Hunter

761 posts

Hunter

Hunter

@Huntoor

Hunting Bugs Everywhere | https://t.co/5Sj1CzQCoV for private audits

Web3 Katılım Haziran 2020
214 Takip Edilen1.4K Takipçiler
Sabitlenmiş Tweet
Hunter
Hunter@Huntoor·
Alhamdulillah, i have won the @InfraredFinance contest. Its been a while since my last posted win😅. 2nd consecutive contest and win, is it the rise? Some stats: - Time spent: 7 days - was the only one to find all high severity issues - Found the only solo in the code The main thing iam happy with in this contest is the amount of learning i got: - read a lot of EIPs (some were unrelated to the code but was intuitive to read more through) - read some geth code, and got a grasp of how consensus/execution layers work on the code level - read one GEAS - run my first local node to build a POC Downside for the above learnings is the % of coverage of those beautiful medium severity edge cases by those beautiful auditors This code has one of the longest call flow i have ever seen. I Love staking More than DEXs Auditing, Had much fun auditing this one Also i may decrease my contests participation alot(in general and not related to specific platform) Plans? - Leverage more time on niches i believe in and love - Join firmsss - Only participate in contests that add to my knowledge and have proper incentives - Become a judge (judging protocols that i love auditing), meh least likely because of the big amount of spams currently in the space and how judging may make me a hated person from newbies.
Hunter tweet media
English
53
3
270
14.2K
Hunter
Hunter@Huntoor·
@0xnirlin wdym, you didn't make your agent yet?
English
0
0
2
305
WhiteHatMage
WhiteHatMage@WhiteHatMage·
If you’re just starting out with bug bounties, here’s a secret: finding the vulnerabilities is the fun part. Actually getting paid? That’s the real skill.
English
13
4
191
7K
Hunter
Hunter@Huntoor·
@0xCharlesWang In general, why speculating?, if i have a clear attack path, then its high and not low. if i don't have a clear attack path, then there are two options: 1. its actually not exploitable 2. its exploitable but i won't bother searching enough, lets just report rounding as low.
English
0
0
3
1.4K
CharlesWang
CharlesWang@0xCharlesWang·
This is usually the low severity finding everyone ignores because it’s „only dust“ …. Until it’s no longer „only dust“
Silo Intern@SiloIntern

Why permissionless DeFi is a double edged sword? dTRINITY got exploited for $257K today. here's what actually happened: their dLEND pool (an Aave v3 fork) had a rounding flaw in the cbBTC aToken share math. mint and burn both used the same half-up rounding conversion. at a high liquidity index, withdrawals could exceed deposits. attacker flash loaned, deposited ~$772 USDC valued as ~$4.8M collateral, borrowed 257K dUSD, then looped 127 deposit/withdraw cycles through a helper contract. each cycle extracted a bit more cbBTC than was put in. net profit after gas: ~$257K. pool TVL was only ~$435K. on March 5, @HypurrFi publicly disclosed a structural rounding vulnerability in Aave v3 versions prior to 3.5 with the same exploit pattern. conditions: high per-unit token price, low decimals, low gas fees. cbBTC checks all three. dLEND is an Aave v3 fork. unclear whether they were running a patched version, but the exploit matching a known vulnerability from 12 days earlier raises questions.

English
2
0
17
2.7K
Hunter
Hunter@Huntoor·
you are a good auditor when you submit smart bugs (logical). but what some misses is that you are a bad auditor when you submit invalid/info bugs. AI made it really easy to run and generate reports. please don't treat your private audit report bugs by kilo. VERIFY.
English
1
0
22
1.3K
Hunter
Hunter@Huntoor·
@adeolRxxxx I call this AI tools MEV. Good for others that goes one layer more deep.
English
1
0
2
171
playboi.eth
playboi.eth@adeolRxxxx·
So basically, I have not been resting as I am currently competing in contests and also consistent in bug bounties. > So I think it would be nice to share my dups with the public for those who wanna learn. > But bug bounties have been a hell hole, or maybe let me say crazy. A bounty dropped last week in the heat of the day. I was asleep when I got pinged by my tool. I quickly woke up, checked, and saw it was in DLT. I have been preparing all my life for this. 4 hours just after this dropped on @HackenProof , I was able to find a critical that could allow an attacker to drain the entire pool in a single transaction by forging a block. I quickly wired an end-to-end POC to prove this issue, even estimating the time it would take the attacker. But unfortunately, I was met with "this issue has been found by another whitehat", bro, 4 hours?? Here, if you wanna learn: github.com/blessingblockc…
English
11
8
105
6K
Hunter
Hunter@Huntoor·
@Al_Qa_qa i disagree, audits are time bound, your best use of time would be to prevent hacks and disfunctionalities of the SMART CONTRACT, you don't need to use that small bounded time to guard for those mistakes.
English
1
0
1
41
Al-Qa'qa'
Al-Qa'qa'@Al_Qa_qa·
@Huntoor We should make sure the Web3 works safely, and don't get tied to a given niche
English
1
0
1
166
Al-Qa'qa'
Al-Qa'qa'@Al_Qa_qa·
There is a difference between Protocol security and safety. We all remember the 50M $USDC trade that resulted in only 35k worth of $AAVE - Is the protocol secure? Yes, there was no technical exploit - Is the protocol safe? No, users can still lose everything. The problem is that DeFi protocols are built to work fine only when used correctly. They aren't designed to protect unaware users. We must ensure protocols work regardless of the input, handling user mistakes whenever possible.
English
7
4
27
2.3K
Hunter
Hunter@Huntoor·
sometimes i browse some finished contests randomly. its insane how some valid bugs for 5 figures can never be valid in 1 million years in a contest and be marked as spam in another contest. insane how trivial bugs are considered smart here and unrealistic there. i'm confused.
English
5
0
60
2.8K
Hunter
Hunter@Huntoor·
@oot2k1 What you describe is understandable, the space evolves. But what i saw in the same timeframe is complete madness
English
1
0
1
136
oot2k
oot2k@oot2k1·
changed a lot over the years as well. I will never forget the 25k safe transfer issues. A good example as well is sequencer downtime, today it is mostly considered invalid but at some point in time it was in almost every codebase and judged medium-high. (I think its still ok to consider it a risk if the network is new and it would block liquidations or something)
English
1
0
1
254
Hunter
Hunter@Huntoor·
@auditor_nate what is more problem is that discrepancy isn't small.
English
1
0
2
217
Auditor-Nate
Auditor-Nate@auditor_nate·
@Huntoor It’s nuts mate, particularly the last 8 or so months. Just 0 consistency what so ever on any platform
English
1
0
2
234
Martin Marchev
Martin Marchev@MartinMarchev·
Unpopular opinion: the biggest risk AI poses to security researchers is not replacing them. It's making them comfortable.
English
10
3
76
2.9K
Hunter
Hunter@Huntoor·
@0xKaden easy to say when you have financial stability. but when life gets tough?, your kids will only care about food, not your respect in the space
English
0
0
5
64
kaden.eth
kaden.eth@0xKaden·
hot take: being a whitehat means that you should be willing to disclose bugs regardless of whether you will be rewarded sure, disclosure deserves a reward, but your priority should be doing the right thing rather than getting paid besides, i think this approach will always be rewarded in some way eventually
English
14
2
75
4K
Hunter
Hunter@Huntoor·
@asen_sec > The people who make it now are the ones who adapt fast. that does what?
English
0
0
1
108
0xasen
0xasen@asen_sec·
It's not too late to start in web3 security. But the game you're entering isn't the game you've been reading about. Contests take months to judge. Platforms limiting submissions. AI finds the easy bugs before you do. The people who make it now are the ones who adapt fast.
English
8
3
117
3K
Hunter
Hunter@Huntoor·
@adeolRxxxx i'm not exhausted of working, i'm exhausted of twitter
English
0
0
3
224
playboi.eth
playboi.eth@adeolRxxxx·
I don’t think I can continue this career path for long. - I’ve experienced exhaustion every day for the past week bro that I can’t even sleep at night. Bro I’m sad I’m mentally exhausted.
English
35
3
152
12.9K
playboi.eth
playboi.eth@adeolRxxxx·
Hi @sherlockdefi how do I login into my old acct on Sherlock without needing to create a new one?
English
1
0
6
1.4K
Hunter
Hunter@Huntoor·
as we are speaking, some auditors are using claude code to perform parallel private audits. wdyt?, is this a productivity boost or illegitimate?
English
8
0
15
2.3K
Hunter
Hunter@Huntoor·
you didn't create you first claude skill yet?
GIF
English
0
0
3
283
oot2k
oot2k@oot2k1·
Most profitable business right now in crypto: - validator + mev - market making - consultancy (audits, dev...) - ...? Right or wrong?
English
3
0
7
713