🚀 Launching first beta release of the Auditor-Toolbox - Your all-in-one solution for auditing tools!
🔧 Public repo with diverse tools & one-click installs.
📚 Read about it:
Preferably here: https://t.co/hFan0SdT2o
💻 Dive into the code & contribute: https://t.co/oXhk3iNuMS
@m4rio_eth Have you tried gandalf lakera ctf like for prompt injection? 20 min run, pretty fun to break the security. They also have other versions harder
https://t.co/eQrItqoQuD
Amazed by the attacks happening in the space. Good to have learned about CPIMP backdoor attack. Due to this, always ensure that your proxy deployment + initialization happens in one transaction.
https://t.co/3fyVDtcefo (h/t @Deivitto )
Video from DSS https://t.co/WTPsDCKnua
34 Auditing Tips to crush it in 2026
- Think in bets
- Constraint behaviour
- If it's hard for you it's hard for everyone
- Seek truth
- Understand it first, then break it
- Building is harder than breaking
- Tools are substitutes for thinking
- A fully understood Low is better than an untested fix
- If it's not tested, it's broken
- AI is a brainstorming tool
- Work with Progressive Escalation
- Understand the meaning of being average
- Formally verify stateless libraries to extract constraints
- There are no easy paths, you have to get better
- Understand when to clamp and when not to
- Rewrite it your way and compare notes
- Peak experiences are like a wave.
- Most Contest winners have a brutal track record
- There's no rush in writing a report and POC
- it's always a very serious deal or just don't bother
- Start with the end in mind
- Read the code until you can't anymore, then try something else
- You don't understand the intensity of reviewing code, until you've seen it
- If you're done before the end of the engagement, you're probably wrong
- Understand your edge and use it to your advantage
- There is no overnight success, only the world catching up to you
- The path to mastery is simple, do the thing with 100% of intention, review the results, learn
- Model people that inspire you
- Forge your own path
- Read about common bugs
- Create your own category defining bugs
- Resting is work
- Be careful about your own biases
- The only constant is you
@drdr_zz@0xGianfranco Yes, it's pretty smart. I also find interesting the fact that it avoids being left outside of an update, so you cant remove it
The fix at the end is the one we always took into account for frontrunning initializations + being more aware of an initialization result.
Got nerd-sniped this morning by the USPD CPIMP incident with @0xGianfranco, so I turned our rabbit hole conversation into a write-up
🧬 how CPIMP sneaks a proxy in the middle of your proxy
👁 how Etherscan UX can trick you
🔗https://t.co/z3mUZVw1at
@YSmaragdakis@dedaub@summit_defi Now link to the medium post too: https://t.co/pTkPZcF3Ff
Link to the hackmd analysis: https://t.co/z3mUZVvtkV
Link to the @USPD_io exploit announcement: https://t.co/Y5IcMbHzRE:
🚨 URGENT SECURITY ALERT: USPD PROTOCOL EXPLOIT 🚨
1/ We have confirmed a critical exploit of the USPD protocol resulting in unauthorized minting and liquidity draining.
Please DO NOT buy USPD. Revoke all approvals immediately.
@Deivitto@0xGianfranco 15 hours is all it's taken since I sent a link to the hack announcement tweet on our group chat to having a comprehensive technical write-up 😂😂😂
@PaulRBerg@GalloDaSballo Looks great. It feels like the next step of using symlinks + bash scripts that i used to interact with github.
Just because of the huge amount of options you have there are more commands that I would remember to have