Storm

1.5K posts

Storm banner
Storm

Storm

@Stormbreak0

Storm Breaker

Katılım Ekim 2022
937 Takip Edilen110 Takipçiler
Storm retweetledi
pashov
pashov@pashov·
Hyperbridge exploit story: >single audit, no bug bounty >rude to whitehats, publicly mocking their efforts >April Fool's - "Security Incident Report xD lolllz" >claims they're unhackable >gets hacked 2 weeks later - "Bridge update!" Always respect the whitehat efforts, always🙏
pashov tweet media
English
58
125
1.2K
80.4K
Storm retweetledi
Mx (beta)
Mx (beta)@0xMSF14·
Blackhats get 100 ETH while whitehats get "3 months unpaid internships".
Gyroscope@GyroStable

⚠️ Message to who executed the GYD bridge security incident To 0x7DD4075A6eAe9f18309F112364f0394C2DfA8102: This is Gyroscope governance. We propose a resolution to the GYD smart contract incident. You can return 200 ETH that you hold from this incident. Gyroscope is then in a position to consider the remaining over 100 ETH as a fixed whitehat settlement credit. This generous of a settlement is possible because it gives the protocol a chance of making users whole by canceling GYD’s system surplus. If you take this offer, Gyroscope will cease investigations and consider you as a whitehat who performed an emergency recovery of funds and made users whole. It’s a win for all. You will be taking a big everlasting risk if you take all of the funds, which isn’t even that much in total. With this offer, for the same order of magnitude of reward, your risk would be reduced massively and users would be made whole. If the funds are not returned, Gyroscope will alternatively offer the same deal to the public for anyone for information that leads to prosecution and full recovery of funds. Security researchers have already found significant leads that could aid in this direction. We believe it doesn’t have to go that way though, and we believe you can be a whitehat. To accept this settlement, return 200 ETH to the Gyroscope GovernanceManager contract 0x78EcF97572c3890eD02221A611014F30219f6219 on Ethereum by 18:30 UTC on February 5th. If you would prefer to communicate in private, you can contact security@gyro.finance.

English
11
12
232
27.2K
Storm retweetledi
Alex Filippov
Alex Filippov@alexfilippov314·
Thank you! If I could give my past self one piece of advice, it would be to set up e2e testing from day one. It is often faster and simpler to check things directly than to trace execution by reading the code. For Cosmos-based protocols there is a good resource by Trail of Bits: secure-contracts.com/not-so-smart-c…. I ran into many similar issues myself.
English
2
6
80
1.9K
Storm retweetledi
guhu
guhu@Guhu95·
Some Fusaka contest thoughts: The Good: - Client diversity still a mind boggling security super power. - EF doing contests for upgrades is great for security, and sets the right example. - AI is a game-changer, indispensable in huge complex scopes. - Geth is still the Goat - more secure, more readable, and more correct than even the spec. - @alexfilippov314 dominates again! Only 1 info finding is a crazy flex. The Bad: - Cryptography is still a bug hotspot. - 2 KZG libraries for 11 clients is the Achilles heel of client diversity. - PeerDAS is a whole new blockchain (a sharded one!) which is awkwardly entangled in the existing Ethereum chain. The surface area for severe issues is now much larger, even in parts that used to be non-critical. The Ugly: - Contest rules were even more impossible than for Pectra. The more frustrating a contest is, the less participation it gets. Less eyes -> less security. There were 950 submissions for Monad, and only 360 submissions for Ethereum - it should be the other way around. - The upgrade did not go smoothly this time :( A crazy ride and learning experience as always.
guhu@Guhu95

Some Pectra contest thoughts: The Good: - Client diversity is an ETH superpower. Always liked it, but now 10x more. - Testing sophistication is unbelievable. Beyond each client's tests, and the testnets, there are independent external tests (in python), a tool to run devnets (kurtosis), and probably much more. - EF funding more big contests is great, and will pay huge dividends. With a pretty big low pot and the "public good" vibe it probably got a lot of eyes 🙌 - AI IDEs really help with new code: a huge complex codebase in a language you don't know - no problem. Was never as fast and easy to get going. - While all clients are well engineered, my appreciation for Go and Geth is even higher now. Amazing in balancing design & readability & flexibility. The Splinter of the clients. The Bad: - Despite the above, nasty bugs still make it through as evident from the issues announced in discord. More are likely to be still there. Clients with smaller network share qualified only for low severity issues, so probably have more remaining issues. - Cryptography integration points seem to be a hotspot (judging by the announced finds). - EIP-7702 is too powerful, breaks a lot of assumptions. It may become the new selfdestruct (always somehow breaking something), especially by making bytecode mutable again. Maybe in a few years 7702 will be nerfed too (limited to one-time action). The Ugly: - Scope was a changing hall of mirrors. Code is shifting as you review it, and hundreds of open issues and open PRs on each of the ten+ repos mean that any bug may be old news. - Unlike contracts, there's no "diff" to guide the review, all past, future, unrelated, and hypothetical code is all there all the time on the main branch behind feature flags. - Some codebases are much harder to follow and grok. Overall, an amazing challenge and experience. Can't wait to read all the issues and watch the upgrade roll in 🍿

English
3
6
76
13.5K
Storm retweetledi
0xfirefist
0xfirefist@0xFireFist·
It's so strange how you see something, and you're like "Wtf, there is no way I can understand this, this is some big brain thing," and then you put the effort and understand that it's nothing special. Put the effort!⚔️
English
3
3
45
2.1K
Storm retweetledi
Hunter
Hunter@Huntoor·
@SpecterAnalyst whitehat bounty to a phishing attack😂
English
1
1
6
729
Storm retweetledi
Nolan | Exvul
Nolan | Exvul@ma1fan·
First time receive USDC bug bounty at @hackerone 😀😀😀
Nolan | Exvul tweet media
English
10
7
123
8.5K
Storm retweetledi
Toad
Toad@TrainTestToad·
My DMs are a wasteland of junior auditors I gave advice to and asked to update me on their progress, never to be heard from again. One day someone will have the sticking power 🙏
English
10
1
64
7.2K
Storm retweetledi
0xSimao
0xSimao@0xSimao·
1/ Wondering how to make sure the math accounting adds up? I've got you covered, here's how you can become a human fuzzer 101. In the mentorship episode #14, we show exactly how to do it 0xsimao.com/blog/mentorshi…. Thread 🧵
English
2
8
79
14.1K
Storm retweetledi
pkqs90
pkqs90@pkqs90·
Lessons learnt: 1. Never do weird conditional pots. 2. If zero questions were answered during the contest, leave contest immediately. 3. When sponsor suddenly comes back 3 months after contest ended and tells everyone a core feature which was extremely buggy is out-of-scope because it was unfinished, don't bother arguing. Anyways, still happy to win my first non-solidity contest.
Cantina 🪐@cantinasecurity

The @spaceandtime competition has wrapped. Researchers audited the full SXT stack, from the zk coprocessor to staking and payments. 🥇 @pkqs90: $12,888.28 🥈 @Chupinexx: $3,755.38 🥉 Rareone: $2,995.26 Congratulation to everyone that contributed.

English
9
5
195
11.3K
Storm retweetledi
ControlZ
ControlZ@ControlZ_1337·
Ok, here are the statistics for confirmed and paid findings from the past ~2 months, assisted by the AI tools I’ve been working on: @immunefi : 2 Criticals 1 High 1 Low (marked as Critical but should be downgraded due to default configuration restraints) @HackenProof : 1 High @Hacker0x01: 1 High Private Bug Bounties: 2 Critical 1 Low Total payouts are expected to be roughly ~$400K. Payouts tend to move slowly, so more of the results should become public over time.
ControlZ tweet media
ControlZ@ControlZ_1337

Yesterday I shared that, over the past ~2 months, I’ve been working on AI agents for security research in the Blockchain/DLT space. It seems to have sparked some interest, so I’m wondering - would you be interested in seeing the actual results and stats from that period?

English
13
7
137
13K
Storm retweetledi
Gowtham Naidu Ponnana🇮🇳
Gowtham Naidu Ponnana🇮🇳@gowtham_ponnana·
Today, I'm officially announcing that I'll be joining @trailofbits in January 2026. It's one of the companies I've always wanted to work for since starting my cybersecurity journey. Huge thanks to @CarterToB for keeping me in the loop and for your support—you made the process much easier. I'll be working under @thebensams, and I'm excited to help secure top protocols. Special thanks for believing in me, Ben 🫂 By the way, Ben also approves that I'm 6'6", so no more doubts, anyone 😏 Thanks to @Montyly for all the tips and sharing your experience about ToB. When I applied, I wanted to work with you, but life had other plans. That's it, everyone! I'm now a new family member of Trail of Bits ❤️❤️ [So basically, I've engraved my age onto AirPods to remember when I made it into ToB] — Thanks for the home-setup, team 😅😘 While there's some time before I join, I'm gonna touch some grass 😉
Gowtham Naidu Ponnana🇮🇳 tweet mediaGowtham Naidu Ponnana🇮🇳 tweet media
Gowtham Naidu Ponnana🇮🇳@gowtham_ponnana

Age 20 ended, And Today, Officially retiring from @techfund_inc as Senior Security Researcher, The last few years there have been nothing short of brilliant. Had a chance to represent TECHFUND where I go. Along with it, Concluded by final private audit with @Hashlock_ !! Thank you for believing me throughout and giving me the opportunities. Some unexplored road awaiting my arrival 😉 Guess where I'm going nexttt!!

English
69
6
413
30.7K
Storm retweetledi
WhiteHatMage
WhiteHatMage@WhiteHatMage·
I'm sure I should be able to automate some things. Once I get some very specific heuristics, with a great static analyzer rule, or some smart AI, it should be able to detect the issue with great confidence. I'm getting better at those heuristics, but still too much manual work.
English
4
1
25
1.6K
Storm retweetledi
0xSimao
0xSimao@0xSimao·
Just finished uploading with notes 12 mentorship videos! 6 hours of pure alpha on the Mento V3 contest on Cantina 🫡 Enjoy 🫶 0xsimao.com/blog/mentorshi…
English
4
6
127
5.1K
Storm retweetledi
Drastic Watermelon
Drastic Watermelon@DrasticWM·
very very very happy to share that I've been promoted to SR level at @spearbit I've had the goal of reaching this feat ever since I've started working in web3sec and I've looked up to researchers in this spot for so very long. can't wait to see what 2026 brings 🥳
Drastic Watermelon tweet media
English
17
3
99
3.6K
Storm retweetledi
phil
phil@philbugcatcher·
What’s stopping you from auditing like this, anon?
phil tweet media
English
47
5
213
8.5K
Storm retweetledi
LonelySloth
LonelySloth@lonelysloth_sec·
Bug bounty hunting isn’t about getting good at one hard thing. It’s about learning new things and getting good at them again and again and again. Each year feels a bit like starting from scratch again.
English
5
7
124
3.3K