Binance Square
#futurakey

futurakey

777 views
17 Discussing
Lucas_Key
·
--
At 4:28 a.m., the Symbiosis bridge was hit. Not theft—creation. The attacker minted 2 to the 62nd power worth of syBTC in a brand-new account: 46.1 billion dollars in face value. 46.1 billion. That number is so huge I can’t even wrap my head around it anymore. I can understand 330,000 bucks, and I can understand 300 million—but 46.1 billion feels like reading the subtitles to a sci-fi movie. In reality, only 4.39 WBTC and $336,000 were actually cashed out. Someone might think: “That’s not too bad—the loss isn’t that big.” But I don’t see it that way. What truly makes my skin crawl isn’t “how much was lost,” it’s “how much was created.” Imagine someone at your house: they don’t break in, they don’t bypass your lock, they don’t even guess your password—they just print a few bank deposit slips from your account, with a face value of $46.1 billion. In the end, he only redeems $336,000. Are you afraid of that $336,000? What you’re afraid of is the act of “printing deposit slips” itself. What’s most terrifying about this isn’t the numbers. It’s the process: created → everything downstream accepts it → traded for real money. None of the three steps ever gets stuck. This month is already the third incident. Liquid, Nomic, Symbiosis—same playbook, performed three times. Who taught them? #Symbiosis #BTC #Web3 #链上安全 #FuturaKey
At 4:28 a.m., the Symbiosis bridge was hit.

Not theft—creation. The attacker minted 2 to the 62nd power worth of syBTC in a brand-new account: 46.1 billion dollars in face value.

46.1 billion. That number is so huge I can’t even wrap my head around it anymore. I can understand 330,000 bucks, and I can understand 300 million—but 46.1 billion feels like reading the subtitles to a sci-fi movie.

In reality, only 4.39 WBTC and $336,000 were actually cashed out. Someone might think: “That’s not too bad—the loss isn’t that big.” But I don’t see it that way. What truly makes my skin crawl isn’t “how much was lost,” it’s “how much was created.” Imagine someone at your house: they don’t break in, they don’t bypass your lock, they don’t even guess your password—they just print a few bank deposit slips from your account, with a face value of $46.1 billion. In the end, he only redeems $336,000. Are you afraid of that $336,000? What you’re afraid of is the act of “printing deposit slips” itself.

What’s most terrifying about this isn’t the numbers. It’s the process: created → everything downstream accepts it → traded for real money. None of the three steps ever gets stuck.

This month is already the third incident. Liquid, Nomic, Symbiosis—same playbook, performed three times.

Who taught them?

#Symbiosis #BTC #Web3 #链上安全 #FuturaKey
After seeing the news that Morgan Stanley has been adding to BTC holdings for three consecutive days to reach 7,855 coins, and then seeing reports that the Symbiosis bridge was breached, I suddenly feel that this market is especially divided. On one side, Wall Street quietly accumulates over three days; on the other, on-chain projects have fake coins with a face value of 46.1 billion minted through the night at 4 a.m. Different ways to live, different kinds of risk, within the same industry. Retail traders watch the price, institutions watch position management, and hackers look for vulnerabilities in your processes. Everyone is in this market, but they’re not really playing the same game. Sometimes I wonder: when this round of reshuffling is over, what will remain? It won’t be the bridges that raise funding by telling stories, and it won’t be the projects that get breached at 4 a.m. What will remain are the people who take the most boring things to the extreme—verifying goods, monitoring, auditing, risk control. Everything is boring, but everything saves lives. Morgan Stanley adding to its position isn’t unusual. What’s unusual is that it added for three straight days and even did so publicly. This signal is worth thinking about more than the price action itself: someone, from this position, cast a vote for “the long term” with real money. The FOMC is just ahead. The excitement is short-term, but the account is long-term. #BTC #机构 #Web3 #链上安全 #FuturaKey
After seeing the news that Morgan Stanley has been adding to BTC holdings for three consecutive days to reach 7,855 coins, and then seeing reports that the Symbiosis bridge was breached, I suddenly feel that this market is especially divided.

On one side, Wall Street quietly accumulates over three days; on the other, on-chain projects have fake coins with a face value of 46.1 billion minted through the night at 4 a.m. Different ways to live, different kinds of risk, within the same industry.

Retail traders watch the price, institutions watch position management, and hackers look for vulnerabilities in your processes. Everyone is in this market, but they’re not really playing the same game.

Sometimes I wonder: when this round of reshuffling is over, what will remain? It won’t be the bridges that raise funding by telling stories, and it won’t be the projects that get breached at 4 a.m. What will remain are the people who take the most boring things to the extreme—verifying goods, monitoring, auditing, risk control. Everything is boring, but everything saves lives.

Morgan Stanley adding to its position isn’t unusual. What’s unusual is that it added for three straight days and even did so publicly. This signal is worth thinking about more than the price action itself: someone, from this position, cast a vote for “the long term” with real money.

The FOMC is just ahead. The excitement is short-term, but the account is long-term.

#BTC #机构 #Web3 #链上安全 #FuturaKey
Arcana0:
一边大摩扫7855枚一边凌晨被铸461亿假币,消息面太碎实在跟不上,现在只管挂着代跑踏实睡,闲下来可以看看 他的帖子
A month, three incidents of anomalous minting. Liquid, Nomic, Symbiosis. Some people call this “a coincidence,” but I don’t believe it. The three events follow the same playbook: a flaw in the coin-minting logic → mint coins out of thin air → downstream processes are allowed to proceed normally → swap out real, hard currency. Even the locations of the vulnerabilities are pretty much the same—no one checks the source “before the assets come in.” This isn’t coincidence; it’s a pattern. Cross-chain bridges, at their core, outsource “trust” to contract code. And the industry’s habit in contract auditing is: look at the functions, not the flow. No matter how beautifully written the functions are, if one step in the process—“verifying the goods”—is missing, people will still use fake IOUs to withdraw money. I remember when cross-chain bridges blew up a couple of years ago, everyone was shouting that “bridges are the future.” Now when you look back, bridges didn’t become the future—they became hackers’ ATMs. Three in a row this month; what about next month? I’m not here to discourage anyone. The bridge narrative won’t die; what will die is bridges that don’t verify. People in this business have to think clearly about one thing: when your users hand assets to you, their first priority isn’t high returns—it’s “sleeping well at night.” First, do the verification. Then talk about everything else. #Symbiosis #BTC #Web3 #跨链桥 #FuturaKey
A month, three incidents of anomalous minting. Liquid, Nomic, Symbiosis.

Some people call this “a coincidence,” but I don’t believe it. The three events follow the same playbook: a flaw in the coin-minting logic → mint coins out of thin air → downstream processes are allowed to proceed normally → swap out real, hard currency. Even the locations of the vulnerabilities are pretty much the same—no one checks the source “before the assets come in.”

This isn’t coincidence; it’s a pattern. Cross-chain bridges, at their core, outsource “trust” to contract code. And the industry’s habit in contract auditing is: look at the functions, not the flow. No matter how beautifully written the functions are, if one step in the process—“verifying the goods”—is missing, people will still use fake IOUs to withdraw money.

I remember when cross-chain bridges blew up a couple of years ago, everyone was shouting that “bridges are the future.” Now when you look back, bridges didn’t become the future—they became hackers’ ATMs. Three in a row this month; what about next month?

I’m not here to discourage anyone. The bridge narrative won’t die; what will die is bridges that don’t verify. People in this business have to think clearly about one thing: when your users hand assets to you, their first priority isn’t high returns—it’s “sleeping well at night.”

First, do the verification. Then talk about everything else.

#Symbiosis #BTC #Web3 #跨链桥 #FuturaKey
The white-hat bounty paid out by Symbiosis is 20%. The deadline has passed—there’s been no follow-up. I’ve been turning this over and over in my mind for a long time. What does 20% even mean? The actual loss is $336,000, and the bounty is just over $60,000. Get someone who has just proven, “your bridge can print unlimited money,” to hand over what they’re holding for $60,000? There are only two possibilities. Either they don’t care about that money—if so, the problem is even more frightening: if someone who doesn’t care about money is going after you, what are they after? Or they’re waiting for a better price. No matter which it is, this doesn’t sound like a “white-hat” storyline. White hats want a name; black hats want money. This time, the party involved isn’t in a hurry for either fame or profit—they’re just dragging it out. Dragging it out for what? Until the official complete incident report is released, until BridgeV2’s technical details are made public, until the next negotiation window. To be honest, among the three abnormal minting incidents this month, the one that worries me most is the wrap-up by Symbiosis. Liquid at least refunded 85%—the money has somewhere to go. With Symbiosis, there’s a $46.1 billion face-value question mark hanging in the air: the official report hasn’t come out yet, and nobody has claimed the bounty. An open question is the most frustrating. #Symbiosis #BTC #Web3 #跨链桥 #FuturaKey
The white-hat bounty paid out by Symbiosis is 20%. The deadline has passed—there’s been no follow-up.

I’ve been turning this over and over in my mind for a long time. What does 20% even mean? The actual loss is $336,000, and the bounty is just over $60,000. Get someone who has just proven, “your bridge can print unlimited money,” to hand over what they’re holding for $60,000?

There are only two possibilities. Either they don’t care about that money—if so, the problem is even more frightening: if someone who doesn’t care about money is going after you, what are they after? Or they’re waiting for a better price.

No matter which it is, this doesn’t sound like a “white-hat” storyline. White hats want a name; black hats want money. This time, the party involved isn’t in a hurry for either fame or profit—they’re just dragging it out. Dragging it out for what? Until the official complete incident report is released, until BridgeV2’s technical details are made public, until the next negotiation window.

To be honest, among the three abnormal minting incidents this month, the one that worries me most is the wrap-up by Symbiosis. Liquid at least refunded 85%—the money has somewhere to go. With Symbiosis, there’s a $46.1 billion face-value question mark hanging in the air: the official report hasn’t come out yet, and nobody has claimed the bounty.

An open question is the most frustrating.

#Symbiosis #BTC #Web3 #跨链桥 #FuturaKey
As I watched the U.S. stock market and the crypto market today, I stared at the screen for a long time. AI safety panic dragged tech stocks down, and the S&P tech sector was all red. In theory, risk assets should go down together. But Bitcoin strengthened against the trend, holding steadily above 77K, moving as calmly as anyone. After doing development for so many years and mixing in both the AI and Web3 circles, this is the first time I’ve seen them tear at each other this openly. In the past, everyone said these two were “family”: both were risk assets, both were fish in the same pot of U.S. dollar liquidity—when things rose, they rose together, and when they fell, they fell together. After today’s performance, that claim probably needs to be revised. I thought it through for a whole night and came up with an angle—maybe it’s not entirely right, but it’s pretty interesting. Right now, the market prices AI as “productivity,” while it prices Web3 as “insurance.” If something goes wrong with AI, what people worry about is “expectations not being delivered.” And the more panicked the traditional markets get, the more someone will move money into Bitcoin, that “drawer outside the system.” Since the direction of fear is different, the direction of money is different too. Of course, I might be overthinking it. The market always has to make up a story every day to explain prices. Today’s story just happened to be “AI crashes, coins surge.” Tomorrow it might be something else. With market moves, everything looks logical in hindsight, but before it happens, it’s all noise. What truly made me remember today was a message from a friend. He works at an AI startup and told me last night: the company’s funding fell through, so they’re laying people off. I asked him if he wanted to come work with me on blockchain-related stuff. He replied with one line: “Over there—has it been safe recently?” I thought for a long time and only answered with four words: “So far, so good—keep surviving.” #AI #BTC #Web3 #科技股 #FuturaKey
As I watched the U.S. stock market and the crypto market today, I stared at the screen for a long time.

AI safety panic dragged tech stocks down, and the S&P tech sector was all red. In theory, risk assets should go down together. But Bitcoin strengthened against the trend, holding steadily above 77K, moving as calmly as anyone.

After doing development for so many years and mixing in both the AI and Web3 circles, this is the first time I’ve seen them tear at each other this openly.

In the past, everyone said these two were “family”: both were risk assets, both were fish in the same pot of U.S. dollar liquidity—when things rose, they rose together, and when they fell, they fell together. After today’s performance, that claim probably needs to be revised.

I thought it through for a whole night and came up with an angle—maybe it’s not entirely right, but it’s pretty interesting. Right now, the market prices AI as “productivity,” while it prices Web3 as “insurance.” If something goes wrong with AI, what people worry about is “expectations not being delivered.” And the more panicked the traditional markets get, the more someone will move money into Bitcoin, that “drawer outside the system.” Since the direction of fear is different, the direction of money is different too.

Of course, I might be overthinking it. The market always has to make up a story every day to explain prices. Today’s story just happened to be “AI crashes, coins surge.” Tomorrow it might be something else. With market moves, everything looks logical in hindsight, but before it happens, it’s all noise.

What truly made me remember today was a message from a friend. He works at an AI startup and told me last night: the company’s funding fell through, so they’re laying people off. I asked him if he wanted to come work with me on blockchain-related stuff. He replied with one line: “Over there—has it been safe recently?”

I thought for a long time and only answered with four words: “So far, so good—keep surviving.”

#AI #BTC #Web3 #科技股 #FuturaKey
Tonight I scrolled through my team chat group and found a message I sent myself last month: “Let’s put the minting volume monitoring on hold for now, and do it together when V2 goes live.” Reading this, I felt a chill down my spine. It wasn’t because something happened with Symbiosis. It was because I knew how many team chat groups that sentence has appeared in. Features to launch, schedules already packed—then that monitoring seems “not needed for now”… and suddenly it’s 4:28 a.m. Accidents never come at a time when you’re prepared. They target exactly the places you “put on hold.” After years of building on-chain products, my biggest realization is this: security isn’t a feature—it’s an overdue list. If you cross off one item today, tomorrow you’ll have one fewer reason to be woken up at 4 a.m. If you delay one more, it will wait for you in some corner of a bridge. So tonight I pulled the minting monitoring out of the backlog and scheduled it for next Monday. No discussion. No “let’s wait a bit longer.” The market can wait. The code can’t. I’ve said that to myself many times—but today I finally understood what’s between saying it and doing it. #Symbiosis #BTC #Web3 #链上安全 #FuturaKey
Tonight I scrolled through my team chat group and found a message I sent myself last month:

“Let’s put the minting volume monitoring on hold for now, and do it together when V2 goes live.”

Reading this, I felt a chill down my spine.

It wasn’t because something happened with Symbiosis. It was because I knew how many team chat groups that sentence has appeared in. Features to launch, schedules already packed—then that monitoring seems “not needed for now”… and suddenly it’s 4:28 a.m.

Accidents never come at a time when you’re prepared. They target exactly the places you “put on hold.”

After years of building on-chain products, my biggest realization is this: security isn’t a feature—it’s an overdue list. If you cross off one item today, tomorrow you’ll have one fewer reason to be woken up at 4 a.m. If you delay one more, it will wait for you in some corner of a bridge.

So tonight I pulled the minting monitoring out of the backlog and scheduled it for next Monday. No discussion. No “let’s wait a bit longer.”

The market can wait. The code can’t. I’ve said that to myself many times—but today I finally understood what’s between saying it and doing it.

#Symbiosis #BTC #Web3 #链上安全 #FuturaKey
Seeing Jiang Zhuoer publicly maintain a full-position short and even called out a level: after a rise to 76,000, it will pull back. First, let me state this: I don’t comment on other people’s positions—whether they profit or lose is their own ability. But this situation is worth thinking one layer deeper. A big V publicly calls the trade—the traffic is real. What about the people who follow? Most follow because he got it right a few times in the past and they rush in; nobody asks a more fundamental question: is his position size and risk tolerance the same as yours? If he blows up, he can come back again; if you blow up, you’re out. The most expensive tuition in this business is placing orders based on someone else’s trades. You can’t learn the other person’s logic—at most you learn the entry price. When you win, it’s because he’s a genius; when you lose, it’s because you were greedy. My own principle is simple: any viewpoint should be treated only as a source of information, not a substitute for your own judgment. Especially when it comes with specific levels—the more concrete it is, the more you should put a question mark on it. Levels are the easiest-to-cash-in “traffic currency” in someone’s view. Back to the market: the FOMC is right ahead. At times like this, people will believe whatever direction is called out, but none of it is worth trusting fully. Control your hands—harder than controlling your position. #BTC #FOMC #合约 #FuturaKey # risk management
Seeing Jiang Zhuoer publicly maintain a full-position short and even called out a level: after a rise to 76,000, it will pull back.

First, let me state this: I don’t comment on other people’s positions—whether they profit or lose is their own ability. But this situation is worth thinking one layer deeper.

A big V publicly calls the trade—the traffic is real. What about the people who follow? Most follow because he got it right a few times in the past and they rush in; nobody asks a more fundamental question: is his position size and risk tolerance the same as yours? If he blows up, he can come back again; if you blow up, you’re out.

The most expensive tuition in this business is placing orders based on someone else’s trades. You can’t learn the other person’s logic—at most you learn the entry price. When you win, it’s because he’s a genius; when you lose, it’s because you were greedy.

My own principle is simple: any viewpoint should be treated only as a source of information, not a substitute for your own judgment. Especially when it comes with specific levels—the more concrete it is, the more you should put a question mark on it. Levels are the easiest-to-cash-in “traffic currency” in someone’s view.

Back to the market: the FOMC is right ahead. At times like this, people will believe whatever direction is called out, but none of it is worth trusting fully. Control your hands—harder than controlling your position.

#BTC #FOMC #合约 #FuturaKey # risk management
I just saw a number today: on the Base chain, a tokenized stocks DEX—daily trading volume has broken $100 million. I think this is being underestimated. While everyone is arguing about the market, there’s a group of people actively moving stocks on-chain. Just think about what that means. In the past, on-chain only worked for cryptocurrencies. Now the boundary of what you can touch on-chain is expanding outward. It’s not a one-step, overnight breakthrough—it’s that direction slowly becoming clearer. To be honest, I’ve always been half-skeptical about the narrative of tokenized stocks. Compliance is a big issue. Liquidity is a big issue. One regulatory call can upend the whole venue. But look at it from another angle: the demand is real. Traditional markets have limited trading hours, high entry barriers, and plenty of cross-border hassle. On-chain, it’s 7×24, and it’s globally accessible. As long as the demand is real, supply will find a way—sooner or later. For people building on-chain products, this matters a hundred times more than short-term market movements. It reminds me of one thing: don’t just focus on whether things are up or down today—watch which way the boundaries of the infrastructure are expanding. I don’t want to talk too much about the market today. Before the FOMC results come out, anything you say is just noise. #Base #Web3 #RWA #FuturaKey #On-chain Finance
I just saw a number today: on the Base chain, a tokenized stocks DEX—daily trading volume has broken $100 million.

I think this is being underestimated. While everyone is arguing about the market, there’s a group of people actively moving stocks on-chain.

Just think about what that means. In the past, on-chain only worked for cryptocurrencies. Now the boundary of what you can touch on-chain is expanding outward. It’s not a one-step, overnight breakthrough—it’s that direction slowly becoming clearer.

To be honest, I’ve always been half-skeptical about the narrative of tokenized stocks. Compliance is a big issue. Liquidity is a big issue. One regulatory call can upend the whole venue. But look at it from another angle: the demand is real. Traditional markets have limited trading hours, high entry barriers, and plenty of cross-border hassle. On-chain, it’s 7×24, and it’s globally accessible. As long as the demand is real, supply will find a way—sooner or later.

For people building on-chain products, this matters a hundred times more than short-term market movements. It reminds me of one thing: don’t just focus on whether things are up or down today—watch which way the boundaries of the infrastructure are expanding.

I don’t want to talk too much about the market today. Before the FOMC results come out, anything you say is just noise.

#Base #Web3 #RWA #FuturaKey #On-chain Finance
Today I want to talk about something a bit less well-known, but I think it matters more than the market: the kimchi premium on crypto in South Korea is up again—1.33%. Many people don’t know what that means. In simple terms, coins on Korean exchanges are a little more expensive than they are overseas, because money leaving the country isn’t as easy to move out. The higher the premium, the more urgent the people trying to get in are. 1.33% isn’t that high, but the direction is worth paying attention to. When the premium has spiked in the past, it often wasn’t retail traders getting excited—it was someone in a hurry to convert Korean won into on-chain assets. I don’t really believe the idea that premium is a bottom-fishing signal. A signal is something you treat as one. If you believe it, it becomes a signal; if you don’t, it’s just a number. I’d rather think of it as a kind of mood thermometer: someone is more anxious than we are. Those who are anxious usually end up with two outcomes: buying at the best possible spot, or selling at the worst. My mindset right now is pretty calm. The FOMC is right around the corner. At a time like this, it’s better not to stare at the premium and guess the direction—finish the code instead. The market will move on its own; code you don’t finish won’t. #BTC #泡菜溢价 #Web3 #FuturaKey #行情
Today I want to talk about something a bit less well-known, but I think it matters more than the market: the kimchi premium on crypto in South Korea is up again—1.33%.

Many people don’t know what that means. In simple terms, coins on Korean exchanges are a little more expensive than they are overseas, because money leaving the country isn’t as easy to move out. The higher the premium, the more urgent the people trying to get in are.

1.33% isn’t that high, but the direction is worth paying attention to. When the premium has spiked in the past, it often wasn’t retail traders getting excited—it was someone in a hurry to convert Korean won into on-chain assets.

I don’t really believe the idea that premium is a bottom-fishing signal. A signal is something you treat as one. If you believe it, it becomes a signal; if you don’t, it’s just a number. I’d rather think of it as a kind of mood thermometer: someone is more anxious than we are.

Those who are anxious usually end up with two outcomes: buying at the best possible spot, or selling at the worst.

My mindset right now is pretty calm. The FOMC is right around the corner. At a time like this, it’s better not to stare at the premium and guess the direction—finish the code instead. The market will move on its own; code you don’t finish won’t.

#BTC #泡菜溢价 #Web3 #FuturaKey #行情
Blockstream says no to ransom. 47 million dollars—if they don’t want it, they don’t want it. I saw this last night. My phone was left on, and I stared at the ceiling for a long time. First, let’s say who the other side is: someone who calls himself a white-hat, holding 600 BTC. He previously returned 3,400 BTC, keeping these as change. Now the official position is set in stone: there’s been no negotiation, and there won’t be—this is a crime, and they will pursue it through the law. My first reaction was satisfaction. This kind of thing has been poisoned for too long by people who act first and then try to reason. Empty your house of your belongings, then come back and say I was helping you. Get lost. But after the satisfaction, I ran a test: if it were me, could I hold up? I thought honestly for ten minutes. I couldn’t. I would pay—and then, afterward, I’d say to the outside world that it was a bounty. So this move is impressive—impressive because I couldn’t do it. Later I figured out why they dare to. If they pay today, then tomorrow all the on-chain reserves become a withdrawal machine. The ransom is first used as damage control, and the second time it’s financing. Some money looks like savings, but it’s actually high-interest loans. What do you think? If it were you, would you pay? #Liquid #BTC #Web3 #链上安全 #FuturaKey
Blockstream says no to ransom. 47 million dollars—if they don’t want it, they don’t want it.

I saw this last night. My phone was left on, and I stared at the ceiling for a long time.

First, let’s say who the other side is: someone who calls himself a white-hat, holding 600 BTC. He previously returned 3,400 BTC, keeping these as change. Now the official position is set in stone: there’s been no negotiation, and there won’t be—this is a crime, and they will pursue it through the law.

My first reaction was satisfaction. This kind of thing has been poisoned for too long by people who act first and then try to reason. Empty your house of your belongings, then come back and say I was helping you. Get lost.

But after the satisfaction, I ran a test: if it were me, could I hold up? I thought honestly for ten minutes. I couldn’t. I would pay—and then, afterward, I’d say to the outside world that it was a bounty.

So this move is impressive—impressive because I couldn’t do it.

Later I figured out why they dare to. If they pay today, then tomorrow all the on-chain reserves become a withdrawal machine. The ransom is first used as damage control, and the second time it’s financing.

Some money looks like savings, but it’s actually high-interest loans.

What do you think? If it were you, would you pay?

#Liquid #BTC #Web3 #链上安全 #FuturaKey
“Legal remedies to pursue payment” — everyone in the comments is laughing. If the money is on the chain, who do you chase? The address won’t talk, and the private key won’t confess. The people laughing have their reasons. But I asked a compliance friend, and he replied with a line that left me stunned: characterization is worth more than chasing the money. What does that mean? Once a criminal case is filed, those 600 BTC become proceeds of crime. Global compliant exchanges aren’t playing around—addresses linked to illicit funds can’t trade, and cross-chain laundering will also be flagged. Hackers may hold digital gold, but they can’t spend it. The toughest counterattack isn’t getting the money back—it’s letting the money rot in the other party’s hands. Every time they want to cash out, they have to live in fear again and again. That “every time they cash out, they’re terrified”—it’s more tormenting than prison. So don’t rush to laugh at “law doesn’t work on-chain.” In this round, the battlefield is off-chain. #Liquid #BTC #Web3 #区块链安全 #FuturaKey
“Legal remedies to pursue payment” — everyone in the comments is laughing.

If the money is on the chain, who do you chase? The address won’t talk, and the private key won’t confess. The people laughing have their reasons.

But I asked a compliance friend, and he replied with a line that left me stunned: characterization is worth more than chasing the money.

What does that mean? Once a criminal case is filed, those 600 BTC become proceeds of crime. Global compliant exchanges aren’t playing around—addresses linked to illicit funds can’t trade, and cross-chain laundering will also be flagged. Hackers may hold digital gold, but they can’t spend it.

The toughest counterattack isn’t getting the money back—it’s letting the money rot in the other party’s hands.

Every time they want to cash out, they have to live in fear again and again. That “every time they cash out, they’re terrified”—it’s more tormenting than prison.

So don’t rush to laugh at “law doesn’t work on-chain.” In this round, the battlefield is off-chain.

#Liquid #BTC #Web3 #区块链安全 #FuturaKey
Tonight, let’s put a few signals from September together and take a clear look at the conclusion: this is not a time to guess the bottom—it’s a time to set discipline. First, let’s inventory the notable things worth remembering this week. One is that Liquid was stolen of $320 million. Anchor assets were effectively “minted” through without authorization, and the attacker claimed to be a white hat. After returning 85%, they still left behind about $47 million. Two is that Cronos suffered a rollback due to a lending attack—on-chain “immutability” has been actively broken once. Three is that net inflows into the XRP ETF in a single day overtook BTC and ETH, with funds shifting toward the asset narrative that is “most clearly backed by regulation.” Four is that the greed index is still above 70, but the price has ground down from 78K to 76K. This suggests this round of decline isn’t an emotional collapse—funds are voluntarily withdrawing in the face of macro data. Looking ahead, the FOMC meets next Tuesday and Wednesday, with the decision expected in Beijing time on 9/17. After CPI and PPI have repeatedly come in above expectations, the market has already been betting on persistence. My view: in September, there’s likely no rate hike—but if Powell is firm just once, risk assets will likely shake again. As the founder of FuturaKey, I’ve set three rules for myself, and I’m sharing them with you: First, don’t add positions or try to bottom-fish before the decision is released. Keep your “ammo” and let the market choose the answer first. Second, go back through the security audit checklist for the projects you’re working on. The density of attacks this month shows: the market can wait; code can’t. Third, a weak market is a window for polishing tools. Needs like on-chain monitoring and alerts for abnormal minting are increasing—this is exactly why I keep building security-focused products. One last blunt truth: the market isn’t short of opportunities—it’s short of people who still have ammunition when opportunities arrive. How many percent of your position are you in right now? Let’s discuss in the comments. The above are only my personal observations and do not constitute investment advice. #BTC #FOMC #Web3 #链上安全 #FuturaKey
Tonight, let’s put a few signals from September together and take a clear look at the conclusion: this is not a time to guess the bottom—it’s a time to set discipline.

First, let’s inventory the notable things worth remembering this week.

One is that Liquid was stolen of $320 million. Anchor assets were effectively “minted” through without authorization, and the attacker claimed to be a white hat. After returning 85%, they still left behind about $47 million. Two is that Cronos suffered a rollback due to a lending attack—on-chain “immutability” has been actively broken once. Three is that net inflows into the XRP ETF in a single day overtook BTC and ETH, with funds shifting toward the asset narrative that is “most clearly backed by regulation.” Four is that the greed index is still above 70, but the price has ground down from 78K to 76K. This suggests this round of decline isn’t an emotional collapse—funds are voluntarily withdrawing in the face of macro data.

Looking ahead, the FOMC meets next Tuesday and Wednesday, with the decision expected in Beijing time on 9/17. After CPI and PPI have repeatedly come in above expectations, the market has already been betting on persistence. My view: in September, there’s likely no rate hike—but if Powell is firm just once, risk assets will likely shake again.

As the founder of FuturaKey, I’ve set three rules for myself, and I’m sharing them with you:

First, don’t add positions or try to bottom-fish before the decision is released. Keep your “ammo” and let the market choose the answer first.

Second, go back through the security audit checklist for the projects you’re working on. The density of attacks this month shows: the market can wait; code can’t.

Third, a weak market is a window for polishing tools. Needs like on-chain monitoring and alerts for abnormal minting are increasing—this is exactly why I keep building security-focused products.

One last blunt truth: the market isn’t short of opportunities—it’s short of people who still have ammunition when opportunities arrive.

How many percent of your position are you in right now? Let’s discuss in the comments.

The above are only my personal observations and do not constitute investment advice.

#BTC #FOMC #Web3 #链上安全 #FuturaKey
Partly True
Before the FOMC, my three rules: no additional buys, no bottom-catching, and keep some cash on the sidelines This week, CPI and PPI both beat expectations consecutively, and market bets on further rate hikes are heating up. The FOMC will meet next Tuesday and Wednesday, with the decision released the early hours of 9/17 Beijing time. My view: There’s a good chance of no rate hike in September, but if Powell plays tough with his rhetoric even once, risk assets will likely shake again. At a time like this, staying alive to see the answer matters more than guessing the direction correctly. I set three rules for myself and I’m sharing them with you: First, don’t add to positions or try to catch the bottom before the decision is out. The market will give the answer first—there’s no need to wager real money. Second, go through the safety audit checklist for the projects you’re holding again. The attack intensity this month shows: markets can wait, but code can’t. Third, a weak market is a window to refine your tools. Demand for things like on-chain monitoring and anomaly alerting is increasing, and that’s why I’ve been sticking with building security-focused products at FuturaKey. Lastly, a blunt truth: the market lacks opportunities, not them. What it lacks is people who still have bullets when opportunities arrive. How much of your portfolio are you currently in? Let’s chat in the comments. The above is based only on personal observations and does not constitute investment advice. #BTC #FOMC #Web3 #链上安全 #FuturaKey
Before the FOMC, my three rules: no additional buys, no bottom-catching, and keep some cash on the sidelines

This week, CPI and PPI both beat expectations consecutively, and market bets on further rate hikes are heating up. The FOMC will meet next Tuesday and Wednesday, with the decision released the early hours of 9/17 Beijing time.

My view: There’s a good chance of no rate hike in September, but if Powell plays tough with his rhetoric even once, risk assets will likely shake again.

At a time like this, staying alive to see the answer matters more than guessing the direction correctly. I set three rules for myself and I’m sharing them with you:

First, don’t add to positions or try to catch the bottom before the decision is out. The market will give the answer first—there’s no need to wager real money.

Second, go through the safety audit checklist for the projects you’re holding again. The attack intensity this month shows: markets can wait, but code can’t.

Third, a weak market is a window to refine your tools. Demand for things like on-chain monitoring and anomaly alerting is increasing, and that’s why I’ve been sticking with building security-focused products at FuturaKey.

Lastly, a blunt truth: the market lacks opportunities, not them. What it lacks is people who still have bullets when opportunities arrive.

How much of your portfolio are you currently in? Let’s chat in the comments.

The above is based only on personal observations and does not constitute investment advice.

#BTC #FOMC #Web3 #链上安全 #FuturaKey
Liquid returned 85%, leaving 47 million dollars as a bounty—does that count as a white hat? Over the past couple of days, the community has been arguing about this, and I’ll share my take. First, let’s lay out the facts clearly: the attacker created 4,000 LBTC that were fabricated out of thin air, then followed the normal process to withdraw 3,996 real BTC. After Blockstream fixed the nodes, the attacker returned 3,400 more, leaving about 598.5 LBTC, which—at current prices—amounts to roughly 47 million USD. The attacker claims to be a “white hat”: “I’m not here to steal money. I’m here to remind you there are vulnerabilities.” But there’s a logic problem here. What’s the standard process for responsible disclosure? Discover a vulnerability → report it to the project → wait for a fix → collect the bounty. And this time it’s: drain 95% first → wait for the project to fix it → refund 85% → keep 15% as the bounty. The order is reversed, and so is the nature of it. Once Blockstream confirms on-chain that the nodes are fixed and refunds are possible, this also makes things more complicated—in the attacker’s eyes, it effectively confirms a “pay back money equals a settlement” pathway. Ledger’s CTO put it even more directly: this isn’t a white hat—it’s kidnapping first, then negotiating. As the founder of FuturaKey—someone who also builds on-chain products—I understand why the community is split into two camps. One side argues: most of the money came back, so it turned out fine. The other side argues: if this kind of behavior is encouraged, next time attackers will be emboldened—empty the reserves first, and if they refund part later, they can wash themselves as “white hats.” My position is the latter. The reason is simple: if “strike first, then refund” can still be called “white hat,” then the hacking industry has no failure cost—keep a portion when the attack succeeds, call yourself a white hat and ask for mercy when it fails. That is extremely unfair to researchers who do responsible security disclosure the right way. What’s even more concerning is the industry signal: this month Liquid saw 320 million, and Cronos had a rollback—so the density of security incidents is rising. In bear markets, hackers are more active than in bull markets. Project defense budgets are being cut, but the returns from attacks haven’t changed. For ordinary users, I have just one suggestion: anchor the security level of your assets and sidechain assets—always keep it lower than mainnet. Don’t put large positions there just because the yield is a bit higher. Do you think “drain first, then refund 85%” counts as a white hat? Let’s discuss in the comments. The above is only my personal observation and does not constitute investment advice. #Liquid #BTC #Web3 #链上安全 #FuturaKey
Liquid returned 85%, leaving 47 million dollars as a bounty—does that count as a white hat?

Over the past couple of days, the community has been arguing about this, and I’ll share my take.

First, let’s lay out the facts clearly: the attacker created 4,000 LBTC that were fabricated out of thin air, then followed the normal process to withdraw 3,996 real BTC. After Blockstream fixed the nodes, the attacker returned 3,400 more, leaving about 598.5 LBTC, which—at current prices—amounts to roughly 47 million USD.

The attacker claims to be a “white hat”: “I’m not here to steal money. I’m here to remind you there are vulnerabilities.”

But there’s a logic problem here. What’s the standard process for responsible disclosure? Discover a vulnerability → report it to the project → wait for a fix → collect the bounty. And this time it’s: drain 95% first → wait for the project to fix it → refund 85% → keep 15% as the bounty.

The order is reversed, and so is the nature of it. Once Blockstream confirms on-chain that the nodes are fixed and refunds are possible, this also makes things more complicated—in the attacker’s eyes, it effectively confirms a “pay back money equals a settlement” pathway.

Ledger’s CTO put it even more directly: this isn’t a white hat—it’s kidnapping first, then negotiating.

As the founder of FuturaKey—someone who also builds on-chain products—I understand why the community is split into two camps. One side argues: most of the money came back, so it turned out fine. The other side argues: if this kind of behavior is encouraged, next time attackers will be emboldened—empty the reserves first, and if they refund part later, they can wash themselves as “white hats.”

My position is the latter. The reason is simple: if “strike first, then refund” can still be called “white hat,” then the hacking industry has no failure cost—keep a portion when the attack succeeds, call yourself a white hat and ask for mercy when it fails. That is extremely unfair to researchers who do responsible security disclosure the right way.

What’s even more concerning is the industry signal: this month Liquid saw 320 million, and Cronos had a rollback—so the density of security incidents is rising. In bear markets, hackers are more active than in bull markets. Project defense budgets are being cut, but the returns from attacks haven’t changed.

For ordinary users, I have just one suggestion: anchor the security level of your assets and sidechain assets—always keep it lower than mainnet. Don’t put large positions there just because the yield is a bit higher.

Do you think “drain first, then refund 85%” counts as a white hat? Let’s discuss in the comments.

The above is only my personal observation and does not constitute investment advice.

#Liquid #BTC #Web3 #链上安全 #FuturaKey
Mellissa Prach:
Good point $BTC there is always a fake out before a break out..
"The era of "Uniswap, but on a new chain" is over" Let’s talk about V4 Hooks design In the past few days, I’ve been studying the Uniswap V4 architecture and jotting down some thoughts. In the past, the most common project form in the DeFi space was: fork Uniswap, deploy it on another chain, tweak it here and there, and modify the UI. Because under the V3 architecture, each trading pair required its own contract deployment. So to differentiate, you basically had to rewrite things. V4 changes this logic. There are two key points: **Singleton architecture**: the state of all pools is consolidated into a single PoolManager contract. Pool creation becomes a "state update" rather than "deploying a new contract," dramatically reducing gas costs. **Hooks system**: external contracts are attached to lifecycle nodes of the pool to inject custom logic. If you want dynamic fees, you don’t need to rewrite the whole AMM—just write and plug in a Hook. The core market-making logic and safety guarantees are inherited from Uniswap itself. This design lowers the "innovation barrier," but it also brings new problems: who guarantees the security of the Hook itself? No matter how solid the foundation is, if your Hook logic has a vulnerability, it can still be exploited. To some extent, audit responsibility is shifted onto each Hook developer. I’ll write a more detailed technical breakdown next. #Uniswap #DeFi #Web3 development #FuturaKey
"The era of "Uniswap, but on a new chain" is over" Let’s talk about V4 Hooks design

In the past few days, I’ve been studying the Uniswap V4 architecture and jotting down some thoughts.

In the past, the most common project form in the DeFi space was: fork Uniswap, deploy it on another chain, tweak it here and there, and modify the UI. Because under the V3 architecture, each trading pair required its own contract deployment. So to differentiate, you basically had to rewrite things.

V4 changes this logic. There are two key points:

**Singleton architecture**: the state of all pools is consolidated into a single PoolManager contract. Pool creation becomes a "state update" rather than "deploying a new contract," dramatically reducing gas costs.

**Hooks system**: external contracts are attached to lifecycle nodes of the pool to inject custom logic. If you want dynamic fees, you don’t need to rewrite the whole AMM—just write and plug in a Hook. The core market-making logic and safety guarantees are inherited from Uniswap itself.

This design lowers the "innovation barrier," but it also brings new problems: who guarantees the security of the Hook itself? No matter how solid the foundation is, if your Hook logic has a vulnerability, it can still be exploited. To some extent, audit responsibility is shifted onto each Hook developer.

I’ll write a more detailed technical breakdown next.

#Uniswap #DeFi #Web3 development #FuturaKey
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number