Synthrax

152 posts

Synthrax banner
Synthrax

Synthrax

@0xSynthrax

Blockchain Security Researcher | Ex C low-level developer | Auditing with @CODESPECT | https://t.co/ZnRgn86x5T

Katılım Kasım 2023
315 Takip Edilen143 Takipçiler
Sabitlenmiş Tweet
Synthrax
Synthrax@0xSynthrax·
2025 was an interesting year. • Left my dev job at the beginning of the year • Became full time crypto degen • Missed programming after 6 months and decided to learn blockchain development • Discovered Web3 audits and fell in love • Got my first contest result in September • Got my first private audit 2 months ago • Made a lot of great connections • Closing the year with 4 private audits Plans for 2026: make it all count
Synthrax@0xSynthrax

My first private audit collaboration got finalized today🔥 Grinding started to pay off 😎 Feels like a big step forward

English
1
1
14
3.5K
Synthrax
Synthrax@0xSynthrax·
When you know there is an issue in this suspicious function but you just can’t prove it yet.
Synthrax tweet media
English
0
0
6
254
Synthrax retweetledi
Synthrax
Synthrax@0xSynthrax·
Did you already register for the upcoming @CODESPECT contest? Good contest performance is a lot more valuable during markets like this. Btw I’m going to be the judge 👀 Don’t miss the opportunity👇
English
3
3
16
1.5K
Synthrax
Synthrax@0xSynthrax·
Started a solo audit a few days ago. The ones grinding through bad markets are the ones who win when things turn around. Stay busy, anon.
English
0
1
3
201
Synthrax
Synthrax@0xSynthrax·
@lonelysloth_sec Gaming community doesn’t like anything AI generated in the games, so studios are afraid of adding things like that. There were a lot of cases with negative backlash when community discovered that in some aspects(not connected to programming) there was AI used.
English
0
0
1
93
LonelySloth
LonelySloth@lonelysloth_sec·
Are all new videogames coming out using real time LLMs for realistic interactive NPCs? If not, why not? Is it a matter of time? Of cost? Seems to me like a no brainer use for the technology. You shouldn’t even need good models. Stuff from a year or more ago would probably be good enough. Are there any games that use it? Any recommendations?
English
8
0
17
2K
Synthrax
Synthrax@0xSynthrax·
@blckhv Which “auditors are cooked” ai innovation are we on right now? I’ve just lost count
English
1
0
2
191
Talfao
Talfao@talfao1·
I have first impersonators, be careful. I never want your crypto keys or never share with you any code etc.
Talfao tweet media
English
1
1
8
334
Synthrax retweetledi
CODESPECT
CODESPECT@CODESPECT·
CODESPECT is proud to support @Solbuildersclub. We've agreed to provide special perks for community members. If you're part of SBC, you can reach out to us for discounted security services, security guidance, and a free initial consultation on the security behind your project. Supporting builder communities is core to what we do. @solana is a great example of how strong communities ship great products. Members can DM us or reach out through the club to get started.
CODESPECT tweet media
English
2
6
8
506
LonelySloth
LonelySloth@lonelysloth_sec·
"Coded" by Claude on Feb 1st. "Audited" by Claude on Feb 2nd. "Fixed" by Claude on Feb 3rd. Deployed to mainnet (by Claude?) on March 19th. Funded on April 24th. Rekt (by Claude?) on April 28th. Welcome to the future. 🤡🤡🤡🤡🤡🤡🤡
PeckShield Inc.@peckshield

It seems a @tradingprotocol vault, i.e., YieldCore-3rd-deal, was exploited with $398k loss. There is a missing check on the caller authorization, which is exploited to drain all funds from the vault. Here is the related tx: etherscan.io/tx/0x6b04344d5…

English
11
16
168
15.7K
Synthrax
Synthrax@0xSynthrax·
There are audit review fix comments in the code. Was the code audited by AI? Because even junior auditor wouldn’t miss this kind of bug👀
PeckShield Inc.@peckshield

It seems a @tradingprotocol vault, i.e., YieldCore-3rd-deal, was exploited with $398k loss. There is a missing check on the caller authorization, which is exploited to drain all funds from the vault. Here is the related tx: etherscan.io/tx/0x6b04344d5…

English
0
0
5
932
Synthrax retweetledi
sudo rm -rf --no-preserve-root /
the negative and positive things that have happened since saturday are the result of _centralised_ points of building. everything that has happened (the bad and good things) would not have happened if we built in a truly decentralised way. overall, dprk would have far fewer "gains" if we stuck to cypherpunk principles. like, dprk does _not_ focus on smart contract hacks, they almost exclusively target centralised attack vectors. if we want to win against dprk (and any other state actor, which all focus on web2-based attack vectors), we need to go full cypherpunk mode. if this is not a wake up call, i do not think we will get a second chance.
English
22
35
240
17.4K
Synthrax retweetledi
Talfao
Talfao@talfao1·
This weekend KelpDao lost $292M. @LayerZero_Core just published their incident report. The protocol worked as designed. The smart contracts were fine. The money left through an RPC poisoning attack on a single-DVN configuration that multiple parties had warned against. A thread on what this teaches us about every attack surface. 🧵
English
1
6
11
910
Firepan
Firepan@FirepanHQ·
@0xSynthrax Should we build a new option? Every SR gets an AI copilot. Audit competition on steroids
English
1
0
1
14