Soner

199 posts

Soner banner
Soner

Soner

@sonrcol

backend engineer — automation addict

Toronto Beigetreten Temmuz 2010
38 Folgt276 Follower
Soner
Soner@sonrcol·
@LilFatFrank @loyal_hq This is the kind of a vulnerability that could burry the whole business. Hopefully you did get a nice reward.
English
0
0
0
48
karan
karan@LilFatFrank·
TL;DR: I found a critical bug on Loyal [@loyal_hq] that let anyone drain any user's private balance using only their public address. I reported it privately, the Loyal team fixed it within days. Loyal is a privacy protocol on Solana: you deposit funds into a shielded balance that stays private and earns yield, and you can send it to others privately. It's Telegram-first. I was exploring the Loyal protocol for a possible integration into Swish. I didn't set out to find a bug. I was solving a UX problem. When you shield through Loyal with an external wallet like Phantom, the wallet warns "this transaction may fail, funds may be lost." It's a false alarm. Loyal relies on MagicBlock's delegation, which wallet simulators can't model but a warning like that loses users, so we set out to remove it. The approach was to let the server handle the steps that trigger the warning, while the user's wallet only signs the parts it can simulate cleanly. To do that safely, I had to map exactly which of Loyal's actions required the owner's signature and which didn't. That audit is what surfaced the bug. The instruction that moves a shielded balance didn't require the owner's signature. It only checked that the owner's address was listed in the transaction, and an address is public information. In practice, anyone could move someone else's shielded balance to themselves using only the victim's public address, with no permission from the owner. That affected every shielded balance on the protocol. I confirmed it with a minimal test moving ~$0.10 between two of our own wallets and returning it which was enough to verify the issue was real, nothing more. I didn't publish it. I reported it privately to the Loyal team the same day, with the root cause, a reproduction, and the fix needed. The Loyal team fixed it within days: transfers now require the owner's signature. I re-ran our test against the patched contract, and it was rejected for a missing owner signature. Confirmed resolved. Super glad it's resolved, and credit to the Loyal team for the quick turnaround.
English
27
9
137
14.4K
Soner
Soner@sonrcol·
@absolodev @github They have changed the pricing model not the actual prices. Before it was $40 for roughly a billion tokens when utilized with high end models but now it’s more like 100k tokens for the same price.
English
0
0
0
11
ABSOLO
ABSOLO@absolodev·
@sonrcol @github What pricing? It has same pricing, with worse model catalog, based on how pricing works, it’s 40 dollar or just gift us 10 dollar situation, because 10 dollar plan seems more like joke.
English
1
0
0
14
GitHub
GitHub@github·
The GitHub Copilot app is now generally available. 🙌 The new home base for your work. Pick up what's next, direct agents in parallel, and land your PRs, all in one place. ⬇️ github.blog/changelog/2026…
English
79
144
879
185.8K
Tibo
Tibo@thsottiaux·
What do you use
English
240
7
375
103.7K
Soner
Soner@sonrcol·
@RockstarGames I hate that I have to experience this on console instead of pc 😭😭
English
0
0
0
1.3K
Rockstar Games
Rockstar Games@RockstarGames·
Pre-orders for Grand Theft Auto VI will officially begin on June 25 on digital storefronts and at other select retailers. Check out the official cover art, also available as downloadable artwork at rockstargames.com/VI
English
19.9K
106.1K
585.5K
77.4M
Soner
Soner@sonrcol·
@suni_code They have their own model now
English
0
0
0
13
Soner
Soner@sonrcol·
I was able to use @cursor_ai waaay beyond my limits for the last couple of days, even after hitting 100% for both Composer and API. Today, I saw the glorious limit reached modal for the first time🥹
Soner tweet media
English
0
0
0
40
Edd Coates | Game UI Database 2.0
I am so fucking sick of my website getting scraped. Millions of requests per minute, somehow designed to bypass all my security rules, choking the site until it completely stops loading. If I were paying for bandwidth, it would cost me a fortune. How is this still legal?
Edd Coates | Game UI Database 2.0 tweet media
English
489
61
2.1K
408.2K
Soner
Soner@sonrcol·
@thsottiaux could you please kindly remove the 5 hour limit nonsense??
English
0
0
0
7
Soner
Soner@sonrcol·
@SmilingKylan @pcoronaf @amazon Nope they bcc bunch of addresses and send mail to literally “undisclosed-recipients;” mail protocol itself is a scam for still allowing this.
English
0
0
0
17
Kylan Hurt | smilingkylan.eth
Kylan Hurt | smilingkylan.eth@SmilingKylan·
@pcoronaf @amazon (No recipient) must be the literal display name they use. I’m a software engineer and I could be tricked like this. Normies stand no chance
English
1
0
5
1.8K
Pablo Corona Fraga
Pablo Corona Fraga@pcoronaf·
Este phishing está interesnate. Usan una direción @amazon.com
Pablo Corona Fraga tweet media
Español
88
221
2.2K
745.9K
Soner
Soner@sonrcol·
@BaldKnower If you lend 15k in sol he owns 15k in sol. If you lend 75 sol he owns 75 sol. Pretty simple tbh.
English
0
0
0
8
Bald Knower 🧑🏼‍🦲
Bald Knower 🧑🏼‍🦲@BaldKnower·
i lent my friend 15k in Solana (Solana was at 200 bucks and i sent him 75SOL) He's trying to square up with me and send me 75 solana today, but 75 solana is now worth 4875 am i wrong here that he owes 15k not 75 SOL?
English
2.1K
75
5.6K
1.8M
Soner
Soner@sonrcol·
@philz1337x It’s crazy how an individual can achieve such an amazing model. Respect!
English
0
0
0
206
philz1337x
philz1337x@philz1337x·
Crystal Upscaler can now turn any image into a 2GB PNG 😂
English
79
127
3K
647.7K
Soner
Soner@sonrcol·
@sideeyegg will soon have an iOS app for it’s 71 users 😭 meanwhile go try the desktop app, it’s awesome sideeye.gg
Soner tweet media
English
0
1
1
23
Soner
Soner@sonrcol·
@synthwavedd It’s not your intellectual property, why did you watermarked it leo 😭😭
English
0
0
1
323
leo 🐾
leo 🐾@synthwavedd·
GPT-5.6 is exceptionally good at replicating designs from an image in code. This is a 0-shot SVG output (!) from 5.6, with a 1-sentence prompt and no tools, alongside an image of an Xbox One controller. 🔥
leo 🐾 tweet media
English
68
20
819
194.5K
Soner
Soner@sonrcol·
@ritu_twts First? Oh damn, it was Pawno for me. I step into coding with gta samp servers
English
0
0
1
65
Reethu
Reethu@ritu_twts·
What was your first code editor?
Reethu tweet media
English
360
9
309
29.1K
Marc Lou
Marc Lou@marclou·
AI is so good at backend, but so bad at UI/UX. Any recent models one-shot my new features, but I'd have to spend another 10+ prompts to get the design right.
English
487
50
1.5K
137.7K