注册并分享邀请链接,可获得视频播放与邀请奖励。

与「CryptoOG」相关的搜索结果

CryptoOG 贴吧
一个关键词就是一个贴吧,路径全站唯一。
创建贴吧
用户
未找到
包含 CryptoOG 的内容
币圈 OG 郭宏才(宝二爷)确认出席 4月19日 Meta Girls Party 区块链意见领袖、资深投资人 @ChandlerGuo 确认受邀出席本次活动。作为行业极具影响力的传奇人物,二爷将以其敏锐的市场直觉与硬核的投资逻辑,现场拆解 Web3 未来演进风向。在中环 18F,与最具流量号召力的 OG 面对面。 🍸 主办方: @MetaEraCN, @iPolloClaw, @DesunHK 🤝 联合主办: @trondao, @TheoriqAI, AImall 📅 时间:2026.04.19|19:00–23:00 📍 地点:香港中环云咸街60号中央广场18F 🎟️ 报名锁定席位,预定您的社交高光时刻: #CryptoOG# #Web3Festival2026# #MetaGirlsParty#
显示更多
Ethereum is both an abstract philosophical concept (the ontological Turing machine) and a practical research and development effort that aims to answer this question that pertains to the nature of Ethereum. How the nature of "Ethereum" as a protocol comes to be determined through the ACD governance mechanism, how cryptographic truth comes to be defined, and how convergent consensus is reached using majority representation of Ethereum's observers is what reduces the ontology of the world computer down to what we today call the Ethereum network. Here's how the world computer comes to be defined:
显示更多
0
29
292
34
转发到社区
The cryptographic world computer: My attempt to express in somewhat concise terms the true meaning of basically everything planned to happen to Ethereum starting from the fork after Hegota. It's really not just a blockchain anymore. It's a hybrid architecture that combines together blockchains and modern cryptography, to enable much more powerful properties. FOCIL, EIP-8288, Lean consensus, state management, formal verification, advanced mempool improvements (including privacy), and the longer-term specter of obfuscation all mentioned.
显示更多
0
496
5K
849
转发到社区
🚨 On September 6, 2026, @Liquid_BTC was affected by a cache key collision vulnerability in rangeproof verification. An attacker minted ~3,998.5 L-BTC with no corresponding peg-in. Within minutes, the unbacked L-BTC was pegged out into real BTC on the Bitcoin mainnet. About 3,400 BTC was later returned to the federation peg wallet, while ~598.5 BTC remains under the attacker’s control. The SlowMist Security Team traced the fund flows on the #Bitcoin# side using @MistTrack_io and fully analyzed the incident. 🧩 Attack flow: 1️⃣ Two setup transactions first landed valid rangeproofs and commitments, while embedding a crafted payload in the locking script to seed node caches. 2️⃣ A follow-up minting output reused a colliding cache key — the same raw concatenation of proof, commitment, asset commitment, and scriptPubKey, but with different field boundaries. 3️⃣ On a cache hit, nodes skipped secp256k1_rangeproof_verify and min-value checks, accepted an unbacked commitment, and minted ~3,998.5 L-BTC. The fake UTXOs were consolidated and pegged out within minutes. ⚙️ Root Cause: The Elements rangeproof cache key concatenated variable-length fields without length prefixes. Distinct argument tuples could hash to the same key, so a positive cache hit meant skipping cryptographic verification. 🛡️ SlowMist Insight: A positive-result cache in a consensus verification path is itself a cryptographic primitive. Every field the verifier reads — and every field boundary — must be unambiguously bound into the key. Treat cache-key integrity as a mandatory item in consensus-layer audits. Full analysis👇
显示更多
A note on recursive STARK mempools (EIP-8288) This is an EIP that I am hoping we can get included in I-star (the fork after Hegota) that you can think of as the next step after Frames, that would unlock extreme amounts of power. Particularly: * Ultra-cheap quantum-safe signatures (SPHINCS-). Much of the cost savings comes from the fact that the signature data (~3 kB) does not have to go onchain * Ultra-cheap quantum-safe privacy protocols. Status quo minimum cost for private txs is ~300k if you engineer very well (no one does), status quo quantum-safe is ~10M gas, this could reduce it to low tens of thousands. * Universal support for your favorite new signature or proof scheme without needing EVM changes. Whatever you use (Falcon, ML-DSA, some other lattice-based thing, something code-based or isogeny-based or even more esoteric), you can just wrap it client-side in a STARK, onchain gas cost low tens of thousands just like privacy protocols. Hopefully, Ethereum will never need "please support my favorite cryptographic algo" politics again. * Private account abstraction: keep your account logic private, and in a private location onchain. Then you can make one transaction to change the ownership of all your onchain state - accounts, defi positions, privacy protocol notes, everything - without revealing which objects' ownership you're changing. Here's how it works. Your transaction can include a type of frame that we call a "dependency frame". The frame is a list of statements, asserting claims like "message hash M was signed by SPHINCS- public key P" and "data hash D was proven to satisfy a statement defined by verification key V". When you send your transaction, you send it in an envelope, which includes a signature or a STARK for each statement in a dependency frame. Once the transaction reaches the mempool, nodes aggregate them. Each node runs a loop: wait one tick (eg. 500ms), aggregate all new envelopes (either single-tx or multi-tx) that you've seen, remove any transactions that are expired, generate a STARK recursively proving all dependencies, and send a new multi-tx envelope containing that STARK. Hence, the bandwidth load is bounded: each node's outbound is one STARK (~100-300 kB) per tick, plus each transaction getting broadcasted through the network once (as happens already). The block builder acts as "yet another mempool node", receiving envelopes from the mempool (plus any side channels), generates its own STARK covering the subset of transactions it intends to include in the block, and adds that STARK to the block. Total onchain overhead: one STARK (100-300 kB), plus 96 bytes for each statement being proven. This is what I've called before ( ) "The Proof Singularity". Today, we have all the ingredients to actually implement it. As a developer, this requires a somewhat different workflow than you are used to, but it is conceptually simple. Any signatures or STARKs, you put into a separate frame. Then the main logic that today is verifying a signature or STARK, you replace with checking for the existence of a frame that includes the correct statement as a dependency. Examples of useful statements: * [tx sighash] verifies against [the pubkey at sload(0)] * there exists a secret and a merkle branch such that hashing secret+0 and applying the merkle branch outputs (public) root R, and hashing secret+1 outputs (public) nullifier N * there exists a secret address A, salt S and signature Z such that sload(0) = hash(A, S) and a merkle proof of address A inside a recent ethereum state contains some pubkey D where [tx sighash] was signed by D [this is private account abstraction; all variables except [tx sighash] and sload(0) are private; you can also make D a STARK verification key] * there exists an ML-DSA signature signing [tx sighash], that verifies against an ML-DSA pubkey whose hash is sload(0) At the core, this is moving any compute and data other than bookkeeping "business logic" outside the core path of Ethereum execution, sharding and parallelizing it via the mempool. Notice also that this requires agreeing on a _language_ (aka. an ISA) for the recursive STARKs to define statements in. The current leading candidate is RISC-V. So this would also de-facto be Ethereum adding RISC-V (or something else we decide on) as a canonical ISA - a big decision that should be done carefully, but that I think will be necessary to drive Ethereum forward.
显示更多
Welcome Havenex. Series A is underway and closing soon, already applied for all required licenses (even more than required). DM me if interested to invest, note that allocation is already quite packed. After extensive discussions with regulators, central bank governors, Financial Market Authority leadership, banks, family offices, exchanges, wallet providers and custodians, my mission became very clear: Build the most transparent, safest, institutional-grade, fully regulated exchange possible, with continuous, verifiable proofs of solvency. Not just web3. Havenex is not trying to become another Coinbase, Binance, Bybit or Kraken. The focus is different: infra that allows financial institutions to offer digital and traditional financial assets to their customers, while meeting the standards they expect around regulation, custody, security and transparency. My principles are simple: 100% multi-chain. Verifiable custody. Continuous solvency proofs. Multi-sig by default. Quantum-safe keys. Hardware 2FA wallets. Confidential and RWA assets wherever regulation allows. Unique self-custody and key-loss protection mechanisms. Some of the best engineers and experts in cryptography, exchanges and privacy-preserving technology are joining the effort. Havenex will use Sui tech wherever it makes sense, but it will also integrate the best primitives, assets and bridges from other ecosystems. I'm personally helping Havenex as an advisor, although it was my idea. Mysten Labs and Sui remain my focus, nothing changes there. Chief & Hacker team Officer, as always, innovating at daily basis :) As all of you know since my Satoshi days, my goal has always been bigger: help crypto meet regulation without sacrificing ownership, transparency or security, while protecting users against malicious and shady activity and giving the best ecosystems room to thrive. We cannot keep accepting another FTX or Mt. Gox as the cost of doing business, nor the silly, insane bugs driven by LLMs lately. Havenex intends to set a different standard. The most transparent effort in regulatory-friendly crypto. You have my signature.
显示更多
0
38
225
43
转发到社区
Illia on the two types of post quantum cryptography, and which one Near prefers "There's a difference between types of cryptography, so-called lattice based and hash based, and there's a bit of a debate right now in the Web3 space about what should be used, with different tradeoffs" "People are used to signing with their wallet, the traditional way, but if we go to more institutional adoption, people use multi party computation, MPC. That's also what backs Near Intents and a lot of the cross chain work Near is doing. Today we have an announcement that we have a consortium testing multi party computation across custodians, banks and regulators, to showcase how this is going to work in production for real institutional use cases" "This is where we need the social consensus for the whole of Web3 to work together in a reasonable way, because hash based is actually very hard to support with hardware wallets and MPC solutions. So it's important for us that there's consensus on lattice based" "We want to be ahead of the curve and showcase how all of these tools work, and bring it to both individual users and institutional usage. That enables both security and trust in blockchain, which we've seen plummet a bit since post quantum concerns started coming out late last year"
显示更多
My third (and last) post in my series on obfuscation (iO): local mixing Local mixing is a very different philosophy from the other two, no prior background in lattices required, and very different tradeoffs (eg. in terms of computational overhead, it's viable today; the entire question is verifying the security of what's ultimately a novel family of cryptography). I highly encourage following their work, they plan to publish much more soon.
显示更多
0
119
327
38
转发到社区
🚨 Recently, @COLDCARDwallet suffered a major private key vulnerability. Multiple waves of attacks resulted in at least 1,719 BTC (~$111M) in losses, involving over 5,200 addresses. Using Mk3 firmware 4.1.9 as an example, the SlowMist Security Team fully reproduced the attack chain and uncovered the truth behind the theft of thousands of bitcoins. 🧩 Attack flow: 1️⃣ After power-on, the remaining unpredictable state is reduced primarily to a single enumerable 32-bit pad (UID ^ SysTick), with the remaining state values either fixed or coming from very small enumerable spaces. 2️⃣ Attackers precisely model the three typical button-press consumption profiles (retail first-boot, empty-NVRAM, paper wallet) that advance the PRNG before seed generation. 3️⃣ From the weak random_bytes(32), the full deterministic pipeline (SHA-256 → BIP-39 → PBKDF2-HMAC-SHA512 → BIP-32 → address derivation) is reproduced offline. 4️⃣ GPU clusters brute-force the candidate pad space and button-count variations, then match the derived addresses against the global set of single-signature P2WPKH addresses to identify vulnerable wallets and sweep their funds. ⚙️ Root Cause: A build configuration error set MICROPY_HW_ENABLE_RNG to 0, disabling the STM32 hardware TRNG. The random number generation path silently fell back to the non-cryptographic Yasmarang software PRNG, whose state was almost entirely predictable, reducing effective entropy to ~40 bits (Mk2/Mk3) or ~72 bits (Mk4/Mk5/Q). 🔒 SlowMist Insight: Affected users should immediately upgrade to the patched firmware, generate a completely new seed, transfer a small amount of funds as a test, confirm the new address works correctly, then migrate all remaining funds. Full analysis 👉
显示更多
Preparing multi-chain assets for a post-quantum future. Illia Polosukhin explains how NEAR gets there. With Chain Signatures, Bitcoin, Ethereum, Solana, and stablecoins held via NEAR Intents can be secured with post-quantum cryptography and kept confidential, with protocol upgrades handling the transition automatically. Confidential and quantum-resistant. A powerful combination for future-proofing your assets.
显示更多
0
11
208
28
转发到社区