Clover
1.5K posts

Clover
@actuallyclover
26 y/o artist w/ Bachelors in Cyber Operations 💻 | Current System Administrator, Security Researcher & Bug Bounty Hunter 👾
🖥️~root@localhost: Katılım Haziran 2017
689 Takip Edilen4.1K Takipçiler
Sabitlenmiş Tweet

@rez0__ hasn't caido had a proxy mcp available for a while now? I've been using one with claude code that does what this article mentions, presumably the one they're talking about?
English

I have had a support ticket open with your team for a little over a week (with no response) regarding a paid cert that I can't access @TCMSecurity, can you please get back to me.
English

@the_cia_hacker was it the zero day that exposed emails/numbers tied to the acc then you just sim swapped? i remember when that bug was floating around and accounts were getting popped.
English

i had a twitter 0day back in 2014 with another hacker named XTM which gave us access to ANY account. we hacked CartiB, FamousDex, Lil Uzi, etc
its 2026 now and i have to pay someone 10k just to access my own account
which level in Dantes Inferno is this?
Justin Liverman@the_cia_hacker
highkey ill pay someone $10k to recover my twitter @_d3f4ult since nikita is busy doing anything but assisting users and every contact i had there was fired
English


Another red week together with the critical gov representative @bankrollgov whos making WAFs blush left & right
with dem new swaggy pins,
a waf = waffle




English

essentially used this tool but a buffed version that I haven't released.. tbh I just modified skills and added more autonomous reviewing.. all added with AI. x.com/actuallyclover…
Clover @actuallyclover
made a tool that maps every HackerOne bug bounty program to its github repos (116+ programs). github.com/actuallyclover… #bugbounty #tools #opensource
English

Yay, I was awarded a $500 bounty on
@Hacker0x01! hackerone.com/0xclover #TogetherWeHitHarder (I had my AI review an open source code base and found an SSRF within an APK).
English


This is actually insane 🤯
JaredFromSubway's MEV bot (the one that's been printing money for ages) just got cooked for $7.5 million in one of the sneakiest exploits I've seen.
This wasn't a contract hack. It wasn't phishing.
The bot basically approved its own robbery because it thought it was about to feast on a juicy MEV opportunity.
What happened:
> Attacker deploys fake wrapper tokens (fWETH, fUSDC, fUSDT) along with fake liquidity pools designed to look profitable
> The bot spots the "opportunity" and does what it's programmed to do, approving attacker-controlled helper contracts as spenders
> During early tests, those approvals get used immediately, so nothing appears suspicious
> In later transactions, the bot grants approvals that are never consumed or revoked, leaving the attacker with unlimited spending power
> Once enough approvals are collected, the attacker executes the final drain
> WETH, USDC, and USDT are pulled directly from the bot contract via transferFrom and sent to the attacker's wallet (0x3e37f4A10d771Ba9dE44b6d301410b1BEdeA65d0)
One example:
The bot approved more than 92 WETH to one of the attacker's helper contracts, and that approval simply remained active until the funds were drained.
This wasn't some random wallet drainer.
The bot's own automation was turned against it. It was doing exactly what it was designed to do, and that logic ended up being its downfall.
Wild times in MEV land.
Always revoke approvals, kids.
Even if you're a bot making millions.



English

Ive been trying hard to stop @bankrollgov from eating the akamai pills, and multiple wafs later this is the results on the best platform out there @intigriti




English

@hshagshsu honestly xss was something i got into early as a kid just from messing around with HTML code and learning about HTMLi and then learning that you could do XSS, I started early maybe around 2013. There are SO many great resources for XSS online.
English

2 years later and I'm over $20k+ in earnings from bug bounty. Consistency and practice pay off!
Clover @actuallyclover
So so so happy that I finally achieved my first bug bounty report that wasn't a duplicate!!😅On a private program too! Such a good way to start off the New Year! ❤️🔥 Thank you! @Hacker0x01
English

@TheMrEviil complete the hackerone ctfs or hunt on VDPs on hackerone!
English

@n4itr0_07 there is ALWAYS time to get back into it, don't get mad at yourself 😎 you got this <3 i also took a lot of breaks along the way due to life but coming back never hurts ;)
English

@actuallyclover I think we started the same, but I lost consistency. I just see read posts, write-ups, but in practical i never gave my time. I am pissed, bro.
BTW, Congrats, keep hunting.
English

@hshagshsu i always look for everything but my main niche is definitely xss
English










