The DRE App audit contest is now live!
Sherlock researchers can review dreUSD core contracts, with up to $60,000 USDC available through conditional rewards.
Jump in here ๐
https://t.co/FcX1GZp3ec
Continue examining @Morpho the periphery section. Up to this part, I am almost convinced that there is no high vulnerability here. And finding medium need tons of luck.
Still grinding @Morpho midnight. Though it was said to be solid as my country's hope. Let's just keep grinding until finished with the intention to sharpen my skill.
There's plenty of chaos in Web3 this year alone, especially in security. My focus is simple: keep sharpening my skills until I'm capable of making a meaningful impact.
What Smart Contract Security Research Really Is
Most people think blockchain security is just โchecking code for bugs.โ
It isnโt.
Smart contract security research is psychological warfare against invisible adversaries.
A smart contract security researcher studies decentralized systems the same way a thief studies a bank vault.
The job is to think like an attacker before attackers arrive.
To identify weaknesses before they become headlines.
To understand how complex financial systems break under pressure, manipulation, and human assumptions.
In Web3, code is law.
And unlike traditional software, smart contracts often control real money directly.
No customer support.
No chargebacks.
No emergency rollback button.
One vulnerability can drain millions of dollars in seconds.
Thatโs why smart contract auditing has become one of the most critical disciplines in blockchain cybersecurity.
Every DeFi protocol, governance system, bridge, staking platform, and DAO depends on security researchers seeing what everyone else missed.
Sometimes that means catching catastrophic flaws before launch.
Sometimes it means watching exploits happen in real time and realizing nobody can stop them.
After months of auditing, I rarely touched liquidation logicโit's long, complex, and intimidating for beginners.
But in every contest results, liquidation operations are always where most bugs are found.
So for K2, I'm biting the bullet and grinding through liquidation. ๐ช
New: We just launched the BEST Web3 opportunities page! Bug bounties & Audit competitions aggregated all in one place in a beautiful customizable UI. Check it out here: https://t.co/9VSMTuk0c2
Audit update. Nothing new, continue grinding K2 for flash liquidation. It has been almost a month grinding K2, with only 3 days short break for Solana Audit Arena.
Three major hacks in just 4 days!
On May 15, #THORChain was exploited, with stolen funds exceeding $10M.
On May 18, the Verus-Ethereum Bridge (@VerusCoin) was hacked, with ~$11.5M stolen.
Today, @EchoProtocol_ was exploited, the hacker minted 1,000 $eBTC ($76.64M) and has already used it to steal 385 $ETH($821K).
Stay safe.
Crazy โ another hack just happened!
According to @dcfgod, @EchoProtocol_ on Monad was exploited.
The hacker:
minted 1,000 $eBTC ($76.64M) on Monad;
deposited 45 $eBTC ($3.45M) into Curvance;
borrowed 11.3 $WBTC ($867K) from Curvance;
bridged the 11.3 $WBTC to Ethereum and swapped it for 385 $ETH ($821K);
then deposited the 385 $ETH into Tornado Cash to launder the funds.
The hacker still holds 955 $eBTC ($73.2M).
https://t.co/iswmvC0Gk1
Continuing k2 audit today. Today for price oracle and internal liquidation. Tomorrow will be the 2 step liquidation.
Having a nice zen moment yesterday with Ikea coffee & almond cake.