Gerard Persoon

329 posts

Gerard Persoon banner
Gerard Persoon

Gerard Persoon

@gpersoon

Solidity security reviews @cantinasecurity https://t.co/2Ql2W2pa9w

Rotterdam, Nederland Katılım Ekim 2010
2K Takip Edilen3.2K Takipçiler
Gerard Persoon retweetledi
cmichel
cmichel@cmichelio·
It's not the end, it's still living on in the LLM data training sets. That's why you see so many zero-address check suggestions and inflated severities. (My feeling is that it has improved with recent models though?) The very early 2021 days with @0xRajeev @gpersoon @sockdrawermoney were peak fun. What ruined contests from an SR's POV was: Fewer real bugs because devs and tooling got a lot better, once foundry came along devs started actually testing their code with high coverage. This led to more (arguably) out-of-scope bug submissions which made the highest-impact move arguing about your own & others' issues. The difference between a high and a medium was not well defined in practice & there were some incompetent judges (sorry). Pool sizes also never kept up with the increase in participants. In the end, the audit contest payout structure changed so much that many were just pre-deployment bug bounties (different pool size unlocks for H/M). Ironically, now would be a great time for contests again as everyone is boasting about their AI being the best. Would love to see more real results instead of vagueposting.
pashov@pashov

🤯CODE4RENA SUNSETTING. THE END OF AN ERA Thank you for everything, code4rena, forever in our hearts <3

English
3
8
154
9.1K
rahul rumalla
rahul rumalla@rsquare·
I'm looking for solutions using LLMs/AI/Agents that are enabling a super charged defensive model for teams, products & companies. In particular for @SafeLabs_ Who should I talk to?
English
15
0
17
6.8K
Hari
Hari@hrkrshnn·
I'm looking for interesting targets to point Apex at. Claude Code was interesting because 1) it's closed source and 2) it's the product of the year. Where should we point it next? If we haven't scanned it yet and we get a bounty for it, I'll give you a piece.
Hari@hrkrshnn

Breaking Claude Code and getting a high severity bounty from @AnthropicAI! Apex, our autonomous bug hunter, found a way to bypass a permissions check by Claude Code for untrusted codebases. Want Apex to break your code next? Link below

English
9
0
11
3K
Gerard Persoon
Gerard Persoon@gpersoon·
Cool idea. Why not use the exact bounty amount as liquidity? That removes the uncertainty if the white hat pays back the 90%. And that is the amount that the protocol should reserve anyway.
RajΞΞv@0xRajeev

@cyfrin Interesting initiative. Curious: 1. Why will a protocol want to deploy here with real liquidity? 2. Is this meant to replace a protocol's BB?

English
2
0
13
1.9K
Wei Dai
Wei Dai@_weidai·
Who's working on "secure" agent harnesses? Ingredients: track all tool calls, semantically label them (what was read, what is the effect), enforce policies, etc. Would love to chat.
Viv@Vtrivedy10

x.com/i/article/2031…

English
15
4
37
5.2K
Gerard Persoon
Gerard Persoon@gpersoon·
@thedaofund There is a lot of reinventing the same thing. This could potentially be improved with more generic modules / libraries, which are well tested and reviewed.
English
0
0
0
34
thedao.fund
thedao.fund@thedaofund·
As we think about funding Ethereum security long term: what parts of security do you believe are most underfunded today? We’re listening.
English
51
6
100
11.2K
Alex the Entreprenerd
Alex the Entreprenerd@GalloDaSballo·
Is there a way to create a private key that becomes public over time? So that for a period of time only one person can sign But after some time anyone can
English
16
0
24
4.6K
Nick Mudge 💎
Nick Mudge 💎@mudgen·
Does anyone want to make a new diamond graphics for the next ERC standard for diamonds? How could this graphic be much prettier?
Nick Mudge 💎 tweet media
English
9
2
22
2.6K
Gerard Persoon
Gerard Persoon@gpersoon·
Vitalik explaining the blockchain
Gerard Persoon tweet media
English
0
0
8
1.4K