You can measure how vulnerable the code is after a contest. This can help:
- Projects and users to estimate hack risk
- Bug hunters to scope targets
- Ecosystem to track what works best
- Platforms to manage reputation risk
TL;DR: More solo findings -> more hidden bugs.
This…
Code4rena will run audit contests for free, as public goods.
100% of funds from sponsors will go directly to auditors and judges. We won't take any cut.
Why?
1. Competitions are commodities.
They're CRUD apps. Why should builders pay premium for a website just to submit bugs?…
BOUNTYHUNT3RZ Episode 12: w/
@tpiliposian@0xriptide
Bringing out the AUDITOOOR
We discuss how auditors and bounty hunters differ, @hexensio audit model, what the @CertoraInc prover actually does, what devs should do prior to deploying, RED FLAGS to look for when looking at a…
The best time to start writing searchable notes about design and gotchas of the protocols I work on was a couple of years ago. The second best time is now
🎧@bountyhunt3rz
“Multiply it by infinity and take it to the depths of forever, and you will still have barely a glimpse of what I’m talking about.”
- SR escalating their finding
From pentesting to Web3 security, he addresses threats like phishing, fake interviews, and stolen private keys.
With a focus on eliminating single points of failure, @theSouilos prioritizes risks that could shut down an entire company or protocol.
His mission: protect…
What is the #1 code quality measure?
It's BORING.
Below is one of my bookmarks from well before I started my security research journey. Yet, I find it even more relevant to this field.
youtu.be/5TJiTSWktLU?fe…
Introducing Zenith: an auditing firm that delivers good, affordable audits ASAP.
Teams want to ship this week, not next month. And without critical bugs.
We pick a team of top auditors and manage the audit. It's hassle-free.
No more waiting: we can start at a moment's notice.
anyone using @solana/web3.js, versions 1.95.6 and 1.95.7 are compromised with a secret stealer leaking private keys. if you or your product are using these versions, upgrade to 1.95.8 (1.95.5 is unaffected)
if you run a service that can blacklist addresses, do your thing with…
21 contests running simultaneously: 6 of these have 6-figure pots, one has 7 figures (source dailywarden.com); this without considering bug bounty programs.
Can protocols putting less than $50k on the table for a public contest really expect decent coverage in return?
this is precisely how I stopped actively hunting on Immunefi and started on C4 mid 2023. I feel you bro 🥺
To me it still serves well as an alternative to emails: randomly found a bug? That’s the way to tell the project
this is precisely how I stopped actively hunting on Immunefi and started on C4 mid 2023. I feel you bro 🥺
To me it still serves well as an alternative to emails: randomly found a bug? That’s the way to tell the project
712 Followers 93 FollowingSolo auditors, made mainstream.
Commission-free, vetted network of top SRs.
Browse, filter, connect — or ask us to matchmake.
👇👇👇
336 Followers 932 FollowingWeb3 security researcher - 30+ H/M findings in public contests this year - Currently grinding contests + learning Rust 🦀 - DM for private audit
1 Followers 172 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If i nterested, please contact https://t.co/dcCpUhsfzr
1K Followers 6K FollowingOpen to freelance
Fullstack Developer👨💻
•Builder for @Bridge23ai (AI Agent) Pre-seed Stage
•Solana Dev talent part by @solanaturbine
•remote working
947 Followers 2K FollowingBuilding *probably the biggest innovation in DeFi since crvUSD* or something like it at @Ammalgam. Red, Green, Refactor. Mathlete & roman candle dueler.
774 Followers 399 FollowingDiscover Next-Gen Blockchain at https://t.co/1JbpH0BPDl & https://t.co/K2KWq5acED! Join our Discord for updates and new Migalabs services: https://t.co/tvYiwvnsIX
1.8M Followers 91 FollowingOfficial account of Ray Dalio, founder of Bridgewater Associates, author of #1 New York Times bestseller 'Principles,' professional mistake maker
2K Followers 1 Followingbountyhunt3rz: LIFE ON THE BLOCKCHAIN
We interview the top bounty hunters in crypto to discover their secrets to finding live bugs and making millions
1K Followers 291 FollowingPrincipal Security Engineer @halbornsecurity focusing on R&D/digital assets security “opinions/shitpost are solely my own” ex @cyberstruggle SCO made in 🇪🇬
7K Followers 34 FollowingThe premiere developer institute, innovation lab, research hub, talent source, dev shop on @solana The Solana Talent Engine. Visit at https://t.co/VI3RQ8R0CO
4K Followers 136 FollowingInstitutional Grade Web3 security, for when it has to be right the first time. Guarded $10 Billion.
Book an audit → https://t.co/eDa6yn6Fsh
2K Followers 2 FollowingZenith assembles auditors with proven track records to secure your project. We find the critical bugs now—freeing you to launch this week—not next month.
973 Followers 128 FollowingBreaking web3 infrastructure for a living
Rust | Go | Bitcoin | Solana
Senior All Star @immunefi
ZR @zenith256
Profile: https://t.co/SCCO0nE5US
335K Followers 465 FollowingA better internet starts with privacy. Stay in control with e2e encrypted email, drive, docs, password mng, AI, & VPN.
🫶 Help @ProtonSupport
🐈⬛ New @asklumo
15K Followers 1K FollowingHacking all the things since 1997 • @PwnieAwards Winner • Created Mythril • Hunting Bugs for @Spearbit • AI Research Lead @SherlockDefi