My sister

34 posts

My sister

My sister

@Goodproject0

I have been working in blockchain for exactly three years

Solana Beach, CA Katılım Ağustos 2024
4 Takip Edilen20 Takipçiler
Sabitlenmiş Tweet
My sister
My sister@Goodproject0·
Solana Seazon Giveaway 4 lucky degenz get $25 SOL each How to ape in: - Smash follow + turn on notis - RT + Like cuz u ain’t broke - Tag 2 frens & drop ur addy in replies Don’t fade the szn. WAGMI or NGMI.
My sister tweet media
English
10
6
8
400
My sister
My sister@Goodproject0·
@toly I haven't followed you, why do you keep recommending your posts to me?
English
0
0
0
8
toly 🇺🇸
toly 🇺🇸@toly·
What group are you? A) AGI is near, QC breakthrough is near B) AGI is far, QC breakthrough is near C) AGI is near, QC breakthrough is far D) AGI is far, QC breakthrough is far
English
44
3
53
12.6K
Sam
Sam@samgoody1220·
@PERK_FUND @MeClaudeDEV @grok If you look back at all your posts you will see me in most of them defending the project against haters and fudders. And today is only day I asked for boost because of the huge price drop!!!
English
1
0
0
20
My sister retweetledi
PERK
PERK@PERK_FUND·
Well said 👏👏
English
7
12
42
2.3K
My sister retweetledi
fabino.sol
fabino.sol@OwlinOne_fun·
He is the one who always dig every project very deeply!! @toly follows him .
English
0
4
16
562
My sister retweetledi
eXonyte
eXonyte@tradingrealmfx·
$PERK ... built different, kudos to this team.. a rare thing to see lately! F8Pz2mx7V8exRkBNFzvpkZAwjNPxWPGqzYJL2ckrpump
English
0
3
19
436
My sister retweetledi
PERK
PERK@PERK_FUND·
I know some communities out there like to dog on us for being the only product live on mainnet, but here's what one round of automated security review found on a competitor's codebase It goes to show this is not an easy product to develop. Perpetual futures protocols are among the most complex DeFi primitives to build correctly. Here's a sample of what we found: 🔴 CRITICAL: Circuit Breaker Only Exists Off Chain The price movement safety check only runs in the keeper bot (TypeScript). The on chain program accepts ANY price from the authority keypair. Compromised key = unlimited price manipulation = full vault drain. There is no on chain enforcement by default. 🔴 CRITICAL: Engine State Returns Garbage Data on Mainnet - The market discovery parser hardcodes field offsets for one slab version but also processes mainnet and devnet slabs with completely different layouts. Every engine field (total OI, funding rate, mark price, liquidation cursors) reads from wrong memory offsets. The UI/keeper/cranker all operate on corrupted data. 🔴 CRITICAL: Admin Secret Length Leaked via Timing The admin authentication for the circuit breaker endpoint leaks the LENGTH of the API secret through timing side channels. Attacker discovers length first, then brute forces character by character. 🟠 HIGH: Zero Fee Exploit via Dust Trades Trading fee uses floor division. When notional × feeBps < 10000, fee = 0. Split a $1M trade into thousands of micro trades, each paying zero fees. Ironically their dynamic fee function correctly uses ceiling division. Inconsistency between the two. 🟠 HIGH: Fee Split Has No Sum Validation No check that LP + protocol + creator fee shares equal 100%. If they sum to less, the creator silently absorbs the gap. Example: configure 20% + 20% + 10% = 50%. Creator quietly takes the other 50% of all fees. 🟠 HIGH: Chainlink Oracle Has No Staleness Check Reads the latest price answer but never reads the timestamp. A feed that hasn't updated in days still returns a "valid" price. The OraclePrice interface doesn't even have a timestamp field, making it structurally impossible to check downstream. 🟠 HIGH: External Price APIs Trusted Without Cross Validation - DexScreener, Jupiter, and Pyth prices are fetched over HTTPS with zero response integrity checks. Returns the highest confidence source without comparing against other sources. DNS hijack on one API = arbitrary price injection. 🟠 HIGH: Keeper Registration Allows Arbitrary Mint Injection - An authorized caller can set any token mint address for any existing market. The oracle keeper then fetches prices for the WRONG token. No validation that the mint matches the original market. 🟠 HIGH: Solana Account Owner Never Checked fetchSlab() returns raw account data without verifying the owner matches the program ID. Attacker creates a fake account with valid magic bytes + crafted slab data. Any off chain consumer trusts the forged market state. 🟠 HIGH: Pyth Feed ID Parsing Inconsistency One function strips the 0x prefix from hex feed IDs. The sibling function doesn't. Wrong PDA derived = oracle reads fail = potential fallback to stale alternative oracle. 🟠 HIGH: Private Key Stored in localStorage Slab rent keypair secret stored in plaintext localStorage. Any XSS vector = immediate key theft. 🟠 HIGH: Rate Limiter Fails Open If the database has a connectivity blip, the faucet rate gate fails OPEN instead of closed. Trigger DB errors = unlimited minting. 🟠 HIGH: EMA Circuit Breaker Scales Linearly With Time - The price cap grows linearly with the number of slots since last crank. If no crank for a few days, circuit breaker allows 10,000%+ price swings in a single update. Alpha also clamps to 100% for large gaps meaning the EMA completely discards previous price and jumps to the new one. 🟡 MEDIUM: Fee Split Rounding Always Favors Creator LP and protocol shares use floor division. Creator gets the remainder. Even with creator set to 0%, creator receives 1 unit on every odd fee. Over millions of trades this adds up. 🟡 MEDIUM: Stale Oracle Fallback Has No Timestamp Gate When the keeper goes down, code falls back to lastEffectivePriceE6 which could be hours old. UI shows a staleness warning but nothing actually blocks trades at the stale price. 🟡 MEDIUM: Admin Middleware Doesn't Check Admin Users Table Auth middleware exists but doesn't verify against the actual admin users list. Pattern without substance. This was one round of review on a public repo. No manual exploitation, no fuzzing, no formal verification. Just reading the code. Building a perpetual futures protocol that doesn't lose user funds is genuinely hard. We take it seriously because we've seen what happens when you don't. 🫡
English
8
21
62
9.9K
My sister retweetledi
Akiza Crypto
Akiza Crypto@AkizaCrypto·
If you read this and you're not ULTRA bullish on $perk then your reading comprehension sucks Insane Incentive to use the platform - more (new) users - more volume - new pairs - incentive to promote pairs and trading (refs) More Users == AMAZING x.com/PERK_FUND/stat…
English
1
3
18
728
My sister retweetledi
PERK
PERK@PERK_FUND·
Season 1 is live tomorrow. 50,000,000 $PERK up for grabs. 5% of total supply. 30 days. How to earn: ⚡ Trade — 5 points per $1 in volume 🔗 Refer — 1 point per $1 your referrals trade 🏗 Create a market — 1,000 points 🎯 First trade — 500 point bonus 🔥 Daily streak — 2x multiplier for consecutive days Every market on Perk is permissionless. Create one for any SPL token and earn 10% of fees on that market forever. Points will determine your share of the prize pool! Points page is live now → perk.fund/points
English
24
32
107
11.8K
My sister retweetledi
eXonyte
eXonyte@tradingrealmfx·
A rare REAL Utility Coin Project that came in hot yesterday with a slick stealth luanch WITH a WORKING Product that puts all the rest to shame! $PERK FAST on the updates and SUPER responsive on fixing reports of bugs/errors.. my current long term play right now! F8Pz2mx7V8exRkBNFzvpkZAwjNPxWPGqzYJL2ckrpump
English
0
2
16
410
My sister retweetledi
PERK
PERK@PERK_FUND·
Welcome to Perk Nation. You're early to the first fully permissionless perpetual futures DEX on Solana. Anyone can create a leveraged trading market for any token and earn 10% of fees forever. What you need to know: Trade: perk.fund 📄 Docs: docs.perk.fund 💻 Code: github.com/kai-builds-ai/… 🪙 CA: F8Pz2mx7V8exRkBNFzvpkZAwjNPxWPGqzYJL2ckrpump Rules are simple: no spam, no scam links, don't be weird. Everything else is fair game. If you have questions about trading, creating markets, or building on the SDK, ask here. We read everything. Let's build.
English
22
35
134
42.4K
My sister
My sister@Goodproject0·
Everyone get active, right? Let's talk
English
1
0
7
179
My sister
My sister@Goodproject0·
That's right, I've already bought quite a few. Not sold for less than 1 million
English
0
0
9
216
霖
@weibaofu8·
@MyCrypt0world keep building ,more imformation about project , not stop boss , more people interest in X ,not just pump video. let CA in your bio , the price will keep moving high
English
1
0
1
48