Want to take part in the $53,440 Sablier competition? 🚀
Check out the recorded code walkthrough on the Cyfrin YouTube channel:
- Dive into the codebase
- Step-by-step signup
- Submissions guidelines
When?
Premiering Now!
(1/2)
With @chainlink oracles being one of the most widely used oracle networks in the space.
Make sure to add this to your reading recourse list this weekend. Thanks, @DevDacian for the breakdown. 🫡
https://t.co/lXDeXL98xK
Just finished a contest & I'm jumping straight into the next one.
I think I'm getting quite good at understanding protocols at a deeper level !
💣It's the second time in a row that I experience the following:
At 70% of contest duration I stop looking for bugs, because I don't have enough time to submit the ones I've already found ( explanations, POC, recommendations etc.)
And I'm not talking about fee-on-transfer, no-slippage and all the other superficial vulnerabilities we all know.
I'm talking about bugs that are tightly related to the logic flow of the particular protocol(the real bugs).
I feel that once you start getting deep enough, bugs start popping up like popcorn🍿. Finding one deeper nested bug unlocks something like a ⛓️chain reaction that leads to new ones.
And just when I think that I'm done and start validating and preparing my submissions, a plethora of really good questions come up that lead to new exploits.
Problem is that once I'm at the stage of submitting my findings, there is no time left to tackle these new opportunities.
P.S Since it's a recent experience that I'm having, contest results are not out yet to prove that I'm actually making quite the progress.
🎯But as far as my intuition goes, things feel VERY right
In 2024, we are going to witness TONS of projects built with Rust, and specifically Cosmwasm and Solana.
My favorites are those built on Injective and Kujira ecosystems. These two will be the DeFi hubs on Cosmos blockchains.
If you are security researcher, then you MUST start getting your hands dirty with Rust.
By just learning the fundamentals, you can then start diving into frameworks such as cosmwasm and anchor!
Till now, I have published two articles explaining in GREAT detail cosmwasm, while solving CTFs that address real-world scenarios.
I even encountered a similar issue, that I first found in the CTFs, in one of my recent Cosmwasm audits!
Grind away 👇👇
We've released over 50 new security assessment reports 🐞 📃 🎉
Targeting Solidity, Go, and Rust codebases, these security reviews have been conducted over the past 4 years for prominent projects (L1s, L2s, bridges, smart wallets, DeFi primitives, etc)
https://t.co/AOY9t137Ob
magicId=00192729301
Set-Cookie: SessionId=<sessionId.00192729301>
magicId=00192729302
Set-Cookie: SessionId=<sessionId.00192729302>
2023 and we still have these types of bugs lol
By the way, this is P1 In my books 🤓👆🏽
So proud to see some of the Smart Contract Hacking course students slowly climb the @code4rena leaderboard 🪜
If you are new to web3 security, keep grinding and never give up! Hard work pays off 💪
#ImmunefiSecurityAlert
1/ On July 11, an exploit on @Rodeo_Finance resulted in a loss of ~472 ETH, valued at roughly ~$890,000.
This was caused by what’s known as an oracle manipulation attack.
Let’s break this hack down in a human-readable format
👇
Today we celebrate 6 years of #Binance!
Thank you for your extraordinary support over the last 6 years and we can't wait for what lies ahead.
Here's a message from @cz_binance to all of you for #BinanceTurns6.