TGViewer
Channel Public Channel
0•Bytes•1

0•Bytes•1

@technical_private_cat

Здравствуй, Нео🎩
Следуй за белым кроликом, не забывая пить таблетки🐇
Тогда ты увидишь удивительные глубины мира ИБ и не только.
Но помни, кроличья нора глубже чем кажется.
Subscribers
3.52K
Photos
86
Videos
1
Links
147
Recent Posts 20 shown
Post #586 790

Forwarded from Tor Zireael

Еще в июле 2026 вышла статья (https://arxiv.org/pdf/2607.07062) по деанонимизации XMR узлов в сети Tor, чем навел достаточно много шума. Сам оригинал статьи можете почитать по ссылке выше, ниже предлагаю ознакомится с ее переводом на русский язык, который выполнил “лягушонок Кермит” с damagelib66*/threads/41867

Также статья дополнена переводом транскрипции с видео https://www.youtube.com/watch?v=CQumGn_M28M что делает материал более полным и интересным.

От себя скажу:
В статье идет речь об атаках на узлы, как локальные так и удаленные, которые подключаются в P2P монеро через Tor, и не просто через Tor, а через Tor к скрытым сервисам, т.е. не способ подключения к узлу посредством Tor, например через RPC узел в .onion, а сам способ monerod публиковать транзу в сеть Monero. Конкретно в данном случае проблемой стало слишком много Tor это плохо, и к примеру если оставить RPC в Tor, но сам узел будет публиковать транзы через P2P Monero сеть без Tor или через Tor, но не скрытые сервисы Tor, то это конкретно описываемую в статье атаку уже будет не провести.

В статье атака нацелена статья на деанонимизацию узлов/нод XMR, для деанонимизации транзакции и IP-адреса узла, это интересно, потому как многие считают что самым надежным способом будет скачать себе блокчейн и локально проводить транзы и чтоб конечно же скрыть IP-адрес кошелька = компьютера = узла, первое что приходит в голову использовать Tor, да еще лучше чтоб это было Tor+Tor (через скрытые сервисы), и именно эта инфраструктура и подпадает под вектор атаки в описываемой статье. Еще добавлю к вектору атаки, что используя локальный узел, им пользуетесь только вы и все транзы с него будут ваши, что добавляет еще проблем. Потому что это выглядит в P2P Monero так: появляется НОВЫЙ узел в 20:00 в сети, с него прилетает 2-3 транзы и в 20:30 он уходит в оффлайн, вот уже можно соединить эти 3 транзы с этим узлом, а теперь еще и можно узнать настоящий IP этого узла, даже если он был скрыт за Tor.

Что плохо в этом всем?
1) узел включается выключается как раз перед транзой
2) все транзы узла = все транзы кошелька
3) ip узла = ip кошелька

Все существующие рекомендации (https://www.youtube.com/playlist?list=PLPDPejqPzKnPlOcKaQtEja-XICMXROLrJ) по использованию XMR остаются актуальны, локальные узлы как были плохи так и остались. Размещайте свой собственный узел, делайте его доступным как через клирнет так и через скрытый сервис, сам же узел должен шарить транзы без Tor в Monero P2P. Подключится к узлу можно как и через Tor, так и через клирнет, и да, другие узлы в сети Monero P2P будут видеть его настоящий IP адрес, адрес этого узла, но через него будут идти не только ваши личные транзы, а и транзы других кто будет им пользоваться, потому что он будет зашарен во все агрегаторы, и будет доступен всегда, а не только тогда, когда вам нужно воспользоваться кошельком. И что главное, так тот факт что узел доступен через RPC скрытого сервиса, это защищает IP адрес всех кошельков которые подключаются к узлу, даже узел не знает их IP.

https://onion.as/840
onion.as Деанонимизация транзакций Monero в сети Tor - onion.as Еще в июле 2026 вышла статья (https://arxiv.org/pdf/2607.07062) по деанонимизации onion XMR узлов в сети Tor, чем навел достаточно много шума. Сам оригинал статьи можете почитать по ссылке выше, ниже предлагаю ознакомится с ее переводом на русский язык, который…
  • ❤ 6
  • 🔥 3
Post #585 1.47K
ai_myths_en.pdf4.3 MB
Hello everyone, my Alices and Cheshire cats! 🐈‍⬛🎀

It's finally done - the article some of you have been waiting for since last year! 🎉

This time I'm debunking the myths
that make people believe their conversations with popular AI are at least somewhat "private" 🫥
We'll look at why that's not true, and how neural networks actually collect your data -from "private mode" to chat deletion and premium subscriptions.

But the most important part isn't just to scare you - it's to show you methods that actually work 🛠 I'll walk through a few approaches I've personally tested that genuinely help reduce the risks, including local models that don't send anything outside your device.

I hope you find this topic as interesting to dive into as I did! ♥️

And if you're into AI topics,
I might soon put together a separate post or short article on AI-related cybersecurity incidents, since there's a lot happening on that front right now 🫠

#ai #anonymity #local_ai #OPSEC #privacy #neural_networks #data_leaks #tools
  • 🔥 13
  • ❤ 2
  • 👍 2
Post #584 2.12K
ai_myths_ru.pdf4.3 MB
Всем привет, мои Алисы и Чеширские котики! 🐈‍⬛🎀

Свершилось - статья, которую некоторые из вас ждали ещё с прошлого года, готова! 🎉

В этот раз я разберу мифы,
из-за которых люди уверены, что их переписки с популярными ИИ хотя бы относительно "приватны".🫥
Разберём, почему это не так, и как именно нейросети собирают ваши данные - от "приватного режима" до удаления чатов и премиум-подписок.

Но самое главное здесь - не просто попугать вас страшилками, а показать рабочие методы для защиты🛠

Я расскажу про несколько проверенных мной лично способов, которые помогают снизить риски, включая локальные модели, которые не отправляют ничего наружу

Надеюсь, вам будет интересно погрузиться в эту тему! ♥️

И да, если тема нейросетей вам понравиться -
возможно, сделаю отдельный пост или небольшую статью про инциденты в кибербезопасности связанные с ИИ, потому что на этом фронте сейчас происходит немало интересного 🫠

#ai #anonymity #local_ai #OPSEC #privacy #neural_networks #data_leaks #tools
  • 🔥 22
  • 💘 2
  • ❤ 1
Post #583

This post (sticker, poll or similar) has no web preview. Open in Telegram

  • 😨 12
  • 🫡 4
  • 🍓 2
Post #582 2.53K

Forwarded from W1R3L355

fckpython.exe11.1 MB
fckpython v0.6.0
- nuitka constants — полный дамп констант из Nuitka блоба: строки, числа, туплы, дикты, code objects, --filter regex, --format json/text/strings
- anti-debug — автоматический поиск и патч IsDebuggerPresent, NtSetInformationThread, CPUID/RDTSC в PE, --dry-run, --patch-all
- decrypt-strings — извлечение ASCII/UTF-16 строк из бинарников + авто-расшифровка base64, XOR (7 ключей), ROT13
- cython — анализ .pyd/.so: PyInit_* экспорты, Python строки, DLL импорты, --pyinit-only, --strings, --format json
- deobfuscate — деобфускация .pyc: dead branches (LOAD_CONST + POP_JUMP), opaque predicates, NOP sequences
- deps — зависимости из PE/.pyc: imports, from-imports, globals/builtins, интересные константы
- nuitka constants --list-modules — быстрый просмотр всех модулей в Nuitka бинарнике
- Безопасный парсинг PE и marshal — больше не крашится на кривых/маллисивных файлах
  • ❤ 8
  • 🔥 2
Post #579 2.08K
Enjoy your tea, Hatters🎩

Today I want to share an interesting project with you: Ermine OS 🗻🦦. It’s a private live system based on Debian, created specifically for secure crypto operations 💲 and anonymous web browsing (for example, visiting forums)🌐.

Here is the repository: https://github.com/ermiusio/ermine_os

In addition to the system itself, the author has written a fairly long article that provides a detailed analysis of popular privacy-focused live distributions.

I particularly liked the breakdown of Tails OS🧅.
It explains the inner workings of the system "related to privacy"⚙️

For example, at the level of systemd services, scripts, and iptables, it shows how the killswitch works. It also covers issues with video memory (yes, this was a known problem, but I hadn't seen a breakdown of it in other reviews before). It even explains why Persistent Storage partially undermines the Tails concept itself and analyzes how application protection is implemented via AppArmor. It's a shame the author didn't go even deeper (for example, looking for backdoors in the source code), but overall, I hadn't seen such a high-quality review in Russian available publicly before.

The article also covers other "private live" systems like Whonix Live, Heads, Kicksecure Live, and so on.

And now about Ermine OS 🦦 itself:
The system runs entirely from a USB drive and writes almost nothing to the disk. All traffic goes exclusively through Tor with a kill-switch (if Tor were to suddenly fail, the network simply shuts down). There is an automatic MAC address and hostname changer. Among the applications, it includes Tor Browser with the author's own Fingerprint Spoofer plugin, a separate browser for I2P🚦, a separate i2pd with a GUI using zenity, and Cake Wallet.

Regarding security: it has custom AppArmor policies for all programs🔒, kernel hardening via sysctl, protection against cold-boot attacks using sdmem, and a completely disabled swap.

Additionally, the author has created an experimental option - RAM-mode which can be selected at boot. In this mode, the system continues to work even after the USB stick is removed, staying entirely within RAM.

The author has also prepared a detailed step-by-step guide on how to build your own live system in the second part of the article, plus they tested the killswitch and other important features.

The project looks quite interesting. Yes, it is still a bit rough around the edges, but as an article with a working example of a private live system, it is already excellent material.
It will be especially useful for beginners who want to build their own distribution for privacy purposes 🧩. There aren't many projects like this with decent articles and guides.

Of course, Heads also has documentation, but it's from 2017 and lacks such an in-depth comparison with other systems.

In general, big thanks to the author
☝️ I don't understand why the repository is still so niche; in my opinion, it deserves much more attention. Alas, the article is written in Russian, and the author did not provide a translation. But I have translated it into English for them; enjoy it🌟

P.S. I only translated the md, the images are not included, but you can view the original tests and images in the github.

I hope you find it useful too ❤️

#anonymous_networks #crypto_protection #browsers #OPSEC #linux #i2p #privacy #tools #tor
GitHub GitHub - ermiusio/ermine_os: Репозиторий объясняет работу приватных дистрибутивов и содержит обзор защищённых ОС. В качестве примера… Репозиторий объясняет работу приватных дистрибутивов и содержит обзор защищённых ОС. В качестве примера выложена Ermine минималистичная Live-система на Debian с kill-switch, AppArmor и усиленным яд...
  • ❤ 8
  • 👍 2
Post #578 2.3K
Приятного чаепития, Шляпники🎩
Сегодня хочу поделиться с вами одним интересным проектом Ermine OS 🗻🦦. Это приватная live-система на Debian, сделанная специально для безопасной работы с криптой 💲и анонимного использования браузера(допустим посищение форумов)🌐.

Репозиторий вот:
https://github.com/ermiusio/ermine_os

Кроме самой системы автор написал довольно большую статью, где подробно разбирает популярные приватные live-дистрибутивы.

Особенно мне понравился разбор Tails OS🧅
Там разобрана внутренния работа системы "связанная с приватностью"⚙️

Допустим на уровне systemd-сервисов, скриптов и iptables показано, как работает killswitch. Хорошо освещены проблемы с видеопамятью(да, это давало известная проблема, но я не видела её разбора в обзорах).
Ещё рассказано почему Persistent Storage частично рушит саму концепцию Tails. И даже разобрано и как устроена защита приложений через AppArmor.
Жаль, что автор не пошёл ещё глубже (например, в поиск закладок в исходниках), но в целом такого качественного обзора на русском в открытом доступе я раньше не встречала.

Также в статье другие "приватные live" вроде Whonix Live, Heads, Kicksecure Live и тд.

А теперь про саму Ermine OS 🦦
Система полностью работает с флешки и практически ничего не пишет на диск. Весь трафик идёт исключительно через Tor с kill-switch(если Tor вдруг упадёт, сеть просто отключится).
Есть автоматическая смена MAC-адреса и hostname. Из приложений там стоит Tor Browser с собственным плагином Fingerprint Spoofer от автора, отдельный браузер для I2P🚦, отдельный i2pd с GUI на zenity и Cake Wallet.

По безопасности там: кастомные политики AppArmor для всех программ🔒, hardening ядра через sysctl, защита от cold-boot атак с помощью sdmem и полностью отключённый swap.

Дополнительно авто сделал и экспериментальную опцию - RAM-mode, который можно выбрать при загрузке. В этом режиме система продолжает работать даже после извлечения флешки внутри RAM.

Ещё Автор подготовил подробное пошаговое руководство по сборке своей live-системы во второй части статьи, плюс протестировал killswitch и другие важные моменты.

Проект выглядит давольно интересно. Да, он ещё немного сыроват, но как статья с рабочим примером приватной live-системы это уже отличный материал.
Особенно полезно будет новичкам, которые хотят собрать свой собственный дистрибутив под приватности 🧩. Подобных проектов с нормальными статьями и руководствами не так много.

Конечно, у Heads тоже есть документация, но она 2017 года и без такого глубокого сравнения с другими системами.

В общем, автору спасибо
☝️ Не понимаю, почему репозиторий до сих пор такой нишевый по-моему, заслуживает куда больше внимания.

Надеюсь, и вам будет полезно ❤️

#anonymous_networks #crypto_protection #browsers #OPSEC #linux #i2p #privacy #tools #tor
GitHub GitHub - ermiusio/ermine_os: Репозиторий объясняет работу приватных дистрибутивов и содержит обзор защищённых ОС. В качестве примера… Репозиторий объясняет работу приватных дистрибутивов и содержит обзор защищённых ОС. В качестве примера выложена Ermine минималистичная Live-система на Debian с kill-switch, AppArmor и усиленным яд...
  • ❤ 9
  • 🔥 4
  • 👍 2
Post #577 1.48K
Hello everyone, my Cheshire cats 🐈‍⬛🌟
I decided to write a little cheat sheet about how generative models like GPT work.

I think it's important to clarify❗️: I will hardly touch on neural network learning. I'll pay more attention to exactly how it generates responses.


How does the neural network perceive our question?
Of course, she doesn't see the words we wrote to her. Text is divided into tokens (pieces words or whole words).
Each token is assigned a vector of numbers🎲. Initially, these vectors are random, but during training they change a lot and are eventually fixed.

During training, the model learns from lot of text to predict the next token by finding patterns between them. After training, she already has sets of weights (ready-made "rules" according to which probabilities are distributed)⚖️


What happens when a model receives a message and prepares to respond?
After receiving the message, the model analyzes the entire context, both the current message and the chat history, if any.

How does the analysis work?
Three basic things are built for each token: query, key, and value.
To put it more clearly, "what do I want to learn from other tokens"🔎, "how can I be found"🗝, and "what information do I offer"🧩

Next, each token compares its request with the keys of other tokens. This comparison takes place through a scalar product. The model measures how well a query for one token matches the key of another👥

For example: in the sentence "mom ate porridge" the "ate" token will most strongly pay attention to "mom" (who performs the action) and "porridge" (what is the object).
Each token updates its state, becoming a mixture of information from the rest of the tokens, taking into account their importance.

To do this, the model first turns similarity scores into attention weights☝️
Then, using softmax, it makes sure that all the weights add up to one and are positive. And only after that it calculates the total weighted sum of values from other tokens.

As a result: "mom" learns possible actions and objects, "porridge" who eats it, and "ate" who participates in the process and what exactly happens.
In other words, the neural network seems to see the general meaning of the phrase, but "from different angles"📷

Naturally, all this happens in parallel in several threads🧠, usually from 8 to 128.
If the calculations were done strictly in turn, it would take too long to generate the answer.

How does the model determine the close context?
After training, numbers arrays (from queries and keys) are generated for each token.
Proximity is calculated based on the similarity of these arrays: the more similar they are, the more closely the tokens are connected🪢 in the current context.


How is the response generated? ✒️
When the representation is formed, the ai does not go through its entire knowledge base. Instead, it calculates the next token within the representation.

The response itself is created using a single token: a new token is added to the context, the entire context is recalculated, and the process repeats. Simply put, with each message, the model receives the history📖 of the dialog and builds a response based on this entire history📝

That's why the new models work with context much better than the old ones, before the advent of transformers🤔
They can just pick up the connections between words at a much greater distance.

It also explains why jailbroken chat😈 continues to work even after a long conversation the chat. However, if you enter the same jailbreak in a new chat, it will most likely be immediately blocked by censorship.

The possibilities of the model are not unlimited.
It has limit on the size of the context window, how many tokens it can process at the same time. When the new models first appeared, it was better.
But now, due to savings, companies are reducing the number tokens💲 available (especially in the free versions, it's much better in the paid versions). Therefore, the context window is getting smaller...😥

#ai #llm #transformers #GPT #attention_mechanism #neural_networks #tokenization
  • ❤ 10
  • 👍 4
  • 🔥 4
Post #576 1.43K
Всем привет, мои Чеширские котики 🐈‍⬛🌟
Я решила написать небольшую шпаргалку о том, как работают генеративные модели вроде GPT 🧬

Думаю важно уточнить❗️: в этой шпаргалке я почти не буду затрагивать обучение нейросети. Больше внимания уделю именно тому, как она генерирует ответы.


Для начала как вообще нейросеть воспринимает наш вопрос?
Конечно же, она не видит просто слова, которые мы ей написали. Сначала текст разбивается на токены (кусочки слов или целые слова).
Каждому токену присваивается вектор чисел🎲. Изначально эти векторы случайные, но во время обучения они сильно меняются и по итогу фиксируются.

Во время обучения модель смотрит на огромные объёмы текста и учится предсказывать следующий токен, находя закономерности между ними. После обучения у неё уже есть наборы весов(готовые "правила", по которым распределяются вероятности)⚖️


А теперь самое главное: что происходит, когда модель получает сообщение и готовится ответить?
Получив сообщение, модель анализирует весь контекст целиком и текущее сообщение, и историю чата, если она есть.

Как происходит анализ?
Для каждого токена строятся три основные вещи: запрос, ключ и значение
.
Если говорить понятнее, то: "что я хочу узнать от других токенов"🔎, "как меня можно найти"🗝 и "какую информацию я предлагаю"🧩

Далее каждый токен сравнивает свой запрос с ключами остальных токенов. Это сравнение происходит через скалярное произведение модель измеряет, насколько хорошо запрос одного токена совпадает с ключом другого👥.

Например: в предложении "мама ела кашу" токен "ела" сильнее всего обратит внимание на "мама" (кто выполняет действие) и на "кашу" (что является объектом).
В этом процессе каждый токен обновляет своё состояние, становясь смесью информации от остальных токенов с учётом их важности.

Для этого модель сначала превращает оценки схожести в веса внимания☝️
Затем с помощью специальной нормализации делает так, чтобы все веса в сумме давали единицу и были положительными. И только после этого вычисляет итоговую взвешенную сумму значений от других токенов.

В итоге: "мама" узнаёт возможные действия и объекты, "каша" кто её ест, а "ела" кто участвует в процессе и что именно происходит.
То есть нейросеть будто видит общее значение фразы, но "с разных ракурсов"📷

Естественно, всё это происходит параллельно в нескольких потоках🧠 обычно от 8 до 128. Если бы вычисления шли строго по очереди, генерация ответа занимала бы слишком много времени.

Как модель определяет близкий контекст?
После обучения для каждого токена формируются массивы чисел (из запросов и ключей).
Близость считается по схожести этих массивов: чем они более похожи, тем сильнее токены связаны🪢 в текущем контексте.


Как генерируется ответ? ✒️
Когда представление сформировано, нейросеть не перебирает всю свою базу знаний. Вместо этого она вычисляет наиболее вероятный следующий токен в рамках представления которое сформировала ранее.

Сам ответ создаётся по одному токену: новый токен добавляется в контекст, весь контекст пересчитывается заново, и процесс повторяется. Проще говоря, при каждом сообщении модель получает историю диалога📖 и строит ответ с учётом всей этой истории📝

Именно поэтому новые модели работают с контекстом гораздо лучше старых, до появления трансформеров🤔 Они просто могут улавливать связи между словами на гораздо большем расстоянии.

Ещё это объясняет, почему джейлбрейкнутый чат😈 продолжает работать даже после долгого общения с моделью. Однако если ввести тот же самый джейлбрейк в новом чате, он, скорее всего, будет сразу заблокирован цензурой.

И конечно, возможности модели не безграничны. У неё есть ограничение на размер контекстного окна сколько токенов она может одновременно обрабатывать. Когда новые модели только появлялись, с этим было получше.
Но сейчас из-за экономии компании сокращают количество доступных токенов💲(особенно в бесплатных версиях, в платных с этим гораздо лучше). Поэтому контекстное окно становится всё меньше...😥

#ai #llm #transformers #GPT #attention_mechanism #neural_networks #tokenization
  • 🔥 13
  • ❤ 9
Post #575 2.39K

Forwarded from Яша просто Яша

https://krebsonsecurity.com/2026/02/kimwolf-botnet-swamps-anonymity-network-i2p/

В течение последней недели масштабный ботнет "Интернета вещей" (IoT), известный как Kimwolf, нарушает работу The Invisible Internet Project (I2P), децентрализованной сети зашифрованной связи, предназначенной для анонимизации и защиты онлайн-коммуникаций. Пользователи I2P начали сообщать о сбоях в сети примерно в то же время, когда ботмастеры Kimwolf стали использовать её для обхода попыток блокировки серверов управления ботнета.

Kimwolf — это ботнет, появившийся в конце 2025 года и быстро заразивший миллионы систем, превратив плохо защищенные устройства IoT, такие как ТВ-приставки, цифровые фоторамки и маршрутизаторы, в ретрансляторы для вредоносного трафика и аномально масштабных распределенных DDoS-атак.

I2P — это децентрализованная сеть, ориентированная на конфиденциальность, которая позволяет людям общаться и обмениваться информацией анонимно.
Krebs on Security Kimwolf Botnet Swamps Anonymity Network I2P For the past week, the massive "Internet of Things" (IoT) botnet known as Kimwolf has been disrupting the The Invisible Internet Project (I2P), a decentralized, encrypted communications network designed to anonymize and secure online communications. I2P users…
  • 🔥 8
  • 🤔 4
Post #574
Channel photo updated
Post #572 2.93K
0•Bytes•1 Good afternoon, my Cheshire cats 🐈‍⬛ Most voted for me to add donations. So here they are, it's purely voluntary, and I'm glad you're reading me anyway ❤️ Wallet links: ETH: 0x23B9319436504f57454aFD864cC9E45DD438FFAb Monero: 4B43PtQ2zWsJvjjJqnUKR9ERRv…
Кстати, по поводу Нового года...
У вашего админа сейчас, мягко говоря, не самые хорошие времена с финансами.

Было бы невероятно здорово, если бы кто-то из вас смог задонатить хоть сколько-нибудь. Это стало бы для меня очень приятным подарком под ёлочку 🌲

Плюс, честно говоря, сильно прибавило бы мотивации писать длинные, статьи и разборы🧩

Но даже если донатов не будет я всё равно очень рада, что вы здесь, читаете, делитесь моими постами. Это уже само по себе огромный подарок🎁

Спасибо вам огромное за то, что вы здесь!❤️
🍪



By the way, about the Holidays..
Your admin is having a hard time financially right now, to put it mildly.

It would be incredibly cool if any of you could contribute anything. It would be a very pleasant gift for me under the Christmas tree🌲

Plus, to be honest, it would greatly increase the motivation to write long articles and reviews.🧩

But even if there are no donations, I am still very glad that you are here, reading, sharing my posts. That in itself is a huge gift🎁

Thank you so much for being here!❤️🍪
  • ❤‍🔥 19
  • ❤ 10
  • 🎄 7
  • 👏 2
  • 😁 1
Post #571 2.37K
Hello, Cheshire cats, and Merry Christmas to you!🐱🎄

Yesterday, just before Christmas, Trust Wallet🛡 gave its users a "gift"🎁

Namely, on December 24, they released a vulnerable wallet extension for Chrome, and on December 25, it turned out to be compromised. As a result, this resulted in losses of over $6 million (including ETH, SOL, and BTC)🫠

The attack took place without user involvement: there was no need to import or interact with suspicious dApps. It was enough for a person to simply open a wallet, and the money was instantly debited, so quickly that the user did not have time to react and cancel the transaction.

I, like many others, quickly determined that it was a supply chain attack, as it occurred suspiciously soon after the update was released🦠
In this attack, the attackers embedded payload in the update. Most likely, through a compromised developer account or insiders🌟

Trust Wallet has not officially disclosed the details of exactly how the attack occurred, but there is information from independent researchers that a malicious script is to blame 4482.js , which masqueraded as analytics.

This code monitored the wallet's activity and was activated at the time of importing the seed phrase or opening the extension with already saved data.

As soon as the seed got into the local storage📱, the script instantly packaged it along with other data (such as private keys and balances) and sent it to a controlled domain. metrics-trustwallet.com this is a newly registered fake website that has already been shut down.

After receiving the seed, the attackers' system automatically generated and signed transactions on behalf of the user🌟
I noticed that the records on the blockchain show the high speed of these transactions: bitcoin, ethereum, and BNB were lost in value, and in all reported cases, funds were transferred almost instantly. After the initial launch, the funds were moved between several wallets🤔

Trust Wallet responded pretty fast: they officially confirmed the incident, emphasizing that the problem affected only the browser extension version 2.68. Mobile applications, desktop and other versions are fine.

Now activists like @zachxbt are investigating exactly what happened, and you can join them, in particular, analyze the addresses and transactions where the funds went🔎

Here is their list:
Ethereum and other EVM networks:

0x3b09A3c9aDD7D0262e6E9724D7e823Cd767a0c74
0x463452C356322D463B84891eBDa33DAED274cB40
0xa42297ff42a3b65091967945131cd1db962afae4
0xe072358070506a4DDA5521B19260011A490a5aaA
0xc22b8126ca21616424a22bf012fd1b7cf48f02b1
0x109252d00b2fa8c79a74caa96d9194eef6c99581
0x30cfa51ffb82727515708ce7dd8c69d121648445
0x4735fbecf1db342282ad5baef585ee301b1bce25
0xf2dd8eb79625109e2dd87c4243708e1485a85655


Bitcoin:
bc1qjj7mj50s2e38m4nn7pt2j0ffddxmuxh2g8tyd8
bc1ql9r9a4uxmsdwkenjwx7t5clslsf62gxt8ru7e8
bc1q4g8u7kctk6f2x3f6nh43x76qm4fd0xyv3jugdy
bc1qw7s35umfzgcc7nmjdj9wsyuy9z3g6kqjr0vc7w
bc1qgccgl9d0wzxxnvklj4j55wqeqczgkn6qfcgjdg
bc1q3ykewj0xu0wrwxd2dy4g47yp75gxxm565kaw6


Solana:
HoQ6z1wW3LUnEGHnseC3ND3PoC6i6RghMCphHhK42FEH

In the end, I'll give you some advice🛠: alas, browser extensions even from the official developers of the most reliable wallets can pose a threat. Therefore, for large amounts, switch to hardware wallets, check for updates manually, and never import a seed phrase into browser plugins🔒❤️

That's all that's known at the moment✒️
Let's see how the situation develops and how Trust Wallet reacts to this incident, especially given the relatively recent incident on Binance (which Trust Wallet owns).

#blockchain #bitcoin #crypto #crypto_wallet #crypto_protection #cve #web #attacks #news #chrome_extension #Trust_Wallet #supply_chain
X (formerly Twitter) Akinator | Testnet Arc (@0xakinator) on X @TrustWallet So here’s what’s happening : In the Trust Wallet browser extension code 4482.js a recent update added hidden code that silently sends wallet data outside It pretends to be analytics…
  • ❤‍🔥 5
  • 🔥 3
  • ❤ 2
Post #570 1.49K
Привет, Чеширские котики и с Рождестаом вас!🐱🎄

Вчера, прямо накануне Рождества, Trust Wallet
🛡 устроили своим пользователям "подарок" 🎁

А именно: 24 декабря они выпустили уязвимое расширени кошелька для Chrome, а уже 25 декабря оно оказалось скомпрометировано. В итоге это привело к потерям на сумму более 6 миллионов долларов (включая ETH, SOL и BTC)🫠

Атака происходила без участия пользователя: даже не нужно было импортировать или взаимодействовать с подозрительными dApps. Человеку достаточно было просто открыть кошелёк, и деньги мгновенно списывались, так быстро, что пользователь не успевал отреагировать и отменить транзакцию.

Я, как и многие другие, быстро определила, что это была supply chain attack, поскольку она произошла подозрительно скоро после выпуска обновления🦠
В этой атаке злоумышленники внедрили payload в обновление. Cкорее всего, через скомпрометированный аккаунт разработчика🌟

Официально Trust Wallet не раскрыли детали, как именно произошла атака, но есть информация от независимых исследователей, что виноват вредоносный скрипт 4482.js, который маскировался под аналитику.

Этот код отслеживал активность кошелька и активировался в момент импорта сид-фразы или открытия расширения с уже сохранёнными данным

Как только seed попадала в локальное хранилище📱, скрипт мгновенно упаковывал её вместе с другими данными (типа приватных ключей и балансов) и отправлял на подконтрольный домен metrics-trustwallet.com, это свежезарегистрированный фейковый сайт, который уже выключили.

Получив seed, система злоумышленников автоматически генерировала и подписывала транзакции от имени пользователя🌟
Я заметила что записи на блккчене показывают высокую скорость этих транзакций: биткоин, эфириум и BNB терялись в цене, и во всех зарегистрированных случаях средства переводились почти мгновенно. После первожа средства перемещались между несколькими кошельками🤔

Trust Wallet пореагировали довольно быстро: они официально подтвердили инцидент, подчеркнув, что проблема затронула только браузерное расширение версии 2.68. Мобильные приложения, десктоп и другие версии в порядке.

Сейчас активисты вроде @zachxbt исследуют, что именно произошло, и вы можете к ним присоединиться, в частности, проанализировать адреса и транзакции, куда ушли средства🔎

Вот их список:
Ethereum и другие EVM-сети:

0x3b09A3c9aDD7D0262e6E9724D7e823Cd767a0c74
0x463452C356322D463B84891eBDa33DAED274cB40
0xa42297ff42a3b65091967945131cd1db962afae4
0xe072358070506a4DDA5521B19260011A490a5aaA
0xc22b8126ca21616424a22bf012fd1b7cf48f02b1
0x109252d00b2fa8c79a74caa96d9194eef6c99581
0x30cfa51ffb82727515708ce7dd8c69d121648445
0x4735fbecf1db342282ad5baef585ee301b1bce25
0xf2dd8eb79625109e2dd87c4243708e1485a85655


Bitcoin:
bc1qjj7mj50s2e38m4nn7pt2j0ffddxmuxh2g8tyd8
bc1ql9r9a4uxmsdwkenjwx7t5clslsf62gxt8ru7e8
bc1q4g8u7kctk6f2x3f6nh43x76qm4fd0xyv3jugdy
bc1qw7s35umfzgcc7nmjdj9wsyuy9z3g6kqjr0vc7w
bc1qgccgl9d0wzxxnvklj4j55wqeqczgkn6qfcgjdg
bc1q3ykewj0xu0wrwxd2dy4g47yp75gxxm565kaw6


Solana:
HoQ6z1wW3LUnEGHnseC3ND3PoC6i6RghMCphHhK42FEH

Под конец дам вам совет🛠: увы, расширения браузеров даже от официальных разработчиков самых надёжных кошельков могут нести угрозу. Поэтому для крупных сумм переходите на аппаратные кошельки, проверяйте обновления вручную и никогда не импортируйте сид-фразу в браузерные плагины🔒❤️

Это пока всё, что известно на данный момент✒️ Посмотрим, как будет развиваться ситуация и как отреагирует Trust Wallet на этот инцидент особенно с учётом относительно недавнего инцендента на Binance(которым владеет Trust Wallet).

#blockchain #bitcoin #crypto #crypto_wallet #crypto_protection #cve #web #attacks #news #chrome_extension #Trust_Wallet #supply_chain
X (formerly Twitter) Akinator | Testnet Arc (@0xakinator) on X @TrustWallet So here’s what’s happening : In the Trust Wallet browser extension code 4482.js a recent update added hidden code that silently sends wallet data outside It pretends to be analytics…
  • ❤ 7
  • ❤‍🔥 6
  • 🔥 2
  • 💋 2
  • 👨‍💻 1
Post #569
Channel photo updated
Post #568 2.87K
2507.05558v3.pdf1.7 MB
How does A1 work?🛠
First, the tool loads the contract code:
its ABI (an interface that describes which functions can be called) and up-to-date blockchain data: balances, transactions, and network status. This is important because the vulnerability may depend on the number of tokens on the contract or recent transactions.

Then the system analyzes the code🔎: it examines the structure, functions, and variables, and looks for suspicious places. For example, A1 may detect a function that does not check the caller, or logic that allows the function to be called again before the state is updated.

When a vulnerability is found, the fun begins: A1 creates an exploit✏️
Let's say she discovered reentrancy. A1 then generates an attacking smart contract that invokes the vulnerable function in a loop.

This code is being tested in a blockchain simulation, for example, on a local Ethereum node, to see if the attack will work. If the attack is successful, A1 estimates the profit: how many tokens or ether can be withdrawn and how this correlates with gas costs.

If the result is positive, the exploit is saved as a proof-of-concept, a ready-made example of an attack🧪

However, A1 is not limited to one scenario. If the analysis reveals a suspicious function, the system tries different ways of operation: it changes parameters, the order of calls, and combines functions. If the attack did not work, A1 searches for the cause and tests a different approach.

The article states that A1 found vulnerabilities in real contracts that were missed by tools like Mythril and Slither. She even identified bugs that required complex attacks, such as manipulating oracles or using flash credits💸

In general, for those who want to dig even deeper, take a look at the article there is code, examples of attacks and details, for example, how A1 works with EVM ❤️

#smart_contract #crypto #crypto_protection #attacks #pentest #explication #neural_networks
  • ❤‍🔥 8
  • 🍌 4
  • ❤ 3
  • 🔥 1
Post #567 2.05K
Hello, Cheshire cats! 😁

I recently came across an interesting article about how AI is used to find vulnerabilities in smart contracts and write real exploits 🔹🧬

First, let's look at what smart contracts are
These are programs that run on the blockchain and manage assets, tokens, etc. Contracts are usually written in Solidity for the Ethereum network or other blockchains like Binance Smart Chain.

The problem is that these contracts often contain a bunch of legacies and also have bugs 💊
Errors can range from incorrect logic to vulnerabilities that allow attackers to steal tokens. For example, in 2024 there was a case with the Penpie protocol when $27 million in Eth was stolen due to a reentrancy vulnerability.

There are several ways to find such problems🔑
The first way is to use tools like fuzzers that search for vulnerabilities based on predefined patterns. However, complex attacks, such as manipulation of MEV (maximum recoverable value) or reentrancy (re-entry), are usually not found by such tools. The second way is to hire auditors who manually check the code. But it is expensive and takes a lot of time.

The article described a new approach⚙️ Researchers have developed the A1 system, which uses an AI language model with six tools.🛠 These tools are needed for A1 to find vulnerabilities in smart contracts and check if they can be exploited, or if this is a false positive.

P.S
I also found some similar tools on GitHub:
IAcontract: A tool for finding vulnerabilities in smart contracts. He makes reports with examples of exploitation. Similar to A1, with an emphasis on automation and convenience for developers.

Automated-Vulnerability-Scanning-with-Agentic-AI: Here, several AI agents work together to find vulnerabilities.

Aether: A framework for deep analysis of smart contract code to find unconventional vulnerabilities, as A1 does.

#smart_contract #tools #crypto #crypto_protection #attacks #pentest #explication #neural_networks
  • ❤‍🔥 6
  • 🔥 3
  • 🍌 3
  • ❤ 2
Older posts →

About this channel

How can I read @technical_private_cat without a Telegram account?
TGViewer shows the public web preview Telegram publishes for 0•Bytes•1: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does 0•Bytes•1 have?
0•Bytes•1 (@technical_private_cat) has 3.52K subscribers on Telegram, refreshed roughly every 30 minutes.
Does 0•Bytes•1 know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →