Decentralized Intelligence AG

147 posts

Decentralized Intelligence AG banner
Decentralized Intelligence AG

Decentralized Intelligence AG

@d23e_AG

Clara: Biggest DeFi Attack Dataset, Real-Time. https://t.co/LdwDaRLNM3 EVMDecompiler: Readable EVM Bytecode, integrated into Etherscan. https://t.co/nJmQgWS9tN

Web3 Katılım Mart 2023
20 Takip Edilen291 Takipçiler
Decentralized Intelligence AG retweetledi
Kaihua Qin
Kaihua Qin@KaihuaQIN·
Check this out 👇 evmdecompiler.com/public/result/… A heavily customized / obfuscated contract (likely not written in Solidity) that breaks essentially all existing decompilers. Our model, interestingly, recovers clean, seemingly reasonable Solidity matching the logic. No ground truth and I’m too lazy to fully verify 😅, leaving it to those interested to take a closer look.
English
1
6
21
3.5K
Decentralized Intelligence AG retweetledi
Real-time DeFiHacks Intelligence
Source: TenArmorAlert. At Ethereum block 24,575,085, $42.6k was drained from a USDC holder via UniswapV4Router04 calldata manipulation. It matters because a caller check tied to a fixed byte offset can let attackers spend from approved wallets.
Real-time DeFiHacks Intelligence tweet media
English
3
8
17
3K
Decentralized Intelligence AG retweetledi
Real-time DeFiHacks Intelligence
Source: @pennysplayer. Ploutos Market was exploited through an oracle feed misconfiguration. In block 24538897, an attacker posted only 8.879192 USDC and borrowed 187.366746 WETH. One wrong feed mapping broke collateral safety.
Real-time DeFiHacks Intelligence tweet media
English
3
4
13
3K
Decentralized Intelligence AG retweetledi
Decentralized Intelligence AG retweetledi
Decentralized Intelligence AG retweetledi
Liyi Zhou
Liyi Zhou@lzhou1110·
With @Zyy0530 ’s help, we just launched a new website that tracks the latest blockchain attacks, with detailed analysis and full exploit code. I have tested it myself and it is genuinely useful. Understanding and tracking new attacks is now much easier. No more jumping across different websites and piecing everything together alone. The key idea is simple. For each incident, we provide a very clean exploit implementation with clear explanations. While studying the transaction trace, you can directly compare it side by side with the victim contract’s source code. You quickly see why it was exploitable and where the bug is. Big thanks to @d23e_AG and @clara_oracle for covering the costs. Really generous support. We will gradually complete the entire dataset and fully open source it to the community. I will also document how to use it properly. The goal is to build another industry benchmark after the already excellent @DeFiHackLabs dataset. Open to collaboration of course. Ping us if you are interested. DM open
Liyi Zhou tweet mediaLiyi Zhou tweet media
English
3
3
24
1.3K
Decentralized Intelligence AG retweetledi
Wesley Wang
Wesley Wang@Zyy0530·
🚨 DeFi exploits have already caused over $15.75B in losses, yet incident response remains slow and fragmented. Traditional postmortem analysis faces several major challenges: 1⃣ Postmortem Lag Current workflows are heavily manual and evidence-limited, often taking days. This delay leads to incorrect root-cause conclusions and prevents timely defenses. 2⃣ Fragmented Data and Uneven Coverage The DeFi ecosystem lacks a comprehensive dataset for scientific evaluation. Incident coverage is uneven, and Proof-of-Concept (PoC) outputs vary greatly in quality. 3⃣ Incorrect Initial Analyses Early community reports frequently point to the wrong root cause, misleading defenders and slowing down effective mitigation.
Wesley Wang tweet media
English
5
4
23
4K
Decentralized Intelligence AG retweetledi
Real-time DeFiHacks Intelligence
Thanks to @DefimonAlerts — quoting the original post. TL;DR: On Ethereum, the LiteV3 Bridge Aggregator proxy 0x3f568a…b766 was upgraded, but not initialized atomically. In the gap, an adversary initialized + upgraded it, taking control of the UUPS proxy.
Defimon Alerts@DefimonAlerts

💬 Onchain Message: Hello, your proxy deployments have been backdoored by the malicious actors (CPIMP attack): 1. etherscan.io/address/0x3f56… 2. arbiscan.io/address/0x3f56… Consider calling initialize() atomically together with the proxy deployment to avoid the front-run. etherscan.io/tx/0x94c994929…

English
1
1
4
299
Decentralized Intelligence AG
Smart contract security starts beneath the surface, where most can't see. The EVM Decompiler lets auditors unlock Ethereum bytecode and catch hidden risks fast. Deep code, real visibility.
English
0
0
1
224
Decentralized Intelligence AG
Everyone's still chasing perfect code and clean audits. While hidden attack vectors are quietly breaking "secure" systems. To truly protect, focus on what auditors actually find. The next exploit won't come from obvious bugs. it'll come from complexity no one saw coming
English
0
0
0
185
Decentralized Intelligence AG
1/ Then I map attack vectors against those assumptions. The framework is simple: trust boundaries, state transitions, economic incentives. Most critical issues hide where these three intersect.
English
0
0
0
97
Decentralized Intelligence AG
Finding vulnerabilities isn't about running tools and hoping. It's pattern recognition layered with threat modeling. I start surface-level: what's the contract trying to do, where's the money flow, what assumptions does the code make.
English
1
0
1
128
Decentralized Intelligence AG
Everyone's chasing whales and quick wins. Meanwhile AI is quietly rebuilding the infrastructure underneath. The real transformation isn't the obvious plays. It's the processes no one's watching yet.
English
0
0
0
77
Decentralized Intelligence AG
The progression isn't sexy. Most top auditors spent months finding nothing, years grinding through false positives and missed vulnerabilities. The industry sells overnight mastery, but real expertise in smart contract security is built on consistency, not brilliance.
English
1
0
0
66
Decentralized Intelligence AG
Security tools scan for what's there in code. But the real vulnerabilities? They're in what's missing. unchecked inputs, absent constraints, ignored edge cases. AI-enhanced auditing must detect absence, not just pattern-match presence.
English
0
0
0
51
Decentralized Intelligence AG
2/ They build comprehension, then flip to adversarial thinking with that foundation locked in. That's how you find real vulnerabilities, not theoretical ones.
English
0
0
0
29
Decentralized Intelligence AG
1/ Understand too long and you miss vulnerabilities hiding in plain sight. Break too early and you're guessing, not hunting. The best auditors and the best AI security tools switch between these modes systematically.
English
1
0
0
38
Decentralized Intelligence AG
Security work runs on two modes. Understanding mode: you map the system, trace the logic, learn how it breathes. Breaking mode: you think like an adversary, hunt the edge cases, exploit what you now understand. The trap is staying too long in either.
English
2
0
0
66