Most articles on the npm worm did not provide tangible practices or a clear course of action for preventing future attacks. We know because we studied more than 20 articles on the subject 😮💨
Here's our take on what to do, a collab with @alcuadrado 🫡
blog.theredguild.org/how-to-npm-and…
New Free Training: Operational Security for Non-technical Web3 Teams
Thursday 2 Oct | 4–5pm CEST | Online
Not just devs! BDs, marketers, community managers & execs face cyber threats too.
Seats are limited, secure yours now: docs.google.com/forms/d/14TUFp…
Everyone talks about zkVMs. Few talk about the constraint languages that define them.
We demonstrated examples with Halo2, Zirgen, and Plonky3 AIR.
Not to benchmark, but to show how each expresses computation: hexens.io/blog/zkvm-dsls
Thank you for accepting my application @rektoff_xyz. The next step in cementing my skills to help secure web3. I said it before, but will say it here again. Find something you love to do and it won't feel like work.
last call to get into cohort #2
(apps after that go straight to the waitlist for cohort #3)
soft close TODAY, sept 24, 11:59pm est
75 seats. 6 weeks. free to join
🦀
rektoff.xyz/bootcamp
Experimenting with an AI automation that can get one of your contracts to 100% of coverage.
Looking for feedback and to improve it.
Anyone interested in trying it out?
Today's research lead to a deeper understanding, of hardware and Rust handling of reading values in registers. The difference (or similarity) in X86_64 and ARM and registers, and RISC-V calls and implementing opcodes. zkVM compilers,transpilers and elf files. Memory and segments.
Be careful if you use Booking.
If you get a sudden invitation to an event where the host pays for all the costs, and it seems too good to be true, be careful. There is some phishing that I haven't fully analyzed yet, but it involves attackers hijacking Booking profiles ⬇️
cohort #2 is loading ⟳
maybe you’re doubting if you should apply
maybe you already applied and wonder if it’s worth joining if accepted
that’s why we’re running an AMA with your tutors:
@m4rio_eth
daniel cumming (@rv_inc)
lucas (ops guy @rektoff_xyz)
-> monday, sept 22
->…
48 Followers 542 FollowingI have been working in the penetration testing for web, API and mobile since 2019 I was working for an American company as a web application penetration tester
379 Followers 1K FollowingI tweet about web3 tech, products and security
Web3 and DeFi since 2016
Founder at FipeFinance
Top auditor at @stronghold_dao
32K Followers 489 FollowingRISC-V International is the non-profit home of the open standard RISC-V Instruction Set Architecture (ISA), related specifications, and stakeholder community.
712 Followers 93 FollowingSolo auditors, made mainstream.
Commission-free, vetted network of top SRs.
Browse, filter, connect — or ask us to matchmake.
👇👇👇
4K Followers 20 FollowingA unique annual event for education and technical advances in securing blockchain decentralized applications.
Nov 20-21, 2025
📍La Rural, Buenos Aires
657 Followers 267 FollowingHome of the Offbeat Blog created with the goal of engaging the blocksec community, sharing ideas, and increasing collaboration.
❤️ Together we are strong 🦾