Sign in

AccessDenied403

@ad403.bsky.social
71 followers 186 following 29 posts

Share my learning journey in the field of Blockchain, Crypto and Web3. Security Engineer at taurushq.com See my blog rya-sge.github.io/access-denied

PostsRepliesMedia
AccessDenied403 @ad403.bsky.social · 23/09/2026
September 22 More than $1 billion in BTC was sent in a single block. The average transaction was 3.3366 BTC, worth approximately $288,364. See www.blockchain.com/explorer/blo...
Bitcoin Block 968,052
000
AccessDenied403 @ad403.bsky.social · 24/07/2026
CMTA has released CMTAT Confidential: tokenize an asset or issue a stablecoin with the amounts kept private. Built on CMTAT Solidity for compliance and OpenZeppelin's ERC-7984 for confidential tokens. v1.0.0 audited by OpenZeppelin, sponsored by Zama. github.com/CMTA/CMTAT-C... #tokenization #FHE
github.com
GitHub - CMTA/CMTAT-Confidential: Version of CMTAT supporting encrypted balances via Zama FHE.
Version of CMTAT supporting encrypted balances via Zama FHE. - CMTA/CMTAT-Confidential
000
AccessDenied403 @ad403.bsky.social · 30/06/2026
How do you add on-chain compliance without modifying the token contract? Chainlink ACE is now integrated into the open-source CMTAT framework, enabling policy-based compliance and access control. Implementation on GitHub: github.com/CMTA/CMTAT-ACE #tokenization #ethereum
github.com
GitHub - CMTA/CMTAT-ACE: CMTAT version for Chainlink ACE
CMTAT version for Chainlink ACE. Contribute to CMTA/CMTAT-ACE development by creating an account on GitHub.
000
AccessDenied403 @ad403.bsky.social · 06/05/2026
Nethermind implemented a way to represent FIX (Financial Information eXchange) data on-chain using deterministic encoding and a Merkle root commitment instead of storing raw messages. This enables efficient verification of structured trade data without on-chain parsing. github.com/CMTA/CMTAT-FIX
github.com
GitHub - CMTA/CMTAT-FIX: Integration of FIX descriptor support for CMTAT
Integration of FIX descriptor support for CMTAT. Contribute to CMTA/CMTAT-FIX development by creating an account on GitHub.
060
AccessDenied403 @ad403.bsky.social · 30/04/2026
Glad to have made my first PR on the Ethereum repository related to ERC-1404, a tokenization standard that has so far only been represented as a GitHub issue dating back to 2018. github.com/ethereum/ERC...
github.com
Add ERC: Simple Restricted Token by rya-sge · Pull Request #1701 · ethereum/ERCs
One of the standards which often appear in tokenization report and also used by Centrifuge, CMTAT and TokenSoft is ERC-1404. ERC-1404 is one of the oldest tokenization standard on Ethereum (2018) d...
020
AccessDenied403 @ad403.bsky.social · 17/03/2026
Enabling cross-chain token transfers with CMTAT and LayerZero. ERC-7802 & ERC-3643 supported. Code available on GitHub: github.com/CMTA/CMTAT-L...
github.com
GitHub - CMTA/CMTAT-LayerZero: This repository contains example of how CMTA Token can be bridged with LayerZero
This repository contains example of how CMTA Token can be bridged with LayerZero - CMTA/CMTAT-LayerZero
000
AccessDenied403 @ad403.bsky.social · 06/02/2026
"The problem is that clicking on the link to that web page is enough to trigger a cross-site WebSocket hijacking attack because OpenClaw's server doesn't validate the WebSocket origin header." thehackernews.com/2026/02/open...
thehackernews.com
OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link
A high-severity OpenClaw flaw allows one-click remote code execution via token theft and WebSocket hijacking; patched in v2026.1.29.
000
AccessDenied403 @ad403.bsky.social · 03/02/2026
Prompt injection and RCE in Qodo Merge, an open-source AI code review tool. Great write-up! kudelskisecurity.com/research/qod...
kudelskisecurity.com
How We Exploited Qodo: From a PR Comment to RCE and an AWS Admin Key - Leaked Twice - Kudelski Security Research Center
Jan 15, 2026 - Nils Amiet -
000
AccessDenied403 @ad403.bsky.social · 02/02/2026
"The attack involved infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org. The incident began from June 2025 until December" Recommend version: v8.9.1 notepad-plus-plus.org/news/hijacke...
notepad-plus-plus.org
Notepad++ Hijacked by State-Sponsored Hackers | Notepad++
000
AccessDenied403 @ad403.bsky.social · 26/01/2026
"The North Korean threat actor known as Konni has been observed using PowerShell malware generated using artificial intelligence (AI) tools to target developers and engineering teams in the blockchain sector." thehackernews.com/2026/01/konn...
thehackernews.com
Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers
North Korean group Konni uses AI-assisted PowerShell malware and phishing via Google ads and Discord to breach blockchain development environments.
020
Reposted by AccessDenied403
BleepingComputer @bleepingcomputer.com · 20/01/2026
Using only natural language instructions, researchers were able to bypass Google Gemini's defenses against malicious prompt injection and create misleading events to leak private Calendar data.
bleepingcomputer.com
Gemini AI assistant tricked into leaking Google Calendar data
Using only natural language instructions, researchers were able to bypass Google Gemini's defenses against malicious prompt injection and create misleading events to leak private Calendar data.
1124
AccessDenied403 @ad403.bsky.social · 20/01/2026
ERC-1643, part of ERC-1400, is one of the oldest tokenization related standard on Ethereum (2018) developed by PolymathNetwork. It allows to manage on-chain document which is very useful for tokenization and RWA. More information on the Ethereum magician forum: ethereum-magicians.org/t/erc-1643-d...
ethereum-magicians.org
ERC-1643: Document Management Standard (ERC-1400)
This ERC allows documents to be associated with a smart contract and a standard interface for querying / modifying these contracts, as well as receiving updates (via events) to changes on these docume...
000
AccessDenied403 @ad403.bsky.social · 19/12/2025
The latest release of CMTAT Solidity (v3.1.0), a security token framework for on-chain RWA, includes now Chainlink CCIP support for seamless cross-chain transfers. Available on GitHub
github.com
GitHub - CMTA/CMTAT: Reference Solidity implementation of the CMTAT security token framework developed by CMTA to tokenize financial instruments.
Reference Solidity implementation of the CMTAT security token framework developed by CMTA to tokenize financial instruments. - CMTA/CMTAT
000
AccessDenied403 @ad403.bsky.social · 09/12/2025
How do you tokenize RWAs on Solana? CMTA just released a new specification leveraging the Token Extensions Program (Token-2022). Now available on GitHub: github.com/CMTA/CMTAT-S... Glad to have contributed through my work at Taurus
github.com
GitHub - CMTA/CMTAT-Solana: Solana version of CMTAT
Solana version of CMTAT. Contribute to CMTA/CMTAT-Solana development by creating an account on GitHub.
000
AccessDenied403 @ad403.bsky.social · 26/11/2025
Tracking the latest NPM supply-chain attack (“Shai Hulud”): • Socket: socket.dev/blog/shai-hu... • Aikido: www.aikido.dev/blog/shai-hu...
socket.dev
Shai Hulud Strikes Again (v2) - Socket
Another wave of Shai-Hulud campaign has hit npm with more than 500 packages and 700+ versions affected.
000
Reposted by AccessDenied403
Quarkslab @quarkslab.bsky.social · 19/11/2025
Quarkslab engineers Robin David, Mihail Kirov and Kaname just completed the first public security audit of Bitcoin Core, led by @ostifofficial.bsky.social and funded by Brink.dev Details on the blog post: blog.quarkslab.com/bitcoin-core... Congrats to developers for such software masterpiece !
blog.quarkslab.com
Bitcoin Core audit - Quarkslab's blog
The Open Source Technology Improvement Fund, Inc. mandated Quarkslab to perform the first public security audit of Bitcoin core, the reference open-source implementation of the Bitcoin decentralized p...
065
AccessDenied403 @ad403.bsky.social · 18/11/2025
Great YouTube playlist to learn more about Hash-Based quantum-safe signature schemes (LMS, XMSS and SPHINCS+). www.youtube.com/watch?v=pt5W... #cryptography
youtube.com
Lecture 1. Introduction (Hash-Based Signatures)
YouTube video by Cryptography 101
010
AccessDenied403 @ad403.bsky.social · 12/11/2025
Coinbase Security series: what is MPC and how to use it for Key Management: youtu.be/qdhM3syDkxM #cryptography
youtu.be
Coinbase Security Series: Open Source MPC Key Management
YouTube video by Base
000
AccessDenied403 @ad403.bsky.social · 01/10/2025
Breaking server SGX via DRAM bus: wiretap.fail
wiretap.fail
WireTap: Breaking Server SGX via DRAM Bus Interposition
Breaking Server SGX via DRAM Bus Interposition
010
AccessDenied403 @ad403.bsky.social · 09/09/2025
See also www.aikido.dev/blog/npm-deb... and www.securityalliance.org/news/2025-09...
aikido.dev
npm debug and chalk packages compromised
The popular packages debug and chalk on npm have been compromised with malicious code
010
AccessDenied403 @ad403.bsky.social · 28/08/2025
"The malware did more than just steal SSH keys, npm tokens, and .gitconfig files - it weaponized AI CLI tools (including Claude, Gemini) to aid in reconnaissance and data" www.stepsecurity.io/blog/supply-...
stepsecurity.io
000
AccessDenied403 @ad403.bsky.social · 13/07/2025
Algebraic intermediate Representation (AIR) for Blake Hash youtu.be/INtBA-9vJpU?... hackmd.io/@starkware-h...
youtu.be
Stav Beno (starkware) - From Design to Benchmarking: BLAKE Hash AIR for the Stwo Prover
YouTube video by [EthCC] Livestream 6
000
AccessDenied403 @ad403.bsky.social · 01/07/2025
Coinbase MPC wallet library presentation at EthCC m.youtube.com/live/ppeyz_J...
m.youtube.com
Yehuda Lindell (Coinbase)_Coinbase's cb-mpc Open-Source Library
YouTube video by [EthCC] Livestream 4
021
AccessDenied403 @ad403.bsky.social · 29/06/2025
My last article about ERC-20 ConditionalTransfer is available on Taurus blog: www.taurushq.com/blog/tokeniz... Based on CMTAT, an open-source project: github.com/CMTA/CMTAT #solidity
taurushq.com
Taurus Blog - Conditional Transfers with CMTAT & Taurus-CAPITAL: A Step-by-Step Guide
Conditional Transfers with CMTAT & Taurus-CAPITAL: A Step-by-Step Guide
120
Reposted by AccessDenied403
BleepingComputer @bleepingcomputer.com · 27/04/2025
Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised.
bleepingcomputer.com
Coinbase fixes 2FA log error making people think they were hacked
Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised.
031
Reposted by AccessDenied403
BleepingComputer @bleepingcomputer.com · 16/04/2025
MITRE Vice President Yosry Barsoum has warned that U.S. government funding for the Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE) programs expires today, which could lead to widespread disruption across the global cybersecurity industry.
bleepingcomputer.com
MITRE warns that funding for critical CVE program expires today
MITRE Vice President Yosry Barsoum has warned that U.S. government funding for the Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE) programs expires today, which could lead to widespread disruption across the global cybersecurity industry.
0118
AccessDenied403 @ad403.bsky.social · 02/04/2025
NFTs are used to represent unique items on the blockchain. As you may know, the most known standard on Ethereum is ERC-721. Since its creation, several other standards (ERC-1155, ERC-2981, ERC-4907,...) have emerged to meet various use cases. More details here: rya-sge.github.io/access-denie...
rya-sge.github.io
Ethereum NFT Standards: ERC-721, ERC-1155, ERC-6551, and More
Non-Fungible Tokens (NFTs) enable unique, verifiable ownership of digital and real-world items on the blockchain. While ERC-721 remains the main standard to represent NFTs on Ethereum and EVM blockcha...
020
AccessDenied403 @ad403.bsky.social · 27/03/2025
Ledger's article on the security and integrity of the Trezor Safe 3 crypto wallet firmware is a great read to better understand how the new Trezor models (Safe Family) work (Secure Element, firmware integrity, chips used) www.ledger.com/why-secure-e... blog.trezor.io/trezors-mult...
ledger.com
Why Secure Elements make a crucial difference to Hardware Wallet Security | Ledger
In contrast with the previous generations of Trezor devices, which the Ledger Donjon showed to be vulnerable to physical seed recovery attacks, the Trezor Safe line of products brings huge security im...
000
AccessDenied403 @ad403.bsky.social · 25/03/2025
How to tokenize on Ethereum and EVM based blockchain? My last article on Taurus blog is a deep dive into ERC-1400, one of the oldest tokenization standards (2018). www.taurushq.com/blog/erc-140...
taurushq.com
Taurus Blog - ERC-1400 for Tokenized Securities: Analysis and Deployment with Taurus-CAPITAL
ERC-1400 for Tokenized Securities: Analysis and Deployment with Taurus-CAPITAL
000
Reposted by AccessDenied403
BleepingComputer @bleepingcomputer.com · 18/03/2025
A cascading supply chain attack that began with the compromise of the "reviewdog/action-setup@v1" GitHub Action is believed to have led to the recent breach of "tj-actions/changed-files" that leaked CI/CD secrets.
bleepingcomputer.com
GitHub Action hack likely led to another in cascading supply chain attack
A cascading supply chain attack that began with the compromise of the "reviewdog/action-setup@v1" GitHub Action is believed to have led to the recent breach of "tj-actions/changed-files" that leaked CI/CD secrets.
035
Reposted by AccessDenied403
ZK Hack @zkhack.dev · 17/03/2025
A couple weeks ago we published our monthly release of ZK Mesh: the February 2025 Recap. Wondering which articles/threads are the most popular amongst our #ZKMesh readers so far? ZK Mesh Feb 2025 Top 5, here we go 🧵 👇 open.substack.com/pub/zkmesh/p...
111
Reposted by AccessDenied403
David Wong @cryptodavidw.bsky.social · 14/03/2025
damn this halo2 book is soooo goooood halo2.zksecurity.xyz/intro/
halo2.zksecurity.xyz
Introduction - Halo Hero
001
Reposted by AccessDenied403
BleepingComputer @bleepingcomputer.com · 14/03/2025
A large-scale Coinbase phishing attack poses as a mandatory wallet migration, tricking recipients into setting up a new wallet with a pre-generated recovery phrase controlled by attackers.
bleepingcomputer.com
Coinbase phishing email tricks users with fake wallet migration
A large-scale Coinbase phishing attack poses as a mandatory wallet migration, tricking recipients into setting up a new wallet with a pre-generated recovery phrase controlled by attackers.
076
AccessDenied403 @ad403.bsky.social · 13/03/2025
Sepolia Pectra fork incident recap: "we quickly realized that, because the deposit contract is token gated, an ERC-20 transfer event was emitted whenever a deposit was processed. mariusvanderwijden.github.io/blog/2025/03...
mariusvanderwijden.github.io
Sepolia Pectra fork incident recap
Blog on semi-cool ethereum stuff
000
AccessDenied403 @ad403.bsky.social · 12/03/2025
Bybit hack deep dive by ncc group www.nccgroup.com/us/research-...
nccgroup.com
000