Introducing Claude Code Security, now in limited research preview.
It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss.
Learn more: https://t.co/n4SZ9EIklG
Thank you @ethereumfndn team for supporting our work 🙌
Its very important to have security frameworks in place for over all security of Smart Contracts!
Aerodrome and Velodrome front-ends getting compromised today is another reminder of something we don’t talk about enough:
Most users interact with DeFi through the front-end, not the contract.
You can have perfectly audited smart contracts…
and still lose user funds if:
• DNS gets hijacked
• Build pipelines are compromised
• An injected script swaps wallet destinations
• A dependency update introduces malicious code
In Web3, the most secure part of the stack is often the smart contract.
The least secure is the thing users actually touch.
Maybe the real conversation isn’t "audit the contracts."
It’s:
How do we bring enterprise-grade security to front-ends, pipelines, and hosting?
Curious: How many teams here treat their front-end like a critical security asset, not just UI/UX?
#Security #Web3 #FrontEndRisk
AI tools miss subtle smart contract bugs or overwhelm auditors with false positives.
@cyberboyIndia, CEO of @CredShields, will speak at DSS about enhancing LLMs with dependency-aware context and auditor-labeled data to uncover complex vulnerabilities and scale Web3 security.
We’re expanding AppSec to Web3.
Proud to join @Checkmarx, trusted by hundreds of global enterprises, as their Web3 security technology partner, powering the next chapter of enterprise AppSec through CredShields.
https://t.co/I3Bm143Je5
Enterprises are accelerating into Web3. Security must keep pace.
We partnered with @CredShields to expand Checkmarx’s AppSec leadership into decentralized ecosystems, giving customers confidence to innovate across smart contracts and dApps.
Learn more about our partnership: https://t.co/2kygFjaSxQ
Happy to announce that @CredShields building @SolidityScan has partnered with @Checkmarx
Together, CredShields and Checkmarx are empowering customers to confidently innovate across smart contracts, dApps, and entire blockchain ecosystems backed by industry-leading automation and intelligence via SolidityScan, our AI-powered Smart Contract Vulnerability Scanner!
Crypto market surges to $4.2T, with BTC hitting $125,500 and ETH topping $4,600. Stablecoin cap exceeds $300B. CFTC’s tokenized collateral push signals regulatory progress.
https://t.co/WZShpylgby
Smart contract hacks drained over $1.5B in 2023. Manual audits aren't able to keep up with hundreds of thousands of contract audits required every year.
@cyberboyIndia, founder of @CredShields showed how AI-driven analysis changes the game:
1) Contextual analysis of contract behavior → fewer false positives
2) Role-based access control modeling → understands nuanced permissions
3) Continuous learning from exploits → gets smarter over time
Grateful to the bug bounty community Started with zero coding knowledge, learned along the way through bug hunting. I don’t do it regularly, but whenever I do, I end up finding impactful bugs. Crossed $100k in bounties on @Hacker0x01#bugbounty
CERT-In has developed & issued Comprehensive Cyber Security Audit Policy Guidelines to provide a structured, standardized, and practical framework for conducting effective cyber security audits across organizations.
https://t.co/P7EWlRJ2w7
To all Blockchain Companies. Your private key gets compromised with such similar attempts. Below are the simple key things you can follow.
1. When someone asks you to hop on a call and send you a link. Go to https://t.co/u8IXSENNCK and check if the domain has been recently registered. Any recently registered domain won't be a trusted source.
2. Also keep an eye if that Zoom link is actually Zoom and not a typosquatted domain like zoo0m[.]com
3. If someone asks you to download an app. Go to https://t.co/kpVGUDqqnW and upload the file first.
These malware are malicious softwares that simply pull all your saved passwords, access your file system, and send the files to the hacker's server, access your camera , access what you type etc.
These malware are malicious softwares that simply pull all your saved passwords, access your file system, and send the files to the hacker's server, access your camera, access what you type, etc.
Stay safe and share the post with your team members.
Although there are regular malware encounters, but just came across a nice malware attempt. Sadly, the X user -> shaolasaba3 chose the wrong person to target.
1. Contacted me to hop on a podcast by @CoinDesk
2. The user (shaolasaba3) has 22k followers and past history of tweets so looked ledgit.
3. Has a Korean profile and asked me to join a Korean platform. [kakaoroom(.)com] - Suss begins.
4. Domain Whois record says registered 20 days ago lol
https://t.co/70FT4t5JP6
5. Scanned the binary file in VirusTotal.
2. The user (shaolasaba3) has 22k followers and a history of tweets, so it looked legit. 1902?nocache=1it a
The guy blocked me from everywhere.
🎙️AMA: Crowdsourced Security vs Automation — What Web3 Protection Looks Like in 2025
We’ll explore how AI-powered tools and crowdsourced security are shaping the future of Web3 protection — and what to prioritize if you're building on a budget.
Who should join:
- Bug bounty hunters
- Auditors & security researchers
- Web3 developers
- Project founders
📅 July 30
🕐 1:00 PM UTC | 6:30 PM IST
📍 Twitter Space
Speakers:
-@DmytroMatviiv , CEO HackenProof
- @cyberboyIndia , Co-Founder and CEO @CredShields
- @rish48 , Overseeing Growth at @CredShields
Don’t miss it — a special surprise awaits those who join us live 😉
💰 Finance runs fast. Cyber threats run faster.
That’s why we’re thrilled to welcome @Anuprita_Daga, Group CISO at AngelOne , to BSides Ahmedabad 0x6 as a CXO Speaker at the Finest Cyber Security Conference Around 🧠🔥
With deep roots in the BFSI industry, she’s bringing the kind of boardroom-to-SOC wisdom that every cyber leader needs to hear.
From scaling security to surviving real-world threats — this session is a must.
🎟️ Standard Sale is LIVE — book your pass now before they vanish!🔗https://t.co/SXQrWw5X6g
#BSidesAhmedabad #CXOSpeaker #AngelOne #CyberLeadership #Hacking #Cybersecurity #infosec
🎬 Millions stream. One secures it.
Meet Mohd. Shadab Siddiqui, CISO at JioHotStar, speaking at BSides Ahmedabad 0x6 as a CXO Speaker🎤🔥
From high-traffic streaming to high-stakes security — he's been in the trenches where scale meets threats.
🎟️ Standard Sale is LIVE — grab your pass before they vanish faster than a buffer-free stream!
🔗https://t.co/SXQrWw6uVO
#BSidesAhmedabad #CXOSpeaker #JioHotStar #CyberSecurity #Hacking #infosec #CommunityDriven
🚜 From tractors to threat intel — this keynote hits different.
We’re excited to welcome Carl Kubalsky, Director & Deputy CISO at @JohnDeere , as a keynote speaker at BSides Ahmedabad 0x06!
Carl brings real-world insights from the frontlines of industrial cybersecurity — protecting smart machines and critical infrastructure on a global scale 🌍🔐
🎤 This isn’t theory. It’s hands-on, high-impact cyber leadership.Don’t miss it!
🎟️ Standard Sale is ON — grab your pass NOW!➡️🔗https://t.co/SXQrWw6uVO
#BSidesAhmedabad #CyberSecurity #CISO #Keynote #Hacking #infosec