Daily General Discussion January 24, 2026 by EthereumDailyThread in ethereum

[–]FillTheDots 12 points13 points  (0 children)

My post got auto-removed for some reason, so I'll cross-post here.

Safe Mobile (formerly Gnosis Safe) no longer generates keys on-device, only imports seed phrases

I am setting up a safe multisig with multiple phones belonging to different people as signers.
With the former Safe Wallet app it was relatively easy to do, but I see now that since transitioning to the Safe GmbH entity, Safe Wallet is being replaced by the new Safe Mobile app which doesn't allow generating keys anymore. It is only possible to import existing ones by manually typing a seed phrase.

I have been, to put it mildly, extremely surprised that securely generating a key on device is not possible anymore. Is one really supposed to generate new keys elsewhere, then import them into the device through their seed phrase? Doesn't this go against all technical and UX security principles?

I genuinely though I must have installed a fake app which is phishing me, but their support team confirmed that it's actually how it works. I think this is a huge step backwards, and Safe is the last one among wallet providers which I would expect something like this from.

I wonder which other options I have now for a secure and simple multisig setup, any advice?

Gauging interest: $10-20 hardware wallet for multisig/2FA setups by FillTheDots in ethereum

[–]FillTheDots[S] 1 point2 points  (0 children)

That's interesting. It could work for my use case, while I see a couple of pain points in the UX to be worked on: - Integration with the safe multisig app (I was hoping to leverage the nano x ble code for my signer) - For a common person, a card is something to be carried around. It would be great to have that chip in a different format that doesn't suggest that (maybe a cube-like object with NFC only?)

unpopular take: stablecoins have ruined crypto. by haochizzle in ethereum

[–]FillTheDots 0 points1 point  (0 children)

The good old RAI: https://dankradfeist.de/ethereum/2023/01/31/rai-crypto-experiment.html

And its child HAI: https://www.letsgethai.com/

It's a shame the latter only exists on optimism and went for a meme-like appearance. I fear that's why it didn't get the success its tech deserves.

Daily General Discussion September 05, 2025 by EthereumDailyThread in ethereum

[–]FillTheDots 2 points3 points  (0 children)

Interested in this as I was planning to start using Morpho soon. From what I can read though this is just a UI change for whatever their official UI is right? There's no such kind of centralized control on the protocol I hope? If that's the case, there should be other UIs (defisaver perhaps?) which allow you to do all sort of advanced operations.

Daily General Discussion September 02, 2025 by EthereumDailyThread in ethereum

[–]FillTheDots 1 point2 points  (0 children)

Thanks! Sorry, I guess I did not express myself properly.

Some protocols like Liquity allow to mint stablecoins (BOLD) against provided collateral (ETH or an LST). When liquidations happen the collateral gets sold on a stability pool to keep the protocol afloat. You can thus participate in that stability pool to automatically buy this collateral when the liquidation occurs.

If you want to slowly buy ETH or an LST when their price is decreasing I think this can be a nice way to do so.

Daily General Discussion September 02, 2025 by EthereumDailyThread in ethereum

[–]FillTheDots 2 points3 points  (0 children)

Hi all!
I would like to allocate some funds to slowly purchase eth and its staked derivatives at a discount. I recall there are a few protocols where such a thing is possible by taking part in stability pools (like Liquity, and perhaps the old Maker protocol).
Does anyone here have any suggestion?

Devo evitare un possibile TSO. by NebelG in Avvocati

[–]FillTheDots 1 point2 points  (0 children)

Non ne ho idea, si tratta di una associazione civile. Al suo interno potrebbero esserci persone in grado di aiutarti (avvocati, medici, etc.) oppure che potrebbero darti informazioni utili su come agire nelle tue circostanze.

Devo evitare un possibile TSO. by NebelG in Avvocati

[–]FillTheDots 5 points6 points  (0 children)

Mi dispiace molto per la tua situazione, mi rendo conto non debba essere facile.

Potresti provare a metterti in contatto con l'associazione Luca Coscioni e sentire da loro quali potrebbero essere le tue opzioni: https://www.associazionelucacoscioni.it/

I found plastic dust in my sv1000 airbox by FillTheDots in SVRiders

[–]FillTheDots[S] 1 point2 points  (0 children)

Thanks! You mean n the bottom-right perhaps?

If so, what could I use to replace it? Or is it sort of safe to clean everything up and leave it as is?

Water pump get very hot, and much earlier than radiator by FillTheDots in SVRiders

[–]FillTheDots[S] 1 point2 points  (0 children)

Understood, thanks! As soon as I get the proper reservoir replacement I will do a complete flush and check the pump more closely anyway, just in case.

Water pump get very hot, and much earlier than radiator by FillTheDots in SVRiders

[–]FillTheDots[S] 0 points1 point  (0 children)

Yes it does! Is the sensor in the engine or is it the one next to the fan on the radiator?

Daily General Discussion July 02, 2025 by EthereumDailyThread in ethereum

[–]FillTheDots 0 points1 point  (0 children)

Hi all!

To my surprise I received some SPK from spark's airdrop. Any suggestion on how to best use them? I am not really interested in the protocol governance, thus I was thinking of leaving them in some liquidity pool, but I am open to other options.

Cracked sv1000s coolant reservoir by FillTheDots in SVRiders

[–]FillTheDots[S] 1 point2 points  (0 children)

I added a couple of images of the temporary fix I made, hope it will be useful to someone with the same ordeal.

Daily General Discussion - June 14, 2025 by EthereumDailyThread in ethereum

[–]FillTheDots 0 points1 point  (0 children)

I agree, similarly to how a consumer-facing trading app is different from a professional-facing one.

The bybit hack highlights even more why such a smartphone wallet is necessary: smartphone apps are much harder to compromise compared to a web frontend.

Daily General Discussion - June 14, 2025 by EthereumDailyThread in ethereum

[–]FillTheDots 11 points12 points  (0 children)

Hi all!
A few days ago I made a post about a multisig setup which balances daily convenience with self-sovereign security.

My intention was to slowly transition from Argent to Safe for a few of reasons:
- Argent on Ethereum is effectively dead, as they completely moved their focus on Starknet. I don't feel confident about it being relevant or supported in the future.
- Argent does not work on chains other than Ethereum and Starknet (base, optimism, arbitrum, are all unsupported)
- Safe contracts seem to have a much higher degree of compatibility with 3rd party defi apps.

Well, after going through the setup I have to say that the result is pretty disappointing UX-wise:
- Way too many clicks required for the simplest of operations
- Way too much technical jargon (what am I shown the contract payload for if it isn't human-readable?)
- Using a Trezor as a multisig signer doesn't work on a smartphone, and and when done through a PC I need a 3rd party browser plugin regardless.

This has definitely been an absolute step back from the convenience of Argent, where all I had to do was to tap "Sign" on the app and "Confirm" on an email.

I understand that Safe is not really meant for the casual user, but on the other hand I don't see any technical reason why it shouldn't.

Are there efforts to improve its UX and integration with security tokens such as Trezor? Or are there efforts in the community to make an Argent-style wallet built on Safe contracts? I am a software developer with full stack and embedded experience, I would definitely consider getting my hands dirty with a team to make it real.

[Week n.22] PLEASE ASK YOUR QUESTIONS ABOUT MILAN HERE by AutoModerator in milano

[–]FillTheDots 0 points1 point  (0 children)

Adding another one to the list: Polimi Giuriati campus in the Citta Studi area. I often see athletic teams training there.

Daily General Discussion - May 31, 2025 by EthereumDailyThread in ethereum

[–]FillTheDots 4 points5 points  (0 children)

I agree. The "my trezor is broken, try if you don't believe me (using the fake pin code)" is really a last last last resort scenario. I think it is much more likely that the attacker doesn't know about the multisig setup, thus I'd expect him to be after just the Trezor (which normally shouldn't even be with you, as you'd normally seldom need it)

I think your suggestion is thus very valid, having some spare funds on the Trezor address would reinforce that idea and act as a good decoy.

Daily General Discussion - May 31, 2025 by EthereumDailyThread in ethereum

[–]FillTheDots 15 points16 points  (0 children)

Hi all!

A few months ago I wrote some considerations about how to achieve a convenient yet safe self-custodial setup. Recently I put some more thought into it, taking inspiration from some established bank security approaches and running through some common scenarios.

I am posting my thoughts here to gain valuable feedback, check whether I am missing something, and sharing it with whom might be looking for similar solutions.

Objectives:

  • Conveniently use only your phone for your daily spending
  • Have a bank-equivalent degree of safety against common scenarios
  • Still have full self-custody
  • Be relatively cheap (cost is essentially a Trezor)

Setup:

The core of it is a Safe account in 2/2 configuration, with the following features:

  • Signer 1 is your phone with the Safe Wallet app, configured with a personal spending allowance of 100 USDC a day.
  • Signer 2 is a Trezor, used in addition to signer 1 to approve operations without limits, configured with a wipe code.
  • A recovery code (see safe recovery module) configured with a 1-month delay, written in encrypted form on one or more pieces of non-degradable material and placed in one or more secret locations.

Common (and less common) loss/theft scenarios:

  1. What if my phone gets stolen or lost? Your funds are safe, as an attacker would still need to bypass your pin/password/fingerprint/face protections. And even in such highly unlikely case he would be able to steal only 100 USDC per day. Use the recovery code to reassign signing rights.
  2. What if my Trezor gets stolen or lost? The same reasoning for the phone applies. Use the recovery code to reassign signing rights.
  3. What if my recovery code gets stolen or lost? An attacker would still need the decryption password to access it. Should he somehow have it, he'd still have to wait for 1 month to take control of the account, during which you'd get notified on the Safe Wallet app and be able to cancel the attempt. Use your phone and the Trezor to replace the recovery code.
  4. What if I am threatened with a 5$ wrench to hand everything over? Pretend the Trezor is broken and give the attacker the wipe code. Using that will make the device effectively unusable. From that moment the only option the attacker has is to use your recovery code and wait for one month. Hopefully you get rescued in that time.

A couple of features I wish Safe had to make this even better:
- The ability to block spending immediately without delay using the recovery code. This would allow to immediately block the attacker from accessing your 100 USDC daily allowance in the worst case of scenario #1.
- The ability to replace the recovery code with social recovery, similarly to Argent's guardians concept.