@CryptoKaspi
iAccount based inSwitzerland
About this account
- Account based in
- Switzerland
- Connected via
- Switzerland App Store
Account-level information from X, not a live location or the device used for a specific post.
Head EMEA and Financial Institutions @ Ledger Enterprise. Securing onchain assets for institutions. Your keys, your independence. Sunny days = coffee rides.
Switzerland
Joined October 2023
- Tweets495
- Following341
- Followers92
- Likes553
Private $ZEC transactions are live!
🛡️🛡️🛡️Shielded Zcash transactions are now available in Ledger Wallet desktop 🛡️🛡️🛡️
I personally committed to this one. It took far longer than I expected, but it is now delivered, and that is what matters.
Privacy here is not a server setting. To keep your shielded balance private, the scanning and the transaction building happen on your machine: your unified viewing key is stored locally and is never shared with anyone, including us. That is exactly what made the integration trickier.
When it comes to signing the TX, the ZKP is computed on your machine (it's much faster with Ironwood now 🚀), and then the transaction is signed on your device, on a screen you can trust.
Make sure your Ledger Wallet Desktop and Zcash app are up-to-date, and you're good to interact with Ironwood!
Privacy is normal ✊
Stay safe.
This is why private keys do not belong on a general purpose OS. This is why @Ledger exists.
⚠️ ALERT: iPhone users warned of a potential Safari zero-day that could expose crypto private keys and seed phrases
Security researchers are warning iPhone users about a potential Safari zero-day exploit that could put sensitive data at risk, including cryptocurrency private keys, recovery phrases and information stored in Apple’s Keychain.
The reported attack involves a Safari-based exploit chain that could progress from WebKit/JavaScriptCore memory corruption to sandbox escape and kernel-level access.
The warning reportedly covers iOS versions ranging from 13 to 26.5, although the full range has not been independently confirmed.
If you use an iPhone, check for the latest iOS update and install it as soon as possible.
Avoid opening untrusted links in Safari, especially if you store crypto wallet data on your device.
Crypto. AI. Quantum computing.
Three technologies redefining security, trust, and who controls the infrastructure underneath both.
Each is transformative alone. Together they're raising a question nobody has fully answered yet: what does trusted infrastructure actually look like when all three are in play?
Been having fun building my own iOS apps for various use cases. Crypto portfolio tracker, coffee bean logging. Now built an app for #watchcollectors and decided to push it all the way through to the #AppStore. Two weeks later it made it live!
Incredible times we live in, as a product manager I always had to explain my ideas to developers and wait until they build it. No longer, so much fun!
Try it out here -> apps.apple.com/app/rotorfoli…
USDC on Arc. Secured by Ledger from Day 1 🔐
Arc is live, and your USDC on @Arc is fully usable in Ledger Wallet™ from the moment it launches. Send, receive, and swap and put our USDC to work with your keys in your hand the whole time.
Getting in early shouldn't mean compromising. Open Ledger Wallet and add your USDC on Arc today.
Kasper Luyckx retweeted
I’ve said many times that the CLARITY Act is essential to ensuring America wins the global race for new technology. That’s the reason Congress passed the GENIUS Act: to ensure that stablecoin infrastructure, a revolutionary financial technology, will be built in America.
Ensuring that America’s community bank sector continues to thrive has been a constant focus of mine since day one. And the administration’s dual focus on enabling new digital technology to flourish and appropriately tailoring community bank regulation is key to both sectors driving U.S. economic growth together over the next several decades.
The final draft of the CLARITY Act furthers this mission. It gives the Secretary of the Treasury additional authority to act if the facts around deposit flight change to the detriment of community banks. If stablecoins cause harm to community banks, I will not hesitate to use these tools to ensure they remain fully protected. Community banks are essential to U.S. economic performance and Main Street growth. Economic security is national security, and community banks play a major role in this principle.
Inflation and rates spiking at the same time, perfect storm. Looks like Iran has the leverage here. Oil needs to come down for rates to come down. Markets could react soon if things to do not settle. Not good for stocks, not good for crypto.
Good luck in preventing the proliferation of open source models around the globe, or agree with China how fast is “safe”. If you believe you’re driving too fast just slow down the car?
We Must Pace the Frontier: I’ve written a new essay on why the AI industry should slow down, with a three-part plan for doing so.
Anthropic is unilaterally committing to the first of these steps. We’ll provide third-party evaluators with permanent, employee-level access to our systems, so that they can verify adherence to our safety measures, report on incidents, and assess models’ alignment during training.
You can read the full post here: darioamodei.com/post/we-must…
Kasper Luyckx retweeted
Institutional crypto is growing. So is the sophistication of the people trying to take it.
When billions are on the table, governance and hardware security stop being best practice and start being the only practice.
@iancr and @sebadault on why institutions are the next big target — and how Ledger Enterprise is built for exactly this moment.
For years, the @DonjonLedger has found vulnerabilities across the ecosystem, and disclosed every one of them the right way: privately, patched, then published.
Today that standard becomes a shared industry commitment, alongside @Trezor, @FoundationHQ, @AnchorWatch and @_SEAL_Org.
Responsible disclosure protects users. Attention farming doesn't. 👇
📌 AI made finding bugs cheap, but it didn’t make responsible disclosure optional.
Finding and exploiting vulnerabilities has never been easier. A few hours of prompting now does what used to take a skilled researcher weeks. Unfortunately, defenders no longer enjoy the asymmetry they relied on. Security is still a cat-and-mouse game, but with many more cats, the user suffers.
Which is exactly why the process around disclosure matters more than ever.
How it works, and it is not complicated:
➤ A researcher finds a bug and contacts the vendor privately.
➤ The vendor reproduces, acknowledges, and both sides agree on a timeline. 90 days is the common default, more or less depending on severity, capacity to fix...
➤ During that window both sides keep it secret while the vendor fixes and ships.
➤ Once users are protected, both sides publish. The ecosystem learns. The researcher usually gets paid.
The issue now is the barrier is so low that anyone can surface a finding with no security background, and some skip straight to the audience:
❗Presenting a reproduction of an already-fixed bug as a live compromise.
❗Full disclosure of a bug that is not fixed yet.
❗"Critical vulnerability found" teasers, dripping details for engagement.
Call it what it is: attention farming with someone else's risk. When the bug sits between a user and their funds, this is reckless. Especially in crypto, where there is no chargeback. But the damage doesn't require live funds to be at stake. Manufactured panic causes harm of its own, because it drives people away from self-custody, and that damages the whole ecosystem.
So I have three asks:
1️⃣ For users: software and hardware have bugs, always. The single most effective thing you can do is stay updated and follow basic security hygiene. That has never mattered more than today. The time between releases and malicious actors exploiting the vulnerabilities have shrunk dramatically due to LLMs and that one can't afford to be passive and postpone security updates any more
2️⃣ For new researchers with a fresh model and a real, validated finding: welcome, we need you. Use the vendor's disclosure process. That is not bureaucracy. It is the difference between making the ecosystem safer and putting users in the crosshairs for a few likes. Remember that security communication must be accurate and proportionate. State the severity, affected versions, and fix status in the first sentence, not the tenth.
3️⃣ And to everyone building in this industry, vendors and researchers alike: let's make coordinated disclosure the norm we defend out loud, not the fine print. Reward the researchers who do it right. Refuse to amplify the ones who trade user safety for reach. This is how we win, together.
Some of the actors already support the initiative. @Ledger @Trezor @FoundationHQ @AnchorWatch @_SEAL_Org and others
Spread the message.
Another tragedy, about $320m stolen by the hacker. It seems there is a communication channel with the hacker, I hope the funds get returned. With AI models getting better at a rapid pace, hacks like these will accelerate. Everyone should be using the latest models to pentest systems and re-write their code.
Can't wait for Cybercabs to go mainstream. Humans will regain so much lost time. Sitting in traffic every day.
Friday GIVEAWAY anyone?
We thought we'd end the week on a high and give you the chance to win a Ledger Nano Gen5.
Here's how to enter:
1. RT this post
2. Follow @ledger
3. Comment which color Ledger signer you'd like to win
It's THAT simple. Lets go. 🔒