Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

Introducing: Social Logins Create wallets bound to your socials (Google, Apple ID or email) ❌ No seed phrases = no leakages ✅ Private keys are encrypted, backed up in cloud + TEE tech Easier onboarding. Same security layers. Still self-custodial. Making #Crypto4Everyone easy

78,894 Aufrufe • vor 9 Monaten •via X (Twitter)

0 Kommentare

Keine Kommentare verfügbar

Kommentare vom Original-Post werden hier angezeigt

Ähnliche Videos

ZKForge V1 is now live and the source code is public on GitHub: Visit: Users can sign up, log in, and chat privately using zero-knowledge authentication (ZK-STARK) with full end-to-end encryption and non-custodial wallet integration. No passwords, no stored private keys, all encryption and identity verification happen locally on the user’s device. Core Features • Zero-Knowledge Authentication (ZKAuth) Users sign up and log in using a locally generated Ed25519 keypair. Authentication uses zero-knowledge proofs (ZK-STARK-compatible), proving identity ownership without revealing the secret key. The backend never sees or stores private keys , only the derived public key and Solana address. • End-to-End Chat Encryption Every conversation is encrypted with per-room symmetric keys (nacl.secretbox AES-grade security). Keys are sealed and exchanged using ephemeral Curve25519 boxes derived from each user’s Ed25519 keypair. Messages are signed for sender authenticity. The server cannot decrypt messages; all encryption happens client-side. • Global Lounge (Public Encrypted Room) Encrypted public discussion room using a temporary shared key. Messages self-destruct after a defined time window. Rate-limit and anti-spam protections are enforced through Supabase RLS policies. • Wallet Integration (Non-Custodial) Each user derives a Solana wallet from their zero-knowledge secret. Private keys are generated and stored locally, never sent to the backend. Supports in-app USDC transactions signed locally. • WebSocket-Based Real-Time Updates Secure WebSocket channel for live message delivery, typing indicators, and presence tracking. Each message includes cryptographic nonce, ciphertext, and signature validation before render. Architecture Overview Frontend (React + Tailwind): Encryption, proof generation, local key storage, message rendering. Backend (Express + Supabase): Stateless API for sessions, rate limits, and metadata. Crypto Layer (tweetnacl, ed2curve, bs58): Signing, sealing, encryption primitives. Database (Supabase PostgreSQL): Stores ciphertext and public keys only. Realtime (WebSocket): Delivers encrypted payloads instantly. Key Design Principles Zero Storage of Private Keys All signing keys exist only in the user’s local storage. Provable Authentication Login requests include cryptographic proofs verified without revealing secrets. Encrypted-At-Rest and In-Transit All messages are encrypted before leaving the device. Verifiable Sender Identity Each message includes a detached Ed25519 signature verifying authorship. Tech Stack Frontend: React, TailwindCSS, TypeScript, Vite Backend: Node.js (Express), Supabase, MongoDB Cryptography: TweetNaCl, ed2curve, bs58, genSTARK Blockchain: Solana Web3.js Realtime: WebSockets Security: Row-Level Security, JWT Sessions, Proof Verification What’s next x402 protocol implementation

ZKForge

24,207 Aufrufe • vor 10 Monaten

WATCH: CNN’s Scott Jennings absolutely embarrasses liberal historian Tim Naftali for making Nixon-Trump comparisons about the federal government using citizenship information to ensure only American citizens are voting... Naftali: “How do we know that the Social Security information that would be used by the federal government would be used for the purposes that some people are saying it would be used for? It might be used to go after people. So, isn't it better that the federal government not share our private information.” Jennings: “Go after them for what? Naftali: “We have an administration that looks for whatever weakness or opportunity to indict people, the people they don't agree with. They've taken what Richard Nixon did secretly and made it an overt policy of the United States. Jennings: “You're saying we could take your social security number, and somehow —” Naftali: “You could do all kinds of terrible things. Jennings: “— divine your political leanings?” Naftali: “You could — you could, well, Social Security — the idea was Social Security information. Abby Phillip: “I think the answer is potentially yes. There's a — there's a reason Social Security numbers are one of the most private pieces of information that Americans have.” Naftali: “Scott, Scott, Do you support the establishment of ID cards for Americans? Jennings: “Of ID cards?” Naftali: “Yes. All Americans should have an ID card.” Jennings: “You mean like the driver's license in my wallet?” Naftali: “No, no, no, no, no. A national ID card because that has — the Republican party — Jennings: “Like a Social Security card in my bag?” Naftali: “No, no, no, the Republican party has been against national ID cards.” Jennings: “Like a passport?” Naftali: “No, no. Require it because of the concern of centralizing private information in a place where it could be misused by the federal government. And — and why should we do that now? Why should we allow people to have access for Social Security information for political purposes?”

Curtis Houck

36,841 Aufrufe • vor 3 Monaten

YOUR HARDWARE WALLET SUCKS. PERIOD. ZachXBT just said what we've known for years: hardware wallets are garbage. We won't go as far but we surely feel they are not for everyone. They are for advanced users and by no means for wallets that are meant to be accessed frequently. There is one thing hardware wallets are good at: that is keeping crypto secure if someone physically trying to rip private keys (those that give you access to crypto) out of the chip. The reality is that attack almost never happens!😀 When it comes to the attacks that actually drain wallets, hardware wallets make them worse: >> 1. NOT DISCREETE The moment someone sees that little device, you're a confirmed high-value target. >> 2. LEAKED EMAILS AND ADDRESSES Buying one doxxed thousands of people. Leaked customer databases with the real names and home addresses. You just joined a phishing hit list. Emails targeting hardware wallet owners are now so convincing that even veterans get fooled. Privacy can't fail harder than that. >> 3. PAPER BACKUPS You still write your keys on paper. The seed phrase backup negates the entire point of the device. BTW, mobile wallets already moved on: Unstoppable now has passkey wallets allowing to create and restore with zero seed phrase, secured by your device. That will likely become the golden standard in the future. >> 4. YOUR PHONE ALREADY HAS A VAULT Your phone is designed for security. There's a state of the art secure storage chips in your pocket already. Apple and Google built isolated secure elements to guard the most sensitive data in your life. If integrated right by the devs, it's the most battle-tested security hardware on earth. >> 5. MOBILE APP = DISCREETE Nobody knows you're carrying a vault. A phone is the most discreet way to hold crypto. >> 6. MOBILE APPS CAN BUILT CREATIVE SECURITY FEATURES The mobile OS allows many possibilities for secure use. Hardware wallets are meant to stay primitive by design and therefore can't ship security features that are are needed. - Your wallet can wear a disguise. Some wallet apps look like calculators. - Unstoppable's Duress Mode gives you unlimited unlock PINs - under coercion, you show a decoy and keep the rest invisible. - Unstoppable's phishing protection catches look-alike addresses before you send - blocking the #1 way people actually lose crypto today. Hardware wallets solved 2015's problem. Your phone solves 2026's. MOBILE WALLETS ARE THE FUTURE!

Unstoppable | Privacy Wallet

21,732 Aufrufe • vor 2 Monaten

HERMES AGENT IS NOW IN THE CLOUD. NO VPS. NO TERMINAL. NO SETUP. PICK A MODEL. PICK A SERVER SIZE. AGENT IS LIVE IN 60 SECONDS. Nous Portal just launched hosted Hermes Agent. two clicks. one minute. done. Nous Research WHAT THIS MEANS: before today: install Hermes on a VPS or your laptop. configure providers. set up gateway. manage updates. run hermes setup. edit config.yaml. great for power users. friction for everyone else. now: go to pick a model. pick a server size. your agent is live and reachable in 60 seconds. no terminal. no SSH. no Docker. same Hermes. same features. same tools. someone else handles the infrastructure. FOR TEAMS: this is where it gets interesting. spin up agents for everyone at your org. each team member gets their own Hermes instance. granular access controls per user. unified billing through Nous Portal. your team gets Hermes on day one. no DevOps needed. no VPS per person. one admin dashboard. one bill. WHAT'S INCLUDED: → 300+ models via Nous Portal (Claude, GPT, Gemini, DeepSeek, Grok, MiniMax, and more) → Tool Gateway (web search, image generation, TTS, browser automation) → all messaging platforms (Telegram, Discord, Slack, WhatsApp, Signal) → full feature set (profiles, cron, kanban, skills, memory, sub-agents, MoA, /goal, /learn, /journey) → automatic updates ONE PORTAL. FOUR TIERS: Free: $0/month. pay-as-you-go credits from $10. Plus: $20/month. $22 in monthly usage credit. Super: $100/month. $110 in monthly credit. Ultra: $200/month. $220 in monthly credit. highest rate limits. every paid tier includes Tool Gateway. one OAuth. one subscription. no extra API keys. SELF-HOSTED IS NOT GOING ANYWHERE: Hermes is MIT licensed. open source. free forever. you can still run it on your laptop, VPS, or GPU cluster. nothing changes for self-hosted users. the cloud version is for people who want the agent running without managing the machine. pick your path: → self-hosted: full control. you manage everything. → cloud: zero ops. Nous manages infrastructure. → hybrid: self-host your main agent, cloud for team members. HOW TO START: cloud: self-hosted: hermes setup --portal both connect to the same Nous Portal. same models. same tools. same billing. learn how to replace your entire team with 8 hermes agents 👇

YanXbt

45,446 Aufrufe • vor 2 Monaten

Private transactions between wallets now possible on Solana using ZERAs Private Cash Addresses. A closer look at last week’s MVP drop: Private P2P. Most "privacy" on Solana still falls back to withdraw-to-address (recipient + metadata leaks) or multi-step send flows that leave trails. Our P2P is different: one atomic in-pool transaction, the sender’s note is nullified, and two new encrypted notes are created, all inside the vault. No stepping out. No re-deposit choreography. Why it’s so hard to deanonymize: ✅ Your Private Cash Address has zero link to your Solana wallet: it’s an X25519 keypair derived from a wallet signature, and the public key becomes your private address. ✅ Notes are encrypted with NaCl box using a fresh ephemeral key every send, meaning even two payments to the same person looks unrelated. ✅ Recipients discover incoming notes via trial decryption, the chain never learns "who owns what." While we have immense respect for those building privacy on Solana, we are proud to be the first to achieve one-shot, in-pool P2P with full privacy. To our knowledge, this remains an industry first. This is the difference between hiding balances inside a pool and moving value privately between people. Note: Right now, the sender’s wallet still signs the private transaction, so on-chain you can see that a wallet performed a P2P action, but the amount and recipient remain private. The upcoming P2P Relayer removes that footprint too, completing the "cash-style" flow with no on-chain sender trace. What’s coming next: ✅ More assets: At least SOL + ZERA alongside USDC. ✅ P2P Relayer: A decentralized signing/relaying network that can submit transactions for you — enabling withdrawals with minimal linkage after the initial deposit, and removing the sender’s on-chain P2P footprint. Try it out in the ZERA Dashboard below ⤵️

ZERA

36,595 Aufrufe • vor 6 Monaten

Most crypto wallets make you choose between self custody and real world compatibility 💰 Avici just solved that with Named Virtual Accounts This is the bridge we've been waiting for 1/ THE SETUP You want to hold your own keys But your employer pays via bank transfer. Your contractor only accepts wire payments. Your family sends money through traditional rails Every offramp eats fees and forces you back into custodial accounts That friction keeps most people stuck in banks 2/ THE BREAKTHROUGH Avici gives you real account numbers and IBANs powered by MoonPay 🟣 Anyone can send you fiat through normal bank transfers It auto converts to USDC or EUROC and lands in YOUR self custodial wallet on Solana Fiat compatibility with true ownership 🔐 3/ HOW IT WORKS Receiving: → Someone sends $1,000 USD or €1,000 SEPA to your account number → System auto converts to stablecoins → Lands in your Avici wallet under your control Sending: → You hold 1,000 USDC in Avici → Add payee bank details in app → You send stablecoins, they receive fiat One click. No CEX stops in between 4/ WHY THIS MATTERS This isn't just a better offramp It's the infrastructure that makes stablecoins actually usable in a fiat world without giving up custody Your primary account stays self custodial while working with every business and person still on traditional rails The more this works at scale, the less you need traditional banks at all -- Avici is building what internet money was supposed to look like from day one Named Virtual Accounts are live now. Self custody meets real world compatibility without compromise

DeFi Oracle 🔮

21,340 Aufrufe • vor 7 Monaten

You can't pretend you care about security if you are still sharing API tokens in .env files or sharing SSH keys. This might be good enough to provide simple access to a resource, but it's a horrible way to do security when it really matters. Look into "Identity-Based Access". The state of the art today is Identity-Based Access. With traditional security, you have to present a key to get access to the resource (an API key, a password, or an SSH key). These are long-lived keys you need to keep secret somehow. If somebody steals your key, they become you and get the same access you had. With Identity-Based Access, you need to prove who you are instead. If you are a human, you can prove this with a passkey, SSO with Google or GitHub, or Multi-Factor Authentication. If you are a computer, you can use AWS IAM, Kubernetes, a cloud service account, or any other trusted environment. Once the system verifies your identity, it checks your permissions and gives you a short-lived credential. Prove identity → Permissions → Short-lived credential → Access The difference here is huge, because those credentials are: • Short-lived • Tied to a specific identity • Scoped to specific permissions • Automatically expired • Much easier to audit In practice, implementing this is as simple as integrating with Teleport, which will handle everything for you. Here is a full explanation of how Teleport works and how you can start using it: Thanks to the Teleport team for partnering with me on this post.

Santiago

20,971 Aufrufe • vor 1 Monat