Antics Decoded

975 posts

Antics Decoded banner
Antics Decoded

Antics Decoded

@AnticsDecoded

Security Researcher Rust, Solidity, C++, Go

Katılım Nisan 2024
5 Takip Edilen381 Takipçiler
0K
0K@ZeroK_____·
I built AI, and it passed a test I gave it, it found 3 out of 4 bugs that I already knew existed. Thinking a bit like a blackhat, it’s around 90% automated and 10% guided by me. No hype for now, it’s way too early to celebrate such a small success. But I genuinely hope I’m building something that can help prevent even 0.1% of the hacks happening today. If it works the way I want, I’ll share the full process and everything I learned along the way. If I win, all of you here should win too. We’re fighting blackhats, not each other. Don’t be too optimistic about this post(yet!) 😄 I just enjoy sharing small progress with the community.
English
6
0
46
1.6K
Antics Decoded
Antics Decoded@AnticsDecoded·
@dersonxyz But I think the max credits stated should be the exact amount used to run a scan
English
1
0
0
54
Jeff Security
Jeff Security@jeffsecurity·
If you're crossing from web2 sec into web3 (or vice versa), this repo is gold. Hundreds of bug bounty writeups grouped by class - IDOR, race conditions, RCE, SSRF, auth bypass. github.com/devanshbatham/…
English
1
2
30
1K
Antics Decoded
Antics Decoded@AnticsDecoded·
@DevDacian @cyfrin That’s great Is solace open source and can it audit large complex Blockchain/DLT codebases?
English
0
0
0
74
Dacian
Dacian@DevDacian·
Beautiful composite exploit found by my AI Solace in @cyfrin private audit. Solace automagically chained together 3 individual component findings into a devastating critical drain attack 🚀 solodit.cyfrin.io/issues/onchain…
Dacian tweet media
English
2
1
52
2.1K
Antics Decoded
Antics Decoded@AnticsDecoded·
@zooko Ok Thank you!! And please also I’d like to confirm… are the rewards stated there the exact amount given to a researcher that gets a confirmed finding? For example, if I find and submit a critical vulnerability under the core nodes, do I receive $225,000 (Base payout & Bonus)
English
0
0
0
15
Antics Decoded
Antics Decoded@AnticsDecoded·
@zooko Yes i have seen that already but that is not the confusion i am talking about. The confusion actually comes between the security researcher and the project reviewers/triagers. Some of the assets stated there like librustzcash isn't even aware of this
English
1
0
1
11
Derson
Derson@dersonxyz·
Using @hakiraio AI, I was able to earn $15,000 from multiple bug bounty programs. If you want to save time and discover real vulnerabilities in smart contracts and web applications, this tool is built for you.
Derson tweet media
English
3
4
102
5.2K
Essential
Essential@only01Essential·
Another project saved 🙌 A chain halt bug this time. $4,000 for the disclosure. Expected more, but we move
Essential tweet media
English
29
1
251
8K
Antics Decoded
Antics Decoded@AnticsDecoded·
It will eventually be crazily worth the sleepless nights, just keep at it... See you at the top :)))
English
2
2
7
225
Antics Decoded
Antics Decoded@AnticsDecoded·
@arsen_bt This is more than gold and i can even use it better in training my LLms
English
0
0
0
36
Arsen
Arsen@arsen_bt·
4 questions I ask for every finding I miss. After every contest, I revisit what I missed. • Why did I miss it? • What thinking led me somewhere else? • Was I too shallow, or looking at the wrong thing? • What pattern am I now aware of? Your findings library grows. Your miss library grows faster. A year of this and you see patterns nobody else does.
English
4
5
46
1.5K
Antics Decoded
Antics Decoded@AnticsDecoded·
@gosasu1 @Zcash Which LLM did you make use of or which tools? We could talk via private DM I also submitted vulnerabilities to Zebra
English
1
0
0
213
Revofusion
Revofusion@revofusion·
@hrkrshnn Kind of funny that formal verification has become a magic tool. It only proves what you say it proves, its not that far from invariant testing.
English
2
0
4
262
quasar
quasar@quasar249·
Firedancer v1.0 audit contest, 3 days left. Several BHM issues, all turned out to be already patched in upstream - so ineligible as duplicates. Still fuzzing.
English
3
0
14
1.5K
Antics Decoded
Antics Decoded@AnticsDecoded·
@hrkrshnn --dangerously-skip-permissions let me see if i could be the next black hat 👿
English
0
0
1
110
Hari
Hari@hrkrshnn·
If you believe human in the loop is the future of AI, what config do you run Claude? 1. It asks permissions for everything; I approve all runs 2. --dangerously-skip-permissions
English
11
0
10
2.5K
Antics Decoded
Antics Decoded@AnticsDecoded·
@pashov Yes definitely a good thing I would use it on new contracts and save more protocols from hacks
English
1
0
4
355
pashov
pashov@pashov·
What if we open source pashov/skills solidity-auditor v3 that is better than most paid solutions and it can find Criticals left and right? Is this a good thing? What do you think
English
30
4
162
6.9K