zpan
120 posts


Yeay, I was awarded for my first valid submission on
@HackenProof
hackenproof.com #hackenproofed #bugbounty

English
zpan retweetledi

Today I am releasing IsItVulnerable: a new tool I’ve been working on for the past several months:
github.com/montyly/isItVu…
It builds on recent LLM progress and over a decade of experience building security tools. I developed a new technique that combines abstract interpretation with machine learning
The key insight is that this method abstracts the intelligence away entirely. I call it Abstract Intelligence, or AI
The result is a major breakthrough in program analysis: IsItVulnerable finds all bugs with 100% recall
Yes, all bugs. Fully guaranteed
I have tested it extensively, and it has never failed. The results are honestly incredible
April 1, 2026 marks a turning point for security, and the industry will never be the same
My DMs are open for investors. Entry ticket starts at $500k.
English
zpan retweetledi
zpan retweetledi

Are AI agents ready for detecting and exploiting smart contract vulnerabilities?
We re-evaluated @OpenAI's EVMbench with a contamination-free dataset of real-world hacks.
Our data shows different results. 🧵
Paper: arxiv.org/abs/2603.10795
OpenAI@OpenAI
Introducing EVMbench—a new benchmark that measures how well AI agents can detect, exploit, and patch high-severity smart contract vulnerabilities. openai.com/index/introduc…
English
zpan retweetledi

Ever since launched, people have been “recharging” , but it’s all my buddies 😂
So of course I refunded every single one of them… and topped their accounts up with a spicy $99,999 bonus.
Now they actually want to withdraw it, like, bro....
BradMoon@xy9301
Due to cost considerations, the paid mode is currently enabled. You must make a payment to use txanalyzer.xyz/payments. 哪位有钱的把它买走 Which rich person wants to buy it?
English

Paradigm 和 Openai 合作合作开发了一个名为 EVMbench 的 EVM 合约漏洞检测框架😲可对漏洞进行检查、修复和利用
paradigm.xyz/2026/02/evmben…
中文
zpan retweetledi
zpan retweetledi

@shredscrt The PDA seed uses a user-controllable `user_name` instead of `user.key()`, allowing anyone to preemptively create a vault for any username, resulting in a lack of ownership binding.
English

We’re launching a bug-hunting challenge series for EVM(in Solidity mainly), Solana and Blockchain related vulnerabilities.
Challenge #1: Can you spot the bug in this code?

English

Holiday season is here, and we @taichiaudit are starting a DeFi source code walkthrough campaign: one article every 1–2 days, from now until the end of January 2026. If you're a dev or security researcher leveling up in the bear market, this is for you.
English

@ret2basic @ustas_eth @CertiK 要穿唐装用中文说
China is my second homeland, and I feel I'm Chinese at heart!
中文

I am starting a 100 days challenge, building my web3 security portfolio in public until my dream company @CertiK hires me.
📅Day 001/100, I saw CertiK team doing suidex contest on hackenproof real-time leaderboard, so I am doing it as well. Let's hunt down some bugs!🫡
English









