๐งต1) Spent time this weekend on understanding of low level solidity and evm. Was refreshing to read and brush up internal workings.
Resources linked:
How does ethereum contract creation works internally by @RareSkills_io https://t.co/7fldRvRf6n
Web3 security firms are getting carried away with their AI claims ๐งต
Firms are falling over each other to announce AI breakthroughs โ some even going as far as saying their agent outperforms their own researchers. Bold claim.
Yet not a single one has released their model for public testing. Funny how that works.
What makes it stranger โ these same founders charging $130k for a 14-day audit are now offering free AI pre-audits. Suddenly so generous ๐ค
Here's the thing though, none of these companies have poached a senior AI researcher from Anthropic or OpenAI. These are security researchers who've fine-tuned frontier models on mostly public audit data. Respectable work, but let's not overstate what it is, because everyone is building on the same foundation:
โ Same frontier models (Claude, GPT-4o, Gemini)
โ Same public vulnerability datasets
โ No proprietary data moat
โ No dedicated AI infrastructure advantage
So if everyone has the same ingredients, why are some founders acting like they've invented fire? The gap between any two firms here is a few weeks at best.
And the context matters here โ the web3 security industry is under real pressure right now. Firms that used to rely on a pool of contract researchers to handle overflow are now getting by with just their core staff.
Clients have caught on, rates are being pushed down, and firms are quietly doing more with less.
So when you see these AI announcements, ask the one question nobody wants to answer โ where are the benchmarks? Where is the model? If it's already free, why not release it?
Until then, please go easy on your AI ๐ซก
Too many programmers waste time bouncing from one study subject to another.
They fear that what they are studying currently is not "optimal."
A less charitable interpretation is that most people cannot focus...
...but I don't think this is the correct diagnosis for many people.
The space of subjects to study is massive, but time is limited.
Therefore, the "fear of misplaced priorities" is reasonable.
Here's what I have to say:
Bouncing from one subject to another is unquestionably less optimal than picking the "wrong" subject and sticking to it for at least a month.
The more you know, the easier it is to pick up other subjects as they "feel related" to something you already know.
So don't worry if you "study the wrong subject."
Two years from now, it might be the key that makes the right opportunity easy to learn.
- Compilers will make you better at leetcode
- Operating systems will make you better at blockchains
- ZK will make you better at quantum computing
Math will make you better at machine learning
Plus, the more deeply you study more subjects, the better intuition you will have for what the "right subject is."
Without that grounding, you are liable to being swayed by tech influencers who are optimizing for their engagement rather than your well-being.
Being a generalist doesn't mean watching 3 hours of content on a lot of subjects.
It means having the ability and prerequisites to go deep into an arbitrary subject on command.
You can only grow that skill by going deep several times, which only comes through sustained focus.
Too many people study a subject until they hit the worst part of the Dunning-Kruger curve, then move on to the next subject. Such a study habit is very destructive.
Great writeup on setting proper liquidation threshold and liquidation bonus for lending protocol to ensure no bad debt is created https://t.co/ws3iZsdcD5
Another one on spectrum of Health factor and position's recovery based on HF
https://t.co/F9grmE8dKC
h/t @S3v3ru5_
Phylax just blocked its first live exploit attempt on Linea.
An external integration misconfiguration caused some wallets to approve a 0x Settler address directly. Working with @0xProject, we deployed a targeted mitigation...
and the first drain attempt was stopped!
Read on
@BautiDeFi@0xjuaan Then it makes sense. But he has written as "Your funds are effectively being moved out of the unsafe vault, and into one of it's safer underlying markets, via our vault.".
How does the funds move to safer underlying markets? It doesn't makes sense to me
@0xjuaan How does accounting of total assets of Obsidian vaults happen? Since liquidity supplied to affected markets can't be considered, won't you just be giving shares to the user who didn't contributed anything to obsidian vault? Maybe I am missing something here.
Is there any detailed articles comparing slippage of Uniswapv2 vs curve V1 and how the dynamics changes based on the reserves in the pool?
Any blogs, resources or papers?
I Saved Injective's $500M. They Pay Me $50K.
I like hunting bugs on @immunefi . I'm decent at it.
- #1 โ Attackathon | Stacks
- #2 โ Attackathon | Stacks II
- #1 โ Attackathon | XRPL Lending Protocol
- 1 Critical and 1 High from bug bounties (not counting this one)
Life was good. Then I found a Critical vulnerability in @injective .
This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk.
I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity.
Then โ silence. For 3 months. No follow up. No technical discussion. Nothing.
A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either.
I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten.
I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible โ until Injective pays what I deserve.
Full Technical Report: https://t.co/lki2tL9bxw