Sign in

sudo rm -rf --no-preserve-root /

@pcaversaccio.com
484 followers 111 following 449 posts

𝐖𝐨𝐫𝐤𝐢𝐧𝐠 𝐨𝐧 𝐰𝐡𝐚𝐭'𝐬 𝐧𝐞𝐱𝐭. ꟼGꟼ: 063E 966C 93AB 4356 492F E032 7C3B 4B4B 7725 111F 📌 w021d 🔗 github.com/pcaversaccio

PostsRepliesMedia
Reposted by sudo rm -rf --no-preserve-root /
GrapheneOS @grapheneos.org · 29/08/2026
We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We're unable to complete the port due to lack of support for ARM hardware memory tagging in software, firmware and near certainly hardware. It appears Google cut an important security feature to save money.
24632137
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 07/12/2025
1/ so, hmm, we rely on firmware we can't inspect, compilers we don't build, closed-source LLMs, proprietary enclaves, remote updates etc. Each of these layers is a target and more will join in the coming years/decades.
172
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 29/11/2025
1/ Had a fun convo recently where some dude was talking about Uber and ride-sharing. I told him I've never used any of those services in my life (I'm being serious here). He looked confused and asked how I get around usually.
110
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 23/11/2025
if someone ever managed to breach all _private_ GitHub repos (I mean it's insanely difficult but not impossible) it would be one of the most catastrophic events in the security history, and if I were a state-level actor that's exactly the kind of target I'd prioritise rn.
2121
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 18/11/2025
RIP Internet
042
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 12/10/2025
folks, hear me out, the best long-term trading strategy is privacy itself. Those who build and hold it are shaping the foundation of a free economy. And guess what, its yield is true sovereignty: the _only_ return that truly endures.
051
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 29/09/2025
1/ Ethereum's worst enemy is institutional adoption. Honestly, think about it guys, the more institutions get involved, the more influence they wanna have on future hard fork decisions (and thus will make a core dev's job even more complicated),...
153
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 30/08/2025
1/ The soul of Ethereum was Cypherpunk. It _is_ Cypherpunk. It will always be Cypherpunk. You can chase your glossy, VC-driven narratives, build your fancy protocols, but the ones that will endure are the ones that preserve our privacy, defend against censorship & stand tall in the face of tyranny.
161
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 03/08/2025
1/ This morning I've been reviewing our last months' SEAL 911 tickets. Guys, it's clear that soon (probably sooner than you think) a large portion of our ecosystem will be running on compromised devices. I mean, man, infostealers are probably the _biggest_ ecosystem problem right now.
120
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 27/06/2025
My periodic reminder: if someone offers you a slick-looking hardware gadget at EthCC (or any other crypto event), don't plug it in, don't take it home. Just walk away. Treat it like malware wearing a shiny casing. We've got enough infostealers in the wild already.
030
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 19/06/2025
so I've been thinking about this for a while now and I'm more and more convinced that crypto was never meant for mainstream. The main reason being that crypto's purpose is _liberation_, not popularity. It's effectively for those who choose sovereignty over simplicity.
120
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 14/06/2025
you know, I'm a simple guy: I roll (mostly) with ETH, Tornado Cash, Railgun, BTC, Zcash, and XMR these days. I don't use L2s. I don't use Solana. I don't use fancy DeFi protocols (I like it KISS and trustless). Simply put: just tools that work and don't ask permission.
231
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 10/06/2025
I know guys, you're all bullish on Claude etc. but if you keep outsourcing more and more of your thinking to LLMs, you'll eventually become whatever the algorithm decides. You lose your uniqueness, your edge. Just don't.
010
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 27/05/2025
1/ There is nothing I want more than for Ethereum to lead on privacy (scalability has always been a second priority for me tbh; not implying it's not important to be clear). Not conditional privacy. Unconditional.
120
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 19/05/2025
1/ Listen guys, many might disagree with me on this, but Ethereum's lasting success is all about its Cypherpunk soul. Real (IMO unconditional) privacy, security, censorship resistance; that's the core and must always remain the core.
130
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 14/05/2025
An OS that goes all-in on simplicity. There's so much virtue in simplicity. What we need is more of less. duskos.org
010
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 11/05/2025
1/ There is absolutely no valid reason why prices are pumping right now. We're still a clown-show industry, light-years away from making any _meaningful_ dent in the lives of 99.9% of people on this planet.
150
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 09/05/2025
1/ time for a quick vibes check on where our industry's at security-wise; well, folks, guess what, 95% of last months' SEAL 911 tickets were the same shitshows on repeat: folks running sketchy code some rando DMed them (stop cloning & running GH repos u got from random dude who asks for your "help")
130
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 07/05/2025
I love how Xwitter cares about their security
020
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 06/05/2025
1/ Most crypto work (partially mine included) runs on some sort of 'hope Microsoft keeps GitHub online' mode. Git is decentralised but GitHub isn't. Shutting down key repos is one of the easiest ways to censor or disrupt upgrades and dev coordination. And yes, Microsoft can do that.
172
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 20/04/2025
found the major bottleneck for scaling Ethereum
060
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 09/04/2025
1/ "Make Ethereum Cypherpunk Again" isn't simply a slogan for me — it's a statement of intent. This isn't branding. It's resistance. This isn't about playing nice. It's about reclaiming Ethereum's soul! hackmd.io/@pcaversacci...
140
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 07/04/2025
1/ folks, can we please fucking stop normalising `curl | bash` as an installation method (yes, I'm also looking at you Foundry)? It's a _massive_ footgun that blindly executes remote code with zero verification. You're literally giving arbitrary internet bytes root access to your machine.
110
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 14/03/2025
Happy π day!
000
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 27/02/2025
1/ People keep asking me since days how to secure their systems and what the best strategy is. I will be very honest with u all as I'm always. If u want real security (and there will be never 100% security), it's not (just) about tools—it's about fucking mindset. At least 80% of it is pure paranoia.
140
Reposted by sudo rm -rf --no-preserve-root /
lefterisjp.bsky.social @lefterisjp.bsky.social · 21/02/2025
This is the biggest blind signing compromise of a multisig to date Bybit lost ~$1.5bn by signing a compromised tx on their safe (more details to be determined) But FOR GOD'S SAKE if you deal with such amounts use verification tools such as the one by @pcaversaccio.com github.com/pcaversaccio...
github.com
GitHub - pcaversaccio/safe-tx-hashes-util: This Bash script calculates the Safe transaction hashes by retrieving transaction details from the Safe transaction service API and computing both the domain...
This Bash script calculates the Safe transaction hashes by retrieving transaction details from the Safe transaction service API and computing both the domain and message hashes using the EIP-712 st...
051
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 19/02/2025
1/ Ethereum is this fucking phenomenal economic playground—the biggest we'll witness in our lifetime. It's a wild frontier, open to boundless experimentation, but that also means it's a hunting ground for criminals.
151
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 16/02/2025
1/ If you get scammed by presidential meme tokens, that's on you at first. It's your fucking degeneracy that makes you trade real money for pure stupidity. We're all grown-ass adults who can think, right?
140
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 06/02/2025
1/ Picture if all the resources poured into L2/L3 grifts had been directed at improving L1 directly. Picture a world without "select/add network", where shielded transactions are the standard, and an L1 with snooth cross-shard communication.
130
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 02/02/2025
1/ The crypto bubble keeps circle jerking about how mass adoption is just around the corner, completely ignoring that this bold experiment started a _decade_ ago. The only real "adoption" we've seen so far is people getting rugged, phished, or scammed (& stablecoins tbf).
130
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 29/01/2025
The fun fact is that DeepSeek is actually Open AI.
010
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 23/01/2025
1/ Folks, the biggest security threat right now is people blindly running code, invoking obscure commands, or installing applications just because some random person or website told them to.
140
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 09/01/2025
Our industry excels in producing an insane number of subpar projects that get heavily overfunded. Many crypto investments are simply a masterclass in capital misallocation.
030
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 02/01/2025
1/ I truly believe the only way to fix the broken EF capital allocation is by making them expendable. It's our responsibility to cultivate a thriving ecosystem that isn't dependent on a single, centralised source of funding.
110
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 31/12/2024
Here we go guys; it was a fucking insane year at SEAL 911: x.com/pcaversaccio.... A heartfelt thank you to all of the SEAL 911 volunteers, past and present, who contribute to making this wild space a better place. It's an honour to stand and work alongside you. Happy new year!
020
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 25/12/2024
Looks like there was a pretty ugly deanonymisation vulnerability present in Wasabi wallets until recently (specifically related to CoinJoins). Such disclosures always remind me how hard it is to implement true privacy into your applications. But it's def worth the battle. github.com/GingerPrivac...
030
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 22/12/2024
1/ The soul of crypto feels fucking gone in 2024. We've let "training wheels" for L2s become an excuse for dragging ass on decentralisation, KYC is fucking everywhere, and way too many of us just accept it (fucking stop!).
241
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 21/12/2024
1/ ffs, don't ask ChatGPT/LLMs if a file is safe. First, new malware is not part of past training data used for the LLMs (even tho certain, e.g. infostealer pattern, are recycled over time), second ChatGPT cannot execute files (needed to detect behaviours that only manifest during execution),
100
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 18/12/2024
I have come to the conclusion that 95% of security products in our industry are nothing more than vaporware, offering the illusion of security rather than actual protection.
130
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 14/12/2024
Every time I skim through the (updated) EOF specs, it's a reminder of how we've drowned in complexity for the sake of flexing. There is no reason this monstrosity should ever see the light of day. Sorry. Let’s get back to KISS.
010
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 13/12/2024
Rust devs after their 101th rewrite-in-rust
000
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 06/12/2024
Sometimes (tbh multiple times a day), I wish we could rewind to the early crypto days—when everything felt like the wild west, principles-based, and full of endless possibilities.
030
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 05/12/2024
So this morning I found a rather annoying bug in the Safe UI for older Safe versions `<=1.2.0`. TL;DR: the domain hash displayed is wrong. x.com/pcaversaccio...
020
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 03/12/2024
1/ This is such a retarded take. A VPN is your digital armour. People might use a public Wi-Fi or want to prevent government/ISP tracking when logging into Coinbase. I'm not sure if this a personal view or a Coinbase view, but if it's a company-wide opinion you're fucking anti-privacy clowns!
130
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 30/11/2024
Sooner or later, we'll come to a powerful realisation: the most pivotal move for L2s will be acknowledging that, in the long run, we may not need them at all. In hindsight, Layer 2 solutions will appear as temporary stopgaps. Not now, not in 6 months, but in 3-5 years' time. That's my bet.
020
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 29/11/2024
It amazes me how L2s think that it's a great idea to modify the source code of one of the most successful smart contracts to date. If you ask me this is just insane. What can go wrong? hint: insufficient approval to self. Can we fucking stop this fragmentation, it only hurts. Welcome to Blast's WETH
040
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 27/11/2024
1/ For those who want to exercise their privacy rights and want to use an uncompromised Tornado Cash interface, here are some secure IPFS hashes: - bafybeicu2anhh7cxbeeakzqjfy3pisok2nakyiemm3jxd66ng35ib6y5ri - bafybeia7cu2axyyxsarmaemvlpdpofa4q23lzpltbl4jbrnfixdn573h4y x.com/iampaulgrewa...
x.com
x.com
150
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 23/11/2024
So we have an "official" (i.e. NIST-based) deadline now: ECDSA should be deprecated by 2030 (for 112 bits only) and completely disallowed by 2035. Thx for the crazy ride secp256k1 (and secp256r1). nvlpubs.nist.gov/nistpubs/ir/...
051
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 21/11/2024
Vitalik is back writing Vyper code - what a beautiful day github.com/ethereum/res...
130
sudo rm -rf --no-preserve-root / @pcaversaccio.com · 18/11/2024
today I was looking again into BLAKE3 and I'm getting more convinced that we should add it to the EVM. Thoughts? Like, it's way more efficient than SHA-256 and - maybe this is just my paranoia - SHA-256 was designed by the NSA... interesting fact, the Beacon deposit contract uses SHA-256 12 times.
230