Devs – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 13 Sep 2025 20:49:48 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Devs – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Ethereum Devs Are Underpaid by Over 50%: Report https://earlybirdsinvest.com/ethereum-devs-are-underpaid-by-over-50-report/ https://earlybirdsinvest.com/ethereum-devs-are-underpaid-by-over-50-report/#respond Sat, 13 Sep 2025 20:49:48 +0000 https://earlybirdsinvest.com/ethereum-devs-are-underpaid-by-over-50-report/

A new report from Protocol Guild has shown that Ethereum’s core developers are being paid far below industry standards.

The survey collected responses from 111 out of 190 Guild members and found that most are earning 50% to 60% less than their peers in similar roles.

Compensation Gap

Median salaries for surveyed Ethereum developers came in at about $140,000, compared with offers averaging $300,000 at rival projects. The report also detailed pay by area of focus, with average salaries at $130,000 for client developers, $215,000 for researchers, and $130,000 for coordination roles.

Additionally, these contributors said that they don’t get any equity or token exposure from their employers. The general allocation was $0, with only 37% of respondents receiving anything. On the other hand, final-stage offers made to their peers at rival organizations in the past year included a median equity or token share of 6.5%. This ranges from cofounder-level allocations of 10% to 30% to early employee grants of 0.1% to 3%.

The gap has created pressure; almost 40% of respondents have received outside job offers in the past year. In total, 108 were disclosed across 42 individuals, with the average package reaching $359,000. Some developers said they had been offered as much as $700,000 to move elsewhere.

Closing the Pay Disparity

Established in 2022, Protocol Guild has become a lifeline for such developers. Backed by the “1% Pledge” from projects including EigenLayer, Ether.fi, Taiko, and Puffer, the group has distributed over $33 million since launch. VanEck also pledged 10% of profits from its spot Ether ETF to the initiative in 2023.

Over the last 12 months, the average Guild member received $66,000 through this funding, while the median distribution was $74,285. That support represented nearly one-third of total annual compensation for many employees, with the mean pay rising from $140,000 to $207,121.

Survey responses show how important this extra support has been, with 59% of participants rating Guild funding as “very” or “extremely important” to their ability to keep working on Ethereum.

The network has secured nearly $1 trillion in value, serves millions of users, and powers thousands of applications reliant on key upgrades. Protocol Guild warned that inadequate compensation puts Ethereum at risk by undermining developer retention, slowing progress on the roadmap, and threatening long-term neutrality.

The group also emphasized that aligning pay with market rates is important to keep talent in place and ensure the ecosystem’s future growth.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

]]>
https://earlybirdsinvest.com/ethereum-devs-are-underpaid-by-over-50-report/feed/ 0 58290
Samson Mow Slams Bitcoin Core Devs: Contempt for Users Threatens Network Future https://earlybirdsinvest.com/samson-mow-slams-bitcoin-core-devs-contempt-for-users-threatens-network-future/ https://earlybirdsinvest.com/samson-mow-slams-bitcoin-core-devs-contempt-for-users-threatens-network-future/#respond Tue, 09 Sep 2025 20:57:06 +0000 https://earlybirdsinvest.com/samson-mow-slams-bitcoin-core-devs-contempt-for-users-threatens-network-future/

A dispute has emerged within the Bitcoin community, with Jan3 CEO Samson Mow accusing Bitcoin Core developers of treating users with disdain, and warning that such attitudes could jeopardize the network’s long-term success.

Mow stressed that no project can succeed if its builders look down on the people they are meant to serve.

Mow’s Indictment of Developer Conduct

In a lengthy post published on X, the BTC advocate argued that Bitcoin’s core issue is not merely technical but deeply cultural. He asserted that a toxic attitude among some developers is poisoning the ecosystem.

“You cannot develop software for users that you despise,” Mow stated.

He pointed to specific behaviors to illustrate his claim, alleging that developers have been branding user nodes as “fake,” telling them “they don’t matter,” and even engaging in “DDoSing their nodes and laughing about it.”

The Jan3 executive described this behavior as “appalling” and suggested it stems from a problematic mindset:

“Somehow we’ve ended up with node software developers that have both a god complex and a victim mentality at the same time,” he wrote.

According to him, the only solution to the issue is a return to professionalism and humility. He stated that anyone looking to work on Bitcoin should not make it all about themselves or take out their frustrations on other users.

“If you are really such a talented developer, then how come you are completely incapable of convincing people that your changes are good?” Mow asked, alluding to the ongoing debate surrounding the decision to remove the longstanding 80-byte limit on OP_RETURN outputs, which has seemingly divided the community.

His sentiment found support from others, with developer ‘Uncle Rockstar’ pointing out that it was “easy for developers to fall into the trap of thinking that technical proficiency equals intellectual superiority.”

However, not everyone agrees with this characterization. Earlier, BTCAzores co-founder Antoine Poinsot stated that Bitcoin is money and that protocol developers cannot force anyone to use it one way or the other.  Meanwhile, security expert Jameson Lopp offered a more pragmatic view, suggesting programmers may simply be “building for a different set of users” and that the “free market tends to sort these things out.”

The Technical Catalyst

Initially, the 80-byte OP_RETURN cap was implemented as a “gentle signal” to discourage excessive non-financial data from being embedded on the blockchain. However, some developers now say the limit is obsolete because miners have found ways to bypass it, even though they are complex and inefficient.

According to them, removing it will promote cleaner data storage and uphold network neutrality. Some, like Gregory Sanders, have asserted that “this is not endorsing non-financial data usage, but accepting that as a censorship-resistant system, Bitcoin can and will be used for use cases not everyone agrees on.”

Still, their justification has failed to placate critics. One of them, Bitcoin Knots maintainer Luke Dashjr, called the removal “utter insanity,” a sentiment also echoed by Mow and others who fear it will lead to network spam and a departure from the blockchain’s main function as peer-to-peer electronic cash. This change has become the battleground for a much larger war over the soul and future direction of the Bitcoin network.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

]]>
https://earlybirdsinvest.com/samson-mow-slams-bitcoin-core-devs-contempt-for-users-threatens-network-future/feed/ 0 57612
Google to verify all Android devs to block malware on Google Play https://earlybirdsinvest.com/google-to-verify-all-android-devs-to-block-malware-on-google-play/ https://earlybirdsinvest.com/google-to-verify-all-android-devs-to-block-malware-on-google-play/#respond Wed, 27 Aug 2025 03:46:13 +0000 https://earlybirdsinvest.com/google-to-verify-all-android-devs-to-block-malware-on-google-play/

Google to verify all Android devs to block malware on Google Play

Google is introducing a new defense for Android called ‘Developer Verification’ to block malware installations from sideloaded apps sourced from outside the official Google Play app store.

For apps on Google Play, there was already a requirement for publishers to provide a D-U-N-S (Data Universal Numbering System) number, introduced on August 31, 2023.

Google says this has had a notable effect in reducing malware on the platform. However, the system didn’t apply to the vast developer ecosystem outside the app store.

“We’ve seen how malicious actors hide behind anonymity to harm users by impersonating developers and using their brand image to create convincing fake apps,” reads Google’s announcement.

“The scale of this threat is significant: our recent analysis found over 50 times more malware from internet-sideloaded sources than on apps available through Google Play.”

Although the threat is more prevalent outside Google Play, the developer verification requirement applies to both apps on Google Play and apps hosted on third-party app stores.

Starting in 2026, all apps installed on certified Android devices must come from developers who have verified their identity with Google.

Early access to the Developer Verification program will begin this year in October, and the system will open to all Android application developers in March 2026.

In September 2026, the identity verification requirement will become mandatory for Brazil, Indonesia, Singapore, and Thailand, before it rolls out globally in 2027.

The expected effect is to have sideloading, non-compliant apps blocked by the operating system with a security message on certified devices.

Certified Android devices are those that have passed Google’s Compatibility Test Suite (CTS) and are approved to ship with Google Play Services, Play Store, and Play Protect.

In practice, this encompasses all mainstream devices from Samsung, Xiaomi, Motorola, OnePlus, Oppo, Vivo, and the Google Pixel line.

Non-certified devices are those from Huawei, Amazon Fire tablets, and shady Chinese TV boxes or smartphones that use heavily modified OS images and questionable components.

Those devices are not subject to the new rule enforcement, and their users will be able to continue sideloading APKs from unverified and anonymous developers.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/google-to-verify-all-android-devs-to-block-malware-on-google-play/feed/ 0 55307
Google Cloud is adding six new AI agents for devs, scientists, and power users https://earlybirdsinvest.com/google-cloud-is-adding-six-new-ai-agents-for-devs-scientists-and-power-users/ https://earlybirdsinvest.com/google-cloud-is-adding-six-new-ai-agents-for-devs-scientists-and-power-users/#respond Wed, 06 Aug 2025 14:10:33 +0000 https://earlybirdsinvest.com/google-cloud-is-adding-six-new-ai-agents-for-devs-scientists-and-power-users/

What you need to know

  • Google is rolling out AI agents in Cloud that can handle everything from data analysis to code execution.
  • Gemini CLI is gaining GitHub Actions, an agent that automates issue and contribution triage and serves as an AI teammate.
  • The five other agentic solutions are aimed at data scientists and engineers working in Google Cloud business environments.

Google Cloud is bolstering its offerings in the agentic era with six new AI agents tailor-made for developers, data scientists, and data engineers alike. The agents are available in preview starting today, Aug. 5, including a GitHub Actions helper for the Gemini command-line interface (CLI).

The company says the fresh AI tools are the start of an agentic enterprise for its customers, which aims to bridge the operational and analytical needs of a business. Alongside the agentic helpers, Google Cloud is creating Gemini Data Agents APIs and the Agent Development Kit (ADK), which are the foundation for a customizable platform that can be used to create custom AI tools for unique workflows.

These are the new AI agents developers and businesses can try out now in Google Cloud:

  • Data Engineering Agent in BigQuery — a data-prepping agent optimized for cleaning, transforming, and preparing information for AI use.
  • Data Science Agent in BigQuery Notebooks — a workspace agent that turns notebooks into intelligent infrastructure for data science teams.
  • Conversational Analytics Agent + Code Interpreter — a chatbot-style tool that supports conversational question-and-answer dialogue using the context of unique data sets.
  • Migration Agent for Spanner — a data modernization agent designed for Google Cloud’s global database service, Spanner.
  • Conversational Analytics API — a custom agent builder for developers and businesses.
  • Gemini CLI GitHub Actions — a coding teammate for your GitHub repository, found in Gemini CLI.

Everything you need to know about Google’s new AI agents

Google Cloud is for businesses, first-and-foremost, and these AI agents are intended to help with everything from software development and data analytics to managing global distribution and infrastructure networks. For example, the Data Engineering Agent can automate workflows that were once manual processes. It supports data ingestion from external sources, like Google Cloud Storage, and can complete contextual actions on your behalf.

Google provides the example prompt of “Create a pipeline to load a CSV file, cleanse these columns, and join it with another table.” With that, the Data Engineering Agent can complete the multi-action requests independently. The Spanner Migration Agent can work in tandem with the Data Engineering Agent, as it’s intended for legacy systems that are still needing modernization.

The data science agent in Google Cloud.

(Image credit: Google)

The Data Science Agent can automate typical analytical workflows, according to Google. It handles common tasks like exploratory data analysis (EDA), data cleaning, featurization, and machine learning predictions based on provided data sets in either BigQuery or Vertex AI.

Conversational analytics agent in Google Cloud.

(Image credit: Google)

The Conversational Analytics Agent is also getting a boost, as it’s now getting a Code Interpreter function. It receives thorough and specific natural language questions, and automatically converts them into Python code. From there, Code Interpreter can run the generated code, creating visual and interactive graphics based on the results. It’s all running in Google Data Cloud, and thus the company claims it’s secure and governed.

Gemini CLI is getting better for teams with GitHub Actions

Finally, Gemini CLI is getting an upgrade that enhances multi-user support and GitHub integration. For those unfamiliar, Gemini CLI is a command-line terminal for Gemini that’s open-source and can be run locally. It’s available in beta globally now on GitHub.

The story behind Gemini CLI’s new GitHub Actions agent is pretty interesting. Amidst a heavy burden of GitHub feature requests and contributions for the open-source Gemini CLI, Google needed a way to respond quickly at scale. So, it created GitHub Actions — an autonomous agent that can handle issue triage and pull request reviews independently. Now, it’s giving away what it created to manage Gemini CLI issues and contributions as GitHub Actions.

GitHub Actions running in Gemini CLI.

(Image credit: Google)

Aside from issue triage and pulling request reviews, GitHub Actions also serves as a collaborative coding agent that can work as your AI teammate.

All of these Google Cloud features are available in preview or beta starting today, and you can try them now.

]]>
https://earlybirdsinvest.com/google-cloud-is-adding-six-new-ai-agents-for-devs-scientists-and-power-users/feed/ 0 51798
US Fairphone OS devs hit back against GrapheneOS security claims https://earlybirdsinvest.com/us-fairphone-os-devs-hit-back-against-grapheneos-security-claims/ https://earlybirdsinvest.com/us-fairphone-os-devs-hit-back-against-grapheneos-security-claims/#respond Tue, 22 Jul 2025 14:53:26 +0000 https://earlybirdsinvest.com/us-fairphone-os-devs-hit-back-against-grapheneos-security-claims/
Fairphone Gen 6 in hand

Paul Jones / Android Authority

TL;DR

  • The team behind the /e/OS Android fork has addressed some security claims about the platform.
  • This comes after GrapheneOS developers criticized /e/OS for “lagging far behind” in terms of updates.
  • The /e/OS software ships on the Fairphone Gen 6 in the US.

The Fairphone Gen 6 will launch in the US next month using the Google-free /e/OS platform. However, the developers behind the privacy-focused GrapheneOS Android fork made a few concerning claims about this platform. The team behind /e/OS has now published a blog post addressing these claims.

Murena, the company behind /e/OS, published a blog post stating that it took security issues seriously. However, it also criticized the GrapheneOS developers for making what it called “misleading claims.”

The team confirmed that it targeted “standard industry practices” for timely security updates:

Therefore, for a given release on month N, our current work-flow is to integrate Android security patches from month N-1. As a result, in the worst case, it will take up to nine weeks to roll out the latest available security updates. In most cases, it will be much sooner.

The team also explained that it makes an exception for zero-day exploits and tries to deliver these patches “as soon as possible.” It also posted a table showing how major Android smartphone makers compare in terms of update lag. This suggests that /e/OS is in line with some major OEMs as far as typical patches go. You can view this screenshot below.

Murena Android OEM updates

Murena also took umbrage with claims that it lagged on browser updates for WebView issues. The company said it issued two zero-day WebView fixes and the June security patch level with the recently released /e/OS 3.0.4 update. For what it’s worth, these two zero-day exploits were disclosed in early June and late June, respectively.

What’s next for Murena, though? Well, the company confirmed that it will be making some improvements:

Murena is taking security issues seriously, and our policy about integration of security patches in /e/OS is very comparable to or even better in some cases than many of mobile OS vendors in the smartphone industry.

However, as part of our ongoing efforts to continuously improve we have decided to reduce the integration time of monthly security updates in /e/OS. Therefore we’ll progressively update our build infrastructure to allow the roll-out of latest security updates following the days after they have been released.

Murena will continue to deploy urgent /e/OS builds for 0-day security fixes

The company also disputed several other claims by the GrapheneOS team. For one, it said that /e/OS didn’t hide the true patch level but exposes these fields “exactly like stock Android.” The GrapheneOS developers argued that the Fairphone Gen 6 lacks a secure element, which made it “trivial” for bad actors to brute-force a PIN code or basic password. Murena downplayed these assertions, arguing that Qualcomm’s secure processing unit means it could take “years” for attackers to recover a six-digit PIN.

What do you think of /e/OS’s security and privacy?

37 votes

Murena also confirmed that it uses the open-source microG framework to hook into a few Google services (e.g. push notifications) but adds that users can swap Google’s notification service out for the UnifiedPush platform. It’s worth noting that microG is a long-established, popular alternative to Google Play Services that allows people to use Google apps and services. This framework is particularly useful on devices for custom ROMs and HUAWEI phones, which typically lack Google services. So this is a sensible inclusion if you want to let people use some Google apps on an otherwise deGoogled platform.

There’s evidently some room for Murena and Fairphone to improve their security practices. However, not every Android fork has the same security and privacy priorities. Thankfully, the beauty of the Android ecosystem means you can switch to a different Android skin, Android fork, or custom ROM if you have specific needs. In any event, you can read the full blog post for a more comprehensive response by the /e/OS team.

Got a tip? Talk to us! Email our staff at news@androidauthority.com. You can stay anonymous or get credit for the info, it’s your choice.
]]>
https://earlybirdsinvest.com/us-fairphone-os-devs-hit-back-against-grapheneos-security-claims/feed/ 0 49047
Spam Wars: Bitcoin Core Devs At Center Of Heated Debate https://earlybirdsinvest.com/spam-wars-bitcoin-core-devs-at-center-of-heated-debate/ https://earlybirdsinvest.com/spam-wars-bitcoin-core-devs-at-center-of-heated-debate/#respond Mon, 09 Jun 2025 00:08:09 +0000 https://earlybirdsinvest.com/spam-wars-bitcoin-core-devs-at-center-of-heated-debate/

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

According to a joint statement released on June 6, 2025, 31 Bitcoin Core developers have taken a clear stance on how the network should handle non-monetary uses. They stressed that their role is not to support or block data inscriptions and other non-financial activities.

The move has stirred strong feelings across the community, with debates touching on freedom, fees, and the very purpose of Bitcoin.

Developer Stance On Data Policies

Based on reports, the Core team said they won’t step in to stop “harmless” data from entering the blockchain. They pointed out that Bitcoin’s main strength is its resistance to censorship. So, any user-driven software choices must stand.

They made it plain: it’s up to node operators to pick what they accept. This approach aims to keep the network free, even if that means it carries extra data.

Community Voices Split

Following the statement, reactions poured in. Samson Mow, CEO of JAN3, called the developers’ tone hollow and said recent changes have “opened the floodgates” for spam. He argued that removing technical barriers encourages unwanted data.

On the flip side, Jameson Lopp of Casa praised the clear explanation of relay rules. Lopp pointed out that a unified voice from developers helps to cut down on past confusion over policy.

Recent Upgrade Sparks Worries

On May 8, 2025, Core developers removed a long-standing limit on transaction data size. That tweak lets anyone include bigger chunks of information in transactions. Critics worry this will drive up blockchain bloat and push fees higher.

BTC is now trading at $106,052. Chart: TradingView

Supporters say predicting what miners will include—and passing that info along—is key to keeping Bitcoin running smoothly. They claim this neutral relay policy helps miners and users alike, even if not everyone buys into it.

Future Forks And Layer Solutions

Looking ahead, some think a new fork could split off a “pure money” chain that blocks data inscriptions. Others foresee layer-2 networks or sidechains taking on the heavy lifting for art, messaging, and other uses.

Either way, most agree that wallets and node software will soon offer options: one for clean, finance-only transactions, and another for those who don’t mind extra data. This choice will let users vote with their settings instead of relying on developers to make the call.

Featured image from Unsplash, chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

]]>
https://earlybirdsinvest.com/spam-wars-bitcoin-core-devs-at-center-of-heated-debate/feed/ 0 40923
Bitcoin community is divided over Core devs’ statement on transaction relay https://earlybirdsinvest.com/bitcoin-community-is-divided-over-core-devs-statement-on-transaction-relay/ https://earlybirdsinvest.com/bitcoin-community-is-divided-over-core-devs-statement-on-transaction-relay/#respond Sun, 08 Jun 2025 23:57:40 +0000 https://earlybirdsinvest.com/bitcoin-community-is-divided-over-core-devs-statement-on-transaction-relay/

A debate has erupted among the Bitcoin community over a joint statement released by 31 Bitcoin Core developers on June 6.

In their statement, the developers argued that while the new transaction relay policy might lead to more non-financial use cases, protecting censorship resistance is one of the core tenets of the blockchain.

The developers noted that the Bitcoin network is “defined by its users, who have ultimate freedom” to choose whether they utilize the blockchain for financial or non-financial use cases. As such, the Bitcoin core developers are “not in a position to mandate” what software or policies they choose.

Several Bitcoiners have opposed the developers’ opinion, calling it a drift away from the blockchain’s original intended function. On the other hand, some have defended the developers’ viewpoint, leading to a global debate among Bitcoiners.

The Bitcoin transaction relay policy is at the core of the debate

Transaction relay is a ‘core tenet’ of a Bitcoin node. Nodes relay block transactions and validations to other nodes to ensure that the blockchain remains updated across all nodes.

On May 5, core contributors to the Bitcoin network announced that the next upgrade will remove the 80-byte data cap for transaction relays. This would allow users to embed larger data segments more efficiently, the post noted, adding:

“The long-standing cap, originally a gentle signal that block space should be used sparingly for non-payment proof of publication data, has outlived its utility.”

The developers argued that users have found ways to circumvent the data limit, which can potentially harm the network. Therefore, “retiring a deterrent that no longer deters” large-data inscriptions will enable the fee market to “arbitrate competing demands.”

The announcement sparked a debate with some considering the move to be logical, while others considered it an open invitation to spam transactions.

Bitcoin core developers defend stance to remove data limit for transaction relays

In their Friday statement, the Bitcoin core developers defended their decision to remove the data cap for transaction relays. They noted that it is their responsibility to ensure that their software is efficient and reliable, contributing to Bitcoin’s success as a decentralized digital currency. They stated:

“With regards to transaction relay, this may include adding policies for denial of service (DoS) protection and fee assessment, but not blocking relay of transactions that have sustained economic demand and reliably make it into blocks.”

According to the developers, transaction relay has three major goals. This includes predicting which transactions will be mined, which also serves to prevent denial-of-service (DoS) attacks. In DoS attacks, miscreants flood the network with spam transactions, overwhelming the network and preventing it from processing transaction requests from legitimate users.

Additionally, transaction relay also speeds up transaction propagation, which in turn prevents large miners from gaining an unfair advantage. It also helps miners learn about fee-paying transactions, the developers noted. Therefore, they wrote:

“Knowingly refusing to relay transactions that miners would include in blocks anyway forces users into alternate communication channels, undermining the above goals.”

Besides, the Bitcoin node software should not intervene through a data cap where both transaction creators and miners consent to add a large data inscription to a block, the developers noted. This is because Bitcoin was built on the ethos of censorship resistance, they explained, adding that large data transactions are “largely harmless at a technical level.”

The developers clarified, however:

“This is not endorsing or condoning non-financial data usage, but accepting that as a censorship-resistant system, Bitcoin can and will be used for use cases not everyone agrees on.”

They added that while they are aware of the dissent among Bitcoiners, they sincerely believe the move “is in the best interest of Bitcoin and its users.”

Bitcoiners split over transaction relay policy change

Among those who are opposed to the transaction relay policy change is Bitcoin core developer and OCEAN Bitcoin mining pool creator Luke Dashjr, also known as Luke Kenneth Casson Leighton. In an X post, Dashjr noted:

“The goals of transaction relay listed are basically all wrong. Predicting what will be mined is a centralizing goal. Expecting spam to be mined is defeatism. Helping spam propagate is harmful.”

He added that the statement portrays the abuse of the blockchain through spam transactions as legitimate use cases instead of treating them as DoS attacks. However, he believes such transactions are the same as DoS attacks.

Pseudonymous X user SatsScholar, who runs Bitcoin Knots, a specialized version of Bitcoin Core that is maintained by Dashjr, called the new relay policy an ideological drift, noting:

“Core’s new stance essentially says, “if someone pays enough, any use is valid.” That’s economically naive and ignores Bitcoin’s fundamental purpose as a monetary network.”

Several Bitcoiners echoed SatsScholar’s views, including Dennis Porter, CEO of Bitcoin mining advocacy firm Satoshi Action Fund, who said the policy change is “absolutely condoning bloat.” In a more scathing post, one user wrote:

“It’s Bit”Coin” not Bit”Bucket” or Bit”Store” or whatever general purpose data store you have in mind. It’s a “peer to peer electronic cash system”.”

The user added that keeping the network focused on its original purpose is not censorship.

Dissenters of the proposal also include miners, one of whom claimed that the removal of the data cap “risks diluting Bitcoin’s monetary focus, overburdening future nodes, further centralizing power, possibly threatening scalability, and fracturing the Bitcoin community’s faith.”

Jameson Lopp, co-founder and chief security officer of Bitcoin wallet Casa, was among those who supported the developers’ statement, noting:

“Core Devs are a group saying we can’t force anyone to run code they don’t like, here is our thinking on relay policy & network health.”

Mentioned in this article
]]>
https://earlybirdsinvest.com/bitcoin-community-is-divided-over-core-devs-statement-on-transaction-relay/feed/ 0 40917
Malicious PyPi package hides RAT malware, targets Discord devs since 2022 https://earlybirdsinvest.com/malicious-pypi-package-hides-rat-malware-targets-discord-devs-since-2022/ https://earlybirdsinvest.com/malicious-pypi-package-hides-rat-malware-targets-discord-devs-since-2022/#respond Thu, 08 May 2025 19:25:05 +0000 https://earlybirdsinvest.com/malicious-pypi-package-hides-rat-malware-targets-discord-devs-since-2022/

Discord

A malicious Python package targeting Discord developers with remote access trojan (RAT) malware was spotted on the Python Package Index (PyPI) after more than three years.

Named “discordpydebug,” the package was masquerading as an error logger utility for developers working on Discord bots and was downloaded over 11,000 times since it was uploaded on March 21, 2022, even though it has no description or documentation.

Cybersecurity company Socket, which first spotted it, says the malware could be used to backdoor Discord developers’ systems and provide attackers with data theft and remote code execution capabilities.

“The package targeted developers who build or maintain Discord bots, typically indie developers, automation engineers, or small teams who might install such tools without extensive scrutiny,” Socket researchers said.

“Since PyPI doesn’t enforce deep security audits of uploaded packages, attackers often take advantage of this by using misleading descriptions, legitimate-sounding names, or even copying code from popular projects to appear trustworthy.”

Once installed, the malicious package transforms the device into a remote-controlled system that will execute instructions sent from an attacker-controlled command-and-control (C2) server.

The attackers could use the malware to gain unauthorized access to credentials and more (e.g., tokens, keys, and config files), steal data and monitor system activity without being detected, remotely execute code for deploying further malware payloads, and obtain information that can help them move laterally within the network.

discordpydebug on PyPI
discordpydebug on PyPI (BleepingComputer)

​While the malware lacks persistence or privilege escalation mechanisms, it uses outbound HTTP polling instead of inbound connections, making it possible to bypass firewalls and security software, especially in loosely controlled development environments.

Once installed, the package silently connects to an attacker-controlled command-and-control (C2) server (backstabprotection.jamesx123.repl[.]co), sending a POST request with a “name” value to add the infected host to the attackers’ infrastructure.

The malware also includes functions to read from and write to files on the host machine using JSON operations when triggered by specific keywords from the C2 server, giving the threat actors visibility into sensitive data.

To mitigate the risk of installing backdoored malware from online code repositories, software developers should ensure that the packages they download and install come from the official author before installation, especially for popular ones, to avoid typosquatting.

Additionally, when using open-source libraries, they should review the code for suspicious or obfuscated functions and consider using security tools to detect and block malicious packages.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/malicious-pypi-package-hides-rat-malware-targets-discord-devs-since-2022/feed/ 0 35122
North Korean's Lazarus Group Targets Devs with Bogus Crypto Companies https://earlybirdsinvest.com/north-koreans-lazarus-group-targets-devs-with-bogus-crypto-companies/ https://earlybirdsinvest.com/north-koreans-lazarus-group-targets-devs-with-bogus-crypto-companies/#respond Sat, 26 Apr 2025 15:15:37 +0000 https://earlybirdsinvest.com/north-koreans-lazarus-group-targets-devs-with-bogus-crypto-companies/

North Korean hackers have set up fake crypto consulting firms to trick developers into downloading malware, according to a report published on April 24 by Silent Push Threat Analysts.

The group behind the scheme, called Contagious Interview, is part of the Lazarus network. They created three front companies—BlockNovas, Angeloper Agency, and SoftGlide—with two officially registered in the United States.

The hackers use these fake companies to post job listings on platforms like GitHub, freelancer websites, and recruitment boards.

What is Blockchain? (Animated Examples + Explanation)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Interested applicants are asked to record a video introduction as part of the interview process. When they try to do so, they receive an error message along with instructions to quickly fix it. If they follow the instructions, they unknowingly download malware onto their devices.

Silent Push identified three types of malware being used: BeaverTail, InvisibleFerret, and OtterCookie. BeaverTail is mainly used to steal system information and open a path for more malware. InvisibleFerret and OtterCookie focus on stealing sensitive data such as crypto wallet keys and clipboard contents.

The fake companies also use convincing websites and employee profiles to seem real. Some of these profiles are made with artificial intelligence (AI) generated images, while others are altered versions of real people’s photos.

Zach Edwards, a senior analyst at Silent Push, explained that the hackers would slightly modify real images to make them harder to trace.

On April 11, Jake Gallen, CEO of Emblem Vault, warned the crypto community about a scam that cost him over $100,000 in digital assets. How does the scam work? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/north-koreans-lazarus-group-targets-devs-with-bogus-crypto-companies/feed/ 0 32941
Vitalik Buterin Urges Ethereum Devs to Build With Values in Mind https://earlybirdsinvest.com/vitalik-buterin-urges-ethereum-devs-to-build-with-values-in-mind/ https://earlybirdsinvest.com/vitalik-buterin-urges-ethereum-devs-to-build-with-values-in-mind/#respond Mon, 14 Apr 2025 12:18:31 +0000 https://earlybirdsinvest.com/vitalik-buterin-urges-ethereum-devs-to-build-with-values-in-mind/

Vitalik Buterin stated that developers building apps on Ethereum
ETH


$1,665.78

should think more about the values behind their work.

He believes that the application layer—not the core infrastructure—is where thoughtful ideas and social responsibility matter most.

His comments came in a post on Warpcast on April 12. He responded to a user who said Ethereum needs a new wave of builders who understand and care about the project’s original values. Buterin agreed in part, but added that it was the app layer where those values are most needed.

What is an Automated Market Maker in Crypto? (Animated)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Buterin compared Ethereum to a programming language. A tool like C++, he said, works pretty much the same no matter who created it or what they believed.

However, Ethereum still reflects the choices made by its creators even though the base layer is partly neutral. Buterin pointed to Ethereum’s shift to proof-of-stake and support for light clients as examples. These changes were driven by certain beliefs, like wanting to save energy and support decentralization.

Still, the biggest influence of values shows up in apps. Buterin gave a few examples of projects he thinks are built with the right mindset, such as privacy app Railgun, Web3 platform Farcaster, prediction market Polymarket, and messaging tool Signal.

Recently, a clip of Buterin meowing at a robot has stirred mixed reactions among the crypto community on X. What did they say? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/vitalik-buterin-urges-ethereum-devs-to-build-with-values-in-mind/feed/ 0 30721