0xScourgedev

367 posts

0xScourgedev banner
0xScourgedev

0xScourgedev

@0xScourgedev

CEO & Lead Fuzzing Specialist @perimeter_sec

Canada Katılım Nisan 2023
199 Takip Edilen712 Takipçiler
Sabitlenmiş Tweet
0xScourgedev
0xScourgedev@0xScourgedev·
It's a lot of responsibility being one of the final lines of defense! Our invariant fuzzing harnesses uncovered and prevented several severe vulnerabilities (all issues fixed) from reaching production. Lots of respect to @berachain for taking security extremely seriously 🫡
Perimeter@perimeter_sec

Excited to share that over the past 6+ months, we've helped secure critical infrastructure for @berachain using invariant fuzzing. Big credit to @berachain for their industry-leading commitment to security. Looking forward to continuing our partnership in securing Berachain 🫡

English
0
0
13
2.9K
Josselin Feist
Josselin Feist@Montyly·
Anyone at OpenAI interested in blockchain who could help with this?
Josselin Feist@Montyly

@sama If OpenAI is looking to onboard trusted security researchers from the blockchain space, the EthSecurity Badge initiative is worth a look: @thedao.fund/thedao-is-becoming-a-dao-again" target="_blank" rel="nofollow noopener">paragraph.com/@thedao.fund/t… / opensea.io/collection/eth… It's a peer-curated set of trusted security researchers in the ecosystem cc @thedaofund

English
2
1
20
2.7K
0xScourgedev
0xScourgedev@0xScourgedev·
Depends what my goal is. Is the goal that a cure to cancer is found? Or is it that I want to be the one to cure cancer. If it’s the former then I would be extremely happy, if it’s the latter, then I would feel like I was too slow. Regardless, I would either go into an adjacent field or try to cure the remaining 10%.
English
1
0
3
438
Hari
Hari@hrkrshnn·
If you spent 10 years of your life becoming a cancer specialist and all of a sudden a pharma company is going to drop a cancer vaccine that cures 90% of cancer, how will you react?
English
18
3
46
8.8K
0xScourgedev
0xScourgedev@0xScourgedev·
Hopefully codex will write my POCs without workarounds now 😅
0xScourgedev tweet media
English
0
0
4
157
0xScourgedev
0xScourgedev@0xScourgedev·
I first met Gianluca and heard about his work at @Montyly's amazing W3ST event in Buenos Aires. We had deep conversations about his approach to Web3 security, and it's one of the most unique and effective that I've seen. Extremely excited to be working with each other!
Perimeter@perimeter_sec

Built the tools. Found the bugs. We’re excited to welcome Gianluca Brigandi (@gbrigandi) to Perimeter as Tooling Specialist. • Author of Traverse, Tameshi, and ThalIR • Multiple confirmed bounties

English
0
0
7
382
0xScourgedev retweetledi
Jeff Schroeder
Jeff Schroeder@SEJeff·
Unpopular opinion. It isn’t always feasible to do formal verification on large applications or protocols. I’ve done two engagement wilts a well known FV firm and got mediocre results in both. FV isn’t a magic bullet, but it is a wonderful tool when applicable. Fuzzing is easier to get running and finds many of the bugs FV does and often in less time. Both are valid approaches but one will often cost you less I people time and compute if done well.
toly 🇺🇸@toly

If they can get you to sign a tx they can steal your source code. Immutable open source with formal verification is the only real option

English
1
2
17
2.1K
pashov
pashov@pashov·
Say the name of a web3 security company and I will say 1 good and 1 bad thing about it
English
83
5
148
23.8K
0xScourgedev retweetledi
0x310f1.sh
0x310f1.sh@0x310f1sh·
Echidna v2.3.2 is out 🦔 Better Foundry support, improved reproducer generation, and fixes for coverage and Osaka compatibility. Big thanks to Gustavo, @BowTiedRadone, and @argotorg hevm folks for pushing a lot of this forward 🙏
English
1
1
3
272
0xScourgedev
0xScourgedev@0xScourgedev·
@nisedo_ It was with Opus 4.5, think it's worth revisiting with 4.6/gpt?
English
1
0
0
91
nisedo
nisedo@nisedo_·
Fuzzing a codebase from scratch takes hours of setup What if it took 1 command? Echidna/Medusa harness + basic invariants, auto-generated for ANY Foundry project Soon™
English
9
1
67
4.7K
0xScourgedev
0xScourgedev@0xScourgedev·
While developing our tool, I played around with AI adding some fuzzing features into the harness. Couldn't get it to be precise enough and it introduced issues that would take a while to debug or would miss some edge cases. So I made it fully deterministic and instead used AI for suggestions. I think it's a better approach for our use case. Curious on how you got past this problem!
English
1
0
3
114
nisedo
nisedo@nisedo_·
Currently working with a mix of deterministic setup (mined from the project tests/scripts) and AI filling for the rest I’m stress testing it against all weird codebases I can think of to fix the edge cases (and there are a lot of them, but hopefully we’ll find the right balance between deterministic and AI so it works with all codebases)
English
1
0
4
339
0xScourgedev
0xScourgedev@0xScourgedev·
Anyone else noticed that Codex 5.3 has gotten much worse over the past few days? Feel like it got significantly lazier and making simple mistakes that it wouldn't have a few days ago
English
0
0
3
264
0xScourgedev
0xScourgedev@0xScourgedev·
For the past two months, I've been using a physical stopwatch to record how many hours of focused work I do each day... My productivity has been through the roof
0xScourgedev tweet media
English
0
0
6
259
Immunefi
Immunefi@immunefi·
Security researcher ily2 has just earned a staggering $3,000,000 from submitting a critical smart contract bug via Immunefi. That's the largest single payout in web3 security in recent memory. In total, he's submitted 3 reports. All 3 were paid. 100% accuracy. His leaderboard update is coming soon, but you can pledge IMU to him now and earn when he finds the next one: immunefi.com/pledge/ily2
Immunefi tweet media
English
194
153
1.2K
345K
0xScourgedev
0xScourgedev@0xScourgedev·
@nisedo_ To be honest, I think the reason is purely economical like @deadrosesxyz said in his reply, especially with the rise of AI spam submissions
English
0
0
1
123
nisedo
nisedo@nisedo_·
@0xScourgedev I’ve done 3 audits in a row with full fuzzing suites, so I’m probably biased right. And I’m still trying to rationalize why audit contests are dying, I guess I haven’t fully grieved yet 🥲
English
1
0
2
292
nisedo
nisedo@nisedo_·
Contests are dying in part because fuzzing replaced them. Devs now run extensive fuzzing suites as the final step of their security process, whereas contests used to act as human fuzzers.
English
6
0
27
5K
0xScourgedev retweetledi
Perimeter
Perimeter@perimeter_sec·
fuzzlib v1.1.0 released – now with broader compatibility and new utilities for Solidity fuzzing What's new: - clampArr: Efficient array clamping - scaleDec: Decimal scaling helper - errAllow: Full support for pre-Cancun chains - Updated cheatcodes to allow latest functionalities
Perimeter tweet media
English
1
3
11
662