Agustin Gianni (@agustingianni) 's Twitter Profile
Agustin Gianni

@agustingianni

@coinspect - Mamma mia kernel mode is hard!

ID: 31419434

linkhttp://gruba.blogspot.com calendar_today15-04-2009 14:28:46

1,1K Tweet

1,1K Followers

1,1K Following

Coinspect Security (@coinspect) 's Twitter Profile Photo

As you know, we have multiple security research projects with an open-ended scope on #web3 and #crypto. This 🧵is on *Software Wallets* (1/5)

Coinspect Security (@coinspect) 's Twitter Profile Photo

Recently during our research on software wallet security, we came across a mobile wallet that was **automatically and silently** approving signature requests from connected DApps, which would allow an attacker to steal your all your favorite NFTs or tokens. 1/6 🧵

Sean Heelan (@seanhn) 's Twitter Profile Photo

New post on using CodeQL to find C/C++ code patterns that lead to missed auto-vectorisation opportunities. sean.heelan.io/2023/03/01/fin… I couldn't find many static analyses for optimisation that I could use off-the-shelf on arbitrary C/C++, so I built one myself. Summary: (1/N)

Agustin Gianni (@agustingianni) 's Twitter Profile Photo

"This week, we discovered that GitHub.com’s RSA SSH private key was briefly exposed in a public GitHub repository. " oooooofffff github.blog/2023-03-23-we-…

Coinspect Security (@coinspect) 's Twitter Profile Photo

🔎Our ongoing research on wallets contributes to the security of the crypto ecosystem. 💪 🚀 Check out our latest finding, which impacted over 40 vendors! 😲 📡 Stay tuned for further updates. 🌐 coinspect.com/chainId-EIP-71…

Coinspect Security (@coinspect) 's Twitter Profile Photo

Coinspect research 🔥🔥 Sorry for reporting on a friday 😬 dea5ad37fc03eb2c95336ebc089af3e67bb04a6d20896bd85754d956cb852a79

Agustin Gianni (@agustingianni) 's Twitter Profile Photo

Thanks easyJet for making us wait outside during snow while carrying a baby. Next time have the courtesy of letting us know in advance so we can at least dress for the occasion.

thaddeus e. grugq (@thegrugq) 's Twitter Profile Photo

Chromium money tree A map of all the bug bounties paid for Chrome, mapped to source files, in a tree. By Rebane lyra.horse/misc/chromium_…

Chromium money tree

A map of all the bug bounties paid for Chrome, mapped to source files, in a tree. 

By <a href="/rebane2001/">Rebane</a> 

lyra.horse/misc/chromium_…
Anton Gerashchenko (@gerashchenko_en) 's Twitter Profile Photo

Two-time European weightlifting champion Oleksandr Pielieshenko died at war “Defending Ukraine from the invaders, Honored Master of Sports of Ukraine, two-time European champion and Olympic weightlifting participant Oleksandr Pielieshenko died heroically,” Viktor Slobodianiuk,

Two-time European weightlifting champion Oleksandr Pielieshenko died at war 

“Defending Ukraine from the invaders, Honored Master of Sports of Ukraine, two-time European champion and Olympic weightlifting participant Oleksandr Pielieshenko died heroically,” Viktor Slobodianiuk,
Agustin Gianni (@agustingianni) 's Twitter Profile Photo

Has anyone else received Google Drive requests for files that are already public? Strangely, they’re asking for Editor access. Seems suspicious.

Coinspect Security (@coinspect) 's Twitter Profile Photo

🚨Coinspect's dApp integrity monitoring tool captured Compound's front-end attack. We are analyzing the JavaScript payload, join our Discord for updates discord.gg/DuwywSQK

Coinspect Security (@coinspect) 's Twitter Profile Photo

🚀 Wallet Security Ranking Launched! 🔎After months of thorough testing, our comprehensive crypto wallet security framework is live. ⚠️Which wallet do you use, and how did it score? ➡️We test, you decide. coinspect.com/wallets/

pspaul (@pspaul95) 's Twitter Profile Photo

Ever wondered what the Alt-Svc header is used for? Well, it can make you a MitM if you control it! I can finally publish the writeup to my GymTok challenge: control the header, become MitM, and perform a cross-protocol attack! blog.pspaul.de/posts/gymtok-b…

Coinspect Security (@coinspect) 's Twitter Profile Photo

🚨 Curve Finance Frontend Hijack Still Active DNS hijack began ~2025-05-12 21:30 UTC. Users visiting the Curve frontend are being served malicious JavaScript wallet drainer code. Malicious dApp is hosted via Cloudflare infrastructure. We’ll keep this thread updated. 🧵