riptide

4.3K posts

riptide banner
riptide

riptide

@0xriptide

deep in your storage slots host of @bountyhunt3rz podcast/substack | cofounder @therealgregoai ranked top 50 on @immunefi https://t.co/vWgt74l17W

LIFE ... on the blockchain Katılım Eylül 2011
2.9K Takip Edilen9K Takipçiler
Sabitlenmiş Tweet
riptide
riptide@0xriptide·
🚨 Welcome Bug Hunter! 🚨 bountyhunt3rzdeclassified.substack.com/p/welcome-bug-… @bountyhunt3rz just launched a juicy substack (join the discord for a humble discount) for all the bug hunters out there (including the pros) ... BOUNTYHUNT3RZ: DECLASSIFIED I have a unique insight into how to find bugs among the millions of smart contracts deployed across hundreds of blockchains My objective is to guide and assist you in finding your next critical bug that pays you millions of dollars Whether you are an experienced security researcher or just getting started, I hope to provide you with information that does not exist elsewhere and that can help you on your bug hunting quest Featuring ... OBSERVATIONS FROM THE BLOCKCHAIN I read hundreds of contracts each month and notice patterns, commonalities, trends, bugs, etc. I will summarize and share my notes and observations of value to help you think creatively and find new types of bugs or emerging bug patterns. WHERE'S RIPTIDE? Everyone asks: Which chain should I look on? What project? What type of project? How do I know where to look? I will show you where i'm looking and share my rationale for doing so. Every bug hunter will view things in a different lens, so the information I provide should get your synapses firing to dream up some unique scenarios to exploit. THE GLENGARRY LEADS I will share my private notes of live targets, contract addresses, github, etc. with any accompanying tests or due diligence I have performed and why I recommend you spend some time trying to bug hunt on these protocols. You may identify something that I missed (it happens to every researcher) and hopefully it leads to a monster multi-million dollar bug find for you ...
English
6
6
61
16.4K
riptide retweetledi
Wonderland
Wonderland@Wonderland·
Wonderland CTF prizes are in: $30,000 on the line. $15k, $10k & $5k for the top 3. Plus a few surprises. May the best teams win.
Wonderland tweet media
English
12
25
120
13.6K
riptide
riptide@0xriptide·
13:51 ristretto 20 pull ups back to the blockchain
English
3
0
18
839
riptide
riptide@0xriptide·
@xKeywordx ofc pull up comp in cannes if you're in
English
2
0
7
131
riptide
riptide@0xriptide·
Comedy gold 🥇
Grug 🪨@grugcapital

I was farming airdrops and reading the Ethereum yellow paper in the front seat of my Uniswap police cruiser when a ping came in. It was the chief. “Bad news, detective. We got a situation.” What? Did Solana go down again?” “Worse. Somebody just launched another layer-2.” The hardware wallet practically fell out of my hand. “My God. How many do we have now?” “Hard to say. Every time we count them, three more appear funded by a16z & Paradigm.” I lit a cigarette and refreshed the mempool. “What’s the damage?” “Billions in venture funding. Thousands of tweets about ‘Ethereum scaling.’ A whitepaper written entirely in diagrams of arrows pointing at other arrows.” “Do we have any leads?” “Only that the founders used to work at Coinbase.” I shook my head. “Typical.” “Listen,” the chief said. “We’re going to track this thing down and shut it off before it launches a token.” “Easy, chief,” I said. “Tokens are the foundation of the modern startup business model.” He sighed. “Just get down there and see what you can find.” Ten minutes later I was at the scene: a co-working space filled with beanbags, venture capitalists, and a giant TV displaying a dashboard that just said “TPS.” “Coinbase™ Presents The Police!®” I yelled, flashing my badge, my hardware wallet, and a laminated screenshot of Vitalik. “Nobody pivot unless you want to!” They didn’t. “All right,” I said. “Which one of you punks launched the new rollup?” A man wearing a hoodie that said “Zero Knowledge, Zero Revenue” slowly raised his hand. “It’s not a rollup,” he said nervously. “It’s a modular settlement-availability execution layer.” I squinted at him. “That’s a rollup.” The room murmured. “Listen,” I said. “Without a strong economic incentive, I’m not investigating anything. Are you people going to pay me?” A venture capitalist stood up. “We can offer you an allocation in the seed round.” “I don’t work for equity,” I said. “I work for tokens that unlock in eighteen months and immediately go to zero.” Just then an intern ran in. “Detective! The protocol just hit a billion dollar valuation!” “Already?” I asked. “We haven’t launched anything yet.” “Of course not,” I said. “That would be irresponsible.” Suddenly the founder made a break for the door. “Paradigm™ Freeze, Scumbag!®” I yelled. Too late. He was already halfway down the hallway tweeting “gm.” I chased him. “Stop right there!” I shouted. “You can’t keep launching infrastructure companies that only exist to make other infrastructure companies slightly more complicated!” He turned around. In his hand was a pitch deck. He fired. I ducked as a slide titled “The Future of Decentralized Modular Interoperability” whizzed past my head. “All right!” he yelled. “I confess! I built the protocol!” “Why’d you do it?” I asked, slapping a pair of Ledger™ Hardware Handcuffs® on him. “Because I was afraid.” “Afraid?” “Afraid there might be only twelve crypto infrastructure startups instead of thirteen.” I nodded slowly. Years ago, a man like this rugged my partner with an NFT project called Pixel Apes but With Hats. I looked him dead in the eye. “Listen carefully,” I said. “No matter how many rollups you launch, no matter how many seed rounds you raise, you will never destroy the dream of a decentralized financial system.” He lowered his head. “You’re right,” he said quietly. Then a venture capitalist walked up and handed me a term sheet. “Good work, detective,” he said. “We’d like to lead your next round.” I signed it immediately.

English
3
0
9
1.7K
riptide
riptide@0xriptide·
Now this is a public good
@levelsio@levelsio

✨ 7 years after I set up a Quake III server, I have it running again, but now in the web browser, much easier 😊 👉 q3.pieter.com 👈 Back in 2019 we'd play a fork of Quake III called OpenArena in a Bali villa with @daniellockyer @marckohlbrugge @dannypostmaa @lenilsonjr_ @gvrizzo @AndreyAzimov @SeanParkRoss and other ppl But it broke after a new Mac update and they never really fixed it, it kinda sucked because it was actually the only game we could just load with friends online and play death match a bit and then continue your day Luckily @lukathedev built Q3JS which successfully compiles ioquake3 to WebAssembly and now it works in the browser To make it extra simple, I've set up a Q3JS server and frontend for you to use at q3.pieter.com, which loads you straight into the game A big problem is that most of the times, nobody's playing, so I've also added Web Notifications, which notifies you if enough human players join, so you can join a match. And I've added a daily match at 8 PM GMT every day which everyone also gets notified when it starts If you want more servers and maps etc, you can check out @lukathedev's own q3js.com HAPPY FRAGGING

English
1
0
5
1.5K
riptide retweetledi
@levelsio
@levelsio@levelsio·
✨ 7 years after I set up a Quake III server, I have it running again, but now in the web browser, much easier 😊 👉 q3.pieter.com 👈 Back in 2019 we'd play a fork of Quake III called OpenArena in a Bali villa with @daniellockyer @marckohlbrugge @dannypostmaa @lenilsonjr_ @gvrizzo @AndreyAzimov @SeanParkRoss and other ppl But it broke after a new Mac update and they never really fixed it, it kinda sucked because it was actually the only game we could just load with friends online and play death match a bit and then continue your day Luckily @lukathedev built Q3JS which successfully compiles ioquake3 to WebAssembly and now it works in the browser To make it extra simple, I've set up a Q3JS server and frontend for you to use at q3.pieter.com, which loads you straight into the game A big problem is that most of the times, nobody's playing, so I've also added Web Notifications, which notifies you if enough human players join, so you can join a match. And I've added a daily match at 8 PM GMT every day which everyone also gets notified when it starts If you want more servers and maps etc, you can check out @lukathedev's own q3js.com HAPPY FRAGGING
@levelsio@levelsio

🔫 I set up an OpenArena DM server (free version of Q3), if you wanna join: server is 128.199.152.194, download OpenArena for Win/Mac/Linux @ openarena.ws

English
63
23
407
294K
@levelsio
@levelsio@levelsio·
Ok I set max players to 32 now q3.pieter.com Pure chaos :DDD
@levelsio@levelsio

✨ 7 years after I set up a Quake III server, I have it running again, but now in the web browser, much easier 😊 👉 q3.pieter.com 👈 Back in 2019 we'd play a fork of Quake III called OpenArena in a Bali villa with @daniellockyer @marckohlbrugge @dannypostmaa @lenilsonjr_ @gvrizzo @AndreyAzimov @SeanParkRoss and other ppl But it broke after a new Mac update and they never really fixed it, it kinda sucked because it was actually the only game we could just load with friends online and play death match a bit and then continue your day Luckily @lukathedev built Q3JS which successfully compiles ioquake3 to WebAssembly and now it works in the browser To make it extra simple, I've set up a Q3JS server and frontend for you to use at q3.pieter.com, which loads you straight into the game A big problem is that most of the times, nobody's playing, so I've also added Web Notifications, which notifies you if enough human players join, so you can join a match. And I've added a daily match at 8 PM GMT every day which everyone also gets notified when it starts If you want more servers and maps etc, you can check out @lukathedev's own q3js.com HAPPY FRAGGING

English
120
53
844
290.4K
riptide
riptide@0xriptide·
@pashov did not think nigeria was a whitehat hotspot until i checked @bountyhunt3rz podcast stats pashov on the cutting edge
riptide tweet media
English
8
2
42
1.4K
riptide retweetledi
f4lc0n
f4lc0n@al_f4lc0n·
I Saved Injective's $500M. They Pay Me $50K. I like hunting bugs on @immunefi . I'm decent at it. - #1 — Attackathon | Stacks - #2 — Attackathon | Stacks II - #1 — Attackathon | XRPL Lending Protocol - 1 Critical and 1 High from bug bounties (not counting this one) Life was good. Then I found a Critical vulnerability in @injective . This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk. I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity. Then — silence. For 3 months. No follow up. No technical discussion. Nothing. A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either. I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten. I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible — until Injective pays what I deserve. Full Technical Report: github.com/injective-wall…
English
518
526
4.5K
1.8M
riptide retweetledi
Academy of Ideas
Academy of Ideas@academyofideas·
Nietzsche on the danger of waiting too long to start living.
Academy of Ideas tweet media
English
11
332
2.6K
56.5K