Things to not vibe code :
- Security
- Cryptography
- Smart contracts
- Wallets
The cost could be millions and billions paid by your clients and users.
Few weeks ago, I found a vulnerability that allows me to use all models for free thru a vulnerable endpoint, anthropic team closed it as informative, today I was checking if the vulnerability still works with fable 5, turns out they patched it silently, shame on you.
#hackerone
Almost every bug I report is on a code base audited by "top firms".
Some were math issues in code written and reviewed by BigTech alumni with PhDs in cryptography from Stanford/Ivy-League.
Everyone misses bugs. I miss too. AI misses bugs.
Let's stop talking about finding bugs missed by lots of experts as something new and unheard of.
It's so common I've been making a living off of it for 5 years straight.
I'm not the only one.
1/ New post alert! ⏰
Is onchain ZK PQ-ready? Round two of putting WHIR on Ethereum gave us an inconvenient result: small fields shrink proofs but make them challenging to verify. We rebuilt WHIR verifier over a 31-bit KoalaBear field and measured where the gas goes.
https://t.co/xFjBJtKK1n 🧵
First white-hat exploit on Ethereum: I unlocked 1,003.62
Ξ ($2,000,000) trapped in a 2016 ICO smart contract
for 9 years.
The 48 original investors can now claim their funds.
🚨 JUST IN:
@gravity_bridge appears to have been exploited for ~$5.4M.
Gravity Bridge connects Ethereum assets with the Cosmos ecosystem.
Root cause: compromised bridge contract key or signing/authorization path.
Another cross-chain bridge. Another key compromise.
"All of DeFi is unsafe" is going around today.
AI did not invent new bug classes. It mass-produces the old ones.
Reentrancy, access control, broken assumptions. Same bugs, shipped faster and with more confidence.
Real audits are the only way to catch them.
We built a real-world OpenAC implementation for privacy-preserving proof of personhood.
It uses an existing government-issued credential, proves eligibility in zero knowledge, supports revocation checks, and runs the proof flow on mobile devices.
Check threads for links and summary 🔗
“CLAUDE I’VE EXPLAINED THIS BUG TO YOU 10 TIMES AND YOU STILL KEEP BREAKING IT, THINK LIKE A SOFTWARE ENGINEER WITH 15 YEARS OF EXPERIENCE AND FIX IT PROPERLY MAKE NO MISTAKES”