# Crypto

Published articles for Crypto.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Libreboot 20140309 release

DevFeed: [Libreboot 20140309 release](<https://devfeed.tech/articles/libreboot-20140309-release-32684.md>)

Original publisher: [Read original article](<https://libreboot.org/news/libreboot20140309.html>)

Author: Leah Rowe

Published: 2026-09-17T04:32:50.666044Z

Content type: release

Language: en

Sources: [News about Libreboot releases and development](<https://devfeed.tech/sources/news-about-libreboot-releases-and-development.md>)

Topics: [libreboot](<https://devfeed.tech/topics/libreboot.md>), [boot](<https://devfeed.tech/topics/boot.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [battery](<https://devfeed.tech/tags/battery.md>), [bios](<https://devfeed.tech/tags/bios.md>), [boot](<https://devfeed.tech/tags/boot.md>), [canoeboot](<https://devfeed.tech/tags/canoeboot.md>), [coreboot](<https://devfeed.tech/tags/coreboot.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [free-software](<https://devfeed.tech/tags/free-software.md>), [libre](<https://devfeed.tech/tags/libre.md>), [libreboot](<https://devfeed.tech/tags/libreboot.md>), [opensource](<https://devfeed.tech/tags/opensource.md>), [processor](<https://devfeed.tech/tags/processor.md>), [release](<https://devfeed.tech/tags/release.md>), [uefi](<https://devfeed.tech/tags/uefi.md>)

### AI overview

The Libreboot 20140309 release reduces boot time, adds cryptographic and cryptodisk modules to GRUB, includes cbfstool in binary archives, and provides separate ROM images for faster booting or debugging. It also describes changes intended to reduce battery impact.

### Source excerpt

Article: Libreboot 20140309 release Web link: https://libreboot.org/news/libreboot20140309.html

## Node.js 26.9.0 (Current)

DevFeed: [Node.js 26.9.0 (Current)](<https://devfeed.tech/articles/node-js-26-9-0-current-31549.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v26.9.0>)

Published: 2026-09-16T18:17:42Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [crypto](<https://devfeed.tech/tags/crypto.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [node](<https://devfeed.tech/tags/node.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [version](<https://devfeed.tech/tags/version.md>)

### AI overview

Node.js 26.9.0 is a current release with semver-minor additions and fixes across cryptography, module loading, Web Workers, benchmarking, builds, and diagnostics.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Solana: Building, Proving and Earning Trust in Public

DevFeed: [Solana: Building, Proving and Earning Trust in Public](<https://devfeed.tech/articles/solana-building-proving-and-earning-trust-in-public-17467.md>)

Original publisher: [Read original article](<https://solana.com/news/solana-building-trust-in-public>)

Author: Jacob Creech

Published: 2026-09-14T11:00:00Z

Content type: article

Language: en

Sources: [Solana News Feed](<https://devfeed.tech/sources/solana-news-feed.md>)

Topics: [Network](<https://devfeed.tech/topics/network.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [incident](<https://devfeed.tech/topics/incident.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Transactions](<https://devfeed.tech/topics/transactions.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [aws](<https://devfeed.tech/tags/aws.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [blockchain-technology](<https://devfeed.tech/tags/blockchain-technology.md>), [building](<https://devfeed.tech/tags/building.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [crypto-news](<https://devfeed.tech/tags/crypto-news.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [defi](<https://devfeed.tech/tags/defi.md>), [ecosystem](<https://devfeed.tech/tags/ecosystem.md>), [incident](<https://devfeed.tech/tags/incident.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [network](<https://devfeed.tech/tags/network.md>), [nfts](<https://devfeed.tech/tags/nfts.md>), [outages](<https://devfeed.tech/tags/outages.md>), [podcasts](<https://devfeed.tech/tags/podcasts.md>), [routing](<https://devfeed.tech/tags/routing.md>), [solana](<https://devfeed.tech/tags/solana.md>), [solana-ecosystem](<https://devfeed.tech/tags/solana-ecosystem.md>), [technology](<https://devfeed.tech/tags/technology.md>), [transactions](<https://devfeed.tech/tags/transactions.md>), [uptime](<https://devfeed.tech/tags/uptime.md>), [web3](<https://devfeed.tech/tags/web3.md>)

### AI overview

Solana describes how repeated public testing, transparent incident reporting, and corrective engineering have strengthened trust in the network. It highlights a 2026 routing failure that took nearly 29% of network stake offline while blocks and transactions continued, followed by recovery of the infrastructure provider in just over 30 minutes. The article also cites validator capacity improvements, stake-weighted quality of service, and a redesigned transaction scheduler as examples of resilience work.

### Source excerpt

Solana has maintained 100% uptime since February 2024, including when a routing failure took nearly 29% of network stake offline.

## Zstd Improvement For Linux 7.4 To Avoid Redundant Initialization

DevFeed: [Zstd Improvement For Linux 7.4 To Avoid Redundant Initialization](<https://devfeed.tech/articles/zstd-improvement-for-linux-7-4-to-avoid-redundant-initialization-12425.md>)

Original publisher: [Read original article](<https://www.phoronix.com/news/Zstd-Linux-7.4-Avoid-Redundant>)

Author: Michael Larabel

Published: 2026-09-13T14:04:23Z

Content type: news

Language: en

Sources: [Phoronix](<https://devfeed.tech/sources/phoronix.md>)

Topics: [Compression](<https://devfeed.tech/topics/compression.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [benchmark](<https://devfeed.tech/tags/benchmark.md>), [compression](<https://devfeed.tech/tags/compression.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [desktop-linux](<https://devfeed.tech/tags/desktop-linux.md>), [development](<https://devfeed.tech/tags/development.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [linux-benchmarking](<https://devfeed.tech/tags/linux-benchmarking.md>), [linux-hardware-benchmarks](<https://devfeed.tech/tags/linux-hardware-benchmarks.md>), [linux-hardware-reviews](<https://devfeed.tech/tags/linux-hardware-reviews.md>), [linux-how-to](<https://devfeed.tech/tags/linux-how-to.md>), [linux-performance](<https://devfeed.tech/tags/linux-performance.md>), [linux-server-benchmarks](<https://devfeed.tech/tags/linux-server-benchmarks.md>), [open-source-graphics](<https://devfeed.tech/tags/open-source-graphics.md>), [performance](<https://devfeed.tech/tags/performance.md>), [phoronix](<https://devfeed.tech/tags/phoronix.md>), [phoronix-test-suite](<https://devfeed.tech/tags/phoronix-test-suite.md>), [speed](<https://devfeed.tech/tags/speed.md>), [ubuntu-benchmarks](<https://devfeed.tech/tags/ubuntu-benchmarks.md>), [ubuntu-hardware](<https://devfeed.tech/tags/ubuntu-hardware.md>)

### AI overview

The article reports Linux 7.4 patches that defer Zstd stream initialization until the first walk iteration, eliminating redundant initialization. Benchmarks show single-digit compression speed improvements and decompression speedups of 13% on bare metal or 35% in a virtual machine.

### Source excerpt

In addition to Usama Arif's recent Linux patches for addressing a major inefficiency within the Linux kernel's Zstd compression code, he also has a separate patch series destined for Linux 7.4 to further enhance the Zstd compression/decompression performance by avoiding redundant initialization...

## \[Crypto\] Time-based one-time password (TOTP) for 2FA, part I

DevFeed: [\[Crypto\] Time-based one-time password (TOTP) for 2FA, part I](<https://devfeed.tech/articles/crypto-time-based-one-time-password-totp-for-2fa-part-i-20550.md>)

Original publisher: [Read original article](<https://yurichev.com/blog/TOTP1/>)

Published: 2026-09-09T22:00:00Z

Content type: tutorial

Language: en

Sources: [Dennis Yurichev](<https://devfeed.tech/sources/dennis-yurichev.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [QR Code](<https://devfeed.tech/topics/qrcode.md>), [Google](<https://devfeed.tech/topics/google.md>), [Python](<https://devfeed.tech/topics/python.md>), [Unix](<https://devfeed.tech/topics/unix.md>), [App](<https://devfeed.tech/topics/app.md>), [email](<https://devfeed.tech/topics/email.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [app](<https://devfeed.tech/tags/app.md>), [argument](<https://devfeed.tech/tags/argument.md>), [backup](<https://devfeed.tech/tags/backup.md>), [code](<https://devfeed.tech/tags/code.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [env-file-security](<https://devfeed.tech/tags/env-file-security.md>), [github](<https://devfeed.tech/tags/github.md>), [google](<https://devfeed.tech/tags/google.md>), [password](<https://devfeed.tech/tags/password.md>), [protection](<https://devfeed.tech/tags/protection.md>), [python](<https://devfeed.tech/tags/python.md>), [run](<https://devfeed.tech/tags/run.md>), [server](<https://devfeed.tech/tags/server.md>), [smartphone](<https://devfeed.tech/tags/smartphone.md>), [unix](<https://devfeed.tech/tags/unix.md>)

### AI overview

This tutorial explains how time-based one-time passwords work for two-factor authentication. It covers importing a base32-encoded secret from a QR code into Google Authenticator, generating 6-digit login codes, and calculating them with HMAC-SHA-1 from the secret and Unix time. It also discusses backup codes and securely storing TOTP secrets separately from passwords.

### Source excerpt

[Crypto] Time-based one-time password (TOTP) for 2FA, part I

## Acceleration of Curve25519 Field Operations with Java Software and Intrinsics

DevFeed: [Acceleration of Curve25519 Field Operations with Java Software and Intrinsics](<https://devfeed.tech/articles/acceleration-of-curve25519-field-operations-with-java-software-and-intrinsics-15129.md>)

Original publisher: [Read original article](<https://inside.java/2026/09/03/java-acceleration-curve25519-field-operations/>)

Author: Shawn Emery

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Inside Java](<https://devfeed.tech/sources/inside-java.md>)

Topics: [Java](<https://devfeed.tech/topics/java.md>), [JDK 27](<https://devfeed.tech/topics/jdk-27.md>), [JDK 28](<https://devfeed.tech/topics/jdk-28.md>), [Security](<https://devfeed.tech/topics/security.md>), [Post-Quantum](<https://devfeed.tech/topics/post-quantum.md>)

Tags: [crypto](<https://devfeed.tech/tags/crypto.md>), [ed25519](<https://devfeed.tech/tags/ed25519.md>), [java](<https://devfeed.tech/tags/java.md>), [jdk](<https://devfeed.tech/tags/jdk.md>), [jdk-27](<https://devfeed.tech/tags/jdk-27.md>), [jdk-28](<https://devfeed.tech/tags/jdk-28.md>), [performance](<https://devfeed.tech/tags/performance.md>), [post-quantum](<https://devfeed.tech/tags/post-quantum.md>), [security](<https://devfeed.tech/tags/security.md>), [tls](<https://devfeed.tech/tags/tls.md>), [x86](<https://devfeed.tech/tags/x86.md>)

### AI overview

JDK 27 and JDK 28 improve Curve25519 field-operation performance through software changes and architecture-specific intrinsics. The improvements benefit X25519, Ed25519, and X25519MLKEM768 operations, with gains varying by algorithm, JDK build, and x86_64 or AArch64 platform.

### Source excerpt

Find out about the improved Curve25519 field performance in JDK 27 and JDK 28.

## 7 Whop Alternatives for Creators and SaaS Sellers in 2026

DevFeed: [7 Whop Alternatives for Creators and SaaS Sellers in 2026](<https://devfeed.tech/articles/7-whop-alternatives-for-creators-and-saas-sellers-in-2026-10445.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/whop-alternatives/>)

Author: Deepak Jangir

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Software as a service](<https://devfeed.tech/topics/saas.md>), [Software](<https://devfeed.tech/topics/software.md>), [stripe](<https://devfeed.tech/topics/stripe.md>)

Tags: [alternatives](<https://devfeed.tech/tags/alternatives.md>), [comparison](<https://devfeed.tech/tags/comparison.md>), [creators](<https://devfeed.tech/tags/creators.md>), [cross-border](<https://devfeed.tech/tags/cross-border.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [fees](<https://devfeed.tech/tags/fees.md>), [global](<https://devfeed.tech/tags/global.md>), [india](<https://devfeed.tech/tags/india.md>), [merchant-of-record](<https://devfeed.tech/tags/merchant-of-record.md>), [payments](<https://devfeed.tech/tags/payments.md>), [pricing](<https://devfeed.tech/tags/pricing.md>), [saas](<https://devfeed.tech/tags/saas.md>), [stripe](<https://devfeed.tech/tags/stripe.md>), [subscriptions](<https://devfeed.tech/tags/subscriptions.md>), [us](<https://devfeed.tech/tags/us.md>), [usage-based-billing](<https://devfeed.tech/tags/usage-based-billing.md>), [vat](<https://devfeed.tech/tags/vat.md>)

### AI overview

A comparison of seven Whop alternatives for creators and SaaS sellers, focusing on effective fees, international transactions, payouts, tax handling, and fit for software businesses.

### Source excerpt

Whop's headline 2.7% + 30c climbs toward 7% once FX and payout fees stack. Compare seven alternatives with verified 2026 pricing and pick the right fit.

## Stablecoin Payments: How the Infrastructure Works

DevFeed: [Stablecoin Payments: How the Infrastructure Works](<https://devfeed.tech/articles/stablecoin-payments-how-the-infrastructure-works-10387.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/stablecoin-payments-guide/>)

Author: Aarthi Poonia

Published: 2026-08-03T00:00:00Z

Content type: article

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Network](<https://devfeed.tech/topics/network.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>)

Tags: [blockchain](<https://devfeed.tech/tags/blockchain.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [guide](<https://devfeed.tech/tags/guide.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [payments](<https://devfeed.tech/tags/payments.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

A guide to the infrastructure behind stablecoin payments, covering wallet-to-address transfers, blockchain settlement, network selection, confirmation and finality, treasury flows, and the distinctions among fiat-collateralised, crypto-backed, and algorithmic stablecoins.

### Source excerpt

How stablecoin payments work as infrastructure: settlement flow, network choice, on-ramps and off-ramps, finality risk, treasury handling, and compliance.

## Raspberry Pi Projects That Sound Great But Are Usually a Bad Idea

DevFeed: [Raspberry Pi Projects That Sound Great But Are Usually a Bad Idea](<https://devfeed.tech/articles/raspberry-pi-projects-that-sound-great-but-are-usually-a-bad-idea-10813.md>)

Original publisher: [Read original article](<https://raspberrytips.com/raspberry-pi-projects-bad-idea/>)

Author: Patrick Fromaget

Published: 2026-07-18T05:00:00Z

Content type: opinion

Language: en

Sources: [RaspberryTips](<https://devfeed.tech/sources/raspberrytips.md>)

Topics: [Hardware](<https://devfeed.tech/topics/hardware.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Security](<https://devfeed.tech/topics/security.md>), [servers](<https://devfeed.tech/topics/servers.md>), [1Password in the browser](<https://devfeed.tech/topics/1password-in-the-browser.md>)

Tags: [crypto](<https://devfeed.tech/tags/crypto.md>), [experiment](<https://devfeed.tech/tags/experiment.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [inspiration](<https://devfeed.tech/tags/inspiration.md>), [linux](<https://devfeed.tech/tags/linux.md>), [projects](<https://devfeed.tech/tags/projects.md>), [raspberry-pi](<https://devfeed.tech/tags/raspberry-pi.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosting](<https://devfeed.tech/tags/self-hosting.md>)

### AI overview

The article argues that although Raspberry Pi computers can run many projects, some are poor choices for long-term reliance because they require more reliability and maintenance than a Pi setup can provide. It presents cryptocurrency mining and self-hosting an email server as examples: both can be useful learning exercises, but Raspberry Pi hardware is generally unsuitable for profitable mining or dependable email hosting.

### Source excerpt

After years of testing and writing tutorials on RaspberryTips, I can tell you one thing: you can make your Raspberry Pi do almost anything. However, just because it works doesn't mean it's a good idea. Let's talk about it. A Raspberry Pi can run many home projects, but some are poor choices for long-term use....

## How Bullet uses ClickHouse Cloud to give DeFi's fastest exchange real-time analytics

DevFeed: [How Bullet uses ClickHouse Cloud to give DeFi's fastest exchange real-time analytics](<https://devfeed.tech/articles/how-bullet-uses-clickhouse-cloud-to-give-defi-s-fastest-exchange-real-time-analytics-5017.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/bullet-real-time-analytics>)

Author: ClickHouse

Published: 2026-07-15T00:00:00Z

Content type: article

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [clickhouse](<https://devfeed.tech/topics/clickhouse.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Latency](<https://devfeed.tech/topics/latency.md>), [real-time](<https://devfeed.tech/topics/real-time.md>), [databricks](<https://devfeed.tech/topics/databricks.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [data](<https://devfeed.tech/topics/data.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>)

Tags: [analytics](<https://devfeed.tech/tags/analytics.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cost](<https://devfeed.tech/tags/cost.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [databricks](<https://devfeed.tech/tags/databricks.md>), [finance](<https://devfeed.tech/tags/finance.md>), [latency](<https://devfeed.tech/tags/latency.md>), [monitor](<https://devfeed.tech/tags/monitor.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [platform](<https://devfeed.tech/tags/platform.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [speed](<https://devfeed.tech/tags/speed.md>), [trading](<https://devfeed.tech/tags/trading.md>)

### AI overview

Bullet uses ClickHouse Cloud to index, analyze, and monitor its real-time DeFi perpetuals exchange. The migration from Databricks reduced query latency from 10-15 seconds to milliseconds, improved data freshness to under five seconds, eliminated a separate serving layer, and supported 1,000 times more data at comparable cost.

### Source excerpt

Switching from Databricks to ClickHouse Cloud cut Bullet's query latency 10,000x and eliminated an entire serving layer, giving DeFi's fastest exchange real-time analytics at comparable cost.

## Turing Award Winner: NSA, Public Key Cryptography, Crypto Wars | Martin Hellman

DevFeed: [Turing Award Winner: NSA, Public Key Cryptography, Crypto Wars | Martin Hellman](<https://devfeed.tech/articles/turing-award-winner-nsa-public-key-cryptography-crypto-wars-martin-hellman-18099.md>)

Original publisher: [Read original article](<https://www.developing.dev/p/turing-award-winner-nsa-public-key>)

Author: Ryan Peterman

Published: 2026-07-06T13:02:52Z

Content type: article

Language: en

Sources: [The Developing Dev](<https://devfeed.tech/sources/the-developing-dev.md>)

Topics: [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Algorithm](<https://devfeed.tech/topics/algorithm.md>), [Security](<https://devfeed.tech/topics/security.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>)

Tags: [algorithm](<https://devfeed.tech/tags/algorithm.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

An interview with Martin Hellman, one of the inventors of the Diffie-Hellman key exchange algorithm, discusses the early development of cryptography, its relationship with the U.S. National Security Agency, and legal conflicts surrounding cryptographic research.

### Source excerpt

Interviewed Martin Hellman recently who was one of the inventors of the Diffie-Hellman key exchange algorithm.

## @mastra npm scope takeover: 143 packages backdoored via compromised contributor account

DevFeed: [@mastra npm scope takeover: 143 packages backdoored via compromised contributor account](<https://devfeed.tech/articles/mastra-npm-scope-takeover-143-packages-backdoored-via-compromised-contributor-account-13149.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mastra-npm-scope-takeover-143-packages-backdoored-via-compromised-contributor-account>)

Published: 2026-06-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [C2](<https://devfeed.tech/topics/c2.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-packages](<https://devfeed.tech/tags/chainguard-packages.md>), [command-and-control](<https://devfeed.tech/tags/command-and-control.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mastra](<https://devfeed.tech/tags/mastra.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-takeover](<https://devfeed.tech/tags/npm-takeover.md>), [packages](<https://devfeed.tech/tags/packages.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [secure-packages](<https://devfeed.tech/tags/secure-packages.md>), [software-packages](<https://devfeed.tech/tags/software-packages.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

The article reports that an attacker used a compromised former contributor account to republish all 143 packages in the @mastra npm scope on June 17, 2026. The malicious versions could disable TLS verification, download a cryptocurrency wallet stealer and remote access trojan, and establish command-and-control access. It recommends auditing dependency trees and lockfiles and rotating credentials on affected hosts.

### Source excerpt

A supply chain attack compromised all 143 @mastra packages. Chainguard customers stayed protected through malware blocking and source-built libraries.

## This month in security with Tony Anscombe - May 2026 edition

DevFeed: [This month in security with Tony Anscombe - May 2026 edition](<https://devfeed.tech/articles/this-month-in-security-with-tony-anscombe-may-2026-edition-8427.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-may-2026/>)

Author: Editor

Published: 2026-05-29T07:30:00Z

Content type: news

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [Google](<https://devfeed.tech/topics/google.md>), [systems](<https://devfeed.tech/topics/systems.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [google](<https://devfeed.tech/tags/google.md>), [news](<https://devfeed.tech/tags/news.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [systems](<https://devfeed.tech/tags/systems.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

A monthly cybersecurity roundup covering cyber-intrusions against Polish water treatment facilities, an AI-directed attack in Mexico that failed to move from IT to OT systems, an AI-developed zero-day exploit identified by Google, and cryptocurrency kiosk scams.

### Source excerpt

In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-day exploit

## NFC, Crypto, Biometrics, And A New Build Cloud

DevFeed: [NFC, Crypto, Biometrics, And A New Build Cloud](<https://devfeed.tech/articles/nfc-crypto-biometrics-and-a-new-build-cloud-19417.md>)

Original publisher: [Read original article](<https://www.codenameone.com/blog/nfc-crypto-biometrics-and-build-cloud/>)

Author: Shai Almog

Published: 2026-05-22T00:00:00Z

Content type: release

Language: en

Sources: [CodeName One](<https://devfeed.tech/sources/codename-one.md>)

Topics: [Device APIs](<https://devfeed.tech/topics/device-apis.md>), [Framework](<https://devfeed.tech/topics/framework.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Bluetooth](<https://devfeed.tech/topics/bluetooth.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [ui](<https://devfeed.tech/topics/ui.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [bluetooth](<https://devfeed.tech/tags/bluetooth.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [device-apis](<https://devfeed.tech/tags/device-apis.md>), [framework](<https://devfeed.tech/tags/framework.md>), [ios](<https://devfeed.tech/tags/ios.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [nfc](<https://devfeed.tech/tags/nfc.md>), [preview](<https://devfeed.tech/tags/preview.md>), [ui](<https://devfeed.tech/tags/ui.md>)

### AI overview

This weekly Codename One update covers biometrics, cryptography, and NFC APIs moving into the framework core, a Bluetooth simulator change, and a new Build Cloud UI available as a preview for feedback.

### Source excerpt

Device APIs move into the framework core, revolutionary Bluetooth debugging, and the Build Cloud's new UI is live in preview.

## Node.js 26.2.0 (Current)

DevFeed: [Node.js 26.2.0 (Current)](<https://devfeed.tech/articles/node-js-26-2-0-current-2850.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v26.2.0>)

Published: 2026-05-20T13:03:28Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [servers](<https://devfeed.tech/topics/servers.md>), [SQLite](<https://devfeed.tech/topics/sqlite.md>), [V8](<https://devfeed.tech/topics/v8.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Promise](<https://devfeed.tech/topics/promise.md>), [Rust](<https://devfeed.tech/topics/rust.md>)

Tags: [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [macos](<https://devfeed.tech/tags/macos.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [rust](<https://devfeed.tech/tags/rust.md>), [servers](<https://devfeed.tech/tags/servers.md>), [sqlite](<https://devfeed.tech/tags/sqlite.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Node.js 26.2.0 is a current release containing minor API and filesystem updates, HTTP support for arbitrary 1xx status codes, stream and benchmark changes, cryptography and Web Cryptography improvements, debugger updates, dependency upgrades, documentation changes, and Rust toolchain installation instructions for Windows.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Dodo Digest: Stablecoins Are Quietly Becoming the Internet's Payment Layer

DevFeed: [Dodo Digest: Stablecoins Are Quietly Becoming the Internet's Payment Layer](<https://devfeed.tech/articles/dodo-digest-stablecoins-are-quietly-becoming-the-internet-s-payment-layer-10165.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/newsletter-may15/>)

Author: Rishabh Goel

Published: 2026-05-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Internet](<https://devfeed.tech/topics/internet.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [bank](<https://devfeed.tech/tags/bank.md>), [cross-border](<https://devfeed.tech/tags/cross-border.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [newsletter](<https://devfeed.tech/tags/newsletter.md>), [payment](<https://devfeed.tech/tags/payment.md>), [payments](<https://devfeed.tech/tags/payments.md>), [stablecoins](<https://devfeed.tech/tags/stablecoins.md>)

### AI overview

The article argues that stablecoins are shifting from primarily crypto assets toward payment infrastructure for internet businesses. It cites changing institutional views, including comments from the Bank of England, and highlights faster settlement, simpler cross-border transfers, and reduced dependence on traditional banking rails. It also announces Dodo Payments support for USDC, USDP, and USDG in v1.97.6, alongside entitlements and subscription-cancellation improvements.

### Source excerpt

Stablecoins are shifting from crypto assets to payment infrastructure. Dodo Payments now supports USDC, USDP, and USDG in v1.97.6, plus entitlements and more.

## Should Your SaaS Accept Crypto in 2026? An Honest Cost-Benefit Analysis

DevFeed: [Should Your SaaS Accept Crypto in 2026? An Honest Cost-Benefit Analysis](<https://devfeed.tech/articles/should-your-saas-accept-crypto-in-2026-an-honest-cost-benefit-analysis-9779.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/crypto-saas-payments-2026/>)

Author: Ayush Agarwal

Published: 2026-05-12T00:00:00Z

Content type: article

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Software as a service](<https://devfeed.tech/topics/saas.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Solana](<https://devfeed.tech/topics/solana.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [extension](<https://devfeed.tech/tags/extension.md>), [payment](<https://devfeed.tech/tags/payment.md>), [payments](<https://devfeed.tech/tags/payments.md>), [qr-code](<https://devfeed.tech/tags/qr-code.md>), [saas](<https://devfeed.tech/tags/saas.md>), [solana](<https://devfeed.tech/tags/solana.md>)

### AI overview

A guide for SaaS founders evaluating crypto payments in 2026. It focuses on stablecoins, processor-based USD settlement, the customer payment flow, and trade-offs including limited readiness among non-crypto-native consumers.

### Source excerpt

Where crypto payments make sense for SaaS in 2026, the stablecoin reality, USD settlement, no chargebacks, and the trade-offs founders rarely think through.

## My brave new code-signing world

DevFeed: [My brave new code-signing world](<https://devfeed.tech/articles/my-brave-new-code-signing-world-20513.md>)

Original publisher: [Read original article](<https://nullprogram.com/blog/2026/04/25/>)

Published: 2026-04-25T18:12:29Z

Content type: opinion

Language: en

Sources: [Chris Wellons](<https://devfeed.tech/sources/chris-wellons.md>)

Topics: [Azure](<https://devfeed.tech/topics/azure.md>), [Security](<https://devfeed.tech/topics/security.md>), [Code](<https://devfeed.tech/topics/code.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [alternatives](<https://devfeed.tech/tags/alternatives.md>), [azure](<https://devfeed.tech/tags/azure.md>), [claude](<https://devfeed.tech/tags/claude.md>), [cli](<https://devfeed.tech/tags/cli.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cpp](<https://devfeed.tech/tags/cpp.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [github](<https://devfeed.tech/tags/github.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>)

### AI overview

The article describes the author's move to code-sign Windows releases using Azure Artifact Signing and custom infrastructure called aas-sign. It discusses the cost, regional identity-verification requirement, difficult Azure portal experience, AI-assisted setup, and alternatives involving Azure CLI, Jsign, and SignTool.exe.

### Source excerpt

The new w64devkit release two weeks ago is the first to be code-signed with my identity, verified by Microsoft's certificate chain. Currently only the release packaging is signed -- the self-extracting archive and its payload -- but I will soon code-sign individual EXEs and DLLs within the distribution. In fact, all Windows builds of my project releases have been code-signed the past two weeks, including dcmake, and so should everything going forward. My signing identity builds reputation with each download, so users will have an easier time with SmartScreen, and security software generally. Azure Artifact Signing creates the actual signature, but the rest is done with new infrastructure I built myself, aas-sign. As is often the case, the existing options were deficient for my needs, so I had to build it myself. This code-signing is not free, and simply having aas-sign on hand, or using the GitHub Actions action, is insufficient. You must be serious enough to spend US$10/month for the Azure subscription. After that you are subjected to the labyrinth that is the Azure portal, the most confusing UI I've ever used. Luckily we live in an age of wonders, and I could describe to Claude in Chrome what I wanted and it would happen (Sonnet works better than Opus for this). It took as much time to figure out Azure as I spent creating a fully-functional, native debugger front-end. Clear your schedule if you're going to try it yourself. If it weren't for AI assistance I would have given up. The one-time setup process is only open to North America, and involves sharing identify documents (i.e. driver's license) with Microsoft. Unlike the rest of Azure, that part was streamlined and fairly painless. Between the cost and this requirement, this is a niche space. However, if this is your niche, aas-sign is currently the best software available. It's the tool Microsoft should have written, but didn't due to ongoing institutional failures. The alternatives are a pair of tools: Azure CLI

## End-to-end encryption for Vercel Workflow

DevFeed: [End-to-end encryption for Vercel Workflow](<https://devfeed.tech/articles/end-to-end-encryption-for-vercel-workflow-1201.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/workflow-encryption>)

Author: Nate Rajlich

Published: 2026-03-17T14:00:00Z

Content type: release

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [End-to-End Encryption](<https://devfeed.tech/topics/end-to-end-encryption.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Vercel](<https://devfeed.tech/topics/vercel.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [browser](<https://devfeed.tech/tags/browser.md>), [cli](<https://devfeed.tech/tags/cli.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [vercel](<https://devfeed.tech/tags/vercel.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

Vercel Workflow now provides end-to-end encryption for workflow data without requiring code changes. Inputs, step data, return values, hook payloads, and stream data are encrypted before being stored in the event log, while authorized users can decrypt data in the dashboard or CLI.

### Source excerpt

Vercel Workflow now encrypts all user data end-to-end without requiring any code changes. Workflow inputs, step arguments, return values, hook payloads, and stream data are automatically encrypted before being written to the event log. This makes it safe to pass sensitive data, such as API keys, tokens, or user credentials, across boundaries. The event log only ever stores ciphertext, while your step functions work exactly as before. Your workflow and step functions work exactly as before; all data flowing through the event log is encrypted automatically. Each Vercel deployment receives a unique encryption key. The key derivation and encryption stack works as follows: Each workflow run derives its own key via HKDF-SHA256 Data is encrypted with AES-256-GCM to ensure confidentiality and integrity Encrypted fields display as locked placeholders in the dashboard until decrypted You can access encrypted data through two methods: Web dashboard: Click the Decrypt button in the run detail panel. Decryption happens entirely in the browser via the Web Crypto API, so the observability server never sees your plaintext data. CLI: Add the --decrypt flag to the inspect command. Decryption follows the same permissions model as project environment variables, meaning you cannot access workflow data if you lack permission to view environment variables. Each decryption request is recorded in your Vercel audit log, providing your team with full visibility into access events. While end-to-end encryption is built into the Vercel platform, custom World implementations can opt into this feature. You can provide your own getEncryptionKeyForRun() method, which the core runtime uses automatically. Learn more in the Workflow DevKit documentation. Read more

## \[Crypto\] Toy SSH client in ~2k SLOC of Python, v6

DevFeed: [\[Crypto\] Toy SSH client in ~2k SLOC of Python, v6](<https://devfeed.tech/articles/crypto-toy-ssh-client-in-2k-sloc-of-python-v6-20549.md>)

Original publisher: [Read original article](<https://yurichev.com/blog/SSH6/>)

Published: 2026-01-19T23:00:00Z

Content type: release

Language: en

Sources: [Dennis Yurichev](<https://devfeed.tech/sources/dennis-yurichev.md>)

Topics: [Python](<https://devfeed.tech/topics/python.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [client](<https://devfeed.tech/topics/client.md>)

Tags: [crypto](<https://devfeed.tech/tags/crypto.md>), [python](<https://devfeed.tech/tags/python.md>), [release](<https://devfeed.tech/tags/release.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

This release of a toy SSH client written in about 2,000 lines of Python fixes mostly network-related bugs. The project began as a learning exercise and became a practical tool for connecting to older routers and devices that use algorithms such as ssh-rsa and ssh-dss.

### Source excerpt

[Crypto] Toy SSH client in ~2k SLOC of Python, v6

## Node.js 24.12.0 (LTS)

DevFeed: [Node.js 24.12.0 (LTS)](<https://devfeed.tech/articles/node-js-24-12-0-lts-2812.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v24.12.0>)

Published: 2025-12-10T16:51:31Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [servers](<https://devfeed.tech/topics/servers.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Web](<https://devfeed.tech/topics/web.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Script](<https://devfeed.tech/topics/script.md>), [V8](<https://devfeed.tech/topics/v8.md>), [SQLite](<https://devfeed.tech/topics/sqlite.md>), [Python](<https://devfeed.tech/topics/python.md>)

Tags: [command-line](<https://devfeed.tech/tags/command-line.md>), [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [debugger](<https://devfeed.tech/tags/debugger.md>), [developers](<https://devfeed.tech/tags/developers.md>), [free](<https://devfeed.tech/tags/free.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [lts](<https://devfeed.tech/tags/lts.md>), [node](<https://devfeed.tech/tags/node.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [python](<https://devfeed.tech/tags/python.md>), [servers](<https://devfeed.tech/tags/servers.md>), [sqlite](<https://devfeed.tech/tags/sqlite.md>), [v8](<https://devfeed.tech/tags/v8.md>), [validation](<https://devfeed.tech/tags/validation.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

Node.js 24.12.0 (LTS) is a release containing minor enhancements and updates across the runtime, including server request optimization, configurable deprecation behavior, stable type stripping, new Node-API and SQLite capabilities, watch configuration, portable compile caching, inspector permissions, CPU profiling, performance improvements, validation fixes, debugger fixes, and dependency updates.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Orchestrating ambient agents with Temporal

DevFeed: [Orchestrating ambient agents with Temporal](<https://devfeed.tech/articles/orchestrating-ambient-agents-with-temporal-35931.md>)

Original publisher: [Read original article](<https://temporal.io/blog/orchestrating-ambient-agents-with-temporal>)

Author: Kevin Martin

Published: 2025-09-18T00:00:00Z

Content type: article

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [Model Context Protocol (MCP)](<https://devfeed.tech/topics/model-context-protocol-mcp.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [auditability](<https://devfeed.tech/tags/auditability.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [model-context-protocol-mcp](<https://devfeed.tech/tags/model-context-protocol-mcp.md>), [orchestration](<https://devfeed.tech/tags/orchestration.md>)

### AI overview

An article describes a 24/7 crypto trading platform built with multiple AI agents, using Temporal for durable workflow orchestration and the Model Context Protocol for tool interfaces. It explains how schedules, signals and queries, the Temporal UI, workflow orchestration, and MCP tools support proactive and self-refining agent behavior.

### Source excerpt

How Temporal and MCP power a 24/7 crypto trading system of ambient agents: Schedules, Signals and Queries, durable tools, and auditability.

## \[Crypto\] Leaking IV in CBC mode

DevFeed: [\[Crypto\] Leaking IV in CBC mode](<https://devfeed.tech/articles/crypto-leaking-iv-in-cbc-mode-20538.md>)

Original publisher: [Read original article](<https://yurichev.com/blog/CBC_IV/>)

Published: 2025-09-15T22:00:00Z

Content type: tutorial

Language: en

Sources: [Dennis Yurichev](<https://devfeed.tech/sources/dennis-yurichev.md>)

Topics: [Encryption](<https://devfeed.tech/topics/encryption.md>), [Code](<https://devfeed.tech/topics/code.md>), [Python](<https://devfeed.tech/topics/python.md>)

Tags: [blog-post](<https://devfeed.tech/tags/blog-post.md>), [code](<https://devfeed.tech/tags/code.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [python](<https://devfeed.tech/tags/python.md>)

### AI overview

This article explains how an initialization vector (IV) in CBC mode can be recovered when plaintext contains known bytes such as zeroes or padding. It demonstrates the issue with zero-padded data and PKCS#7 padding, including Python decryption code.

### Source excerpt

[Crypto] Leaking IV in CBC mode

## Introducing the commerce payments protocol

DevFeed: [Introducing the commerce payments protocol](<https://devfeed.tech/articles/introducing-the-commerce-payments-protocol-1349.md>)

Original publisher: [Read original article](<https://shopify.engineering/commerce-payments-protocol>)

Author: Shopify; Coinbase

Published: 2025-06-12T18:38:14Z

Content type: article

Language: en

Sources: [Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering.md>), [Shopify Engineering - Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering-shopify-engineering.md>)

Topics: [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [Shopify](<https://devfeed.tech/topics/shopify.md>), [coinbase](<https://devfeed.tech/topics/coinbase.md>), [Internet](<https://devfeed.tech/topics/internet.md>), [P2P](<https://devfeed.tech/topics/p2p.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [coinbase](<https://devfeed.tech/tags/coinbase.md>), [cost](<https://devfeed.tech/tags/cost.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [developers](<https://devfeed.tech/tags/developers.md>), [ecosystem](<https://devfeed.tech/tags/ecosystem.md>), [global](<https://devfeed.tech/tags/global.md>), [internet](<https://devfeed.tech/tags/internet.md>), [open](<https://devfeed.tech/tags/open.md>), [payments](<https://devfeed.tech/tags/payments.md>), [shopify](<https://devfeed.tech/tags/shopify.md>), [speed](<https://devfeed.tech/tags/speed.md>)

### AI overview

Shopify and Coinbase introduce the Commerce Payments Protocol, a smart contract protocol for handling complex, multi-stage commercial payments onchain. Available on Base and open to developers, it powers Shopify's USDC payment method and aims to provide faster, cheaper, and globally accessible payments.

### Source excerpt

Learn how we partnered with Coinbase to bring payments onchain at scale with a new smart contract protocol to meet the complex requirements of commerce.

[Next page](<https://devfeed.tech/tags/crypto.md?cursor=WyIyMDI1LTA2LTEyVDE4OjM4OjE0KzAwOjAwIiwgIjYwM2VhNTQxLTdjYWEtNGIxNC1iMmMyLTU0ZTBiYzk5ZDViNCJd>)