Mewt grades your test suite by sabotaging your code. Each change that doesn't get flagged by your tests is a potential bug.
Today we're expanding it to support DAML, @CantonNetwork's native language, with two new mutant classes for DAML's authorization rules.
TOOL RELEASE: Detect plagiarized code even when variable names change and comments disappear. Vendetect uses semantic fingerprinting to catch copied code that traditional tools miss. https://t.co/68HfWUrcCU
This talk is going to be a banger. Imagine being able to keep your treasury safe even if your entire multi-sig is compromised.
It's easy to implement and something you could build tomorrow. Come to my talk to find out how
💎 We are thrilled to announce the release of the PixelSwap Audit Report, conducted by the world-renowned crypto audit agency, Trail of Bits.
🛡️ @trailofbits leverages advanced security research and a real-world attacker mentality to mitigate risks and strengthen code. Their expertise in blockchain security includes audits for prominent projects such as AAVE, Arbitrum, Balancer, Chainlink, Curve, MakerDAO, Optimism, Polygon, Solana, Starknet, and Uniswap.
🔗 The report is now live on the publications repository: https://t.co/5qEWh8l9rP
♾ At #PixelSwap, we are committed to delivering safer and more efficient solutions for DeFi, with security as our top priority. Our DEX employs a modular architecture in its smart contracts, ensuring effective management of user balances and liquidity pair reserves, which enhances both reliability and scalability.
💙 This audit underscores our dedication to true decentralization, transparency, and a robust security architecture. With the release of this audit report, we aim to bolster our users' confidence in our platform.
Radiant Capital receiving unbelievably bad advice here. FFS please separate your sensitive on-chain operations from browsing/discord/telegram/email/etc.
https://t.co/MPKq11EgB1
Great news for Echidna users!
In the upcoming release, coverage reports will display the number of executions per line.
This feature is extremely useful for debugging the efficiency of fuzzing suites. By identifying branches that are rarely reached, you can add clamping or handlers to optimize performance.
I've been waiting for this feature for a long time 😄
You can test it here:
https://t.co/xlyY0iR7n4
Here's a marketing post that rambles on for 90% of T̵w̵i̵t̵t̵e̵r̵ X’s allotted character count, that is just brimming with excitement, trying to make you feel an unbearable sense of FOMO, throwing in some random buzzwords...
all just to say we're presenting @EthCC
Hey everyone!
I'm sure this next job announcement will excite many folks to apply, so I'm preparing myself to review hundreds, if not thousands, of resumes over the next few weeks, lol! We are actively seeking a Senior Security Engineer to join our well-known blockchain team.
We presented our paper on Necessist, "Test Harness Mutilation," at Mutation 2024. Necessist finds bugs in real-world tests! Slides and a preprint of the paper are available at https://t.co/YhgqeNzKwd
Fuzzing is preferred over formal verification because proving the absence of bugs is usually unattainable, and fuzzing identifies the same bugs with less effort. https://t.co/x9Bc2ucwza
Today we're releasing Attacknet, a new tool in the blockchain security arsenal. Built in collaboration with the @Ethereum Foundation, it uses Chaos Engineering to test the most challenging network conditions imaginable for fault tolerance https://t.co/9faMoxt0RR
We are excited to announce @trailofbits won a $1mil @DARPA award to compete in the AIxCC! Learn about our approach and guiding principles:
https://t.co/lSs44ZrYRo
If you are a Solidity dev you should definitely check this out.
High-level recommendations to build more secure smart contracts.
Really helpful stuff that every Solidity dev/auditor should know very well.
https://t.co/l9Jz6ahO7S
@giovannidisiena@trailofbits We use it during our security reviews.
For example:
- Issues 27, 28 and 29 in https://t.co/qG6aQRJZ6E were found with necessist
- It was used for Appendix C of https://t.co/l0gMKowuWZ
Many assume our open source tools are just for marketing. In reality, the effort to build and maintain these tools is immense, and overshadow any direct marketing gain.
And from a business standpoint: competitors even benefit from our work for free.
So, why do we do it? These tools are essential for our work, and we're committed to empowering the community, making the industry a safer space.