๊ณ ์ ๋ ํธ์
JohnnyTime ๐ค๐ฅ
9.8K posts

JohnnyTime ๐ค๐ฅ
@RealJohnnyTime
Founder @ https://t.co/gcgrMm4Njh, JohnnyTime @ Youtube, Securing Web3 @ https://t.co/wJdpJyYcg0 & https://t.co/3d9aL8n5G8
Web3 ๊ฐ์
์ผ ลubat 2012
1.4K ํ๋ก์12.6K ํ๋ก์

paying the checkmark, I have been playing with AI :P
stela-dapp.xyz - starknet banana - best p2p
n4no3d.xyz - me and my wife sometimes like to print 3d shit so its basically for us, test version
apura.xyz - Primavera SQL connector: AI reports.
English

@RealJohnnyTime hehe nope, I tried a lot of them on the kam repo, but nothing :P
English

How to steal millions in 4 steps:
1. Flash borrow 100k ETH
2. Dump on a DEX to crash price
3. Exploit a protocol reading that price
4. Repay loan, keep profit
If step 3 fails, the loan never happened. Zero risk.
smartcontractshacking.com/attacks/flash-โฆ
English

@RealJohnnyTime ur AI is looping defillama deployed addresses and simulating this for each address till exploited on fork for bounties? :P
English

That lens helps you review like an operator, not a checklist runner.
smartcontractshacking.com/tools/most-expโฆ
English

Weekend Challenge #8: What issue would you submit if you saw this in an auditing context, Mr. Hacker?

English

If your note canโt name the exact state change, itโs not a finding yet.
smartcontractshacking.com/learn/securityโฆ
English

If youโre starting in 2026, this roadmap is one of the few thatโs practical and sequenced.
smartcontractshacking.com/learn/securityโฆ
English

50 million dollars worth of tokens were swapped for 35k only.
And this is the consequence of not using the slippage check
etherscan.io/tx/0x9fa9feab3โฆ

English
JohnnyTime ๐ค๐ฅ ๋ฆฌํธ์ํจ

I spent the last 2 weeks analyzing every public AI skill file for smart contract auditing I could find.
Here's what I discovered:
The ecosystem is exploding. Trail of Bits alone has skills covering 6 blockchains. Pashov's audit skill went viral with 125K views. QuillAudits built 10 specialized Solidity skills. New repos are popping up weekly.
But here's what nobody's talking about:
Nobody is checking if these skills are safe.
AI skill files are structured prompts โ YAML and markdown that tell your AI agent what to do. They can instruct your agent to read files, execute commands, access APIs.
A malicious skill file could:
โ Exfiltrate your codebase
โ Inject backdoors into suggested fixes
โ Send your private keys to an external server
And right now, developers are just... copying them. From READMEs. Without reviewing the raw content.
So we built the AI Skills Explorer.
28 skills from 9 top repos. Every single one safety-scanned and labeled. Filter by language, platform, category. One-click copy.
Free. No signup.
Because the AI audit revolution shouldn't come with a supply chain attack.
Link in replies ๐
English
