Check out this article—it provides a great explanation of Raydium’s constant product market maker (CPMM) and OpenBook. These are two of the most important DeFi applications on @solana 🦀:
extremelysunnyyk.medium.com/solana-amm-und…
Procrastinate often? Work 10 hours a day for just one week you’ll start loving the grind more than the delay. Why procrastinate when you can wake up proud every day?
1/
Bookmark this. One of the most important lessons in security research:
Spotting the root cause is not enough.
You must also understand the intent and impact.
Let me walk you through a TWAP bug example that could’ve been easily misunderstood.
🧵
I'm going to explain this important topic in this thread to make sure everyone can benefit from this guide.
All the security checks done by Anchor are handled through constraints, which inject the common operations at runtime.
You can read the docs here: docs.rs/anchor-lang/la…
I'm going to explain this important topic in this thread to make sure everyone can benefit from this guide.
All the security checks done by Anchor are handled through constraints, which inject the common operations at runtime.
You can read the docs here: docs.rs/anchor-lang/la…
Sensei @0xcastle_chain , master of Solana 🙏, may I ask you this in public so we all can benefit.
Is there any checklist anywhere of safety-checks/procedures that Anchor handles for you?
Like resetting account data to 0 when closing an account etc
Ever been so obsessed with some ideas that you had to write them down to see what's produced? Well, that's my latest insight-baby. It's a bit long, but i believe it should be quite good! I hope it'll help you find more bugs (and write good specs!), anon! justdravee.github.io/posts/the-3-pr…
I just realized that @osec_io has 115 public Solana security reports.🫡
I believe that one of the best ways to learn security is by reading past reports and learning from them. Here is a valuable resource—don’t let it die in your bookmarks:😄
ottersec.notion.site/Sampled-Public…
Early on in your auditing journey?
We created a new learning resource: Buggy ERC-20s
Buggy ERC-20s is a repo of 20 (yes that is intentional) ERC-20 contract implementations, but with a bug.
As much as possible, we tried to make these bugs reflect the kind of mistakes…
If you write a lot of tests in Foundry, you'll find this plugin very useful!
It helps to read console logs in a more comfortable way. Especially if a function has a lot of calls in it
Thanks to @eth_fullstack for developing it!
Link to try out the plugin below ⬇️
ANNOUNCING: FOUNDRY v1.0!
Every major DeFi protocol and smart contract developer who wants secure and gas-efficient code uses Foundry.
Today, Foundry is officially stable, and here for the long run.
Congratulations to everyone on today's huge milestone.
`foundryup`!
A lot of…
Whenever I need a refresher on a topic, I search for @MixBytes and usually find exactly what I'm looking for.
Today, for instance, I was researching yield aggregators:
mixbytes.io/blog/yield-agg…
boom
All kinds of attack vectors listed here as missing input validation, unsafe casts, price manipulations, weak RNG, unset initialization flags and more
Another year another great auditor's rewind blogposts, long but a must-read 🫡
hubs.li/Q035bKpS0
A 5 minutes read alpha:
You came across a code that utilises a specific EIP, you don't know about it
Go into: eip.directory
Search about that EIP:
Make sure to actually understand the EIP and go to other referred EIPs when needed
Understood it?, good.
Now go to…
Whenever I find a bug, I look back and ask: How could I have found that faster? I go back, figure out which steps of thought were necessary, and retrain myself to perform only those steps in 30 seconds.
Fooming Shoggoths - Thought That Faster open.spotify.com/track/4zhgRs1n…
If you've been thinking about trying Solana auditing but aren't sure where to start, my quick-start guide has you covered:
- A quick 10-mn read
- Packed with valuable resources to guide you further
- Focuses on the absolute basics to give you a clear idea
infect3d.xyz/blog/solana-qu…
The single most important advice for a new bug bounty hunter was dropped by infosec_us_team in the Immunefi discord:
"Rewire your brain so that instead of hunting for 'bugs' or 'mistakes', you hunt for a specific 'impact'..."
Your income will go way up because... 🧵 1/5
3K Followers 316 FollowingBug bounty wizard - All Stars @immunefi. I cast Exorcise on vulnerabilities and Heal on protocols. Prevented exploits worth over $150M.
2K Followers 1K Followingresearcher & dev
Head of Security at Monad Foundation @monad
Former Lead Security Researcher / Spearbit Core Team @SpearbitDAO.
6K Followers 11 FollowingSecurity audits, development, and research for ZKP, MPC, FHE, PQC, and more generally advanced cryptography. Contact us: [email protected]
501 Followers 0 FollowingWrite your first 1,000 lines of Rust with https://t.co/w50EcsJlD9 | We use AI to explain concepts and expert-crafted exercises for practice.
46 Followers 3 FollowingIlluminating your smart contract vulnerabilities when they are in the dark.
We provide fast, reliable audits today so you don't have to worry about tomorrow 月
42K Followers 40 FollowingDecentralized platform to bring your dream companion & fantasies to life in seconds
Discord: https://t.co/A2xlyekdaT
free gf/bf 👇🏼
3K Followers 1K FollowingCEO @asymmetric_re, Web3 Security Force Multiplier, Bug Hunter/Wrangler, FOSS Advocate, and Problem Solver. Simply walked to Mordor.
129K Followers 3K FollowingCEO of the Post-New Right.
Opposition Activist.
Chief of the Ethnonarcissism Police.
Subscribe to my s00bst4ck for the only correct take on identity
SATIRE
150K Followers 2K Following| Literary Critic at the Jacob Urowsky Center for Frogs Who Can't Read Good | @theammind @thebtcmag @FDRLST @im_1776 | Man I Love Frogs/Birds/Clouds|
90K Followers 1K Following"Science denialist" -Chelsea Clinton. “hardcore, almost clichée-type racist” - Aya Velázquez. indifferent to the suffering of the out-group. cry more.
No recent Favorites. New Favorites will appear here.