holydevoti0n

383 posts

holydevoti0n banner
holydevoti0n

holydevoti0n

@HolyDevoti0n

humble security researcher

Beigetreten Ağustos 2023
587 Folgt1.3K Follower
Angehefteter Tweet
holydevoti0n
holydevoti0n@HolyDevoti0n·
Am I really doing it? I can't believe in a few months I could come this far. After my 1st 5 digits payout from @immunefi I managed to get 1st place in the CodeHaws @beanstalkmoney contest. Let's keep it up! 👨🏻‍💻
Cyfrin CodeHawks@CodeHawks

Awards have been announced for the Beanstalk Part 1 contest🤝 Top 5: 🥇 @HolyDevoti0n - $24,148.11 🥈 @golanger85 - $21,798.57 🥉 @0xInAllHonesty - $18,274.25 🏅 @0xbeastboy - $11,825.65 🏅 @ZealynxSecurity - $8,223.41 (1/2)

English
19
3
161
17.4K
holydevoti0n
holydevoti0n@HolyDevoti0n·
Hard work pays off. Keep pushing! 🫡
holydevoti0n tweet media
English
18
0
66
2.4K
holydevoti0n
holydevoti0n@HolyDevoti0n·
@hrkrshnn The autonomous bug hunter is as good as the ruggditional pot, a very positive contribution to the space. 🫡
English
0
0
3
281
Hari
Hari@hrkrshnn·
Our autonomous bug hunter has already saved 11 figures' worth of funds at risk.
English
16
6
66
24.7K
Joe Dakwa
Joe Dakwa@golanger85·
Let’s go brother. Here’s to 2026.
English
1
0
1
182
holydevoti0n
holydevoti0n@HolyDevoti0n·
@m4rio_eth Agreed. What's most disappointing is taking a closer look at the BBP policies on these(not all) platforms. Few of them(well-known) effectively back scam behavior, i.e: project can fix the issue, avoid pay, close the report, and remain on the platform.
English
1
0
4
363
m4rio
m4rio@m4rio_eth·
In the last couple of weeks, I’ve been doing a bit of bug hunting in my free time. I decided it was time to get back into hunting mode for a while and wanted to see how much the experience had changed after a few years. TL;DR 1: Most projects are cooked, and unfortunately their users will suffer. TL;DR 2: Some of the bug bounty platforms are not bounty platforms. The overall experience of bug hunting is deeply flawed and broken. Projects: Most bounties opened by projects are just marketing schemes and used In the rare case that someone actually discovers a critical issue that could drain the entire protocol at the current block, but anything even slightly theoretical gets immediately closed by most projects. They simply don’t care. Platforms: The hunter experience is horrific on most platforms. Projects just list random code; it’s often unclear what is actually in scope, and the researcher has to spend a huge amount of time just setting up the codebase to start hunting. Sometimes you don’t even know whether your issue is being reviewed, no updates, no communication, nothing. Some anti-spam filters are also flawed. One idea I actually liked is charging me USDC to submit, because I’m not submitting issues just for fun, and if it ends up being closed for legit reasons, I’m okay with not getting the deposit back. On one platform, I was banned because some of my issues were considered either out of scope or “not an issue” by the project. Overall, bad experience but I did enjoyed a bit hunting on 2 platforms out of 6, but the problem with those is that they don’t have that many bounties but hope they will catch up.
English
8
7
72
7.2K
holydevoti0n
holydevoti0n@HolyDevoti0n·
@emerjux Amazing! Glad to hear it helped ser 🫡
English
0
0
1
18
Joe Dakwa
Joe Dakwa@golanger85·
Good tip sir 🥂
English
1
1
2
183
holydevoti0n
holydevoti0n@HolyDevoti0n·
@0xkbb u welcome ser, glad to help 🫡
English
0
0
1
56
kb
kb@0xkbb·
@HolyDevoti0n Thanks a lot for sharing, this will save us a lot of time on figuring what the codebase is really about
English
1
0
1
56
holydevoti0n
holydevoti0n@HolyDevoti0n·
@jaskaranan Yup. They complement each other. This one is focused on docs on a higher level with the option to interact with it.
English
0
0
1
38
Jaskaran Singh
Jaskaran Singh@jaskaranan·
@HolyDevoti0n ever heard of tools like solidity metrics, slither, aderyn? all of em give flowcharts and userflows similar to this
English
1
0
0
14
holydevoti0n
holydevoti0n@HolyDevoti0n·
@quirksham right? we used it a lot in the old days... 😄
English
1
0
1
337
quirksha
quirksha@quirksham·
@HolyDevoti0n That chart is really familiar for me and you bro 😂😂 Saved for future use 💎💎
English
1
0
1
421
holydevoti0n
holydevoti0n@HolyDevoti0n·
@Hcrlen @henc I'd say it is only recommended to understand the big picture(before you start doing a deep dive). Anything beyond this may cause you to waste time and trigger AI hallucination.
English
0
0
1
308
0xch
0xch@Hcrlen·
@HolyDevoti0n i found it few days ago, help me with aave v3 deep dive, but how often the ai hallucinate
English
1
0
2
354
kaden.eth
kaden.eth@0xKaden·
✨2025 has been my best year yet✨ some numbers: - 3 bounties - 4 articles - 39 audits - 25 with @spearbit / @cantinaxyz - 2 with @zenith256 - 12 solo
English
6
0
145
5K