固定されたツイート
JohnnyTime 🤓🔥
9.8K posts

JohnnyTime 🤓🔥
@RealJohnnyTime
Founder @ https://t.co/gcgrMm4Njh, JohnnyTime @ Youtube, Securing Web3 @ https://t.co/wJdpJyYcg0 & https://t.co/3d9aL8n5G8
Web3 参加日 Şubat 2012
1.4K フォロー中12.6K フォロワー

paying the checkmark, I have been playing with AI :P
stela-dapp.xyz - starknet banana - best p2p
n4no3d.xyz - me and my wife sometimes like to print 3d shit so its basically for us, test version
apura.xyz - Primavera SQL connector: AI reports.
English

@RealJohnnyTime hehe nope, I tried a lot of them on the kam repo, but nothing :P
English

How to steal millions in 4 steps:
1. Flash borrow 100k ETH
2. Dump on a DEX to crash price
3. Exploit a protocol reading that price
4. Repay loan, keep profit
If step 3 fails, the loan never happened. Zero risk.
smartcontractshacking.com/attacks/flash-…
English

@RealJohnnyTime ur AI is looping defillama deployed addresses and simulating this for each address till exploited on fork for bounties? :P
English

That lens helps you review like an operator, not a checklist runner.
smartcontractshacking.com/tools/most-exp…
English

Weekend Challenge #8: What issue would you submit if you saw this in an auditing context, Mr. Hacker?

English

If your note can’t name the exact state change, it’s not a finding yet.
smartcontractshacking.com/learn/security…
English

If you’re starting in 2026, this roadmap is one of the few that’s practical and sequenced.
smartcontractshacking.com/learn/security…
English

50 million dollars worth of tokens were swapped for 35k only.
And this is the consequence of not using the slippage check
etherscan.io/tx/0x9fa9feab3…

English
JohnnyTime 🤓🔥 がリツイート

I spent the last 2 weeks analyzing every public AI skill file for smart contract auditing I could find.
Here's what I discovered:
The ecosystem is exploding. Trail of Bits alone has skills covering 6 blockchains. Pashov's audit skill went viral with 125K views. QuillAudits built 10 specialized Solidity skills. New repos are popping up weekly.
But here's what nobody's talking about:
Nobody is checking if these skills are safe.
AI skill files are structured prompts — YAML and markdown that tell your AI agent what to do. They can instruct your agent to read files, execute commands, access APIs.
A malicious skill file could:
→ Exfiltrate your codebase
→ Inject backdoors into suggested fixes
→ Send your private keys to an external server
And right now, developers are just... copying them. From READMEs. Without reviewing the raw content.
So we built the AI Skills Explorer.
28 skills from 9 top repos. Every single one safety-scanned and labeled. Filter by language, platform, category. One-click copy.
Free. No signup.
Because the AI audit revolution shouldn't come with a supply chain attack.
Link in replies 👇
English
