JohnnyTime ๐Ÿค“๐Ÿ”ฅ

9.8K posts

JohnnyTime ๐Ÿค“๐Ÿ”ฅ banner
JohnnyTime ๐Ÿค“๐Ÿ”ฅ

JohnnyTime ๐Ÿค“๐Ÿ”ฅ

@RealJohnnyTime

Founder @ https://t.co/gcgrMm4Njh, JohnnyTime @ Youtube, Securing Web3 @ https://t.co/wJdpJyYcg0 & https://t.co/3d9aL8n5G8

Web3 ๊ฐ€์ž…์ผ ลžubat 2012
1.4K ํŒ”๋กœ์ž‰12.6K ํŒ”๋กœ์›Œ
๊ณ ์ •๋œ ํŠธ์œ—
JohnnyTime ๐Ÿค“๐Ÿ”ฅ
JohnnyTime ๐Ÿค“๐Ÿ”ฅ@RealJohnnyTimeยท
Smart contract security pays WELL. ๐Ÿ’ฐ Top auditors make $500K+ per year ๐Ÿ’ฐ Bug bounties can 10x that ๐Ÿ’ฐ Even โ€œmidโ€ auditors make six figures BUTโ€ฆ Only if you actually put in the work. No shortcuts here.
English
14
26
316
26.1K
JohnnyTime ๐Ÿค“๐Ÿ”ฅ
JohnnyTime ๐Ÿค“๐Ÿ”ฅ@RealJohnnyTimeยท
โ€œMost expensive hacksโ€ shouldnโ€™t be consumed as shock content. Use it as prioritization data. During an audit, your real job is attention allocation: - where losses cluster - which assumptions fail repeatedly - what attack paths carry the highest downside
English
1
1
12
415
JohnnyTime ๐Ÿค“๐Ÿ”ฅ
JohnnyTime ๐Ÿค“๐Ÿ”ฅ@RealJohnnyTimeยท
If your goal is to get sharp at exploits, stop sampling 20 techniques at once. Pick one technique. Study 10 incidents. Extract the repeated broken assumption. Pattern recognition beats trivia every time.
English
5
2
33
1.1K
JohnnyTime ๐Ÿค“๐Ÿ”ฅ
JohnnyTime ๐Ÿค“๐Ÿ”ฅ@RealJohnnyTimeยท
Weekend Challenge #8: What issue would you submit if you saw this in an auditing context, Mr. Hacker?
JohnnyTime ๐Ÿค“๐Ÿ”ฅ tweet media
English
6
3
35
2.1K
JohnnyTime ๐Ÿค“๐Ÿ”ฅ
JohnnyTime ๐Ÿค“๐Ÿ”ฅ@RealJohnnyTimeยท
A safer workflow: - Use AI for enumeration: surfaces, threat ideas, edge-case prompts - Use humans for verification: invariants, exploitability, impact - Require evidence for every claim: code path + state transition + attacker capability
English
1
0
2
270
JohnnyTime ๐Ÿค“๐Ÿ”ฅ
JohnnyTime ๐Ÿค“๐Ÿ”ฅ@RealJohnnyTimeยท
โ€œJust run Slitherโ€ is becoming the new โ€œjust audit harder.โ€ Use tools. Absolutely. But the biggest misses still come from: - invalid assumptions - missing invariants - dangerous integrations Scanners find patterns. Auditors find broken logic.
English
1
2
12
801
JohnnyTime ๐Ÿค“๐Ÿ”ฅ
JohnnyTime ๐Ÿค“๐Ÿ”ฅ@RealJohnnyTimeยท
28 AI audit skill files. 9 repositories. 28 scanned safe. 0 you have to pay for. The AI Skills Explorer is live and free.
English
0
1
13
1.3K
JohnnyTime ๐Ÿค“๐Ÿ”ฅ
JohnnyTime ๐Ÿค“๐Ÿ”ฅ@RealJohnnyTimeยท
The hard truth: You donโ€™t become audit-ready by consuming more content. You become audit-ready with a repeatable system: - threat model first - invariants second - exploit paths third - mitigations with tradeoffs last
English
3
1
15
1K
JohnnyTime ๐Ÿค“๐Ÿ”ฅ
JohnnyTime ๐Ÿค“๐Ÿ”ฅ@RealJohnnyTimeยท
NO FX FEES - Waited for this feature for so long - no I can really earn 4% cashback on everything I SPEND. DM me to get invite link ๐Ÿค Just Use EtherFi.
JohnnyTime ๐Ÿค“๐Ÿ”ฅ tweet media
English
0
0
0
592
JohnnyTime ๐Ÿค“๐Ÿ”ฅ ๋ฆฌํŠธ์œ—ํ•จ
JohnnyTime ๐Ÿค“๐Ÿ”ฅ
JohnnyTime ๐Ÿค“๐Ÿ”ฅ@RealJohnnyTimeยท
I spent the last 2 weeks analyzing every public AI skill file for smart contract auditing I could find. Here's what I discovered: The ecosystem is exploding. Trail of Bits alone has skills covering 6 blockchains. Pashov's audit skill went viral with 125K views. QuillAudits built 10 specialized Solidity skills. New repos are popping up weekly. But here's what nobody's talking about: Nobody is checking if these skills are safe. AI skill files are structured prompts โ€” YAML and markdown that tell your AI agent what to do. They can instruct your agent to read files, execute commands, access APIs. A malicious skill file could: โ†’ Exfiltrate your codebase โ†’ Inject backdoors into suggested fixes โ†’ Send your private keys to an external server And right now, developers are just... copying them. From READMEs. Without reviewing the raw content. So we built the AI Skills Explorer. 28 skills from 9 top repos. Every single one safety-scanned and labeled. Filter by language, platform, category. One-click copy. Free. No signup. Because the AI audit revolution shouldn't come with a supply chain attack. Link in replies ๐Ÿ‘‡
English
6
14
81
4.7K