Community

Contribute by sharing insights and tips to strengthen the community.

All221
search
salaryman
salaryman

July 15, 2025

General Discussion
A lovely chainbounty arrived

it's been while since i can't login talken app, when i saw there has some lovely chainbounty in my wallet. Pretty cool keep it up!

2 likes28 reads
Nomnom
Nomnom

July 09, 2025

General Discussion
Wonderfull

What is join chainbounty and earn reward

1 likes32 reads
UppSecEcho
UppSecEcho

July 09, 2025

Cybersecurity Tips
🚨 A Silent Heist: Fake Crypto Wallets Flood Firefox Add-Ons Store

The crypto world just got hit with another stealthy threat—this time targeting unsuspecting Firefox users through malicious wallet extensions.More than 40 fake Firefox extensions mimicking popular crypto wallets have been discovered since April 2025. These fraudulent add-ons, found directly on the Firefox Add-ons store, aren’t just phishing scams, they’re sophisticated clones capable of stealing private keys and draining entire wallets.🔍 The Deception: Looks Real, Acts EvilThe attackers didn’t build these fake extensions from scratch. Instead, they forked open-source code from legitimate wallets, like MetaMask, Phantom, Trust Wallet, OKX, Bitget, and Coinbase Wallet, and injected malicious scripts designed to silently steal user data.To make things worse, the extensions:• Used identical names and logos• Were stuffed with fake 5-star reviews• In some cases, were signed with valid Mozilla developer accountsThese wallet clones were nearly indistinguishable from the real thing. And once installed, they watched for one thing: your seed phrase.🧠 How the Attack WorksOnce a victim pastes a seed phrase or private key into the fake extension interface, it’s game over.These fake extensions:• Monitor inputs over 30 characters (typical of seed phrases)• Immediately exfiltrate them to attacker-controlled servers• Also log the user’s IP address, likely for geographic targeting🇷🇺 Who’s Behind It?Investigators found Russian-language comments in the code and metadata tied to Russian-speaking actors, although attribution is not conclusive.The infrastructure behind the scam was impressively organized:• Hosting on bulletproof VPS providers• Constantly rotating domain names• Multiple versions pushed across dozens of wallets and language localizationsThis wasn’t a quick smash-and-grab. It was an industrial-scale operation.🧯 Mozilla’s ResponseMozilla has begun purging these fake extensions, but new ones keep popping up. As of July 2025, many remain live on the Add-ons store, making this a whack-a-mole nightmare for security teams.Mozilla stated that it is:• Using automated scanning tools• Relying on user reports• Tightening vetting procedures for crypto-related extensionsBut clearly, more must be done.🛡️ What You Can Do NowIf you use Firefox for crypto-related activity, pause and reassess your security posture. Here's what I recommend:🔐 Action Why It MattersAvoid browser wallet extensions Especially on Firefox, until the dust settles. Use mobile apps or official websites.Install only from verified sources Check the publisher name and history. Don't trust reviews alone.Enable 2FA everywhere Adds a critical second layer to access.Use cold storage for large holdings If it’s not online, it can’t be drained.Report suspicious extensions Help Mozilla remove threats faster.🧰 Free Tool to Check for Scam WalletsAt scamhunter.ai, we’re fighting crypto scams head-on. Uppsala Security offers a free tool to:• Scan suspicious wallet addresses• View scam reports• Flag stolen assetsYou can try it free twice a day. Just paste in a wallet address and we’ll show you what we know.🚨 Final ThoughtsThis latest wave of wallet-cloning extensions on Firefox is a wake-up call for the crypto industry. Browser-based wallets are convenient, but they also open up new attack surfaces.As always in crypto, convenience must be balanced with paranoia. Double-check everything. Trust no extension blindly. And if you’ve ever typed a seed phrase into an extension, you should migrate your funds now.The attackers are evolving. So must our defenses.Stay safe, stay skeptical.

1 likes46 reads
Nomnom
Nomnom

July 08, 2025

General Discussion
Chainbounty

Close or ongoing bounty point.

0 likes27 reads
Deactivated User
Deactivated User

July 08, 2025

General Discussion
체인바운티 왜 입금 안돼죠?

CBP 모은거 전환하지 하루가 다 되어가는데왜 아직도 지갑에 체인바운티 입금 안돼죠?

체인바운티 왜 입금 안돼죠?
1 likes86 reads
Firzapennn
Firzapennn

July 07, 2025

General Discussion
AMA ECLIPSE

🕺 [AMA] 10분 뒤 : 한국에 어서오너라 ECLIPSE- 일시: 오늘밤 11시- 장소: 코인같이투자 스페이스- 손님: Nate, CMO of Eclipse이제 체커도 나오고 재단도 설립한 이클립스가 곧 한국을 온다길래 AMA 스케쥴을 잡았습니다. 여러가지 궁금해 할 사안들과 이클립스가 그동안 어떤 것을 해왔는지에 대해 묻는 시간을 가질 예정이니 이클립스 원령들은 많은 참여 부탁드립니다!📂 이벤트: 스페이스 공지 원문 Like RT: 인증샷 방에 스페이스 참여 인증샷 제출: 구글폼 작성상품: 커피 100잔 + 혹시 모를 스페셜 리워드나중에 만나요~

0 likes24 reads
Nomnom
Nomnom

July 06, 2025

Blockchain Insights
Btc

BTC up to $150000 or not

2 likes28 reads
Deactivated User
Deactivated User

July 06, 2025

General Discussion
톡큰 체인바운티 브릿지 교환 성공

아비트럼 이더리움만 충분히보유하고 있으면 되네요

톡큰 체인바운티 브릿지 교환 성공
2 likes40 reads
Deactivated User
Deactivated User

July 06, 2025

General Discussion
톡큰에서 체인바운티 메인넷 지원하네요

브릿지 이용해봤는데 됩니다클레임까지 되는지는 봐야겠네요

2 likes31 reads
UppSecEcho
UppSecEcho

July 01, 2025

Blockchain Insights
🚨 How a Single Wei Broke ResupplyFi: Inside the $9.6M DeFi Price Manipulation Heist

On June 26, 2025, ResupplyFi—a decentralized stablecoin and lending protocol—became the latest victim in a string of DeFi price manipulation attacks, losing an estimated $9.6 million from its wstUSR lending market.But this wasn’t a typical exploit. This was a surgical, precision-driven manipulation that started with just 1 wei and ended in millions.Here’s how it happened, why it worked, and what this means for the future of DeFi.🧨 The Attack at a Glance• Target: ResupplyFi’s wstUSR market• Method: Oracle manipulation via ERC-4626 vault logic bug• Funds lost: ~$9.6 million in reUSD• Exploited function: _updateExchangeRate() in ResupplyPair contract• Timeline: Single transaction drain within minutes🛠️ How the Exploit WorkedAt the heart of the attack was a poorly designed exchange rate oracle within ResupplyFi’s vault contract. Specifically, the exchangeRate was derived using a value called pricePerShare, common in ERC 4626 vaults.But here’s the catch:➤ The attacker deposited 1 wei into an almost empty vault.This gave them control over how the vault's pricePerShare would respond to subsequent “donations.”➤ Then, they made a large “donation” to the vault.This artificially inflated the share price, skewing the oracle rate. Because of a logic flaw, the protocol calculated the exchangeRate as 0, tricking the system into thinking the collateral was worthless.➤ Result:The attacker borrowed $10 million worth of reUSD against 0 value collateral.⚠️ What Went Wrong?• Broken Oracle Assumptions: The system trusted pricePerShare as a real-world oracle without validation.• No Lower Bound Check: Allowing exchangeRate to drop to zero effectively bypassed the collateralization check.• Missing Guardrails: There were no sanity limits on extreme values coming from vault math.💸 The Drain & LaunderingThe attacker didn’t stick around.They quickly converted stolen reUSD into ETH Funds are now sitting at 0x886f786618623fffb2be59830a47661ae6492e160x31129a5c13306a48e827e851d44e19ca07d4928a🧠 Lessons for the DeFi WorldThis hack joins a growing list of oracle manipulation exploits where DeFi protocols underestimate how easily “trusted” math can be gamed in low-liquidity or edge-case scenarios.✅ Key takeaways for builders:• Never trust raw vault math without bounds.• Validate pricePerShare with a circuit breaker or floor value.• Use multiple oracles for redundancy.• Simulate edge cases with small deposits in testing environments.🗣️ Final ThoughtsThe ResupplyFi exploit is another reminder that a single wei, when paired with flawed logic, can dismantle an entire system.As DeFi continues to innovate, we must slow down and ensure that core primitives like oracles, vaults, and pricing logic are built with security-first principles.If not, there will always be someone waiting to turn one wei into one more heist.

1 likes79 reads