Kiki

992 posts

Kiki banner
Kiki

Kiki

@Kiki_developer

Independent Security Researcher | prev @GuardianAudits | $3B+ secured • 50+ audits • 15+ bounties

Portfolio & Contact → Beigetreten Temmuz 2022
324 Folgt3.1K Follower
Angehefteter Tweet
Kiki
Kiki@Kiki_developer·
There are tier 1 auditing firms, then there are tier 1 mediation teams. Thank you @immunefi 🙏
Kiki tweet media
English
15
10
174
13.3K
Cyba Blockchain Security
Cyba Blockchain Security@CybaSecurity·
Just kicked off a new audit for an extension to a complex DeFi strategy system. Good protocols don't treat audits as a one-time checkbox. Every production change deserves a security review. From first contact to audit kickoff: < 24h. Security doesn't end after the first audit.
English
1
2
7
592
sorryNotsorry
sorryNotsorry@0xSorryNotSorry·
Man this feels awesome
sorryNotsorry tweet media
English
31
3
188
3.6K
Kiki
Kiki@Kiki_developer·
@abarbatei Gold indeed! Thanks for sharing these
English
1
0
1
112
Kiki
Kiki@Kiki_developer·
If you deployed or are deploying on @megaeth dm me
English
1
1
8
812
Kiki
Kiki@Kiki_developer·
@cicada_HQ Great points, appreciate the insight!
English
0
0
0
14
cicada
cicada@cicada_HQ·
@Kiki_developer Blockchain-level attacks are rarer because they require deep consensus or networking flaws, but when they happen, the impact is catastrophic. That’s why the bounties are high and the defenses are so layered.
English
1
0
1
36
Kiki
Kiki@Kiki_developer·
Seeing all of the blockchain/dlt bounty awards posted makes me think two things. 1. I really should expand beyond smart contract level security 2. How have there not been more blockchain level hacks?
English
3
0
29
2K
Kiki
Kiki@Kiki_developer·
@kamensec I was planning on making this same poll haha
English
0
0
1
224
kamensec
kamensec@kamensec·
How much should you pay an intern? Assume: 1. Just started few months ago 2. Can code a little but not great 3. Has done 50% of ethernaut 4. No major contest placements
English
6
0
13
1.7K
Kiki
Kiki@Kiki_developer·
Maybe I’m out of the loop but what’s wrong with an unpaid internship? And how many better options are there? - Contest are scarce and I don’t see that trend changing. - bounties can be a headache for those that are successful let alone people that are just starting out. - Contracting gigs without a network or portfolio are few and far between. Obviously if you can make any of the above three work then it’s a no brainer go do that. But if I started my career in 2026 instead of 2022 I would strongly consider an internship. The value of working through the entire lifecycle of an audit, learning from experienced auditors, building up a portfolio isn’t worthless. It’s actually pretty valuable
English
5
0
33
2.4K
Kiki
Kiki@Kiki_developer·
Excited to see a great friend and an amazing auditor start his own firm! Truly @abarbatei is one of the most thorough auditors I’ve worked with!
Cyba Blockchain Security@CybaSecurity

1/3 Cyba Blockchain Security is now live. Cyba (pronounced sai-ba) is a researcher-led blockchain security firm focused on manual audits, deep protocol reviews and practical security research. Founded by @abarbatei, with 10+ years of security experience across Web2 and Web3. cybasecurity.io

English
1
0
12
874
Kiki
Kiki@Kiki_developer·
@mylifechangefa1 Just a medium. Not the best payout ever but best experience 😄
English
0
0
1
49
Kiki
Kiki@Kiki_developer·
This was the best bounty experience I’ve ever had. Not only were they quick to fix the issue and had no issue offering a very fair resolution But they were ultra responsive. Sending consistent updates on where they were at on their end and proactive in resolving any bottlenecks! The complete opposite of some other protocols I’ve dealt with where at best resolving your report is not a priority, and at worst they are actively trying to get out of resolving the report. The ones that make security a priority like the one here I’ll 100% come back to their bounty program again and again and again
Kiki@Kiki_developer

I just found a bug and got paid on @immunefi #immunefitribe immunefi.com/s/ss/?severity…

English
4
4
48
6K
Kiki
Kiki@Kiki_developer·
@abarbatei @0xMackenzieM Hmm that’s a good question I try and air on the side of caution and just not name names regardless of good or bad. But you are right this would definitely be on the “good” side of publicity for them
English
0
0
1
100
ABA
ABA@abarbatei·
@Kiki_developer can you name them? Like I get it for bad publicity, but this is very good publicity, why not? @0xMackenzieM any thoughts?
English
1
0
1
355
WhiteHatMage
WhiteHatMage@WhiteHatMage·
Here's what you can do to secure your old assets: Add a bonus on top of the expected bounty reward for them. In your token, or vested payments, or anything of value that incentivizes good actors to check those assets. You only pay for real issues.
English
3
0
30
1.5K