CSK3442

vip
Age 1.5 Yıl
Peak Tier 0
No content yet
It's terrible to keep seeing these large exploits but what really irks me is the lack of accountability. They keep getting labelled as 'highly sophisticated' hacks. Yet you look at their opsec and it resembles this photo. I'm sorry but that doesn't wash. Sort it out
post-image
  • Reward
  • Comment
  • Repost
  • Share
Running a protocol multisig with weak governance is like running a high leverage trade with immediate liquidation risk. Only difference is it's other people's money on the line
Ten Solana DeFi red flags sitting in plain sight on chain
- Multi purpose governance keys. Same key approving multisig actions is also trading memecoins, farming airdrops, flipping NFTs, swapping on DEXs. Every dapp it touches is another place that signing power can get phished
- Single signer multisigs. No multisig at all, or one with multiple signers but threshold set to 1. Looks distributed, single point of failure i
SOL-1,05%
DEFI-7,83%
  • Reward
  • Comment
  • Repost
  • Share
Not sure how many warnings Solana DeFi protocols need to harden their security, but there's no better time than the present. Blast radius doesn't just impact internal users. Other protocols potentially get hit in the upstream and downstream too. We're better than this. Come on
  • Reward
  • Comment
  • Repost
  • Share
Hundreds of millions exploited past few weeks. Drift & now Kelp. Many other protocols caught in the crossfire & impacted a lot of people. Still amazes me how this happens time & time again while protocols sit on the same vulnerabilities as the ones that got hacked. What else is so important? Upgrade your security, UI updates & new tools can wait. Wild how complacent people are. Hits different when it's other people's money at risk instead of your own, right? User safety > company revenue
DRIFT0,48%
  • Reward
  • Comment
  • Repost
  • Share
Can we pump these charts
  • Reward
  • Comment
  • Repost
  • Share
1 in 5 solana protocols on solgov are using governance timelocks. 2 protocols have added one since the Drift exploit
DRIFT0,48%
post-image
  • Reward
  • 1
  • Repost
  • Share
GateUser-5fc07732:
And what does this mean?
Blast radius page update. Created solar systems using on chain data showing what is connected to where. Still a WIP
post-image
post-image
  • Reward
  • Comment
  • Repost
  • Share
  • Reward
  • Comment
  • Repost
  • Share
After reading about the 6 month social engineering operation that led to the Drift exploit, I wanted to dig into the on-chain multisig history. Here is what I found across the last 2 multisigs and the one currently in use
DRIFT0,48%
post-image
  • Reward
  • Comment
  • Repost
  • Share
Two new tabs on solgov
GovWatch - tracks governance config changes, voter activity, and execution speed across 33 protocols. All on-chain verified
Blast Radius - helps map protocol dependencies so users can see what they're connected to. The Drift exploit affected 22 protocols through connections that caught people off guard
DRIFT0,48%
  • Reward
  • Comment
  • Repost
  • Share
I think the next update on X should remove profile pictures and names so we just have to guess who's saying what on the feed
  • Reward
  • Comment
  • Repost
  • Share
If you want an insight into how most people trade on CT, just look at how frequently they jump from one ai model to the next
  • Reward
  • Comment
  • Repost
  • Share
1 week after the Drift exploit, 0 protocols on solgov meet minimum Squads recommendations. Also added verified builds and insurance/recovery fund information
DRIFT0,48%
post-image
  • Reward
  • Comment
  • Repost
  • Share
Pumpfun threshold bumped from 2/4 to 3/4. Same 4 signers, no members added or removed. Zero timelock unchanged. No program upgrade since March. Dashboard updated at solgov
post-image
  • Reward
  • Comment
  • Repost
  • Share
- Threshold checks against Squads published best practices
- Multisig configuration (threshold, signers, roles)
- Governance timelocks (on-chain/squads)
- Program timelocks (from protocol teams or public docs where available)
- Program upgrade authorities
- Member permissions (propose/vote/execute)
- Multi program infrastructure
- Active voters vs total members
- Split authority detection
- Effective threshold percentage
- Audit and security context
Updated today
- New sections (protocol disclosed & public documentation with source links)
- 31 of 33 protocols now have additional context
- Thre
post-image
  • Reward
  • Comment
  • Repost
  • Share
Tyson fury tickets cheaper than a domino's pizza. Touts rekt
post-image
  • Reward
  • Comment
  • Repost
  • Share
Keir starmer, donald trump & anthony albanese all speaking today. Should be fun
  • Reward
  • Comment
  • Repost
  • Share
Caught up with the ufc this morning whilst hitting the incline walking pad whilst hitting Claude Code via remote control. Who says men can't multi task? Wife in disbelief
  • Reward
  • Comment
  • Repost
  • Share
Claude mythos leaked
post-image
  • Reward
  • Comment
  • Repost
  • Share
  • Pin