JohnnyTime 🤓🔥

9.8K posts

JohnnyTime 🤓🔥 banner
JohnnyTime 🤓🔥

JohnnyTime 🤓🔥

@RealJohnnyTime

Founder @ https://t.co/gcgrMm4Njh, JohnnyTime @ Youtube, Securing Web3 @ https://t.co/wJdpJyYcg0 & https://t.co/3d9aL8n5G8

Web3 Se unió Şubat 2012
1.4K Siguiendo12.6K Seguidores
Tweet fijado
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
Smart contract security pays WELL. 💰 Top auditors make $500K+ per year 💰 Bug bounties can 10x that 💰 Even “mid” auditors make six figures BUT… Only if you actually put in the work. No shortcuts here.
English
14
26
317
26.1K
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
How to steal millions in 4 steps: 1. Flash borrow 100k ETH 2. Dump on a DEX to crash price 3. Exploit a protocol reading that price 4. Repay loan, keep profit If step 3 fails, the loan never happened. Zero risk. smartcontractshacking.com/attacks/flash-…
English
4
3
43
2.5K
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
“Most expensive hacks” shouldn’t be consumed as shock content. Use it as prioritization data. During an audit, your real job is attention allocation: - where losses cluster - which assumptions fail repeatedly - what attack paths carry the highest downside
English
1
1
12
417
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
If your goal is to get sharp at exploits, stop sampling 20 techniques at once. Pick one technique. Study 10 incidents. Extract the repeated broken assumption. Pattern recognition beats trivia every time.
English
5
2
33
1.1K
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
Weekend Challenge #8: What issue would you submit if you saw this in an auditing context, Mr. Hacker?
JohnnyTime 🤓🔥 tweet media
English
6
3
35
2.1K
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
A safer workflow: - Use AI for enumeration: surfaces, threat ideas, edge-case prompts - Use humans for verification: invariants, exploitability, impact - Require evidence for every claim: code path + state transition + attacker capability
English
1
0
2
272
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
AI can make auditors faster. It can also make them confidently wrong.
English
8
2
24
1.5K
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
“Just run Slither” is becoming the new “just audit harder.” Use tools. Absolutely. But the biggest misses still come from: - invalid assumptions - missing invariants - dangerous integrations Scanners find patterns. Auditors find broken logic.
English
1
2
12
803
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
28 AI audit skill files. 9 repositories. 28 scanned safe. 0 you have to pay for. The AI Skills Explorer is live and free.
English
0
1
13
1.3K
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
The hard truth: You don’t become audit-ready by consuming more content. You become audit-ready with a repeatable system: - threat model first - invariants second - exploit paths third - mitigations with tradeoffs last
English
3
1
15
1K
Al-Qa'qa'
Al-Qa'qa'@Al_Qa_qa·
50 million dollars worth of tokens were swapped for 35k only. And this is the consequence of not using the slippage check etherscan.io/tx/0x9fa9feab3…
Al-Qa'qa' tweet media
English
4
3
26
3.7K
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
NO FX FEES - Waited for this feature for so long - no I can really earn 4% cashback on everything I SPEND. DM me to get invite link 🤝 Just Use EtherFi.
JohnnyTime 🤓🔥 tweet media
English
0
0
0
594
JohnnyTime 🤓🔥 retuiteado
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
I spent the last 2 weeks analyzing every public AI skill file for smart contract auditing I could find. Here's what I discovered: The ecosystem is exploding. Trail of Bits alone has skills covering 6 blockchains. Pashov's audit skill went viral with 125K views. QuillAudits built 10 specialized Solidity skills. New repos are popping up weekly. But here's what nobody's talking about: Nobody is checking if these skills are safe. AI skill files are structured prompts — YAML and markdown that tell your AI agent what to do. They can instruct your agent to read files, execute commands, access APIs. A malicious skill file could: → Exfiltrate your codebase → Inject backdoors into suggested fixes → Send your private keys to an external server And right now, developers are just... copying them. From READMEs. Without reviewing the raw content. So we built the AI Skills Explorer. 28 skills from 9 top repos. Every single one safety-scanned and labeled. Filter by language, platform, category. One-click copy. Free. No signup. Because the AI audit revolution shouldn't come with a supply chain attack. Link in replies 👇
English
6
14
81
4.7K