Here is your plan for the day, thank me later:
- Wake up and get a coffee
- Pump iron or run
- Read code for at least 4 hours
- Read 10 new findings
- Read code again for at least 4 hours
- Repeat every day
Audit competitions can be tough when you don't see results after dedicating so much time on it
It's in the name, you are competing against other people and it's hard to accept you lost
But along the way you got better and your efforts will payoff
Only 1 thing to say about it:
Kann Audits is expanding š
Weāre hiring a Business Development Manager to grow our client base and partnerships.
Requirements:
š¹ Experience in Web3 Business Development or Partnerships
š¹ Network across protocols, DAOs, or VCs
š¹ Ability to source and manage new clientā¦
1% daily improvement leads to 37x growth in a single year.
Don't fade compound growth - show up daily, pay the price, do the work. It's what I did so far and I will continue doing itš«”
1% daily improvement leads to 37x growth in a single year.
Don't fade compound growth - show up daily, pay the price, do the work. It's what I did so far and I will continue doing itš«”
Your goals as an auditor must be simple:
⢠Understand the project profoundly
⢠Find the critical functionalities
⢠Remember code āby heartā
⢠Research edge cases
⢠Break the codebase
⢠Learn meanwhile
⢠Track progress
⢠Repeat it
This is the art of Web3 Security
The fastest way to exploit the system is to know it by heart
Open the Notion and write your answers to these 4 questions:
1. What project does, step by step?
2. What are key functionalities, how it works?
3. Are there known bugs with this type of protocol?
4. What invariantsā¦
I placed 42nd with 3H 4M and 2L on RAAC contest @CodeHawks
So grateful for the opportunity @CodeHawks. This is my first ever payout that I have received.
āDonāt use a compiler, that will make you a bad engineerā
āDonāt use a framework, that will make you a bad engineerā
āDonāt use an AI, that will make you a bad engineerā
What would you do with $16,000,000?
Today, @usualmoney is announcing the largest bug bounty in the history of the world:
A $16,000,000 reward for discovering a single critical vulnerability in @usualmoney's codebase.
Hosted on Sherlock, in partnership with @NexusMutual.
In business, and life, there are only three things you can control:
- Your Actions
- Your Reactions
- Your Mindset
That's it. Nothing more.
So instead of whining about the things that are out of your control, focus your energy on what you can control:
Your:
- Attitude
-ā¦
šØ What are you doing after the contest results are out?
Are you just skimming through your missed findings, thinking:
š "I knew this! How did I miss it?"
š "That was so easy⦠Why didnāt I think of it?"
Simply reading your missed findings isn't enough. Youāll see what youā¦
1K Followers 682 FollowingWeb3 Security Researcher š§āš¬ @CodeHawks Eagle at @CyfrinAudits š¦ More than 100 H/M+ found š @DefendersAudits https://t.co/jhyLB8ujCO
5K Followers 991 FollowingJust a 6'6 feet curly hair guy looking into the code assuming that he'll find bugs. (And he doesš)
Auditor @Hashlock_ & Security Researcher @techfund_inc
2K Followers 1 Followingbountyhunt3rz: LIFE ON THE BLOCKCHAIN
We interview the top bounty hunters in crypto to discover their secrets to finding live bugs and making millions
2K Followers 2 FollowingZenith assembles auditors with proven track records to secure your project. We find the critical bugs nowāfreeing you to launch this weekānot next month.
81K Followers 177 FollowingAscendia is a sovereign Layer 1 blockchain for autonomous AI agents ā agents that think, act, and evolve on your terms. No gatekeepers. No black boxes.
5K Followers 245 FollowingJoin https://t.co/YR6oIDfjA9, the Leading Web3 Cybersecurity Community with exclusive bug bounties, innovative open-source tools, and endless opportunities to level up.