MASTR CRYPTO WIKI
Temas
Escolha um tema e consulte os artigos e termos relacionados.
Os artigos de investigação e as referências são publicados em inglês. A navegação está disponível em sete idiomas.
Investigação MASTR
- LAPTOP: pre-launch inventory and $2.34 million in sale receipts
- LAPTOP: 2 connected claims, 647,428.93 USDC in receipts
- LAPTOP: the completed 49-sale record
- LAPTOP, TRUMP and MELANIA: which connections were established?
- From decentralisation to attention capture
- ANSEM: volume, valuation and the pools underneath
- BlockLayerPod and BeaconLayerPod: the interview invitation
- When a prediction-market win is staged
- SecondFi: wallet reputation and incident communication
- BONK DAO: the governance question in MASTR's July essay
- MASTR's Crypto Survival Guide
- TRUMP: the wallets used again after the rally
- TRUMP: 30 pools, two dominant markets
- FOMO / MEME: launch timing and investor conflicts
- The MiCA migration scam
- Copy trading: the leader's profit is not your result
- MASTR on X: incentives, influence and exchange flows
Binance, CZ e Trump
KOLs e promoção
- Kim Kardashian and EthereumMax
- Floyd Mayweather, DJ Khaled and ICO promotion
- TRX and BTT: the 2023 celebrity-promotion cases
- KOL investors: same token, different deal
- Paid promotion: what the audience needs to know
- Referral income: a promoter can profit when you overtrade
- Manufactured social proof
- PnL screenshots: the missing denominator
- Similar balances do not prove coordinated entry
- Survivorship bias in calls, rankings and research
- Paid promotion: preserve the incentive trail
- KOL investment rounds
- Discounted OTC tokens promoted at market price
- Referral conflicts
- Affiliate-link concealment
- Cherry-picked leaderboards
- PnL screenshots without cash reconciliation
- Copy-trading execution gaps
- Survivorship in call channels
Tipos de fraude
- Fake support: urgency with borrowed branding
- Recovery scams: the second loss
- Relationship-based investment fraud
- Fake airdrops and claim pages
- Address poisoning and clipboard mistakes
- Rug pulls: identify which control caused the loss
- Fake listings and borrowed exchange credibility
- Seed-phrase harvesting
- Wallet-app impersonation
- Fake browser extensions
- Search-ad poisoning
- Discord account takeovers
- Telegram admin impersonation
- X reply-bot traps
- Fake airdrop claims
- Malicious token approvals
- Permit phishing
- Blind-signature phishing
- Simulation spoofing
- Clipboard-address substitution
- Address-poisoning transfers
- QR-code substitution
- SIM-swap attacks
- Number-porting fraud
- MFA fatigue attacks
- Session-cookie theft
- OAuth-consent phishing
- Fake support screen sharing
- Remote-access tool abuse
- Cloud-backup seed exposure
- Hardware-wallet tampering
- Fake firmware updates
- Recovery-phrase verification scams
- Wallet drainer services
- Relationship investment fraud
- Crypto pig-butchering operations
- Task and optimisation scams
- Liquidity-mining impostors
- Cloud-mining fraud
- Fixed-return staking fraud
- Arbitrage-bot scams
- Front-running bot scams
- Fake MEV-bot contracts
- Trading-bot key theft
- Exchange API-key theft
- Fake exchange deposit pages
- Withdrawal-fee escalation
- Advance-fee recovery scams
- Fake law-firm recovery
- Token-migration scams
- Fake bridge interfaces
- Counterfeit DEX frontends
- Fake NFT mints
- Counterfeit NFT listings
- Fake token presales
- Clone tokens and ticker theft
- Counterfeit stablecoins
- Fake proof-of-reserves claims
- Audit-badge laundering
- Fake partnership announcements
- Fake exchange-listing announcements
- Deepfake executive livestreams
- Impersonated crypto giveaways
- Malicious calendar invitations
- Poisoned software dependencies
- Compromised package maintainers
- DNS hijacking
- Homoglyph domains
- Compromised analytics scripts
- Wallet-connect session abuse
- Dust-token message scams
- Memo and destination-tag scams
- OTC escrow impersonation
- Peer-to-peer payment reversals
- Money-mule recruitment
- Crypto-ATM impersonation scams
- Fake crypto recruitment tests
Carteiras e segurança
- Custody: what you control and what you depend on
- Token approvals outlive a trade
- Signed permits: a message can authorise spending
- A valid signature can approve the wrong action
- After a suspected scam or compromise
- What an audit or scanner actually covers
- Upgrade authority and the limits of renounced ownership
- A running chain can have an inaccessible app
- Token-2022: read every authority, not just the ticker
- Permanent delegates: a control the holder cannot revoke
- Transfer hooks: the extra programme inside a transfer
- Typed data: readable fields still need interpretation
- EIP-7702: delegation deserves its own review
- Multisig modules: the threshold is only part of the story
- A trusted frontend can still ask for the wrong transaction
- Transaction simulation: useful evidence with a state boundary
- Upgradeable proxies: the address can stay while the rules change
- Multisig security depends on independent control
- ERC-4337: programmable accounts without assuming one private key is enough
- Proxy-upgrade rugs
- Mint-authority dilution
- Freeze-authority coercion
- Transfer-tax honeypots
- Private whitelist sales
- Selective blacklists
- Anti-bot exemptions for insiders
- Multisignature thresholds
- Smart-account validation
- Proxy implementation changes
- Delegatecall authority
- Reentrancy
- Role-based access control
- ERC-20 allowances
- Token-2022 extensions
- ERC-1271: a contract decides whether a signature is valid
- EIP-712 domains: what stops a signature travelling to another application?
- ERC-2612: a permit deadline is not an allowance expiry
- ERC-1967: finding the implementation behind a proxy address
- ERC-1155: one operator approval can cover many token IDs
- Permit2: token approval and downstream signatures are separate permissions
- PSBT: moving an unsigned Bitcoin transaction between devices
- BIP-39 passphrases: the wrong phrase can open a different wallet
- Closing a Solana token account: check where its SOL goes
Estrutura de mercado
- Wash trading and the appearance of demand
- Market makers: inventory, fees and conflicts
- Market cap is not money available to withdraw
- Concentrated liquidity: TVL can sit outside the trading range
- Slippage, price impact and the price you actually receive
- A ticker is not an asset identifier
- MEV: measure the execution, not just the chart
- PnL screenshots: reconcile the money before admiring the return
- Token unlocks: measure the newly transferable supply
- Constant-product pools: where price impact comes from
- Divergence loss: what a liquidity position gives up relative to holding
- Last price, index price and mark price answer different questions
- Perpetual funding: a transfer between position holders
- Insurance funds and ADL: who absorbs a derivatives shortfall?
- Undisclosed insider allocations
- SAFT discounts and public-market asymmetry
- Vesting side letters
- Launch sniping and privileged block access
- Bundled launch wallets
- Creator-wallet mapping
- Liquidity withdrawal as an exit
- LP-lock marketing
- Market-maker token loans
- Wash trading
- Spoofing and layering
- Self-trade volume
- Rebate-driven fake activity
- Token-unlock framing
- Circulating-supply manipulation
- FDV as a valuation weapon
- TVL without executable depth
- Oracle override power
- Liquidation priority and privileged keepers
- Exchange mark-price discretion
- Opaque insurance funds
- Auto-deleveraging externalities
- Customer-asset rehypothecation
- Related-party lending
- Oracle staleness
- Time-weighted average prices
- Constant-product pool arithmetic
- Stablecoin reserve models
- Maximal extractable value
- Sandwich attacks
- Perpetual futures
- Funding payments
DeFi e governação
- Stablecoins: the peg and the claim behind it
- Yield: identify who pays it
- Leverage and liquidation
- Bridges and wrapped assets
- Oracles: which price controls the contract?
- DAO governance: transparent votes can still concentrate power
- Contagion: one asset, several dependent products
- Governance proposals: read the transaction that will execute
- Bridged assets: the same symbol does not mean the same claim
- Oracle freshness: a valid number can still be unusable
- Liquidation: the threshold, the execution and the remaining debt
- Lock-and-mint bridges: the token depends on both sides
- Liquid staking: a tradable receipt for a less immediate underlying position
- Flash loans
- Overcollateralised debt positions
- Liquid staking receipts
- Restaking and correlated risk
- Bridge trust models
- Collateral liquidation
- ERC-4626: a vault share is not an immediately withdrawable balance
Métodos de investigação
- Wallet attribution: an address is not a person
- How to write a finding people can check
- Checking a crypto-provider authorisation
- Evidence snapshots: make a finding reproducible
- Wallet clusters: confidence is not ownership
- Audit scope drift: the badge can outlive the reviewed code
- Incident updates: distinguish containment from repair
- From lead to finding: a claim ladder for crypto research
- Reserve assets and liabilities: the missing half of a solvency claim
- ERC-165: interface support is a claim, not a security certificate
História cripto
- 2008–2009: Bitcoin and the problem of double spending
- Mt. Gox: the long tail of a custody failure
- The DAO: code, governance and the 2016 split
- The ICO era: selling access to a future product
- OneCoin: a cryptocurrency story without the promised system
- BitConnect: promised returns and the supposed trading bot
- Terra and UST: the peg, the collapse and the fraud cases
- FTX and Alameda: customer money, privileged accounts and the bankruptcy
- Ronin: bridge theft and attribution
- 2015: Ethereum makes shared computation a public service
- 2017: SegWit changes Bitcoin transaction accounting
- 2018: Lightning reaches a mainnet beta
- 2018: Uniswap makes pooled liquidity a trading venue
- 2020: liquidity mining turns usage into a token reward
- 2021: the NFT boom connects provenance, art and speculation
- 2021: EIP-1559 changes Ethereum fees and introduces base-fee burning
- 2022: Ethereum replaces mining with proof of stake
- 2023: Shapella enables staking withdrawals
- 2024: Dencun gives rollups a separate data market
- 2024: US spot Bitcoin ETPs change the access route
- 2023: USDC's peg encounters a banking failure
- 2025: the Bybit theft and the limits of a transaction signature
- 2016–2024: the Bitfinex theft, laundering and later sentencing
- 2022–2025: Celsius, promised yield and CEL price support
- 2022: BlockFi and the regulation of crypto interest accounts
- 2021–2023: Gemini Earn connects a retail interface to Genesis credit risk
- 2021: Tether's reserve representations face an enforcement finding
- 2021: Taproot changes Bitcoin's spending paths
- Coincheck NEM theft
- QuadrigaCX and the missing custody record
- Cryptopia exchange liquidation
- PlusToken investment scheme
- AirBit Club
- IcomTech
- Forsage smart-contract pyramid
- SafeMoon liquidity-pool diversion
- HyperFund and HyperVerse
- Mining Capital Coin
- Three Arrows Capital collapse
- Voyager Digital collapse
- FTX privileged Alameda account
- FTX bankruptcy-claim valuation
- Celsius CEL market support
- Genesis and Gemini Earn structure
- BlockFi interest accounts
- Wormhole message-verification failure
- Nomad trusted-root failure
- Harmony Horizon bridge
- Poly Network cross-chain exploit
- Euler donation-to-reserves exploit
- Mango Markets oracle manipulation
- Beanstalk governance takeover
- Cream Finance lending exploits
- BadgerDAO frontend compromise
- Curve Vyper reentrancy incident
- Multichain bridge collapse
- KyberSwap concentrated-liquidity exploit
- BitMEX Bank Secrecy Act case
- Binance 2023 criminal resolution
- Bybit February 2025 theft
- Ronin validator compromise
- The DAO exploit and Ethereum fork
- EthereumMax paid promotion
- Mayweather and Khaled ICO promotions
- TRX and BTT celebrity promotion cases
- OneCoin without a public blockchain
- BitConnect lending programme
- Tornado Cash sanctions and software questions
- DMM Bitcoin, 2024: a recruitment lure reached a custody workflow
- OneCoin, 2026: asset recovery is not the same as repaying every victim
Redes e cadeias
- Bitcoin: settlement, mining and custody
- Ethereum: applications share a settlement system
- Solana: wallets, token accounts and authority
- BNB Chain and Binance are different subjects
- TRON: resources, tokens and issuer control
- XRP Ledger: validators, XRP and issued assets
- Arbitrum: rollups and AnyTrust have different assumptions
- Optimism: fault proofs and withdrawal assumptions
- Base: familiar addresses, separate balances
- Polygon PoS: checkpoints are not the whole security model
- Avalanche: C-Chain, other chains and bridge exposure
- Cosmos: a framework is not one shared security guarantee
- Sui: objects and ownership
- Cardano: extended UTXO and application risk
- Layer 2: five separate questions
- Solana PDAs: an address can be controlled without a private key
- Solana CPI: follow permissions into the called program
Fundamentos da Web
- HTTP: what your browser asks a server to do
- DNS: the name is part of the security boundary
- TLS: encrypted traffic can still reach a scam website
- Cookies: how a website remembers a session
- Same-origin policy: the browser's boundary between sites
- Content Security Policy: limit what a page may execute
- Session theft: account access without another password prompt
- Password storage: why hashing and encryption serve different jobs
Fundamentos de blockchain
- A transaction's path from signature to confirmation
- Blocks: ordered transactions and a commitment to state
- Proof of stake: agreement has rules, participants and penalties
- Nodes, clients and RPC providers
- Gas: resource usage and transaction price
- Merkle proofs: verify inclusion against a known commitment
- Bitcoin UTXOs: the outputs behind a wallet balance
- Bitcoin halvings: a programmed subsidy reduction
- Transaction malleability: when an identifier changes
- Contract storage: the persistent state a transaction changes
- Optimistic rollups: claims, challenges and the exit route
- Validity rollups: proving a state transition
- Data availability: can the state be independently reconstructed?
- Chain reorganisations: why recent inclusion can change
- NFT metadata: where the image and its description actually live
- Private keys and control
- Mnemonic recovery phrases
- Hierarchical deterministic derivation
- Transaction nonces
- Public mempools
- Confirmations and reorganisations
- Economic and protocol finality
- Proof-of-work mining
- Proof-of-stake validators
- Slashing conditions
- UTXO selection
- EVM account state
- Solana account ownership
- Gas limits and execution cost
- EIP-1559 base fees
- Blob data for rollups
- Calldata
- Contract storage layout
- Events and transaction logs
- Integer precision and rounding
- Light-client verification
- Optimistic rollups
- Validity-proof rollups
- Data availability
- Sequencer control
- NFT metadata persistence
- Token-standard boundaries
- Cross-chain message execution
- Replace-by-fee: an unconfirmed payment is not final settlement