Farhaan
574 posts

Farhaan
@0xfarhaan
Tech Lead - Smart Contracts @maplefinance

Announcing the Solidity Testing Handbook ✨ Fully free, one-stop resource for Solidity developers and security researchers. Resources are currently scattered across blogs, docs, and forums. I found it difficult to keep track of everything in one place. This handbook aggregates all testing patterns from basic unit tests to advanced mutation tests into a single, well-organized guide for quick reference. It’s built from my own learnings and best practices observed in popular codebases. soliditytestingbook.com

"Claude wrote vulnerable code" raised my eyebrows because it doesn't feel right 🤨 So I investigated it with Claude and asked what is the wrong with this PR. It indeed looks like an AI agent made a mistake here. However, the same mistake could have been made by a human. The prompt: "Inspect this pull request and changes and check what oracle address is incorrect and why, causing the ETH rate to be wrong" Claude also gives a good post-mortem analysis; see the screenshots. Also this was not a code vulnerability error, but a configuration error, just to be accurate. Regardless of whether the code is written by an AI or by a human, these kinds of errors are caught in an automated integration test suite. You can ask Claude to generate the test cases regardless of whether you write the code yourself or just autocomplete it. In this case, tests existed, but there was no test case for price sanity, not in the tests, not in the production itself (which I would also recommend: have DAO controlled safe price range). As a human deployer, you will also perform manual checks when deploying changes like this, as part of the DAO process or similar.


Security researcher ily2 has just earned a staggering $3,000,000 from submitting a critical smart contract bug via Immunefi. That's the largest single payout in web3 security in recent memory. In total, he's submitted 3 reports. All 3 were paid. 100% accuracy. His leaderboard update is coming soon, but you can pledge IMU to him now and earn when he finds the next one: immunefi.com/pledge/ily2




The next era of DeFi starts today. @Aave and Maple are establishing a strategic partnership that brings institutional assets to the largest onchain lending market.


syrupUSD has surpassed $1B in supply.

Introducing MapleKit The new syrupUSDC integration guide for developers brings speed and security. What once took days, can now be done in hours or minutes. To support the launch, MapleKit partners can tap into a $250k user reward pool to fuel growth. More details below.

We're thrilled to be celebrating 10 years of Solidity! Let's look at some highlights from the past decade and get a glimpse into the future. 🧵↓


