gbaleeee

225 posts

gbaleeee banner
gbaleeee

gbaleeee

@gbaleeeee

愚钝之人 | SR @sec3dev

Katılım Eylül 2021
1.3K Takip Edilen421 Takipçiler
Sabitlenmiş Tweet
gbaleeee
gbaleeee@gbaleeeee·
Inspired by the "two parser bug," I identified a vulnerability related to precision loss during the audit. If you're interested in precision loss or fuzz testing, check this out: @zxy211965/precision-loss-accumulation-the-two-parser-bug-lurking-in-the-shadows-5d9d11252b2a" target="_blank" rel="nofollow noopener">medium.com/@zxy211965/pre…
Daniel Von Fange@danielvf

I call it a "two parser bug". Two different implementations tracking the same input, and parsing differences cause diverging behavior from different parts of a system. Here's two recent examples used in hacks, and how to avoid. 🧵1/5

English
0
6
23
4.4K
gbaleeee retweetledi
OpenAI
OpenAI@OpenAI·
Introducing EVMbench—a new benchmark that measures how well AI agents can detect, exploit, and patch high-severity smart contract vulnerabilities. openai.com/index/introduc…
English
1.2K
1.3K
8.8K
2.6M
gbaleeee retweetledi
ControlZ
ControlZ@ControlZ_1337·
I’ve been getting a lot of questions about how this bug was found, so here are the answers: kritt.ai/technical-revi… This is a technical review of how Claude Code was used to uncover this crazy bounty, and more broadly how AI can be leveraged to find Critical and High-severity issues.
Immunefi@immunefi

Just a few days ago, the legends behind @_blockian found a max critical that earned them $250,000. Merry Christmas!

English
27
51
455
57.6K
ret2basic.eth
ret2basic.eth@ret2basic·
Holiday season is here, and we @taichiaudit are starting a DeFi source code walkthrough campaign: one article every 1–2 days, from now until the end of January 2026. If you're a dev or security researcher leveling up in the bear market, this is for you.
English
11
5
59
7.3K
gbaleeee retweetledi
UPD.IO | Universal Private Dollar
⚠️ The full technical postmortem for the USPD exploit is now live. The root cause was not contract logic, but deployment atomicity. Our forensic analysis indicates this is an industrial-scale operation: we identified ~200 other proxies on mainnet infected by the same infrastructure. 👉 Read it here: uspd.io/blog/anatomy-o… We deployed the proxy in one transaction and initialized it in another. In that brief window, an attacker installed a "shim" that forwarded calls to our legitimate code while retaining admin control. This allowed the protocol to function normally for 3 months, passing verification checks, until we attempted a routine upgrade. We break down the specific architectural decisions—specifically regarding deterministic addresses—that created the window for the CPIMP attack. Full analysis and data in the article. 👇 V2 architecture is already in motion, moving to strictly atomic deployments to eliminate this vector entirely. Simplified modular architecture, DeFi-compatible yield design, and more. We will share further details as we progress. Next steps: Recovery Tokens and closed group affected holders, protocol adjustments and re-launch preparation. 🤝 Special thanks to @SEAL_911 for their immediate assistance in helping us navigate the aftermath.
English
2
8
21
5.7K
ret2happy
ret2happy@ret2happy·
Given the recent Balancer/Yearn exploits, imagine what on-chain miracles we’d see if Lazarus started developing an LLM for automated attacks. In addition, they should cite the A1 preprint by @lzhou1110, as it is the first work for on-chain AEG.
Anthropic@AnthropicAI

New on our Frontier Red Team blog: We tested whether AIs can exploit blockchain smart contracts. In simulated testing, AI agents found $4.6M in exploits. The research (with @MATSprogram and the Anthropic Fellows program) also developed a new benchmark: red.anthropic.com/2025/smart-con…

English
1
0
1
1.3K
gbaleeee retweetledi
Anthropic
Anthropic@AnthropicAI·
New on our Frontier Red Team blog: We tested whether AIs can exploit blockchain smart contracts. In simulated testing, AI agents found $4.6M in exploits. The research (with @MATSprogram and the Anthropic Fellows program) also developed a new benchmark: red.anthropic.com/2025/smart-con…
English
347
700
4.8K
2.1M
gbaleeee retweetledi
BlockSec Phalcon
BlockSec Phalcon@Phalcon_xyz·
.@Balancer and several forked projects were attacked a few hours ago, resulting in losses exceeding $120M across multiple chains. This was a highly sophisticated exploit. Our initial analysis suggests the root cause was an invariant manipulation that distorted the BPT price calculation, allowing the attacker to profit from a specific stable pool through a single batch swap. Take an attack TX on Arbitrum as an example, the batchSwap operation can be broken down into three phases: 1. The attacker swaps BPT for underlying assets to precisely adjust the balance of one token (cbETH) to the edge of a rounding boundary (amount = 9). This sets up the conditions for precision loss in the next step. 2. The attacker then swaps between another underlying (wstETH) and cbETH using a crafted amount (= 8). Due to rounding down when scaling token amounts, the computed Δx becomes slightly smaller (8.918 to 8), leading to an underestimated Δy and thus a smaller invariant (D from Curve’s StableSwap model). Since BPT price = D / totalSupply, the BPT price becomes artificially deflated. 3. The attacker reverse-swaps the underlying assets back into BPT, restoring balance while profiting from the deflated BPT price. Attack TX on Arbitrum: app.blocksec.com/explorer/tx/ar…
BlockSec Phalcon tweet media
BlockSec Phalcon@Phalcon_xyz

ALERT! @Balancer and several forked projects have been attacked. Any forked projects should stay alert and monitor closely! The losses were as follows: Eth: balancer, 70m Base: balancer, 3.9m Polygon: balancer, 117k Sonic: beets, 3.4m Arb: balancer, 5.9m Op: beethoven, 283k

English
20
80
467
120.7K
ret2basic.eth
ret2basic.eth@ret2basic·
哈基米
Trends@trendsdotfun

Looks like the community is very thrilled about having a Chinese name 中文名 for @solana! (thank you core Solana team for the s/o to this community effort @toly @calilyliu @akshaybd) Given such community enthusiasm, Trends is organizing a competition for community members to give a Chinese name to @solana with a prize pool of 100 SOL Simply quote retweet this post with your proposed Chinese name for Solana to enter the competition the best performing proposal tweet gets 66 SOL, and the second best performing proposal tweet gets 33 SOL, with 1 random participant gets 1 SOL (best performing can mean social media stats, traction on Trends, and many other things 👀) The competition will start from now and ends at October 17, 2025 6am UTC. 让我们一起建造 世界的Solana 人民的Solana

日本語
2
0
4
933
gbaleeee
gbaleeee@gbaleeeee·
@Xor0v0 用力活着用力爱哪怕肝脑涂地
中文
0
0
1
46
Tim 🦀
Tim 🦀@Xor0v0·
充满鲜花的世界到底在哪里
中文
1
0
2
539
Tim 🦀
Tim 🦀@Xor0v0·
好累啊 不想干安全了 审计审得头晕 攻击看得眼花 干技术是最不值钱的:-(
中文
9
0
15
2.1K
gbaleeee retweetledi
Dedaub
Dedaub@dedaub·
Just mitigated: The CPIMP Attack – a stealthy front-running exploit infecting 100s of DeFi proxies across many protocols Attacker inserts hidden proxies that self-restore, spoof Etherscan, and lie dormant for high-value strikes Tens of millions at risk dedaub.com/blog/the-cpimp…
English
3
17
69
17K
ret2basic.eth
ret2basic.eth@ret2basic·
I am starting a 100 days challenge, building my web3 security portfolio in public until my dream company @CertiK hires me. 📅Day 001/100, I saw CertiK team doing suidex contest on hackenproof real-time leaderboard, so I am doing it as well. Let's hunt down some bugs!🫡
English
14
2
111
11.6K
gbaleeee retweetledi
Neodyme
Neodyme@Neodyme·
@GMX_IO V1 has been hacked. Here is how:
Neodyme tweet media
English
2
6
18
4.1K