Robert Chen

400 posts

Robert Chen

Robert Chen

@NotDeGhost

founder @osec_io | web/pwn with @redpwnctf + @dicegangctf | prev @dfsec_com

Katılım Eylül 2018
636 Takip Edilen6.5K Takipçiler
Robert Chen retweetledi
OtterSec
OtterSec@osec_io·
We achieved a guest-to-host escape by exploiting a QEMU 0-day where the bytes written out of bounds were uncontrolled. Full breakdown of the technique, glibc allocator behavior, and our heap spray/RIP-control primitive ↓
OtterSec tweet media
English
6
108
520
39.8K
Robert Chen retweetledi
Michael Debono
Michael Debono@_mixy1·
ctfs are dead PLEASE PLEASE PLEASE stop making jeopardy ctfs. This is not fun at all to put effort into. Lets try and find a new format or something cause I'm gonna [redacted] if I see another ctf get half its challenges cleared in the first 30 minutes.
English
24
26
330
31K
Robert Chen retweetledi
OtterSec
OtterSec@osec_io·
We found the same Fiat-Shamir bug in six independent zkVMs. The result: an attacker can bypass the cryptography entirely and prove mathematically impossible statements (like minting $1M out of thin air). Full breakdown ↓
OtterSec tweet media
English
31
135
833
101K
OtterSec
OtterSec@osec_io·
Spend the summer in NYC (we cover rent). Work alongside our team on audits and tooling, learn how we actually do security research, and get support for your own projects. Apply below ↓
OtterSec tweet media
English
16
31
246
37.1K
Robert Chen retweetledi
OtterSec
OtterSec@osec_io·
We’re excited to announce a shared leadership structure with @asymmetric_re! Teams today face risks that span audits, research, engineering, and incident response, and clear coordination is important.
OtterSec tweet media
English
5
9
72
9.4K
Robert Chen retweetledi
Asgard Finance
Asgard Finance@asgardfi·
There’s never been a better time to take the right position For those Fearless enough to act Forged on Solana
English
58
58
248
41.6K
Robert Chen retweetledi
Harrison Green
Harrison Green@hgarrereyn·
Some thoughts on a recent trend I've been seeing with academic research on applied LLM systems c.mov/academic-arbit…
English
0
3
14
1.8K
Robert Chen
Robert Chen@NotDeGhost·
Excited to speak at Breakpoint this year with @jacobvcreech to talk about Anchor v2 (and why you should not write your own framework)
Robert Chen tweet media
English
22
7
138
21.2K
Robert Chen retweetledi
OtterSec
OtterSec@osec_io·
Our research team achieved client RCE on Minecraft Bedrock Edition via a heap overflow to bypass ASLR and sidestep CFG. Writeup to come.
English
59
277
3.1K
221.2K
Robert Chen retweetledi
OtterSec
OtterSec@osec_io·
NEW: OAuth misconfigurations show how common dev settings can lead to account takeovers. Our second deep dive breaks down real cases where overlooking differences between desktop and mobile environments left SDKs, exchanges, and wallets open to exploits. osec.io/blog/2025-10-1…
English
2
18
75
8K
Marius | Kamino
Marius | Kamino@y2kappa·
This is our second formal verification for Kamino Lend, but an extremely critical one. A completely different methodology, same results (solvency), therefore validating the outcome of the first verification. No need to preach the virtues of formal verification again. This is simply about holding ourselves to the highest standard. Always a pleasure working with @NotDeGhost 🫡
Kamino@kamino

1/ Excited to announce that Kamino Lend has been formally verified by @osec_io — bringing our total formal verifications to 4 This further establishes Kamino as the gold standard for safety and security in @solana DeFi Open source. 18x audits. 4x formal verifications.

English
15
13
153
43.4K
Robert Chen retweetledi
OtterSec
OtterSec@osec_io·
NEW: Proof of Reserves you can verify yourself. We teamed up with @Backpack to build PoRv2, a zero-knowledge system for fast, transparent solvency checks. More on how we designed it ↓ osec.io/blog/2025-08-2…
English
23
27
144
29.2K
Privacy Cash
Privacy Cash@theprivacycash·
@toly We also opened an issue on Osec github 5 days ago, and haven't heard back: github.com/otter-sec/sola… But for now anyone can manually verify the code hashes match for full code integrity. (The verification command is on github)
English
3
0
5
819
wavey cavey ∿
wavey cavey ∿@cavemanloverboy·
if my math is right, hardware to execute 51% attack on btc is cheaper than 33% of sol stake 1ZH / (200 TH/ S21) * ($4K/S21) = $20b 1/3 of SOL mc = $40b
English
7
3
31
3.1K