0xSimao

2K posts

0xSimao banner
0xSimao

0xSimao

@0xSimao

Founding Researcher @blackthornxyz | #2 @sherlockdefi 2025 | 28 Top-3 & 60+ Private Audits | Founder The Contest Academy | DM for audits https://t.co/V6VPeRhRWg

Katılım Eylül 2022
1K Takip Edilen4.6K Takipçiler
Sabitlenmiş Tweet
0xSimao
0xSimao@0xSimao·
1/ Introducing The Mentorship Series 0xsimao.com/blog/introduci… I’m personally mentoring a small, hand-picked group of auditors in 2026. 1st announced tmr. 3 months of 1-on-1 mentoring with me each. Targets: 0 → 4 figures 4 → 5 figures Step 1: Like and repost this post.
0xSimao tweet media
English
66
225
566
60.7K
0xSimao retweetledi
SHERLOCK
SHERLOCK@sherlockdefi·
Here are the results of the @opencover Audit Contest! 1. @0xSimao - $9,596 🥇 2. @_onlyowner - $936 🥈 3. @eeyore0x - $503 🥉 $18,500 in rewards, bringing Sherlock's total researcher payouts to $20.2M+. Link below for the full results 👇
English
4
3
74
2.9K
0xSimao
0xSimao@0xSimao·
Glad to have lead this one 🫡 Super secure codebase, the biggest ever list of known issues, main invariants defined, great testing, and no High/Crits found. Well done @aave 🎉
SHERLOCK@sherlockdefi

The @Aave V4 audit contest results are now published! There were no validated Critical/High/Medium severity issues. The $10,000 USDC gas pot will be split across 6 researchers, proportional to leaderboard points. Thank you to everyone who participated. Full results here: audits.sherlock.xyz/contests/1209

English
2
0
63
3.4K
0xSimao retweetledi
SHERLOCK
SHERLOCK@sherlockdefi·
The @Aave V4 audit contest results are now published! There were no validated Critical/High/Medium severity issues. The $10,000 USDC gas pot will be split across 6 researchers, proportional to leaderboard points. Thank you to everyone who participated. Full results here: audits.sherlock.xyz/contests/1209
SHERLOCK tweet media
English
6
9
66
12.6K
pashov
pashov@pashov·
🚨Ethereum Developers: you can now install your first AI Auditor in 1 minute - fully autonomous, available 24/7, with multiple sub-agent helpers. Open Source. FREE to use (with your AI model) and already finding vulnerabilities in smart contracts. Link below🫡
pashov tweet media
English
167
255
1.3K
147.9K
0xSimao retweetledi
alexander
alexander@a1exander·
🧵How I made $100K+ over some weekends bug bounty hunting on @cantinaxyz Cantina is one of the biggest bug bounty platforms in web3 and hosts some of the biggest bug bounties in the world (Up to $15.5M payouts ). Most people who do bug hunting in web3 are focused on the smart contracts, mostly going through the highly decentralized aspects of web3. But here's what they're all missing: a lot of web3 is still reliant on web2 technologies. And nobody is looking there. While 99% of hunters read smart contract code, the web2 attack surface is completely exposed. And it's simple. - Resource exhaustion on large onchain API queries - Improper signature validation allowing for account takeover - XSS on IPFS gateways allowing for browser wallet popups and cookie hijacking A lot of these are in plainsight and take couple minutes to find because... nobody's looking Web3 companies obsess over contract security. Their web2 infrastructure? They assume it's handled. It's not. Here's the insight: the hardest bugs to find are the ones nobody's hunting for. If you're a web2 security person, you're not competing with 10,000 contract auditors. You're competing with maybe 50 people thinking about infrastructure. The attack surface is massive. The competition is thin. You don't need to be the best auditor. You just need to look at the right layer.
alexander tweet media
English
7
26
424
21.5K
Ihtisham
Ihtisham@ihtishamSudo·
casually dropped crit where attacker can hijack the entire token supply in one of my client's codebase after multiple code changes and follow up audits, as a good will.
Ihtisham tweet media
English
4
0
12
1.4K
0xSimao
0xSimao@0xSimao·
@ChrisWillx depends on the type of work, for web3 auditing I need 27h sleep / day to do this u need to sleep on an airplane going against sunset so u can sleep over 24h / day
English
3
1
23
912
Chris Williamson
Chris Williamson@ChrisWillx·
You don’t perform on 6 hours sleep. One of the most important sleep studies ever ran a brutally simple test. People slept 4h, 6h, or 8h per night for 14 days. No all-nighters. Just “normal” short sleep. Cognitive performance was tested every two hours. By day 14: 6 hours = same impairment as being awake for 24 hours. 4 hours = same as 48 hours awake. But here’s the scary part – after day 3–4, people stopped feeling more tired. Reaction times kept slowing, attention lapses kept increasing, working memory kept degrading. But subjective sleepiness flatlined. Your brain keeps getting worse, your ability to notice it breaks. This is why chronic undersleeping feels sustainable – you adapt to feeling tired but you do not adapt to being cognitively impaired. The participants would’ve told you they felt “okay”. Objectively, they were functioning like they’d pulled an all-nighter. If you’re sleeping 6 hours and think you’re fine, you’ve probably lost calibration. Sleep need is biological. Most adults need 7–9 hours. “I only need 6” usually means “I forgot what normal feels like.” Feeling fine is not evidence you’re functioning well. Chronic sleep loss doesn’t just impair your brain – it blinds you to the impairment. — h/t @aakashgupta
English
408
573
7.7K
866.2K
Boring_Business
Boring_Business@BoringBiz_·
The highest IQ people I know are all either > fully locked in and building or investing in AI. goal is to work towards generational wealth in the midst of a new technological revolution > fully checked out of society and the corporate rat race. they are quitting their job, deleting social media and moving to the middle of nowhere to live a quiet life with no distractions Literally no in between
Beff (e/acc)@beffjezos

All the smartest people you know are in a generational lock-in season right now

English
380
1K
15.1K
1.3M
0xSimao retweetledi
kaden.eth
kaden.eth@0xKaden·
✨Introducing evmresearch✨✨ A knowledge graph of nearly everything I've learned about the EVM in the past six years The graph structure emulates the brain, exponentiating research speeds for both humans and agents evmresearch.io
English
45
90
760
57.4K
0xSimao retweetledi
kaden.eth
kaden.eth@0xKaden·
somehow missed this gem from the solidity 0.8.31 release one less common audit finding 😌
kaden.eth tweet media
English
4
6
56
3.6K
0xSimao retweetledi
Monad
Monad@monad·
Congrats @code4rena wardens for some impressive findings in our recent $500,000 competitive audit Thank you for helping secure the Monad codebase!
Code4rena@code4rena

🚨 Half a million dollars paid. 🚨 The largest-ever unconditional prize pool is officially settled — all $500,000 distributed to participants. 4 high & 7 medium severity findings rewarded. Shoutout to @Monad & @category_xyz for their unwavering commitment to security!

English
55
40
340
43.7K
kaden.eth
kaden.eth@0xKaden·
I HEREBY DECLARE THAT I DO NOT GIVE MY PERMISSION FOR AI AUDIT AGENTS TO USE ANY OF MY AUDIT FINDINGS OR CODE ON MY GITHUB OR ANY RESEARCH I HAVE SHARED ON TWITTER OR ELSEWHERE REPOST THIS TO STOP THE AI AUDIT AGENTS FROM STEALING OUR DATA
English
13
3
64
5.4K
LonelySloth
LonelySloth@lonelysloth_sec·
Beating humans at chess is something used to argue AI is going to beat humans at everything. What sort of AI? LLMs. LLMs suck at chess. Like really suck. Even though they read every transcript of every game ever played and all the books about chess. How does that work?
English
8
0
53
3.6K
0xSimao retweetledi
Smacaud
Smacaud@Smacaud1·
Just deleting some old photos
Smacaud tweet media
English
8
4
50
2.2K
0xSimao
0xSimao@0xSimao·
ZKsync Developers (∎, ∆)@zkSyncDevs

To the participants of the recent $1.1M @code4rena zkSync competitive audit and the zkSync community 👇 As the competition came to a close, as is customary for our team, we conducted an initial review of the results and findings. Integrity, transparency and fairness are core to our ethos, so we always put maximum emphasis on our due diligence process. During this review we noticed anomalies in the findings, which led us to 1) conduct further investigation, and 2) pause the bounty distribution until the investigation concluded. After an in-depth investigation, we identified a conflict of interest between a participant in the competition, HE1M, and a third-party contractor working with Matter Labs. The investigation concluded that HE1M gained an unfair advantage in the competition by failing to disclose that their spouse was a contractor on assignment with Matter Labs. One or both of the following scenarios took place: - The individual purposefully did not disclose bugs in the system to gain an unfair advantage. - The individual’s spouse received unfair positive treatment by the contractor. We have zero tolerance for anything that challenges the fairness and integrity of the contest. From the possible scenarios described above, both are cause for disqualification. Upon conclusion of the investigation, Matter Labs notified Code4rena and immediately terminated the working relationship with the contractor involved. Code4rena followed course with their standard operating procedure of performing their own thorough diligence and providing evidence to an independent judge for review. The independent judge received all of the findings from our internal investigation, and the judge came to the same conclusion. As a result, HE1M, the participant with a conflict of interest, had their submissions deemed ineligible for awards so that competition funds could be distributed fairly to other participants. It is possible that HE1M’s discoveries in previous competitions were also the result of the same conflict of interest. While we are not in a position to retroactively review submissions from prior competitions, the conflict of interest was discovered by the diligent team overseeing the current competition before rewards were distributed. Our team has put parameters in place to ensure that a similar situation does not reoccur. We deeply apologize to the participants and condemn the actions taken by HE1M. In future contests, as well as in all Matter Labs initiatives, we will continue to be transparent in our communications with the community. We are grateful to our and Code4rena’s team of experts for their impressive due diligence and for raising the bar in accountability and integrity for white hats across the space.

QME
1
0
1
1.4K
0xSimao
0xSimao@0xSimao·
ily2 is HE1M
English
11
1
67
8.8K
0xSimao
0xSimao@0xSimao·
My mentee @0xFireFist just landed another W on the @Panoptic_xyz contest on @code4rena! x.com/0xFireFist/sta… All recorded! 0xsimao.com/blog/mentorshi… Officially surpassed $10k+ earnings in the mentorship 🎉🥳
0xfirefist@0xFireFist

Pretty happy with this result from the @Panoptic_xyz contest on @code4rena, having in mind that I worked on it for a few days only. Managed to find a very interesting medium with only one duplicate. Congrats to @ValvesSec for the good job!

English
11
1
93
3.4K