Forwarded from Ahboyash Reads
https://safe.global/blog/safe-research-meet-erc-7955-no-private-key-required
一种新型的 create2 工厂合约的部署方案
一种新型的 create2 工厂合约的部署方案
https://jdstaerk.substack.com/p/we-just-found-malicious-code-in-the
大规模供应链攻击,主要是 chalk 受影响
大规模供应链攻击,主要是 chalk 受影响
Substack
Anatomy of a Billion-Download NPM Supply-Chain Attack
A massive NPM supply chain attack has compromised foundational packages like Chalk, affecting over 1 billion weekly downloads. We dissect the crypto-stealing malware and show you how to protect your projects immediately.
https://blog.trailofbits.com/2025/09/10/how-sui-move-rethinks-flash-loan-security/
#Sui 使用 object 模型优化闪电贷
#Sui 使用 object 模型优化闪电贷
The Trail of Bits Blog
How Sui Move rethinks flash loan security
Sui’s Move language significantly improves flash loan security by replacing Solidity’s reliance on callbacks and runtime checks with a “hot potato” model that enforces repayment at the language level. This shift makes flash loan security a language guarantee…