Security engineer @CertiK | Prev. MetaTrustLabs, CertiK | on-chain hack analysis | Saved $200K tokens from a CEX hack

Blockchain
#EVMCortex An ethereum protocol engineering squad for AI coding assistants. 50 #agents, 94 #skills, 19 hooks, and 15 rules covering #Solidity development, #security auditing, DeFi integration, testing, and deployment from #Chris, a full-stack dev @Uniswap github.com/ccashwell/evm-cor…
🚨Solidity Devs - this awesome repository has 50 agents, 91 skills and 19 hooks for Solidity development, deployment, testing and security Built & compiled by a Uniswap Senior Engineer. Use this for higher quality development, MIT license🫡 github.com/ccashwell/evm-cor…
3
244
#AIMath What if Math is resolved? An 87-year-old core #mathematics problem, the #jacobian conjecture, was casually solved by #Fable 5 on a Sunday evening.
Math is solved.
1
194
crypto.training/ A wonderful site for crypto Training for web3 security engineering, Solidity, and EVM internals. #Web3Security #SmartContract #Audit #Vulnerability
1,100+ runnable EVM exploits — live on crypto.training We’ve crossed 1,100 fully runnable exploit PoCs on crypto.training/hacks. That’s not a list of write-ups or a folder of Solidity files that might compile. Each one is a self-contained, offline-reproducible Foundry PoC you can open in the browser and actually execute — historical DeFi hacks and high-severity audit findings reduced to faithful synthetics. I believe this is the largest public collection of runnable EVM exploits in the world. If you learn security by reading blogs, you get the story. If you step the bytecode, you get the mechanism. What makes the playground different Every hack page can load an in-browser EVM (no backend, no fork server required for the interactive path). The killer features: ✅ Opcode-by-opcode debugging — step, reverse-step, and jump through the real execution trace of the exploit, not a simplified animation ✅ Full EVM state at every step — stack, memory, storage, call depth, and program counter, in sync with the opcode you’re on ✅ Balances panel — watch native currency, ERC-20, ERC-721, and ERC-1155 update as money moves: who was paid, who was drained, at which step ✅ “Go to vulnerability” — jump straight to the blamed source line in the vulnerable contract (real @> lines preserved for audit findings) ✅ “Watch exploit live” — story beats that walk setup → trigger → harm, each tied to executed lines in the trace ✅ Labeled call tree — see contracts by name, not only bare addresses ✅ Same PoC offline — download the analyzer ZIP / registry package and run forge test with no network when you want the Foundry path What’s in the corpus ➡ Hundreds of historical DeFi incidents (the classic SunSec / DeFiHackLabs lineage and beyond) ➡ Hundreds of audit findings from AuditVault / contest reports — reduced to local-deploy synthetics that still demonstrate real harm ➡ One pipeline end-to-end: registry PoC → playground config → verified recording → page → analyzer ZIP Why this matters for auditors and builders ✅ Train on mechanisms, not just CVE titles ✅ Compare how the same bug class shows up across protocols ✅ Teach juniors with a debugger instead of a wall of prose ✅ Re-run and modify PoCs locally when you want to go deeper Open any page on crypto.training/hacks, hit the playground, and step the exploit yourself. Open source tooling: github.com/sanbir/evm-hack-a… Feedback, corrections, and new PoCs welcome. #Web3Security #SmartContractAudit #DeFi #Ethereum #EVM #SecurityResearch #OpenSource #Solidity #BugBounty
2
218
#KelpDAO has paused rsETH contracts across mainnet and several L2s.
Earlier today we identified suspicious cross-chain activity involving rsETH. We have paused rsETH contracts across mainnet and several L2s while we investigate. We are working with @LayerZero_Core, @unichain, our auditors and top security experts on RCA. We will keep you posted as we learn more about this situation. Please follow only the official @KelpDAO handle for the updates.
139
#RheaFiance $7.6M hack. A hacker added liquidity in fresh pools with fake tokens to mislead the oracle and validation layer.
#CertiKInsight 🚨 We have seen an incident affecting @rhea_finance The attacker created fake token contracts and added liquidity in fresh pools, likely misleading the oracle and validation layer. In total, at least ~$7.6M was extracted nearblocks.io/address/31ac7a…
1
2
226
#Tether has froze 3.29M USDT to the hackers. nitter.net/paoloardoino/status/20… Rhea Fiance has temporarily paused the contracts and are conducting a thorough investigation.
The RHEA team is aware of an incident affecting the protocol. As a precautionary measure, we have temporarily paused the contracts while we conduct a thorough investigation. We are working closely with key partners, stakeholders, and security experts. Protecting user positions is our immediate priority, and our team is focused on minimizing any potential impact. RHEA team has reached out to the responsible party through on chain transaction. nearblocks.io/txns/6r5c2iZig…
3
139
Daniel Tan retweeted
#CertiKStatsAlert 🚨 @DriftProtocol seems to be a victim of an exploit for ~$136M losses. Funds are currently being laundered or moved. ~$109M in wallet 7RoMqGAcU7S6ESAhPDvB9iSXvASUhuoE8u7dYRxGBew9 solscan.io/account/7RoMqGAcU… Stay vigilant!
6
15
26
6,587
#AAVEMisconfig A misconfiguration on Aave's CAPO oracle caused wstETH E-Mode liquidations, resulting in a loss of 345 $ETH.
1/ stETH CAPO Misconfiguration Today, a misconfiguration on Aave's CAPO oracle caused wstETH E-Mode liquidations, resulting in a loss of 345 ETH. No bad debt was incurred, and all affected users will be fully reimbursed. More below.
1
196
#ZKVerifierBug on March 10th, the @CertiK Sr. Staff Security Engineer, #XifengJin, will dive into the ZK verifier attack patterns targeting DSL circuits, zkVMs, and proving systems with practical mitigation insights, in the X Space. #CertiK #ZKVM #DSLCircuit #Audit
As ZK adoption accelerates, verifier-side security is increasingly critical. In this X Space, CertiK Sr. Staff Security Engineer Xifeng Jin examines attack patterns targeting DSL circuits, zkVMs, and proving systems with practical mitigation insights. Set a reminder below👇
1
259
A high-level perspective to look at the security in #zkcircuits that abstracts away from specific languages and proving system docs.google.com/presentation…
46
#Makina $4M #PriceManipulation hack. The MIM-3CRV pool was manipulated by inflating the MIM price through a flashloan, which affects DUSD Caliber to reflect an inflated value, then propagated to the Machine AUM, the DUSD exchange rate, and ultimately to the DUSD/USDC Curve pool.
1
338
#TruebitProtocol exploit. The root cause of this $26M hack was that the price calculation #overflow and was manipulated. In the vulnerable smart contract, the SafeMath library is not used, and the Solidity version 0.8.0 or higher is also not used.
#CertiKInsight 🚨 On 8 January 2026, @Truebitprotocol was exploited due to an overflow issue, resulting in a loss of ~$26.6M. To learn more about what happened, read our full analysis here 👇 certik.com/resources/blog/tr…
345
#Top10HacksIn2025 1⃣Bybit Supply Chain $1.46B Attack On Feb 21, 2025, #Bybit suffered the largest single hack in web3 history, losing $1.46B, due to the North Korean #LazarusGroup executing a supply chain attack, compromising a Safe Wallet developer's machine.
You’ve read the stats. Now see the scale. This video from the 2025 Skynet Hack3d Report brings Web3’s most critical security data into focus. Watch the key trends that defined the year.
1
1
407
🔟GMX Reentrancy $42M Exploit On Jul 15, 2025, #GMX V1 lost $42M to a reentrancy attack. Ironically, the vulnerability was introduced by the team's own 2022 bug fix, which lacked proper audit. The hacker exploited a time gap in price updates. Most funds were later returned.
1
180