First #ETH Conference & Hackathon in Romania Re-building ๐Ÿšง

Bucharest
Gm frens! ๐Ÿซ‚ Updates #06 just dropped ๐Ÿงต โ†’ New partner community in Athens ๐Ÿ‡ฌ๐Ÿ‡ท โ†’ ETH Bucharest is heading to Devcon 8 in Mumbai ๐Ÿ‡ฎ๐Ÿ‡ณ โ†’ Belgrade + Amsterdam recaps โ†’ A packed month of shipping โ†’ 20% off security audits Let's go ๐Ÿ‘‡
2
1
9
613
Every valid ZK proof looks the same. So what stops a mixer withdrawal from being replayed? The nullifier. New @AdevarLabs piece by @InfectedCrypto on how @TornadoCash , @Zcash , and @penumbrazone build them, and shows in audits when they fail. Read on ๐Ÿ‘‡
Every valid ZK proof looks the same. So what stops you from withdrawing a mixer deposit twice? โž” The nullifier. In our latest article, @InfectedCrypto walks through how Tornado Cash, Zcash and Penumbra build them, and the audit findings that show up when they fail. adevarlabs.com/functions/bloโ€ฆ
4
111
Most protocol multisigs fail the same way: every key lives with the same team. An independent signer with its own nested multisig, hardware keys, metal backups, and a review SLA is how you stop one compromise from becoming a drain. Read on ๐Ÿ‘‡
What to expect when we come on as your independent multisig signer (Secure Governance Services): โ†’ Our key on your multisig is itself a multisig. Each of our signers generates keys on a dedicated hardware wallet, with backups engraved on metal and stored across physically separate locations. โ†’ We define a clear review and approval process before we sign anything, including turnaround times and escalation paths. โ†’ We review every proposed transaction, flag concerns, and sign within agreed timeframes. Contract upgrades get reviewed first, and we only sign if the hash of the code being deployed matches the code we reviewed. โ†’ We maintain defined protocols for emergency operations, key recovery, and signer replacement, so governance keeps working when something goes wrong. When all the keys on a multisig sit with the same team, one compromise can reach the whole threshold. An independent signer removes that weak link. Learn More Here: x.lingyaoai.com/banescusebi/status/210โ€ฆ
1
3
118
Gm frens! ๐Ÿซ‚ Updates #06 just dropped ๐Ÿงต โ†’ New partner community in Athens ๐Ÿ‡ฌ๐Ÿ‡ท โ†’ ETH Bucharest is heading to Devcon 8 in Mumbai ๐Ÿ‡ฎ๐Ÿ‡ณ โ†’ Belgrade + Amsterdam recaps โ†’ A packed month of shipping โ†’ 20% off security audits Let's go ๐Ÿ‘‡
2
1
9
613
๐Ÿ›ก๏ธ Shoutout to @AdevarLabs, our Security Partner ๐Ÿซก Audits, formal verification, fuzzing, pentesting, opsec. An @_SEAL_Org Certification Partner. Building toward mainnet? ๐Ÿ‘‰ 20% off all services, just mention ETH Bucharest adevarlabs.com/
1
4
51
2026 numbers from our security partner @AdevarLabs : Ops & access hacks lost far more than smart contract ones. Audits need to cover more than just code.
Here's what 2026 looked like so far: ๐Ÿ”บ96 operational and access hacks lost $811M. ๐Ÿ”บ204 code & smart contract hacks lost $152M. ๐Ÿ”บ44 other and mixed-vector hacks (oracle manipulation, bridge exploits, exit scams) lost $353M. Smart contract audits are essential for security. They just don't cover every door attackers are walking through this year. Your infrastructure, ops, and web2 attack surface need their own audits to close that gap. Ship Safely. ๐Ÿš€
1
1
147
Great insight from our security partner @AdevarLabs ๐Ÿ‘‡ Not every code change requires a full re-audit. Smart scope > blanket rules. Their Continuous Security approach reviews PRs based on actual impact so teams only pay for what the change truly touches. Worth a read ๐Ÿ‘‡
Some teams assume a code change means starting the audit over. Full repo, from scratch. The problem is that this gets applied unconditionally, whether or not the change actually calls for it. A client recently asked us on an intro call: when we change the code, we need to re-audit the whole repo, correct? The answer was no, not necessarily. It depends on what changed and what that change actually touches. That distinction is the entire argument for our service called โ€œcontinuous securityโ€, so it is worth being precise about it. A single-line change to an isolated helper function does not put your treasury logic back in question. A change to a shared state variable, an access control check, or anything else the rest of the system depends on might reach further than it looks, but it will rarely require a full re-audit. A one-time audit answers that question once, on one commit hash. It cannot tell you anything about the pull request you merge six weeks later. Continuous Security answers it perpetually. We plug into your development process and review pull requests before they merge, tracing each change out to what it actually affects instead of defaulting to the whole repo out of habit. Findings come with severity rankings, and we work through them with your team before the next cycle opens. The result is that you stop paying for a rule of thumb and start paying for the scope the change actually requires. More of our clients are making this same switch, for the same reason. It ends up costing much less compared to a full re-audit. We will always be truthful and tell you what your code actually needs.
1
3
121
Proud to partner with @ETHGreeceHQ Different country, same job: give builders a place to gather. ๐Ÿ‡ท๐Ÿ‡ด ๐Ÿค ๐Ÿ‡ฌ๐Ÿ‡ท Grateful for the standing invite to the Athens hub, and for treating community as the people, not the annual event. Two communities. One @ethereum Follow @ETHGreeceHQ
1/ Ethereum Greece has a new community partner: @ETHBucharest_, the flagship Ethereum conference and hackathon for Eastern Europe, based in Bucharest, Romania. Different country, same job: give the local Ethereum scene somewhere to gather. ๐Ÿ‡ฌ๐Ÿ‡ท๐Ÿ‡ท๐Ÿ‡ด
2
4
13
1,249
gm frens ๐Ÿซ‚ Updates #04 just dropped. Recap of Arbitrum Founders House, a new Security Partner, and everything shipping across Ethereum this month. Thread ๐Ÿงต
2
3
586
8/ ๐Ÿ—“๏ธ Where to find us this summer: - @ETHGlobal Lisbon (24 to 26 Jul) - @FWB Fest (31 Jul to 1 Aug) - Valley of the Commons - @VotC2026 (24 Aug to 20 Sep) - @ethbelgrade (26 to 27 Aug)
1
1
3
103