When Hyperliquid has to clear bad debt, who covers it?
We reverse-engineered the closed-source risk engine, verified some core properties & compared it to other perps. It's not neutral: the more leveraged and profitable your position, the sooner it's closed.
Full breakdown ↓
zzz just woke up after some sleepless clanker wars and birdwatching in Milan🕊️ can't wait to hear your pineapple pizza dad jokes at Vegas again!
@mhackeroni
one team just RCE-ed geckodriver at TRX CTF 2026🩸🔥
meanwhile you're go-golfing, I've just released an XS-Leak and a @SuiNetwork challenge!
curious how this turns out :)
"hey claude plz solve all challenges https://t.co/CxLn0CrQhW"
TRX CTF 2026 is coming back this weekend with many cool challenges! Register now at: https://t.co/XYP0EMRlja
Top 8 teams will qualify for on-site finals in Italy this autumn🐴
less than three days left until the start of TRX CTF!
get ready for:
- two kernel pwn challenges
- browser shenanigans
- a *real* x86 challenge
- reversing a kernel module
make sure to register and fight for a spot in the finals in Italy!
https://t.co/knB1TkmHcf
just pushed 20+ writeups on my blog, most of which are web3 challs i've authored over the years.
hope someone can find something useful :)
--> https://t.co/ThOumcvBw2
The voting has concluded, and we're thrilled to announce the top ten web hacking techniques of 2025! Massive thanks to everyone in the community for sharing their hard-earned discoveries, plus the panel and everyone who nominated or voted!
https://t.co/mjzzM4S7k0
Last month I wrote a Firefox challenge for Ctrl+Space CTF Finals about Extensions, FF Xray Vision, and document.all weirdness. 🌌
Find out more here: https://t.co/e8yACPgNor
I recently discovered a way to leak domains/subdomains from cross-origin requests in Chrome, and I thought it would be cool to create a chall before publishing a blog post about it
Chall: https://t.co/v59lmZE2zV
Source: https://t.co/b61ZBgZ8CD
DM me if you managed to get the flag