Undercover125

1K posts

Undercover125 banner
Undercover125

Undercover125

@Ril11111

Write, code, lift, repeat l Data & Distributed Systems geek🧢

Singapore Katılım Ocak 2019
636 Takip Edilen144 Takipçiler
Undercover125
Undercover125@Ril11111·
5/ LayerZero 1-of-1 DVN OApps The enabler of this attack was Kelp's 1-of-1 DVN config. There's plenty of LayerZero OFTs still running 1-of-1 DVN setups today. Pulled this list from @Dune
Undercover125 tweet media
English
1
0
0
37
Undercover125
Undercover125@Ril11111·
Built a dashboard to track the rsETH LayerZero OFT exploit rseth-dashboard.vercel.app Biggest DeFi hack in 2026- numerous defi protocols affected plus LayerZero OFT tokens/adapters Data curated from various X threads, on-chain txns, official post-mortems, etc. Shoutout to @banteg his threads carried the early understanding of this exploit. Since then, the key parties involved (@KelpDAO @aave @LayerZero_Core have also released various post-mortems. I built this dashboard to pull it all into one place. Check it out👇
English
1
0
0
66
Undercover125
Undercover125@Ril11111·
@trq212 Hey I wanted to flag a change in behavior I've been experiencing. I use cc regularly to craft PoCs for security vulnerability research, and it's worked well for this use case until recently. Since yesterday, I've been consistently hitting a policy violation error when attempting similar tasks. Has there been any update to Claude's usage policies or safety guidelines that might explain this change? Any context would be helpful, thanks.
Undercover125 tweet media
English
0
0
0
66
Thariq
Thariq@trq212·
I want to do a few more of these calls. If your MAX 20x plan ran out of tokens unexpectedly early and you're willing to screenshare and run some prompts through Claude Code please comment. Trying to figure out how we can improve /usage to give more info.
Kieran Klaassen@kieranklaassen

Resolved!! @trq212 helped me out debug where the token usage came from and it was my fault 100% Script to find token usage gist.github.com/kieranklaassen… I had a recurring script that ran every 5 minutes that should not have run every 5. I hope we can make it easier to detect these within Claude and Claude Code soon too.

English
388
77
1.8K
568.4K
Undercover125
Undercover125@Ril11111·
@chamath If there was a product that does this, would you use it?
English
0
0
0
7
Chamath Palihapitiya
Chamath Palihapitiya@chamath·
This may be a dumb question but I’ll ask it here anyways: I can’t find a good way for my various AI chats to automatically sync its conversation history into a structured knowledge base. So that as I update various chats from time to time and refine context, my knowledge base automatically grows with this new info.
English
1.1K
63
2.4K
806.4K
Undercover125 retweetledi
Tay 💖
Tay 💖@tayvano_·
I beg everyone in crypto to read this in full. I expected this to be another case of social engineering, likely some recruiter/job offer shit. I was very wrong. And the depth of the operation and personas makes me think they already have multiple other teams on lock. 😳
Drift@DriftProtocol

x.com/i/article/2040…

English
175
425
3.2K
721.9K
Undercover125
Undercover125@Ril11111·
Shoutout @bountyhunt3rz for keeping me company. Hearing the perspectives of other SRs was useful
English
0
0
1
21
Undercover125
Undercover125@Ril11111·
Managed to find a bug in monad, had to dig deep for this one. Was interesting to consider threat models and attack vectors unique to DLT networks. Codebase was alr reviewed by multiple tier 1 audit firms + public contest on code4rena. Locking back in🫡
Undercover125 tweet media
English
1
0
2
84
WhiteHatMage
WhiteHatMage@WhiteHatMage·
If you’re just starting out with bug bounties, here’s a secret: finding the vulnerabilities is the fun part. Actually getting paid? That’s the real skill.
English
12
4
200
8.7K
Undercover125 retweetledi
f4lc0n
f4lc0n@al_f4lc0n·
I Saved Injective's $500M. They Pay Me $50K. I like hunting bugs on @immunefi . I'm decent at it. - #1 — Attackathon | Stacks - #2 — Attackathon | Stacks II - #1 — Attackathon | XRPL Lending Protocol - 1 Critical and 1 High from bug bounties (not counting this one) Life was good. Then I found a Critical vulnerability in @injective . This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk. I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity. Then — silence. For 3 months. No follow up. No technical discussion. Nothing. A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either. I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten. I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible — until Injective pays what I deserve. Full Technical Report: github.com/injective-wall…
English
518
524
4.6K
1.8M
Undercover125 retweetledi
riptide
riptide@0xriptide·
if you are looking at AI security to complement your existing security stack, consider the following before you let your traditional audit partners upsell you on an "AI audit": most AI audits only give you a high level analysis, hence the low price point/quick turnaround then they give you hundreds of false positives and hope something sticks or else charge you to manually triage through these by their own SRs absolute waste of time we are not competing in this area we are competing against the top audit firms and security researchers to find the needle in the haystack we designed our @therealgregoAI security engine to go as deep as possible and grind for hours and hours running through thousands of exploit scenarios while filtering out 95%+ of false positives (very difficult to do! IYKYK) DM to enable the Grego AI Security Layer on your protocol and we will show you what everyone else missed
English
5
8
49
3.5K