4 reports have now been confirmed in the @QuantusNetwork audit competition:
• 2 Critical
• 2 High
The competition covers ~70,000 executable lines. The previous figure included docs, tests and libraries.
11 days still to run; get hunting!
https://t.co/sfEX8gxeqS
“Security researchers are doomed because of AI.”
I kept hearing versions of this, so I went back through 500 years of people saying the same thing every time a machine learned a human skill.
Some were idiots.
Some were right.
Here’s where I landed. https://t.co/ghFe7ONlOi
We announced one audit competition this morning, but it doesn't stop there.
Two more are on the way!
For every security researcher who locked in this summer, it’s time to put everything you learned to the test.
Our gift to you for the final month of SR Summer.
As of today, BattleChain testnet is LIVE.
The pre-mainnet, post-testnet blockchain, where whitehats legally attack your smart contracts before they reach production.
Deploy. Get attacked. Ship stronger.
Here's why we built it, what it is, and how you can get involved 🧵
My main takeaway from the recent rounding hacks is that every incorrect rounding needs to be considered a bug
Most of them are not exploitable, or not even vulnerabilities, but they are still bugs
Think of it as: bug → vulnerability → exploit. Every exploit starts from a vulnerability, and every vulnerability starts from a bug. Exploitability of rounding is often tricky because it depends on the system’s conditions, which will evolve
The relation between bugs and exploitability is more common in web2, but we don’t see it as often in web3
The nuance means that:
- If you develop a protocol, you need to be explicit about every rounding decision (cover all bugs)
- If you do a code review, you need to flag every incorrect rounding that can have a security impact (cover all vulnerabilities)
- If you do a bug bounty or contest, you need to focus on exploitable rounding (cover all exploits)
For code reviews: flagging every rounding doesn’t mean creating 100 issues; you can create one issue listing similar risks. But you do need to raise awareness of the risks
For bug bounties/contests: I wouldn’t be surprised to see future exploits that combine multiple rounding or other vulnerabilities (as we often see in web2). It’s something to keep in mind
In June, a @Polymarket bet was created for whether a single $100m hack would occur in 2025.
That bet is over.
Security is standing in the way of trillions coming onchain.
Everything takes time
> I didn't start my first contest with a major payout. First few months were 10-100 USD payout only, most were just 0
> I didn't start finding bugs left and right
> I didn't start auditing being able to look at the screen for 2-3 hours strait (and sometimes I still can't do it)
> I didn't start with 3k X followers.
Trust the grind, slowly all of the pieces will fall into their place.
The path demands effort and patience. More effort than your body wanted to give, and more patience than your soul was ready for.
dude
if i stepped back into the contests circuit today, i’d put in hours to sweep every prize available.
web3 competitions have become painfully rewarding lately (with rare exceptions)—most winners today are only putting in weeks of work but making 6 figures or more with the huge pots available
but instead, this year most of you are doubling down on private audits and not finding cool bugs at @cantinaxyz
not ego, just facts.
accelerate.