Arjuna

249 posts

Arjuna banner
Arjuna

Arjuna

@arjuna_sec

Invariant-based smart contract audits. Rust-Solana. Cross-chain.

Rust Katılım Şubat 2025
61 Takip Edilen320 Takipçiler
Calcifer
Calcifer@calc1f4r·
Another Day Another @cantinaxyz Result Grinding Day by day 🔥
Calcifer tweet media
English
6
0
77
2.4K
Arjuna
Arjuna@arjuna_sec·
Soroban doesn’t just patch Reentrancy : It removes conditions that make it possible With host-managed state, isolated contract calls, and a WASM-based model, the attack is almost impossible by design. ✨Read how Soroban does it in our latest blog arjunasec.xyz/blogs/How-Soro… #Web3 #Web3Security #soroban #rust
English
0
1
14
641
Arjuna
Arjuna@arjuna_sec·
🔥To all struggling to understand vulnerabilities in the @steller smart contract ecosystem: We wrote an article explaining issues, beyond logical vulnerabilities, that can lead to your contract being exploited. arjunasec.xyz/blogs/Soroban%…
English
3
6
24
1.6K
Arjuna
Arjuna@arjuna_sec·
We want to share that @ctrusonchain, our co-founder, is no longer part of @arjuna_sec. We’re deeply thankful for all the passion and dedication brought to the team. Wishing @ctrusonchain the very best in this next chapter.
English
0
0
10
793
Arjuna
Arjuna@arjuna_sec·
@RedsReporter @Bobstroudsnr @GBNEWS Absolutely, @Bobstroudsnr! That film's a mind-bender—great storytelling or subtle foreshadowing? Predictive programming always adds a fun layer of intrigue. What's your favorite "hidden" example? 🎥🕵️‍♂️
English
3
1
1
50
Arjuna
Arjuna@arjuna_sec·
After a lot of months of downships we are soo live to hunt again!!! 🔥
English
0
0
10
935
Arjuna
Arjuna@arjuna_sec·
🧵Remediation 🌿 Before closing the token account, make the token_account.amount ==0 and if not transfer it to some associated address then close the account.
English
1
0
3
256
Arjuna
Arjuna@arjuna_sec·
🦀 Day 30 of #30daysOfSolanaSec 👌 Let's explore a DoS vulnerability that can occur when closing a token account. 🧵1/n Here's a concise example code snippet that allows depositing a mint into PDA token account, withdrawing, and closing the token account once fully withdrawn. Hint : there is a dos up here which can be done that will allow the withdraw instruction to fail. #30days0fSolanasec #web3security #solanasecurity #web3security #sec3 #web3
Arjuna tweet media
English
1
0
18
1.3K
Arjuna
Arjuna@arjuna_sec·
🌿Remediation When working with mint created using token 2022 instruction, try to use all the instruction associated with token 2022 program only and its vice versa.
English
0
0
0
170
Arjuna
Arjuna@arjuna_sec·
🧵4/n What is the issue in the snippet? The super_minter program aims to create and manage a digital coin, SUPER_TOKEN, using the Token-2022 standard for its enhanced features. `Initialize function` : This correctly sets up SUPER_TOKEN using the Token-2022 program to create the mint account (the coin's blueprint). It also generates a Program Derived Address (PDA), the sole entity authorized to mint new SUPER_TOKEN coins. Mint_super_token function: This allows someone to receive new SUPER_TOKEN coins, using the PDA to authorize minting. The Problem : Using the Wrong Tool The error occurs in the mint_super_token function. It correctly identifies the PDA for minting authorization but mistakenly uses the old SPL Token program (spl_token_program) instead of the Token-2022 program (token_2022_program) that SUPER_TOKEN was created with. This will lead to dos vector in the minting.
English
1
0
0
194