Jonatascm 🪐

860 posts

Jonatascm 🪐 banner
Jonatascm 🪐

Jonatascm 🪐

@jonataspvt

SR at @cantinaxyz Breaking things and POCing https://t.co/ztO6GFxOZ4

Remote, Brazil Katılım Temmuz 2010
927 Takip Edilen2.1K Takipçiler
Jonatascm 🪐 retweetledi
Cantina 🪐
Cantina 🪐@cantinaxyz·
Status: High-severity vulnerability found by Cantina’s AI Code Analyzer in @OpenClaw (CVE-2026-26325). Our AI engine detected an allowlist bypass in OpenClaw's npm package. The flaw allows a mismatch between checked commands and executed commands. Full breakdown below:
English
2
14
74
13.9K
Jonatascm 🪐 retweetledi
Cantina 🪐
Cantina 🪐@cantinaxyz·
AI bots like @openclaw's Clawdbot surface 1000s of vulnerabilities every day. So we had to act. 🦞 Introducing ClawdStrike.ai: a free terminal skill to analyze any ClawdBot build, derived from our AI security expertise protecting the most complex production systems. See how it works:
English
51
86
720
180.3K
Jonatascm 🪐 retweetledi
Al-Qa'qa'
Al-Qa'qa'@Al_Qa_qa·
Don't force yourself to understand/studying you don't need them. When auditing a protocol integrating with UniV3, you don't need to fully understand the entire UniV3 protocol. You can see Auditors ask about some things that are not really in the scope of the Codebase they are reviewing, and are core concepts in UniV3, and are unrelated to this scope. The idea is to know which parts for the integrated protocol you should know and will help you in your audit. Most of the time, you will audit Codebases that integrate with a protocol you don't know. Although understanding all the integrated protocols is better, this will not happen all the time. You have a fixed period of time; this can only occur for popular protocols like Uniswap and Chainlink. But sometimes you can see integration with a protocol you first see. Always focus on the points you need and will help you in your audit, without opening unnecessary doors for yourself
English
5
3
65
6K
Jonatascm 🪐 retweetledi
thisvishalsingh | ZippelLabs 🪐
thisvishalsingh | ZippelLabs 🪐@thisvishalsingh·
We're excited to initiate @Zippel_Labs audits, a cryptography security led by I. ZKP's security is extremely important to build secure pillars of Privacy. *Currently most zkVMs are not fully audited, & for them offering subsidized audits.
thisvishalsingh | ZippelLabs 🪐 tweet media
English
4
19
67
7.5K
Jonatascm 🪐 retweetledi
engn33r
engn33r@bl4ckb1rd71·
One interesting thing here is seeing how much has changed in 5 years. 5+ yr old iEarn code on left, OZ ERC4626 on the right. Do you see the difference in share calculation?
engn33r tweet mediaengn33r tweet media
yearn@yearnfi

We're aware of an issue with iEarn's immutable TUSD contract, deployed over 2100 days ago, unrelated to Yearn vaults. The problem is exclusive to iEarn and does not impact current Yearn contracts or vaults. The incident is similar to this 2023 iEarn USDT hack.

English
16
7
128
24.3K
Jonatascm 🪐 retweetledi
Cantina 🪐
Cantina 🪐@cantinaxyz·
Cantina's Managed Detection and Response exists for one reason: turning a validated signal into containment before value leaves the system. In Web3, the hardest step is not executing a pause. It is authorizing it quickly, with evidence. Details below.
Cantina 🪐 tweet media
English
1
6
16
1.2K
Jonatascm 🪐
Jonatascm 🪐@jonataspvt·
This was legendary, it was a real pleasure participating in team america! 🔥
Ultimate Security Games@USGOfficials

Ultimate Security Games - Season 1 gallery is out! Congrats again to team Europe @Zigtur @Montyly @GalloDaSballo and @AliceAndB0b! Shoutout to the legends who brought the heat: Team Americas — @0xleastwood @_Allarious @0xriptide @jonataspvt Team Asia — @HickupH @banditx0x @0xt1moh @kamensec Big thanks to the sponsors who made it possible: @monad @coinbase @immunefi @sigp_io @PashovAuditGrp

English
0
0
8
224
Jonatascm 🪐 retweetledi
Cantina 🪐
Cantina 🪐@cantinaxyz·
We’ve been working behind-the-scenes on something groundbreaking. If you want early access to the only Web3 AI security tool that truly focuses on signal over noise, you can now join the waitlist.
English
3
4
44
15.1K
Jonatascm 🪐 retweetledi
P.M
P.M@p_misirov·
a couple days ago I ran a survey to understand how is AI used by smart contract auditors. here are the results 👇🧵
P.M tweet media
English
3
8
73
5.4K
Jonatascm 🪐 retweetledi
RareSkills
RareSkills@RareSkills_io·
Ultimate Security Games will begin live streaming 5:15 pm EST today (November 20th). You can watch the stream on the dedicated channel in the reply.
English
4
23
89
22K
Jonatascm 🪐 retweetledi
Cantina 🪐
Cantina 🪐@cantinaxyz·
New in Cantina MDR: Spin up a live war room the moment an incident hits. What happens if your team takes five minutes to respond, and the exploit only needs one? That’s exactly what we solve. Instant coordination & zero friction.
English
1
5
14
1.2K
Jonatascm 🪐
Jonatascm 🪐@jonataspvt·
Excited to share that I’ve joined @spearbit as a Full-time Security Researcher! My journey in smart contract security began here, so this step truly feels like coming full circle. Can’t wait to see what the future brings! 🔥
English
14
1
116
4.7K