phil
2.1K posts

phil
@philbugcatcher
Cybersecurity Researcher @Certora | @CyfrinUpdraft alumni | Prev @McKinsey
EVM Katılım Aralık 2022
1.1K Takip Edilen3.4K Takipçiler
Sabitlenmiş Tweet
phil retweetledi
phil retweetledi
phil retweetledi

phil retweetledi

gonna play the heck out of GTA 6 simply because of its status as a cultural artefact: the final big game built before LLMs
no-one will ever invest this much in a game again, no software will ever encode this quantity of hands-on human labour again. the last of the great pyramids
Kalshi@Kalshi
JUST IN: GTA 6 estimated to have cost $1 billion
English
phil retweetledi
phil retweetledi
phil retweetledi
phil retweetledi

In line with the technical plan outlined below, the attacker's rsETH positions on Aave have been liquidated on Ethereum and Arbitrum. The liquidated collateral now sits with the Recovery Guardian as specified in the AIP.
No other users were affected, and Umbrella was also untouched. This was a critical step in the recovery roadmap, with next steps to follow.
Aave@aave
English

@hrkrshnn @shamelesslymean @brian_armstrong Because that’s misleading. The guardrails are part of the code and built by a technical team. So we are talking about a mixed team shipping code together, which is how things have always been, just less siloed
English

On "non-technical" people shipping to production: a recent comment by Coinbase CEO @brian_armstrong hit a lot of nerves, with many concerned users about the security of this code and their own assets.
How software is built, shipped, and secured has completely changed at the frontier. We're a team building a frontier AI security product. Our autonomous bug hunter, Apex, has earned nearly a million dollars in bug bounties and is, in fact, #1 on the @coinbase Web2 bounty leaderboard on HackerOne for 2026.
It's absolutely possible to get "non-technical" people to ship bulletproof code. You need to intentionally build the right guardrails that let your team cook. If it's done right, I 100% believe a non-technical person can ship code that's far more secure than an average engineer in the past!
The right guardrail is neither 'human in the loop' nor 'annual pentests.' It'll look a lot like a 24/7 background security agent. It's always hunting for bugs, always triaging the different signals it's seeing, and evolving itself as you're building based on the inputs and feedback you provide. That's the only way to scale security in this new age.
Lastly, the idea that "non-technical" people can't ship code just doesn't make any sense. A lot of programmers I know pride themselves on being self-taught. Coding agents have just made it so much easier to start coding. One of the best programmers I know learned how to code in the 90s by typing the source code of games printed in magazines onto his computer. If he were the same age today, he'd be asking Claude to build and tinker with it.
If you're a founder or leading a team where security feels like a blocker for scaling with coding agents, reach out to me in DMs. I can chat about how we're seeing teams tackle this well.

English
phil retweetledi

The Solana ecosystem is accerting formal verification and AI
Solana Events@SolanaEvents
Why is @Certora building on @solana? -Clients -Speed -Belief
English

@Nick117317 Wait until you get to the first few years. It gets better
English

phil retweetledi
phil retweetledi

1 day after Haun announces?
did they just get raisemogged
a16z crypto@a16zcrypto
We've raised $2.2B in committed capital to invest in the next generation of crypto. Announcing Crypto Fund 5
English
phil retweetledi

Rounding errors have drained millions from DeFi protocols.
Certora is building an open source static analysis tool for Solidity to prevent them, and we're participating in the @ethereum Security QF Round from @thedaofund.
Your donation helps us go further ↓
English
phil retweetledi

excuse me, pardon me can i interest you in a little witch's brew of
• a Felix spot token which uses
• USDC routed through a Felix smart contract that hits Ondo’s (a tokenize securities provider) mint/redeem endpoint to mint
• STRCon, Ondo's ERC-20 token representing economic exposure (not actual ownership) via a loan note collateralized by
• STRC, a perpetual preferred stock, par $100, dividend manually adjusted monthly to peg the price (ponzi scheme?) concocted by the financial engineers at
• MSTR, a former software company that uses proceeds to buy
• BTC, the fundamental underlying asset
a token, of a token, of a BVI loan note, of a peg-managed preferred stock, of a leveraged BTC holding company, whose underlying is BTC
my head is spinning
GIF
Felix@felixprotocol
Spot STRC is now live on Felix. STRC investors on Felix have economic exposure to the current 11.50% annualized dividend for Strategy’s preferred stock. Access STRC now at trade.usefelix.xyz/equities/STRC
English

@dev_chinmayf To be frank it took that long because I made it into something that she and other teachers who use the same system will be able to reuse
But yes, if it was a one off thing it would have been terrible
English

@philbugcatcher That’s hilarious. I have had the same experience with filing basic excel sheets and docs 😂
AI does a very bad job there
English









