nmirchev8

1.5K posts

nmirchev8 banner
nmirchev8

nmirchev8

@nmirchev8

Security Researcher | Co-founded @EgisSec - LSW in Sherlock | SR in @CertoraInc

EVM, SVM Beigetreten Haziran 2023
517 Folgt1.7K Follower
Angehefteter Tweet
nmirchev8
nmirchev8@nmirchev8·
Proud to win this one! We haven't previous stableswap math experience, but we always want to challenge us, so we can improve.
Code4rena@code4rena

🏆 The results of the Basin competitive audit are in! Congrats to everyone who submitted valid findings, especially to @EgisSec (@nmirchev8 and @dethSCA) for a landslide win in their second team showing! Respect to @basinexchange for their solid commitment to the highest security outcomes. Full list of winners in thread 👇

English
11
1
103
8.7K
nmirchev8
nmirchev8@nmirchev8·
Tempo chain just went live, so here are 3 things devs and auditors should watch for 👇
English
2
4
22
2.4K
nmirchev8
nmirchev8@nmirchev8·
State creation is significantly more expensive. Transfers to new addresses cost ~300k gas. Contract deployments cost 5-10x more than on Ethereum. Any griefing vector that forces your project's wallet to initialize new addresses or deploy contracts hits much harder here. Pay attention to those paths.
English
0
0
1
232
nmirchev8
nmirchev8@nmirchev8·
Gas is paid in stablecoins via a preference cascade. The protocol picks the fee token by checking these levels in order, stopping at the first match: 1. tx-level: explicit fee_token field on the transaction 2. account-level: fee payer's preference set via FeeManager 3. TIP-20 level: if you're calling transfer, transferWithMemo, or startReward on a USD-denominated TIP-20 stablecoin, that stablecoin automatically becomes the fee token 4. DEX level: if you're calling swapExactAmountIn or swapExactAmountOut on the Stablecoin DEX, the tokenIn argument is used as the fee token 5. pathUSD as the final fallback The gotcha: if no explicit preference is set and the user does a TIP-20 transfer, the protocol silently picks that same stablecoin for fees. They need enough balance for the transfer AND the max fee.
English
1
0
0
258
nmirchev8
nmirchev8@nmirchev8·
Just web3sec these days
nmirchev8 tweet media
English
2
1
10
740
samuraii77
samuraii77@s4muraii77·
speed of first bugs != actual speed. If your audit agents tells you 15 bugs and you have to verify them, that is not really faster for a complete audit, actually can be slower. You could use AI to understand codebases faster which can indeed speed things up, but that does not require a custom agent, a vanilla model will do.
English
2
0
1
83
samuraii77
samuraii77@s4muraii77·
@nmirchev8 what would be the reason of doing the second option except mostly for fun?
English
1
0
1
334
nmirchev8
nmirchev8@nmirchev8·
Once you wrote code Then you reviewed code Now you review the reviewers What's comming next, anon?
English
1
1
5
327
nmirchev8 retweetet
Plamen Tsanev
Plamen Tsanev@p_tsanev·
Imagine charging 4 figures for an "AI audit" with a dashboard. Anthropic themselves price the compute like an expensive dinner, not like a used car. Here is what a 25M token audit should cost: - ~$123 - 52 agents - 1,593 lines, full analysis. The gap shall close 🔜🔜🔜
Plamen Tsanev tweet media
English
2
3
27
2.3K
nmirchev8
nmirchev8@nmirchev8·
Bear market is great filter to all "lucrative" protocols During a bull, everyday you read about another opportunity, a new protocol with large investments... so it must be innovative and good However, in the bear you see who survives and where it is safe to stash cash long term
English
0
0
4
175
j3x
j3x@4mj3x·
I'm now officially an @OpenZeppelin Blockchain Security Researcher! 🥳 I've always respected the impact they had on blockchain security, and I can't wait to contribute to making the space safer for everyone!
English
78
0
480
10.6K
nmirchev8
nmirchev8@nmirchev8·
I got my bike stolen 5 mins with claude and I have a running cron job to send me telegram messages with new listings for bikes from the biggest local second hand website (which apparently don't have this feature) Now that's a good use of AI
English
1
1
13
661