Ward Audits

34 posts

Ward Audits banner
Ward Audits

Ward Audits

@WardAudits

The rising duo in the field of Web3 Security. For audit requests: https://t.co/DgwiYEDXdv

Katılım Ocak 2024
20 Takip Edilen66 Takipçiler
Ward Audits retweetledi
pessimist
pessimist@0xpessimist·
Once upon a time, two security researchers discovered a critical severity bug together. After more than seven months of mediation and being ghosted, their report was finally confirmed - only to be absurdly lowballed because of the term "up to". en.wikipedia.org/wiki/Pyrrhic_v…
English
1
2
11
621
Ward Audits retweetledi
pessimist
pessimist@0xpessimist·
Never send a bug report to Injective. You probably remember what @al_f4lc0n went through, but even worse happened, you may hear the story soon. Do not make any business with them.
Cantina 🪐@cantinasecurity

Today, we're launching the @Injective bug bounty program on Cantina. The scope covers the following: injective-core, Peggy bridge, swap, RFQ, and five web surfaces, including Helix, Mito, and Hub. Which bounty are you going after first? Program details: cantina.xyz/bounties/79042…

English
3
6
74
5.1K
Ward Audits retweetledi
pessimist
pessimist@0xpessimist·
We owe you a lot. If it weren't for Code4rena, I probably wouldn't have become interested in web3 security; might not even have realized such a field existed at all. Being such a great pioneer, thank you sincerely for the immeasurable contributions Code4rena has made to web3 and for all the people it has onboarded into the space over the years.
pessimist tweet media
Code4rena@code4rena

After careful consideration, we’ve made the decision to wind down @code4rena. This community has meant a great deal to everyone who has been part of building it, and sharing this news is not easy.

English
0
4
27
813
Ward Audits retweetledi
pessimist
pessimist@0xpessimist·
If the process regarding my three pending bug reports ends badly, I may take a break from bug bounty work -- either until the bull market starts to come back or until the number of AI spammers decreases and project teams start to act more ok towards bug bounty hunters again. This is something I do in my spare time and the treatment I've recently experienced suggests it may not be worth it (at least around these times). I hope my unresolved reports are ultimately handled fairly so that I won't feel the need to take such a break. It's heartbreaking to see that every bug bounty hunter goes through this rn. I'd also like to thank the project teams who consistently remain professional, respect bug bounty hunters and their work, and care about timelines -- simply for doing what should be normal.
DadeKuma@DadeKuma

Inspired by ily2, I temporarily paused private audits to focus fully on bug bounties a month ago. My results so far: - Submitted 4 High + 1 Critical. All valid, 100% signal. - 2/5 were duplicates. Zero payout. - 2/5 were closed as "Informative". The reasons: - "We already know and are OK with it." No fix, no payment. - The other one was a straight-up scam lmao. Fixed with no pay; reasoning was "behavior is considered by design." I can't say much, but it would've resulted in a permanent protocol DoS and locked funds. - 1/5 Critical passed triage, pending review... I'm going to keep grinding for a while.

English
2
2
17
1.1K
Ward Audits retweetledi
pessimist
pessimist@0xpessimist·
As I observe the growing use of AI on both the development and security sides -- and therefore the increasing density of low-quality commits or updates -- I become more convinced that if we had liquidity that was truly decentralized at the level of DeFi Summer, we would all got rekt. What's "protecting" things right now is the centralized and mutable nature of projects. But if you accept that this is how it should be, then you are part of the problem in this industry. Ever since we started treating centralization not as a risk but as a design choice, we've been on the wrong path.
English
4
2
16
642
Ward Audits retweetledi
pessimist
pessimist@0xpessimist·
Since this rant is a roller-coaster of topics, I will divide it into four sections. 1-) How do the best bug bounty hunters deal with problematic project teams? Spoiler: they are mortals like us and can't magically fix anything. I think that by listening/chatting with the best bug bounty hunters, I've understood their strategy: Just keep hunting. From the start, they choose the target mindfully. Hunt on bigger targets (in terms of TVL and bounty size, read this amazing article by @WhiteHatMage on this: whitehatmage.github.io/posts/bug-hunt…) but even then they don't assume that the process will go smoothly, and they focus on finding new vulnerabilities on a different target while their existing reports are being (not) resolved. They try to create as many opportunities as possible so that some bad faith actors won't totally stall them. However, this doesn't mean they don't care about unresolved reports. On the contrary, they behave very professionally in messaging channels and do not let go of a project that tries to avoid paying. This is their full-time job, and they want to get paid. 2-) Why this sucks? Unfortunately, the above situation shows how inclined we are to create more black-hats than white-hats, because there are only two scenarios that can create the incredible level of devotion I mentioned above: * You received one large payout, and because of that, no matter how many bad experiences you have, your belief that another large payout will come never fades. * You have an incredibly strong attraction to feeling like a hero and doing what is ethically right. Note: Many people do bug hunting *occasionally* (like myself), and the situation is completely different for that case. These two scenarios are related to creating devoted full-time bug bounty hunters. If we don't have established standards and legal enforcement (aka incentives), we will remain limited to creating only a ridiculously small number of consistent elite bug bounty hunters. We shouldn't wait for every project to get hacked in order for them to get incentivized to allocate more resources to security. 3-) Market actual security, not your newest product. Because products/services will change over time -- sometimes it will be AI, sometimes audit competitions -- but the need for security will never disappear. What we need to show project teams is not just which fancy tool to use to achieve security, but that they genuinely need a “security-first” mindset. Security is not achieved through a single best product, but rather by getting various services. Instead of only launching a large bug bounty or only paying for one expensive audit, distributing the budget across both of these will produce a much better outcome. It feels like, instead of sharing the pie wisely, we are allowing most of it to be captured by the newest trend. Nothing done with a “let's not miss the boat” mentality is truly innovation. There will be some successful products/services, but most of them will be forgotten, sunset, or be forced to evolve. 4-) Not all founders have been reading @RektHQ for years like we do Maybe you don't think much about it, but it is also important to realize that not all project teams have the same level of maturity. They just don't really think they need to allocate much to security. We need to teach some VCs that security is an actual thing and not a fucking marketing tool. You wouldn't believe how often I've heard bug bounty hunters say about major projects that “X project's codebase is terrible / is a mess.” Do you think the developers, founders, and VCs of those projects are even aware that this is the case?
kaden.eth@0xKaden

seeing all the horror stories on here about bug bounties, and having lived some myself, i don't think i can see myself ever bounty hunting again we desperately need to radically rethink the incentives here

English
1
4
15
1.3K
Ward Audits retweetledi
pessimist
pessimist@0xpessimist·
Last month, I reported a critical severity vulnerability in a Cosmos SDK-based blockchain project and was awarded a $20,000 bounty. Thanks to @WhiteHatMage for the advice on handling communications in private bug bounties.
pessimist tweet media
English
10
9
121
7.9K
Ward Audits
Ward Audits@WardAudits·
Ward is a "W" for our industry. 🏆
English
0
0
2
154
Ward Audits
Ward Audits@WardAudits·
Our team kicked off the year with an outstanding performance, earning bug bounty rewards from three Cosmos ecosystem projects in January, with a few more reports still pending resolution. github.com/WardAudits/por…
English
0
1
10
987
Ward Audits retweetledi
pessimist
pessimist@0xpessimist·
Some projects may still want to fork AAVE v2 governance, which is time-tested and reliable. I've found an edge case that doesn’t have much impact but could cause confusion if it happens. (Got permission to open the issue) 👻👻👻 github.com/aave/governanc…
English
1
4
12
1.4K
Ward Audits retweetledi
pessimist
pessimist@0xpessimist·
Second bounty in a row. 🫡 I wouldn't recommend spending time on Stride (stride.zone), they will give the lowest possible reward. Portfolio updated: github.com/WardAudits/por…
pessimist tweet media
English
0
3
16
1.2K
Ward Audits
Ward Audits@WardAudits·
We are proud to have contributed to bringing Starknet's best aggregator to the Scroll network. It was a pleasure working with Fibrous team and we look forward to many more collaborations! 🤝
Ward Audits tweet media
Fibrous@FibrousFinance

We are thrilled to share that our smart contracts on the Scroll network have been developed with the incredible support of @WardAudits. Big shoutout to @WardAudits for helping us bring our smart contracts to life on the Scroll. Thanks to their magic touch, our contracts are now secure, efficient, and ready to rock the blockchain world! We couldn’t have done it without you, here’s to many more adventures together! 🚀

English
0
6
16
3.5K
Ward Audits
Ward Audits@WardAudits·
We hope that you’ve gained a new perspective by reading these tweets and looking at the examples. And as you may notice, it’s actually more about multiple parsers rather than just two, so think of it that way and don’t limit yourself to look for only two. Thanks! (4/4) 🧵
English
0
0
9
176
Ward Audits
Ward Audits@WardAudits·
Thanks to @bl4ckb1rd71's memory, here is one of the earliest instances of the two parser bug: Gearbox Protocol Vulnerability Report by @__nnez (3/4) 🧵 x.com/bl4ckb1rd71/st…
engn33r@bl4ckb1rd71

@danielvf Here is the earliest instance I recall of this in web3, although the idea is found more often in web2 @nnez/different-parsers-different-results-acecf84dfb0c" target="_blank" rel="nofollow noopener">medium.com/@nnez/differen…

English
1
0
10
375
Ward Audits
Ward Audits@WardAudits·
After reading this thread, you'll gain a new perspective on your audits, get ready to be two parser pilled. 💊 Daniel Von Fange's tweet defines the two parser bug and provides great real-world examples; (1/4) 🧵
Daniel Von Fange@danielvf

I call it a "two parser bug". Two different implementations tracking the same input, and parsing differences cause diverging behavior from different parts of a system. Here's two recent examples used in hacks, and how to avoid. 🧵1/5

English
1
4
19
1.5K