Norman
2.9K posts

Norman
@Normanxbt
Chief Agents Officer @zerodriftsec I find the gap between intention and implementation

During the World Cup, 70%+ of users are winning with insiders.bot Agent and v1.3 Signals. With 2B+ trading data, 20+ functions, and 1.6M wallets, we offered real strategies for 3000+ active users. We are now live on: @RobinhoodCrypto You can trade @Polymarket, @predictdotfun, and soon @Kalshi, @trylimitless, and @world_xyz on insiders.bot.



Renaiss 現已進入 Q3(7 月至 9 月)的重要更新週期。 在這個關鍵里程碑,我今天想主動分享一下,Renaiss 的社區成員如何主動協助我們,讓協議及產品的安全性與長期韌性持續提升 這次合作充分展現了 Web3 的獨特價值。當具備專業知識的社區成員主動參與,並與團隊並肩合作時,安全就能透過早期發現與共享專業而持續強化。這也提醒我們,安全不是一次性的檢查清單,而是與真正關心協議的人建立的長期關係 我們非常感謝社區中同時經營專業安全團隊的朋友。Norman(@normanxbt),ZeroDrift(@ZeroDriftSec)的創辦人——一個正保護數十億鏈上資產的 AI 安全層——主動聯繫我們 他先前為 Renaiss 協議打造了專屬的 AI harness,並透過這項工作,發現了我們 Buyback Flow 中授權邏輯可以進一步強化的機會 收到報告後,團隊迅速確認問題,並在 3 天內完成修復。 當時所發現的潛在風險範圍,是受到可用流動性與已授權金額的限制,並非任意鑄幣類型的問題,但這種由社區發起的力量是我們在這段旅程中發現的重要價值,再看到近日由 @tastedotmd 舉辦的黑客松,有超過 70 支隊伍報名,共產出了45個產品, 我對此衷心感到自豪 亦再此再次感謝,Norman 及 ZeroDrift,Collectibles 是一個建立在社區之上的產業,而這正是我們社區在關鍵時刻展現力量的最佳證明 我們會持續朝著強化協議的方向前進 如果你發現任何值得回報的事項,我的收件匣永遠為你敞開——或者直接聯繫團隊 info@renaiss.xyz 我們誠摯歡迎更多人一起在這個藏品金融世界正在建立的早期加入,共同讓 Renaiss 及整個產業變得更好 另外,如果你是項目方,有安全上的有任何疑問或需求,我們也會衷心推薦聯絡 Norman,他們非常專業

Renaiss 現已進入 Q3(7 月至 9 月)的重要更新週期。 在這個關鍵里程碑,我今天想主動分享一下,Renaiss 的社區成員如何主動協助我們,讓協議及產品的安全性與長期韌性持續提升 這次合作充分展現了 Web3 的獨特價值。當具備專業知識的社區成員主動參與,並與團隊並肩合作時,安全就能透過早期發現與共享專業而持續強化。這也提醒我們,安全不是一次性的檢查清單,而是與真正關心協議的人建立的長期關係 我們非常感謝社區中同時經營專業安全團隊的朋友。Norman(@normanxbt),ZeroDrift(@ZeroDriftSec)的創辦人——一個正保護數十億鏈上資產的 AI 安全層——主動聯繫我們 他先前為 Renaiss 協議打造了專屬的 AI harness,並透過這項工作,發現了我們 Buyback Flow 中授權邏輯可以進一步強化的機會 收到報告後,團隊迅速確認問題,並在 3 天內完成修復。 當時所發現的潛在風險範圍,是受到可用流動性與已授權金額的限制,並非任意鑄幣類型的問題,但這種由社區發起的力量是我們在這段旅程中發現的重要價值,再看到近日由 @tastedotmd 舉辦的黑客松,有超過 70 支隊伍報名,共產出了45個產品, 我對此衷心感到自豪 亦再此再次感謝,Norman 及 ZeroDrift,Collectibles 是一個建立在社區之上的產業,而這正是我們社區在關鍵時刻展現力量的最佳證明 我們會持續朝著強化協議的方向前進 如果你發現任何值得回報的事項,我的收件匣永遠為你敞開——或者直接聯繫團隊 info@renaiss.xyz 我們誠摯歡迎更多人一起在這個藏品金融世界正在建立的早期加入,共同讓 Renaiss 及整個產業變得更好 另外,如果你是項目方,有安全上的有任何疑問或需求,我們也會衷心推薦聯絡 Norman,他們非常專業


Noxa 这么一搞,cashcat 的前景变得非常不明朗了。外盘的 1% 手续费是直接通过 Uniswap LP Position 收取,而不是传的合约配置,合约配置应该是内盘代币。LauncherLocker 可以不停用 LP 来 claim fee。问题是 LauncherLocker 也没有开源,除非反编译仔细审计一下,否则不能保证这个合约里有没有后门能把 LP Position NFT 抠出来撤池子。就算没有这1%的双边税一直给一个停运的台子也不太对劲。我先撤了这次我不买单了






$17M Stolen in 40 Days. An overlooked attack surface is quietly fueling a new wave of exploits: deprecated contracts. Over the past 40 days, attackers have extracted nearly $17M from contracts that were considered obsolete but remained live on-chain. Here’s how deprecated contracts are becoming hackers’ ATMs. 🧵



Introducing OPSeC: a new industry-wide initiative we're convening in partnership with @_SEAL_Org & @asymmetric_re to improve cybersecurity resilience across blockchain ecosystems & onchain software. Join us to ensure security is at the heart of onchain technology development.

ICYMI: A hacker turned roughly $2,600 into more than $263,000 by exploiting an old Polygon-based smart contract. Not by breaking @0xPolygon. Not by hacking private keys. Not by draining user wallets. Instead, they found a flaw in a forgotten "legacy" royalties contract that was still live on-chain. According to security researchers, the attacker used a flash loan and manipulated the contract's reward accounting logic, allowing them to artificially inflate rewards and withdraw far more than they should have been able to. The result? A profit of around $261,000 in a single transaction. What's alarming is that this wasn't a new protocol. It was an old contract. A reminder that in crypto, code doesn't disappear just because a project moves on. Many older contracts remain active for years, often holding funds and permissions long after teams stop paying attention to them. This is why security experts keep warning about "zombie contracts"—outdated smart contracts that quietly sit on-chain until someone discovers a vulnerability. The biggest threats in DeFi aren't always the newest protocols. Sometimes they're the forgotten ones.



The recent phishing attacks against MEV bots are sad, but not surprising. In our recent @acm_ccs 26 paper, we found that many MEV bots are vulnerable to phishing-style attacks because they expose logic to adversary-controlled calls: arxiv.org/abs/2504.13398




$17M Stolen in 40 Days. An overlooked attack surface is quietly fueling a new wave of exploits: deprecated contracts. Over the past 40 days, attackers have extracted nearly $17M from contracts that were considered obsolete but remained live on-chain. Here’s how deprecated contracts are becoming hackers’ ATMs. 🧵




