HHK

647 posts

HHK

HHK

@HHK_eth

fr/en - independant security researcher, mostly @yauditdao, contractor @EnigmadarkLabs and @zenith256 - contact: [email protected]

Katılım Şubat 2021
752 Takip Edilen660 Takipçiler
HHK retweetledi
yAudit
yAudit@yAuditDAO·
Maybe you heard: we're yAudit again
English
12
12
89
22.1K
HHK retweetledi
yAudit
yAudit@yAuditDAO·
yAudit is BACK It's an annual tradition for us to rebrand, but this year is different: we're re-rebranding. We're yAudit, no longer electisec. More updates coming soon!
yAudit tweet media
English
9
11
67
9.8K
HHK retweetledi
corn🛸
corn🛸@omgcorn·
Do YOU need an estimate for an audit but you only have like 15 minutes and you want to get it right meow? quoteplz.com Public codebases don't need a token Private codebases follow ze stuff:
corn🛸 tweet media
English
1
4
12
1.8K
HHK retweetledi
yAudit
yAudit@yAuditDAO·
@Electisec 🤝 @Optimism Proud to announce we're now whitelisted as a Superchain Audit Service Provider! This means projects building on Superchain can access subsidized audits through the Foundation's grant program. Excited to help secure the ecosystem we believe in!
English
2
2
16
717
HHK retweetledi
twyne
twyne@twynexyz·
Your favorite lending market has 2 core problems. Today, we kill both of them. Twyne is LIVE on Ethereum mainnet. 🧵
English
57
57
276
74.6K
HHK retweetledi
Georgios Konstantopoulos
Georgios Konstantopoulos@gakonst·
I'm still baffled that the Ethereum Core Dev community does not prioritize fixing the 2 most cited problem of EVM developers per the Solidity Lang survey despite our repeated efforts: 1. Stack too Deep: yes this is a Solidity skill issue a little bit but just add a SWAP/DUP17-32 opcode range and call it a day. You will burn some opcodes. It's fine, they are meant to be used. You're gonna have another PUSH0-style mismatch, this is also fine, it's not perfect but it's fine. 2. Lift the 24KB limit. I don't really care what you do, make it 32KB, 48KB, 128KB, 256KB, 512KB, do it all at once, incrementally, price it or not but do something! Now, not next year! If you are scaling the L1, ensuring people can write contracts without stupid errors is P0. If the system cannot handle an extra 8KB per bytecode which is a param that was set 10yrs ago literally then there's no chance you will be able to actually scale the L1. Fix stack too deep and bytecode size limit! For the devs!
English
62
49
625
87.5K
HHK retweetledi
twyne
twyne@twynexyz·
Full lending potential. No collateral left behind. Let’s bring capital efficiency to your favorite lending markets: • Boosting lending APYs • Raising liquidation LTVs • Preventing 94% of liquidations All while keeping risks segregated - How? 👇
twyne tweet media
English
3
11
32
5.2K
HHK retweetledi
Drastic Watermelon
Drastic Watermelon@DrasticWM·
24h left to take the entry quiz! LSW and fellowship alumni @0xadrii is one of many heavyweights selected fellows will have direct access to
yAudit@yAuditDAO

Ever opened up a codebase and thought "What does an attack vector actually look like?" or "How do I start looking for a bug?" You'll like this: @0xadrii will join our upcoming fellowship cohort for a live Q&A to talk through all the stuff no one explains. 24 hrs left to apply👇

English
0
3
12
1.1K
HHK retweetledi
yAudit
yAudit@yAuditDAO·
⚠️ Attention @Uniswap V4 Integratoors ⚠️ Creating and managing liquidity positions that involve native ETH on Uni V4? Read carefully: During our latest audit with @vfat_io, we identified a high severity issue in how liquidity is provided by Sickle to Uniswap V4 pools.
English
13
34
186
38.9K
HHK retweetledi
GiuseppeDeLaZara
GiuseppeDeLaZara@windhustler·
To demonstrate @burraSec's expertise, we’re offering a free full-day security review/consultation for projects integrating with LayerZero or Arbitrum—whether you’re already deployed or still in development. We’ll thoroughly review: LayerZero: Configuration (DVNs, Executor, and overall integration), functionality (LzRead, OFTs, vanilla OApps, and more). Arbitrum: Native bridge or token bridge integrations, use of retryable tickets, or custom Orbit chains (e.g., custom gas tokens, USDC bridge standard). DM me to schedule your review!
GiuseppeDeLaZara@windhustler

💡I’ve been asked numerous times to provide a checklist for auditing a LayerZero integration. ⚡️You asked, so here it is: github.com/windhustler/In… 🧠 I’ve dumped everything I could think of that can go wrong and more. @g_vladika spent years building and breaking the core Arbitrum protocol and he’s contributed to the Arbitrum checklist. CCIP checklist is still WIP. I want this to become the go-to place while auditing protocols with cross-chain components. We’re going to be adding Axelar, Wormhole, Stargate, LiFi, Across, and more. If you’ve been auditing cross-chain protocols and found quirks or integration bugs, reach out or contribute via PR. ⭐️ If you find the checklist useful, I’d appreciate a retweet and star on GitHub to raise awareness.

English
4
132
197
60.4K
HHK retweetledi
corn🛸
corn🛸@omgcorn·
Let's welcome @yearnfi security expert and @electisec Resident @spalen_ to the twitter everyone. Better late than never Give him a followrooski
English
2
3
24
1.2K
HHK retweetledi
electisec
electisec@electisec·
We had an incredible 2024: - Completed 59 audits 📋 - $1.9M in revenue 💸 - 90%+ growth compared to the last year 🚀
electisec tweet media
English
4
12
39
5.4K
HHK retweetledi
corn🛸
corn🛸@omgcorn·
Over $2 million in bookings this year (year 2) for yAudit 59 total audits 1 yAcademy block: 125 participants and 2 amazing Residents: @fedebianu @_eperezok
English
0
5
32
1.1K
HHK retweetledi
yAudit
yAudit@yAuditDAO·
Proud to share that @yAuditDAO was the only team to uncover a critical vulnerability during the security review of @eulerfinance. We’re committed to pushing the boundaries of blockchain security. Continuous vigilance & top-notch auditing are key to securing DeFi ecosystem.💪
Euler Labs@eulerfinance

Securing Euler. Today, we're sharing our multi-layer security approach, developed and implemented over the past year. In this 🧵 you'll find some of the highlights. euler.finance/blog/securing-…

English
2
14
76
15.7K
HHK retweetledi
yAudit
yAudit@yAuditDAO·
🎉 We’re stoked to announce the successful completion of our recent security audit of an innovative Automated Liquidity Manager for CLAMMs like UniswapV3. This protocol simplifies liquidity management and provides a set of automated concentrated liquidity strategies. 1/8
English
1
4
40
2.4K
HHK retweetledi
yAudit
yAudit@yAuditDAO·
🌐 We’re open-sourcing of the collective genius from our recent zBlock II cohort! Dive into the juicy output at zblock2.xyz and see the future of ZK security unfold. (1/5)
English
2
19
78
7.5K
HHK
HHK@HHK_eth·
@storming0x Contests are a pvp games while audits are coop games.
English
0
0
3
53
stormblessed🌩️ 💡 🗃️
For those that have done both contests and audits What would you say is the biggest mind shift or difference from a security researcher pov to perform well on contests? I have a few guesses but I haven’t tried contests yet
English
4
0
7
1.1K