sudo rm -rf --no-preserve-root /

@pcaversaccio.com

𝐖𝐨𝐫𝐤𝐢𝐧𝐠 𝐨𝐧 𝐰𝐡𝐚𝐭'𝐬 𝐧𝐞𝐱𝐭. ꟼGꟼ: 063E 966C 93AB 4356 492F E032 7C3B 4B4B 7725 111F 📌 w021d 🔗 github.com/pcaversaccio

if someone ever managed to breach all _private_ GitHub repos (I mean it's insanely difficult but not impossible) it would be one of the most catastrophic events in the security history, and if I were a state-level actor that's exactly the kind of target I'd prioritise rn.

1/ Ethereum's worst enemy is institutional adoption. Honestly, think about it guys, the more institutions get involved, the more influence they wanna have on future hard fork decisions (and thus will make a core dev's job even more complicated),...

1/ The soul of Ethereum was Cypherpunk. It _is_ Cypherpunk. It will always be Cypherpunk. You can chase your glossy, VC-driven narratives, build your fancy protocols, but the ones that will endure are the ones that preserve our privacy, defend against censorship & stand tall in the face of tyranny.

1/ This morning I've been reviewing our last months' SEAL 911 tickets. Guys, it's clear that soon (probably sooner than you think) a large portion of our ecosystem will be running on compromised devices. I mean, man, infostealers are probably the _biggest_ ecosystem problem right now.

My periodic reminder: if someone offers you a slick-looking hardware gadget at EthCC (or any other crypto event), don't plug it in, don't take it home. Just walk away. Treat it like malware wearing a shiny casing. We've got enough infostealers in the wild already.

so I've been thinking about this for a while now and I'm more and more convinced that crypto was never meant for mainstream. The main reason being that crypto's purpose is _liberation_, not popularity. It's effectively for those who choose sovereignty over simplicity.

you know, I'm a simple guy: I roll (mostly) with ETH, Tornado Cash, Railgun, BTC, Zcash, and XMR these days. I don't use L2s. I don't use Solana. I don't use fancy DeFi protocols (I like it KISS and trustless). Simply put: just tools that work and don't ask permission.

1/ time for a quick vibes check on where our industry's at security-wise; well, folks, guess what, 95% of last months' SEAL 911 tickets were the same shitshows on repeat: folks running sketchy code some rando DMed them (stop cloning & running GH repos u got from random dude who asks for your "help")

1/ Most crypto work (partially mine included) runs on some sort of 'hope Microsoft keeps GitHub online' mode. Git is decentralised but GitHub isn't. Shutting down key repos is one of the easiest ways to censor or disrupt upgrades and dev coordination. And yes, Microsoft can do that.

1/ folks, can we please fucking stop normalising `curl | bash` as an installation method (yes, I'm also looking at you Foundry)? It's a _massive_ footgun that blindly executes remote code with zero verification. You're literally giving arbitrary internet bytes root access to your machine.

1/ People keep asking me since days how to secure their systems and what the best strategy is. I will be very honest with u all as I'm always. If u want real security (and there will be never 100% security), it's not (just) about tools—it's about fucking mindset. At least 80% of it is pure paranoia.

1/ Picture if all the resources poured into L2/L3 grifts had been directed at improving L1 directly. Picture a world without "select/add network", where shielded transactions are the standard, and an L1 with snooth cross-shard communication.

1/ The crypto bubble keeps circle jerking about how mass adoption is just around the corner, completely ignoring that this bold experiment started a _decade_ ago. The only real "adoption" we've seen so far is people getting rugged, phished, or scammed (& stablecoins tbf).