Addict
497 posts

Addict retweetledi

We have finished the smart contract audit process for @ZKForge_io🛡️
📷Check our findings and security score here:
app.solidproof.io/projects/zkfor…
Need a Smart contract audit, KYC or development support? Send us a message, our sales team will gladly make a customized offer for you!

English
Addict retweetledi

Only builders stay.
SolidProof.io Daily@solidproof_news
We have finished the smart contract audit process for @ZKForge_io🛡️ 📷Check our findings and security score here: app.solidproof.io/projects/zkfor… Need a Smart contract audit, KYC or development support? Send us a message, our sales team will gladly make a customized offer for you!
English
Addict retweetledi

@ZKForge_io @Isss175 It is already public!
Please use the link as already shared.
English
Addict retweetledi

The SolidProof audit for ZKForge is now officially complete - and all previously identified issues have been fully resolved. The final result: zero risk findings.
Throughout the process, SolidProof identified multiple issues across critical, high, medium, and low severities. After extensive fixes, verification, and refactoring:
• All Critical issues resolved
• All High issues resolved
• All Medium issues resolved
• All Low + Informational issues resolved
Security remains our highest priority, especially when building advanced zkSTARK authentication. We took every auditor comment seriously, improved the entire system, and delivered a fully remediated platform.
Final Words from SolidProof
Below is a condensed overview of SolidProof’s final assessment:
ZKForge V1 Security Re-Audit Analysis - Executive Overview
The platform implements zero-knowledge encrypted messaging using a React/TypeScript frontend, Node.js/Express backend, MongoDB, and Solana integration.
Key Security Achievements:
• zkSTARK authentication with nonce-based replay protection (5-minute TTL)
• Client-side proof generation ensures private keys never touch the backend
• Password-based encryption using PBKDF2 (100k iterations) + AES-GCM 256-bit
• Session tokens hashed with SHA-256 before storage
• CORS restricted to trusted origins via environment variables
• WebSocket authentication secured via subprotocols
• Strict Ed25519 public key validation
• Double-spend protection through safe balance validation
• Nonce reuse detection to prevent cryptographic failures
• Development-only logging for safer production behavior
• NoSQL injection prevention and strict input sanitization
• Global + endpoint-specific rate limits
Conclusion:
ZKForge V1 demonstrates strong security fundamentals with all critical and high-severity issues resolved. The zkSTARK authentication system is correctly implemented with replay protection, encryption is properly handled, CORS is secure, and frontend protections like React auto-escaping eliminate XSS vectors. Remaining notes relate only to code quality, not security.
SolidProof recommends an independent cryptographic review before massive production scale.
We appreciate the patience and trust of our community. We learned, we improved, and now we delivered.
Audit link: app.solidproof.io/projects/zkfor…

English

@GasolineShake @ZKForge_io Bro you are whipping around so hard
Consider atleast that last re audit took more than a few days?
English

The irony of your announcement:
You logged into your dormant ad account to take advantage of an exploit in our Ad Composer — to post a link that deceives users into thinking it’s a video and to artificially increase its reach.
As you may be aware, X believes everyone should have an equal voice on our platform. However, it seems you believe that the rules should not apply to your account.
Your ad account has been terminated.
European Commission@EU_Commission
Today, we fined X for non-compliance with transparency obligations under the DSA. We're holding X accountable for: 🔹Deceptive design of its ‘blue checkmark’ 🔹Lack of transparency of its advertising repository 🔹Failure to provide access to public data for researchers ↓
English

@GasolineShake @DarkShiba_Bonk I'm sticking around for a few more days waiting on Solidproof update/next revision mainly
English

@DarkShiba_Bonk @GasolineShake Although I would prefer more receipts preferably on chain verifiable. Usually that's how I go about it. Until then, I believe the upside for zkfg is just too big to ignore.
English

@DarkShiba_Bonk @GasolineShake I understand him. I've done the same. Exited a token and then kept pestering everyone trying to get them to save their funds. And I was right.
It's possible people who are too invested have tunnel vision and need an outsider pov. I've been in such positions as well
English

@keep0010 @GasolineShake @ZKForge_io you illiterate baboons
the audit got a revision its not even out
can you not fucking read
English

@GasolineShake @ZKForge_io This is a scam. The audit report has been pending for at least 10 days, and there are still issues. The app is also an empty shell with nothing
English

ZKForge Launchpad: How It Works
ZKForge Launchpad introduces a fair and transparent way to launch new Solana tokens while avoiding the steep early-phase bonding curve on pump.fun. Here is the complete process:
1. Users deposit SOL into the launchpad pool during the fundraising period.
2. The launchpad has a fixed SOL cap. Once the cap is reached, deposits close automatically.
3. All participants will receive tokens at the same unified price, instead of suffering from bonding-curve price differences on pump.fun.
4. After fundraising is complete, the launchpad automatically creates the token on pump.fun.
5. The deposited SOL is then submitted to pump.fun to push the token directly to the bonded state.
6. Once the token is bonded, the launchpad distributes tokens proportionally to every buyer based on the amount of SOL they contributed.
7. No early buyer advantage, no bot sniping, and no price variance. Everyone enters at the same price and receives a fair allocation.
This model eliminates bonding-curve manipulation, prevents unfair early entries, and allows new Solana projects to launch with equal opportunity for every participant.
English

@GasolineShake @SolidProof_io Instead of spewing a bunch of bullshit can you instead show where solidproof released the report?
English


