TheSeersec

34 posts

TheSeersec banner
TheSeersec

TheSeersec

@TSeersec

Expert Audit & Pentesting crew securing. DeFi, blockchain,Web and AI Pentest. Uncovering vulnerabilities and fortifying systems. DM for audit

Katılım Eylül 2025
10 Takip Edilen3 Takipçiler
TheSeersec
TheSeersec@TSeersec·
Now, This inverted rounding made nextSqrtP from calcFinalPrice slightly exceed the tick boundary, and then calcReachAmount concluded and thinks the threshold was not reached. And then the fund drainage begins. We distilled you logics and cover edge cases. Just a DM ..,
English
0
1
1
9
TheSeersec
TheSeersec@TSeersec·
while calcReachAmount() function determines the input needed to hit the next tick boundary, and calcFinalPrice() derives the price given the actual input. Then both depend on estimateIncrementalLiquidity() for fee-based deltaL, which rounds down.
English
1
1
1
12
TheSeersec
TheSeersec@TSeersec·
This is just the close summary of kyberswap  attack. Difference perser issue. The Elastic's computeSwapStep() function calls two functions that each compute a price from swap parameters:
0xaudron@0xaudron

@nnez/different-parsers-different-results-acecf84dfb0c" target="_blank" rel="nofollow noopener">medium.com/@nnez/differen… @__nnez solid writeup on different parser causing different result resulting in critical security issue. It reminded me of @orange_8361 ‘s research of SSRF where different parsers parsed input differently leading to bypass of protections for SSRF. If you’re interested in learning more about research: youtube.com/watch?v=R9pJ2Y…

English
1
1
2
92
TheSeersec retweetledi
TheSeersec
TheSeersec@TSeersec·
TheSeersec is made up many Web3 security expert.We don’t just audit smart contracts. We fortify entire ecosystems against the exact class of attacks that just cost the industry another $292 million. We treat security as a holistic, living system , not a onetime report.
English
0
1
2
17
TheSeersec
TheSeersec@TSeersec·
Protocols has to know that smart contract audit is still necessary But they are now table stakes. This like locking the front door while leaving the back gate wide open to the infrastructure and third-party stack.
OpenZeppelin@OpenZeppelin

x.com/i/article/2047…

English
2
1
2
44
TheSeersec
TheSeersec@TSeersec·
4 steps that make ECDSA recover secure • Ensure it's 65 bytes long • Check that "s" is in lower half-order • Ensure "v" is exactly 27 or 28 • Check signer returned isn't address(0) Utilise ECDSA.tryRecover library, instead of reimplementing the wheel
English
0
1
2
10
TheSeersec
TheSeersec@TSeersec·
Be curious. Read widely. Try new things. What people call intelligence just boils down to curiosity. This is brief life of Security researcher.
English
0
0
0
5
TheSeersec
TheSeersec@TSeersec·
Auditing client codebase,and i saw the fear and determination in both face.Project dreams can turn into nightmares .A single vuln can drain project's liquidity. This is why ,We audits with a stress test model to break smart contracts logics because we know what is at stake
English
0
1
1
11
TheSeersec retweetledi
Dacian
Dacian@DevDacian·
Q) Why did audit contests die? All free market businesses without profitable business models eventually die (or get acquired frequently at unattractive terms). That is the root cause, everything else is a secondary consequence.
English
12
1
73
4.7K
TheSeersec retweetledi
dunadan
dunadan@udunadan·
Vulnerability research is the loneliest job in the world.
English
32
60
522
30.9K
TheSeersec
TheSeersec@TSeersec·
149 Million Passwords LEAKED A massive data breach has exposed 149 million credentials from Gmail, Instagram, and Facebook. Discovered by Jeremiah Fowler, this info-stealer malware leak is critical—check your security now.
English
0
0
0
72
TheSeersec
TheSeersec@TSeersec·
Our researchers just wrapped up another private audit 🔥 Report dropping soon @smartdeckk , kills it all and rare gem .. Cheers
English
0
1
1
22
TheSeersec
TheSeersec@TSeersec·
Security review checklist that catches 90% of issues: • Can funds be drained by anyone? • Can state be corrupted by non-owners? • Can the protocol be DOS'd cheaply? • Are all external calls handled safely? • Do economic incentives align with intentions?
English
0
1
0
16
TheSeersec retweetledi
TheSeersec
TheSeersec@TSeersec·
While auditors glance 2-3 times, TheSeersec Guardians stare deep, exploring every edge case to fortify your code. We’re the black hat nightmare, keeping threats at arm’s length....
English
0
1
0
12
TheSeersec retweetledi
TheSeersec
TheSeersec@TSeersec·
We turned down a 2-week Solidity audit yesterday, even though it was probably a lucrative opportunity. Why? we already committed to a 5-week protocol review, and trying to juggle both at once would be unwise.Based on my past experiences, I believe this was the correct choice.
English
0
1
1
24
TheSeersec
TheSeersec@TSeersec·
Auditing Tip Do reductionism. try and break function in smaller path. Understand it, analysis it and then try to go back and understand the whole complex situation. Check what happen when you go back to put everything together..
English
0
1
0
13