Sabitlenmiş Tweet
Jeff Security
2.3K posts

Jeff Security
@jeffsecurity
Independent Smart Contract Researcher & Researcher at @ShieldifySec My mission is to find vulnerabilities in smart contracts for a safer Web3 Space!
Audit portfolio here: Katılım Mayıs 2021
2K Takip Edilen8.4K Takipçiler
Jeff Security retweetledi

I published my Bug Bounty Hunting Methodology on GitHub almost 2 years ago:
github.com/wadgamaraldeen…
Some parts may be outdated, but it still contains practical tips you can use in your AI prompts or to improve your current hunting methodology.
Happy hunting! 🩵
#bugbountytips

English

@shieldifysec is heading toward a record month in audit engagements, and we're not alone - peers across the space report the same trend. Security is being treated as a prerequisite to shipping, not an add-on.
Beautiful ❤️
English
Jeff Security retweetledi

Most "AI auditors" are grep with extra steps. Hound models the system first, hunts second. Scout models explore cheap, strategist models reason deep. That's just how a real audit team works.
github.com/scabench-org/h…
English

New to security? Start here.
Prompt injection works because an LLM can't tell a system prompt from user input. Both are just text. Same root cause as SQLi - different target.
ibm.com/think/topics/p…
English
Jeff Security retweetledi

The gap between a $50 finding and a $50k finding is rarely tooling. It's how you think. The Art of Auditing distills that mindset from proven top-tier hunters. web3-sec.gitbook.io/art-of-auditing
English

AI audit skills built for Solana
github.com/sanbir/solana-…
English

ZK Journey (Old but gold) 🫡
Journey into learning ZK. It is NOT a list of awesome resources; it’s the path I’ve taken in demystifying ZK
📌 Core Beginner Resources
📌 Theoretical Deep Dives
📌 Practical Deep Dives
📌 ZK Vulnerabilities
sunrise-clerk-234.notion.site/Hickup-s-ZK-Jo…
English

imagine deploying a struct with the same field layout as someone's vault and the VM just... hands you their balance. no exploit needed, the cache forgot who owned index 5. Hexens caught it pre-mainnet
defendor.substack.com/p/the-index-th…
English
Jeff Security retweetledi

Sigma Prime dropped a great read on AI in audits. Their internal data: ~80% of findings are known bug classes - exactly what AI eats for breakfast. The other 20%? Still needs a human who thinks like an attacker.
sigmaprime.io/blog/ai-as-a-f…
English

The definitive reading list for anyone building AI into their security workflow. Every serious paper on LLMs for vuln detection - function-level to agentic to smart contracts - indexed and updated daily.
github.com/huhusmang/Awes…
English

Spent weeks on a valid bug, then got ghosted on the payout? There's now a public ledger naming programs that scam researchers. Submit your unresolved reports, hold vendors accountable.
bugbountyscam.com
English




