Prince Allwin

67 posts

Prince Allwin banner
Prince Allwin

Prince Allwin

@allwin199

Smart Contract Engineer | Auditor | Web3 Security Researcher | Interested in #web3 #Blockchain #Ethereum #Defi #DAO | Contributing to @OpenZeppelin

Katılım Haziran 2023
489 Takip Edilen32 Takipçiler
Patrick Collins
Patrick Collins@PatrickAlphaC·
Working on updating everything for the 2024 edition of the Cyfrin Updraft foundry and solidity curriculum. Wish me luck
English
52
19
441
15.3K
Owen | Guardian
Owen | Guardian@0xOwenThurm·
If you have yet to find a partner in the wild west of Web3 Security go ahead and post in the comments of this tweet 👇🫡
Owen | Guardian@0xOwenThurm

Auditing becomes very *very* fun once you're over the hump. Still trying to break through that barrier? Just follow these steps in order: 1️⃣ Learn The Basics I covered it all for you, get all the basics down with the following playlist: youtube.com/playlist?list=… After that, you know everything you need to get started. 🫡 2️⃣ Start Competing In Contests Here are some platforms to try out: - @CodeHawks (First flights to start) - @code4rena - @sherlockdefi - @cantinaxyz - @HatsFinance Now let's set the expectations before you dive in, contests will be hard, that's expected. Rising through the ranks and gaining mastery is extremely time-intensive and in the beginning... quite brutal. In the beginning: • You'll feel overwhelmed in a new codebase • You'll struggle to uncover solid high findings • You'll struggle to uncover solo findings • You'll find it hard to even learn from each audit We need to get out of this beginner phase ASAP. This is where the majority of folks get stuck. Let's not get stuck. 3️⃣ Absorb From Someone Who's Already Done It To rocket out of the beginner's phase let's learn from the experience of those who have done it before us. We can absorb years of Web3 Security experience in weeks just by working alongside a security veteran. Not only that but having a partner to audit with can drastically accelerate your rate of understanding a codebase. → Consult the code → Consult your partner → Understand the code more Do anything you can to get around and learn from someone who's put in the time and done the head-banging for you. Offer to: • Write reports • Write articles • Create PoCs • Create Fuzzing or Test Suites Anything you can do to provide value and get your foot in the door. Spending just 1 week with a Web3 Security veteran can outperform months of work. It's about learning what you don't know that you don't know. 4️⃣ Partner Up! Web3 Security gets tough! If you have a partner you're much more likely to stick it through and see the fruits of your labor on the other side. Not only that but having a partner to audit with can drastically accelerate your rate of understanding a codebase. → Consult the code → Consult your partner → Understand the code more 5️⃣ Get The Feedback Loop Right Your feedback loop is everything when it comes to mastering a new skill. Auditing is no exception. If your feedback loop is off you can spend months working without making any noticeable progress...😨 You can gauge the effectiveness of your feedback loop by your contest results: Clearly increasing with a stair-step effect? Yes → You got the feedback loop down No → You need to go back to the drawing board If you aren't seeing a clear stair-step effect in your contest results here's what might be happening: You do a contest, wait weeks for the findings to come out, see what you missed and study that. Here's what's wrong with that: • The loop is too slow If you're waiting more than a day or so to get feedback on your work, you're wasting time. Plain & simple. Drag your future into the present and figure out a way to shorten that feedback loop. • Auditing is not flash cards You can't memorize findings and then copy-pasta them into new codebases. The worthwhile findings don't function that way. Start seeing real improvements by getting actionable feedback on your auditing approach, not the outcome. A fantastic way to do this is by consulting someone ahead of you or auditing in a team and observing how others come to new findings. 6️⃣ Gain Credibility Security review demand is driven by credibility. Clients are trusting you with millions of $TVL. However, to get credibility you must have secured millions of $TVL already. We have a bit of a chicken & egg situation.🥚 There are several ways to tackle this, here's a favorite of mine: Find a new open-source project being launched by a big name in the space. Learn everything there is to know about it and spend an entire month auditing it. Present your findings to the team in a comprehensive report, and ask for nothing in return. Now you have a fantastic report for a big name in your portfolio of work. Chicken & Egg → Solved. Bonus points if you complete a fuzzing suite for them. 7️⃣ Go To The Market You've got a handful of contests under your belt. You've worked with several auditors & learned from their approach. You've completed a thorough engagement for a well-known team. And now you're ready to go to the market! Now it's time to see the fruits of your labors. 🏆 Use your network to get your initial reviews or shadow audits with a firm. The most important part here is doing your absolute best. Opportunities multiply when you deliver exceptional work. And that is exactly how you can join the Web3 Security industry! Best of luck, we need you in here. 🤝

English
2
1
15
2.3K
Prince Allwin retweetledi
ddimitrov22
ddimitrov22@ddimitrovv22·
A friendly reminder that the PUSH0 opcode is now supported on Arbitrum, Optimism, and most of the L2s. You can use newer pragma versions safely. From the Arbitrum Docs
ddimitrov22 tweet media
English
0
6
24
1.8K
Prince Allwin retweetledi
Patrick Collins
Patrick Collins@PatrickAlphaC·
It's finally time. 3 months ago, we launched Cyfrin Updaft in closed beta because we wanted to give you an amazing experience. And now, Updraft has exited early access and is live for everyone. Let's build the web3 we promised.
Cyfrin Updraft 🟩@CyfrinUpdraft

3 months ago, we launched Cyfrin Updaft in closed beta. Since then, we received: - 70,000+ applications - 11,000+ early access students - 2000+ feedback Today, we open the ultimate web3 education platform to everyone ✨ Here's how to get access for free 👇

English
23
41
236
18.1K
Prince Allwin retweetledi
Bloqarl | Zealynx
Bloqarl | Zealynx@TheBlockChainer·
Beware of this scam from @crankibugatti!! I can see also @ShieldifyGhost and @cholakovv are following him. Pass this on and block him!
holydevoti0n@HolyDevoti0n

Security Researchers... be aware of this scam(@crankibugatti). This guy will approach you to ask for a private audit but in the end, he wants you to download a keylogger/trojan. I noticed several folks are already following him like @xb0g0 @Seecoalba @CrystAlline_K42.

English
3
1
14
913
Cyfrin Updraft 🟩
Cyfrin Updraft 🟩@CyfrinUpdraft·
3 months ago, we launched Cyfrin Updaft in closed beta. Since then, we received: - 70,000+ applications - 11,000+ early access students - 2000+ feedback Today, we open the ultimate web3 education platform to everyone ✨ Here's how to get access for free 👇
Cyfrin Updraft 🟩 tweet media
English
36
75
312
83.3K
Prince Allwin retweetledi
Mr Anon
Mr Anon@ShieldifyAnon·
Tired of failing your Web3 interviews? Web3/Web3 Security interview questions! Try it! 👇 jumpdest.dev
English
5
11
61
7.1K
Prince Allwin
Prince Allwin@allwin199·
@pashov Hard work definitely pays off. Thanks for sharing valuable resources and motivating people like me.
English
0
0
1
119
pashov
pashov@pashov·
I made six figures (~$100k) in profit in the month of August 2023 providing smart contract security services for protocols. I worked like crazy. For years. On a daily basis. It paid off.
English
66
46
922
104.7K
Prince Allwin retweetledi
Cyfrin CodeHawks
Cyfrin CodeHawks@CodeHawks·
🚨New contest: Ditto 🚨 Sign up here: codehawks.com/contests/clm87… Total rewards: $55,000 nSLOC: ~3365 Audit length: 30Days (8th of October) Start date: Tomorrow 8th of September Check it out!
English
1
13
89
16.2K
fedebianu
fedebianu@fedebianu·
Months ago I quit my job to pursue a career as a smart contract security researcher. Here is it went so far. 🧵
English
16
17
168
18.5K
Owen | Guardian
Owen | Guardian@0xOwenThurm·
⚠️ Free Stuff Alert Are you looking to transition into a full-time job in Web3? If you'd like to work with me 1-1 to master your Web3 development skills to get that Web3 job comment down below.👇
English
175
4
105
25.5K
dimulski
dimulski@dimulskiatanas·
🎉Starting today, I'm a member of the @QuillAudits Red team. I am eager to apply my skills and learn from some of the brightest minds in this field!
English
3
0
13
1.5K
dimulski
dimulski@dimulskiatanas·
My stats for August 📊 - earned ~ 170$ - 2 team audits (~ 140$) - 1 solo audit (~ 30$) This was my 4th month in auditing, starting to see some results. I'll work much harder in September 🙏 @code4rena @CodeHawks @sherlockdefi Thanks for the opportunity 🫡.
English
5
2
61
4K
Prince Allwin retweetledi
Sigma Prime
Sigma Prime@sigp_io·
🚨 Reminder: the Goerli testnet will no longer be supported after Q4 2023! 🚨 Developers and users should migrate to Sepolia for testing and development purposes.
English
0
6
25
2.7K