Video yükleniyor...
Video Yüklenemedi
You MUST secure your web2 environment in order to secure your web3 environment. In this video, I show how one could steal a private key from your server using the react2shell exploit. Just by visiting your website. Update ASAP if you have not already!
11,991 görüntüleme • 9 ay önce •via X (Twitter)
31 Yorum

Well this is just one portion of getting rekt. Web2 has multiple ways to compromise your infrastructure resulting in private key takeover. Will be posting our recent finding, which helped us get into infrastructure of a very known protocol where we got full control of cloud and private keys were leaked in logs.

Or just be a real web3 project instead of pretending to be one and just be a shinier web2 project.

hackers right now watching Patrick

Nah, this is a pretty well-documented exploit.

Yep, and it turns out that most Web3 issues stem from problems we have long identified in classical IT security. Like proper key management :)

Yes!!!

I have a wild desire to enter this private key and see what's inside.

@ZeroNewLif It’s the anvil default key

Well, it would be funny if the teacher lost the key, even though he taught us to keep them separate.

Literally this!!!

wild seeing exploits bridge web2 gaps straight into web3 risk

attack surface feels bigger.

Thanks for this, Web3 is nothing without Web2.

CRITICAL risk. One Web2 slip and Web3 keys are gone. automate checks and patch fast

The old layers always matter 💯

Thanks for the clarity

So we should all learn nextjs now as web3 devs ???

Noooo - just a reminder to keep your key hygiene up

🤔

❤️

This is a good reminder that attack surfaces extend far beyond smart contracts.

do you think, rust/go based client-side apps could fix this? because any close to low-level language will be better than JS at security!

No, you have the same issue no matter what language you write the back end in

Thank You :)

I think we will write sites with WASM ))) daamn react is literally revealing framework

PATCH FASTTTT

You're absolutely right - securing that Web2 foundation is everything now. One vulnerable site visit and your Web3 assets could vanish. How often are you checking for these gaps? 🔐

react2shell sounds like a nightmare on tap

Wild times

This is nice 💯

thats wild gotta be more careful out there




