Jeff Security

2.3K posts

Jeff Security

Jeff Security

@jeffsecurity

Independent Smart Contract Researcher & Researcher at @ShieldifySec My mission is to find vulnerabilities in smart contracts for a safer Web3 Space!

Audit portfolio here: Katılım Mayıs 2021
2K Takip Edilen8.4K Takipçiler
Sabitlenmiş Tweet
Jeff Security
Jeff Security@jeffsecurity·
Made $60k last month from audit 😎 What about you?
English
23
0
135
10.4K
Jeff Security
Jeff Security@jeffsecurity·
@shieldifysec is heading toward a record month in audit engagements, and we're not alone - peers across the space report the same trend. Security is being treated as a prerequisite to shipping, not an add-on. Beautiful ❤️
English
2
2
16
580
Jeff Security retweetledi
0xasen
0xasen@asen_sec·
We are SO back Almost as if we have never left Let's see who takes the win in these contests🫡
0xasen tweet media
English
5
5
91
3.5K
Shieldify Security
Shieldify Security@ShieldifySec·
Layoffs everywhere. We're pushing harder🫡 Formal verification, fuzzing, blackhat-mode review. The attackers didn't slow down, so neither did we. Web3 security isn't a solved problem. It's a young one!
English
1
3
9
721
Jeff Security
Jeff Security@jeffsecurity·
Most "AI auditors" are grep with extra steps. Hound models the system first, hunts second. Scout models explore cheap, strategist models reason deep. That's just how a real audit team works. github.com/scabench-org/h…
English
1
0
36
1.6K
Jeff Security
Jeff Security@jeffsecurity·
New to security? Start here. Prompt injection works because an LLM can't tell a system prompt from user input. Both are just text. Same root cause as SQLi - different target. ibm.com/think/topics/p…
English
1
2
13
680
Jeff Security retweetledi
Martin
Martin@ShieldifyMartin·
🚨 Latest ERC-4626 Business Logic Flaw A custom vault on Base & Arbitrum double-paid the WETH side of its Uniswap V3 LP during redeem(). totalAssets() already included the WETH value, but redeem() transferred the WETH again, paying it twice. 💸 Result: ~34 WETH (~$53K) drained
English
3
4
37
3.1K
Jeff Security
Jeff Security@jeffsecurity·
The gap between a $50 finding and a $50k finding is rarely tooling. It's how you think. The Art of Auditing distills that mindset from proven top-tier hunters. web3-sec.gitbook.io/art-of-auditing
English
1
2
19
741
Shieldify Security
Shieldify Security@ShieldifySec·
ZK Journey (Old but gold) 🫡 Journey into learning ZK. It is NOT a list of awesome resources; it’s the path I’ve taken in demystifying ZK 📌 Core Beginner Resources 📌 Theoretical Deep Dives 📌 Practical Deep Dives 📌 ZK Vulnerabilities sunrise-clerk-234.notion.site/Hickup-s-ZK-Jo…
English
1
4
29
1.3K
Jeff Security
Jeff Security@jeffsecurity·
imagine deploying a struct with the same field layout as someone's vault and the VM just... hands you their balance. no exploit needed, the cache forgot who owned index 5. Hexens caught it pre-mainnet defendor.substack.com/p/the-index-th…
English
0
3
14
1.6K
Jeff Security retweetledi
Martin
Martin@ShieldifyMartin·
The best Web3 security folks aren't the most gifted or educated, they're the ones who never stop grinding until every bug in the codebase is found.
English
0
2
13
436
Jeff Security
Jeff Security@jeffsecurity·
Sigma Prime dropped a great read on AI in audits. Their internal data: ~80% of findings are known bug classes - exactly what AI eats for breakfast. The other 20%? Still needs a human who thinks like an attacker. sigmaprime.io/blog/ai-as-a-f…
English
0
1
24
1.2K
Jeff Security
Jeff Security@jeffsecurity·
The definitive reading list for anyone building AI into their security workflow. Every serious paper on LLMs for vuln detection - function-level to agentic to smart contracts - indexed and updated daily. github.com/huhusmang/Awes…
English
1
9
80
3.8K
Shieldify Security
Shieldify Security@ShieldifySec·
POV: you shipped before reading the audit report. Don't be this protocol!
English
1
3
11
877
Jeff Security
Jeff Security@jeffsecurity·
Spent weeks on a valid bug, then got ghosted on the payout? There's now a public ledger naming programs that scam researchers. Submit your unresolved reports, hold vendors accountable. bugbountyscam.com
English
2
6
55
2.6K