2/ I put together a deep dive on it.
What D is supposed to do in StableSwap, how the 3-phase attack actually played out, how it rhymes with the recent Balancer StablePool mess, and what we can learn as DeFi devs/auditors.
Full post 👇
https://t.co/cv16AfwDpZ
1/ Yearn’s yETH exploit wasn’t “just an underflow”.
It was a fragile StableSwap solver, cached vars drifting away from reality, and no guardrails.
AKA: how 16 wei turned into 2.35×10⁵⁶ yETH.
Built "Sentra" after deep-diving Account Abstraction — an ERC-4337 console for 0-balance mints via paymaster, admin funding & allowlists, and UserOp gas/asset/AA error debugging.
Demo in video below 👇
Day 116-119
Holidays in Korea - family time recharged 😎
Day 120-121
Solved 2 Challenges in Damn Vuln DeFi
- Climber: Timelock CEI Violation
- Wallet Mining: Proxy Storage Collision
Shadow auditing DODO Cross-Chain DEX
Rested body, overloaded brain 🧠💥
Every Auditor must know Solana in 2025
Top 3 Resources to learn Solana.
🏴Blueshift Solana
🔗https://t.co/owjiGl29nW
🏴 Solana Tutorial by @RareSkills_io
🔗 https://t.co/H1gtCDWhVF
🏴 Awesome Solana Security
🔗 https://t.co/0DKK7hzxNg
Here is the bug writeup of my 50,000 USDC bounty on @cantinaxyz
This is supposed to be one of my many articles on BBP. If this original article post gets 100 reposts, I will publish a step-by-step playbook for SRs transitioning from audit contests to BBPs and how to succeed in it.
The only AI that actually helps me in the audit process is DeepWiki.
I consider it one of the most underrated AI tools for any security researcher. Here’s how I’ve been using it 👇
Rewarded for 2 Critical vulnerabilities on @HackenProof!
This marks my very first big step into Web3 security.
Happy hacking — more to come! 🛡️✨
#hackenproofed#bugbounty
Just wrote down my full audit process.
Really helpful exercise. It forced me to put into words my ideal approach to a new codebase based on mistakes I've made from past contests.
It's not a rigid checklist since ever codebase is different, but more of a task list that keeps me focused and thorough.
Published it on GitHub if it helps others too.
Link in comments 👇
All web3 security researchers should read this
10/10 report on all web3 security incidents in 2024 and stats around them. Great job by @ChainLight_io. Read below👇
https://t.co/rxtn8n4dQO
Lessons from hitting 5x Top 3 finishes in contests at @cantinaxyz 🔥
Dropping the alpha that moved my rank to top 50s and achieved 5x top 3 finishes at Cantina - zero fluff, pure trenches-tested insights that actually work 💯
Thread 🧵👇
Here's how you can audit any type of proof checking contract in 1 minute:
1. Go to the test with the generated root, leaf and proof;
2. Change 1 hex character of one of the elements of the proof;
3. If the test passes you found a crit