zak.eth Profile picture
serving eth holders @ethcforg
Sep 15 23 tweets 7 min read
🚨 I was just targeted in a sophisticated phishing attempt that almost got me.

But I got the scammer on a live call (video recording below), strung him along, and trolled him with Kim Jong Un gay porn while dissecting his $3k/month malware kit.

Buckle up, this gets wild. 🧵👇 2/21

It all started with a Twitter DM to "Join our podcast!"

The attacker (@0xMauriceWang) posed as someone from @theempirepod. Looked legit after a brief skim so I agreed. Then came an email from studio@theempirepodcast.com with a @StreamYard link. Text said streamyard.com but hyperlinked to streamyard.org.

See the trap?Image
Image
Aug 14 15 tweets 3 min read
SECURITY THREAD: Your .env file WILL get you drained (here's how to not be next) 🧵 👇

Private keys in .env files will get you rekt. It's not if, but when. You're one extension away from $0.

The time between my PK leak to drain: 27 minutes. 2/ .env is PLAINTEXT. Your cat can read it. So can any process on your machine. That helpful AI coding assistant? It's reading your .env. That new Solidity formatter with 50k downloads? It's reading your .env.

youtube.com/shorts/dd4o6C6…
Aug 13 16 tweets 4 min read
🚨 UPDATE: Full Post-Mortem On Cursor Security Incident

In yesterday’s thread I explained how I got drained after installing a malicious extension in @cursor_ai.

This is the deeper dive into what I found, what I did, and how you can avoid it.

🧵 👇 1/ This isn't just about Cursor and it’s not a PSA about vibe coding. This is about IDE extensions and it affects everyone who uses one. Also, think it won’t affect you because you use Vim/Neovim plugins? You’re wrong. They can also call ext servers to execute arbitrary code.
Aug 12 20 tweets 3 min read
I've been in crypto for over 10 years and I’ve Never been hacked. Perfect OpSec record.

Yesterday, my wallet was drained by a malicious @cursor_ai extension for the first time.

If it can happen to me, it can happen to you. Here’s a full breakdown. 🧵👇 1/ Background: I'm obsessive about security. Hardware wallets, segregated hot wallets, unique passwords, 2FA everything.

In 10+ years, I have never lost a single wei to hackers.

Then I rushed to ship a contract last week.
Mar 14 10 tweets 2 min read
Ethereum is bleeding value to L2s. Rollups extract fees, MEV, and liquidity while ETH stakers get left behind. If this keeps up, Ethereum becomes a dumb security layer while L2s print money. Does this sound like a decent model for fixing it? 🧵👇 2/ Rollups extract fees, MEV, and liquidity while ETH stakers get left behind. If this keeps up, Ethereum becomes a dumb security layer while L2s print money.