Revofusion

327 posts

Revofusion banner
Revofusion

Revofusion

@revofusion

DLT & ZK Audits @MoonAISec | Building @luminexio | Rust+C+Solidity proofs with autoformalization

Beigetreten Ağustos 2021
525 Folgt1.9K Follower
Angehefteter Tweet
Revofusion
Revofusion@revofusion·
My latest CVE bounty hit Ethereum, Solana, Sui, Polkadot and more at the same time. can't say much yet, will share details soon 👀
English
3
0
18
1K
Zero Cipher
Zero Cipher@zerocipher002·
After doing extensive Bug Bounty and interacting with dozens of protocols. In the Infra Space among the major blockchains, I believe only these protocols (currently) actually care about security: 1. Solana 2. Ethereum 3. Monad 4. Sei Most of the other blockchains don't care about either security or respecting whitehats.
English
11
1
75
2.8K
Revofusion retweetet
Aalok Thakkar
Aalok Thakkar@AalokDThakkar·
Using Lean 4 to identify contradictions in laws. Very exciting work by Pramaana Labs pramaanalabs.ai. They have build a DSL called LegalLean to formalise US tax codes.
Aalok Thakkar tweet media
English
17
64
497
30.1K
Revofusion retweetet
Immunefi
Immunefi@immunefi·
Security researcher @revofusion just earned $50,000 for a High vulnerability. Their highest win ever...so far. Pledge $IMU to revo here - whoever does will be the first: immunefi.com/pledge/revofus…
Immunefi tweet media
English
7
11
179
6.4K
Revofusion
Revofusion@revofusion·
@trentdotsol I think thats a fair position to take, atleast you guys state it out of scope clearly!
English
0
0
0
21
trent.sol
trent.sol@trentdotsol·
@revofusion if we were competent to write and maintain that logic, we wouldn't be using a dependency in the first place. how are we fit to verify and mitigate the claims? we're more likely to make the problem worse
English
1
0
1
52
trent.sol
trent.sol@trentdotsol·
i don't think i've reviewed a single pr this week. instead massive influx of slop ghsas
trent.sol@trentdotsol

@deanmlittle you should open a bug bounty program if you want to really feel pain

English
2
0
9
3K
Revofusion
Revofusion@revofusion·
@trentdotsol If it affects the execution of your program, does it matter if you wrote it? If you use a networking library and it has a bug that allows an attacker to take down every solana node, it just seems a little light to claim external
English
1
0
0
32
trent.sol
trent.sol@trentdotsol·
@revofusion why would we pay for bugs we did not write? how are we fit to triage the claims? report to upstream. let them do their job. we'll light them on fire if they fuck us with disclosure (has happened)
English
1
0
0
76
Revofusion
Revofusion@revofusion·
@TopengaNFT It was a High from EF (50K). Solana excludes dependencies under bug bounty (weird policy), and Sui was behind 150 points on hacken proof which my account didn’t have yet. For Polkadot, their bug bounty has been unresponsive, reported a month ago.
English
1
0
2
99
Topenga.eth
Topenga.eth@TopengaNFT·
@revofusion and did they categorize as critical or medium? read the report and from my perspective the blast radius is high. also what stopped you from reporting to the others?
English
1
0
0
68
Revofusion
Revofusion@revofusion·
My latest CVE bounty hit Ethereum, Solana, Sui, Polkadot and more at the same time. can't say much yet, will share details soon 👀
English
3
0
18
1K
Revofusion
Revofusion@revofusion·
@TopengaNFT Just primary company, which was Ethereum Foundation in this case
English
1
0
1
91
Topenga.eth
Topenga.eth@TopengaNFT·
@revofusion did you report as bugs to each or just to the dependency provider, my thought is most companies wont accept?
English
1
0
0
77
Revofusion retweetet
f4lc0n
f4lc0n@al_f4lc0n·
I Saved Injective's $500M. They Pay Me $50K. I like hunting bugs on @immunefi . I'm decent at it. - #1 — Attackathon | Stacks - #2 — Attackathon | Stacks II - #1 — Attackathon | XRPL Lending Protocol - 1 Critical and 1 High from bug bounties (not counting this one) Life was good. Then I found a Critical vulnerability in @injective . This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk. I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity. Then — silence. For 3 months. No follow up. No technical discussion. Nothing. A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either. I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten. I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible — until Injective pays what I deserve. Full Technical Report: github.com/injective-wall…
English
524
520
4.5K
1.8M
Sergey Golubev
Sergey Golubev@serge_golubev·
@revofusion Quite a coordinated strike across so many major protocols—hopefully this disclosure follows best practices for responsible security.
English
1
0
1
33
Tom Trevethan
Tom Trevethan@TTrevethan·
@sethforprivacy @bamskki If a dishonest (i.e. didn't securely delete a key share) SO and a previous owner collude, they can spend the UTXO without restriction, and timelocks are irrelevant.
English
6
4
45
13.1K
Revofusion
Revofusion@revofusion·
@bzogrammer atleast my hardness assumption doesn’t get absolutely massacred every time someone finds a new factoring paper on eprint
English
0
0
0
56
Charles Rosenbauer
Charles Rosenbauer@bzogrammer·
Aww, apparently elliptic curve groups are abelian and just reduce to obfuscated cyclic groups. That's disappointing. So elliptic curve crypto is really just RSA in disguise.
English
12
2
158
14K
Revofusion retweetet
Sigma Prime
Sigma Prime@sigp_io·
Lighthouse v8.1.1 (Scary Terry) is out! This is a mandatory upgrade for all users on prior versions due to a security fix. Please upgrade ASAP. Further details to follow. Also fixes VC head monitor timeouts, DataColumnsByRange duplicate bug, and a slow memory leak. github.com/sigp/lighthous…
English
1
17
47
5.9K
Revofusion
Revofusion@revofusion·
@iruletheworldmo @adonis_singh But it’s not really, GPT 5.3 feels much smarter Only Gemini feels comparable when it has its 5% consistently show of intelligence on deep think (rest of the time it hallucinates)
English
0
0
0
178
adi
adi@adonis_singh·
I still believe no one has trained a reasoning model with a base that's as strong as gpt-4.5
English
26
4
304
40.3K
Revofusion retweetet
Octane Security
Octane Security@octane_security·
1/ Octane’s AI found a high-severity liveness bug in the @Nethermind execution client that could have stopped local block production for 38% of @ethereum mainnet validators. This bug was patched via the @ethereumfndn bug bounty program, with no exploitation observed.
Octane Security tweet media
English
22
26
204
54.6K
nathaniel
nathaniel@0xmstore·
please don’t vibe code DLTs 🙏
English
2
0
4
212