cvh
593 posts

cvh
@cvhessert
build, automate, secure, validate, advise, invest & repeat | VP, Security & Smart Contracts @0xPolygonLabs | Re/Tweets are my own | 🇦🇷
Amsterdam, The Netherlands Katılım Aralık 2008
1.1K Takip Edilen663 Takipçiler
Sabitlenmiş Tweet

AppSec in the AI era will be less about reviewing code and more about operating systems that:
Attack. Triage. Improve. Repeat.
AI swarms finding and exploiting weaknesses.
AI triage validating impact, killing noise, scoring real risk.
Even opening the PR.
Continuous. Autonomous. Human-guided.
English

Everyone wants an AI red team swarm constantly breaking their own code
But that’s not the hard part
The real bottleneck is triage
If your system generates 500 findings a day and you can’t automatically validate exploitability, dedupe noise, score real business impact, and chain issues into real attack paths, you don’t have security
You have alert fatigue
Build the triage brain first, thats what I’m focusing on!
English

About time! Thanks 🙏
Boris Cherny@bcherny
Introducing: built-in git worktree support for Claude Code Now, agents can run in parallel without interfering with one other. Each agent gets its own worktree and can work independently. The Claude Code Desktop app has had built-in support for worktrees for a while, and now we're bringing it to CLI too. Learn more about worktrees: git-scm.com/docs/git-workt…
English
cvh retweetledi

New: I'm sharing the @trailofbits Claude Code defaults. This is how we setup, configure, and use claude code:
github.com/trailofbits/cl…

English
cvh retweetledi
cvh retweetledi

cvh retweetledi


@TenderlyApp can you build an @claudeai Agent Skill to build, run and interpret simulations?
English
cvh retweetledi

Top-5 complex attack you must learn
🏴 Kyberswap bounty
🔗 100proof.org/kyberswap-post…
🏴 1inch exploit
🔗 blog.decurity.io/yul-calldata-c…
🏴 GMX $41M Hack
🔗 blog.solidityscan.com/gmx-v1-hack-an…
🏴 VTHO accrual bug
🔗 immunefi.com/blog/all/vecha…
🏴 Euler Finance hack
🔗 cyfrin.io/blog/how-did-t…
English
cvh retweetledi

... after three long days with claude code, i have this to share:
→ SlotScan.info a human readable web ui for evm storage visualization (supports Solidity + Vyper)
→ Blog post documenting my learnings: wavey.info/posts/2025/rev…
English

cvh retweetledi

Nice article, to add a bit on the re-audit aspect. The way I plan and think of this is dividing your budget and yearly plans on GROW and MAINTAIN line items.
GROW is what most projects normally do, bigger budget for new products, features, etc. They all get audited/pen-tested, ideally more than once.
MAINTAIN is a smaller budget, specifically for new audits on existing products/apps. Can be full scope or with a specific one, or targeted to specific objective / goal like a CTF or Red Team engagement.
For example, in traditional web2 / SaaS companies, and also as required by various certifications and regulations, yearly network and application Pentest are the norm.
English





