Participating in web3 bounty/Audit, check out these past reports which helps you learn new ways
@immunefi - https://t.co/PUYNt0yjyc
@code4rena - https://t.co/TRfuDuZS9a
@TheSecureum - https://t.co/sw266Da2mx & https://t.co/cmH7AdIgxx
@sherlockdefi - https://t.co/MGFgZOMybr
A look at the tricks used by @samczsun and the contract that beat him:
- tiny handcoded EVM-level contract, no Solidity
- no function selector (a single function implements both owner() and solve() based on calldatasize 🤯)
- no storage
- optimal memory size (3 words)
Getting ready for @paradigm_ctf tonight.
Final setup repo includes mocks of common tokens, automatic forking in testing environment, OZ preinstalled, and a bash script for pushing completed exploits live.
For anyone else competing, my gift to you...
https://t.co/MUiXkIqHjg
Rent Thief:
1/ An MEV bot has been stealing rent from @solendprotocol by abusing the account initialization process.
This is the story of the curious rent thief ; 🧵
We have collaborated with @NotifiNetwork to provide security alerts in the event of hacks and more!
Simply connect your wallet to Notifi and messaging platform of choice, and opt-in for security alerts to get updates via telegram and other platforms!
1/?
quick analysis of the @CurveFinance
malicious contract address = 0x9Eb5F8e83359Bb5013f3D8eee60bDCe5654e8881
JavaScript code injected on home page here: curve[.]fi/js/app.ca2e5d81.js
@Mudit__Gupta@officer_secret@samczsun
Found a random MEV bot just browsing on etherscan today, and decompiled it's bytecode, just to find it's 1000+ LOC oof 😭 wth who writes these
[https://t.co/FEBOiIFOxu]
As Jet v2 goes live on mainnet today, we are proud to announce the completion of our audit!
We were very impressed by their attention to detail and commitment to security.
Learn more here:
DeFi Attack | Our monitoring system reported that EGD_Finance was attacked (https://t.co/pVD8TekZZB), and the loss is around 36,044 USDT.
This is a typical price manipulation attack.
#DeFi#BSC#CryptoSecurity
https://t.co/tXWRabC4kD
Another day, another setApprovalForAll scam. How to end this epidemic has been a hot topic lately. M*tamask UI upgrade, Revoke extension, on and on, all tenable. And yet, Clawd lost $700k+ worth of apes yesterday.
I'm here to propose one more solution. 1/🧵