webrainsec

120 posts

webrainsec banner
webrainsec

webrainsec

@webrainsec

miss nothing.

web3 Katılım Temmuz 2025
93 Takip Edilen113 Takipçiler
Plamen Tsanev
Plamen Tsanev@p_tsanev·
😱A FREE Open-Source AI Auditor just delivered the same output as a $47,000 audit contest! Plamen ran twice on the same DODO contest as other tools and achieved 90+% coverage both times! Check the entire process below and integrate Plamen in your development workflow now
Plamen Tsanev tweet media
English
15
4
105
4.9K
webrainsec retweetledi
SHERLOCK
SHERLOCK@sherlockdefi·
The @aave team partnered with Sherlock across the V4 upgrade through three major phases: a multi-phase collaborative audit with Blackthorn, a $365K audit contest, and a bug bounty to protect live code after launch. For one of the biggest architectural shifts in Aave’s history, the margin for missed issues was basically zero. Sherlock was brought in to go deeper on the parts of V4 that were entirely new, especially the Hub-and-Spoke architecture + risk premium system.
SHERLOCK tweet media
English
8
13
83
9.1K
webrainsec retweetledi
webrainsec
webrainsec@webrainsec·
ty for quick triage @cantinaxyz 🤝 on to the next
webrainsec tweet media
English
2
2
25
2K
webrainsec
webrainsec@webrainsec·
fair point, FoT reverts at the require so it's DoS not inflation. the fix is still the same though. shares should track the balanceOf delta, not the input amount. that way FoT tokens work instead of reverting, and the accounting stays correct regardless of token behavior. Also, the CEI violation you mentioned is real, state update after external call
English
0
0
0
15
naush
naush@ifkacja·
@webrainsec @HackenProof you are partly right but fee on transfer tokens won't pass the require statement, they will revert. I think rebasing tokens will mess up the accounting of the protocol, if wierd ERC20 are in scope 😁. In addition to that, violation of CEI can also be seen here.
English
1
0
1
35
HackenProof
HackenProof@HackenProof·
Spot the Bug 🧠 ERC20 deposit accounting What’s the issue in this code?👇
HackenProof tweet media
English
12
2
60
4K
webrainsec
webrainsec@webrainsec·
@victorokpukpan_ ye we also see it a lot, maybe even more than before because of vibe coded apps?
English
1
0
0
44
𝗩𝗶𝗰𝘁𝗼𝗿_𝗧𝗵𝗲𝗢𝗿𝗮𝗰𝗹𝗲
I still see developers storing private keys in plaintext. .env files, config files, and even random text files. It feels harmless until one mistake exposes everything. There is a better way to handle this.
English
3
8
143
2.3K
webrainsec retweetledi
Pashov Audit Group
Pashov Audit Group@PashovAuditGrp·
Everyone is shipping AI security tools now. We went through them so you don't have to. 35 tools reviewed - Claude Code skills, standalone scanners, paid platforms. Hand-picked, not bulk imported. Drop the one AI security tool that you love the most🫡
Pashov Audit Group tweet media
English
8
16
174
11K
pashov
pashov@pashov·
Beautiful blog post. If you want to build the best AI security tools, read this. Innovation in the is space about to upgrade the baseline, fast.
BradMoon@xy9301

x.com/i/article/2033…

English
8
15
154
13.4K
webrainsec
webrainsec@webrainsec·
@cvetanovv0 discipline, consistency and hard work lead to success, and eventually the impossible is made possible 🤝
English
0
0
1
38
Dimitar Tsvetanov
Dimitar Tsvetanov@cvetanovv0·
In Web3 security, every finding and every failure forges a stronger auditor. Each challenge is an opportunity to learn. The true expertise is built by those who never stop growing, adapting, and pushing the boundaries of what’s possible.
English
3
5
52
1.1K
webrainsec retweetledi
pashov
pashov@pashov·
AI Web3 Security AI Web3 Security AI Web3 Security AI Web3 Security AI Web3 Security AI Web3 Security AI Web3 Security
Română
9
3
109
4.9K
webrainsec
webrainsec@webrainsec·
@zacodil ye, didn't see the UI yet but you're absolutely right
English
0
0
0
21
Vadim
Vadim@zacodil·
Read both post mortems from CoW Protocol and Aave on the $50M swap. What they reveal is worse than the headlines. Here's what stood out: The auction timeline: - Three solvers quoted. Two found routes returning ~52K AAVE (~$5.7M). One returned ~330 AAVE (~$36K). The two good quotes were rejected by a hardcoded 12M gas limit in the verification system - legacy code nobody updated. The worst quote set the limit price. - A solver later found the good route again and won two consecutive auctions. Then never submitted the transaction. No revert. No error. Just didn't execute. Then stopped bidding. CoW says this is "under investigation." - The last solver standing had the worst route. Won the third auction with no competition. That's what executed. Mempool leak: - The solver submitted via private RPC. Etherscan tagged it as seen in the public mempool. If confirmed, the transaction leaked - enabling ~$34M in backrun extraction. Also "under investigation." Aave's side: - UI showed 99.9% price impact. Checkbox: "I confirm the swap with a potential 100% value loss." User confirmed on mobile. - Initially announced a $600K fee refund. Post mortem now says $110K. That's not a rounding error. - Shipping "Aave Shield" - blocks swaps over 25% price impact by default. A threshold check. After $50M. - The user still hasn't contacted them. What neither report addresses: - Why CoW is hardcoded as the only swap provider with no price comparison. - The SolverParticipationGuard deleted six weeks earlier instead of fixing it - The 12M gas ceiling that rejected 160x better quotes was legacy code. CoW says it's "already fixed." It took a $50M loss to update a hardcoded number. - CoW confirms even the best quotes reflected ~90% value loss. The liquidity wasn't there on any single chain. This isn't a routing problem - it's a liquidity fragmentation problem. - Solver E found a 160x better route, won two consecutive auctions - and never submitted the transaction. Didn't even try. Then stopped bidding. The worst solver won the third auction by default. CoW's explanation: "ongoing investigation."
Vadim tweet media
English
24
23
190
30.6K
ross.wei
ross.wei@z0r0zzz·
@webrainsec cool - hmu - moloch/majeur looks like an ai audit scan contest so far and it would be useful to get your input
English
1
0
2
338
webrainsec
webrainsec@webrainsec·
lucky day on friday the 13th, let's get it
English
0
0
0
36