Blackscale

438 posts

Blackscale banner
Blackscale

Blackscale

@blackscale_

⚓ solidity super c̶o̶d̶e̶r̶ auditor

Katılım Mart 2018
832 Takip Edilen82 Takipçiler
Blackscale retweetledi
Jeff Security
Jeff Security@jeffsecurity·
Reproduce ZKP vulnerabilities. This repo includes 89 vulnerabilities in the following DSLs: I’d appreciate a retweet, spread the knowledge 🫡 github.com/zksecurity/zkb…
English
1
28
110
5.3K
Blackscale retweetledi
Klaas
Klaas@forgebitz·
lots of vibe coders are going to learn the difference between authentication and authorization it's not a fun thing to learn the hard way
English
176
218
5.8K
621.1K
Blackscale retweetledi
Hari
Hari@hrkrshnn·
PSA: Please don't fork Aave's codebase and launch it on a new chain. You are very likely to get hacked if you do. It can look very tempting: there's a new chain, and you see that no lending market is available. Fork Aave, onboard all the top assets, set whatever risk parameters you want, launch a governance token, profit $$$. However, building a lending market is hard. Forking and working with Aave's codebase is even harder if you don't have the right experience. Teams vastly underestimate the complexity of maintaining and securing a lending protocol. I'm pretty confident there are blackhats specifically targeting Aave forks. Don't get rekt 🫡
English
16
18
264
33.9K
Blackscale retweetledi
0xSCSamurai ⚔️
0xSCSamurai ⚔️@0xSCSamurai·
Web3Sec is tough as FCUK. Most beginners quit. 90%-99% joining every year, QUIT. Remind yourself of this fact whenever necessary. And then, double down and grind on. Bugs dont find themselves... This is *not* an April Fool's joke. 👊
English
8
12
130
4.8K
Blackscale retweetledi
0xbow.io
0xbow.io@0xbowio·
gm Ethereum ☀️ It is our great honor to announce the mainnet launch of Privacy Pools! ETH users can now achieve on-chain privacy, while still dissociating from illicit funds It is now up to all of us to Make Privacy Normal Again 🫡 More info in this thread 👇
GIF
English
115
387
1.7K
414.7K
Blackscale retweetledi
Luca Beurer-Kellner
Luca Beurer-Kellner@lbeurerkellner·
👿 MCP is all fun, until you add this one malicious MCP server and forget about it. We have discovered a critical flaw in the widely-used Model Context Protocol (MCP) that enables a new form of LLM attack we term 'Tool Poisoning'. Leaks SSH key, API keys, etc. Details below 👇
Luca Beurer-Kellner tweet media
English
72
389
2.2K
380K
Blackscale retweetledi
Hardhat
Hardhat@HardhatHQ·
Hardhat 3 adds stack traces to your Solidity tests experience, and the paths are clickable! ✌️👷 Check out the alpha release hardhat.org/hardhat3-alpha
GIF
English
4
12
75
6.3K
Blackscale retweetledi
Bloqarl | Zealynx
Bloqarl | Zealynx@TheBlockChainer·
You don’t need to be a genius to be a great security researcher. You need a sharp eye, relentless curiosity, and the patience to dig deeper than others.
English
3
11
127
5K
Blackscale retweetledi
Martin Marchev
Martin Marchev@MartinMarchev·
Lots of bugs in smart contracts don’t come from complex math. They come from confusion. Confusion starts with poor naming. Clear naming = easier audits, fewer bugs and faster dev speed. ‘Meaningful names’ is the first chapter in Uncle Bob’s classic Clean Code for a reason.
English
4
7
111
3.6K
Blackscale retweetledi
Georgios Konstantopoulos
Georgios Konstantopoulos@gakonst·
I'm looking for an API that I can call `/onramp?address=0x1234&chain=1&applePayPaymentInfo=...`. User Pays Apple Pay, gets paid stablecoin. Headless, no KYC for <$500 lifetime value of the user. Acceptance rate >60-70% (hard with crypto :/). Who's building this?
English
83
12
328
212.7K
Blackscale retweetledi
Tay 💖
Tay 💖@tayvano_·
🚨 There are some crazy threat actors lurking among us This guy “Nick” has a year+ persona, is hanging out in the infamous ethsec tg, and has multiple long-running dms open with multiple (legit) security researchers. If you opened his “PDF” pls turn off your computer NOW.
Anton Bukov (e/acc)🦇🔊@k06a

English
32
104
665
197.8K
Blackscale retweetledi
tanuki42
tanuki42@tanuki42_·
Meet Nick Franklin @0xNickLFranklin - Blockchain Security Engineer…. or RGB operative hacking for DPRK? Seemingly this guy has had the entire industry fooled for years.
tanuki42 tweet media
English
26
64
326
118.5K
Blackscale retweetledi
0xFrankCastle🦀
0xFrankCastle🦀@0xcastle_chain·
For those asking which protocol to shadow audit or if they can practice on a previous codebase I’ve audited, you should focus on the highest-quality codebases to understand what secure code looks like. 🫡 Native Rust 🦀: github.com/raydium-io/ray… Anchor⚓️: github.com/raydium-io/ray…
English
0
15
137
5.4K
Blackscale retweetledi
ₕₐₘₚₜₒₙ
ₕₐₘₚₜₒₙ@hamptonism·
I’m addicted to learning because the right information can change your life.
English
39
625
5.9K
144.6K
Blackscale retweetledi
JyteCeo
JyteCeo@JyteTechNft·
If you're a Solidity dev looking to level up (and not get roasted in audit reports 😅), take 10 minutes to read through this. You will be glad you did! 🤝 -- rareskills.io/post/solidity-… --@RareSkills_io
English
1
7
61
2.1K
Blackscale retweetledi
Hardhat
Hardhat@HardhatHQ·
Tests written in Solidity alongside good ol’ Solidity stack traces 👷‍♂️ Check out the Hardhat 3 alpha hardhat.org/hardhat3-alpha
Hardhat tweet media
English
4
14
106
9.8K
Blackscale retweetledi
zack
zack@zack_overflow·
I made a regex visualizer/debugger which lets you visually understand the finite state machine representation of a regular expression And added gratuitous explosions and particle effects of course Made with Zig + sokol
English
102
311
4.3K
243K
Blackscale retweetledi
FFmpeg
FFmpeg@FFmpeg·
FFmpeg makes extensive use of hand-written assembly code for huge (10-50x) speed increases and so we are providing assembly lessons to teach a new generation of assembly language programmers. Learn more here: github.com/FFmpeg/asm-les…
English
91
1.2K
8.6K
461.3K