flacko

702 posts

flacko banner
flacko

flacko

@flack00n

Head of Bugs @therealgregoai researching blockchain security

Portfolio ➟ Katılım Ekim 2019
847 Takip Edilen1.1K Takipçiler
flacko retweetledi
Immunefi
Immunefi@immunefi·
The AI security agent race continues. @0xriptide's gregoai just scored a $100,000 smart contract critical via Immunefi. Whose agent will strike next?
Immunefi tweet media
English
28
28
378
23.9K
flacko
flacko@flack00n·
@MartinMarchev And full-screen ofc with whatever aspect ratio suits your monitor.
English
0
0
1
25
Martin Marchev
Martin Marchev@MartinMarchev·
Your agents don't need sleep. Neither does your Mac. caffeinate -di It keeps your machine awake while your agents grind. Now I just walk by and peek at the progress. You are welcome, anon.
English
3
1
16
1.1K
flacko retweetledi
riptide
riptide@0xriptide·
if you are looking at AI security to complement your existing security stack, consider the following before you let your traditional audit partners upsell you on an "AI audit": most AI audits only give you a high level analysis, hence the low price point/quick turnaround then they give you hundreds of false positives and hope something sticks or else charge you to manually triage through these by their own SRs absolute waste of time we are not competing in this area we are competing against the top audit firms and security researchers to find the needle in the haystack we designed our @therealgregoAI security engine to go as deep as possible and grind for hours and hours running through thousands of exploit scenarios while filtering out 95%+ of false positives (very difficult to do! IYKYK) DM to enable the Grego AI Security Layer on your protocol and we will show you what everyone else missed
English
4
7
43
2.9K
flacko
flacko@flack00n·
@0xriptide yep, 100k -> 74k -> ath is about how I see it
English
1
0
1
226
riptide
riptide@0xriptide·
this rally will fail like all others
English
4
0
17
2.1K
flacko retweetledi
Immunefi
Immunefi@immunefi·
The talented @infosec_us_team just scored a maximum bounty reward of $200,000 for their critical bug report. The protocol was ready to pay in full, but @infosec_us_team decided to donate $100,000 back to their treasury, so that the protocol can keep rewarding future whitehats. This elite security researcher team absolutely didn't have to do this. They chose to. A truly remarkable day of generosity. P.S. This bounty just earned @infosec_us_team a huge amount of Hunt Points for the IMU airdrop. P.P.S. In the future, anyone will be able to back security researchers like these and share in their IMU rewards.
Immunefi tweet media
English
38
29
301
17.9K
Grok
Grok@grok·
The avatars overlaying the faces in the photo match these X handles from the smart contract security community: MartinMarchev, 0xriptide, 0xT1MOH, flack00n, marcohextor, _FortyForty, abarbatei, 0xNetero201, TamayoNft, stan_tsonev, ParthMandale, ll30161313, dan__vinci. They were likely at a gathering in Bulgaria.
English
1
0
0
54
flacko retweetledi
Martin Marchev
Martin Marchev@MartinMarchev·
The usual suspects at the usual spot
Martin Marchev tweet media
English
18
7
165
23.3K
flacko
flacko@flack00n·
@0xDjangoOnChain Oh, tell me about it. Where I'm from people who do anything involved in home renovations are killin it as well.
English
0
0
0
151
0xDjango
0xDjango@0xDjangoOnChain·
@flack00n I've had this exact thought for months. Plumbers around here make bank
English
1
0
2
165
Monad
Monad@monad·
Drop your claim cards below 👇
English
6.5K
1.3K
5.9K
596K
flacko
flacko@flack00n·
@WhiteHatMage @0xjuaan I was hoping for that answer, been itching to write some code for a lil while now
English
0
0
0
119
Juan
Juan@0xjuaan·
many months ago, i spent many days digging into the whole marginfi solana program. seeing this writeup, i thought i missed a crit, so quickly went to read it. turns out, the vulnerability was introduced in a recent update, so i couldn't have found it. lesson in there.
asymmetric research@asymmetric_re

Threat Contained: marginfi Flash Loan Vulnerability by @_fel1x A new instruction broke the flash loan logic, creating a way to borrow without repaying and putting $160M at risk. We explain the vulnerability, potential impact, and how it was fixed. Full post below ↓

English
3
1
36
3.8K
flacko
flacko@flack00n·
@0xjuaan @WhiteHatMage What do you guys use to send you alerts and what do you monitor? Commits to the master branch, onchain data?
English
0
0
0
184
Juan
Juan@0xjuaan·
lesson: identify things that could go wrong due to updates, and set alerts like @WhiteHatMage
English
1
0
12
778