My notes for @pashov interview on @SecuritySeries (@PabloSabbatella):
- Path:
math competitions
-> PC
-> informatics classes
-> university
-> IT company (full-stack)
-> colleague quit to join blockchain
-> got interested
-> self-taught
-> started DeFi development
-> heard about high pay for audits
-> @cmichelio famous article (https://t.co/FYuRm7AXPq)
-> learned more about @code4rena
-> @andyfeili videos (https://t.co/gaiOyiH5eZ), @thesecureum Discord
-> Back then huge money for not many hours, multiple times more than developers ~"six figure sum in under a month of work just didn’t make sense, I immediately understood there was something I didn’t know and needed to learn"
-> started contests
- Advice for new auditors
- No need to start as a dev, but most successful SRs were devs
- Even no need to be very technical, there are many examples of non-devs being successful SRs
- Not very likely
- Requires a lot of motivation
- "Mastering Ethereum" is still worth reading, though hard. If you quit it midway, crypto may not be for you. It contains all basics. Can be read in 1-2 weeks
- Try @cyfrinupdraft, it is very new (it was ~2 months ago). Then their security courses
- After that, start with contests
- Is it important to be self-taught?
- Many people got into SR from @thesecureum
- @pashov took Codecademy courses
- Do research, practice, and make money. That’s most important
- Auditing process
- Not that important to listen to others about auditing style (top to bottom, line by line, docs first, etc), find your own style
- He hasn’t done audits in >6 months because he is an audit company founder now
- Choose a contract to start with
- Go line-by-line, character-by-character
- If you don’t understand a line
- Step back
- Go deeper (docs, ask devs)
- Move to another contract for a while
- He personally doesn’t start with docs, but many successful SRs do
- Mostly just read code, think about attacks, nothing special
- Income for SRs
- Private
- On @PashovAuditGrp and others, usually base pay, stable
- @SpearbitDAO will pay $20k a week
- In private audits, even if you find nothing for a particular audit, you get paid
- Demand matters a lot, but recent months were the best ever in crypto
- Contests
- Good enough to live in almost any city, but you won’t become rich
- Even with the best bugs, you can get nothing due to escalations or minor rule details
- Better in bull markets: bigger pots, more rewards, more work
- Changes in the field in recent years
- Several contest platforms, different models
- SRs get paid better than ever
- Fewer hacks, fewer bugs in production
- Crazy progress overall
- Tooling
- Not much has changed overall
- Static analysis about the same
- Only fuzzing is doing great
- Some teams start using it
- Maybe not enough to build a business on it alone, but a side product for auditing firms
- @PashovAuditGrp doesn’t do it
- No big demand
- Better tooling overall
- People
- Natural selection
- Many new people join, but not enough. Slightly more are needed
- Courses help
- Many rising stars
- On-chain audits
- (My note: I haven't heard much about it)
- Not worth the trouble
- Just commit/message hash on-chain is enough
- No demand, not a real problem
- Strategies
- Focus on one field, like ZK
- + Become the “ZK guy,” get more solo gigs, more invitations for consultations
- - Risky if ZK stops being popular
- @pashov’s strategy
- Focus on everything the first year
- Then specialize in something like lending
- Big TVL
- Big bug bounties
- Tips for protocol companies
- The more time and money spent, the more secure you are
- Hire good devs
- Fewer bugs, fewer audits needed
- Some protocols have 10 critical bugs in 1000 lines found in 1 week, that’s too much and needs multiple rounds to fix
- Multiple audits before deployment
- Every upgrade should be audited
- Tips for audit companies
- It’s best to have a new team for the second round. They will be unbiased (at least in cases where multiple critical bugs were found in the first round)
- Auditing a big project is a big responsibility and a big reputation risk if hacked
- Even big names hire new devs, and you can often find many issues
- Usually big names have great code quality: more money => better devs, better auditors
- Why he founded a company
- After a year of solo audits (50 done), doing everything (marketing, communication, audits), working every day often 12 hours
- Wanted more impact, audit more projects, make more money, have more influence
- Record before opening company: 6-7 audits/month, now 15-16
- Overall quality is better because he works with great SRs
- Some with 10+ years of pentesting and web2 security experience
- Tries to find hidden gems and work with them
- "Use it or lose it," you can’t stay as good of an auditor when running a company
- Coming to web3 from other fields
- If you’re a dev, it’s easy to read Solidity
- Need to learn EVM
- Web2 SRs have a great mindset for finding vulnerabilities
- Best is web2 SR: coding skills plus attacker’s mindset. We see more success from them
- In the end, it’s the individual that matters. Whether web2 SR or dev doesn’t matter too much
- Most important skills
- For @PashovAuditGrp
- Be a great SR, high quality
- Be unbreakable
- Keep pushing when it’s hard
- Have a lot of experience
- Starting a company
- Much harder without a personal brand (having 20k followers on X helps)
- Marketing is important, hard to find someone to do it for you. Or it will be too expensive, like half of the company
- 10x harder without marketing skills
- Brute forcing, just pushing forward, can make good money but not get rich
- Hardest thing for @pashov
- Transitioning from auditing to non-technical role
- Had a technical mindset
- Read 1-2 technical articles a day
- Not as good now
- Intentionally makes it look easy, but it’s hard
- Believing in yourself, some beliefs to overcome:
- You can’t make it, it’s too hard
- Hiring is too hard
- Don’t deserve to increase prices
- Clients aren’t happy with the service
- Auditors aren’t doing a good job
- Can’t find good auditors to work with
- Mistakes
- @PashovAuditGrp
- ~“We’ve done almost everything perfectly”
- Started a bit slower than desired
- Lessons
- If you create good quality content, your business will improve and you’ll get more clients
- Angel investing
- ~"Like a casino but the odds aren’t that much against you"
- Trains your brain to fight cognitive biases, become more rational
- Can make you smarter
- Meet many people, including important ones for business and audits
- Basically a synergy: invest + find clients. A win-win
- Example: Solana 1000x from seed round, a life-changing generational wealth opportunity. Investing $100k could make you rich even in the most expensive part of the world
- Invested in 11 projects, $10-30k each. A minority investor, usually <1%
- Mostly invests in companies his firm audited, when he liked the team and product
- After investing, usually just reads monthly emails from the project and checks their X. Helps when he can, like hiring
- Accepting project tokens as payment
- @PashovAuditGrp doesn’t do it
- Most don’t have a project token yet
- If they don’t have a token, it requires more documentation (like a pre-ICO agreement)
- The project can dump the token
- Rarely a good fit
- Almost all pay in USDC/USDT
- Resources
- Read crypto Twitter/X. He spends hours a day there
- Check who he follows and follow them for a good feed
- Rarely reads newsletters
- Conferences
- The biggest ones are the best
- Attends 1 or 2 a year
- Can waste a lot of time and energy, so he focuses on work more
- Great to meet people
- Before going, find who will do your job while you're out
- A lot of value, but time-consuming
- Anyone can reach him on X, DMs are open, happy to work with a good fit
- https://t.co/FmzZEoj4YF
🔐 Blockchain @SecuritySeries 15 - Nikita Varabei (
@NikitaVarabei ): Founder @ ChainPatrol
- "Scammers operate like an industry, with developers creating scam kits and others deploying them to steal funds."
Topics discussed:
- 00:00 - Intro
- 01:40 - How Nikita got into programming and blockchain security
- 08:05 - How ChainPatrol started
- 10:10 - Scam investigators
- 12:20 - Burn Mywallet
- 15:05 - ChainPatrol early days
- 20:20 - What ChainPatrol does now
- 24:25 - Social engineering
- 28:30 - Post mortems
- 33:04 - Scammers investments and ROI (Return on investment)
- 38:10 - Service providers role: registrars, cloudflare, google ads, twitter, linkedin
- 46:00 - Scammers stack: registrars, hosting providers
- 51:18 - Mixing on-chain and off-chain data to detect threats
- 55:21 - Collaboration between security companies, Threat Intel, SEAL ISAC
- 58:56 - Issues with competitors and ChainPatrol openness
- 01:02:10 - Web3 vs Web2 security
- 01:06:18 - Scammers reporting each other
- 01:10:04 - Methods used by scammers to avoid detection. Cloaking techniques, Cloudflare, Captcha.
- 01:15:07 - Users and community reporting, incentives, threat hunters.
- 01:19:37 - Making scammers lose time
- 01:21:06 - Scammers using hacked domains and legitimate companies' domains getting hacked
- 01:22:43 - Wordpress hacks and secure domain registrars
- 01:25:35 - How to manage legitimate projects domains and accounts being compromised
- 01:31:38 - Transaction simulation bypass. Proxy contracts, exploit of contract variables. Bit flip attack.
- 01:37:20 - Challenge to build for more privacy and improving threat detection at the same time.
- 01:42:24 - Private information retrieval (PIR)
- 01:44:11 - Companies taking more care of their users trend
- 01:48:47 - IPFS being used by scammers
- 01:49:55 - Best tips for crypto companies
- 01:53:39 - Security tips for users
- 01:56:41 - Final thoughts
- “Imagine if there is a vulnerability in one of the clients, consensus -based clients, where an attacker were able to take control of the validators, then the attacker would have access to a lot of validators and in a sense they would be able to hold the network hostage because they would be controlling such a large percentage of validators which... I don't think with the current percentages they could actually do anything major, but the amount of ETH they could potentially get slashed would be huge.” @fredriksvantes
🔐 Blockchain @SecuritySeries 14 - Fredrik Svantes (@fredriksvantes): Security research lead @ Ethereum Foundation
“I think we are still behind when it comes to the protocol security stuff. I think we need to expand that because the more Ethereum grows, the more potential adversaries there's gonna be. And if you want to cause a big effect, if you want to do something big, you can take the protocol down by finding a weakness in the specifications of the protocol or an implementation of the specification in certain clients, then you can potentially cause a much larger issue.”
Topics discussed:
- 00:00 - Intro
- 01:13 - How you started with computers and programming
- 02:41 - Working in Blizzard Entertainment
- 08:12 - Red and blue teams
- 14:19 - Incident response: What should web3 security learn from web2 industry?
- 18:57 - Planned and unplanned war rooms
- 22:58 - Communication mistakes during incident response
- 29:18 - Operational security
- 36:38 - Security awareness
- 39:19 - Social Engineering
- 42:51 - Role at Ethereum Foundation
- 45:38 - EF Bug Bounty Program
- 47:18 - Bounties for the execution and the consensus layer
- 49:01 - Most common types of vulnerabilities reported.
- 51:20 - Vulnerability disclosure process.
- 54:04 - Ethereum Protocol Attackathon with Immunefi.
- 59:39 - Blockchain monitoring and live threat detection.
- 01:01:46 - The future of the security in Ethereum: main challenges
- 01:06:29 - Balance between daily work and technical research
- 01:08:19 - Programming as a skill to be a blockchain security researcher?
- 01:12:16 - Favorite conferences and events
- 01:14:19 - Final thoughts
🔐 Blockchain @SecuritySeries 13 - Pashov (@pashov): Founder @ Pashov Audit Group
“There are a lot of hidden gem auditors in the space really. And this is my mission to find them and to work with them”
Topics discussed:
- 00:00 - Introduction
- 01:06 - How did you get started into computers and programming?
- 05:22 - Mastering Ethereum, Andreas Antonopoulos
- 07:05 - When and why did you decide to switch from developing to security research?
- 11:02 - Do you need to know how to code to be a smart contract auditor?
- 13:07 - What is your advice for someone that is just getting interested in cybersecurity?
- 15:10 - How important do you think it is to be a self-taught person in this industry?
- 16:15 - Reviewing new code step by step. You first understand what the protocol does on a high level or you just jump into de code?
- 19:17 - Income for a security researcher
- 24:12 - What things have changed in the security space in the last years and what things still remain the same?
- 26:42 - What does the ecosystem need in terms of security? More people, better tooling?
- 27:52 - On chain vs off chain audits. How have the incentives mechanisms been evolving and which one is in your opinion the system that works better for auditors? Code Arena, Hats Finance, Cantina, Sherlock, etc.
- 29:37 - How to choose the right audit contest? What strategy should one adopt (focusing only on DeFi protocols, bridges, etc)?
- 32:14 - Recommendations for developers and companies regarding secure software development? In what part of the development cycle should an auditor be involved?
- 35:49 - What can you share with us about your latest audits from some major protocols like Ethena, 1Inch or Layerzero?
- 37:42 - When, why and how did you decide to found a security company?
- 41:03 - Web2 security researcher vs Web3 developers
- 42:51 - Which would you say are the most important skills having worked with teams but also starting your own company?
- 44:03 - Would it have been possible to launch your company without being known in the industry already?
- 46:20 - Did you find it difficult to switch from an independent auditor to run a security auditing company?
- 47:34 - What is the hardest part about launching a boutique web3 security company?
- 48:49 - What are mistakes that should be avoided when building a brand?
- 50:18 - Angel investing. What excites you the most about investing in new companies? Are you planning to focus on other security companies, web3 protocols?
- 53:41 - Do you invest in companies after having audited them?
- 53:30 - How do you get involved with companies you invest into?
- 56:56 - Accepting tokens as payment
- 59:04 - How do you keep updated in web3 cybersecurity? Newsletters, conferences and events
- 01:01:58 - Final thoughts
🔐 Blockchain @SecuritySeries 12 - Stephen Tong (@gf_256): Co-founder & Hacker @zellic_io
"90% of being secure is caring about your code, having tests, documentation, and a clear spec."
Topics discussed:
- 00:56 - Your story: How did you start getting interested in security?
- 04:01 - Perfect blue: A weeb team with a CTF problem. Tell us all about it!
- 06:49 - Similarities between web2 and web3 security. CTF skills comparison
- 09:55 - Traditional security background for auditors
- 11:41 - How did you start Zellic and what’s its focus?
- 13:05 - Development cycle and security.
- 15:11 - Unit testing
- 18:35 - Formal verification: The wETH example
- 23:27 - The current state of DeFi security
- 26:27 - Hacks and kill switches and recovering funds mechanisms
- 30:15 - Monitoring and threat detection
- 31:05 - Code is law?
- 32:18 - Consumer education & mass adoption
- 33:19 - Security Alliance - Whitehat Safe Harbor Agreement
- 35:35 - The Nomad hack: Audit diffs
- 37:50 - Bridges and OpSec importance
- 41:30 - Programming languages. Solidity and it’s origin - 43:15 - Rust & Move programming language
- 46:05 - Key features of a blockchain programming language
- 46:38 - ERC-4626: Standards for yield bearing assets
- 47:40 - MPC from scratch
- 50:04 - Zellic Forky
- 51:03 - How to store crypto safely
- 52:55 - Threat modeling
- 55:15 - Favorite conferences
🔐 Blockchain Security Series 12 - Stephen Tong (
@gf_256): Co-founder & Hacker @zellic_io
"90% of being secure is caring about your code, having tests, documentation, and a clear spec."
Topics discussed:
- 00:56 - Your story: How did you start getting interested in security?
- 04:01 - Perfect blue: A weeb team with a CTF problem. Tell us all about it!
- 06:49 - Similarities between web2 and web3 security. CTF skills comparison
- 09:55 - Traditional security background for auditors
- 11:41 - How did you start Zellic and what’s its focus?
- 13:05 - Development cycle and security.
- 15:11 - Unit testing
- 18:35 - Formal verification: The wETH example
- 23:27 - The current state of DeFi security
- 26:27 - Hacks and kill switches and recovering funds mechanisms
- 30:15 - Monitoring and threat detection
- 31:05 - Code is law?
- 32:18 - Consumer education & mass adoption
- 33:19 - Security Alliance - Whitehat Safe Harbor Agreement
- 35:35 - The Nomad hack: Audit diffs
- 37:50 - Bridges and OpSec importance
- 41:30 - Programming languages. Solidity and it’s origin
- 43:15 - Rust & Move programming language
- 46:05 - Key features of a blockchain programming language
- 46:38 - ERC-4626: Standards for yield bearing assets
- 47:40 - MPC from scratch
- 50:04 - Zellic Forky
- 51:03 - How to store crypto safely
- 52:55 - Threat modeling
- 55:15 - Favorite conferences
Hosted by @PabloSabbatella