0xChiAi

2.6K posts

0xChiAi banner
0xChiAi

0xChiAi

@Chimajax

Building... Wallet/Smart-Contract Security && ZK Proofs || AI Agents || Sometimes...Memes & Shitpost || Road to 100 followers...Follow

LAG 가입일 Mayıs 2024
76 팔로잉84 팔로워
고정된 트윗
0xChiAi
0xChiAi@Chimajax·
Congratulations to Me🎉 I Earned the Advanced Web3 Wallet Security achievement on @CyfrinUpdraft! Learnt a Lot - Wallets - Multi-Sig - Safe - CallData - Tx Type 0, 1, 2, 3, 113 Big Thanks @PatrickAlphaC Security on Signing Takes a Lot of Skills Still More to Learn
0xChiAi tweet media0xChiAi tweet media
0xChiAi@Chimajax

I have earned the Web3 Wallet Security Basics achievement on @CyfrinUpdraft! Wallet Security is Also Something I'm Looking into is still have a long way to go Excited for this You can join too! 🎉 Visit my Cyfrin profile to see it: profiles.cyfrin.io/u/chimajax/ach…

English
1
0
17
399
V
V@kxrd36·
i found chain halting bug on a network carrying $120M in stablecoins and $1.85B in market value. anyway, good morning! @HackenProof #HackenProof
V tweet media
English
32
17
419
12.1K
0xChiAi
0xChiAi@Chimajax·
@0x3b33 🤣Upgradeability plan is "we’ll figure it out"
English
0
0
1
23
Pyro
Pyro@0x3b33·
Patterns I keep seeing in web3 audits: – Developers add whole new feature 3 days before the audit – There are no scripts to 1 click pause everything – Upgradeability plan is "we’ll figure it out" - Admin permissions are "they are our guys, nothing bad will happen" None of those are Solidity bugs. All of them can cost 8 figures.
English
3
1
24
996
Jeremy
Jeremy@Jeremybtc·
A single mistake once locked $150,000,000 in Ethereum forever. No hacker stole it. No scam. Just one mistake. In 2017, a self described Ethereum newbie was exploring the Parity wallet. Software used by hundreds of crypto projects to store funds securely. Parity’s multi-sig wallets relied on a shared library contract. A single piece of code that every wallet depended on to function. That library had never been initialised. Meaning anyone could claim ownership of it. While testing, he did exactly that and accidentally became the owner of the master contract controlling hundreds of wallets. Panicking, he tried to undo it. He deleted it all. Because every Parity wallet depended on that library to operate. Deleting it instantly froze over 500,000 ETH across 598 wallets. Worth around $150 million at the time. Minutes later, he posted on GitHub: “I accidentally killed it.” Nobody could reverse it. Nobody could recover the funds. The coins are still visible on the blockchain. Today they’re worth $1.19 billion. But they can never be moved. One mistake. Hundreds of victims. $1.19 billion frozen forever.
Jeremy tweet media
English
79
12
185
17.8K
Mr Consistent1
Mr Consistent1@mrconsistent001·
@Jeremybtc The $1.19B delete key. What's wild is that multi-sig wallets existed then, but convenience won over security architecture. How many projects today are making the same trade-off?
English
1
0
0
256
0xChiAi
0xChiAi@Chimajax·
@zzebra83 Congratulations to you... So You might not Audit Again?...
English
1
0
1
177
zzebra83
zzebra83@zzebra83·
I haven't posted in a while so thought i would share a life update. It looks like I have retired(or semi retired) atleast for now from web3 security. I started a new position as tech lead in fintech. The team is great, the work is a ton of fun, and I still get to use my adversarial mindset everyday to make sure funds are SAFU. Also i'm based in Dubai, and as you know things are a bit unsettled atm, but surprisingly, life has been mostly normal.
English
5
0
66
2.6K
Essential
Essential@only01Essential·
Bug Bounty 101: Don't hunt on what everyone else is currently looking at.
English
3
0
36
1.5K
sagar (security arc)
sagar (security arc)@soarinskysagar·
Day 107 of sharing my progress till I make it as a web3 SR Started the @dexalot contest on @HackenProof. For this audit, I'm adopting a new methodology to see how it fares. I am done with a lot of the codebase now and have a good idea of what it does.
English
4
0
16
467
Keyword 💙🛠️
Keyword 💙🛠️@xKeywordx·
I always confuse these 2 guys because of their pfps. Anyone else?
Keyword 💙🛠️ tweet media
English
4
0
26
1.4K
0xChiAi
0xChiAi@Chimajax·
@rosarioborgesi "Private" is only invisible to other Contracts... Every other thing can read "Private"
English
0
0
1
11
Rosario Borgesi
Rosario Borgesi@rosarioborgesi·
📌 Why “private” variables in Solidity are still public Most people think private in Solidity means hidden. It doesn’t. Everything stored onchain is public 👇
Rosario Borgesi tweet media
English
2
3
19
414
0xChiAi
0xChiAi@Chimajax·
@RealJohnnyTime 1. liquidate() forgives borrower debt, setting to 0, without transferring collateral to the liquidator 2. liquidate() can allow anyone to liquidate anyone 3. getETHPrice() has no staleness validation on Chainlink ETH/USD price feeds
English
0
0
1
39
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
Weekend Challenge #8: What issue would you submit if you saw this in an auditing context, Mr. Hacker?
JohnnyTime 🤓🔥 tweet media
English
6
3
35
2.1K
sagar (security arc)
sagar (security arc)@soarinskysagar·
Day 104 of sharing my progress till I make it as a web3 SR Continued bug hunting on the codebase and applying my tool, still no luck :')
English
2
0
15
332
Wake
Wake@WakeFramework·
@karenkether @poapxyz @dev3pack Congrats on graduating. Building from here is the best part. If you start writing contracts, Wake's VS Code extension gives security feedback as you code. Nice companion for the next phase.
English
1
0
4
73
0xChiAi 리트윗함
Suraj Sharma
Suraj Sharma@suraj_sharma14·
To every Web3 builder grinding right now This is for you. You're learning Solidity at midnight while your friends are watching Netflix. You're submitting hackathon projects that don't place anywhere. You're applying to grants that take weeks to respond. Sometimes they don't respond at all. You're building in public with 200 followers while others with half your skill seem to be getting all the opportunities. And some days you genuinely wonder is this even worth it? I want to tell you something nobody says out loud in this industry: The people you admire in Web3 right now the ones with the protocol job, the grants, the ecosystem roles... Most of them had 12–18 months where nothing was happening. No replies. No opportunities. No traction. They just kept showing up anyway. Here's what I've learned watching builders succeed and fail in this space: The ones who made it didn't have better skills than the ones who didn't. They just refused to disappear during the quiet months. Web3 is still early. Embarrassingly early. The infrastructure being built right now will be used by billions of people who haven't heard of blockchain yet. The developer who grinds through 2026 when the market is uncertain. That developer becomes the senior engineer, the protocol lead, the ecosystem architect that every team is desperate to hire in 2028. But only if they don't quit now. So if you're in the quiet months right now. Keep building. Keep shipping. Keep showing up. The compounding hasn't shown up yet. But it will. And when it does it will feel like it happened overnight. It never happens overnight. It happens because of exactly what you're doing right now. Don't stop. ♻️ Repost this for a builder who needs to hear it today.
English
25
40
216
5.4K
Immunefi
Immunefi@immunefi·
The @FolksFinance Audit Competition is live! 💸 A $25,000 reward pool is up for grabs for finding bugs in project's Staking Contracts. 📅 Ends: March 17, 2026 💰 Reward pool: $25,000 ⌨️ Scope: 365 nSLOC of Solidity ✅ No KYC required Get hunting: immunefi.com/audit-competit…
Immunefi tweet media
English
20
24
244
18.2K
0xChiAi
0xChiAi@Chimajax·
@Emmit32oz @immunefi @FolksFinance When you say Cybersecurity...I believe you're speaking from the web2 aspect This one you see here is Web3...Solidity lang to be precise You would need lil knowledge of Smart Contract Auditing to start this If you know abt S.Contracts then you can join this from their site
English
0
0
0
23
Emmit
Emmit@Emmit32oz·
@immunefi @FolksFinance As someone going to school for cybersecurity I would like more information on how to enter, how to participate, or even just more information on it in general really interesting
English
1
0
0
479
0xChiAi 리트윗함
Trail of Bits
Trail of Bits@trailofbits·
A single bug in an ERC-4337 smart account can be as catastrophic as leaking a private key. We've audited dozens of smart accounts and found six vulnerability patterns that consistently reappear across codebases. 🧵
Trail of Bits tweet media
English
4
10
66
4.8K
0xChiAi
0xChiAi@Chimajax·
@HackenProof Constructor can bypass this ".code.length == 0" in the constructor... So the bug is that a Contract can Mint
English
0
0
0
13
HackenProof
HackenProof@HackenProof·
Spot the Bug 🧠 EOA-only gate What’s the issue in this code?👇
HackenProof tweet media
English
13
1
52
4.8K
Cyfrin Updraft 🟩
Cyfrin Updraft 🟩@CyfrinUpdraft·
A uint64 can only hold ~18 ETH. If your contract collects more than that in fees, the number wraps to zero. Silently. This is exactly the bug in PuppyRaffle. 🧵
English
5
7
197
8.9K