MASTR CRYPTO WIKI
Thèmes
Choisissez un thème, puis consultez ses articles et les termes associés.
Les enquêtes et les fiches de référence sont publiées en anglais. La navigation est disponible en sept langues.
Recherche MASTR
- LAPTOP: pre-launch inventory and $2.34 million in sale receipts
- LAPTOP: 2 connected claims, 647,428.93 USDC in receipts
- LAPTOP: the completed 49-sale record
- LAPTOP, TRUMP and MELANIA: which connections were established?
- From decentralisation to attention capture
- ANSEM: volume, valuation and the pools underneath
- BlockLayerPod and BeaconLayerPod: the interview invitation
- When a prediction-market win is staged
- SecondFi: wallet reputation and incident communication
- BONK DAO: the governance question in MASTR's July essay
- MASTR's Crypto Survival Guide
- TRUMP: the wallets used again after the rally
- TRUMP: 30 pools, two dominant markets
- FOMO / MEME: launch timing and investor conflicts
- The MiCA migration scam
- Copy trading: the leader's profit is not your result
- MASTR on X: incentives, influence and exchange flows
Binance, CZ et Trump
KOLs et promotion
- Kim Kardashian and EthereumMax
- Floyd Mayweather, DJ Khaled and ICO promotion
- TRX and BTT: the 2023 celebrity-promotion cases
- KOL investors: same token, different deal
- Paid promotion: what the audience needs to know
- Referral income: a promoter can profit when you overtrade
- Manufactured social proof
- PnL screenshots: the missing denominator
- Similar balances do not prove coordinated entry
- Survivorship bias in calls, rankings and research
- Paid promotion: preserve the incentive trail
- KOL investment rounds
- Discounted OTC tokens promoted at market price
- Referral conflicts
- Affiliate-link concealment
- Cherry-picked leaderboards
- PnL screenshots without cash reconciliation
- Copy-trading execution gaps
- Survivorship in call channels
Types d’arnaques
- Fake support: urgency with borrowed branding
- Recovery scams: the second loss
- Relationship-based investment fraud
- Fake airdrops and claim pages
- Address poisoning and clipboard mistakes
- Rug pulls: identify which control caused the loss
- Fake listings and borrowed exchange credibility
- Seed-phrase harvesting
- Wallet-app impersonation
- Fake browser extensions
- Search-ad poisoning
- Discord account takeovers
- Telegram admin impersonation
- X reply-bot traps
- Fake airdrop claims
- Malicious token approvals
- Permit phishing
- Blind-signature phishing
- Simulation spoofing
- Clipboard-address substitution
- Address-poisoning transfers
- QR-code substitution
- SIM-swap attacks
- Number-porting fraud
- MFA fatigue attacks
- Session-cookie theft
- OAuth-consent phishing
- Fake support screen sharing
- Remote-access tool abuse
- Cloud-backup seed exposure
- Hardware-wallet tampering
- Fake firmware updates
- Recovery-phrase verification scams
- Wallet drainer services
- Relationship investment fraud
- Crypto pig-butchering operations
- Task and optimisation scams
- Liquidity-mining impostors
- Cloud-mining fraud
- Fixed-return staking fraud
- Arbitrage-bot scams
- Front-running bot scams
- Fake MEV-bot contracts
- Trading-bot key theft
- Exchange API-key theft
- Fake exchange deposit pages
- Withdrawal-fee escalation
- Advance-fee recovery scams
- Fake law-firm recovery
- Token-migration scams
- Fake bridge interfaces
- Counterfeit DEX frontends
- Fake NFT mints
- Counterfeit NFT listings
- Fake token presales
- Clone tokens and ticker theft
- Counterfeit stablecoins
- Fake proof-of-reserves claims
- Audit-badge laundering
- Fake partnership announcements
- Fake exchange-listing announcements
- Deepfake executive livestreams
- Impersonated crypto giveaways
- Malicious calendar invitations
- Poisoned software dependencies
- Compromised package maintainers
- DNS hijacking
- Homoglyph domains
- Compromised analytics scripts
- Wallet-connect session abuse
- Dust-token message scams
- Memo and destination-tag scams
- OTC escrow impersonation
- Peer-to-peer payment reversals
- Money-mule recruitment
- Crypto-ATM impersonation scams
- Fake crypto recruitment tests
Portefeuilles et sécurité
- Custody: what you control and what you depend on
- Token approvals outlive a trade
- Signed permits: a message can authorise spending
- A valid signature can approve the wrong action
- After a suspected scam or compromise
- What an audit or scanner actually covers
- Upgrade authority and the limits of renounced ownership
- A running chain can have an inaccessible app
- Token-2022: read every authority, not just the ticker
- Permanent delegates: a control the holder cannot revoke
- Transfer hooks: the extra programme inside a transfer
- Typed data: readable fields still need interpretation
- EIP-7702: delegation deserves its own review
- Multisig modules: the threshold is only part of the story
- A trusted frontend can still ask for the wrong transaction
- Transaction simulation: useful evidence with a state boundary
- Upgradeable proxies: the address can stay while the rules change
- Multisig security depends on independent control
- ERC-4337: programmable accounts without assuming one private key is enough
- Proxy-upgrade rugs
- Mint-authority dilution
- Freeze-authority coercion
- Transfer-tax honeypots
- Private whitelist sales
- Selective blacklists
- Anti-bot exemptions for insiders
- Multisignature thresholds
- Smart-account validation
- Proxy implementation changes
- Delegatecall authority
- Reentrancy
- Role-based access control
- ERC-20 allowances
- Token-2022 extensions
- ERC-1271: a contract decides whether a signature is valid
- EIP-712 domains: what stops a signature travelling to another application?
- ERC-2612: a permit deadline is not an allowance expiry
- ERC-1967: finding the implementation behind a proxy address
- ERC-1155: one operator approval can cover many token IDs
- Permit2: token approval and downstream signatures are separate permissions
- PSBT: moving an unsigned Bitcoin transaction between devices
- BIP-39 passphrases: the wrong phrase can open a different wallet
- Closing a Solana token account: check where its SOL goes
Structure de marché
- Wash trading and the appearance of demand
- Market makers: inventory, fees and conflicts
- Market cap is not money available to withdraw
- Concentrated liquidity: TVL can sit outside the trading range
- Slippage, price impact and the price you actually receive
- A ticker is not an asset identifier
- MEV: measure the execution, not just the chart
- PnL screenshots: reconcile the money before admiring the return
- Token unlocks: measure the newly transferable supply
- Constant-product pools: where price impact comes from
- Divergence loss: what a liquidity position gives up relative to holding
- Last price, index price and mark price answer different questions
- Perpetual funding: a transfer between position holders
- Insurance funds and ADL: who absorbs a derivatives shortfall?
- Undisclosed insider allocations
- SAFT discounts and public-market asymmetry
- Vesting side letters
- Launch sniping and privileged block access
- Bundled launch wallets
- Creator-wallet mapping
- Liquidity withdrawal as an exit
- LP-lock marketing
- Market-maker token loans
- Wash trading
- Spoofing and layering
- Self-trade volume
- Rebate-driven fake activity
- Token-unlock framing
- Circulating-supply manipulation
- FDV as a valuation weapon
- TVL without executable depth
- Oracle override power
- Liquidation priority and privileged keepers
- Exchange mark-price discretion
- Opaque insurance funds
- Auto-deleveraging externalities
- Customer-asset rehypothecation
- Related-party lending
- Oracle staleness
- Time-weighted average prices
- Constant-product pool arithmetic
- Stablecoin reserve models
- Maximal extractable value
- Sandwich attacks
- Perpetual futures
- Funding payments
DeFi et gouvernance
- Stablecoins: the peg and the claim behind it
- Yield: identify who pays it
- Leverage and liquidation
- Bridges and wrapped assets
- Oracles: which price controls the contract?
- DAO governance: transparent votes can still concentrate power
- Contagion: one asset, several dependent products
- Governance proposals: read the transaction that will execute
- Bridged assets: the same symbol does not mean the same claim
- Oracle freshness: a valid number can still be unusable
- Liquidation: the threshold, the execution and the remaining debt
- Lock-and-mint bridges: the token depends on both sides
- Liquid staking: a tradable receipt for a less immediate underlying position
- Flash loans
- Overcollateralised debt positions
- Liquid staking receipts
- Restaking and correlated risk
- Bridge trust models
- Collateral liquidation
- ERC-4626: a vault share is not an immediately withdrawable balance
Méthodes de recherche
- Wallet attribution: an address is not a person
- How to write a finding people can check
- Checking a crypto-provider authorisation
- Evidence snapshots: make a finding reproducible
- Wallet clusters: confidence is not ownership
- Audit scope drift: the badge can outlive the reviewed code
- Incident updates: distinguish containment from repair
- From lead to finding: a claim ladder for crypto research
- Reserve assets and liabilities: the missing half of a solvency claim
- ERC-165: interface support is a claim, not a security certificate
Histoire crypto
- 2008–2009: Bitcoin and the problem of double spending
- Mt. Gox: the long tail of a custody failure
- The DAO: code, governance and the 2016 split
- The ICO era: selling access to a future product
- OneCoin: a cryptocurrency story without the promised system
- BitConnect: promised returns and the supposed trading bot
- Terra and UST: the peg, the collapse and the fraud cases
- FTX and Alameda: customer money, privileged accounts and the bankruptcy
- Ronin: bridge theft and attribution
- 2015: Ethereum makes shared computation a public service
- 2017: SegWit changes Bitcoin transaction accounting
- 2018: Lightning reaches a mainnet beta
- 2018: Uniswap makes pooled liquidity a trading venue
- 2020: liquidity mining turns usage into a token reward
- 2021: the NFT boom connects provenance, art and speculation
- 2021: EIP-1559 changes Ethereum fees and introduces base-fee burning
- 2022: Ethereum replaces mining with proof of stake
- 2023: Shapella enables staking withdrawals
- 2024: Dencun gives rollups a separate data market
- 2024: US spot Bitcoin ETPs change the access route
- 2023: USDC's peg encounters a banking failure
- 2025: the Bybit theft and the limits of a transaction signature
- 2016–2024: the Bitfinex theft, laundering and later sentencing
- 2022–2025: Celsius, promised yield and CEL price support
- 2022: BlockFi and the regulation of crypto interest accounts
- 2021–2023: Gemini Earn connects a retail interface to Genesis credit risk
- 2021: Tether's reserve representations face an enforcement finding
- 2021: Taproot changes Bitcoin's spending paths
- Coincheck NEM theft
- QuadrigaCX and the missing custody record
- Cryptopia exchange liquidation
- PlusToken investment scheme
- AirBit Club
- IcomTech
- Forsage smart-contract pyramid
- SafeMoon liquidity-pool diversion
- HyperFund and HyperVerse
- Mining Capital Coin
- Three Arrows Capital collapse
- Voyager Digital collapse
- FTX privileged Alameda account
- FTX bankruptcy-claim valuation
- Celsius CEL market support
- Genesis and Gemini Earn structure
- BlockFi interest accounts
- Wormhole message-verification failure
- Nomad trusted-root failure
- Harmony Horizon bridge
- Poly Network cross-chain exploit
- Euler donation-to-reserves exploit
- Mango Markets oracle manipulation
- Beanstalk governance takeover
- Cream Finance lending exploits
- BadgerDAO frontend compromise
- Curve Vyper reentrancy incident
- Multichain bridge collapse
- KyberSwap concentrated-liquidity exploit
- BitMEX Bank Secrecy Act case
- Binance 2023 criminal resolution
- Bybit February 2025 theft
- Ronin validator compromise
- The DAO exploit and Ethereum fork
- EthereumMax paid promotion
- Mayweather and Khaled ICO promotions
- TRX and BTT celebrity promotion cases
- OneCoin without a public blockchain
- BitConnect lending programme
- Tornado Cash sanctions and software questions
- DMM Bitcoin, 2024: a recruitment lure reached a custody workflow
- OneCoin, 2026: asset recovery is not the same as repaying every victim
Réseaux et chaînes
- Bitcoin: settlement, mining and custody
- Ethereum: applications share a settlement system
- Solana: wallets, token accounts and authority
- BNB Chain and Binance are different subjects
- TRON: resources, tokens and issuer control
- XRP Ledger: validators, XRP and issued assets
- Arbitrum: rollups and AnyTrust have different assumptions
- Optimism: fault proofs and withdrawal assumptions
- Base: familiar addresses, separate balances
- Polygon PoS: checkpoints are not the whole security model
- Avalanche: C-Chain, other chains and bridge exposure
- Cosmos: a framework is not one shared security guarantee
- Sui: objects and ownership
- Cardano: extended UTXO and application risk
- Layer 2: five separate questions
- Solana PDAs: an address can be controlled without a private key
- Solana CPI: follow permissions into the called program
Comprendre le Web
- HTTP: what your browser asks a server to do
- DNS: the name is part of the security boundary
- TLS: encrypted traffic can still reach a scam website
- Cookies: how a website remembers a session
- Same-origin policy: the browser's boundary between sites
- Content Security Policy: limit what a page may execute
- Session theft: account access without another password prompt
- Password storage: why hashing and encryption serve different jobs
Comprendre les blockchains
- A transaction's path from signature to confirmation
- Blocks: ordered transactions and a commitment to state
- Proof of stake: agreement has rules, participants and penalties
- Nodes, clients and RPC providers
- Gas: resource usage and transaction price
- Merkle proofs: verify inclusion against a known commitment
- Bitcoin UTXOs: the outputs behind a wallet balance
- Bitcoin halvings: a programmed subsidy reduction
- Transaction malleability: when an identifier changes
- Contract storage: the persistent state a transaction changes
- Optimistic rollups: claims, challenges and the exit route
- Validity rollups: proving a state transition
- Data availability: can the state be independently reconstructed?
- Chain reorganisations: why recent inclusion can change
- NFT metadata: where the image and its description actually live
- Private keys and control
- Mnemonic recovery phrases
- Hierarchical deterministic derivation
- Transaction nonces
- Public mempools
- Confirmations and reorganisations
- Economic and protocol finality
- Proof-of-work mining
- Proof-of-stake validators
- Slashing conditions
- UTXO selection
- EVM account state
- Solana account ownership
- Gas limits and execution cost
- EIP-1559 base fees
- Blob data for rollups
- Calldata
- Contract storage layout
- Events and transaction logs
- Integer precision and rounding
- Light-client verification
- Optimistic rollups
- Validity-proof rollups
- Data availability
- Sequencer control
- NFT metadata persistence
- Token-standard boundaries
- Cross-chain message execution
- Replace-by-fee: an unconfirmed payment is not final settlement