Raj Shah

82 posts

Raj Shah banner
Raj Shah

Raj Shah

@rj_eth26

Web3 Security Researcher

Katılım Kasım 2024
195 Takip Edilen40 Takipçiler
Raj Shah retweetledi
Dear Self.
Dear Self.@Dearme2_·
If your MOM is still alive, retweet this.
Dear Self. tweet media
English
205
30.1K
68.7K
1.5M
Raj Shah
Raj Shah@rj_eth26·
Exactly! Sponsor thinks public contest are not necessary and they only believe in AI scanning or just 1 Private audits but audit with that same expense or less there are 1000+ Security Researcher's thinking come in play when they do contest audit.
ddimitrov22@ddimitrovv22

Every day an audited project gets hacked. Does that mean audits don’t work? No. Projects just prefer to save $2k on an audit and think that all audits are the same. Spoiler: they are not

English
0
0
2
58
SHERLOCK
SHERLOCK@sherlockdefi·
Sherlock created an audit team assembly system based on deep performance data. Most security firms rely on fixed in-house teams or assign researchers based on availability. Over time, we kept seeing the same gaps: auditors placed on codebases that didn’t match their strengths, and blind spots no small static team can realistically cover. Every researcher in our network is scored on accuracy, severity classification, specialization, and false positive history. When a private audit starts, we assemble audit teams based on who is most likely to catch what matters in that specific codebase.
SHERLOCK tweet media
English
4
4
35
10K
Raj Shah
Raj Shah@rj_eth26·
Last day of @revertfinance contest on @cantinasecurity platform, so wrapping my leads and going deep to find real bug Also thinking for edge cases and looking for integration issue & analysing docs deeply but code is really looking solid
English
0
0
2
59
Raj Shah retweetledi
chrisdior
chrisdior@chrisdior777·
One of the toughest months Web3 has faced. April 2026: • 30+ security incidents • ~$630m drained This chart shows the hacked projects, estimated losses, and the cause behind each incident.
chrisdior tweet media
English
12
14
96
10.3K
Raj Shah
Raj Shah@rj_eth26·
Today i am starting audit of @MonetrixFinance on @code4rena platform - Reading docs deeply and understanding its full flow that how its work - Also analysing areas to focus and known issue related bugs which is previously found by other SR
English
0
0
2
36
Raj Shah retweetledi
Immunefi
Immunefi@immunefi·
Most security firms are quietly moving away from audit competitions. This is one of the biggest mistakes happening in crypto security right now. There is a simple way to think about audit value: what does it cost to find a critical vulnerability? We looked at the actual data on what it costs to find critical bugs in crypto, and the numbers are not surprising. Finding a critical vulnerability in an audit competition costs $6,548 on average. The exact same severity bug through a bug bounty program costs $114,000. That is 17x more expensive for the same result. Now look at the traditional audit model. Some top firms charge $100 per line of code. Others charge as high as $25,000 per auditor per week. A single engagement can easily run $200k to $500k+, and you are getting maybe 2 to 4 people looking at your code. But cost per critical is not even the most interesting part. The interesting part is the structure of who is looking at your code. When you hire a firm, you get 2 to 4 auditors. Maybe they are great. Maybe one of them is having a bad week. You are making a concentrated bet on a small number of people. An audit competition attracts hundreds of security researchers. These are some of the best hackers, people who have found real vulnerabilities in major protocols. These hundreds of researchers are now armed with AI tools. They understand codebases faster. They write PoCs faster. They find bugs that would have taken DAYS in just hours. Think about what that means. You are not just getting hundreds of humans. You are getting hundreds of AI-augmented humans, each running their own workflow, each with their own intuition about where bugs hide. The scaling dynamics are extraordinary. The firms moving away from competitions are optimizing for predictable revenue, not for their clients’ best outcomes. That is understandable from a business perspective. But if you are a project choosing where to spend your security budget, you should optimize for bugs found per dollar spent. Audit competitions now also have scaling pots. The prize pool grows with the scope of the codebase. This aligns incentives in a way that fixed-fee engagements never can. But what about AI spam, low-quality submissions, and the time it takes to triage all of those submissions? Immunefi is addressing these with mechanisms like pay-to-submit, managed triage, and AI triaging agents, which are already showing very strong promise. The best security strategy is not either or. But if you have a limited budget and you want the most eyes, the most diverse skill sets, and the best cost per finding ratio, audit competitions are still the obvious choice.
Immunefi tweet media
English
13
37
235
19.5K
Raj Shah
Raj Shah@rj_eth26·
Been digging into the XRPL contest on @sherlockdefi , and almost every bug or lead I find turns out to already be a known issue 😅 Still a great learning experience which helps refine my approach and think deeper.
English
0
0
6
313
Raj Shah
Raj Shah@rj_eth26·
Completed Solidity2 smart contract audit codebase Submitted 8 findings: 5 High, 1 Medium, 1 Design-choice, 1 Informational. A solid result from a private audit engagement during my internship. Looking forward to deeper audits ahead. @KannAudits thank for an opportunity
English
1
0
4
149
Raj Shah
Raj Shah@rj_eth26·
@sherlockdefi Hi team, are there any upcoming Solidity audit contests scheduled? I would love to participate. Thanks!
English
0
0
0
22
SHERLOCK
SHERLOCK@sherlockdefi·
Sherlock has completed a collaborative audit for AeroBoost. 🤝 AeroBoost automates voting on Aerodrome & Velodrome without locking rewards, and they’ve now opened public release for the first 100 locks. Check them out here: aeroboost.eth.limo Happy Boosting!
SHERLOCK tweet media
English
1
1
14
1.4K
Raj Shah retweetledi
Shieldify Security
Shieldify Security@ShieldifySec·
| ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄| Ai will NOT protect your smart contracts |____________| \ (•◡•) / \ / —— | | |_ |_
English
3
12
77
2.8K
Raj Shah
Raj Shah@rj_eth26·
Today i am still auditing @Superfluid_HQ protocol on @sherlockdefi But still i didn't got any H/M bug, scope taken is too small and still trying to find some hint form code audit
English
0
0
1
50
Raj Shah
Raj Shah@rj_eth26·
Today i am continueing audit of @Superfluid_HQ protocol on @sherlockdefi Now i am entered in code audit, so now my focus is to find some hints which can be converted into real bug.
English
0
0
2
88
Raj Shah
Raj Shah@rj_eth26·
Today i am sarting new contest @Superfluid_HQ on @sherlockdefi platform So now i am firstly analysing its doc to understand whole design and full flow Once its done i will be enter in real code auditing and try to finding some leads.
English
0
0
4
69
Raj Shah
Raj Shah@rj_eth26·
Week-2 day 1 in @KannAudits internship - Starting audit of new protocol - Understanding design deeply
English
0
0
1
44
Raj Shah
Raj Shah@rj_eth26·
Today's update: - Continuing manual review of @revertfinance on @cantinaxyz platform. - I got some hints but lastly it converted into nothing or low at best and focusing more preciously @0xSimao
English
0
0
3
168
Raj Shah
Raj Shah@rj_eth26·
Continuing my audit of @RevertFinance on @CantinaXYZ today. Diving into the codebase and analyzing the full execution flow step by step, understanding how each function interacts, and tracking state changes across the system @0xSimao
English
0
0
2
69