0xSecuri

481 posts

0xSecuri

0xSecuri

@0xSecuri

I hunt bugs to keep users and protocols safe

Portfolio → Katılım Mart 2023
68 Takip Edilen217 Takipçiler
Sabitlenmiş Tweet
0xSecuri
0xSecuri@0xSecuri·
Just received my very first reward as a Security Researcher. Thanks to @code4rena and @dittoproj for the opportunity! I'm looking forward to sharpening my skills and contributing much, much more to securing the web3 space! 🫡
0xSecuri tweet media
English
12
1
48
2.8K
0xSecuri
0xSecuri@0xSecuri·
@blckhv Digging through some gnarly code over here, you know how it makes you feel... and this was the exact boost I needed, thanks for sharing bro!
English
1
0
2
217
Blckhv
Blckhv@blckhv·
Do I really suck at auditing or I'm just not interested?🤔 A friend of mine, smart person, who's been doing web3 security shared with me that it hasn't been a pleasant experience for him since day one - but he has been pushing himself to do it. 🤷 The summary: - Not happy with what he was doing. - Average results. In short: dead-end 🔄 Do you see the correlation? 🪤 "You can't get better if you don't put in the hours, you can't put in the hours if it's not interesting to you" 😉 The problem? - auditing is abstract, not like reading a book or writing code, there you have an end goal, "I should read 100 pages today and write these 2 functionalities" vs. simply staring at the code. If you don't want to be that friend, set yourself structured small goals in the scope of your current audit: - Check the contracts that are the main entry flows. 🔍 - Choose the most important variables and follow their state changes across the code. 🧩 - Review similar codebases and their reports. 📜 Remember, you’ll never feel like you've explored a codebase 100%. Even the best researchers rarely catch half of the vulnerabilities. 🛡️
English
2
9
84
3.2K
Pandit | Ξ🦇🔊
Pandit | Ξ🦇🔊@panditdhamdhere·
My daily tools. Brave Remix Solidity Vs code Foundry Metamask JavaScript Bunch of faucets. What yours?
English
23
4
96
4.1K
0xSecuri
0xSecuri@0xSecuri·
💡 TIP to save you hundreds or even thousands of dollars! Always review your @audit/audit-issue tags! I learned this the hard way - today I realized I missed submitting two high severity findings because I didn’t check my @audit tags at the end of my last contest... 🤦‍♂️
English
0
0
0
250
0xSecuri retweetledi
ddimitrov22
ddimitrov22@ddimitrovv22·
The Ronin bridge was hacked(again!) on 6th of August because of an uninitialized critical parameter. Long story short: - Ronin deployed an update - called `initializeV4` but didn't call `initializeV3` - got exploited for ~$12M - paused the contract and decided to do an audit
English
3
5
29
2.1K
0xSecuri
0xSecuri@0xSecuri·
Don't rely on pattern matching; it won't help you in the long term. Pattern matching can be done by a bot. You want to achieve more than a bot! So, always strive to understand the codebase in depth. This way, you'll find more bugs with fewer duplicates and up-skill yourself!
English
0
0
1
159
0xSecuri retweetledi
Martin Marchev
Martin Marchev@MartinMarchev·
I got targeted by an address poisoning attack today. Never get lazy with your security practices. Stay vigilant and always double-check your transactions!
Martin Marchev tweet media
English
4
3
31
4.7K
0xSecuri
0xSecuri@0xSecuri·
Stop overthinking, just dive in! ✌️
English
0
0
2
103
0xSecuri
0xSecuri@0xSecuri·
Don't let the weekend pass you by without discovering any H/M vulnerabilities 😉✌️
English
1
0
3
127
0xSecuri retweetledi
sammy
sammy@sammyaudits·
Auditing 101 : Sometimes you just need to stare at the code until it starts making sense, even if you don’t know the language.
English
4
9
138
4.3K
0xSecuri
0xSecuri@0xSecuri·
Want to be a top-notch auditor? Find more bugs and score big money? Here’s the key: 1. Start today: read code, read docs, and take steps to be more capable tomorrow than you were today. 2. Repeat. The goal is to improve daily and provide more value! Results won't be late!
English
1
1
7
231
0xSecuri
0xSecuri@0xSecuri·
@Zubeirdayib24 Did you read the entire thread? 😃 Because I've shared the link bro!
English
0
0
1
55
0xSecuri
0xSecuri@0xSecuri·
Mindset Tips for Aspiring Auditors 🧠🧵 (1/3) If you feel unmotivated or think you won’t be able to become a successful auditor, check out these pieces of advice from the legend auditor @milotruck. It’s all about the mindset you need to succeed!
English
3
1
31
2.1K
0xSecuri
0xSecuri@0xSecuri·
(2/3) 1. Stick to one contest at a time 2. Be patient - success doesn’t come overnight 3. Don’t just grind; have a clear goal and focus on daily improvement
English
1
0
3
288
0xSecuri
0xSecuri@0xSecuri·
Sunday grinding ✌️
0xSecuri tweet media
English
2
0
6
839
UAARRRR
UAARRRR@uaarrrrr·
@0xSecuri so you use --vvvv instead of console.log ?
English
1
0
1
59
0xSecuri
0xSecuri@0xSecuri·
@rekxor You've got a sharp eye bro 😀
English
2
0
2
68
rekxor
rekxor@rekxor·
@0xSecuri SideContractLenderPool::withdraw()?😂 Ik its wrong
English
1
0
1
72