Deep dives into SSR, performance, game engines, and distributed systems from 11 years of engineering experience.
The email was sent via Amazon SES carrying a genuinely valid hpe.com DKIM signature and passed SPF/DKIM/DMARC, so Gmail could not block it. Includes timeline, technical analysis, IOCs, response and law-enforcement paths, with bilingual PDF reports and email evidence screenshots.
Starting from the perceive–decide–act–observe loop, this breaks down the essence of an agent: state, tools, and stopping conditions.
A collection of CVEs that are directly related or belong to the same attack family (invalid curve / twist attacks), useful for cross-referencing and triage.
A deep dive into how JavaScript ECC libraries missing public-key curve validation leak private-key remainders through small-order subgroups, then reconstruct the full key via the Chinese Remainder Theorem (CRT).
Discusses the vulnerability mechanism, impact scope and upgrade guidance for private-key extraction in the secp256k1 package under ECDH scenarios.
An integrated on-chain trading system covering contract interaction, Saga distributed transactions, quantitative risk control (VaR/ES) and MPC/HSM security architecture.