Wanted to take the next two weeks off contests. Get my head in the right space.
Looked at this protocol and Iām already seeing a simple DOS lol
Maybe Iāll continue it. Wonāt submit any issue until the last day.
Will see if I can get 100% coverage on this audit.
In January I did a contest and missed an issue.
Studied it and told myself I wouldnāt miss it.
Congratulations I missed it in an audit I did in April
I wouldnāt have missed it if I had used my a checklist.
This is a cue for you to create one. If possible integrate it to an AI
Financial AI Agents just took the world by stormānow handling complex DeFi ops that even non-tech users are accessing DeFi seamlessly.
But increasing cyberattack concerns & questions on how to even secure these Agents?
I was privileged to share exactly this @Web3LagosCon.
Financial AI Agents just took the world by stormānow handling complex DeFi ops that even non-tech users are accessing DeFi seamlessly.
But increasing cyberattack concerns & questions on how to even secure these Agents?
I was privileged to share exactly this @Web3LagosCon. https://t.co/OLzGACpyEU
Took a long walk yesterday without my phone.
Almost now a ritual every last day of the month.
I question myself - Am I on track on achieving my long term goal?
Did I achieve the goal for the month?
Where did i deviate?
How can I get back on track?
Iāve noticed recently that my issue was no longer seeing where the bugs are
But digging enough to get a solid impact/ cause the function to break.
Started working on that. Hopefully before the year ends, I end a contest with 100% coverage.
Iāve noticed recently that my issue was no longer seeing where the bugs are
But digging enough to get a solid impact/ cause the function to break.
Started working on that. Hopefully before the year ends, I end a contest with 100% coverage.
Just realized Iām over 400+ followers. Very unexpected. Account was opened to complain about my journey lol
Now some amazing names, people I look up to are following me.
Hopefully I get to meet with a lot of us here in person and collaborate too.
Hard to find a properly decentralized protocol
A lot are too centralized
Even harder to find ones without terrible design decisions
Youāre safe until a left tail risk event happens and thereās historical precedent that it has happened multiple times.
Yet no plan against it
šØ TRC20 based USDT smart contract breaks with safeTransfer - here's why your DeFi protocol on tron might be vulnerable
At @QuillAudits_AI, in our recent audit, we found this vulnerability and thought of sharing it, so it might be helpful š¤
TRC20 based USDT contract doesn'tā¦
Recently Iāve been learning how to write reports. Iāve had my reports marked invalid even though they were valid.
Kind of figured out that I have to break it down like Iām explaining to a 5 year old.
The way you see the protocol may be different from the judges eyes
I think the best of codes onchain have smaller NSLOC.
Too many lines of codes introduces lots of complexity.
Which forces the protocol to make terrible design decisions.
<24h to go full @jessepollak mode for our mini-app.
->Start with the home-page tutorial then
->Swipe HOT/NOT
->Earn HOTS
->Lock a +0.1Ć streak for activity
Link to our mini-appš
Keep It Simple.
No need for complex routines.
No shiny hack.
Doing the stuff that moves the needle daily is what gets you better.
- Auditing daily
- Read reports from previous contest.
- Learn your mistakes and never repeat them.
Rinse and Repeat.
Met a giga chad @turvec_dev yesterday. Got in contact with him on X about a year ago.
Coincidentally we both work @QuillAudits_AI X @QuillAI_Network
Top Auditor.
One of the folks in this space that I looked up to when I began learning.
Lots of Alphas unpacked. Time to build
Alt season = audit season, but:
Rushed audits become the norm. Teams want to launch while the hype is hot, so they:
⢠Compress 4-weeks audits into 2-3 weeks.
⢠Skip follow-up reviews after code changes.
More demand + time pressure = corner cutting.
We're about to see aā¦
22 Followers 1 FollowingPort Harcourtās go-to tech hub & creative studio. Learn, create, co-work, grow. š Book a space or join a class below #InSpacePH
76 Followers 261 FollowingCybersecurity researcher ā on a 1001-day mission to go full-time in Web3 & cryptography.
Smart-contract security, bug bounties & ZK.
263 Followers 2K FollowingOn the path to becoming a cybersecurity expert. Currently building skills in penetration testing and auditing smart contracts.
844 Followers 38 FollowingWe are here to serve as your go-to solution for secure, launch-ready protocols. An audit firm with a difference. DM for private audits.
211 Followers 584 FollowingEx Web3 Intern @_learnable 22 | Ex Ambassador @calyptus_web3 | Member @base @baseafricaa - @superteamNG Enugu | FE Dev - SR & Web3 Dev Student @cyfrinupdraft
3K Followers 316 FollowingBug bounty wizard - All Stars @immunefi. I cast Exorcise on vulnerabilities and Heal on protocols. Prevented exploits worth over $150M.
69K Followers 804 FollowingFounder of @rotkiappš¦, the portfolio tracker that protects your privacy.
#Berlin. University of Tokyo graduate. Marathon runner. #ethereum developer. #birding
4K Followers 3K FollowingDelivering privacy for @Ethereum. Team lead of @PrivacyEthereum at @EthereumFndn. Always under construction, thanks for your patience šļø
8K Followers 78 FollowingSwarming adversarial AI agents delivering AGI-grade security for Web3 & AI systems || Building the trust layer for the open agentic web.