
Ward Audits
34 posts

Ward Audits
@WardAudits
The rising duo in the field of Web3 Security. For audit requests: https://t.co/DgwiYEDXdv


Today, we're launching the @Injective bug bounty program on Cantina. The scope covers the following: injective-core, Peggy bridge, swap, RFQ, and five web surfaces, including Helix, Mito, and Hub. Which bounty are you going after first? Program details: cantina.xyz/bounties/79042…


After careful consideration, we’ve made the decision to wind down @code4rena. This community has meant a great deal to everyone who has been part of building it, and sharing this news is not easy.

Inspired by ily2, I temporarily paused private audits to focus fully on bug bounties a month ago. My results so far: - Submitted 4 High + 1 Critical. All valid, 100% signal. - 2/5 were duplicates. Zero payout. - 2/5 were closed as "Informative". The reasons: - "We already know and are OK with it." No fix, no payment. - The other one was a straight-up scam lmao. Fixed with no pay; reasoning was "behavior is considered by design." I can't say much, but it would've resulted in a permanent protocol DoS and locked funds. - 1/5 Critical passed triage, pending review... I'm going to keep grinding for a while.


seeing all the horror stories on here about bug bounties, and having lived some myself, i don't think i can see myself ever bounty hunting again we desperately need to radically rethink the incentives here




I heard that this item increases the chance of finding a critical by 10% Thank you @OddlySpecivik for the hat! @immunefi #immunefi








We are thrilled to share that our smart contracts on the Scroll network have been developed with the incredible support of @WardAudits. Big shoutout to @WardAudits for helping us bring our smart contracts to life on the Scroll. Thanks to their magic touch, our contracts are now secure, efficient, and ready to rock the blockchain world! We couldn’t have done it without you, here’s to many more adventures together! 🚀

@danielvf Here is the earliest instance I recall of this in web3, although the idea is found more often in web2 @nnez/different-parsers-different-results-acecf84dfb0c" target="_blank" rel="nofollow noopener">medium.com/@nnez/differen…

I call it a "two parser bug". Two different implementations tracking the same input, and parsing differences cause diverging behavior from different parts of a system. Here's two recent examples used in hacks, and how to avoid. 🧵1/5

