4/ The SDK also handles a lot of the tasks.
You give it prices/sizes.
The SDK handles things like:
→ batching
→ transaction construction
→ signing
→ submission
→ sequence counters
→ blockhash/slot tracking
That's a LOT of infrastructure you don't have to reinvent.
I started looking into @flint_trade_ from a security perspective.
I wanted to understand how it is better for a market maker.
And while going through the architecture + quoting system, I found some things that genuinely caught my attention.
🧵👇
If you are reading this, I wish you get a valid, non-duplicated Critical on a web3 bug bounty platform this month
You never know how close you are to success, keep going🫡
New security audit report published for @hyperlendx
6 days audit of their Leverage Lending logic.
Only 5 Low severity issues found, clean codebase.
Read the report below 👇
https://t.co/Fli8oW4oi6
Most engineering teams are getting AI wrong.🤖
Some teams avoid it and fall behind on costs, while others use it excessively, resulting in code with security flaws.
Last month, 35 new vulnerabilities were traced back to AI tools.
🧵
Three new queries approved.
@KupiaSecurity flags missing access control on onERC1155Received, allowing unauthorized contracts to handle ERC1155 token callbacks.
@dev_razkky flags accounting logic that ignores fee-on-transfer tokens, causing balance discrepancies and potential fund loss.
@xSuiMove flags unsafe type casting that can silently corrupt values when types are incompatible or overflow during conversion.
Queries below:
Moniepoint works with an offline-based architecture model. I wrote an article on this.
So whenever your internet becomes very poor, let’s say from 5G down to Edge, it switches to an offline-based architecture.
Advantage of this? Wider coverage, even in areas with terrible network connectivity.
As for OPay, its main selling point was its switch payment flow.
Both lines above already answer everything.
You guys don’t really engage with my articles by reading them. I’ve written really solid technical articles.
Well, I’m dropping another one soon.
Coming back to the “What’s the biggest thing bug bounties gave you?” Question,
Money aside, BB taught me the art of not giving up and the art of not giving a fuck. Hunting for bugs has been a spiritual journey more than anything else...
If you are in the beginning of your journey, you probably see other people making it big. Making big dollars like @Ehsan1579. You sit there and ask yourself just “How”. What do they have that I don’t? As rejections roll out and your reports get closed one after the other one, all you ever feel like is giving up.
You might feel defeated, unsatisfied, all the small chatter in your head is telling you to give up… But your EGO won’t let you. EGO isn’t all bad, as society likes to condemn it. I’d go as far as to say that ego is the key ingredient in an industry as cut-throat as BB.
In moments like these, your family, your friends and whoever you consider close will try to tell you that maybe it’s just not for you.
Solution? -> cut everyone. Don’t let anyone get to you and put your head down, analyze what is going wrong, how to get better and try new strategies. That’s the only difference between the ones who make it and the ones who don’t.
Do not take “no” for an answer. If a project closes your report but you know you are right, make sure you are right and then ask for mediation with all the facts you have. You’d be surprised how many projects close valid in-scope issues. Same thing applies if they try to reduce the severity or pay you “peanuts” for what it’s worth.
I’ve been working in DEFI for years now, learning the ropes, building projects. All of them were a fluke until I tried Immunefi. I worked every waking minute for 8 months straight without any payout.
Then… in September I got my first bug confirmed. A “Low” for $2000. I was ecstatic, I was excited. For literally 3 days, I was listening to music just staring and the “Confirmed” ticket.
You see bug bounty is a bit like the casino, the difference is instead of betting money, you bet time (sometimes it does cost money too) and the payouts hit like a truck and you never quite expect it fully.
It’s like a drug. And like a drug, you want more of it and you soon become accustomed to a certain level (“the tolerance”). They say you always chase the first high and it’s very true for bug bounty as well.
The months following I was finally averaging at least 1 paid report per month. That was until January. I’ll never forget it, I had 9 confirmed reports in a row. The “High” hit soooo strongly. But with every high comes a low. Doubts cripple in, you start rationalizing it. You tell yourself that “I just got lucky”. The bug Immunefi posted on their page was from January.
This cycle repeats endlessly. Turns out that February was an even better month for me. The thrill of the unknown and the unexpected is what makes it fun. I do not think I would be doing this if you took that out of the picture.
It was a journey, a very difficult one I’d might add. But in the end, it was worth it. It built me into a stronger more resilient person. It thought me patience.
Reports being closed hurt. Probably one of the worst types of rejection out there. But at some point in time you get used to it and have to learn how to detach yourself from the emotions and trust the process. It’s a numbers game after all.
I am waiting for the leaderboard to update now (long due)! I’m curious to see if I finally made it into the top 100 of whitehats of all times. (Currently sitting at $175k in earnings from 22 reports)
It’s all just a matter of time after all (;
I think in the next couple years we’re going to see a lot of outages and cyber attacks across systems.
The reason is obvious.
People with zero code-level understanding are building things they don’t fully understand and shipping them.
Instead of starting small and doing it properly, you jump straight from “I made a simple site with AI” to building a full backend and frontend app then come online to say you’ve built and shipped.
Built what exactly?
You don’t understand how the system works.
You don’t understand security.
You don’t even know where it can break.
That’s how vulnerable your systems would be, it’s a ticking time bomb Dw.
Well, There’s a popular saying, “Time will tell”.
and it will.
At the very least, know the basics.
Understand how things work before you start shipping things people will depend on.
Most people think Web3 security is just about smart contract audits.
Mitchell Amador, CEO of Immunefi reveals why that thinking leaves billions on the table.