to Shor that breaks elliptic curves and RSA at once. Also noteworthy is the striking under-representation of cryptographic breakthroughs among the 722 mathematical results OpenAI published. I've witnessed first-hand the US government censoring academic quantum cryptanalysis results. Backroom interventionism is my base case. I urge large, sophisticated actors to lead by example. Project11's "risq list" (bitcoin-risq-list.projecteleven[.]com) is a great tracker of exposed BTC pubkeys. Binance, Bitbank, Robinhood, Bitfinex, and Tether have an opportunity to harden their cold storage. Next month I'll address institutions in London in a live Q&A (forum.ethereuminstitutional[.]org/london-2026). Again, please do not rush. Wallets holding under 50 BTC enjoy partial cover from "Satoshi's shield", i.e. his 20K exposed addresses that hold 50 BTC each. Load-bearing signers like oracles and L2 security councils should consider rotating ECDSA pubkeys with every signed message and/or multi-signing with a hash-based schemes like SPHINCS. Exiting bunker mode safely will require post-AI cryptography. My inclination is to go all-in on hash-based cryptography and avoid structured mathematical assumptions entirely, whether from curves, lattices, or isogenies. A single battle-tested hash (e.g. from the SHA or BLAKE families) yields plausible post-AI security. The Ethereum roadmap on strawmap[.]org fully embraces hash-based cryptography with end-to-end formal verification as a response to the quantum threat. Those timelines must now be revisited and accelerated in light of mathematical superintelligence. I'll be pushing for maximum defensive acceleration.
Blah blah dogma. Art = art. Period. Humanity needs protection from humanity as much, if not more, than from machines. Besides, if organized religion doesn’t like something, my first inclination is to like it more.
BAL holders approved an orderly wind-down. BIP-928 passed and BIP-929, the fork proposal, did not. Pools keep working as usual until October 30th, and withdrawals stay open the whole way through. Here's the timeline and what it means for LPs and BAL holders.
🚨SlowMist TI Alert🚨 💸 @aave v3 Loop Safe Module Loss: ~114.09 ETH 🔍 Root Cause: FlashLoopAdapter's open()/close() access control only checks ISafe(msg.sender).isModuleEnabled(address(this)), which is spoofable via a fake Safe that always returns true. Its _swap() then executes http://router.call with fully attacker-controlled router and calldata. Since the adapter is an enabled module of the victim Safes, the attacker set router=victim Safe and data=execTransactionFromModule to drain weETH and Aave collateral. 📌 Attacker: 0x42c2633438609881c8fBAb82414eb9A0c45F9353 📌 Victim: 0xe3b23e47df7cd85876ac6cb05bdb9d7cd5b28520, 0xcfedf95a3653a128dfc2e4288758a1a1850d169f 📌 Vulnerable Contract: 0x16bb8b912da187870c23ec6756bb3fad061283d8 Impact: ~114.09 ETH stolen from two Safe multisigs via forged Safe authentication and arbitrary module execution; ~1300 WETH debt repaid to unlock collateral. Powered by http://SlowMist.AI Tx: https://etherscan.io/tx/0x75328f916b1a08…
Blast will be shutting down. We launched Blast with the goal of building a self-sustaining chain for users and developers. Unfortunately, the economics of operating the chain no longer make sense: the ongoing costs of maintaining Blast exceed the revenue generated by the L2, and we do not see a credible path to making the chain economically sustainable. As a result, we've made the difficult decision to wind Blast down. We're sorry to the users and developers who believed in Blast, built on it, and supported the ecosystem. Our priority now is making the shutdown as smooth and safe as possible. We're asking all users to withdraw their assets from Blast to Ethereum mainnet, including any balances held in the Blast PWA. To make this easier, we will be reducing the withdrawal delay to 24 hours. As part of the shutdown process, we'll first begin withdrawing Blast's Lido assets. This process is expected to take approximately one week. During this period, withdrawals will temporarily be unavailable, even after the withdrawal delay is reduced to 24 hours. Once that process is complete, withdrawals will resume with the new 24-hour delay. Users will have until October 26, 2026 to withdraw through the normal Blast interface. After October 26, assets will remain withdrawable, but users will need to interact directly with the Blast bridge contracts on Ethereum L1. We'll publish detailed instructions before then. We strongly encourage everyone to withdraw their assets to Ethereum mainnet before October 26.
Following an investigation into an infrastructure compromise, MetaMask Staking (ex Consensys Staking) has taken precautionary steps to protect client assets related to its operated Ethereum validators. These steps include exiting its Ethereum (ETH) validators in the Lido protocol, and will likely incur foregone rewards as well as possible downtime penalties should validators be taken offline in the near future to reduce risks related to potential network penalties. Relevant validators have begun the exit process, with the final validators expected to be exited (but not fully withdrawn) by the end of October 7th, 2026. No action is required from stETH holders. ETH exited from MetaMask Staking-operated validators is expected to return to the protocol gradually as the relevant validators complete the exit, withdrawal, and re-entry cycle, which is estimated to take approximately up to 45 days due to the extended entry queue. As a reminder, staking operations are non-custodial in nature and MetaMask does not manage withdrawal keys for staking on behalf of clients. As always, the Lido Protocol’s diverse Node Operator set and other security systems including the ad hoc reserve fund (of over 6,750 stETH), are designed to contain and mitigate disruptions to the normal operations of the protocol, in addition to other potential routes. https://research.lido.fi/t/security-disc… A full investigation is underway, and further updates will be shared as they become available. For further details, please refer to the MetaMask Staking release linked below.
Security Update: We are responding to a security incident affecting part of our infrastructure. At this time, we have identified no immediate threat to MetaMask wallets. As a precaution, we are proactively exiting affected validators within our non-custodial staking operations, in coordination with clients, partners and security advisors. We’ll share further updates as appropriate. https://metamask.io/news/user-update?utm…
Namestone.com will shut down effective August 3, 2026. We pioneered API driven gasless subname issuance. We manage over 9 million subnames, more than any other API platform.
Introducing Gemini 4 Argon – our new frontier model. It’s built for complex workflows across coding, enterprise knowledge work, and cybersecurity defense – rolling out today to a set of trusted testers through our Fairwind Program.