Design your surrounding, speak to the guys who are putting in the work, who dare to dream and achieve - it's the growth formula
Learn from the actions of winners, build on top of proven to work models & systems. Ignore others - they just don't know. Strategise your moves🫡
3 beliefs I hold that aren't necessarily true but are definitely useful:
• The codebase is never empty.
• One spot always needs another look.
• A clean week on a flow still counts.
I had six months of zero before my first win.
Then, a single week working on a Chainlink flow landed me the only Medium in the codebase, and a $10K payout.
None of those weeks was wasted.
If you don't progress in Web3 security,
Please do this:
Analyze the problem factors:
> Lack of domain knowledge
> Lack of audit practice
> Drowning in theory
Understand what stops you.
Then, choose the ecosystem:
> Solana
> Move (Sui / Aptos)
> Fuzzing
> FP
Set up your niche positioning.
Then, take the project type you'll work on:
> CLMM
> Lending
> Nodes
> VMs
Afterward, go deep into practice:
> Study all bugs/features of the project type
> Get your hands dirty
> Collaborate with other SRs
> Think about how to improve hunting with AI
> Preserve critical thinking for complex code
> Analyze the mistakes made
> Push results publicly
You don't need to study more; you need to practice more.
No matter how good AI models are, mediocre auditors will still produce mediocre work.
A lot of people are lazy. They blame everything instead of putting effort into proper learning.
They also won’t put in the effort to get the most out of AI.
going to say something i didn't want to admit for months. the first 6 months of learning smart contract security taught me less than the last 2 have.
for a while every course felt like real progress. i was learning things i genuinely needed to know. courses stacked. notes filled. and that foundation had to be built. no shortcut around it.
what i missed is that knowing more doesn't automatically translate into being able to do more. by month 6, i had the knowledge of an auditor and the abilities of a beginner. the two never quite met.
then something shifted. the last 2 months look nothing like the first 6.
i'm not where i want to be yet. but for the first time i can see the gap between me now and me 60 days ago. real change. not the comfortable feeling of doing familiar work and calling it growth.
the difference wasn't harder effort. it was flipping the ratio. maybe 20% learning, 80% doing. actually doing the practical work. tracing real findings on solodit. sitting with patterns until they clicked without help.
if you're a few months in and something feels off despite the hours you're putting in, do more of the actual work. more practical exercises. more findings on solodit. sit with real bugs until you understand them. you'll learn more inside the doing than any amount of consuming can teach you.
still trying to get better at this myself.
The more I think about it the more certain I am that “AI” intrinsically helps attackers more than defenders.
Attacking doesn’t require understanding. It’s about generating chaos.
Throwing a trillion plausible attack vectors at system can break it even without any understanding of how it works, or even if the attack succeeded.
To defend its not enough to have an attack vector. You need to understand that it broke the system, why it broke the system, and how to fix it.
Even if the “AI” can do all of that too — it’s far more expensive than creating chaos.
And its not even a function of “AI” in particular.
The cheaper compute becomes the harder it is to produce systems that are practically secure.
Because you increase the size of the reachable state space you have to enforce invariants in.
In an apparent paradox, producing valuable software becomes more expensive the cheaper computing becomes.
Just published 778 findings in my website https://t.co/PNem20fDtg from contests and private audits 🎉
There are links to the codebase at the right commit, so you can understand the bug yourself instead of just reading about it.
Might be the best way to study, enjoy 🫡
$1,646,858.
That’s what this hacker has made from web3 bug bounties.
Meet @WhiteHatMage
An Immunefi All Star and a bug bounty legend.
We asked him how he does it.
"What is one practical bug bounty strategy that has helped you find better bugs? "
I focus on Critical exploits only. They can be life-changing for me, the protocol, and its users. Hunters' time is very limited. I don't bother looking into paths that can't lead to catastrophic effects. I find lower severity issues as a side effect.
"What habit, routine, or mindset has made you more consistent as a researcher? "
Embrace the asymmetric nature of bounties. I prefer a few big wins instead of small consistent payouts, although that also means long, tough times with no feedback loop. The most difficult part for me is being consistently sharp. I've achieved my best performance during short bursts of a few days or weeks, breathing code 24/7, then taking long breaks of weeks or months.
"Can you share a memorable bug or win, and what helped you find it? "
My last payout on Immunefi was from a codebase I checked a long time ago. I revisited it after a year with more knowledge and found the exploit in a matter of minutes. I backtracked the issuance of funds by following complex graphs and always asking what I would need to break the core invariants. It protected over 50 million dollars in user TVL.
"What is one piece of advice you would give to a researcher trying to level up or land their first bounty? "
Try different things to see what works best for you. Don't blindly follow X trends, audit checklists, or popular posts. Hunters must be a step ahead of the rest of the space. Check niche posts, unpopular writeups, release notes, commit fixes, and anything else nobody is looking at. That's your starting point. Then go deeper.
He was an accountant in India with zero technical background.
18 months later, Vivek has earned $1.07M+ in bug bounties.
No CS degree. No security background.
Just relentless self-teaching and an obsession with finding what everyone else missed.
New episode live now.
At 21, Ehsan went from nearly homeless to earning $1.4M+ in bug bounties in under a year.
No degree. No formal training. Just 15-hour days in public libraries, ruthless discipline, and an obsession with finding bugs others missed.
New episode with @MitchellAmador and @Ehsan1579
There’s a complexity level after which human experts outperform an LLM in accuracy, cost, and speed.
That level is pushed higher by new models (at exponential cost absorbed in training). It doesn’t go away.
The cheap chess analogies are completely backwards.
For bug finding, the idea there are bugs too deep for humans to find is the opposite of truth.
There are bugs so deep only humans can hope to find.
There’s a level after which not even having the human be assisted by an LLM makes a positive difference. It can degrade performance actually.
Classical computing can only work on fully formalized symbolic systems. Humans can do everything electronic computers can, with the same resource scaling laws. But at linearly trillions of times higher costs, time. The lower accuracy can be dealt with added logarithmic factors. But we can’t escape the fact we’re just slower.
Beyond that, humans can easily operate in not fully formalized systems too. Even completely informal systems. In fact that is easier for us than formal systems.
LLMs can bridge the gap and let computers operate with informal symbolic systems in natural language too.
The cost is making it a billion times more expensive than classical compute from the start. And adding an exponential component degrading accuracy, slowing down, and increasing costs.
You can move some of that exponential to training, you can use more tokens to compensate to some extent accuracy issues.
But you can’t escape the exponential.
There’s no free lunch.
Everyone is asking "what to do in web3 security in the AI era"
I've been observing multiple masters of web3 security and their AI usage. While everyone starts with just "summarise/explain the codebase", mostly everyone ends up building their own toolings.
Tools are usually vibecoded Python & Bash scripts plus Markdown files for the AI. It's packaged expertise. Why would you build such tools? Because they do in 1hr what you did before in 5 days or more.
Still, many of the great auditors are not all-in into AI. Many of the top 1% are using A LOT of AI, but their own judgement is still driving the car.
Whatever works - that's the right solution. You need to have the correct metrics, KPIs, Key Results or whatever you want to call them.
Measure rigorously, constantly and iterate. You must find more and better findings than others, faster. Do what works. Now go🫡
I Miss Being Desperate.
4 years ago I made the decision to go all in on web3.
2 years later I was in a bad spot:
- Savings from 100K => -5k
- Pitiful 20k earned
- Wife 8 months pregnant from our third child
- No money to buy diapers
I got a second job to meet ends, working 80h+ every week.
When pressure becomes so high, a strange thing happens. Everything becomes like a static distant sound, as if diving into dark deep waters. Emotions are muted and nothing remains but an iron voice saying "I Will Not Fail", endlessly echoing against the walls of my mind.
I spent about 6 months like that until my opportunity finally came. It was a horribly painful experience but the pure focus and will I was able to summon was extraordinary.
Today I've achieved everything I set out to do. I'm one of the top researchers in one of the top companies worldwide. Respected by my peers and plentiful opportunities to move up or sideways as I so desire. I earn enough to buy a house every year, which is absurd. I've made it.
Yet, I've also become Soft. Comfortable with my life and I hate it.
There are so many great things I could still do, plenty magnificent goals I can see in the distance that only require a few thousand hours of work to realise. If only I can get lazy ass to move.
I miss the beautiful purity of desperation.
🚨 JUST IN:
@adsharesNet was exploited for ~$628K.
Cause: fake bridge mint validation.
The bridge-minter EOA signed 3 wrapTo() calls with non-existent native-chain txids, minting fake wADS to the attacker.
Attacker dumped the wADS for ~148.5 ETH and ~$305K USDC on Ethereum.
🚨 BREAKING: The U.S. Senate Banking Committee has advanced the Digital Asset Market CLARITY Act with a 15 - 9 vote.
All Republicans voted in favor, joined by Democrats Ruben Gallego and Angela Alsobrooks. The bill now heads toward a full Senate vote, a major milestone for crypto regulation in the U.S.
The CLARITY Act aims to define SEC vs CFTC oversight and bring clearer rules for digital assets, stablecoins, and crypto markets.
Big win for the crypto industry, but the lobbying battle is far from over.
I'm changing my strategy on new BBPs.
I used to speedrun them because I'm pretty good at it.
I now think that's better suited for an automated tool.
I’m also afraid of getting duped by some clunky report that only flags weird behavior, missing the impact. Worst-case scenario.