@zodattack Your analysis is thorough! Something you may also want to think about is the effort required to get a job. Even though new grads and mid level engineers are still being employed, applying to any job is a lost cause due to the quantity of ghost jobs and HR tactics companies employ
6/8 findings validated in @CodeHawks SNARKeling Treasure Hunt🔥
Highlights include broken double-spend protection, permanently blocked owner withdraw(), and plaintext PRIVATE_KEY in deployment script.
See my reports in my audit portfolio:
https://t.co/uhgpMpUckh
#Web3
Awards have been announced for First Flight #59: SNARKeling Treasure Hunt!🤝
Top 5:
🥇 copperbramble - 466 XP
🥈 virgilbb - 446.8 XP
🥉 webrainsec - 446 XP
🏅 fredo182 - 404 XP
🏅 lightpat - 344 XP
(1/2)
@CodeHawks Stoked to land in the Top 5 for @CodeHawks SNARKeling Treasure Hunt 🏅! Huge thanks to the team/judges. 6/8 findings validated and a ton of learning on this. I hope to use these skills on other competitive audits!
We’ve spent years teaching devs not to trust user input. Now we’re giving AI tools full read access to our machines and repos. This isn’t just a “nice-to-have” anymore.
Thread (4/4)
🚨 Quick PSA for any developer using AI:
DO NOT STORE YOUR SECRETS IN PLAINTEXT.
If you’re still dropping API keys, database credentials, or any sensitive secrets into a .env file… it’s time to stop.
Thread (1/4)
Even if that file is in .gitignore and never touches Git, anything in your .env is effectively public the moment you use any AI coding assistant that can see your local project files.
Thread (2/4)
Just shipped a production-grade overcollateralized stablecoin on Sepolia (Foundry tests + Chainlink oracles). Live interactive demo: https://t.co/6haQrLZSfe
@FACEITcs@FACEIT_Darwin I think there's an issue with not getting the match accept popup when queuing. I've missed queue 3 times in a row because I never got a dialogue to accept the match. Also it's happening to my friends on edge and chrome and brave browser