Shalafat

293 posts

Shalafat banner
Shalafat

Shalafat

@0xlookman

web3 security research. DM for thorough smart contract audits.

blockchain Katılım Mart 2024
104 Takip Edilen225 Takipçiler
Sabitlenmiş Tweet
Shalafat
Shalafat@0xlookman·
I know its tough for new projects/protocols Security is very essential but sometimes can be unaffordable at the start. I am giving out a chance to the first 10 protocols with no budget or a very limited one, interested. Contact me so that we can secure that codebase.
English
0
2
3
314
Shalafat
Shalafat@0xlookman·
@arsen_bt Yah, at times I also stopped on phase 2 And missed alot of bugs
English
0
0
0
15
Arsen
Arsen@arsen_bt·
The 3 phases of every Solana audit ■ Phase 1 - Contextualize. > Skim every function. > Find entry points, actors, integrations. ■ Phase 2: Line by line. > Understand every atom. > Goal: walk the code in your head ■ Phase 3: Research. > List invariants. > Eliminate ideas > Conduct research > Do fuzzing > Dive into integrations Most auditors stop after phase 2 and wonder why they find nothing. The bugs live in phase 3.
English
2
2
32
854
Shalafat
Shalafat@0xlookman·
@0xShaedyW Cantina at it again Cantina, Cantina, Cantina every where Cantina Wherever you find something bad in web3, cantina is likely involved
English
1
0
2
199
Sir. M. Shade⒮🌴
Sir. M. Shade⒮🌴@0xShaedyW·
🚨 Cantina Apex is officially the top spammer in web3 security. 65 reports to MetaMask, 5 valid. 19 to Coinbase, 8 valid. 40 to Anthropic, 4 valid. 24 valid out of 167 closed: 14.37% accuracy. This is the future? A Spammertozoa?
Sir. M. Shade⒮🌴 tweet media
English
24
6
146
20.6K
chrisdior
chrisdior@chrisdior777·
left Web3. starting something more stable 🤡
chrisdior tweet media
English
14
3
140
4.2K
Shalafat
Shalafat@0xlookman·
@windhustler I believe they just didn't put in efforts to monetize. There were many ways they could monetize. They didn't just apply them
English
0
0
0
15
GiuseppeDeLaZara
GiuseppeDeLaZara@windhustler·
Immunefi Audit Comp | Firedancer V1 had 644 submissions, each costing $100. If the critical pot gets unlocked, they'll pay out $1 Million to researchers. Taking a wild guess, their cut is at least 10-15%. They'll earn $64.4k + $150k = $214.4k. How is this not a profitable business?
Patrick Collins@PatrickAlphaC

@PeatPeater2 Because contest platforms make $0

English
13
0
77
9.8K
bbl4de
bbl4de@bbl4de_xyz·
The first time I participated in a Solidity contest I was learning vector calculus at my university - I remember precisely what formulas surrounding gradients I was studying when I got the notification from Discord with the result. Now, I'm observing how contests fade-away while studying gradient descent to better understand machine learning concepts and play around with neural networks. What a ride.
English
3
0
34
1.9K
Shalafat
Shalafat@0xlookman·
But contests can not die like that, They are better than private audits security wise Because the more eyes on your code The more secure it is No other way can you get these eyes.
English
0
0
1
37
Pyro
Pyro@0x3b33·
Contests are dead, cantina killed them
Pyro tweet media
English
20
10
242
15K
chrisdior
chrisdior@chrisdior777·
Holy shit 🤯 I started my Web3 security journey on C4, and earned my first money there too. It onboarded thousands of people into Web3 security. Funny thing is that when I was starting, @cmichelio was #1 all-time. Now that C4 is sunsetting, he’s still #1. #unbeatable 👏
chrisdior tweet media
0xasen@asen_sec

🚨 CODE4RENA just announced they are shutting down End of an era for web3 security contests. Thousands of auditors built their careers there. What happens to the contest model now? Will it survive in a new form? Who absorbs the talent? Let's hear your takes

English
5
2
84
3.9K
Shalafat
Shalafat@0xlookman·
@asen_sec Everything comes to an end, but I didn't expect it to end like this
English
0
0
1
147
0xasen
0xasen@asen_sec·
🚨 CODE4RENA just announced they are shutting down End of an era for web3 security contests. Thousands of auditors built their careers there. What happens to the contest model now? Will it survive in a new form? Who absorbs the talent? Let's hear your takes
0xasen tweet media
English
18
7
121
11.3K
playboi.eth
playboi.eth@adeolRxxxx·
Hacks are happening on a steady. @code4rena just decided to wind down. What a terrific year to be in web3 security.
English
12
1
112
3.9K
pashov
pashov@pashov·
A young and smart Nigerian guy messaged me last night. Hopped on a call. He was like "Pashov Audit Group is one of a kind and all other security companies suck, I want to work with you" There definitely are other good security companies. Already working with the guy though🫡
English
16
19
167
7.5K
Shalafat
Shalafat@0xlookman·
Been engaged in a solo audit recently More details to come
English
0
0
0
10
Dacian
Dacian@DevDacian·
Looking back on this post in light of recent on-chain events, instead of finding honest work like plumbing jobless auditors turned to the dark-side by actively attempting (sometimes successfully) to exploit live protocols. Watchmen became wolves. Very sad to see.
Dacian@DevDacian

Easy money mostly gone in auditing. Many skilled auditors w/great portfolios looking for work + tons of new firms => more competitive market than ever, hence recent ambulance chasing / grave dancing. If you haven't made it already, consider pivoting to AI or learn plumbing.

English
6
0
32
3.2K
Hunter
Hunter@Huntoor·
where are those roadmap to success posters. i miss you guys.
English
7
1
32
1.8K
Shalafat
Shalafat@0xlookman·
@0xapple_ @code4rena Good luck, attorney I have a case, dm when all is done. But I will need to know results of this case, before before we can proceed
English
1
0
1
119
0xApple
0xApple@0xapple_·
10 days auditing Monetrix on @code4rena now 20 days of being a lawyer 😭 already drafting arguments for findings I know judges will try to invalidate audit ends, the real work begins at this point in contests, fighting a homicide case would've been easier 💀
English
5
1
40
1.7K
Shalafat
Shalafat@0xlookman·
Be polite, be good to people You lose nothing from being good And remember every action has a reward Good for good, bad for bad No other way
English
0
0
0
14
Shalafat
Shalafat@0xlookman·
Hey dev, hey founder, is your protocol secure? Let's secure it
English
0
0
0
16