0xGhost | Co-founder @ Shieldify Security

594 posts

0xGhost | Co-founder @ Shieldify Security banner
0xGhost | Co-founder @ Shieldify Security

0xGhost | Co-founder @ Shieldify Security

@ShieldifyGhost

Making web3 a safer place through @ShieldifySec. Have a chat with us at https://t.co/KcE7hlhN5P We have audited IPOR, Colb, Ion, among 90+ security audits.

Somewhere in the ether. Katılım Ocak 2023
926 Takip Edilen1.3K Takipçiler
0xGhost | Co-founder @ Shieldify Security retweetledi
Shieldify Security
Shieldify Security@ShieldifySec·
@nftgoy @absterxyz @Abstract_Eco @AbstractChain Even if the smart contract is properly audited, security doesn’t stop there. This incident shows that vulnerabilities can arise from off-chain components, so an off-chain audit is equally critical!
English
1
1
6
183
0xGhost | Co-founder @ Shieldify Security retweetledi
Shieldify Security
Shieldify Security@ShieldifySec·
We've seen the reports around @absterxyz and users being charged more than expected when placing bets. We audited Abster's smart contracts, so naturally people are asking - did we miss something? Short answer: NO! Here's what actually happened 🧵👇
English
2
3
10
1.2K
0xGhost | Co-founder @ Shieldify Security retweetledi
Shieldify Security
Shieldify Security@ShieldifySec·
Our latest Abstract security audit report is out for @absterxyz 🤝 Serious team, good collaboration, and important findings uncovered! Read the report below👇 github.com/shieldify-secu…
Shieldify Security tweet media
English
3
3
16
2.5K
0xGhost | Co-founder @ Shieldify Security retweetledi
Jeff Security
Jeff Security@jeffsecurity·
That $50M loss wasn't a hack. It was just a brutal lesson in MEV. EigenPhi breaks down the slippage mistake that searchers jumped on. A prime case for why we need encrypted mempools ASAP. 🛡️ open.substack.com/pub/eigenphi/p…
English
0
1
10
1.1K
0xGhost | Co-founder @ Shieldify Security retweetledi
Jeff Security
Jeff Security@jeffsecurity·
Open rates for cold reachouts to protocols were sitting at 2%, so I had to escalate. If this doesn’t get me a discovery call, nothing will.
Jeff Security tweet media
English
1
2
11
692
0xGhost | Co-founder @ Shieldify Security retweetledi
Martin
Martin@ShieldifyMartin·
Crowdsourced audit competitions were the primary initial driver of the Web3 security space, most of the top talent was onboarded from them. Contest platforms operate on a percentage of the pool and applying an entry fee will prevent a large portion of the newcomers from joining. There should be a different solution to handle AI slop reports.
Hari@hrkrshnn

@Anh084879445581 We don't host it for free FYI. Part of the degradation of the C4 competition had to do with it being free -- there's no incentive to invest time, money and resources if it's a loss making product.

English
2
1
7
1.3K
0xGhost | Co-founder @ Shieldify Security retweetledi
Shieldify Security
Shieldify Security@ShieldifySec·
Sol-azy is a static analysis tool for the sol eco, allowing you to: - reverse ⏪ - analyze 🧐 - poke at Solana programs 👈 github.com/FuzzingLabs/so…
English
0
4
22
1.3K
0xGhost | Co-founder @ Shieldify Security retweetledi
Shieldify Security
Shieldify Security@ShieldifySec·
EIP-7702 is an auditor’s nightmare💀 Sticky storage can leave dirty slots behind between delegatecalls — wallets can get bricked. On top of that: huge init front-running risk. 🔎 A must-watch breakdown from @theredguild youtube.com/watch?v=ZFN2bY…
YouTube video
YouTube
English
1
6
31
2.8K
0xGhost | Co-founder @ Shieldify Security retweetledi
Shieldify Security
Shieldify Security@ShieldifySec·
Want to start experimenting with AI for Web3 security? Check out Hound — an open-source project that’s still v1, but already a strong base to build on Huge thanks to @muellerberndt 🫡 🔗github.com/scabench-org/h…
English
2
3
30
1.9K
0xGhost | Co-founder @ Shieldify Security retweetledi
Martin
Martin@ShieldifyMartin·
After 1 hour brainstorming session with my AI assistant, we built great OKRs and KPIs. Clear targets, fewer blind spots, and a solid plan to scale. 🫡
English
0
1
3
165
0xGhost | Co-founder @ Shieldify Security retweetledi
Shieldify Security
Shieldify Security@ShieldifySec·
New audit report for @onchainheroes, this time for their game - Maze of Gains✳️ Maze of Gains is turn-based roguelike dungeon crawler, playable on desktop and mobile, where every run competes for a shared weekly ETH prize pool 🎮 Read the report below👇 github.com/shieldify-secu…
Onchain Heroes: World's Eve@onchainheroes

The Maze is OPEN. Your skills. Your treasure. Your ETH. $3,000 initial Jackpot pool. Here's everything you need to know to start playing 🧵⬇️

English
4
4
20
2.3K
0xGhost | Co-founder @ Shieldify Security retweetledi
Shieldify Security
Shieldify Security@ShieldifySec·
Smart Contract Auditor on vacation☀️ Yess, butt....
Shieldify Security tweet media
English
2
3
19
1.5K
0xGhost | Co-founder @ Shieldify Security retweetledi
inhuman
inhuman@inhuman·
Forgot to mention this due to how busy the last few days have been: Despite being in an early alpha state, every smart contract on Shiny has already been audited and approved by the amazing team at @ShieldifySec
inhuman tweet media
English
9
5
49
3.2K
0xGhost | Co-founder @ Shieldify Security retweetledi
Shieldify Security
Shieldify Security@ShieldifySec·
If you're auditing a protocol that uses Uniswap V4 Hooks - these papers and articles are essential reading 🫡 🚩Questions To Ask Before Writing a Uniswap v4 Hook 🔗blog.openzeppelin.com/6-questions-to… 🚩Uniswap V4 Hooks Security Talk 🔗youtu.be/Fbxsv8rxHZw 🚩Uniswap V4 Hooks Security Deep Dive 🔗youtu.be/4o8yGcq6tfM 🚩Auditing Uniswap V4 Hooks 🔗hacken.io/discover/audit… 🚩Security Considerations 🔗quillaudits.com/blog/web3-secu… 🚩Integration Security Considerations 🔗certik.com/resources/blog…
YouTube video
YouTube
YouTube video
YouTube
English
2
13
68
4.7K
0xGhost | Co-founder @ Shieldify Security retweetledi
Prime Vaults
Prime Vaults@PrimeVaultsHQ·
The core of Prime Vaults is built on two pillars: Security and Strategy. To support a high-performance environment, our codebase has completed independent audits by @salus_sec and @ShieldifySec Continuous security is what allows Prime Vaults to operate reliably, 24/7 📄 Full audit reports below
Prime Vaults tweet media
English
3
7
34
2.7K
0xGhost | Co-founder @ Shieldify Security retweetledi
Martin
Martin@ShieldifyMartin·
Such a low number of contests 🧐 Pros: higher competition -> better results Cons: fewer opportunities, less talent onboarded in space The market is plateauing or it's shifting into a different direction.
Martin tweet media
English
0
1
7
311
0xGhost | Co-founder @ Shieldify Security retweetledi
Martin
Martin@ShieldifyMartin·
Thanks for reading! 🫡 Re-Share this knowledge to strengthen security across the ecosystem and help prevent future exploits 🤝
English
0
1
5
120
0xGhost | Co-founder @ Shieldify Security retweetledi
Martin
Martin@ShieldifyMartin·
3/ Moonwell (Base) - Nov 4, 2025 ~ $1M stolen + ~$3.7M bad debt The protocol followed standard Oracle best practices and used Chainlink’s off-chain oracle, which is designed to resist these attacks. However, the oracle incorrectly priced wrstETH at about $5.8 million, even though ETH was trading below $3,500. The attacker exploited the error within 30 seconds, depositing 0.02 wrstETH to receive roughly $116k in collateral. They used this to take a 20 wstETH flash loan and repeated the process across multiple transactions, ultimately draining 295 ETH. Security Considerations The project relied on a single price source and had no guardrails to flag unrealistic values, such as wrstETH pricing far above ETH, so a faulty Chainlink update directly enabled the exploit. Securing DeFi protocols requires anticipating supply chain failures and enforcing technical controls to limit the blast radius of upstream errors. halborn.com/blog/post/expl…
English
1
1
7
133
0xGhost | Co-founder @ Shieldify Security retweetledi
Martin
Martin@ShieldifyMartin·
2/ Trust Wallet - Dec 24-26, 2025 ~$7 million+ The attackers gained access to Trust Wallet’s source code and Chrome Web Store API key, enabling them to publish a tampered extension that redirected PostHog analytics to the attacker-controlled domain api.metrics-trustwallet. Security Considerations This incident demonstrates the importance of strong deployment and monitoring processes for off-chain infrastructure as well as on-chain. Real-time monitoring of deployed code may have identified the unauthorized release and enabled it to be removed before it caused significant harm to the business. halborn.com/blog/post/expl…
English
1
1
6
290