DemoreXTess

301 posts

DemoreXTess banner
DemoreXTess

DemoreXTess

@demorextess

LSW in @sherlockdefi 15+ Top 5 in Audit Contests Portfolio: https://t.co/HeLYSWtZTI

DM for audit Katılım Haziran 2024
262 Takip Edilen420 Takipçiler
Sabitlenmiş Tweet
DemoreXTess
DemoreXTess@demorextess·
New milestone unlocked: I’m now officially an LSW at Sherlock DeFi after securing 1st place in the recent “Burve” contest with a solo high-severity finding. This is just the beginning. Holding this title requires consistency, and I’m fully committed to maintaining the standard. Big thanks to @sherlockdefi for the opportunity. I’ll do my best not to let anyone down.
DemoreXTess tweet media
English
20
5
156
5.4K
DemoreXTess retweetledi
pashov
pashov@pashov·
🥷One-shotting Threat & Trust models, invariants (stated & inferred), Git History & tests analysis and much more within a sub-10min run. This is the new "X-Ray" tool on pashov/skills. Free & Open Sourced. Let us know if we should keep building these🫡
English
12
21
130
12.3K
Fav_Truffle
Fav_Truffle@Fav_Truffle·
Crypto is dropping. Gold and stocks are dropping too. Real estate in Turkey looks similar. What do we buy now?
English
8
0
13
1.4K
DemoreXTess retweetledi
pashov
pashov@pashov·
🚨Solidity Devs: this FREE AI security tool's been used by 1000+ people and has found tens of Critical/High vulns in real codebases. solidity-auditor v2 is OUT - now with 7 specialized sub-agents on top of v1. Free. Open Source. 1min install. Pls share if you find it valuable🫡
pashov tweet media
English
18
56
335
21.4K
DemoreXTess
DemoreXTess@demorextess·
@Fav_Truffle We still face with multi million dollar hacks which lives for 4 years in old projects. I keep getting surprised by this.
English
0
0
2
75
Fav_Truffle
Fav_Truffle@Fav_Truffle·
What keeps surprising you in 2026 security researchers? On the business side, I keep getting surprised by how many teams value audit reports more than the actual findings lol.
English
4
0
20
1.4K
DemoreXTess
DemoreXTess@demorextess·
@0xSilvermist Coverage is good but more context is needed, what did it miss ?
English
0
0
0
189
Silvermist
Silvermist@0xSilvermist·
Is 18 out of 23 bugs good coverage for an AI? Asking for a friend 🤔
English
5
0
32
3K
Fav_Truffle
Fav_Truffle@Fav_Truffle·
Fav Junior is 3.5 months old already 😎 The best present from the best team - Thanks @sherlockdefi 🤍❤️
Fav_Truffle tweet mediaFav_Truffle tweet media
English
13
0
151
3.4K
phil
phil@philbugcatcher·
I'm happy to share that I've been promoted to Senior Security Researcher at @Certora!!! 🎉🎊 Now I have twice as many bugs to catch Back to work
phil tweet media
English
64
5
372
5.8K
Martin Marchev
Martin Marchev@MartinMarchev·
I am happy to share that I have been promoted to Senior Security Researcher at @Certora. Huge thanks to the team for the trust, support and for setting the bar high every single day 🫡 Onward. Plenty more work to do 💪
English
43
0
196
3.5K
DemoreXTess
DemoreXTess@demorextess·
@vinicaboy Of course, especially if the guy is vinica boy. 🥳
English
1
0
2
274
vinica_boy
vinica_boy@vinicaboy·
seems like you can still make some money from contests
vinica_boy tweet media
English
23
0
224
4.3K
DemoreXTess
DemoreXTess@demorextess·
@0xCharlesWang Nope, you're not the only one. But I think the problem is not the function, solidity extension in vscode, it would be good to see it can forward to correct one
English
0
0
0
66
CharlesWang
CharlesWang@0xCharlesWang·
Am i the only one who dislikes it when there are same function names with different parameters? It really becomes confusing if there are suddenly three internal functions with the same name but different parameters
English
6
1
29
1.6K
DemoreXTess
DemoreXTess@demorextess·
@s4muraii77 It makes sense, a little unlucky from your side 🫤, I wish you find Critical next 🐐
English
0
0
1
215
samuraii77
samuraii77@s4muraii77·
@demorextess it is because even though the manager is not considered trusted in regards to not stealing funds, he is still a manager and not just everyone can steal the funds. This is explained in the project's bounty page, so it is the fair decision.
English
1
0
6
861
Essential
Essential@only01Essential·
This is why I think @immunefi mediation is mostly pointless. if the project doesn't pay well,or doesn't want to pay at all, you are on your own. For this project I found a bug in their in scope assets, were a user loses funds for a certain product type. It was clearly critical, so I submitted it as one. Few days later they acknowledged the bug then told me they don't currently use such products that it was implemented for the future usage, then lowered severity to Medium. Given their reward tiers 25k+ for highs, and the severity of the bug, I was hopeful, that they will pay well, ladies and gentlemen, I was in awe when they marked my report as paid, and what they sent me was $300. The most annoying part here is how they completely ignored me, they ignored all prior questions I asked, even when immunefi tagged them to respond, they still ignored, until they paid $300 they never responded even once to my comment. Given that their program shows they are willing to pay over a million for critical findings, then paying $300 for one, it was a very painful experience. Now, three months after requesting mediation, immunefi left without a word. In cases like this, it makes you wonder if you should have just withheld the bug, cause most of this projects are monsters, all your time and efforts means nothing to them. I have learnt not to trust this projects and the platforms, so always explore other options and see what works. Through out December I focused mostly on @xyz_remedy bug bounty, they work fast, but their SLA is hardly adhered to. Currently, i think when it comes to feedbacks and support @HackenProof is the best right now. I don't know about you guys, but having your report closed for a very stupid reason then having to request mediation inorder to comment is a pain. And mediation takes a very long time, or sometimes forgotten, like my case. Though there are projects that wait for your input before closing on immunefi.
Essential tweet media
English
18
1
109
7.4K
Fav_Truffle
Fav_Truffle@Fav_Truffle·
I'm excited to announce that 5 out of 6 teams awarded @OptimismGov Season 8 OP Audit Grants is coming from me 😎
SHERLOCK@sherlockdefi

We are excited to announce that 6 of the 11 teams awarded @OptimismGov Season 8 OP Audit Grants applied with Sherlock, the most of any audit firm. We are proud to continue to support growth and security in the @Optimism ecosystem through their generous grant program. Congratulations to our awarded partner teams! @40acres_Finance - 75,000 OP @ArcadiaFi - 53,950 OP @HighwayFi - 52,800 OP @ownfinanceHQ - 48,250 OP @super_dca - 33,000 OP @metromxyz - 28,000 OP

English
6
0
30
1.9K
samuraii77
samuraii77@s4muraii77·
Happy to share yet another win 🫡 This is now my 5th consecutive @sherlockdefi win.
samuraii77 tweet media
English
14
0
138
14.8K
DemoreXTess
DemoreXTess@demorextess·
@cvetanovv0 I feel like that's my photo which is taken with you 1-2 weeks later 😂
English
0
0
1
101
0xSimao
0xSimao@0xSimao·
The audit is only finished once you've memorized the codebase entirely, no excuses
English
8
6
135
6.6K