Tay πŸ’– Profile picture
Aug 28, 2020 β€’ 4 tweets β€’ 2 min read β€’ Read on X
I love Dan and folks like @mcutler who take the time to write this shit up in glorious detail.

Another lesson: people w deep niche expertise don't get crazy loud w what they know to be true. It can be weird bc they do yell about theoretical specs. Inverse them both. Then, run πŸ˜‚ ImageImageImage
Related readings bc this topic is endlessly fascinating.

β€’ β€’ β€’

Missing some Tweet in this thread? You can try to force a refresh
γ€€

Keep Current with Tay πŸ’–

Tay πŸ’– Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @tayvano_

Oct 18
I went through the addresses in the MilkSad list for this specific vuln to see what else was there.

There's 64 addresses in this batch.

The Chen Zhi/Lubian addresses were the only ones with real balances at the time.

Meaning: it wasn't like someone was picking and choosing. Image
For reference, the research + dataset I'm referencing here is:

milksad.info/posts/research…

git.distrust.co/milksad/data/s…

I'll break down the different activity for these addresses.
Cluster 1: the 25 addresses in the forfeiture



Pretty simplejustice.gov/usao-edny/medi…Image
Read 14 tweets
Jul 18
This first witness in Roman's trial immediately caught my attention bc the victim was a classic Pig Butchering case.

The only issue is....uh.....those scammers don't use Tornado Cash? And they never have?

So, like, wtf?
I'm not talking out of my ass here.

My team and I have talked to thousands of these victims. We've tracked nearly a billion dollars stolen on Ethereum.

We have a dashboard for all known victims of the "Approval" variant of this scam btwn 2021-2023.

dune.com/tayvano/sha-zh…
So..why did this victim end up on the stand in the Tornado trial?

Simple question. Insane journey of an answer.

It all starts with a dude on WhatsApp/Line and a website "NTU Capital."

He makes promises. She wires $250k. The money goes *poof.*

therage.co/tornado-cash-d…
Read 25 tweets
Feb 22
People keep calling this is the "largest crypto hack ever" but I think it might be the largest hack ever....period?
Bangladesh Bank Heist (also DPRK 🫠) was *almost* $1 billy ($951m) But....

1. There was a lil glitchy so they only got $100m out initially and then $20m was quickly recovered. Total loss ended up being ~$81m.

2. Bybit Hack is bigger than that either way

bbc.com/news/stories-5…
Carbanak thefts (2013-2015) were maybe ~$1 billy when it was all said and done. But...

1. It was a series of hacks against different banks over a couple years.

2. That's more like saying all of DPRK's crypto or SWIFT heists were a single theft.

3. Bybit Hack is bigger than that.

4. $4B-$5B (DPRK's crypto thefts) is also bigger than that.

web.archive.org/web/2015022001…
Read 8 tweets
Jan 8
That's a lot of Single Points of Failure. 😳
Single Point of Failure: The API Image
Single Point of Failure: The Binary Image
Read 10 tweets
Dec 28, 2024
🚨 Heads up allβ€”some dudes have a slick, new way of dropping some nasty malware.

Feels infostealer-y on the surface but...its not.🫠

It'll really, deeply rekt you.

Pls share this w/ your friends, devs, and multisig signers. Everyone needs to be careful + stay skeptical. πŸ™Image
If you get hit with this, you need to wipe your computer. Esp. if your wallets haven't been drained.

Shoot SEAL-911 a message @ and we will help you assess -> next steps.

p.s. mention 'Willo' so we can help you faster (holidays, ppl are afk, etc.)t.me/seal_911_bot
How it works / what we've seen:

Usually starts with a "recruiter" from known company e.g. Kraken, MEXC, Gemini, Meta.

Pay ranges + messaging style are attractiveβ€”even to those not actively job hunting.

Mostly via Linkedin. Also freelancer sites, job sites, tg, discord, etc.Image
Read 10 tweets
Dec 22, 2024
DPRK's trading career is...uh....going.....πŸ™ˆ

tbh if i was the dude managing Hyperliquid's 4 validators (or those fucking ghetto ass binaries on gh) I would be shitting my pants right now.

Hyperliquid dudes dont seem worried at all though so im sure its fine. 🫠 Image
lol @ all you retards who think the risk is USG forcing Hyperliquid to freeze AAAAAAAAAAHHAHAHHHAHAHAHAHAHAHHAHHAHAHHAHAHHAHAHAHAHHAHAHHAHAHHAHAHAHHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHHAHAHAHAHHAHAHAHAHAHAAHAHHAHAHAHHAHAHAHHAHAHAHA

Yall, DPRK doesn't trade. DPRK tests.πŸ€¦β€β™€οΈ
my offer from 2 weeks ago still stands @HyperliquidX

i'm still happy to do it async or via a call. i can even give you one of my super nice happy colleagues if you don't like me.

but a massive amt of harm will come to people if you don't harden your ass asap. Image
Read 4 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(