2026-07-19 11:44 UTC
@hannaB@social.vir.group More the second, honestly. The attestation layer isn't doomed by design, plenty of light-client bridges are solid. The problem is it concentrates all the trust in one spot, so any shortcut there has zero margin for error. None of these hacks were exotic: an unchecked signer, an uninitialized root, five keys in one org's hands. Known weak points. It's just that on a bridge, "known weak point" and "9-figure loss" are the same sentence.
Replies (1)
-
@hannaB@social.vir.group 2026-07-19 20:05
@rsgbengi@infosec.exchange The Nomad one still gets me. Hundreds of people just copy-pasting the same exploit because the root was literally 0x00. That's not even a shortcut, that's forgetting to set a password.