๐Œ‹๐Œ„๊Š

487 posts

๐Œ‹๐Œ„๊Š banner
๐Œ‹๐Œ„๊Š

๐Œ‹๐Œ„๊Š

@CipherShade

๐Œ‚๊Š๐Œ๐Œ”๐Œ‰๐Œ”๐Œ•๐Œ„๐Œ๐Œ‚๐Œ™ ๐ŒŠ๐Œ‰๐Œ‹๐Œ‹๐Œ” ๐Œ‚๐Œ“๐Œ„๐Œ€๐Œ•๐Œ‰แ•“๐Œ‰๐Œ•๐Œ™!

ู…ุฌู‡ูˆู„ Bergabung Nisan 2023
907 Mengikuti76 Pengikut
๐Œ‹๐Œ„๊Š me-retweet
chrisdior.eth
chrisdior.eth@chrisdior777ยท
Auditing feels impossible at first. Hereโ€™s what progress actually looks like: 0โ€“100h -> lost most of the time 200โ€“300h -> start spotting patterns 500โ€“700h -> can handle big codebases 1000h+ -> it clicks, bugs stand out instantly The skill compounds over time. Keep going๐Ÿ™
English
7
9
135
3.1K
๐Œ‹๐Œ„๊Š me-retweet
Bernhard Mueller
Bernhard Mueller@muellerberndtยท
Hereโ€™s my new article on finding soundness bugs in ZK circuits, with concrete examples in Circom, Cairo, and Rust. Link in reply.
Bernhard Mueller tweet media
English
14
25
224
10.3K
JohnnyTime ๐Ÿค“๐Ÿ”ฅ
JohnnyTime ๐Ÿค“๐Ÿ”ฅ@RealJohnnyTimeยท
ITโ€™S HEREโ—๏ธ Together with @Starknetfndn, in no particular order, we are thrilled to welcome 18 new CSCH students to the community ๐Ÿฅ @Om_Santoshwar @MSG_Encrypted @ayur_27 @0xaudron @1techhunter @Pelz_Dev @rejwar @0xLegendaire @AnmolSirola @Icon_70 @dmtrbch @CipherShade @0xjarix @scarcemrk @ManiVeer198 @Sriki09182003 @Likitd_ @SerahOluwatosin Congratulations! You will be receiving access to the learning platform shortly ๐Ÿซก To everyone who did not get in this time, keep up the great work, and Iโ€™m sure there will be more opportunities for you in the future ๐Ÿ‘€ You are also welcome to reach out for individual feedback๐Ÿค
English
26
15
76
5.3K
Angelina | itsangelina.eth ๐ŸŒธ
Angelina | itsangelina.eth ๐ŸŒธ@angelinarusseยท
Gm Web3! Fun Alchemy stickers for the win!! Thinking about making an envelope full of stickers to send to people! Also, how cute is the ZK <> Alchemy one? ๐Ÿ˜„๐ŸŽ‰
Angelina | itsangelina.eth ๐ŸŒธ tweet media
English
56
7
195
6.3K
Angelina | itsangelina.eth ๐ŸŒธ
Angelina | itsangelina.eth ๐ŸŒธ@angelinarusseยท
Thank you for everyoneโ€™s patience! Iโ€™m going through the list! Will give a shirt to everyone I can ๐Ÿ˜Šโค๏ธ
English
2
0
7
418
Angelina | itsangelina.eth ๐ŸŒธ
Angelina | itsangelina.eth ๐ŸŒธ@angelinarusseยท
It's that time again.๐Ÿ‘€ The holidays are here, and Iโ€™ve got a little surprise for you! Bitcoin shirts are back in stock! Let me know if youโ€™d like one. Thanks for being part of the Alchemy community! โค๏ธ
Angelina | itsangelina.eth ๐ŸŒธ tweet media
English
109
6
167
11.3K
๐Œ‹๐Œ„๊Š me-retweet
zokyo
zokyo@zokyo_ioยท
Level up your cybersecurity knowledge! A compilation of the best Web3 security alpha from our top engineers ๐Ÿงต ๐Ÿ“š Blog Posts 1๏ธโƒฃ Preparing for the Challenges of Smart Contract Audits ๐Ÿ”— zokyo.io/blog/navigatinโ€ฆ Compilation of essential tips for pre-audit preparation 2๏ธโƒฃ The Power of Penetration Testing ๐Ÿ”— zokyo.io/blog/unlockingโ€ฆ Why penetration testing is crucial for identifying security gaps in Web3 systems 3๏ธโƒฃ Understanding Subdomain Takeovers ๐Ÿ”— zokyo.io/blog/when-web2โ€ฆ A comprehensive guide to subdomain takeovers in the context of Web3 4๏ธโƒฃ Design: Push vs. Pull Pattern in EVM ๐Ÿ”— zokyo.io/blog/design-puโ€ฆ The benefits and trade-offs of different smart contract design patterns within the Ethereum Virtual Machine 5๏ธโƒฃ Bug Bounty Programs ๐Ÿ”— zokyo.io/blog/bug-bountโ€ฆ The evolution and critical role of bug bounty programs in cybersecurity 6๏ธโƒฃ AI & Smart Contract Security ๐Ÿ”— zokyo.io/blog/ai-in-cryโ€ฆ How AI is reshaping security practices in smart contract coding and auditing 7๏ธโƒฃ Under the Hackerโ€™s Hood: JSON Injection in NFTs ๐Ÿ”— zokyo.io/blog/under-theโ€ฆ Understanding vulnerabilities in NFT metadata and risks from JSON injection attacks 8๏ธโƒฃ The Role of Invariant Testing in Cybersecurity ๐Ÿ”— zokyo.io/blog/ensuring-โ€ฆ How invariant testing ensures robustness in smart contracts 9๏ธโƒฃ Flash Loan Attacks ๐Ÿ”— zokyo.io/blog/flash-loaโ€ฆ How flash loan attacks work, their impact on DeFi, and strategies to avoid them ๐Ÿ”Ÿ Chainlink VRF ๐Ÿ”— zokyo.io/blog/chainlinkโ€ฆ An examination of Chainlinkโ€™s VRF and the security considerations for its use 1๏ธโƒฃ1๏ธโƒฃ The Top 10 Vulnerabilities in Large Language Models (LLMs) ๐Ÿ”— zokyo.io/blog/exploringโ€ฆ Insights into the top vulnerabilities in AI models and the security measures to consider 1๏ธโƒฃ2๏ธโƒฃ Best Practices for Web3 Wallet Security ๐Ÿ”— zokyo.io/blog/safeguardโ€ฆ Guidelines to securing private keys and wallet security 1๏ธโƒฃ3๏ธโƒฃ Web3: A Promising Frontier Fraught with Deception ๐Ÿ”— zokyo.io/blog/web3-a-prโ€ฆ Lessons from a recent YouTube-promoted crypto scam case study ๐Ÿ’ฌTwitter Threads 1๏ธโƒฃ Recap of OpenSense Interview ๐Ÿ”—x.com/zokyo_io/statuโ€ฆ Key insights from top engineer @SakshamGuruji on Web3 security, hackathon competitions, AI in auditing, and best practices 2๏ธโƒฃ Boss goes on NASDAQ TradeTalks ๐Ÿ”—x.com/zokyo_io/statuโ€ฆ Our CEO Hartej discusses Generative AI, asset auditing challenges, and the future of cybersecurity 3๏ธโƒฃ Top 10 Security Issues Discovered by Zokyo ๐Ÿ”—x.com/zokyo_io/statuโ€ฆ Our top audit findings of 2024, from rounding errors to DoS vulnerabilities 4๏ธโƒฃ Fuzz Testing:All You Need to Know About ๐Ÿ”—x.com/zokyo_io/statuโ€ฆ Why fuzz testing is a practical alternative to formal verification for blockchain Virtual Machines 5๏ธโƒฃ Zokyo's Top Security Insights on Solodit ๐Ÿ”—x.com/zokyo_io/statuโ€ฆ A deep dive into 1,200+ expert audit findings on Solodit
English
2
8
45
7.5K
Shieldify Security
Shieldify Security@ShieldifySecยท
How to become a Better Smart Contract Auditor? It's simple, put maximum time into it and do it willingly, every single day, no Excuses First is learning, then the first letter of the word Learn is removed LEARN -> EARN
English
7
10
122
5.5K
Shieldify Security
Shieldify Security@ShieldifySecยท
Stop thinking about it, just quit your job and become a Smart Contract Researcher/Auditor. That's it!
English
15
7
97
6.8K
๐Œ‹๐Œ„๊Š me-retweet
CharlesWang
CharlesWang@0xCharlesWangยท
Ether Transfers in Solidity: transfer(), send(), and call() In Solidity, there are three primary ways to transfer Ether between contracts or to external accounts: transfer(), send(), and call(). Each method has different behaviors, including safety mechanisms and gas consumption, so it's important to understand when and how to use each one. 1. transfer() The transfer() method is the simplest and most secure way to send Ether. It forwards 2300 gas to the recipient, preventing reentrancy attacks and ensuring that only basic operations (like logging) can be performed in the recipientโ€™s fallback function. If the transfer fails, it automatically reverts the transaction. Key Points: Gas forwarding: Only 2300 gas is forwarded, which protects against reentrancy. Auto-revert: The transaction reverts on failure, so you donโ€™t need to handle errors. Simple to use, but can fail if the recipient's fallback function requires more than 2300 gas. Many auditors think it's an issue if a smart contract wallet is interacting with a contract and the transfer method transfers funds to the smart contract wallet. This will however only revert if there is gas-consuming logic in the fallback/receive function. 2. send() The send() method works similarly to transfer(), but it does not automatically revert if the transaction fails. Instead, it returns a boolean (true on success, false on failure). You must manually handle the failure case. Key Points: Gas forwarding: Like transfer(), it only forwards 2300 gas. Error handling: It does not revert on failure, so you must check the return value and handle failures manually. 3. call() call() is the most flexible and method for sending Ether. It allows arbitrary interactions with contracts, including sending Ether and invoking functions. Unlike transfer() and send(), it forwards all available gas, which makes it more prone to reentrancy attacks. However, it's useful when dealing with contracts that require more than 2300 gas to execute their logic. To avoid security risks, call() should always be followed by a check of the return value and, ideally, a proper gas management or protection against reentrancy attacks. One can also forward a custom gas value, if desired. Key Points: Gas forwarding: Forwards all available gas by default, making it flexible but potentially dangerous. Error handling: Like send(), it returns a boolean that must be checked to ensure the transaction succeeded. Reentrancy risk: Since all gas is forwarded, itโ€™s vulnerable to reentrancy attacks unless guarded with checks like the nonReentrant modifier.
CharlesWang tweet mediaCharlesWang tweet mediaCharlesWang tweet media
English
5
14
97
6.4K
SHERLOCK
SHERLOCK@sherlockdefiยท
Anonymous keyword in Solidity Solidity includes an "anonymous" keyword for events that's not commonly used. When might a developer choose this option, and what does it actually do in a smart contract?
SHERLOCK tweet media
English
3
2
24
2.1K
CharlesWang
CharlesWang@0xCharlesWangยท
FIND THE BUG - CHALLENGE A simple refund mechanism that lets the owner refund tokens to recipients - what could go wrong here? Bonus: What could go wrong if the array of recipients is in the storage and users could become part of the array by depositing funds?
CharlesWang tweet media
English
10
3
37
6.2K
๐Œ‹๐Œ„๊Š me-retweet
SHERLOCK
SHERLOCK@sherlockdefiยท
Spot this bug, and you might become a Sherlock Lead Senior Watson (LSW) one day. The winner will be picked in 24 hours. This code is a simplified version of an actual vulnerability found in a Sherlock contest. Hint: Look closely at the disableMaxLock function, consider all the edge cases. Good luck!
SHERLOCK tweet media
English
12
8
54
8.6K
pashov
pashov@pashovยท
Security researchers don't need sex Escalations fck them every day
English
10
2
76
5.2K
vukan (blkn/acc)
vukan (blkn/acc)@vukan0xยท
replied to like 300+ invites, will continue sending rest in a bit just want to say how amazing it is to work in web3 / crypto, everyone is so nice, friendly and collaborative maximalism in crypto is DYING, interoperability and collaboration is THRIVING and Iโ€™m super happy that this also goes for my own project, @BlockformerLLC, and for the projects that we work with, like @ApexFusion please, ping me again in DMs if I didnt get back to u, reply here for speedy reply
vukan (blkn/acc)@vukan0x

are you under 25 working in crypto? reply and I'll send you an inv to a group filled with genz gooners all working fulltime in web3 to build partnerships, connections, and to collaborate props to @0xMatt1 for starting this, amazing initiative, already met some amazing ppl!

English
131
4
136
22.7K