Haz Æ 41 Profile Banner
Haz Æ 41 Profile
Haz Æ 41

@hazae41

Followers
1,003
Following
232
Media
791
Statuses
3,692

Le diable se cache dans les détails • @BrumeWallet

☀️☀️☀️
Joined May 2020
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@hazae41
Haz Æ 41
12 days
Create immutable webapps that are secure and resilient against server-side attacks and censorship 🗿
3
2
15
@hazae41
Haz Æ 41
1 year
@hazae41
Haz Æ 41
1 year
the future
Tweet media one
5
40
286
2
30
672
@hazae41
Haz Æ 41
1 year
the future
Tweet media one
5
40
286
@hazae41
Haz Æ 41
1 year
@hazae41
Haz Æ 41
1 year
wait
Tweet media one
Tweet media two
Tweet media three
7
19
127
0
7
274
@hazae41
Haz Æ 41
1 year
@fireship_dev There had to be 21 iterations to accomplish this I'm still stuck with Java 8 btw
3
0
175
@hazae41
Haz Æ 41
6 months
@GigaBasedDad who are the 1%
Tweet media one
2
0
161
@hazae41
Haz Æ 41
1 year
wait
Tweet media one
Tweet media two
Tweet media three
7
19
127
@hazae41
Haz Æ 41
8 months
Dear @rainbowdotme 🌈 If you could stop injecting local databases in my app, corrupting the data of my users, and leaking their privacy by injecting your telemetry, that would be great Thanks☁️
Tweet media one
Tweet media two
9
11
108
@hazae41
Haz Æ 41
3 years
don't use Google, Facebook, Twitter ; own your identity and use @MetaMask , @rainbowdotme , @WalletConnect
Tweet media one
5
16
98
@hazae41
Haz Æ 41
1 year
@hazae41
Haz Æ 41
1 year
the library importooor
Tweet media one
3
8
44
0
5
105
@hazae41
Haz Æ 41
2 years
Tweet media one
2
8
97
@hazae41
Haz Æ 41
1 year
Each time you sign a structured message using Ledger's JavaScript SDK, it does a request to their servers 😳 This means they have the IP address of everyone who signs structured messages through their SDK (almost all wallets on the market 💀) Even worse, since you often send a
Tweet media one
Tweet media two
Tweet media three
6
9
59
@hazae41
Haz Æ 41
1 year
@PR0GRAMMERHUM0R The world if everyone used milliseconds since epoch instead of randomly timezoned datetime
3
1
57
@hazae41
Haz Æ 41
10 months
WalletConnect replied to my 2 critical vulnerabilities "Thanks for the report. It's a known and accepted issue and outside of the scope of our security bounties. Purpose of this feature is not to prevent such attacks but to make them harder." - With just one line of code I can
@hazae41
Haz Æ 41
10 months
WalletConnect continues to promote its Verify protocol, even though I reported them two critical vulnerabilities, and they won't respond to me
Tweet media one
11
0
9
8
5
49
@hazae41
Haz Æ 41
9 months
@ctjlewis my github is full because i'm unemployed
0
0
44
@hazae41
Haz Æ 41
1 year
Tweet media one
1
0
44
@hazae41
Haz Æ 41
1 year
the library importooor
Tweet media one
3
8
44
@hazae41
Haz Æ 41
7 months
WalletConnect is CRYPTO 😎 - Closed-source software - Requires listing in order to be used - Your privacy doesn't matter - Paid by VC money - Terrible security - OFAC zealotry Learn more👇
8
9
55
@hazae41
Haz Æ 41
11 months
Tweet media one
1
0
43
@hazae41
Haz Æ 41
6 months
Introducing Sighash — The decentralized version of the 4Bytes database (function hash to signature) Stored on @gnosischain and indexed by @graphprotocol
4
4
39
@hazae41
Haz Æ 41
2 years
Tweet media one
2
0
35
@hazae41
Haz Æ 41
1 year
@EricLarch Trusting the manufacturer one time when the device is made, is not the same as trusting the manufacturer all the time during the whole device life
1
2
39
@hazae41
Haz Æ 41
2 years
The Solidity Optimizor
Tweet media one
0
3
39
@hazae41
Haz Æ 41
6 months
1 like = 1 shame for Google
Tweet media one
5
0
39
@hazae41
Haz Æ 41
2 years
@hashnode i spend all my weekends refactoring all the mess i coded months agos when i was unskilled
Tweet media one
2
0
35
@hazae41
Haz Æ 41
1 year
@fireship_dev Github stars
0
0
36
@hazae41
Haz Æ 41
8 months
@protolambda You will enjoy @BrumeWallet : - Log of RPC calls, tx hashes, etc? 🚧 Coming soon - Account management that isolates each account?✅ Yes + multiple seeds per user - Introspection of signing requests? ✅ - Different RPCs for the same chain.✅ Yes + aggregated responses to know
4
6
35
@hazae41
Haz Æ 41
1 year
@matthew_d_green we need that recession
2
0
36
@hazae41
Haz Æ 41
1 year
@TheBTCTherapist @WhatBitcoinDid @ODELL @_pgauthier - "You do have xpubs but you had them before too on Ledger Live, right?" - "There is no real information for the IRS on this" Creepy conversation
1
0
29
@hazae41
Haz Æ 41
10 months
The next update is going to be SO GOOD - WalletConnect over Tor - Badge for active/inactive sessions - Badge for number of requests - Lower CPU and RAM usage - Better resource pooling - New logo - Custom nonce - A lot of bugs fixed Probably this week 🔥
1
2
27
@hazae41
Haz Æ 41
6 months
We just reached +80 users on Chrome 🔥
Tweet media one
6
0
27
@hazae41
Haz Æ 41
2 years
Tweet media one
2
0
24
@hazae41
Haz Æ 41
7 months
Sign-only — Sign transactions without sending them - Works on hardware wallets - Works on ERC-20 transfers - Works on custom data - Still requires internet to fetch gas price (for now) Available right now on the web version
Tweet media one
1
1
26
@hazae41
Haz Æ 41
1 year
@hazae41
Haz Æ 41
1 year
*without using Copilot
Tweet media one
1
1
7
0
0
23
@hazae41
Haz Æ 41
10 months
To people following me in an attempt to fork my stuff and fuck me You can't I did in 3 months as a solo dev what your whole company couldn't do in 3 years You don't have the required skills
6
0
27
@hazae41
Haz Æ 41
9 months
Imagine flagging a competitor as unsafe without any particular reason
Tweet media one
4
0
24
@hazae41
Haz Æ 41
7 months
Here is the first draft of @BrumeWallet governance contract 👀 Solidity devs, please take a look at it 🫡 Code: Spec:
10
5
27
@hazae41
Haz Æ 41
6 months
Now live 🔴
@hazae41
Haz Æ 41
6 months
☁️
Tweet media one
2
2
23
3
0
25
@hazae41
Haz Æ 41
1 year
- You're not worried about your privacy? - No, I use @BrumeWallet 🗿
Tweet media one
4
5
25
@hazae41
Haz Æ 41
1 year
All these Ethereum requests used a different Tor circuit and IP address, thanks to a new "just-in-time" pooling mechanism 🤯 This means that when using @BrumeWallet , every single wallet address can use a different IP address When we need to make a request, we take a random
3
7
24
@hazae41
Haz Æ 41
2 years
Dapps will soon be able to use Tor without any installation Imagine a Dapp that's hosted on IPFS, has a domain name on ENS, and has an API on Tor In other words, a reproducible front-end, a transparent domain, and a fully uncensorable API
4
6
23
@hazae41
Haz Æ 41
8 months
Not affecting @BrumeWallet 😎
@blockaid_
Blockaid
8 months
🚨 We've detected a potential supply chain attack on ledgerconnect kit 🚨 The attacker injected a wallet draining payload into the popular NPM package. This currently affects a couple of popular dapps including but not limited to
49
309
742
4
7
23
@hazae41
Haz Æ 41
7 months
Copy transaction hash without opening Etherscan
Tweet media one
@hazae41
Haz Æ 41
7 months
Send transactions but you have access to custom data and you can do offline signing
Tweet media one
Tweet media two
2
1
14
2
1
25
@hazae41
Haz Æ 41
1 year
Tweet media one
1
1
22
@hazae41
Haz Æ 41
6 months
☁️
Tweet media one
2
2
23
@hazae41
Haz Æ 41
1 year
Sign with Ledger ✅ This signature has been made from a Ledger without using Ledger SDK It's 100% private 🥷
Tweet media one
Tweet media two
@hazae41
Haz Æ 41
1 year
Ledger request-response using zero-copy reading and writing 🗿
Tweet media one
0
0
2
3
3
24
@hazae41
Haz Æ 41
1 year
@davidfowl CORS was made because browsers sent cookies by default, and instead of fixing the browsers, they made all websites requiring responses headers no one understands The worse is that now you have to make an OPTIONS request before your actual POST request, and double your bandwidth
5
0
23
@hazae41
Haz Æ 41
9 months
@PR0GRAMMERHUM0R Sell the support, so the more your code sucks, the more you get paid
0
1
23
@hazae41
Haz Æ 41
8 months
Snaps are coming soon to @BrumeWallet , with the strongest security thanks to WebAssembly and Rust This is an example JSON-RPC echo using Rust 😎
Tweet media one
4
1
23
@hazae41
Haz Æ 41
7 months
Create @PeanutProtocol link
Tweet media one
3
2
20
@hazae41
Haz Æ 41
1 year
How @BrumeWallet uses Tor to hide your IP address from Ethereum RPCs It creates an end-to-end encrypted tunnel between your computer and the Ethereum RPC This tunnel is in fact a path of 3 Tor nodes that encrypt and route your packets back-and-forth between your computer and
Tweet media one
5
4
22
@hazae41
Haz Æ 41
5 months
Not enough gas? Get some for free and fully anonymously, powered by Network protocol Coming soon to @BrumeWallet
Tweet media one
2
0
25
@hazae41
Haz Æ 41
8 months
@mynameis_davis "Some company liked our tweet back then"
0
0
20
@hazae41
Haz Æ 41
1 year
@m__btc @Harrythehorse8 This is how BTC became deflationary
Tweet media one
2
1
21
@hazae41
Haz Æ 41
1 year
5
0
20
@hazae41
Haz Æ 41
7 months
We just reached 50 users on @BrumeWallet Chrome extension 🔥
1
1
22
@hazae41
Haz Æ 41
2 years
Tweet media one
2
3
19
@hazae41
Haz Æ 41
2 years
@VitalikButerin @BigImpactHumans until your transaction gets stuck and you can't make another for one day because Metamask made a mistake in the fee estimation
18
0
10
@hazae41
Haz Æ 41
9 months
WalletConnect continues to promote its shitty "Verify" protocol as "safe", even though it still has a major security hole And they don't want to pay pentesters to fix it, they don't want to take any action and don't reply to security issues on GitHub and by email This is not a
Tweet media one
2
2
20
@hazae41
Haz Æ 41
8 months
Not your packages, not your software
1
1
20
@hazae41
Haz Æ 41
10 months
GM 🫡 Are you ready to see one of the most stupid vulnerability you will ever see in crypto space? Here is the first vulnerability I found about the WalletConnect's Verify API 👇
2
4
20
@hazae41
Haz Æ 41
2 years
@Timccopeland We are used to taxes
0
0
17
@hazae41
Haz Æ 41
6 months
Ah yes, I'm impersonating my own project
Tweet media one
Tweet media two
@hazae41
Haz Æ 41
6 months
1 like = 1 shame for Google
Tweet media one
5
0
39
2
0
18
@hazae41
Haz Æ 41
5 months
I just released @BrumeWallet 0.5.12 with transaction simulation 😎 Download in reply 👇
Tweet media one
5
0
19
@hazae41
Haz Æ 41
11 months
I have no words to say how fast the encoding is ⚡️ Best scenario on the left (bytes-to-bytes) is almost 700x times faster than Ethers 🤯 Worst scenario on the right (bytes-to-hex) is still 5x times faster than Viem 🤯
Tweet media one
Tweet media two
3
0
19
@hazae41
Haz Æ 41
11 months
"So you're telling me you reimplemented Tor, TLS, and various other protocols in JavaScript, made an Ethereum wallet out of it, reimplemented Ledger, WalletConnect, and various other protocols, and still have time to optimize your WebAssembly stuff to be 700x faster than Ethers?"
Tweet media one
6
5
19
@hazae41
Haz Æ 41
10 months
Just achieved 500 subscribers ☀️ Building in public works, if you find a way to show it Big thanks to everyone
2
0
19
@hazae41
Haz Æ 41
6 months
We reached more than 110 users on Chrome 🤯
Tweet media one
0
0
17
@hazae41
Haz Æ 41
7 months
We just hit 70 users on @BrumeWallet Chrome extension, with 56 (80%) daily users 🤩
Tweet media one
1
1
18
@hazae41
Haz Æ 41
1 year
@CurveFinance Solidity / Vyper are such bad languages
7
0
17
@hazae41
Haz Æ 41
1 year
@jokoono But people wanted to use closed-source software from a random company
2
1
17
@hazae41
Haz Æ 41
7 months
I just claimed a @PeanutProtocol link made with @BrumeWallet
Tweet media one
0
0
17
@hazae41
Haz Æ 41
10 months
EIP-6963 is done
Tweet media one
2
0
18
@hazae41
Haz Æ 41
6 months
Brume 0.5.3 — Android - The wallet is now available as an APK for Android
3
0
17
@hazae41
Haz Æ 41
1 year
Tweet media one
1
3
16
@hazae41
Haz Æ 41
6 months
app + extension👀
Tweet media one
Tweet media two
0
0
17
@hazae41
Haz Æ 41
5 months
Just click the cute cloud
Tweet media one
1
0
16
@hazae41
Haz Æ 41
6 months
New wallet
Tweet media one
0
0
17
@hazae41
Haz Æ 41
10 months
Trade anonymously on GMX with @BrumeWallet and WalletConnect 🔥
Tweet media one
3
0
17
@hazae41
Haz Æ 41
7 months
@tsoding I would love someone criticizing my code because that would mean someone has actually read it
0
0
15
@hazae41
Haz Æ 41
9 months
Fuck it, the next big @BrumeWallet feature will be Account Abstraction
@hazae41
Haz Æ 41
9 months
What's the next big thing for @BrumeWallet ?
0
0
3
1
0
15
@hazae41
Haz Æ 41
2 years
i only use @developer_dao for memes, what you guys use it for?
5
1
16
@hazae41
Haz Æ 41
7 months
I just released @BrumeWallet 0.4.17 - You can now create @PeanutProtocol links from native tokens and ERC-20 tokens - Faster Tor resumption when the device becomes offline Download 👇
1
0
15
@hazae41
Haz Æ 41
7 months
Trezor coming soon to ⁦ @BrumeWallet
Tweet media one
2
1
14
@hazae41
Haz Æ 41
2 years
@hazae41
Haz Æ 41
2 years
The Solidity Optimizor
Tweet media one
0
3
39
0
0
14
@hazae41
Haz Æ 41
2 years
@vzverovich relevant
Tweet media one
0
0
16
@hazae41
Haz Æ 41
1 year
@peer_rich It's just a function that gets called whenever one of the deps changes And you can return a cleanup function that will get called on unmount / before the next call It doesn't require 200 IQ to understand that
1
0
16
@hazae41
Haz Æ 41
9 months
Brume Wallet users
Tweet media one
4
0
15
@hazae41
Haz Æ 41
7 months
Send transactions but you have access to custom data and you can do offline signing
Tweet media one
Tweet media two
2
1
14
@hazae41
Haz Æ 41
2 years
End of the game Here is a HTTPS (HTTP + TLS) request tunneled through Tor, all in the browser All the TLS stream is sent with Tor's RELAY_DATA cells, the final HTTP response is sent through this TLS stream Which means it's both end-to-end encrypted and anonymous
Tweet media one
@hazae41
Haz Æ 41
2 years
This HTTP request has been tunneled via Tor, entirely in the browser, using Fleche (HTTP) over Echalote (Tor) over Cadenas (TLS) TLS is used to establish an end-to-end encrypted connection between you and a Tor entry node Soon, TLS will be used over the exiting HTTP request
Tweet media one
0
0
0
1
2
15
@hazae41
Haz Æ 41
5 months
Some folks at Google Play Store are censoring our Android app with a fake "impersonation" reason They don't want to explain and don't want to hear anything, besides factual evidence that I'm the official developer I will publish the app to F-Droid very soon, the APK is already
@hazae41
Haz Æ 41
6 months
HELP NEEDED Does anyone know someone who work at Google? Thanks🫡
1
2
6
1
0
14
@hazae41
Haz Æ 41
9 months
2ms delay for a HTTPS request over Tor ⚡️🤯🎉
Tweet media one
0
1
15