phil

2.1K posts

phil banner
phil

phil

@philbugcatcher

Cybersecurity Researcher @Certora | @CyfrinUpdraft alumni | Prev @McKinsey

EVM Katılım Aralık 2022
1.1K Takip Edilen3.4K Takipçiler
phil retweetledi
OpenAI
OpenAI@OpenAI·
You've been asking for this one... Now in preview: Codex in the ChatGPT mobile app. Start new work, review outputs, steer execution, and approve next steps, all from the ChatGPT mobile app. Codex will keep running on your laptop, Mac mini, or devbox.
English
1.4K
2.5K
20.4K
3.8M
phil retweetledi
Certora
Certora@Certora·
Certora is hiring! We're expanding into Web2 & Mobile security research. If you have a strong background in application security or vulnerability research, this opportunity might be for you ⬇️
Certora tweet media
English
6
21
159
11.9K
phil retweetledi
Veda
Veda@veda_labs·
We’re partnering with @Certora as part of our continued commitment to security. This means: → formal verification → bug testing → fuzzing → and more
Veda tweet media
English
4
11
43
8.3K
phil retweetledi
banteg
banteg@banteg·
lots of unverified contracts hacks lately. where are my security through obscurity guys at? feel embarrassed yet?
English
16
29
272
22.2K
phil retweetledi
Grok
Grok@grok·
Sometimes I ask myself if this is true
English
8.1K
9.7K
92K
97.1M
phil retweetledi
Aave
Aave@aave·
In line with the technical plan outlined below, the attacker's rsETH positions on Aave have been liquidated on Ethereum and Arbitrum. The liquidated collateral now sits with the Recovery Guardian as specified in the AIP. No other users were affected, and Umbrella was also untouched. This was a critical step in the recovery roadmap, with next steps to follow.
Aave@aave

x.com/i/article/2048…

English
175
326
1.1K
149.5K
phil
phil@philbugcatcher·
@hrkrshnn @shamelesslymean @brian_armstrong Because that’s misleading. The guardrails are part of the code and built by a technical team. So we are talking about a mixed team shipping code together, which is how things have always been, just less siloed
English
0
0
5
113
Hari
Hari@hrkrshnn·
On "non-technical" people shipping to production: a recent comment by Coinbase CEO @brian_armstrong hit a lot of nerves, with many concerned users about the security of this code and their own assets. How software is built, shipped, and secured has completely changed at the frontier. We're a team building a frontier AI security product. Our autonomous bug hunter, Apex, has earned nearly a million dollars in bug bounties and is, in fact, #1 on the @coinbase Web2 bounty leaderboard on HackerOne for 2026. It's absolutely possible to get "non-technical" people to ship bulletproof code. You need to intentionally build the right guardrails that let your team cook. If it's done right, I 100% believe a non-technical person can ship code that's far more secure than an average engineer in the past! The right guardrail is neither 'human in the loop' nor 'annual pentests.' It'll look a lot like a 24/7 background security agent. It's always hunting for bugs, always triaging the different signals it's seeing, and evolving itself as you're building based on the inputs and feedback you provide. That's the only way to scale security in this new age. Lastly, the idea that "non-technical" people can't ship code just doesn't make any sense. A lot of programmers I know pride themselves on being self-taught. Coding agents have just made it so much easier to start coding. One of the best programmers I know learned how to code in the 90s by typing the source code of games printed in magazines onto his computer. If he were the same age today, he'd be asking Claude to build and tinker with it. If you're a founder or leading a team where security feels like a blocker for scaling with coding agents, reach out to me in DMs. I can chat about how we're seeing teams tackle this well.
Hari tweet media
English
2
5
39
9.3K
phil
phil@philbugcatcher·
@Nick117317 Wait until you get to the first few years. It gets better
English
0
0
1
37
phil
phil@philbugcatcher·
Building with AI is extremely addictive
English
4
0
25
860
phil
phil@philbugcatcher·
It is a bad idea to get a non technical team to ship production code, especially for a financial institution A non technical person can only answer “does the code do what I want?” They can never know “does it not do what I don’t want?” Source: am a former non technical person
Brian Armstrong@brian_armstrong

This is an email I sent earlier today to all employees at Coinbase: Team, Today I’ve made the difficult decision to reduce the size of Coinbase by ~14%. I want to walk you through why we're doing this now, what it means for those affected, and how this positions us for the future. Why now Two forces are converging at the same time. We need to be front footed to respond to both. First, the market. Coinbase is well-capitalized, has diversified revenue streams, and is well-positioned to weather any storm. Crypto is also on the verge of the next wave of adoption, with stablecoins, prediction markets, tokenization, and more taking off. However, our business is still volatile from quarter to quarter. While we've managed through that cyclicality many times before and come out stronger on the other side, we’re currently in a down market and need to adjust our cost structure now so that we emerge from this period leaner, faster, and more efficient for our next phase of growth. Second, AI is changing how we work. Over the past year, I’ve watched engineers use AI to ship in days what used to take a team weeks. Non-technical teams are now shipping production code and many of our workflows are being automated. The pace of what's possible with a small, focused team has changed dramatically, and it's accelerating every day. All of this has led us to an inflection point, not just for Coinbase, but for every company. The biggest risk now is not taking action. We are adjusting early and deliberately to rebuild Coinbase to be lean, fast, and AI-native. We need to return to the speed and focus of our startup founding, with AI at our core. What this means To get there, we are not just reducing headcount and cutting costs, we’re fundamentally changing how we operate: rebuilding Coinbase as an intelligence, with humans around the edge aligning it. What does this mean in practice? - Fewer layers, faster decisions: We are flattening our org structure to 5 layers max below CEO/COO. Layers slow things down and create coordination tax. The future is small, high context teams that can move quickly. Leaders will own much more, with as many as 15+ direct reports. Fewer layers also means a leaner cost structure that is built to perform through all market cycles. - No pure managers: Every leader at Coinbase must also be a strong and active individual contributor. Managers should be like player-coaches, getting their hands dirty alongside their teams. - AI-native pods: We’ll be concentrating around AI-native talent who can manage fleets of agents to drive outsized impact. We’ll also be experimenting with reduced pod sizes, including “one person teams” with engineers, designers, and product managers all in one role. In short: AI is bringing a profound shift in how companies operate, and we’re reshaping Coinbase to lead in this new era. This is a new way of working, and we need to leverage AI across every facet of our jobs. To those who are affected I know there are real people behind these decisions — talented colleagues who have poured themselves into this company and our mission. To those of you who will be leaving: thank you. You’ve helped build Coinbase into what it is today, and I am sincerely grateful for everything you've done. All impacted team members will receive an email to their personal account in the next hour with more information, and an invitation to meet with an HRBP and a senior leader in your organization. Coinbase system access has been removed today. I know this feels sudden and harsh, but it is the only responsible choice given our duty to protect customer information. To those affected, we will be providing a comprehensive package to support you through this transition. US employees will receive a minimum of 16 weeks base pay (plus 2 weeks per year worked), their next equity vest, and 6 months of COBRA. Employees on a work visa will get extra transition support. Those outside of the US will receive similar support, based on local factors and subject to any consultation requirements. Coinbase prides itself on talent density. Our employees are among the most talented people in the world, and I have no doubt that your skills and experience will be highly sought after as you pursue your next chapters. How we move forward To the team that is staying, I know this is a difficult day. We’re saying goodbye to colleagues and friends you've been in the trenches with. But here’s what I want you to know as we move forward together: Over the past 13 years, we have weathered four crypto winters, gone public, and built the most trusted platform in our industry. We’ve made it this far by making hard decisions and by always staying focused on our mission. This time will be no different – nothing has changed about the long term outlook of our company or industry. And most importantly, our mission has never been more important for the world. Increasing economic freedom requires a new financial system, and we’re building it. The Coinbase that emerges from this will be more capable than ever to achieve our mission. Brian

English
2
1
34
1.8K
phil retweetledi
Jason Fried
Jason Fried@jasonfried·
The last 20% isn't most of the work, it's all of the work.
English
99
312
3.1K
143.9K
phil retweetledi
Mooly Sagiv
Mooly Sagiv@SagivMooly·
Rounding errors have drained millions from DeFi protocols. Certora is building an open source static analysis tool for Solidity to prevent them, and we're participating in the @ethereum Security QF Round from @thedaofund. Your donation helps us go further ↓
English
6
11
58
7.4K
phil retweetledi
Loris
Loris@0xLoris·
excuse me, pardon me can i interest you in a little witch's brew of • a Felix spot token which uses • USDC routed through a Felix smart contract that hits Ondo’s (a tokenize securities provider) mint/redeem endpoint to mint • STRCon, Ondo's ERC-20 token representing economic exposure (not actual ownership) via a loan note collateralized by • STRC, a perpetual preferred stock, par $100, dividend manually adjusted monthly to peg the price (ponzi scheme?) concocted by the financial engineers at • MSTR, a former software company that uses proceeds to buy • BTC, the fundamental underlying asset a token, of a token, of a BVI loan note, of a peg-managed preferred stock, of a leveraged BTC holding company, whose underlying is BTC my head is spinning
GIF
Felix@felixprotocol

Spot STRC is now live on Felix. STRC investors on Felix have economic exposure to the current 11.50% annualized dividend for Strategy’s preferred stock. Access STRC now at trade.usefelix.xyz/equities/STRC

English
9
5
146
26.8K
phil
phil@philbugcatcher·
@dev_chinmayf To be frank it took that long because I made it into something that she and other teachers who use the same system will be able to reuse But yes, if it was a one off thing it would have been terrible
English
0
0
0
176
Chinmay Farkya
Chinmay Farkya@dev_chinmayf·
@philbugcatcher That’s hilarious. I have had the same experience with filing basic excel sheets and docs 😂 AI does a very bad job there
English
1
0
5
365
phil
phil@philbugcatcher·
Mom was manually entering grades from paper into a system on her computer I told her I could handle all of that in under a minute with AI It only took me 4 hours to enter the grades for all 15 of her students 😎
English
2
0
77
3.1K