frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Binance's Trust Wallet extension hacked; users lose $7M

https://www.web3isgoinggreat.com/?id=trust-wallet-hack
69•ilamont•2h ago

Comments

addams•1h ago
One of CZ's tweets hints at an insider threat, but Trust Wallet was one of the GitHub organizations pwned by Sha1 Hulud. What are the odds this is a fallout of that?
gigatexal•1h ago
I can’t have any more schadenfreude than I have now
3eb7988a1663•55m ago
That is a great domain name.
wyldfire•54m ago
I love the concept of cryptocoins. But in practice, there are some enormous hazards that make it not worthwhile IMO. This is just one such hazard, but by now we've seen several flavors of "this custody/storage mechanism failed to securely store some wealth." If securing it yourself, it's so easy to mishandle and either destroy your wealth or have it stolen. If delegating it to an "expert" you risk the custodial agent falling victim to theft/exit scam/ineptitude. Does any third party insure these agents?

Having a government-insured bank deposit means that I've never had to think about this in my lifetime. It's a problem that I don't need.

sunshine-o•14m ago
> Having a government-insured bank deposit means that I've never had to think about this in my lifetime. It's a problem that I don't need.

Government-insured bank deposits are mostly BS, the fine prints say they have about 10 years to reimburse you and in case of a systemic failure good luck.

In case the bank app, their "system" or your computer is compromised most banks will not reimburse you. It is very easy for them to say you were ultimately responsible for the hack. Very few banks have the policy of taking the loss and it is hard to know which one still do that unless you know someone in their fraud department.

sunshine-o•30m ago
I believe the Achilles' heel of Web3 is really that is was built on Web1&2.

Whatever opinion you might have about this industry, the core work is done by the Bitcoin and Ethereum teams and it is pretty admirable. They have been progressing for 10 years in a system where any mistake can collapse the entire system.

But ultimately those wallets and Web3 apps are built with web technologies and run in a browser and this is just not made for this.

This hack was targeting seed phases or private key because the keys have to be stored in the browser extension. How insane is that? But there isn't really any other ways to do it within the framework of a web browser.

Ultimately if the extension or web app is compromised an hardware wallet cannot really ultimately protect you (at least you would only be compromised when interacting with it).

Ethereum also now built in the secp256r1 signature checker so passkey/yubikey can be used but, same problem the "web" is the weak link.

Bottom line if they want that thing to succeed they will have to create a way to interact with smart contracts outside of the web browser. Maybe it will take building a simpler "dapp browser". Their apps are pretty basic in the end, a TUI would be enough to swap a token and approve a transaction...

Uptrenda•1m ago
But it has trust in the name. How can it be hacked?

Google is dead. Where do we go now?

https://www.circusscientist.com/2025/12/29/google-is-dead-where-do-we-go-now/
307•tomjuggler•2h ago•257 comments

ManusAI Joins Meta

https://manus.im/blog/manus-joins-meta-for-next-era-of-innovation
33•gniting•32m ago•18 comments

Flame Graphs vs Tree Maps vs Sunburst (2017)

https://www.brendangregg.com/blog/2017-02-06/flamegraphs-vs-treemaps-vs-sunburst.html
75•gudzpoz•2d ago•17 comments

Static Allocation with Zig

https://nickmonad.blog/2025/static-allocation-with-zig-kv/
144•todsacerdoti•6h ago•74 comments

List of domains censored by German ISPs

https://cuiiliste.de/domains
233•elcapitan•4h ago•90 comments

All Delisted Steam Games

https://delistedgames.com/all-delisted-steam-games/
140•Bondi_Blue•3h ago•53 comments

Left Behind: Futurist Fetishists, Prepping and the Abandonment of Earth (2019)

https://www.boundary2.org/2019/08/sarah-t-roberts-and-mel-hogan-left-behind-futurist-fetishists-p...
23•naves•3h ago•15 comments

A production bug that made me care about undefined behavior

https://gaultier.github.io/blog/the_production_bug_that_made_me_care_about_undefined_behavior.html
76•birdculture•4h ago•50 comments

AI is forcing us to write good code

https://bits.logic.inc/p/ai-is-forcing-us-to-write-good-code
41•sgk284•3h ago•23 comments

Which Humans? (2023)

https://osf.io/preprints/psyarxiv/5b26t_v1
24•surprisetalk•2h ago•14 comments

When someone says they hate your product

https://www.getflack.com/p/responding-to-negative-feedback
49•jger15•3h ago•51 comments

Show HN: Aroma: Every TCP Proxy Is Detectable with RTT Fingerprinting

https://github.com/Sakura-sx/Aroma
48•Sakura-sx•4d ago•25 comments

Stop Claude Code from forgetting everything

https://github.com/mutable-state-inc/ensue-skill
4•austinbaggio•26m ago•1 comments

AI Employees Don't Pay Taxes

https://alec.is/posts/ai-employees-dont-pay-taxes/
3•arm32•28m ago•1 comments

Obelisk 0.32: Cancellation, WebAPI, Postgres

https://obeli.sk/blog/announcing-obelisk-0-32/
9•tomasol•2h ago•1 comments

Show HN: Superset – Terminal to run 10 parallel coding agents

https://superset.sh/
50•avipeltz•6d ago•43 comments

GOG is getting acquired by its original co-founder

https://www.gog.com/blog/gog-is-getting-acquired-by-its-original-co-founder-what-it-means-for-you/
469•haunter•6h ago•265 comments

Libgodc: Write Go Programs for Sega Dreamcast

https://github.com/drpaneas/libgodc
188•drpaneas•9h ago•45 comments

Linux DAW: Help Linux musicians to quickly and easily find the tools they need

https://linuxdaw.org/
161•prmoustache•10h ago•79 comments

Kidnapped by Deutsche Bahn

https://www.theocharis.dev/blog/kidnapped-by-deutsche-bahn/
866•JeremyTheo•10h ago•805 comments

Pandas with Rows (2022)

https://datapythonista.me/blog/pandas-with-hundreds-of-millions-of-rows
6•fud101•3d ago•1 comments

High-performance C++ hash table using grouped SIMD metadata scanning

https://github.com/Cranot/grouped-simd-hashtable
36•rurban•5d ago•13 comments

Static Allocation for Compilers

https://matklad.github.io/2025/12/23/static-allocation-compilers.html
16•enz•6d ago•7 comments

Nvidia takes $5B stake in Intel under September agreement

https://www.reuters.com/legal/transactional/nvidia-takes-5-billion-stake-intel-under-september-ag...
166•taubek•5h ago•64 comments

You can't design software you don't work on

https://www.seangoedecke.com/you-cant-design-software-you-dont-work-on/
215•saikatsg•15h ago•75 comments

Show HN: Evidex – AI Clinical Search (RAG over PubMed/OpenAlex and SOAP Notes)

https://www.getevidex.com
28•amber_raza•5h ago•14 comments

Binance's Trust Wallet extension hacked; users lose $7M

https://www.web3isgoinggreat.com/?id=trust-wallet-hack
69•ilamont•2h ago•7 comments

Karpathy on Programming: "I've never felt this much behind"

https://twitter.com/karpathy/status/2004607146781278521
219•rishabhaiover•3d ago•201 comments

Why is calling my asm function from Rust slower than calling it from C?

https://ohadravid.github.io/posts/2025-12-rav1d-faster-asm/
90•gavide•2d ago•30 comments

Meta's ads tools started switching out top-performing ads with AI-generated ones

https://www.businessinsider.com/meta-ai-generating-bizarre-ads-advantage-plus-2025-10
104•zdw•3h ago•60 comments