1/8
We're hiring for technical and sales roles!
1. Blockchain Security Engineers (multiple)
2. Business Development Engineer
Here’s a bit about what working at ChainSecurity looks like.👇🧵
The ETHSecurity badge distribution from @thedaofund is finished.
7 ChainSecurity auditors earned their place.
@hritzdorf co-uncovered issues that delayed Constantinople and shaped Istanbul & Berlin hard forks. 100+ protocols audited since 2017. Designed ChainSecurity's deployment validation framework. 13 academic papers on blockchain & cloud security.
@a_permenev co-authored Securify and VerX, two foundational smart contract analysis tools. 3rd & 4th place at Paradigm CTF (2021, 2022).
@k_besic introduced read-only reentrancy as a vulnerability class. Lead auditor for @enzymefinance. Co-led the disclosure that protected $100M+ across Curve, MakerDAO, Enzyme, Abracadabra, TribeDAO, Opyn.
@trooocher reported 100+ bugs in the Vyper compiler. Lead auditor for @CurveFinance. Helped push ChainSecurity to #5 on the Ethereum Execution Layer Bug Bounty leaderboard.
Dominic Brütsch is auditing at ChainSecurity since 2018, before DeFi existed. Lead auditor for @SkyEcosystem. Found a bug in Geth, earning a spot on the Ethereum Foundation Bug Bounty leaderboard.
@simon_perriard is ChainSecurity's ZK lead. Found a bug in the Solidity compiler. Disclosed critical soundness bugs in EY's Nightfall V3 circuits and served as lead auditor in top-tier DeFi projects.
@MatthiasEgli co-disclosed vulnerabilities in the Ethereum protocol itself and oversees all our audits as Managing Director.
TheDAO's mission is to make Ethereum safer. ETHSecurity is how they vet the researchers capable of contributing to that work. Congrats to everyone who made it on this epic list.
We made people eat bugs at Devconnect Buenos Aires. Check the first comment to see who’s in the video & vote for the best reaction.
🏆 Winner gets a lifetime bug supply + a printed copy of the EF mandate.
PS: This is not an April's fools, we're completely serious.
EF Mandate reading by @chain_security was AN EXPERIENCE
s/o to @EmilieRaffo and the team for putting this together!
this kind of stuff happen only at @EthCC or @EFDevcon
someone just swapped $50m for $36k on cowswap through aave's frontend, effectively losing 50m
if you try to make this swap on llamaswap the UI won't let you at all, buttons get locked
we've spent years building a price API with the highest coverage of defi tokens to avoid this
9/13
What to do if you find a malicious ad:
- Report via https://t.co/R6CD4V4gEX
- Collect screenshots + landing URL
- Escalate through Google’s abuse form with your official domain via https://t.co/w6miW2jqDz
- Warn your community
🇨🇭Just discovered that the fastest crypto-native way of paying CHF bills is this:
- Buying ZCHF on @CurveFinance;
- Sending those to @mtpelerin;
- Paying CHF from there, conversion is 1:1!
Powered by our FX pools apparently
Inaccurate gas estimates on @ton_blockchain can lead to critical security issues. 🛡️
Today, our TON specialists share the knowledge gained from vulnerabilities uncovered during recent DeFi audits.
Dive into the technical details: https://t.co/7xup9Z6lab
Briefly checked this one. Still not everything clear to me, and @yearnfi team told that the official post-mortem is still to be made only after they understand everything.
But two takeaways for buidlers:
- Be careful with unsafe math. It's unsafe unless you proved it is safe;
- Fuzz, fuzz, fuzz. Don't trust yourself and fuzz again.
🧵Hola Buenos Aires! ChainSecurity is in town for @EFDevcon & @partyactionppl 🇦🇷
From talks, panels, MC duties, and community events,
here’s your full chronological guide to where you can catch our team 👇