Wolf_Kalp

181 posts

Wolf_Kalp banner
Wolf_Kalp

Wolf_Kalp

@KalpShah_eth

Web3 Security Researcher || Prev Intern @kannaudits

Katılım Haziran 2025
209 Takip Edilen20 Takipçiler
Mitchell Amador
Mitchell Amador@MitchellAmador·
Big news from Immunefi: we just shipped Proof of Duplicate, and it's *the* feature I've been wanting to see for a long time. For years, one of the most frustrating experiences a whitehat could have was submitting a report, putting in the hours of research, the careful write-up, the working PoC… and getting back a one-line "duplicate, closing." No justification and no transparency. No way to push back. That era is over. Starting now, when a submission is closed as a duplicate, it points to the original report. The researcher can read the original. They can compare the reports for themselves... and if they believe the call was wrong, they get a formal dispute button. Verdict upheld means the report stays closed. If the verdict is overturned, the report gets reopened and goes back through triage like nothing happened, including reward eligibility. This matters beyond the feature itself. The whitehat community is the immune system of crypto. Every protocol secured, every exploit prevented, every billion in TVL that didn't get drained. For this immune system to keep working, things have to keep improving for whitehats. Proof of Duplicate is just one piece. There will be more. SR Summer 2026 is coming.
Mitchell Amador tweet media
English
35
29
250
27.6K
Wolf_Kalp retweetledi
CertiK
CertiK@CertiK·
A few weeks ago we threw CertiK's AI Auditor into the fire: hide a real, fund-draining bug inside a production-style DeFi contract, get multiple tries to tune it against the live tool, and see if you can sneak it past. The results are in. 🧵
CertiK tweet media
English
9
11
64
5.5K
Wolf_Kalp
Wolf_Kalp@KalpShah_eth·
Planted Critical Issue and got 3rd position in Certik Challenge!
CertiK@CertiK

5/🥉 @KalpShah_eth - a single added line that let a vault's internal accounting inflate out of nothing: invisible in review, fatal over time. $250 in credits + a fast-tracked interview.

English
0
0
2
40
forefy
forefy@forefy·
🚨🚨 C4 SHUTS DOWN (and what does it mean) > since June last year @zellic_io did not take any profit to themselves for keeping @code4rena alive despite platform obvious costs > why? we can defer that Zellic's customers enjoyed the services there, and that its hell of a business lead-gen to be this middleman, even for free > bear market + AI submission spam is a bad combo, but even worse that it continues overtime without breathing air to many the OG stepping down might signal "contests are dead" (which was already the vibe with thedailywarden homepage) but to me it just says that it's a hard business running a contest platform nowadays if you're an auditor, don't use it as an excuse to give up - but take the lesson here that "easy" wins are no longer valuable - contests that pay need real criticals, real impact, hard research, niche focus areas and strengths its your time to shine ☀️ thanks @code4rena for reimagining crowdsourced security
Code4rena@code4rena

After careful consideration, we’ve made the decision to wind down @code4rena. This community has meant a great deal to everyone who has been part of building it, and sharing this news is not easy.

English
6
0
72
8.7K
Wolf_Kalp retweetledi
Arsen
Arsen@arsen_bt·
Attacker drained $209K from @renegade_fi. Then messaged claiming to be a whitehat. Unfortunately, that's bug bounty state in 2026.
Arsen tweet mediaArsen tweet media
English
29
27
278
23.9K
0K
0K@ZeroK_____·
AI sucks at catching bugs, at least for me, if you used AI to catch bugs in bug bounties or contest, I’d genuinely love to know how you use it! And please don’t DM me trying to sell your $1K/month AI tool that produces ton of false positives bugs.
English
15
0
70
6.4K
Wolf_Kalp
Wolf_Kalp@KalpShah_eth·
@LuxLode I think, Buzz words such as AI Layoffs are masks!
English
0
0
1
70
lodelux
lodelux@LuxLode·
I don’t understand AI layoffs, if you can now do more with the same team why not, hear me out, do more? Why do you need to cut your workforce in order to do the same but now using AI? Seems to me AI is an excuse to simply save money by firing people
English
3
0
7
945
chrisdior
chrisdior@chrisdior777·
Web3 Auditors: - it took you years. - it took failures you don’t talk about. - it took pushing through when quitting made more sense. - it definitely wasn’t risk-free. That’s why you’re here now. 👏 To everyone starting now: Respect the process. It’s brutal, but it compounds.
English
4
7
74
1.7K
Wolf_Kalp
Wolf_Kalp@KalpShah_eth·
Day 1 of @revertfinance StableSwap Hooks audit on @cantinasecurity Started with docs & design understanding. A bit late to the party, but focusing on critical user flows to make the most of my time. Let's go!
English
0
0
2
28
Wolf_Kalp
Wolf_Kalp@KalpShah_eth·
Wrapping up the @MonetrixFinance contest with @code4rena I managed to uncover and submit a few medium‑severity findings, No highs or criticals were discovered Next focus: shifting gears to the @revertfinance Stable Swap Hooks contest hosted by @cantinasecurity 🚀
Wolf_Kalp@KalpShah_eth

Day 1 of Monetrix Contest On @code4rena My focus is on understanding the design, roles, and invariants thoroughly before beginning issue hunting—reading docs and building context is always the foundation of effective auditing.

English
0
0
2
58
Wolf_Kalp
Wolf_Kalp@KalpShah_eth·
Oh My God. Looks Like all Blackhats favourite month is April
BlockSec Phalcon@Phalcon_xyz

ALERT! Our system detected a series of unusual transactions involving @wasabi_protocol on #Ethereum and #Base, with total abnormal fund movements of roughly $5.15M. Preliminary traces suggest that Tornado Cash-funded accounts were later granted ADMIN_ROLE-related privileges and were involved in the relevant WasabiLongPool, WasabiShortPool and WasabiVault flows. We are sharing the related transactions for visibility and encourage the team to review and clarify the associated fund movements and role changes. WasabiLongPool & WasabiShortPool: 1) app.blocksec.com/phalcon/explor… 2) app.blocksec.com/phalcon/explor… WasabiVault: 1) app.blocksec.com/phalcon/explor… 2) app.blocksec.com/phalcon/explor…

English
0
0
1
23
JohnnyTime 🤓🔥
JohnnyTime 🤓🔥@RealJohnnyTime·
What's the most dangerous AI hallucination you've seen in a smart contract audit? The core problem with AI in smart contract auditing isn't that it gets things wrong. It's that it gets things wrong in exactly the same tone it uses when it's right. I've seen AI tools flag "critical vulnerabilities" that are impossible to exploit on-chain, hallucinate complex DeFi math, and completely miss actual attack vectors in the same file they were analyzing. If you don't understand the protocol you're auditing, you can't filter that. You'll present both the real findings and the hallucinations with equal confidence. AI is genuinely useful in auditing - but only once you have enough context to know when to trust it.
English
4
0
9
484
CertiK
CertiK@CertiK·
Can you fool our AI? We're running a 2-week public challenge against CertiK AI Auditor. If you can plant a bug that slips past it, you could win $1,000 in credits and a fast-track interview at CertiK. Apply at ai.certik.com/challenge More details 🧵👇
CertiK tweet media
English
13
14
66
9.8K