
DadeKuma
878 posts

DadeKuma
@DadeKuma
Independent Security Researcher | Collaborating with @zenith256 @cyfrin @PashovAuditGrp | Available for private audits, Solana/Rust & EVM 🗓️
Book an audit ⇢ Katılım Mart 2014
299 Takip Edilen2.1K Takipçiler
Sabitlenmiş Tweet

Note: I just made this repo public, so it would be awesome if you could star it 🌟
I've also included an audit template that you might find useful for creating your own!
⬇️
github.com/DadeKuma/audits
English

@WhiteHatMage In my experience, you need a very fast tool. Valid bugs are submitted a few minutes (1-10) after a BB starts now.
I think it's better to focus either on speed or depth/edge cases, doing both doesn't work well since AI is in play IMO.
English

@rosarioborgesi I don't want to be a doomer, but it seems the industry as a whole is struggling hard🥲
English

@ScrewCopper @bytes032 @0x3b33 They introduced conditional pots, which significantly reduced profitability for both platforms and auditors
English

AI is crazy good, but once the devs realize they can run the tools themselves for a fraction of an audit's cost, the value of AI findings will quickly drop to the average token cost.
Before, it was more difficult; you had to build a good harness / agent orchestration to have something usable. Now, you can do the same with a good prompt, context management, and SOTA models.
There are still bugs that AI can't find, so to be 'future-proof' you have to focus on these edge cases.
I tested this in a BB: I found a bug in March 2026 on a top protocol that was introduced back in June 2025. No AI found it, and I'm pretty sure the project was scanned many, many times.
You can still be very successful with AI only for now (you're living proof), but I don't think this will last...
English

@DadeKuma not even hacked. production system randomly sends all ETH to 0xdeadbeef.
English


@GalloDaSballo North Korean hackers don't want you to know about this one simple trick
English

@0xcastle_chain Thank you, mate! I appreciate what you're doing with the Solana Audit Arena. Respect! 🫡
English

They are all good depending on your personality and goals.
Bug Bounty: You must have very good skills, and you can handle rejection after rejection / unfair situations. Potentially it's the best ROI.
Engagements with Firms: You have freedom, but work is capped by availability and your daily rate.
Looking for full-time: I guess good stability, but hard capped earnings and limited opportunities.
Solo audits: You have to market hard. Mid-revenue, big protocols usually don't care about spending a lot, so they go directly with firms.
English

@MartinMarchev No way, so that was you lmao. Got duped here last month by a single day. Can I DM to be sure?
English
DadeKuma retweetledi

@real_philogy New models = training costs. Even if the inference API is profitable, most people use the subscription, which is definitely not.
English

I hate this dumb AI timeline. Within a few years, 80% of current security auditors will be gone, and not for the reason you think.
People don't realize that AI costs are actually increasing with each new model, not decreasing. Companies are selling at a loss just to capture the market; they'll pull the rug once we're all fully dependent by massively increasing prices.
Those who rely entirely on AI have already stopped thinking for themselves. When this system eventually collapses, they will be left completely helpless.
English















