Another day, another win! 🏆
I’ve managed to find a High vulnerability in one of the biggest projects in the web3 space @usualmoney!
Thanks for the opportunity 🫡@sherlockdefi
If you want me to secure your protocol, don’t hesitate to contact me! 🔥
When reaching out to protocols about an audit, follow three simple rules: 👇
1) Lead with value. Offer to help—don’t pressure them into getting an audit. 🫡
2) Respect their decision. If they’re not interested or have already completed an audit, don’t keep pushing. 🕹️
3) Keep the door open. A “no” today doesn’t mean “no” forever. Leave a positive impression and let them reach out when the timing is right. 🚀
Good outreach is about building relationships, not forcing a sale. 🍎
Most audits still stop at the contract.
The bug that actually drains you is usually one layer outside it. A signer that got shown the wrong payload. An upgrade that looked fine until storage moved. A helper contract nobody re-read after the last change.
We keep finding those at @DefendersAudits. Not because the code is ugly. Because the path around it is.
If your review ends when the functions look clean, you’re only half done.
This is a dataset of over 20000+ security findings. It includes everything you need: severity, description, POC. It was provided by @RightNowInhuggingface.co/datasets/Zaev…
🚨 Web3 Builder 🚨
"No audit needed—our team's GOAT! 🐐
*2 weeks later:* Protocol rekt, funds vaporized. 💥😩
Stat: 80% of hacked DeFi protocols were UNAUDITED. Lesson: Audits save asses. Get one or get gone. 👇
#DeFi#Crypto#Web3Security
How should a Web3 security researcher behave?
⏰ Be on time. 📩 Be responsive. If someone asks for a quote, get back to them ASAP. 🔍 Own your findings. Be ready to explain and defend your work. 🤝 Be available when the protocol owner needs you. 🗣️ Communicate clearly. 💯 Be reliable. Do what you said you’d do.
Security research isn’t just about finding bugs.
It’s about being someone protocols can trust.
The biggest unlock in Web3 right now isn't just digital—it's physical. 🌍⛓️
RWA (Real-World Asset) tokenization is bridging TradFi and DeFi by bringing real estate, treasury bonds, art, and commodities on-chain.
Why it matters:
💧 Massive liquidity for traditionally illiquid assets
🧩 Fractional ownership that lowers the barrier to entry
🌐 24/7 borderless markets with instant settlement
The multi-trillion-dollar traditional finance market is slowly moving on-chain.
#RWA#Web3#Tokenization#DeFi
While everyone was busy celebrating Bitcoin’s sprint back to $87K, the rest of crypto had a rough few days: 🚀
Bitget just got drained for $352M.
KelpDAO is now suing LayerZero over that $292M April bridge exploit.
Classic crypto week. 😩
Two years since I watched my first Web3 security video from PatrickAlphaC (@PatrickAlphaC).
That single video completely shifted how I viewed smart contracts — it opened my eyes to the critical importance of security and sparked my deep dive into auditing. 🤿
Two years later, the difference is night and day! 🔥
Today I get hands on experience with Opus 5.5 and I see improvements in the token efficiency and pricing. Also it is much better at coding than Opus 5.0. 🚀
Here is a good article comparing the benchamarks:
vellum.ai/blog/claude-opus-5…
As an auditor, you should not fully rely on AI for findings. You should verify every finding and be 100% sure about it before adding it to the report.🐞
Today I get hands on experience with Opus 5.5 and I see improvements in the token efficiency and pricing. Also it is much better at coding than Opus 5.0. 🚀
Here is a good article comparing the benchamarks:
vellum.ai/blog/claude-opus-5…
Most Uniswap v4 hook bugs aren't clever exploits. They're basic assumptions nobody checked. 🧵
Here's how I audit hooks, in the order I'd actually do it:
9/ Oracle hooks: assume flash loans.
If a price can be moved and read in the same block, it will be. Check manipulation resistance and observation cardinality.
10/ Admin keys and upgradeability.
A proxy hook that can change its implementation breaks the whole address-bit permission model. Flag every privileged role, and ask what a compromised key could do.