codetilda @codetilda
web 3 security researcher 🇨🇦 Joined August 2022-
Tweets174
-
Followers20
-
Following422
-
Likes277
Layer 2 blockchains are probably one of the most misunderstood topics in crypto, so let's fix that. A guide on how L2s actually work 🧵:
Sometimes when I talk with Devs/Auditors, I feel they lack knowledge of Tokenomics (supply, demand, ROI, game theory, etc.). So, here's the best resource I know on the topic: Tokenomics 101: The Basics of Evaluating Cryptocurrencies Check it out: every.to/almanack/token…
Hardhat has a brand new Ethereum runtime written in Rust! 🚀 Performance improvements, a blank slate for new features, and new information about the upcoming Hardhat 3. Check it out blog.nomic.foundation/rust-powered-h…
Whenever a protocol developer ask for a pre-audit security checklist, share this with them I often forget about it, but it is still valuable (and ready) advice. github.com/transmissions1…
Top 5 Places to Learn Smart Contract Development (Solidity!) - Cyfrin Updraft - My YouTube :) - Speed Run Ethereum - Alchemy University - Rare Skillz
Another amazing article worth reading for every Web3 sec auditor, as well as for the Solidity developers who use Inline Assembly to save gas, by @DevDacian. It consists of a deep dive into 6 vulnerabilities, so you won't let them slip away next time: dacian.me/solidity-inlin…
Auditing becomes very *very* fun once you're over the hump. Still trying to break through that barrier? Just follow these steps in order: 1️⃣ Learn The Basics I covered it all for you, get all the basics down with the following playlist: youtube.com/playlist?list=… After that, you know everything you need to get started. 🫡 2️⃣ Start Competing In Contests Here are some platforms to try out: - @CodeHawks (First flights to start) - @code4rena - @sherlockdefi - @cantinaxyz - @HatsFinance Now let's set the expectations before you dive in, contests will be hard, that's expected. Rising through the ranks and gaining mastery is extremely time-intensive and in the beginning... quite brutal. In the beginning: • You'll feel overwhelmed in a new codebase • You'll struggle to uncover solid high findings • You'll struggle to uncover solo findings • You'll find it hard to even learn from each audit We need to get out of this beginner phase ASAP. This is where the majority of folks get stuck. Let's not get stuck. 3️⃣ Absorb From Someone Who's Already Done It To rocket out of the beginner's phase let's learn from the experience of those who have done it before us. We can absorb years of Web3 Security experience in weeks just by working alongside a security veteran. Not only that but having a partner to audit with can drastically accelerate your rate of understanding a codebase. → Consult the code → Consult your partner → Understand the code more Do anything you can to get around and learn from someone who's put in the time and done the head-banging for you. Offer to: • Write reports • Write articles • Create PoCs • Create Fuzzing or Test Suites Anything you can do to provide value and get your foot in the door. Spending just 1 week with a Web3 Security veteran can outperform months of work. It's about learning what you don't know that you don't know. 4️⃣ Partner Up! Web3 Security gets tough! If you have a partner you're much more likely to stick it through and see the fruits of your labor on the other side. Not only that but having a partner to audit with can drastically accelerate your rate of understanding a codebase. → Consult the code → Consult your partner → Understand the code more 5️⃣ Get The Feedback Loop Right Your feedback loop is everything when it comes to mastering a new skill. Auditing is no exception. If your feedback loop is off you can spend months working without making any noticeable progress...😨 You can gauge the effectiveness of your feedback loop by your contest results: Clearly increasing with a stair-step effect? Yes → You got the feedback loop down No → You need to go back to the drawing board If you aren't seeing a clear stair-step effect in your contest results here's what might be happening: You do a contest, wait weeks for the findings to come out, see what you missed and study that. Here's what's wrong with that: • The loop is too slow If you're waiting more than a day or so to get feedback on your work, you're wasting time. Plain & simple. Drag your future into the present and figure out a way to shorten that feedback loop. • Auditing is not flash cards You can't memorize findings and then copy-pasta them into new codebases. The worthwhile findings don't function that way. Start seeing real improvements by getting actionable feedback on your auditing approach, not the outcome. A fantastic way to do this is by consulting someone ahead of you or auditing in a team and observing how others come to new findings. 6️⃣ Gain Credibility Security review demand is driven by credibility. Clients are trusting you with millions of $TVL. However, to get credibility you must have secured millions of $TVL already. We have a bit of a chicken & egg situation.🥚 There are several ways to tackle this, here's a favorite of mine: Find a new open-source project being launched by a big name in the space. Learn everything there is to know about it and spend an entire month auditing it. Present your findings to the team in a comprehensive report, and ask for nothing in return. Now you have a fantastic report for a big name in your portfolio of work. Chicken & Egg → Solved. Bonus points if you complete a fuzzing suite for them. 7️⃣ Go To The Market You've got a handful of contests under your belt. You've worked with several auditors & learned from their approach. You've completed a thorough engagement for a well-known team. And now you're ready to go to the market! Now it's time to see the fruits of your labors. 🏆 Use your network to get your initial reviews or shadow audits with a firm. The most important part here is doing your absolute best. Opportunities multiply when you deliver exceptional work. And that is exactly how you can join the Web3 Security industry! Best of luck, we need you in here. 🤝
Quotation Checklist: How do I personally quote for an audit? In the following you will find a little checklist of what should be considered when quoting contracts. So far, I have quoted 300-400+ projects myself. First of all, as a project founder and developer you should directly decline any auditor that quotes based on SLOC. The only good metric where SLOC can be used is if you have already quoted a project and they have refactored contracts but not necessarily introduced new logic. In such a scenario you could partially rely on your previous quote and adjust the new quote based on the SLOC change. However, lets come to the really important topic: The complexity and security of a smart contract is not necessarily proportional to its length. A good quote reflects a deep understanding of the contract's functionality, potential vulnerabilities, and the amount of state transitions. Let's break down the essential components for an accurate quote: 1. Understanding the Contract's Purpose The initial step involves a quick check to identify what the contract aims to achieve. This understanding is foundational because you need to know which sections are important and how much time to allocate to each section. A vault-style protocol faces different risks and complexities than a simple NFT marketplace. This phase might include discussions with the development team to clarify intentions and expectations. 2. Math-Heavy Sections Smart contracts often incorporate sophisticated mathematical models, these requiring precise validation mechanisms. These sections are critical because even minor inaccuracies can lead to significant vulnerabilities. A lot of time should be allocated to these parts 3. Reviewing Algorithms Similar to the previous part, Algorithms demand careful analysis and time allocation. This scrutiny ensures not only their correct implementation but also evaluates their resilience against attack vectors. Special attention is required to verify that these algorithms perform as expected under a wide range of conditions. Specifically creativity plays a role here: You want to validate these mechanism against extreme boundaries. 4. Evaluating External Integrations Contracts rarely operate in isolation. They interact with other contracts, protocols, and external data sources. Each interaction point introduces potential vulnerabilities, especially when considering the full call-flow and edge cases from interacting protocols. The audit must simulate various interaction scenarios to identify weaknesses effectively. This takes a lot of time 5. Assessing Contract Modes Many smart contracts include governance mechanisms allowing parameters to be modified or simply bringing the contract in another “phase”. Each mode can significantly alter the contract's behavior and interaction with other components. It's crucial to audit these modes comprehensively, understanding the implications of each possible state or mode on the contract's security and functionality. Crafting the Quote Given the complexity outlined, the approach to quoting emphasizes the need for a thorough and time-intensive audit process. It's essential to allocate sufficient time to explore each of these areas deeply. This methodical approach is what sets apart more experienced auditors from those less familiar. It is possible that less experienced auditors will not only quote less because they are less known, more importantly, they might not realize what needs attention (and what not). This is exactly where this post aims to help: to raise awareness on what's important. When formulating your quote, consider: Time Allocation: Estimate the time required for each section of the audit. You don’t really want to be the one that underquoted a scope and then did a bad job. Expertise Required: Factor in the need for specialized knowledge, particularly for algorithms and math-heavy sections. Interactions with external protocols rely on proper knowledge of the underlying protocol.
Full break down of 3 Critical findings that can apply to any codebase: youtube.com/watch?v=N9VtIo…
Tour of the new design for @getreconxyz Looking forward to shipping this and a lot more! Join us next Thursday for a demo of our Pro Version!
If you want to learn Uniswap V2 read this book: Link: rareskills.io/uniswap-v2-book If you want to learn Compound V3 read this book: Link: rareskills.io/compound-v3-bo… If you want to learn Zero Knowledge read this book: Link: rareskills.io/zk-book If you want to learn Gas Optimization read this book: Link: rareskills.io/post/gas-optim… Thank you @RareSkills_io 🫡
I'm sharing a beautiful invoice template with you that you can use when sending to clients. It's a Figma file, so you can easily customize it to suit your own needs. Link below 👇
A great article about the different types of AMMs and the attack vectors associated with them. A lot to learn from it🫡 mirror.xyz/millietez.eth/…
Oracles are vital to the Web3 ecosystem as they feed real-world data to smart contracts. Here are the 3 types of oracles: 1. Push-based Oracle - Chainlink 2. Low latency Oracle - Pyth, RedStone 3. TWAP - Uniswap Let's take a look at each of them 🧵
What a great video breaking down the MultiChain Bridge Heist! youtube.com/watch?v=DuYews… Thank you @Jun1on for producing such high-quality easy to understand and engaging content 🫡
The upcoming Ethernaut CTF has great prizes ($7K over 2 days) 👀Theres a rumor that OpenZeppelin recruiters might look at the CTF leaderboards for Security Researcher candidates x.com/OpenZeppelin/s…
Get ready for the Ethernaut CTF! Do you have what it takes to secure first place? Starting 16/03, compete for: 💰 $7k cash prizes + Defender subscriptions 🔒 48h of unique blockchain challenges 🏆 A chance to earn special POAPs Register now at ctf.openzeppelin.com!
With so many resources available, it is important to filter the ones you need. I save interesting resources in a reading list and decide whether to delete them after reading. It helps me to quickly find something in a given topic. P.S. Should I make my list public?🤔
If you're auditing a protocol that uses Compound V3, you should read these papers! @RareSkills_io 🫡 1. The Architecture of the Compound V3 Smart Contract Link: rareskills.io/post/compound-… 2. DeFi Interest Rate Indexes Link: rareskills.io/post/defi-inte… 3. Understanding Collateral, Liquidations, and Reserves in Compound V3 Link: rareskills.io/post/compound-… 4. cUSDC V3 (Compound V3) as a non-standard Rebasing Token, CometExt.sol Link: rareskills.io/post/cusdc-v3-…
MelissaNorth @50tCm93m3Fy2UL7
27 Followers 1K Following
Wendy Bartles @WBartles97007
0 Followers 154 Following Recruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/nJCP62qxbN
محمود @atta38_mahmoud
9 Followers 359 Following
Tohatiez @tohatiez80284
60 Followers 969 Following
0xVlad @shtankova
356 Followers 1K Following I tweet about web3 tech, products and security Web3 and DeFi since 2016 Founder at FipeFinance Top auditor at @stronghold_dao
pratik.eth @eth_ethpratik
844 Followers 1K Following Bug Bounty hunter | Smart Contract Auditor | Private Audits l CVE 2022-36022 | CRTP | CRTO
Robert Wong @CryptoWong_LFG
337 Followers 2K Following Think Positive, Think Prosperity. Over 10 Years Investing. Multiple Business Owner. Making Money Online Is The Future. Join For Daily Microcap Gems
picaroloco @picaroloco1
48 Followers 618 Following En esta cuenta defendemos la criptografia fuerte y lean4
Or Duan @hacking_this
824 Followers 1K Following CTO @ Sayfer | White-hat Hacker 🚀 We are hiring! If you care about web3 security - talk with us!
Milus @Milus56218763
49 Followers 260 Following
Sipan V'artagnan ⚖�... @Hexen1337
6K Followers 3K Following Co-founder @hexens & @glider_xyz || https://t.co/qvK94LY8Fu 🦇🔊 Opinions are my own!
MEMEguy @MEMEguyCrypto
708 Followers 2K Following
Alexander @0xalexanderhg
757 Followers 1K Following Doing something new | @safaryclub | prev. @debridge
Julian Rachman @julrach
3K Followers 3K Following Building on-time instructed money @otimlabs, 7702 OG
Anurag Arjun @anuragarjun
89K Followers 1K Following Founder @AvailProject. Previously founder @0xPolygon. Building ShieldTX for shielded Hyperliquid perps - check out https://t.co/XPeVqncjVc to see who’s copying you
Jarry Xiao @jarxiao
13K Followers 1K Following architecting @PhoenixTrade | co-founder @ellipsis_labs
Hunter Horsley @HHorsley
83K Followers 4K Following CEO @Bitwise ($15B+ client assets). 8 years in crypto. Formerly Facebook, Instagram & Wharton. Husband, father, & caretaker of Winnie the beagle.
Ty.ai @TyPrompts
29K Followers 15K Following crypto class of 2017. @parabolicfamily advisor | @strykrai team | Varren studio Operator
Mason @masoncags
17K Followers 5K Following Your favorite degens favorite degen Co-founder, @CloverDigitalAI Ex: Deutsche Bank, Abstract, Wasabi.
Abril Zucchi @abrilzucchi
51K Followers 4K Following growth fundamentalist, part-time shitposter and sometimes writer. member of staff @usecorgi.
binji @binji_x
48K Followers 7K Following Post-Economic because @x pays me. Currently building @ethereum via @ethlabs_org. Previously built @ethereum via @ethereumfndn, @optimism & @coinbase.
Spirit DAO @spiritdao
18K Followers 115 Following A collective of entrepreneurs, collectors & investors
Dem (Animechain arc) @DemAzuki
33K Followers 5K Following Ecosystem Growth @animecoin | ex-Google | believe in something (you) 🔫(ò_ó )
Icedcoffee 🧊☕ @IcedcoffeeEth
36K Followers 3K Following Buy, Sell and Trade TCG One Piece, Pokemon, Gundam @icedtcg on IG HMU for whatever
superphiz.eth @superphiz
74K Followers 1K Following Ethereum Decentralization Advocate #stakefromhome
Hudson Jameson @hudsonjameson
58K Followers 4K Following I enjoy my cats, privacy tech, & ice cream. Now: @CertiK and @_SEAL_Org member Previous: Polygon, Ethereum Foundation, Flashbots, USAA, Zcash Poly/Bi 🏳️🌈
state @statelayer
49K Followers 1K Following
Lefteris Karapetsas @LefterisJP
73K Followers 814 Following Founder of @rotkiapp🐦, the portfolio tracker that protects your privacy. Berlin. University of Tokyo graduate. Marathon runner. software developer. birding.
𝕯𝖆𝖓𝖌𝖊�... @safetyth1rd
52K Followers 857 Following DeFi news: https://t.co/NnvZY0qVHE Risk Research: https://t.co/xjduIOOO5G Farming: https://t.co/ddnODYehqC
owockai @owocki
135K Followers 4K Following sisyphus at @gitcoin i spin bits 4 fun & profit, watch out for my megabyte
Ameen Soleimani @ameensol
47K Followers 12K Following coordination arms dealer @unchainiran @0xbowio https://t.co/mH2RCmSK73 @letsgethai @reflexerfinance @molochdao
nick.eth @nicksdjohnson
93K Followers 887 Following Lead developer of ENS & Ethereum Foundation alum. Certified rat tickler. he/him. bsky: https://t.co/RdZTUkWNq2 wc: https://t.co/nvP0lHPJqz
zak @0xzak
20K Followers 883 Following 👁️⃤ explorer in the further regions of experience ⃤⃟⃝ ㅤㅤ 𓆝 𓆟 𓆞 𓆝𓆝 𓆟 𓆞 𓆝ㅤㅤㅤㅤㅤ ☠︎︎ིྀ☠︎︎ིྀ☠︎︎ིྀ @numbergroupxyz ⫘⫘⫘ @ethcforg
Rood @0x_rood
29K Followers 348 Following Messy | Digital Nomad Lifestyle 💎 | Not doing collabs, not selling courses
N$🌟 @__nav1n_
29K Followers 266 Following Security | Web & Mobile Pentesting | Infrastructure & AI | Bug Bounty Hunter | 2× Microsoft MVR @msftsecurity | Cricket 🏏 https://t.co/4rFXYywxXA
payloadartist @payloadartist
46K Followers 292 Following I discuss AI, Cybersecurity & Hacking • Helped secure organizations like Google • Opinions are my cat's • Part-time shitposter
Abhishek @aacle_
50K Followers 292 Following Building @Vulncure ⚡| Helping founders fix vulnerabilities before hackers find them. Talk to me about: Bug Bounties, LLM Security & React.
Sam Curry @samwcyo
102K Followers 1K Following
Joseph Thacker @rez0__
74K Followers 1K Following christian. father. hacker. founder. advisor. podcast: https://t.co/1aFavJN2h8 blog: https://t.co/JBPT1CJWJH products: 💻 https://t.co/iPdpsEAc1h 🤖 https://t.co/EVhQl8HTlp 📚 https://t.co/MMmhw0cnaz
JS0N Haddix @Jhaddix
180K Followers 7K Following CEO, Trainer, Hacker, and Speaker. Cybersecurity + Hacking + AI + Sec Leadership @arcanuminfosec
PentesterLab @PentesterLab
209K Followers 0 Following Don’t just learn tools and payloads. Learn why vulnerabilities exist. Hands-on web hacking, security code review, and real-world CVE labs.
🇷🇴 cristi @CristiVlad25
56K Followers 784 Following
Tarek @Conan0x3
2K Followers 776 Following Smart Contract Auditor @code4rena | Offensive Security Consultant | OS(EP/WE/CP) and others.. DM for private audits.
soap.rwo @s04p_
19K Followers 4K Following ¯\_(ツ)_/¯ REMILIA WORLD ORDER | milady | ^-^ Copper alchemist | DM to order the green exchange @ourbit https://t.co/NgLh6Fkgid
Arrogant 🔺 @AvaxArrogant
16K Followers 8K Following BTC since 2009 We are Web3 Artist - Dev - Creator - Advisor Avalanche Network - Art & NFTs
Wolfi Land 🔺 @wolfilandnfts
11K Followers 623 Following AVAX Mascot $Wolfi | First official NFT project of Wolfi, the most popular mascot of Avalanche | $Wolfi CA: 0x5DDc8d968a94cf95CfeB7379F8372d858B9C797d
Coop⏱️ @coopernicus01
37K Followers 4K Following Previously @avalabs marketing, currently enjoying life
E MoNeY BaGs 🩸 @1EMoNeYBaGs
17K Followers 3K Following




































