Siri

730 posts

Siri banner
Siri

Siri

@CodingSirius

Katılım Eylül 2020
111 Takip Edilen53 Takipçiler
Siri
Siri@CodingSirius·
@pashov Thanks for the insight Pashov, godspeed!
English
0
0
1
39
pashov
pashov@pashov·
@CodingSirius Just check out coinmarketcap sir This space is growing, so security demand grows with it as well
English
1
0
0
51
pashov
pashov@pashov·
If you are a web3 security company/auditor and you are not close to being fully booked and crushing records this month you are probably doing it wrong or not working hard enough Everybody I know in this space is blowing up right now, good time to say "I told you so"✌️
English
8
3
110
6.8K
Siri
Siri@CodingSirius·
@pashov Care to elaborate why? Being in the field so deep now, you surely know some things we don't.
English
1
0
0
40
MackenzieM 🛠️
MackenzieM 🛠️@0xMackenzieM·
@CodingSirius @MitchellAmador Making sure projects pay for valid bugs is our bread & butter 👍 Project ghosting and disputes do inevitably come up, but a lot of our work is taking care of whitehats in these situations We got fresh news on how we're innovating even better ways to do it coming out
English
1
0
1
63
Mitchell Amador
Mitchell Amador@MitchellAmador·
Just a reminder that Immunefi has had a mandatory PoC policy for… 3 years now. Why a competitor is claiming this is an ‘industry-first’, when it’s a long implemented Immunefi standard, you’ll have to judge for yourself.
GIF
English
3
2
28
1.5K
Siri
Siri@CodingSirius·
@MitchellAmador What I mean is, if a protocol is listed on Immunefi, and a valid bug is found and confirmed by Immunefi too, they shouldn't have the option to not to pay.
English
0
0
1
44
Siri
Siri@CodingSirius·
@MitchellAmador Hi Mitchell, while I appreciate Immunefi a lot, I think it would be better to spend time on making sure that the protocols on Immunefi actually always pay for valid bugs. I've been seeing on my timeline ppl talking about getting ghosted by protocols and Immunefi can't do anything
English
2
0
3
163
Siri
Siri@CodingSirius·
You might be talking to a bot.
English
0
1
3
47
Siri
Siri@CodingSirius·
@0x3b33 That's some serious stuff mate, thanks for answering. Wishing you the best💪
English
0
0
1
25
Pyro
Pyro@0x3b33·
@CodingSirius I don't track them, but would guess 8-10, with chill days around 4-6. Where about 50% is hard focus and the rest is just normal auditing and writing reports.
English
1
0
1
91
Pyro
Pyro@0x3b33·
💥Lessons learned - Sentiment💥 Short summary: 🐛 Found: 4M 🕐 Time spent: 6 days 💰Results: 245 USD TL;DR - You don't need to be focused all the time This audit was again one of my experiments, taking concepts to an extreme just to see what leverage they have. The one I had here is to audit only under hard focus. Which meant I audited only 4-5 hours a day... The bad side is that I had little to no time to do much reviewing and thinking and only expanded on the basic leads found on the first pass. The only positive is that I found a few solo vulnerabilities, that were valid, but due to the rules and the large amount of high impact bugs were deemed invalid. For now I can suggest to keep it 50/50 hard/low focus. Overall it was a negative experience, but it helped me get to another one, which might have turned out pretty well.
English
4
0
56
3.3K
Siri retweetledi
Cyfrin CodeHawks
Cyfrin CodeHawks@CodeHawks·
Announcing First Flight #27: Trick or Treat! nSLOC: 109 Start date: October 24, 2024 Noon UTC Duration: 1 week Get real auditing experience! Check it out! 👇 (1/2)
Cyfrin CodeHawks tweet media
English
3
4
25
1.6K
Siri
Siri@CodingSirius·
@GalloDaSballo Hi Alex, thank you for onebugperday, but I have a feedback: Currently it is NOT possible to unsubscribe from the email list, because the confirmation code never shows up. I needed to block and mute the address from the account I want to unsubscribe...
English
1
0
0
11
Siri
Siri@CodingSirius·
Also I was wondering why platforms like Sherlock or Codehawks had a field for deposit address even though you were already connecting via your browser wallet. That's why I guess.
English
0
0
0
20
Siri
Siri@CodingSirius·
Be paranoid, then, more paranoid. Do not keep anything in your hot wallet, yes, use a multisig, yes, I'll check gnosis safe.
English
1
0
0
37
Siri
Siri@CodingSirius·
You know how you need to be very careful with your Metamask wallet seed phrase, that you need to write it down somewhere safe and if you lose it, you'll -supposedly- lose access to your funds forever? Well, I just found out that it is not the case at all.
English
3
0
1
94
Siri retweetledi
SHERLOCK
SHERLOCK@sherlockdefi·
🚨 New contest: Rumpel Point Tokenization Protocol @RumpelLabs 🚨 Sign up here: audits.sherlock.xyz/contests/494 Total Rewards: 16,000 USDC nSLOC: 498 Lead Senior Watson: @0xSimao Starts Monday, August 26th at 15:00 UTC Check it out!!
GIF
English
0
3
10
6.6K