InfectedCrypto

2.6K posts

InfectedCrypto banner
InfectedCrypto

InfectedCrypto

@InfectedCrypto

Web3 Security tryhard | SR @AdevarLabs

Katılım Eylül 2021
520 Takip Edilen1.2K Takipçiler
InfectedCrypto
InfectedCrypto@InfectedCrypto·
Something I like to do, is that when I think I have an interesting lead, I ask the LLM to verify it, and in the mean time I continue to verify it myself and see if I can confirm it before the agent finishes lmao
English
2
0
5
166
InfectedCrypto
InfectedCrypto@InfectedCrypto·
That's funny how LLMs tends to forget the atomicity of blockchain transactions. e.g.: "subsequent invoke_signed for allocate would fail — but the transfer at L193-202 would already have succeeded, resulting in lost funds sent to the wrong account" No bruh, this is a tx
English
0
0
5
282
InfectedCrypto
InfectedCrypto@InfectedCrypto·
Maybe a good idea is be to run automation after completing the audit, to cover possible missed spots? On my end I still use LLMs mostly to questions the code, explore, or verify leads. I find that LLMs are really good as smart-search-engine on steroids (not only that obviously)
Joran Honig@joranhonig

x.com/i/article/2034…

English
1
0
1
209
InfectedCrypto
InfectedCrypto@InfectedCrypto·
@0x3b33 Chainlink data feeds also work on the same idea. Get a price report offchain, signed by multiple party, verify it onchain. Same potential issue. Can be fixed by registering the last verified report timestamp
English
0
0
0
22
InfectedCrypto
InfectedCrypto@InfectedCrypto·
@arsen_bt Very nice and well written codebase. We tried hard until the end to make this work 🙏
English
1
0
3
85
Arsen
Arsen@arsen_bt·
I audited the SPL stake pool. Integrated with Fogo Sessions. @InfectedCrypto and I found: - 1 high - 3 low - 3 enhancements And learned a lot in the meantime. x.com/AdevarLabs/sta…
Adevar Labs - Security Audits@AdevarLabs

We’ve completed a security review for @ignitionxyz . Ignition is a liquid staking protocol on @fogo , letting users stake tokens and earn yield while keeping assets usable across DeFi. It plays a useful role in expanding liquidity options on chain. Grateful to work with the Ignition team and support their efforts to Ship Safely.🚀 Public report and testimonial below: 👇🧵

English
5
0
31
1.8K
InfectedCrypto
InfectedCrypto@InfectedCrypto·
@AdevarLabs For a long time during my contest period I skipped (or postponed for later, which never came) complex calculations as I thought the risk/reward to find issue against time spent was not worth it. In fact that is exactly where you'll find issues other misses.
English
0
0
8
145
InfectedCrypto
InfectedCrypto@InfectedCrypto·
After having two LLMs argue about the validity of a finding (one saying its valid, the other it is not valid), I finally understand how it feels to be a judge during contests escalations Both are so convinced they are right, or they don't care and just want to push their version Man that's exhausting I can't imagine doing this for 10s of issues
InfectedCrypto tweet media
English
3
0
8
544
InfectedCrypto
InfectedCrypto@InfectedCrypto·
@bbl4de_xyz That's what I wrote at first, but I hope all AI sloppers don't escalate their slop, and only a few issues get escalated 🥲
English
0
0
0
23
bbl4de
bbl4de@bbl4de_xyz·
@InfectedCrypto > I can't imagine doing this for 10s of issues you mean 1000s ? 💀
English
1
0
1
76
InfectedCrypto
InfectedCrypto@InfectedCrypto·
@testmachine_ai True and good point tbh in that case it implied cross program interaction (solana) and I knew LLMs would struggle af to make a working PoC so I didn't try
English
0
0
0
21
TestMachine
TestMachine@testmachine_ai·
@InfectedCrypto You need systems like TestMachine that prove exploitability or refute it, otherwise you’re just arbitrating opinions.
English
1
0
1
34
InfectedCrypto
InfectedCrypto@InfectedCrypto·
LLMs couldn't solve that puzzle (took me more time that I want to admit) Baba is You might be an interesting benchmark tbh (it is bonus stage world 3 if you're wondering)
InfectedCrypto tweet media
English
0
0
0
169
InfectedCrypto
InfectedCrypto@InfectedCrypto·
@Huntoor I've seen +$5k invalid bugs being validated more than once
English
0
0
2
157
Hunter
Hunter@Huntoor·
sometimes i browse some finished contests randomly. its insane how some valid bugs for 5 figures can never be valid in 1 million years in a contest and be marked as spam in another contest. insane how trivial bugs are considered smart here and unrealistic there. i'm confused.
English
5
0
60
2.8K
Afriauditor
Afriauditor@Afriauditor·
Holy shit!!😂😂 Guy see what my AI is telling me... This was after numerous attempt to get it to write me the report. Should the model the able to this @AnthropicAI 😂😂
Afriauditor tweet media
English
8
0
13
1.2K
InfectedCrypto retweetledi
bheau
bheau@bh359·
correct me if I'm wrong but this seems like the largest ever single-block builder profit in ethereum history, ~$33m to titan it also may be one of the largest MEV block rewards ever on eth, a 568 ETH proposer payment which falls just behind the SVB USDC depeg (had a 692 ETH payment), 2023 sushiswap whitehat hack (689 ETH), and 2023 curve whitehat hack (584 ETH) others already commented on the original issues with the order (illiquid route + insane $155k AAVE limit price), but here's where the $50m went: - $36k to the user's cowswap order (331 AAVE) - $619k cowswap solver fee - ~$9.9m to the MEV bot that backran the 17,957 ETH -> 331 AAVE swap (backrun was 128 AAVE -> 17,959 ETH) - another ~$2.6m to the same MEV bot from backrunning the $50m USDT -> $37m WETH swap over multiple txs - ~$34.3m fee to titan from the MEV bot (includes $1.2m to lido as the block proposer) - ~$3.5m in dex swap fees + residual smaller arb txs insane payday for titan, who sent their profits to coinbase, and this single MEV bot took the majority of the arbs in both the illiquid AAVE/WETH pool and the $13m slippage swap in the main USDT/WETH pool
bheau tweet media
deebeez@deeberiroz

Poor fellow swapped $50m -> $35k on eth mainnet 😭😭😭 etherscan.io/tx/0x9fa9feab3…

English
45
42
483
181.3K
InfectedCrypto retweetledi
Adevar Labs - Security Audits
Most smart contract audits slow down for avoidable reasons. Preparation is usually the difference. Here’s the audit readiness checklist to get the most value from your audit. 🧵👇
Adevar Labs - Security Audits tweet media
English
4
4
19
1.2K