Norman

2.9K posts

Norman banner
Norman

Norman

@Normanxbt

Chief Agents Officer @zerodriftsec I find the gap between intention and implementation

Katılım Ekim 2022
1K Takip Edilen5K Takipçiler
Sabitlenmiş Tweet
Norman
Norman@Normanxbt·
2025年末你只需要一个人不到100美元就能开一个硅谷级的初创公司: 免费用Gemini 3开发并部署一个产品级的网站 免费用 @0xinfini business 注册企业级收单 2美元从namecheap买一个域名 8美元注册一个带蓝标的x账号 60美元从looka买logo和brand kit That's all. 甚至加起来只有70美元。 然后你就可以开始做市场营销,内容宣发,找客户开始赚钱了。
Norman tweet media
中文
63
196
850
128.5K
Mr.RC|𝟎𝐱𝐔
Mr.RC|𝟎𝐱𝐔@MrRyanChi·
Yes, $IN is officially live today. From day one of @insidersdotbot, every user has been a major shareholder. And I mean that literally, back in November last year, our entire launch capital came from our first batch of subscribers. It's thanks to those early Pro users who believed in us that we evolved from a simple signal bot → copy-trading bot → the super platform we are today: AI, smart money explorer, trading terminal, and everything in between. Those subscribers still enjoy ever-improving signals and a growing list of member-exclusive features. They are, quite literally, our shareholders — and they always will be. Powered by community alone, we've out-shipped and out-performed products that raised millions in VC money, on product, features, and user activity. That's exactly the logic behind the $IN TGE. Bring more people in. Grow together. Build in public, for real. Over the past two years, I've watched projects TGE for all kinds of reasons: marketing, flywheel narratives, "product utility," fundraising, you name it. For $IN, it comes down to two things: 1️⃣ Product. 2️⃣ Ecosystem. On the product side, $IN gives users more ways to participate, more crypto-native ways. In our first year post-launch, I personally spent a lot of time doing customer support. Roughly 10% of that time was spent explaining how to buy Pro, how Agent credits work, and how fees and gas are handled. $IN changes that. It introduces staking- and swap-based access to memberships, trading, copy-trading, and Agents, so DeFi-native users can jump into prediction markets directly through our Agent interface. More flexibility, and a better insiders.bot for everyone. Then there's the ecosystem side. To me, the reason prediction markets still have serious staying power after the World Cup is simple: they're essentially high-granularity options products. But for prediction markets to truly merge with financial markets, we need something more DeFi, more AI-driven, a model that can actually tame this asset class. That requires exposure within the DeFi ecosystem. And the $IN TGE delivers exactly that. TL;DR, with $IN, we're putting insiders.bot in front of far more people, and helping them do more than just trade prediction markets: we're helping them find real, long-term +EV strategies. Let's Lock $IN.
insiders.bot@insidersdotbot

During the World Cup, 70%+ of users are winning with insiders.bot Agent and v1.3 Signals. With 2B+ trading data, 20+ functions, and 1.6M wallets, we offered real strategies for 3000+ active users. We are now live on: @RobinhoodCrypto You can trade @Polymarket, @predictdotfun, and soon @Kalshi, @trylimitless, and @world_xyz on insiders.bot.

English
15
4
29
4.5K
Tronn 🔶 BNB
Tronn 🔶 BNB@Tronn_lyu·
很开心和大家分享我加入了BNB Chain,担任 APAC BD,主要负责 BNB Chain 全球的隐私生态建设,推动新项目与各个成熟的Ecosystem Partners的合作。 过去几年, 我尝试过不同的工作: 相信好的设计能够真实地改变人的感受和生活,所以我在浙大读了建筑设计; 相信好的产品能够服务更多的人,所以我在NUS学产品设计; 相信区块链可以带来未来世界的金融改变, 所以我和队友在黑客松做了人生第一个Dapp,获得了 Franklin Templeton 的 Grant; 相信长期的公共物品和隐私、开源项目可以为行业带来长期正向影响,所以我加入了一个支持公共物品的捐赠基金; 不同的经历让我意识到,把一个项目做出来,和判断一个方向为什么值得做、应该在什么时间做,是两种不同的能力。于是我加入了美元 VC 做投资研究,围绕交易所、公链和稳定币等方向,逐渐建立起对行业更系统的认识 在研究的过程中,我发现,许多真正推动行业长期发展的工作——例如开源工具、底层研究、隐私与安全基础设施——都具有很强的公共物品属性。它们在很大程度上支撑着整个行业的发展,却很难从传统价值投资的角度被直接定价,也未必能在短期内形成清晰的价值捕获。 作为行业领先的公链生态, 我们有责任也有义务推动行业的健康发展,我相信BNB Chain 能够成为更多机构、项目和用户进入 crypto 世界的重要入口,我也很乐意成为一个协调者,在技术、项目、机构和真实需求之间,让好的技术找到场景,让值得建设的事情获得支持,也推动更多合作真正发生。欢迎大家随时联系我,一起建设 BNB Chain 生态。 一路走来,我始终希望尽自己所能做成一些事情,创造一些真实的价值。如果一定要给自己一个标签,我想应该是 Builder:从构筑空间、打磨产品,到建设项目、支持项目,再到今天参与一个更大的生态。感谢@nina_rong@v_bnbchain@Lukexiao0@cydeologie 的认可与信任,让我有机会加入 BNB Chain,在一个拥有广泛用户基础、充足流动性和丰富应用场景的生态中继续建设。 BNB — Bring the Next Billion on chain 💛 I'm glad to share that I've joined BNB Chain as APAC BD, where I'll be building out BNB Chain's privacy ecosystem globally and driving collaboration between new projects and our Ecosystem Partners. Over the past few years, I've tried quite different kinds of work: Believing good design could genuinely change how people feel and live, I studied architecture at Zhejiang University. Believing good products could serve more people, I studied product design at NUS. Believing blockchain could reshape the financial world to come, my teammates and I built our first Dapp at a hackathon, which earned a grant from Franklin Templeton. Believing that public goods — along with privacy and open-source projects — can bring lasting, positive impact to the industry, I joined an endowment fund dedicated to public goods. These experiences taught me that shipping a project and judging why a direction is worth pursuing, and when, are two different skills. So I joined a Venture Capital firm as an investment researcher, covering exchanges, L1s, and stablecoins, and gradually built a more systematic view of the industry. The research led me to a realization: much of the work that genuinely moves this industry forward — like open-source tooling, foundational research, and privacy and security infrastructure — has the character of a public good. It underpins much of the industry's progress, yet it's hard to price through a traditional value-investing lens and rarely captures clear value in the short term. As a leading public-chain ecosystem, we have both the responsibility and the obligation to advance the industry's healthy growth. I believe BNB Chain can become a major entry point for more institutions, projects, and users coming into crypto, and I'm glad to serve as a coordinator — sitting between technology, projects, institutions, and real demand, helping good tech find its use case, helping work that deserves support get it, and making more collaboration actually happen. Feel free to reach out anytime — let's build the BNB Chain ecosystem together. Looking back, I've always hoped to get things done and create real value, to the best of my ability. If I had to pick one label for myself, it would be Builder: from building spaces and refining products, to building and supporting projects, and now to helping build a larger ecosystem. I'm grateful to @nina_rong , @v_bnbchain , @Lukexiao0 and @cydeologie for their trust, and for the chance to keep building in an ecosystem with a broad user base, deep liquidity, and applications people actually use. BNB — Bring the Next Billion on chain 💛 @BNBCHAIN @BNBCHAINZH @heyibinance @cz_binance
Tronn 🔶 BNB tweet media
中文
106
3
221
68.6K
Norman
Norman@Normanxbt·
谢谢 Winchman,也很高兴这次我们能帮助 Renaiss 发现 Buyback Flow 中的授权逻辑问题,并协助团队快速完成修复。 行业里一直有一个问题:为什么项目已经做过多轮安全审计,协议上线后仍然可能出现漏洞? 一个重要原因是,传统安全审计本质上是对某一特定时点代码状态的审查。它能够确认当时提交的代码已经过检查,但随着新功能上线、产品持续迭代和代码不断更新,新的风险也会随之产生。 根据我们审查过的案例,超过 80% 的漏洞来自规模不大、却没有经过充分安全审查的代码更新。真正决定项目长期安全性的,不只是“是否做过审计”,而是每一次代码变化能否被持续发现、分析和验证。 因此,我们认为,动态安全能力比一次性的审计结果更能反映一个项目真实的安全水平。这也是我们持续投入 AI Security Layer 的原因:人的带宽终究有限,而 AI 可以持续、不间断地扫描代码、监控链上状态,并审查每一次产品变化。 它不是要替代专业安全人员,而是将专业能力扩展到传统审计难以持续覆盖的地方,让安全从一次性的检查,变成贯穿产品生命周期的基础设施。
Winchman@Renaiss@Plus_Ultra_715

Renaiss 現已進入 Q3(7 月至 9 月)的重要更新週期。 在這個關鍵里程碑,我今天想主動分享一下,Renaiss 的社區成員如何主動協助我們,讓協議及產品的安全性與長期韌性持續提升 這次合作充分展現了 Web3 的獨特價值。當具備專業知識的社區成員主動參與,並與團隊並肩合作時,安全就能透過早期發現與共享專業而持續強化。這也提醒我們,安全不是一次性的檢查清單,而是與真正關心協議的人建立的長期關係 我們非常感謝社區中同時經營專業安全團隊的朋友。Norman(@normanxbt),ZeroDrift(@ZeroDriftSec)的創辦人——一個正保護數十億鏈上資產的 AI 安全層——主動聯繫我們 他先前為 Renaiss 協議打造了專屬的 AI harness,並透過這項工作,發現了我們 Buyback Flow 中授權邏輯可以進一步強化的機會 收到報告後,團隊迅速確認問題,並在 3 天內完成修復。 當時所發現的潛在風險範圍,是受到可用流動性與已授權金額的限制,並非任意鑄幣類型的問題,但這種由社區發起的力量是我們在這段旅程中發現的重要價值,再看到近日由 @tastedotmd 舉辦的黑客松,有超過 70 支隊伍報名,共產出了45個產品, 我對此衷心感到自豪 亦再此再次感謝,Norman 及 ZeroDrift,Collectibles 是一個建立在社區之上的產業,而這正是我們社區在關鍵時刻展現力量的最佳證明 我們會持續朝著強化協議的方向前進 如果你發現任何值得回報的事項,我的收件匣永遠為你敞開——或者直接聯繫團隊 info@renaiss.xyz 我們誠摯歡迎更多人一起在這個藏品金融世界正在建立的早期加入,共同讓 Renaiss 及整個產業變得更好 另外,如果你是項目方,有安全上的有任何疑問或需求,我們也會衷心推薦聯絡 Norman,他們非常專業

中文
3
0
5
643
RickyW
RickyW@0xRickyW·
Great work guys 🫡
Winchman@Renaiss@Plus_Ultra_715

Renaiss 現已進入 Q3(7 月至 9 月)的重要更新週期。 在這個關鍵里程碑,我今天想主動分享一下,Renaiss 的社區成員如何主動協助我們,讓協議及產品的安全性與長期韌性持續提升 這次合作充分展現了 Web3 的獨特價值。當具備專業知識的社區成員主動參與,並與團隊並肩合作時,安全就能透過早期發現與共享專業而持續強化。這也提醒我們,安全不是一次性的檢查清單,而是與真正關心協議的人建立的長期關係 我們非常感謝社區中同時經營專業安全團隊的朋友。Norman(@normanxbt),ZeroDrift(@ZeroDriftSec)的創辦人——一個正保護數十億鏈上資產的 AI 安全層——主動聯繫我們 他先前為 Renaiss 協議打造了專屬的 AI harness,並透過這項工作,發現了我們 Buyback Flow 中授權邏輯可以進一步強化的機會 收到報告後,團隊迅速確認問題,並在 3 天內完成修復。 當時所發現的潛在風險範圍,是受到可用流動性與已授權金額的限制,並非任意鑄幣類型的問題,但這種由社區發起的力量是我們在這段旅程中發現的重要價值,再看到近日由 @tastedotmd 舉辦的黑客松,有超過 70 支隊伍報名,共產出了45個產品, 我對此衷心感到自豪 亦再此再次感謝,Norman 及 ZeroDrift,Collectibles 是一個建立在社區之上的產業,而這正是我們社區在關鍵時刻展現力量的最佳證明 我們會持續朝著強化協議的方向前進 如果你發現任何值得回報的事項,我的收件匣永遠為你敞開——或者直接聯繫團隊 info@renaiss.xyz 我們誠摯歡迎更多人一起在這個藏品金融世界正在建立的早期加入,共同讓 Renaiss 及整個產業變得更好 另外,如果你是項目方,有安全上的有任何疑問或需求,我們也會衷心推薦聯絡 Norman,他們非常專業

English
4
0
5
661
长尼玛
长尼玛@raylin51·
你们是不是真以为台子的币迁移到 uniswap 以后就跟台子没关系了?加池子的 LP 还在台子的 LaunchLocker 合约里,合约又不开源,你们这帮不会反编译的 sb 连 LP 能不能抠出来给池子撤了都不知道。就算不能撤 LP 的 1% 手续费也不停给已经 rug 的团队,你告诉我这币的前景还好吗?
长尼玛 tweet media
长尼玛@raylin51

Noxa 这么一搞,cashcat 的前景变得非常不明朗了。外盘的 1% 手续费是直接通过 Uniswap LP Position 收取,而不是传的合约配置,合约配置应该是内盘代币。LauncherLocker 可以不停用 LP 来 claim fee。问题是 LauncherLocker 也没有开源,除非反编译仔细审计一下,否则不能保证这个合约里有没有后门能把 LP Position NFT 抠出来撤池子。就算没有这1%的双边税一直给一个停运的台子也不太对劲。我先撤了这次我不买单了

中文
21
1
20
16.3K
Norman
Norman@Normanxbt·
针对最近社区对 @Noxa_Fi 和 cash-cat:native 的机制问题,我们团队通过链上反编译确定了: 1. Noxa Dev确实可以收到5%的LP 手续费,这部分的fee本身也是属于1% uni手续费池子里的。 2. Noxa dev无法撤池,无法移走用户本金,也没有增发权限。 3. Noxa现在的factory,Locker,Feerouter都是一个钱包地址掌控,中心化风险很高。 至于说CashCat本身还不存在蜜罐之类的风险。
Zerodrift@ZeroDriftSec

x.com/i/article/2077…

中文
1
0
1
574
Norman
Norman@Normanxbt·
"of the 533 traced bugs, 72% were introduced after launch, in an upgrade or a feature commit, not on day one." 其实这就是为什么我们需要持续性的安全审查,因为项目的很多升级,新功能和产品事实上并不会做安全审计,漏洞就随着代码悄悄上线了。
Gustav Hartz@GustavHartz

x.com/i/article/2073…

中文
1
1
1
485
Norman
Norman@Normanxbt·
@GustavHartz Great analysis! thats exactly we need AI to implement the continuous review
English
0
0
0
91
Mudit Gupta
Mudit Gupta@Mudit__Gupta·
An arbitrary state write bug in Aptos chain was disclosed by @hexens today. This is the worst kind of bug possible on a chain. Why? Not only everything on the affected chain can be stolen but also most assets across all chain can be stolen. Your stablecoins, LSTs, everything
English
41
137
459
68.1K
Norman retweetledi
Geeq
Geeq@GeeqOfficial·
This thread by @ZeroDriftSec caught our eye. When users have access to live code, they should have a reasonable expectation that someone is continuing to verify whether it remains appropriate to use. Why is the burden of verification falling on users?
Zerodrift@ZeroDriftSec

$17M Stolen in 40 Days. An overlooked attack surface is quietly fueling a new wave of exploits: deprecated contracts. Over the past 40 days, attackers have extracted nearly $17M from contracts that were considered obsolete but remained live on-chain. Here’s how deprecated contracts are becoming hackers’ ATMs. 🧵

English
4
7
12
1.4K
Norman
Norman@Normanxbt·
@ohyishi 支持onekey这样的开源精神
中文
0
0
0
729
Yishi
Yishi@ohyishi·
信任从来不会凭空产生。 它来自一家公司愿不愿意把代码公开,愿不愿意让所有人检查,愿不愿意把最核心的东西交给时间验证。 从 2019 年创立第一天起,OneKey 就选择全开源。从 App 到固件,任何开发者、安全机构,甚至 AI,都可以独立检查。基于 OneKey 代码 Fork 的钱包我见过不下十个。 我们最早从 Trezor 的开源方案出发,随后一步一步完成自主研发,建立自己的硬件、固件与软件体系,掌握核心技术,也拥有完整的自主知识产权。 这些年,OneKey 成为第一个,也是目前唯一一个被 bitcoin[.]org 收录的亚洲硬件钱包品牌。销量做到亚洲第一,全球第三。 但真正让我们珍惜的,从来不只是这些排名和记录。 是几轮牛熊过去,用户逐渐学会自托管,把资产存在自己的 OneKey 钱包;是行业最混乱的时候,还有人相信我们会把安全放在第一位;是很多人买下第一台 OneKey 后,又把它推荐给家人和朋友。 六年过去,我们越来越确信,安全要靠公开证明,信任要靠时间积累,口碑要靠每一台产品慢慢赢回来。 OneKey 不辜负每一份托付。
Yishi tweet media
中文
63
19
319
107.5K
Norman
Norman@Normanxbt·
新的一天,新的废弃合约被盗,闪电贷操纵价格盗走了26万美元。
The Crypto Times@CryptoTimes_io

ICYMI: A hacker turned roughly $2,600 into more than $263,000 by exploiting an old Polygon-based smart contract. Not by breaking @0xPolygon. Not by hacking private keys. Not by draining user wallets. Instead, they found a flaw in a forgotten "legacy" royalties contract that was still live on-chain. According to security researchers, the attacker used a flash loan and manipulated the contract's reward accounting logic, allowing them to artificially inflate rewards and withdraw far more than they should have been able to. The result? A profit of around $261,000 in a single transaction. What's alarming is that this wasn't a new protocol. It was an old contract. A reminder that in crypto, code doesn't disappear just because a project moves on. Many older contracts remain active for years, often holding funds and permissions long after teams stop paying attention to them. This is why security experts keep warning about "zombie contracts"—outdated smart contracts that quietly sit on-chain until someone discovers a vulnerability. The biggest threats in DeFi aren't always the newest protocols. Sometimes they're the forgotten ones.

中文
0
1
18
6.2K
Channi Greenwall
Channi Greenwall@ChanniGreenwall·
@Normanxbt @jaredsmev As systems become more autonomous, the attack surface shifts from code execution to decision manipulation.
English
1
0
1
66
Norman
Norman@Normanxbt·
前两天 @jaredsmev 的mev bots被攻击导致损失超过750万美金大家应该都看到了。 简单来说攻击者提前部署了一批假 token、假 pool、假交易路径,让这些路径看起来像有利可图的 MEV 机会。 bot 按自己的策略去执行时,给了攻击者控制的 helper contract 一些 ERC-20 授权。后面攻击者调整路线,让授权没有被立刻消费或撤销,于是留下 open allowance,最后用 transferFrom 把 bot 合约里的 WETH、USDC、USDT 盗走了。 但这并不是个例,事实上Sen Yang团队在去年发表的论文里就做了针对mev bots被攻击的研究。一些数字: 他们收集了 6,554 个 MEV bot 地址。 SKANF 发现 1,030 个合约有潜在漏洞。 其中 394 个可以自动生成 exploit。 这些漏洞潜在损失约 $10.6M。 他们还回溯发现 104 起真实 MEV bot 被攻击事件,总损失约 $2.76M 论文里最有意思的概念是 MEV phishing attack。 简单讲就是: 攻击者不是直接去黑 bot,而是先造一个“看起来有利润的 MEV 机会”。Searcher 看到机会后,用自己的 bot 去执行套利/夹子/回补路径。结果这个路径里藏了恶意 token、恶意 pool 或恶意 callback,bot 自己在执行过程中把危险函数调用了,或者把资产授权/转走了。 mev bots已经是一个很成熟的技术和产品了,我觉得现在更危险的反而是trading agents/agentic wallets。包括 @DonutAI @byreal_io @wallet @BitgetWallet 。因为agents不仅要面对传统的phishing attacks,还有prompt inejctions等AI面的风险。 大家以为AI很聪明,但事实上AI远比我们想象的容易操纵和攻击
Norman tweet media
Sen Yang@syang2ng

The recent phishing attacks against MEV bots are sad, but not surprising. In our recent @acm_ccs 26 paper, we found that many MEV bots are vulnerable to phishing-style attacks because they expose logic to adversary-controlled calls: arxiv.org/abs/2504.13398

中文
6
21
124
25.9K
Norman
Norman@Normanxbt·
@joezhoublack 非常好的文章,不过有一处错误,后面喜欢的创始人特质“第二类”重复了
中文
1
0
0
312
Norman
Norman@Normanxbt·
alright guys this jared account is fake,sorry for tagging the wrong account
English
0
0
1
346
Norman
Norman@Normanxbt·
@3heeeeee @jaredsmev 不要用 tx.origin 做授权;对 callback/caller 做精确验证,例如 Uniswap V3 pool 要按 factory + CREATE2 反推合法 pool 地址
中文
0
0
1
302
sanhe
sanhe@3heeeeee·
@Normanxbt @jaredsmev open allowance 算是 MEV bot 的共性风险了,searcher 执行完一轮后有自动 revoke 的标准做法吗?
中文
1
0
1
484
Norman
Norman@Normanxbt·
我们最近发现一个新的攻击面:废弃合约。最近 @humafinance @Scallop_io @Raydium 都因为已经废弃的合约被攻击,40天类似的case累计损失了超过1700万。 过去废弃合约属于三不管地带,用户交互不了,项目方不维护,安全团队也不看。但是现在有了AI,黑客可以大规模地在链上去攻击,经济成本大大下降。 任何有废弃合约的项目方,特别是链上还有流动性的建议都自己查一查,或者也可以找我们帮忙。DM随时开放
Zerodrift@ZeroDriftSec

$17M Stolen in 40 Days. An overlooked attack surface is quietly fueling a new wave of exploits: deprecated contracts. Over the past 40 days, attackers have extracted nearly $17M from contracts that were considered obsolete but remained live on-chain. Here’s how deprecated contracts are becoming hackers’ ATMs. 🧵

中文
3
8
65
13.6K