Procur3
160 posts

Procur3
@procur3
The intelligence & procurement layer for smart contract security. Real-time data on 50+ audit firms. Any language, any chain. Instant quotes.


New python audit report published, this one is for @__HLOS 🤝 3 High, 4 Medium, 2 Low Severity Vulnerabilities. Happy with the work of our security experts. The code is now secure! 🙏 Read the report below👇 github.com/shieldify-secu…

There are lots of tools being shipped to help smart contract auditors audit, but we've just shipped something every builder needs... Real-time stats, search and discover - the ultimate auditor due diligence. Here's how to choose a smart contract auditor 🧵

Security procurement in Web3 is broken. So we fixed it. With @Procur3, you can: • Publish an RFP in 60 seconds • Compare proposals from 50+ vetted security firms • Award with confidence Structured RFPs. Transparent comparison. Faster decisions. Book your audit today. 🎥👇


Security procurement in Web3 is broken. So we fixed it. With @Procur3, you can: • Publish an RFP in 60 seconds • Compare proposals from 50+ vetted security firms • Award with confidence Structured RFPs. Transparent comparison. Faster decisions. Book your audit today. 🎥👇



The amount of new / smaller audit firms signing up to @procur3 this month has been insane The levels are the same as when we first launched late last year More auditor diversity means no matter your budget, timelines, needs, you’re guaranteed to find a security partner


Security researcher ily2 has just earned a staggering $3,000,000 from submitting a critical smart contract bug via Immunefi. That's the largest single payout in web3 security in recent memory. In total, he's submitted 3 reports. All 3 were paid. 100% accuracy. His leaderboard update is coming soon, but you can pledge IMU to him now and earn when he finds the next one: immunefi.com/pledge/ily2

$300,000 from a single bounty. Also yes, it was Move related. Move helps, but it doesn’t magically make protocols safe. The real bugs still live in assumptions, invariants, and integrations. Proud of what VulSight has been doing too. We’ve cleared over $500k in bounties in the last 2 months. If you’re a founder and you want an audit team that consistently finds criticals, we’re a DM away.

this absolutely needed to be said it turns out that the biggest bottleneck for onchain "permissionless" innovation is paying $200k+ for smart contract audits 1. you have open-source tooling; foundry, hardhat 2. you have cursor to “assist” you in writing code; basically free 3. you can deploy on EVM without paying anyone (just gas; and it’s <0.1 gwei rn) 4. your code runs on the EVM once you deploy on mainnet; users pay fees, you don’t need to in this journey to production, anyone with decent solidity experience + a laptop can permissionlessly ship a perpetually-running piece of software the only catch: YOUR CODEBASE ISN'T AUDITED. and no one is gonna interact with your app without an audit "stamp" why? because you can’t really pay a tier-2/3 auditor $50k+ (let alone tier-1) so it basically becomes an “entry fee” to be considered acceptable + secure enough for people to actually use to me, it’s the single biggest bottleneck for any early-stage team building in crypto rn this has to change sooner or later. hopefully AI disrupts smart contract security the same way it’s already disrupted coding workflows (also: this doesn’t even touch ongoing audit costs when you ship upgrades / new modules — it’s a BIG FUCKING RECURRING TAX that nobody talks about)




