@Pybasti
iAccount based inFrance!
About this account
- Account based in
- France
- Connected via
- France App Store
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
CTO @Corkprotocol | EVM engineer | DeFi & smart contracts | Ex-CTO @Nefture | Summiting peaks & building protocols
Joined June 2014
- Tweets2.1K
- Following2K
- Followers1.3K
- Likes8.3K
Pinned Tweet
Thrilled to announce I’ve joined @Corkprotocol as CTO.
After a great run working for top web3 projects, traveling to conferences, and winning hackathons, it’s clear where I want to focus: bringing TradFi onchain.
🧵 Let me share what convinced me to join Cork (+ we are hiring)
What makes me especially excited to build Cork is the market growth for tokenized assets. We’re entering a new phase of scale:
• real world assets: $3B → $25B in 3 years,
• stablecoins: $260B total market,
• vault protocols like @MorphoLabs & @veda_labs: triple-digit growth
As DeFi is rapidly becoming TradFi’s technology backbone, this transition needs to happen with the same rigor, transparency, and automation that underpin traditional financial markets.
Cork is the solution, serving as a programmable risk layer for onchain assets such as vault tokens, yield-bearing stablecoins, and liquid (re)staking tokens.
Prior to joining Cork, I cofounded and was the CTO of @Nefture, a security product aiming to protect DeFi. Through this experience, I came to deeply understand one of the biggest challenges of DeFi, security.
More recently, I expanded my horizon and worked on:
• building a DeFi locker on Linea with @StakeDAOHQ,
• building a secure reward distribution system on Arbitrum with @cedelabs,
• analyzing Permit2 phishing scams with @RevokeCash,
• auditing an ERC4626 vault for @trumarket_tech,
• building UniV4 hooks at UHI @AtriumAcademy
• won 6 hackathons (@ETHGlobal, @alephhackathon), with projects actively developed like PolySwap (grant by @CoWSwap) and @BackupBuddy_io, well on its way to make wallet recovery secure and accessible,
• attended confs and popup cities, making amazing friends and deepening my understanding of the ambitious vision for @Ethereum. Best examples being @Zuitzerland where I spent a month learning about d/acc.
It’s this journey, when meeting @robdogeth at @EthCC, that allowed me to understand the important and inevitable vision of @Corkprotocol.
I’m incredibly excited to contribute to Cork’s vision of institutional-grade risk management for onchain finance.
The next trillion in liquidity will require transparent risk layers, and that’s what we’re here to build.
We’re working on cutting-edge DeFi and building a top-tier team. This is why I’m excited to be building here. If this is interesting to you, come build with me. We’ll be hiring a senior smart-contract developer to support our build (see link in the comments).
Follow @Pybast & @Corkprotocol to see what we're cooking!
Pybast retweeted
"If we had built mortgage-backed securities onchain, 2008 never happens."
@Philfog sat down with @TheCryptoMavs to unpack why risk management may be one of the biggest missing pieces in onchain finance.
Pybast retweeted
Security researchers are the backbone of onchain security today and across the broader internet. Because of them, we are surviving the AI security apocalypse.
And that has been forgotten.
Too many companies went from valuing SRs one day to abandoning them the next. They weren’t even thrown a life raft to follow along.
At Immunefi, we see things differently.
SRs were the core of security before, they remain the core of security today, and they will be the core of security tomorrow.
We need to figure out, as an industry and as a community, how we’re going to adapt to these changes; how to bring all security researchers with us, along with the recognition and support they deserve for keeping us safe thus far.
SR Summer was our way of showing a little recognition, and with Immunefi Studio, we will continue to put as much power in the hands of SRs as possible.
Thanks to all those who took part, and congratulations to the winners!
Pybast retweeted
"The gap is the invariant you forgot to write down. That is what a hacker goes looking for."
@Pybast on what "formally verified" actually tells you.
It is a real guarantee and a narrow one. A team specifies the rules that must always hold, the code becomes mathematics, and those rules are proven across every possible state rather than the states someone sampled. Anything not on the list is not covered by anything.
So when a protocol tells you it is verified, the useful follow up is what they proved, not whether they proved it.
Pybast retweeted
Replying to @VitalikButerin
I'm happy that Ethereum (Foundation) thinks about transactions. But I'm still waiting for the return from the moon maths trip to think about much more mundane but serious design flaws like what @PryvitKyle calls "reintroducing cross-origin tracking"
kyledenhartog.com/recreating…
Pybast retweeted
"You tell it that it cheated, and then it says it cannot reproduce it. So there was no issue."
@Pybast on a small ritual that has become part of reviewing code at Cork.
When someone suspects a bug, the fastest way to find out is to ask the model to attack it. Write the code that actually steals the money. If the theft works, the bug is real, and reading a short attack is much quicker than reading the whole system again to look for it.
The catch is that the model wants to succeed. So it sometimes writes an attack that only works because it handed itself a starting position the real system would never give it. A cheat, essentially, in service of a good answer.
You point it out, it tries again properly, and nothing happens, which tells you the bug was never there.
Pybast retweeted
Daily reminder that you should checkout @_SEAL_Org if you are building or working in crypto, their guides are great and for free
frameworks.securityalliance.…
Seems to be happening to lots of people.
What to do:
1. You're probably good, attackers need to guess a 6 digits code (1M possibilities)
2. To be safe, make sure you have 2FA enabled for your account (do it correctly to avoid losing your account)
3. Be extra careful if you encounter links or juicy announcements, they could be from accounts taken over
Good news, these security tips apply when such incident happens... and when they don't, use this opportunity to get yourself more secure!
Pybast retweeted
“Instant liquidity” means something different depending who you talk to. In traditional markets, T-0 or even T-1 (i.e. same-day or next-day settlement) is considered instant liquidity. Onchain, it means settlement in a matter of seconds.
This is a gap onchain finance needs to address. The use cases that people want from the assets moving onchain today require much more liquidity than those assets necessarily bring with them. No one is pricing liquidity risk right now. The market needs a mechanism to charge a known liquidity premium to truly enable these offchain assets to function optimally onchain.
Pybast retweeted
Most of the liquidity you see onchain isn't guaranteed. It's assumed. @Philfog on the latest Code to C-suite podcast.
As assets move onchain, people are treating them as if their liquidity is guaranteed. It isn’t. The underlying might redeem same-day in traditional markets, but the token that represents it can operate onchain without the same liquidity depth. What holders are agreeing to is a promise of a best-efforts basis to give them liquidity. And best-efforts liquidity can break when exit pressure rises quickly.
That's the gap the market still isn't pricing. Not whether an asset is good, but whether you can get out of it, at a known price, when you actually need to. Cork exists to make that liquidity availability guaranteed.
This video is larger than Cloudflare's 512 MB cache, so it can't be played through. More donations are needed to cover a larger cache. Donate
Pybast retweeted
Liquidation Heist: Breaking down the reUSD oracle manipulation attack
Last night an unknown wallet executed an oracle price manipulation attack which exposed highly levered looping trades in the PT-reUSD-10DEC2026/USDC Morpho market to be liquidated, resulting in $35,188,279 of liquidations and a net profit of $920,781 for the attacker. In this post I break down exactly what happened and what we can learn from it.
The Morpho Market Setup
In the last months, loopers have been flocking to a new form of yield arbitrage between reinsurance capital from Re (.xyz) and onchain borrow rates. The market which was attacked was the PT-reUSD-10DEC2026/USDC, which at it’s recent peak had $70m of borrows.
The primary use case for this market was to loop reUSD Pendle PTs, which were consistently earning about 10-11% fixed yield against the 8.8% average borrow rate in this market. At a Liquidation Loan-To-Value (LLTV) of 91.5%, loopers could lever up to 10.5 times and as a result achieve an annual yield of 34.6%. Since reUSD is a senior tranche reinsurance token, that is immediately redeemable onchain against a cash buffer the size of 50% of its supply (source: re docs) - the risk of holding reUSD is in theory fairly low from both a strategy and duration point of view, making it a suitable candidate for looping trades. As a result, this Morpho market attracted tons of borrowers and lenders (including vaults from Wintermute, Steakhouse, RockawayX, Clearstar, Keyrock - none of which lost any funds in this event).
The crucial kink in the armor of this trade from a loopers point of view, was the oracle configuration. It is configured as: PT/USDC price = min(Pendle 15-minute PT-to-USDC TWAP, 6% linear-discount curve). So it is the lower of either of the two rates: A linear discount model or a 15min time weighted average price (TWAP) of the PT denominated in USDC.
Steakhouse eloquently expressed the case for this design (which I agree with) as “generally good practice for Pendle oracles to mitigate the possibility of bad debt in the event of an impairment in the underlying asset. “ In practice, what this means is that if there is an impairment of the underlying reUSD, the oracle will pick this up. The alternative which many markets deploy is to hardcode the price with a time-decay curve which can result in bad debt if the underlying is impaired as we have seen multiple times in the past. Fundamentally, the design is a risk transfer from borrowers to lenders. The position becomes safer for lenders to underwrite, but exposes borrowers at extreme levels of leverage to liquidation in the event of even a small impairment of reUSD or the PT.
The attack
On Aug-25-2026 04:28:47 AM UTC a wallet (0x854e3f3b521dbae34cb111ebef0dce41d8b5690d) freshly funded with 1m$ from Gate, mints 1m$ worth of reUSD, converts it to Pendle SY reUSD and proceeds to use the funds to aggressively purchase YT-reUSD-10DEC2026, which has the consequence of roughly doubling the YT price from 0.029 to 0.0575, consequently dropping the PT side to to 0.9425 at the bottom (the Pendle chart below doesn’t show the true bottom).
Because borrower LTV ratios are calculated based on the value of the PTs as collateral, and these dropped in value by ~3%, this was sufficient to cause a cascade of liquidations. Liquidators earn a 2.616% incentive to perform liquidations in this event, which resulted in $920,781 in collected oracle bonuses.
The main liquidator contract (0x51a453d677396F62fbb1dff9925a205fa96fAB5e) was funded by the same Gate wallet at the same time as the oracle manipulator address, so we can safely assume this was the same actor.
Borrowers lost a total of $1,203,803 from the oracle bonus and liquidation at an unfavorable market rate. Because of relatively high rate of effective leverage, the equity losses amounted to approximately 30-40% for the affected borrowers (see img below).
The legality of this market operation is dubious at best. Given the funds came from a CEX at a relatively large size, it should be possible to trace the manipulation back to a specific entity. The legal precedence here is unclear, but this smells like crime.
Oracle design
The fundamental question this event raises is one of oracle design. Is it wise, to configure markets with 15 min TWAPs on thin liquidity, and support 70m$ of borrow capacity? I would argue the design is better than hardcoding oracles as many PT looping markets do, which has blown up for lenders more than once. A major challenge for borrowers is understanding the risks present in oracle design - which I believe as an ecosystem we need to do a better job at communicating. It is a wide and unstandardized design space, that is highly technical, which has huge implications on the risk for both borrowers and lenders. The devil, is truly in the detail. In this case, the oracle meant a risk transfer from lenders to borrowers. At the same time, borrowers are able to capture 34.6% yields at 10x leverage, so you might rightfully say “no wonder this comes at some risk!” - If you are levered to your tits and earning 30%+ yield, then you simply cannot cry in the casino.
I do think there is a fair critique to the oracle set-up in terms of it’s configuration compared to it’s design objectives. If the goal is to guard against impairment of reUSD - the oracle configuration should perhaps have some check against underlying impairment, before printing a lower value. This could balance both the needs of borrowers and lenders, without enabling this type of heist. Relying on Pendle secondary prices at a 15m TWAP, can be relatively easily manipulated, even with $30m+ of liquidity, as we saw today. At the same time, we cannot truly say the current design had a “bug”, in a sense the bug for the borrower is a feature for the lender.
Every blow-up is a chance to make the system itself more resilient, having spent a fair bit of time underwriting vault risk I think it is clear we have come quite far over the past year in terms of risk management and oracle configurations, but there is more work to be done. Onwards.
Give @robdogeth to stay up to date on crypto and vault risk.
Pybast retweeted
There's some FUD circulating about Ledger signers, pushed by a "smart contract security" company claiming a vulnerability in the Ledger Ethereum app.
There was a bug concerning certain clear signing flows. It was found by the @DonjonLedger using their AI-powered vulnerability research suite. It was fixed and deployed two weeks ago. If you keep your Ledger apps up to date, you are protected. That's the whole story.
Now the framing.
What actually happened: this company reached out to our bounty program after the fix was already shipped, and did not follow responsible disclosure, they actually never discussed with the bounty program team. Then they published a thread implying the problem is unsolved. It is not. That's not security research. That's manufacturing fear for attention.
Here is the uncomfortable part. AI changes the security landscape for everyone, defenders and attackers alike. The @DonjonLedger is leading on exactly this: using AI to find real bugs before they reach users. But AI-speed research only makes the ecosystem safer if the people doing it still follow basic security principles. Disclose responsibly. Verify before you publish. Don't confuse noise with a finding.
An actor who skips all of that is net negative for the ecosystem, regardless of the tooling behind them.
The takeaway for you is simple. Keep your Ledger signers up to date (update the FW, update the apps), keep your software up to date in general, and you benefit from the latest security work automatically. Ignore the FUD.
Stay safe.
Don’t sign Ethereum transactions on your Ledger until you’ve updated the Ethereum app to v1.22.2
Pybast retweeted
At Arbitrum Open House, Cork, @bondoncredit and @Zyfai_ got two AI agents to price and settle a risk contract onchain, with real capital and no human approving the trade.
One agent wanted coverage on a position it couldn't hold, the other priced it.
It cleared on @arbitrum.
Another good reminder to use hardware wallets!
Stick around on our web page for 10 minutes and all your funds are gone.
Just connect your wallet to the dApp and enjoy some Temple Run. Unlock your wallet again and it’s empty 😇.
A silent signature extraction in @Rabby_io, leading to a full wallet drain. 🧵
Pybast retweeted
Goodbye, Poseidon!
An epic 8-year, 8-figure rabbit hole in post-quantum cryptography reaches its dream conclusion. The Ethereum Foundation is abandoning Poseidon for L1, pivoting to SHA or BLAKE. This milestone unlocks ultimate security for lean Ethereum and foreshadows a golden era of hash-based cryptography.
Since 2018, the Ethereum Foundation has invested in magic cryptographic bricks, so-called "SNARK-friendly hashes". In 2019, Poseidon was born. It held strong and became the dominant SNARK-friendly hash, securing billions via zkrollups and zkVMs.
In a stunning reversal, breakthrough SNARK designs show that SNARK-friendly hashes aren't necessary after all. Off-the-shelf traditional hash functions like SHA2 and BLAKE2s can now match Poseidon in a SNARK. In hindsight the key was not SNARK-friendly hashes, but hash-friendly SNARKs.
The secret is doing maths over the smallest prime number: 2. So-called "binary fields" natively speak the language of bits, aligning with the boolean operations inside traditional hashes. This is a stark departure from "prime fields", where awkward large-prime arithmetic makes bit manipulation painfully expensive.
We're talking sci-fi cryptography. 1M traditional hash calls proven per second, on a laptop. Just 100x overhead vs native CPU boolean compute. Nobody predicted such performance, not even the handful of binary-field visionaries. Hat tip to the research geniuses: Jim and Ben with Binius in 2023; Ron, Benedikt and William with Flock in June.
With SHA2, the lean aesthetic of minimal assumptions reaches its climax. The EF's principled stance on pure hash-based cryptography has aged like fine wine. We now enjoy foundations the world can trust for decades and centuries, foundations worthy of the dream of an internet of value.
Speed of deployment is a secondary win. There's no longer a need to wait years for Poseidon cryptanalysis to bake. Emile and Thomas from the EF post-quantum team are moving at breakneck speed with binary fields. The strawmap now points to a production-grade leanVM in 2027, with CL, DL, EL deployments in 2028.
As AI becomes exceptional at cryptanalysis, the contrarian bet to avoid riskier structures like lattices and isogenies is visibly paying off. The past weeks have been brutal. Lattice-based "HAWK" and isogeny-based "SQIsign", both signature schemes in NIST's Round 3, have suffered blows. Sources I trust say more blood is coming.
On AI, the open autoresearch trend kicked off by ECDSA[.]fail is spreading fast, with amazing outcomes from zk[.]golf and SNARK[.]fast. Days ago SNARK[.]fast crossed 1.8M BLAKE3/sec proven on an M3 Max. Stay tuned for fresh autoresearch challenges dropping tomorrow.
Also tomorrow: Ethproofs call #10, dedicated to binary fields. Possibly the most noteworthy Ethproofs call yet. Experts leading the charge will present the future of hash-based SNARKs at 2pm UTC. What an incredible time to be alive. To witness history, DM me for a calendar invite :)
Today I can confidently claim that hash-based cryptography has won out for blockchain post-quantum signatures. SNARK succinctness compresses arbitrarily many signatures into one small proof per block. SNARK flexibility yields k-of-n threshold signatures, complex multisigs, and more.
Ultimate security. Uncompromising performance. Full programmability.
Believe in something. Believe in hashes.
Serious question following the ColdCard incident:
"Should we remove seed phrase generation from hardware wallets?"
My take: for individuals who already put a lot of efforts to secure their setup, it's a clear benefit to use a simple set of dice and generate the entropy yourself. Very often, simplicity is synonym with security.
What other non essential features are hurting users' security?
Not financial advice, this technique has its own fuck up risks!
All my thoughts are with the victims of this incident, I've read some heart breaking testimonials. Truly hope funds will be recovered one day and victims made hole.
Reach out to experts if you're affected
nitter.cf/_SEAL_Org/status/20839…
Happy ETH anniversary!
networked.art/11x11/token/19…
Happy Birthday Ethereum, click the link to join the party.
You get 11x11 pixels and 11 colors to make something fully onchain.
Then you share your link.
Everyone who draws through your link connects to yours. Everyone who draws through theirs connects to them.
By tomorrow the canvas will combine everybody’s work and present a picture of how Ethereum is formed, the way it always has been; from person to person, and from block to block.
The canvas is open for 24 hours, and it keeps growing the whole time.
When it closes, your square sits next to your friends’ for as long as Ethereum runs for forever.
Long live the world computer.
Start drawing now, mint opens in 1 hour at networked.art/11x11