To whomever is on my feed: why not share a unique discovery made from public / private audits instead of X audits done and $Y made?
Best kind of sharing is knowledge; it's power, spread it around!
This is the MOST ALPHA research paper about smart contract security EVER. 🧵
THEORY: They examined 516 smart contract security bugs & exploits.
FACTS: They applied the THEORY in @code4rena contests & bug bounties and received a total prize of $102k 🤯
github.com/ZhangZhuoSJTU/…
Two of my audit reports for @GuardianAudits are now published
Take a look at my portfolio : (inspired from @gogoauditor )
github.com/chinmay-farkya…
DM for security audits 🫡
Fellow auditors, RT for better reach
1/22 Fact: Whitehats have received 70 MILLION+ dollars in bounties via @immunefi. The top whitehat has earned over $13 million in just 4 reports. To those of you who haven’t yet made much on Immunefi despite hearing about whitehats earning crazy payouts, this thread is for you.
Since the @optimismFND contest rewards were announced, a bunch of people have asked me about the logistics of working with @trust__90.
How did we share information? How did we support each other?
I've experimented with this a lot so figured it might be useful to share publicly.
One of the hardest things for new auditors is getting your head around a code base.
I remember feeling like I was aimlessly jumping in circles. Based on the DMs I've been getting, seems like this is a common experience.
Here's the process I now use for every audit...
Learn more about Spearbit's SEAL 🦭initiative, a collaboration with @0xRajeev@TheSecureum, aimed at upskilling security researchers through challenging security reviews! youtu.be/VhUUUN8Z-jw
1/ Are you a Security Researcher intimidated by the rapidly changing Ethereum security landscape? Fear not!
Here are seven things you should know about SEAL, a Spearbit initiative to upskill JSRs through guided audits led by experienced Lead Security Researchers
if you want to create web3 security content, instead of creating the hundredth auditor roadmap, auditing tips that are just common knowledge, or spot the bug challenge content, try this instead: create cheat sheets for protocols you audited 1/7
A comprehensive resource covering most gas optimisations in solidity.
This will come in really handy when making those gas reports for C4.
hackmd.io/@DlM5Hmp7QSqUc…
1/6 🚀NinjAudit Launch🚀
We are happy to announce the launch of NinjAudit
✅Our Features
🕵️♂️Top Auditors👉2/n
🏃♂️Competitive System👉3/n
📜“Proof of Audit”👉4/n
for Clients
0% of Network Fee as a campaign👉5/n
for Auditors
You can join as an auditor👉6/n
ninjaudit.com
There are some extremely successful bounty hunters in web3.
However, nobody tells you how they do it.
Until now.
Here is how you can become a bug bounty millionaire.
🧵👇
Scammers are becoming more clever. I'm starting to see a new type of scam where it appears that YOUR address is selling NFTs to someone else.
Here's how the scam works, the 23 lines of code to replicate it, and how to differentiate between fake and legit sales 🧵:
I’ve trying to read audit reports lately, so I compiled this list of MY TOP 10 public audit repositories by notable audit companies.🧵
In the next 2 months, I will read ALL their public reports 👇
Want to share the journey with me? Retweet this post, and let's do it together. 🫡
1K Followers 2K FollowingSecurity Researcher Web2 and Web3.
Embracing the freedom of an undefined journey, where the absence of constraints unleashes limitless possibilities.
14K Followers 139 FollowingMaster smart contracts to ship world-class dApps.
Compete in challenges to earn rewards and build your on-chain resume.
Live on Aptos & Sui.
34K Followers 934 FollowingEngineering and research solutions, empowering developers & enterprises to build upon the decentralized web. Ethereum @NethermindEth Starknet @NethermindStark
1K Followers 859 FollowingSenior at @hexensio
Whitehat at @immunefi
Senior Watson at @sherlockdefi
Judge && Backstage Warden at @code4rena
Give me a DM if u need anything
16K Followers 15 FollowingSecurity reviews and research that keep winners winning. We apply unmatched hacking talent to secure critical software for the most innovative teams.
432 Followers 188 FollowingA decentralized community of security researchers, hackers, and enthusiasts with a shared goal to make #InfoSec and #Web3 Security solutions accessible.🛡️
20K Followers 1K FollowingCo-founder and CEO @Sablier. Open-source developer. I have a broad range of interests, including longevity, epistemology, physics, and psychology.
148 Followers 11 FollowingGet the security peace-of-mind you and your users deserve
🕵️ Ex-black-hats at your service
🤝 Incentivized security
🛡 Full stack protection
📈 Sec dashboards
89K Followers 404 FollowingSlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
558 Followers 142 Following• Web3 security researcher
• Dev and cybersec consultant
Ex:
• Head of SC audits at Hacken
• Co-founder at Tabia (dev outsourcing)
17K Followers 1K FollowingSecuring web3 since 2020 | Over 400 audits conducted | Trusted by the largest protocols | Outperforming all competitors | Lead Auditor @bailsecurity
7K Followers 149 FollowingAjna is a peer to pool, oracleless, permissionless lending protocol with no governance, accepting both fungible and non fungible tokens as collateral.