We've put together a @NotionHQ dashboard for web3 security researchers!
It contains heaps of resources and a neat template to help you organise your findings and navigate codebases.
Let us know what you like or whats missing below!
https://t.co/YrxJTsbQyp
Here are 3 more resources where you can test your auditing skills through competitive audits and get your name out while possibly earning some well deserved bounties🤩
♦️ @sherlockdefi
♦️ @saloonfinance
♦️ @code4rena
Are you familiar with the challenges borrowing and lending protocols face?
Dive into:
- Illiquid liquidations
- Collateral Safeness
- The dangers of governance
- Oracle risk and cost of manipulation
And much more...
article by: @0xnikceth
https://t.co/VU0pSzipfR
Having a dashboard with details about all DeFi exploits to help you become an exploit master mind sounds almost too good to be true.
But @DefiLlama has got you covered!
https://t.co/QZ1Y98y9U6
Incredibly valuable resource with foundry tests to help you understand and replicate vulnerabilities worth more than $1B (B for billions)!
You can find many more resources like this within our security researcher dashboard (pinned).
https://t.co/CGFrDDxG4X
@shunduquar@real_philogy 0% APR and $0 direct deposit combined are not allowed.
Projects must choose at least one (X% APR or $X deposit), but are encouraged to choose both.
Saloon custodies all funds in it's vault and is control of validation/payments. So fake reports would just be nullified.
In the span of a few days:
1. USDC depeg making us re-evaluate our dependency on fiat.
2. Vulnerability in SHA3(keccak) https://t.co/h9btLeT0o4
3. Euler $197m exploit.
https://t.co/MajEyUbTnD
4. What's next?
Don't let your guard down.
@realgmhacker credit for SHA3 news.
There are still some ongoing attacks on the SwapX contract over the past few days.
More than 20,000 addresses have approved to 0x6D8981847Eb3cc2234179d0F0e72F6b6b2421a01
⚠️Pls revoke your approval ASAP.
@peckshield To whoever needs to hear this:
MEV doesn't care about your hard-to-read bytecode. Develop secure contracts regardless of verifying or not.
Stay safe 💛
Many protocols allow users to create contracts for others to interact with.
In this C4 audit for @escherxyz , auditor @hansfriese et al. highlights how things can go wrong if contract creation is not carefully implemented.
🧵4
Bug: For all sales, creators create new sales contracts with arbitrary data. Malicious creators can create fake contracts that implemented IEscher721 and fake buyers to get free earnings because there is no check to verify if the contract was deployed through the Escher Factory.