Been getting lots of DMs lately: "How do I break into web3 security?"
I've dropped 4 detailed threads on my exact path.
Not the most perfect roadmap. Not the most updated.
Just what actually worked for me.
Take what resonates. Leave the rest.
Here's where to start 👇
These 3 blogs will make you DANGAREOUS in Web3.
If you are a dev or auditor and actually trying to level up - stop scrolling and start reading:
1. https://t.co/ajrs7kGiYX
2. https://t.co/QJeOZqJdcP
3. https://t.co/1X9bMvQwzl
Read with intent. Crazy content ✌️
If I were starting blockchain security from scratch, here’s the roadmap I’d follow.
I wasted a lot of time early on because I didn’t know where to begin or what actually mattered.
If I could start over, I’d do things in this order:
Want to get into web3 security and don’t know where to start?
I started getting this question more and more again, and I'm guessing there’s a new wave of learners, which is awesome.
So for whoever doesn’t know I wrote this exactly for these cases 🫡
https://t.co/QQDC3CCDdn
🚀 Want to break into cybersecurity but don’t have job experience? Read this. 🧵👇
Everyone says “build a home lab” or “practice on TryHackMe,” but these may not translate to the real-world experience hiring managers are looking for.
What if you could gain cybersecurity experience, add it to your resume, and stand out - without needing a security job first?
Here are 7 unconventional, resume-ready cybersecurity experiences you can start today. 🔥
2/
After that, jump straight into competitive audits. https://t.co/4nyFp2YBn0 has a solid rundown of contests going on.
Prep yourself to suck hard — it’s fine. Keep your expectations low, humble yourself, and go in curious.
This is where you get a real taste of projects & blockchain in action. Pick a contest and get hands-on:
i) Read the docs
ii) Listen to podcasts or interviews with founders
iii) Send transactions if the protocol is deployed and debug with Tenderly
iv) Figure out how to read data on block explorers like Etherscan (https://t.co/1OkZ8Oatrq)
v) Check Solodit for bugs (https://t.co/pdrcieYWrN)
vi) use AI tools to speed up the understanding of user flows https://t.co/uH60lmpszT
Just found a GOLDMINE for ZK security researchers🔥
A Github repository containing close to 100 security vulnerabilities related to zero-knowledge proofs. Whenever you do ZK audits, make sure to go through those🫡
https://t.co/UNYL7oPM4q
The top blogs that I recommend to all aspiring web3 security researchers:
- https://t.co/V7qH5XBJF2
- https://t.co/aCnnNKoyhH
- https://t.co/uHcknfUG2N
- https://t.co/V5rWRPg52S
Thank me later! 🫡
If you are a Solidity dev or a Junior-Mid auditor, make sure you pay attention here.✍️
Must-know contracts:
Token contracts: The most used token standards are EIP20 for fungible tokens, and EIP721 for NFTs.
Proxies: There are many different proxy implementations, have a look at the OpenZeppelin Upgradable Proxies.
MasterChef contract: A staking contract by SushiSwap where users deposit LP tokens and receive rewards.
Compound: A must-know protocol if you want to have solid knowledge of Lending/Borrowing codebases.
UniswapV2: The basis for understanding automated market makers (AMMs) in general. You should also understand how LP tokens work.
Here’s one of my preferred sources for staying updated:
I’ve been reading it for 2 years now!
It’s a weekly, independent newsletter covering the latest security news, tools, events, vulnerabilities, and threats in the cryptocurrency space.
Link: https://t.co/f8Xi8q5qG8
January marks the anniversary of my X account.
I am sure that there will be lots of newcomers right around this time. Let me help all of you, as me personally I lost 6 months doing what I should have done in 1.
📌📌📌
Here is a step by step what to do in order to get into contest as fast as possible.
1. Open https://t.co/Qbarn6ri9E and do blockchain basics and the solidity path.
2. Watch both parts of @0xOwenThurm videos about advanced web3 security
- https://t.co/3lwqRTRNJ7
- https://t.co/oeFxoyVil4
3. Do @1nf0s3cpt's supreme resource https://t.co/iLjldgh3GM
4. Whenever you've done 1-3, just jump straight into contest, try something that is around 100-600 nsloc
Don't think about it a lot just jump in, and start accruing hours of practice.
Have fun y'all, web3 is the place to be. ✌️
Conducting more than 15 Solana audits , Many asked about Security roadmap🦀
This is your guide to leveling up your skills, starting from the basics of Rust to becoming a Solana security expert. You will be prepared for contests and private audits where you can start making money.
Here are the fundamental resources you should go through before starting your Rust Smart Contract auditing journey:
1. https://t.co/ZQSl1DjTyP
2. https://t.co/9Rmf9c9QvZ
3. https://t.co/WyzrZD60KL
4. https://t.co/huGqRxYUPv
5. https://t.co/ctnNo5geBK
Every time when you find vulnerability, you get all excited and feel like on the top of the world.
Now comes part 2: 👇
How to rank this vulnerability's severity?
First when I started I thought everything was a critical 😅, but that's not always the case.
Here is a great video by @0xOwenThurm that pinpoints exactly how you can determine a bug's severity.
This will be a great help in your future contests and private engagements. ✌️
https://t.co/x9cn7UE9HX