Shred Security

40 posts

Shred Security banner
Shred Security

Shred Security

@ShredSecurity

Industry grade security audits for Blockchains and DeFi protocols | Rust, Go, Solidity and beyond | Helped secure @0xProbable, @RatehopperAI and more.

Global انضم Ağustos 2025
5 يتبع295 المتابعون
Shred Security
Shred Security@ShredSecurity·
Most DeFi protocols don't have an incident response plan. They have a group chat and a prayer. We built the Incident Response Checklist, a production-grade IR standard for Web3 protocols, covering: — Communication — Post-Mortem — Containment — Forensics — Recovery The #1 rule we outlined: Containment BEFORE detailed tweets, until losses are stopped. It’s Free, open-source, and built for real incidents. Star it. Fork it. Add it to your runbook. Your future self at 3am will thank you. Link in the comments below👇
English
1
2
7
1.1K
Shred Security
Shred Security@ShredSecurity·
Security is non-negotiable. Shred Security x @RatehopperAI RateHopper has reappeared pursuing one more elite-grade security review! Super excited to have them back as we keep offering strong protection for their expanding setup — a clear sign of our great client retention and ongoing collaboration to build securely. Their beta program is now live, learn more here: ratehopper.ai
Shred Security tweet media
English
0
0
6
860
Shred Security
Shred Security@ShredSecurity·
Thanks @nooz0x for participating. The issue here is: Using time(dot)Now().Unix() (local system time) in the permit precompile for deadline validation. This is non-deterministic across validators — due to slight clock drift, network latency, and propagation delays, different nodes can get slightly different values from time(dot)Now() when processing the same transaction in the same block. → Different state transitions on different nodes → different state roots → possible consensus failure. Recommendation / Fix: Replace time(dot)Now() with the deterministic block timestamp: block.Header.Time.Unix() (or equivalent chain context time).
English
0
0
2
179
Shred Security
Shred Security@ShredSecurity·
Challenge #4: Can you spot the bug in this code snippet?
Shred Security tweet media
English
2
2
6
1.1K
Shred Security
Shred Security@ShredSecurity·
Challenge #3: Can you spot the bug in this code snippet? Hint: It’s a deployment script, so expect the unexpected!🧐
Shred Security tweet media
English
4
0
5
1.3K
Shred Security
Shred Security@ShredSecurity·
Shoutout to @nooz0x for solving it correctly and thanks @0xalifweb3, @0xkun4l for participating. The root cause is silent precision loss/truncation on the scaling-down path. Major hacks due to rounding bug: Balancer ($128M) in 2025, zkLend ($9.5M) in 2025 etc. Fix: Implement safe rounding mechanisms in mathematical operations. You can find the next challenge here: x.com/ShredSecurity/…
English
1
0
4
222
Shred Security
Shred Security@ShredSecurity·
Challenge #2: Can you spot the bug in this code snippet?
Shred Security tweet media
English
4
1
14
1.2K
Shred Security
Shred Security@ShredSecurity·
Shoutout to @0xalifweb3, @0zpan, @nooz0x, @0xkun4l who have solved correctly. The root cause is user controlled PDA seed. It can cause PDA seed collisions -- DOS or account mixups. Fix is simple: Use unique seeds with users public key. You can find the next challenge here: x.com/shredscrt/stat…
English
0
1
5
291
Shred Security
Shred Security@ShredSecurity·
We’re launching a bug-hunting challenge series for EVM(in Solidity mainly), Solana and Blockchain related vulnerabilities. Challenge #1: Can you spot the bug in this code?
Shred Security tweet media
English
6
4
62
5.5K
Shred Security
Shred Security@ShredSecurity·
Back in November, we collaborated with @burraSec to audit the @PancakeSwap-backed project @0xProbable. A solid codebase with just 2 lows and bunch of informational findings.🫡 Report is in the first comment.
English
1
3
9
1.2K
Shred Security
Shred Security@ShredSecurity·
Our researchers just wrapped up another private audit 🔥 Report dropping soon 🚀 Salute to our brave Shredders for securing another protocol 🫡
English
1
1
15
973
Shred Security أُعيد تغريده
kenzo | shredsec.xyz
kenzo | shredsec.xyz@kenzowhitehat·
At @shredscrt, we're really passionate about fortifying protocols with our layered defense audit suite: AI scans, formal verification, fuzzing, and secure deployment. Secure your project end-to-end. Learn more at shredsec.xyz
kenzo | shredsec.xyz tweet media
English
7
2
21
3.1K
Shred Security
Shred Security@ShredSecurity·
Quick stats from the first 2 months of Shred Security 🚀
yashar@yashar0x

🧵/1 First 2 months of building @shredscrt, here’s what we shipped:👇 In 60 days, we: - Secured 5 protocols through private audits - Built the first-ever Protocol Deployment Checklist - Developed our in-house AI Security Auditor agent Still early, but the foundation is strong!

English
0
0
4
506