In 2025, Code4rena Wardens prevented 286 high- and medium-severity vulnerabilities from entering production.
Here’s a look back at what the C4 community accomplished this year!
@1_00_proof IMO, it is a bad take. Simulating black‑hat incentives too closely effectively legitimizes black‑hat behavior. I do not think there is a "brutal asymmetry", if you go black hat, you’ll always be looking over your shoulder.
🚀 Introducing AuditHub: The next-generation blockchain security platform for Web3 developer teams.
Built by Veridise — now available to the entire dev community. Follow @AuditHubDev for updates.
Thread 🧵
@czar102 I fully agree! We should be putting way way more effort on this front. There are real builders working on this like @PlumaaID, but sadly they're far too few.
@czar102 In other words, tech adoption failures aren't always about the technology itself. Good/mature solutions may exist but face barriers such as: outdated regulations, cultural resistance, and institutional inertia that favors maintaining the status quo over adopting new solutions.
@czar102 The way I see it is that there are several use cases that are fully solved in terms of scalability and security but it is the regulation and other legacy systems which have not caught up for these applications to reach a greater scale.
Join us for an insightful fireside chat with Rami Khalil (@ramikhalil), Senior Protocol Engineer at @RiscZero and @boundless_xyz, to discuss the design space for building applications using the RISC Zero zkVM.
Hosted by @FormallyJon from @VeridiseInc.
Timestamps:
0:00 - What is a zkVM, specifically RISC Zero's zkVM?
03:04 - What’s the dev experience like, and what are the benefits?
06:01 - What guarantees does the zkVM provide?
08:04 - What do you mean by “underconstrained input”?
10:24 - Can you build privacy apps with RISC Zero?
11:11 - Can you maintain privacy while using the proving network?
13:08 - What new apps are now possible thanks to zkVMs?
17:22 - Who’s Boundless for, and how will decentralized proving work?
20:42 - How does integrating RISC Zero impact a protocol’s security?
24:17 - How do you ensure the zkVM is secure?
26:03 - Are you using the best crypto, constraints, and proving systems?
29:18 - Can you leverage parallelism based on machine count?
30:17 - What would you love to see built with RISC Zero?
30:47 - What’s the value of using FHE inside a zkVM?
32:28 - What advice do you have for devs building zkVM-based apps?
33:12 - Examples when ZK proofs won’t benefit an application?
34:45 - Jon’s security tips for developers
40:02 - Has anyone shared interesting use cases for Steel?
46:37 - What else is RISC Zero building beyond Boundless?
49:17 - Any upcoming apps aside from Keccak?
There is one fundamental truth we must understand regardless of your age, your position, the money you have:
The greatest measure of success in life is your ability to remain content and in absolute acceptance internally with whatever is going on externally in your life.
Very few get this.
@0xEV_om There is actually tons of evidence of the opposite. Mastering of prerequisites is a must to achieve high-expert performance. Whether currently you need that to spot bugs or whether those alleged 'security courses' work is another discussion.