Just found some very handy tools for the everyday EVM dev
Decoding, hashing, bit manipulation, merkle trees, wallet/signatures EIPs, Uniswap hooks and more - a bit of everything, make sure to add it to your toolbelt🫡
evmtools.xyz
I've been in crypto for over 10 years and I’ve Never been hacked. Perfect OpSec record.
Yesterday, my wallet was drained by a malicious @cursor_ai extension for the first time.
If it can happen to me, it can happen to you. Here’s a full breakdown. 🧵👇
.@SuperRare’s staking contract (v1) on #Ethereum was exploited, with the root cause traced to a flawed updateMerkleRoot function—key validation checks were incorrectly inverted. As a result, instead of restricting updates to privileged accounts (e.g., the owner), any account…
hey @Uniswap v4 devs — OpenZeppelin Uniswap Hooks Contracts v1.1 is here 🦄
MEV protection, limit orders, Just-In-Time penalties, and a series of improvements to existing hooks deliver everything you need to build advanced Uniswap v4 pools.
Here’s what’s new in this release 👇
Introducing: Rarible NFT MCP Server
Built for AI agents, Web3 builders, and power users.
You can now query the Rarible Protocol using Model Context Protocol (MCP)—a fast, type-safe way to plug into NFT infrastructure using LLMs like Claude, Cursor, and more.
🧵「 1/8 」
Step up your DeFi development skills with Aave V3 Protocol Development on Updraft 🌟🚀
@ProgrammerSmart teaches you how to work with Aave V3.
Learn:
- Aave’s core functionality
- Reserves, tokens, liquidity
- Aave flash loans
And build a functional app!
Start learning today…
New blog post is up in the Uniswap V3 Series:
getSqrtRatioAtTick() Deepdive
Hefty math algorithms are hard to explain; it took us a while to make something so complex-looking feel so simple.
Researchers looking to audit math-heavy code will get a lot of inspiration from this…
We @VennBuild just discovered a critical backdoor on thousands of smart contracts leaving over $10,000,000 at risk for months
Along with the help of security researchers @dedaub@pcaversaccio, the seals team @SEAL_911 and others, we managed to rescue the majority of funds…
This is the biggest ERC4626 checklist that I've ever seen. More than 350 direct vulnerabilities, many pitfalls, integration errors and more.
Every security researcher should know these and it can easily be fed into AI. Great work @DevDacian 🫡
github.com/devdacian/ai-a…
GOLDEN RESOURCE ALERT🥇
I've noticed many Solana-based projects having lower security hygiene than EVM-based ones. This must change.
Developers & security researchers - read this. Lots of Solana/Rust-specific vulnerabilities listed here, 10x @0xIchigo🫡
helius.dev/blog/a-hitchhi…
BLS signatures are everywhere, from Ethereum’s consensus to EigenLayer. But it’s easy to use them wrong.
What are BLS signatures? Let’s talk about the right way and the wrong way to use them:
Our analysis shows that the @meta_pool staking contract has a critical bug that allows for free mint of mpETH.
This specific tx freely mints 9700+ mpETH ($27m), but the low-liquidity of mpETH limits the profit to ~10 ETH.
Our analysis shows that the @meta_pool staking contract has a critical bug that allows for free mint of mpETH.
This specific tx freely mints 9700+ mpETH ($27m), but the low-liquidity of mpETH limits the profit to ~10 ETH. https://t.co/IE9p8UEMXP
𝗘𝘁𝗵𝗲𝗿𝗲𝘂𝗺 𝗧𝗵𝗲𝘀𝗶𝘀 — Root Chain for the World Computer
We invest in, build on and love Ethereum ❤️ — since 2014.
cyber.fund/content/eth
Here we share our conviction & discuss:
‣ Ethereum's state
‣ Rollup-centric future
‣ L1 & DA moats
‣ ETH value accrual
🧵
New on Updraft: @CiaraNightingal’s Fundamentals of Zero-Knowledge Proofs (ZKPs) 🌟🚀
A high-level, 1 hr course to help you understand ZK protocols and apps.
Discover
- What ZKPs are and their requirements
- Interactive vs non-interactive ZKPs
- ZK terminology
And more!
👇
Cetus AMM on the @SuiNetwork has suffered a catastrophic ~$200M hack🚨
Root cause: an arithmetic overflow in the liquidity calculation that allowed an attacker to withdraw astronomical amounts of tokens from a small liquidity position.
How did they pull this off? 🧵
Ugh I wish someone would make a video on incremental Merkle trees🤔
I was trying to understand how @zksync, Tornado Cash and other fun ZK stuff worked and it’s just so flipping confusing
Oh wait a minute! I just made one 😁
INCREMENTAL MERKLE TREES EXPLAINED!!! 🌳🩷
Now that EIP7702 is live, I think it is time to retire Permit2, as it provides nothing that EIP7702 doesn't, and it is an added security risk.
What is Permit2?
Before Permit2, there was Permit: a method to grant token approvals using gasless signatures.
Permit improved UX for…
3 Followers 170 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/1zhiPhlHUe
1K Followers 6K FollowingOPEN TO WORK!!!
Long life Fullstack Developer👨💻
•Builder for @Bridge23ai (AI Agent) Pre-seed Stage
•Solana Dev talent part by @solanaturbine
•remote working
550 Followers 812 Followingsmart contract and web security researcher/engineer. bug hunting @spearbit and @cantinaxyz. available for solo audits. prev: @makerdao
209 Followers 762 FollowingI'm glad you can check out my homepage. I like making new friends. I hope to make more new friends during this period of using X
52K Followers 0 FollowingThe EF is a non-profit that supports Ethereum. We work alongside the wider ecosystem to improve the protocol, grow our community, and advocate for Ethereum.
566 Followers 284 FollowingSecurity Researcher since 2022 | Over 60 audits conducted | Member of @PashovAuditGrp | Book an audit, Telegram: https://t.co/mUCi0cJFDJ
143K Followers 2K FollowingWeb3 Identity for Everyone. Start your .SOL obsession @ https://t.co/1xMYzfaNK1 | Build with us @ https://t.co/cYLr12NHAs | Join the .sol family @ https://t.co/vnxiDNuB8U
36K Followers 2K FollowingAccelerating the world's transition to a cybernetic economy. Member of Lido DAO with Mission to Keep Blockchains Decentralised
8K Followers 333 FollowingA dev conf on anything Ethereum, DeFi, NFT, EVM, decentralization and community projects such as Yearn. April 28-29, 2025. tg: https://t.co/Z2u2nBtIMc
12K Followers 29 FollowingPrivacy Stewards of Ethereum (PSE) is a research and development team building free resources to expand the world of programmable cryptography.
2K Followers 1 Followingbountyhunt3rz: LIFE ON THE BLOCKCHAIN
We interview the top bounty hunters in crypto to discover their secrets to finding live bugs and making millions
4K Followers 215 FollowingWeb3/Web2 Security Company. Trusted by Dinero, Multipli, Ambire, Ion, IPOR, Colb, Pear, Kanpai, Hana & many more. Book an audit: https://t.co/Jf6SO3wlMP
550 Followers 812 Followingsmart contract and web security researcher/engineer. bug hunting @spearbit and @cantinaxyz. available for solo audits. prev: @makerdao
713 Followers 1 FollowingEVM CTF Platform by @bobface16 . Elevate your skills, compete against other enthusiasts, and join a community of passionate security researchers.
135K Followers 2K Following#TOKEN2049: The World’s Largest Crypto Event. We bring together the leading voices in crypto.
🌏 Singapore: 1-2 October 2025
🌍 Dubai: 29-30 April 2026
2K Followers 1K Followingresearcher & dev
Head of Security at Monad Foundation @monad
Former Lead Security Researcher / Spearbit Core Team @SpearbitDAO.
5K Followers 4K FollowingSemi-tokenized. In it for the tech and all-you-can-drink conferences.
@LidoFinance | @daedalus_angels | @laptop_friendly
Pleb @10b57e6da0 | @smoldapp
141K Followers 195 Following$MOEW, a memecoin turned into an AI agent @MOEW_Agent, created by @BitgetWallet, multi-chain (BASE: 0x15ac90165f8b45a80534228bdcb124a011f62fee)