CredShields

1.9K posts

CredShields banner
CredShields

CredShields

@CredShields

Providing best-in-class services for all security requirements | OWASP Smart Contract Top 10 Pioneers | SOC2 Type ll Audited | Building @Solidityscan

Katılım Aralık 2021
62 Takip Edilen3.1K Takipçiler
Sabitlenmiş Tweet
CredShields
CredShields@CredShields·
CredShields and @SolidityScan are proud to contribute to the release of the @owasp Smart Contract Top 10 2026. OWASP Smart Contract Top 10 defines the primary contract-level failure patterns that repeatedly lead to loss in blockchain systems. Sincere gratitude to @ethereumfndn Ecosystem Support Program for supporting the OWASP Smart Contract Security initiative. owasp.org/www-project-sm…
CredShields tweet media
English
20
40
65
7.1K
CredShields
CredShields@CredShields·
Most people in blockchain have never heard of DAML. The institutions rebuilding financial infrastructure are using almost nothing else. DAML is the smart contract language Canton Network runs on. It's what Goldman Sachs, DTCC, and Broadridge are building with. And as trillions in real assets move on-chain, it's the environment where smart contract security matters most. This week CredShields breaks down DAML security, what makes it different, where the risks are, and what rigorous audit looks like here. Follow along. 👇
CredShields tweet media
English
0
0
1
108
CredShields
CredShields@CredShields·
@RealJohnnyTime Incident to pattern library is exactly the right mental model. Raw hack news is noise. Mapped to attack class and PoC it becomes muscle memory.
English
0
0
0
14
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
A hacks database is only useful when it changes how you review code. Make each incident actionable by mapping it to: - attack class - PoC pattern - reusable lesson for future audits Do this consistently and “hack news” becomes a practical pattern library.
English
2
1
15
821
CredShields
CredShields@CredShields·
@binji_x Decentralized protocol, centralized keys. That gap is where most exploits live.
English
0
0
0
23
binji
binji@binji_x·
decentralization is the whole point of blockchains
English
45
29
245
16.3K
Cyfrin Updraft 🟩
Cyfrin Updraft 🟩@CyfrinUpdraft·
Most reentrancy exploits follow the same pattern. External call before state update. That's it. That's the whole vulnerability. 🧵
English
5
5
53
1.9K
CredShields
CredShields@CredShields·
@ddimitrovv22 The best audit workflows right now use AI for the low hanging fruit and free up human hours for the complex logic nobody else is looking at.
English
0
0
0
15
ddimitrov22
ddimitrov22@ddimitrovv22·
Things AI Audit agents are good at: - finding leads - checking math and rounding errors - clearing all low-hanging bugs Things AI Audit agents are bad at: - coverage - finding complex business logic bugs - many false positives that sound convincing
English
6
6
38
1.8K
Imparableub , integra )✣(
Imparableub , integra )✣(@imparableub·
Happy New Month Anons!🌞 If you're into #Web3, set realistic targets & stay informed If you're into #Crypto, stay calm & be patient If you're into #Web3Security, take a look at OWASP Smart Contract Top 10 overview by @CredShields. This is my lil advice for y'all this month.🤝
Imparableub , integra )✣( tweet media
English
7
1
24
544
Firepan
Firepan@FirepanHQ·
The OWASP Smart Contract Top 10 for 2026 is out. Access control flaws alone caused $953M in losses. If you're building on-chain and not running automated security scans, you're gambling with user funds. Don't be the next case study.
Firepan tweet media
English
2
0
2
49
CredShields
CredShields@CredShields·
@cuechain667221 Appreciate you highlighting the OWASP 2026 framework and the need for security-first development.
English
1
0
1
7
Cuechain
Cuechain@cuechain667221·
🚨 Smart Contract Security Is Now a Top Priority The OWASP Smart Contract Top 10 (2026) reveals real vulnerabilities already exploited across DeFi and blockchain protocols. With billions in digital assets at stake, security-first development is no longer optional. #Web3
Cuechain tweet media
English
2
1
5
106
Nobleini
Nobleini@nobleini47498·
Most smart contract hacks aren’t magic, they’re the same mistakes repeating themselves. That’s exactly why the OWASP Top 10 Smart Contracts exists; to highlight the risks projects keep overlooking.
Nobleini tweet media
English
5
4
25
270
CredShields
CredShields@CredShields·
@cyfrin Appreciate the mention and your strong perspective on evolving Web3 threat models.
English
0
0
0
10
Cyfrin Audits
Cyfrin Audits@cyfrin·
The OWASP Smart Contract Top 10 2026 dropped yesterday. The headline finding: governance manipulation, multisig compromise, and supply chain exposure caused more losses in 2025 than any category of code bug. Security isn't just about your contracts anymore.
English
3
3
15
1.2K
CredShields
CredShields@CredShields·
@HYDNSecurity Great breakdown of the OWASP 2026 changes, especially the shift toward systemic risks.
English
0
0
1
10
HYDN - Cybersecurity Experts
HYDN - Cybersecurity Experts@HYDNSecurity·
OWASP just dropped the Smart Contract Top 10 for 2026. The changes between this year and last tell you more than the list itself. Here's what moved, what's new, what got cut and what it means. 🧵
HYDN - Cybersecurity Experts tweet media
English
2
0
3
60
CredShields
CredShields@CredShields·
Team CredShields will be at @ParisBlockWeek, where digital assets meet institutional adoption, on April 15 & 16, 2026 at the Carrousel du Louvre, Paris. Building at the intersection of finance and Web3? Security is where it starts. Let's connect.
CredShields tweet media
English
0
2
3
131
CredShields
CredShields@CredShields·
@WStaking_net @RouniyarAdarshh 8/ Key Takeaway In the next cycle, yields will win short-term. But the protocols that last will be the ones where users can actually see where yield comes from. Verifiability is not a feature. It is what #DeFi survival looks like.
English
1
0
0
20