ChainSentry retweetledi
ChainSentry
30 posts

ChainSentry
@ChainSentry
Web3 Sherlock Holmes🔍I talk about all things Web3 security🕸️||$250k+ earned via c4/Sherlock & Immuefi || I'm @kassyolisakwe
Your smart contract. Katılım Mayıs 2023
47 Takip Edilen61 Takipçiler
ChainSentry retweetledi

With @chainlink oracles being one of the most widely used oracle networks in the space.
Make sure to add this to your reading recourse list this weekend. Thanks, @DevDacian for the breakdown. 🫡
dacian.me/chainlink-orac…
English
ChainSentry retweetledi
ChainSentry retweetledi

Just finished a contest & I'm jumping straight into the next one.
I think I'm getting quite good at understanding protocols at a deeper level !
💣It's the second time in a row that I experience the following:
At 70% of contest duration I stop looking for bugs, because I don't have enough time to submit the ones I've already found ( explanations, POC, recommendations etc.)
And I'm not talking about fee-on-transfer, no-slippage and all the other superficial vulnerabilities we all know.
I'm talking about bugs that are tightly related to the logic flow of the particular protocol(the real bugs).
I feel that once you start getting deep enough, bugs start popping up like popcorn🍿. Finding one deeper nested bug unlocks something like a ⛓️chain reaction that leads to new ones.
And just when I think that I'm done and start validating and preparing my submissions, a plethora of really good questions come up that lead to new exploits.
Problem is that once I'm at the stage of submitting my findings, there is no time left to tackle these new opportunities.
P.S Since it's a recent experience that I'm having, contest results are not out yet to prove that I'm actually making quite the progress.
🎯But as far as my intuition goes, things feel VERY right
English
ChainSentry retweetledi

In 2024, we are going to witness TONS of projects built with Rust, and specifically Cosmwasm and Solana.
My favorites are those built on Injective and Kujira ecosystems. These two will be the DeFi hubs on Cosmos blockchains.
If you are security researcher, then you MUST start getting your hands dirty with Rust.
By just learning the fundamentals, you can then start diving into frameworks such as cosmwasm and anchor!
Till now, I have published two articles explaining in GREAT detail cosmwasm, while solving CTFs that address real-world scenarios.
I even encountered a similar issue, that I first found in the CTFs, in one of my recent Cosmwasm audits!
Grind away 👇👇
English
ChainSentry retweetledi
ChainSentry retweetledi

Liquidations 101
This article solely helped me find plenty of vulnerabilities
Highly recommended ✌️
blog.smlxl.io/defi-lending-c…
English
ChainSentry retweetledi
ChainSentry retweetledi
ChainSentry retweetledi

We've released over 50 new security assessment reports 🐞 📃 🎉
Targeting Solidity, Go, and Rust codebases, these security reviews have been conducted over the past 4 years for prominent projects (L1s, L2s, bridges, smart wallets, DeFi primitives, etc)
github.com/sigp/public-au…
English
ChainSentry retweetledi

tl;dr ChatGPT is great for learning code, but terrible about finding bugs.
Feels like the hype train around ChatGPT has come & gone
Pappa Pug@PappaPug
Woof woof! 🦴 Look what I dug up... A recent paper discusses the usage of ChatGPT in software security (arxiv.org/abs/2307.12488) pdf: arxiv.org/pdf/2307.12488… Here are some takeways before you read the paper:
English
ChainSentry retweetledi
ChainSentry retweetledi

So proud to see some of the Smart Contract Hacking course students slowly climb the @code4rena leaderboard 🪜
If you are new to web3 security, keep grinding and never give up! Hard work pays off 💪
English
ChainSentry retweetledi
ChainSentry retweetledi

2023 Crypto Crime Mid-year Update: Crime Down 65% Overall blog.chainalysis.com/reports/crypto…
English
ChainSentry retweetledi

#ImmunefiSecurityAlert
1/ On July 11, an exploit on @Rodeo_Finance resulted in a loss of ~472 ETH, valued at roughly ~$890,000.
This was caused by what’s known as an oracle manipulation attack.
Let’s break this hack down in a human-readable format
👇

English
ChainSentry retweetledi

Today we celebrate 6 years of #Binance!
Thank you for your extraordinary support over the last 6 years and we can't wait for what lies ahead.
Here's a message from @cz_binance to all of you for #BinanceTurns6.
English
ChainSentry retweetledi

.@binance never delisted XRP. Trading link below.
binance.com/en/trade/XRP_B…
English











