Sabitlenmiş Tweet
Chidubem Kingsley
637 posts

Chidubem Kingsley
@KingsleyCaesar1
Founder @SecurityDfortre | Security Researcher. Portfolio: https://t.co/uFmCklkM6E
MARS 🔆🔆 Katılım Ağustos 2022
286 Takip Edilen345 Takipçiler
Chidubem Kingsley retweetledi
Chidubem Kingsley retweetledi

😭 auditing for weeks and finding zero bugs?
it's not bad luck, you just haven't trained on the right codebases
💡 the fix: shadow audits
audit a closed contest yourself → then read the report → see what you missed
but pick the RIGHT ones. small nSLOC, diverse bug types, don't start with 5k line monsters 💀
here are 5 @sherlockdefi contests perfect for this (2 days each max):
🔹 Surge — audits.sherlock.xyz/contests/51
🔹 Telcoin — audits.sherlock.xyz/contests/49
🔹 Olympus — audits.sherlock.xyz/contests/60
🔹 Cooler — audits.sherlock.xyz/contests/107
🔹 Crestal — audits.sherlock.xyz/contests/755
the fun part? check the results after
see what you could've earned if you'd submitted makes it feel real 💰
that gap between your findings and the winners = exactly where to improve 🧵
English

@StellarOrg I need early users + brutal feedback.
Try it here → time-lock-vault-jng1.vercel.app
If you’re serious about:
• saving
• group accountability
• or building discipline on-chain
This is for you.
Reply “VAULT” and I’ll personally guide you through your first setup.
THANKS 👍
English

@StellarOrg ⚖️ No rug risk
Funds go directly into the contract
Not to the creator. Not to any wallet.
🧠 Why this matters
Savings apps rely on trust
This runs on code + incentives
No excuses. No middlemen.
English

Most people don’t have a discipline problem with money.
They have a system problem.🚩
So I built one.
Lock your funds.
Remove temptation.
Rewarded for staying committed.
Introducing: Time-Locked Vault + Collective Commitment Protocol (on @StellarOrg )
Time Locked Vault:👇



English

Let’s be honest.
You can’t “fight blackhats” with good intentions.
Blackhats are motivated by immediate money. They spend countless hours looking for ways to break protocols because the reward is instant.
Whitehats are also expected to think like attackers, find critical bugs, report them responsibly, and then pray they get paid fairly.
That’s the problem!!
The only real difference between a whitehat and a blackhat should be responsible disclosure. Both need the same aggressive, adversarial mindset to find critical bugs.
But the incentives are completely different.
A blackhat finds a bug and can drain funds immediately.
A whitehat finds the same bug and has to go through uncertainty, delays, disputes, underpayment, or sometimes no bounty at all.
So people will naturally ask:
Why should I protect a protocol that doesn’t seem to care about security??
Why should I report a critical bug when the blackhat path pays instantly??
We can pretend everyone will “always do the right thing,” but that’s not how people behave when life-changing money is involved.
At the end of the day, security is an incentive game.
If protocols don’t make responsible disclosure worth it, they shouldn’t be surprised when hacks keep happening.
playboi.eth@adeolRxxxx
Another hack @AftermathFi. It’s been raining. $1.4m gone I think I have to finally say. We white hats are not in a ready position to fight against blackhats on chain. We are so bounded and limited to contests and bug bounties that our scope is dependent on these. Maybe when we see beyond ourselves, we’d be a ready match for blackhats. Those mfers are active on blocks, we are there fighting for a report to be escalated in our favor. This is becoming sad. WE CANNOT WIN, OUR TRAINING MODEL IS FLAWED.
English

@0x15_eth They probably have massive faith in their senior developers who told them what they want to hear till the inevitable happens outta nowhere
English
Chidubem Kingsley retweetledi

iam sharing best resources to train web3 security in my opinion for the new auditors.
its 2026 and nothing is more than learning resources.
i will be myself doing it to change my auditing mindest.
1- solana audit arena by the goat @0xcastle_chain.
best place to practice solana security.
my two cents,
before we said there are no solana contests, but now there are no contests, its bug hunting era and solana knowledge will give huge advantage and make you super rare.
2- training.valvessecurity.com by @ValvesSec
underrated, completing all the challengess alone will make you another auditor, and you can be ready for real world hunting.
3- shadow auditing @code4rena contests
nothing to say, it's best place to learn for long time.
start with small codebases and try to pick one category at a time.
4- real world hunting on @HackenProof
thats the final stage- where you can use the knowledge you have on-chain
its simple roadmap but hard to apply.
English


@0xapple_ @LayerZero_Core They actually rendered my high to informational. Something that is so clean clear that it is a vulnerability.
English

5k lines of @LayerZero_Core zero findings
turns out "intended behavior" is doing a lot of heavy lifting in that codebase 😭
how can there be a bug if everything is a design choice 🙂🔒

English

@0xapple_ @LayerZero_Core The whole thing is crazy per see but all I can smell from here is dishonesty from their part. Something ain't right somewhere.
English
Chidubem Kingsley retweetledi

Ethereum needs more security engineers.
Attackers are scaling faster than defenders, and the pipeline of qualified researchers is too small.
Guild Academy is building that pipeline — 5 cohorts in.
We're in @thedaofund 500 ETH Ethereum Security round on @Giveth, and it uses Quadratic Funding.
That means $1 from 100 donors > $100 from 1 donor. Your small donation unlocks much more from the matching pool.
If our work matters to you, even $1 helps.👇
🔗 qf.giveth.io/project/guild-…
English

Found a valid vulnerability in Injective Peggy Bridge protocol in the @code4rena public contest.
We keep looking and keep defending anon🫡

English

🚀 Built a P2P Naira ↔ STRK Marketplace. Send ₦ via any Nigerian bank — receive STRK instantly on-chain.
Send ₦ via bank transfer → receiver gets crypto.
Powered by Starkzap ⚡
Demo: zappay-ngn.vercel.app
GIthub: github.com/Chidubemkingsl…
@Starknet @StarkWareLtd
#Starknet

English

Live proof 👇
sepolia.voyager.online/tx/0x34cb779c3…
Deployed on Starknet sepolia
English


