TGViewer
crab notes 🦀 lobsterdao crab notes 🦀 lobsterdao @crab_notes · 8.06K subscribers
Post #931 3.85K
​​🧠 [Long Research] Topic: Fucking around with keys is a bad idea!

Migrate your seed to another hot wallet: no.
Migrate your keys from ledger to metamask: no.
Fuck around with seed generation: no!

💡 This news piece is not new-new. It's more of a wake-up call, based on recent recent information on how big the numbers were. Stop using unsafe systems if switching costs are so low! Changing a 2FA app or sending a few coins to the a address isn't hard at all…

Remember the GCR tweet from a couple of years ago? It says that even if you hold some of the good assets, a gazillion non-economic attack vectors can mess you up: your mobile phone security is weak, your keys will get lost, your seed phrase sheet will get seen by a random person, etc. There is no need to be a security junkie, but at least don't hold 7 figures in a phone app LoL 😰 like the atomic sers below.

It's not even about wrenches or sophisticated attacks, it's just common sense. For instance, a friend of mine almost lost their seed phrase from their Metamask when the laptop was broken... "I just never took the time to save the phrase after 6 months of daily trading". Another one had a similar situation, despite being knowledgeable about security. It's just negligence; it's not rocket science.

And just yesterday 👀 yet another Profanity thing came to light, unfortunately affecting KP3R, see the post-mortem. An attacker got hold of the governor of a whitelisted job in Keep3rNetwork v1. Tthe governor address was generated via Profanity, making it vulnerable.

Again: fuck around with cryptography, find out. Similar to fucking around with oracles in DeFi.

-> Back to the hack summary of Atomic Wallet
NEW 🔥 more losses were found, reaching $100M . See fresh Tay's thread.

The breach started on June 2, with reports of assets disappearing from users' wallets surfacing on June 3. The largest victim of the hack was on Tron, with 7.95 million USDT stolen, and the total losses amount to $35+ million. The stolen funds were converted into Bitcoin (BTC) and then laundered through a mixer called Sinbad, favored by the North Korean hacker cell Lazarus. Ahhh, it's all Lazarus isn't it…

The exact cause of the hack is still unknown, causing concern for the over a million users who may still be vulnerable. One theory suggests that a malicious update transferred users' private keys to the perpetrator when they opened the app. Atomic Wallet's security has been questioned before, and an audit conducted in 2021 raised concerns. Who says Trust Wallet or any other closed source wallet or extension doesn't suffer the same…

Software wallets, like Atomic Wallet, are considered fundamentally flawed, as they can be compromised easily. These recent incidents highlight the need for better security in the crypto community. To mitigate risks, it is recommended to trust open-source wallets, diversify holdings, and remember the importance of controlling your keys. And not by generating through weird apps! Stay safu, crabs 🦀

For more info:
- Thread by ZachXBT
- Visual & thread by Tay

PS: sumimasen, we were swamped with work for a few days, back to slow writing again.
  • 🔥 9
  • 👍 7
  • ❤ 2
  • 😱 1
  • 👌 1
  • 🐳 1
More from @crab_notes
  1. Aug 6, 2026Sooooo, the issuance reduction debate… 💠 My journey with this topic started with a “this…
  2. May 28, 2026A few weeks ago, in Cannes, we hosted two full days of DeFi roundtable sessions with 7️⃣0️…
  3. Sep 25, 2025New longread 🧰 "HUMBLE ft Gearbox Protocol" Today's piece is about the shift in DeFi valu…
  4. May 15, 2025In 2019, almost every VC said "F*ck tokens, we want equity. Tokens were a mistake!" A year…
  5. Aug 29, 2024Ethereum Twitter fights of the past week(s) got me to write on a broader topic... Did anyo…
  6. Apr 30, 2024Modular Lending / Modular Leverage Some thoughts about the lending space and modularity: 1…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →