🐸Smart🐸Contract🐸Programmer🐸 retweeted
Some news: I’m no longer at Aztec following the recent restructuring I’m on the hunt for a new role in DevRel or technical sales, so if you’re hiring, reach out! In the meantime, I will be getting back to making videos again after a much needed rest 🩷
22
14
247
15,809
🐸Smart🐸Contract🐸Programmer🐸 retweeted
If you don't know the current situation in @code4rena, here is the brief: Code4rena hosted K2 competition, which was the last one before announcing a winding down. After distributing rewards to participants and sending judging fees, two SRs, @MaxZuvex and @0xArav, found what appears to be a Sybil attack. They found that two wardens created their accounts days before the competition ended and submitted findings clearly copied from other wardens' work. One submission belonged to a less-duplicated issue group, which increases their profit, and the other one was a QA report that resembles another warden's QA report and got 1st place. Code4rena Team believes that the Judger is the one responsible for this, as he was one of the few people who had access to the submission before closing. Code4rena was able to recover funds from these 2 newly created accounts (propabbly as KYC process and newly created account payout delays). Code4rena asked the Judger to return the funds, but he has not responded to date. C4 head judge will review the issues, remove duplicate sybil issues, review QA reports, and post the final result, and wardens will receive the amount deducted from their reward.
9
4
101
10,194
🐸Smart🐸Contract🐸Programmer🐸 retweeted
Every SR who's ever submitted a finding in contests/bounties has operated on the same quiet assumption - *hope the privileged roles dont rip you off* this was one of those rare incidents that showed.. such assumptions are assumptions after all K2 was Code4renas' last ever contest, hours after the report was made public - @MaxZuvex and I observed some things - that were too good to be just coincidences after some digging, we found more and more undeniable proofs that all pointed to an exploit by none other than - the judge of the contest this contest also had one of the highest Judging rewards $9.5k - and apparently that wasnt enough we'll withdraw from sharing further as this could've been a rare mistake by the individual. In truth however- this is more than any single person, recording such incidents in public is how better systems can evolve. Respect to the C4 team (esp Cloudellie / Bytes32) for being supportive throughout and handling it with real transparency "The happy ending we want to celebrate is that in the end, it was members of the Code4rena community who stood up and called out misbehaviour, and helped us make things right." peace _/\_
1
4
46
1,993
🐸Smart🐸Contract🐸Programmer🐸 retweeted
We just can't stop learning new stuff every day 🤯 ... I thought my list of forcefully sending ETH to smart contract was complete, but apparently not: 1. SELFDESTRUCT opCode — can select a smart contract to receive the ETH balance of another smart contract. No receive() triggered. 2. Pre-deployment — If we are able to calculate the smart contract address before the deployment time we can fund it with ETH. Deploying with non-zero balance isn't going to revert. 3. Crediting the block priority fees — the validator who is the current block producer can place a smart contract address to receive the block priority fees. No receive() triggered. And now adding 4. as explained by @ProgrammerSmart's tweet. thank you ser 🫡
How to send ETH to any address without SELFDESTRUCT? 1. Deposit 32 ETH, create a validator with withdraw credential set to the target address 2. Exit the validator (not EIP 7002 request) 3. 32 ETH + rewards sent to target (silently, no fallback triggered)
2
1
698
🐸Smart🐸Contract🐸Programmer🐸 retweeted
Replying to @windhustler
They should investigate all team mates that had access to the reports Not only dadekuma. Cos why do you assume he is the culprit. Protocol team can be the one because what stops them from doing this to dilute the pot. We have seen instances that teams downplay just no to pay
2
2
10
1,915
How to send ETH to any address without SELFDESTRUCT? 1. Deposit 32 ETH, create a validator with withdraw credential set to the target address 2. Exit the validator (not EIP 7002 request) 3. 32 ETH + rewards sent to target (silently, no fallback triggered)
5
8
132
11,141
🐸Smart🐸Contract🐸Programmer🐸 retweeted
We are hiring a security researcher at @aave Join us to review our smart contracts, build our AI-assisted tools, and help secure the ecosystem You will work directly with me, have room to experiment, and develop new approaches as our industry evolves aave.com/careers/protocol-se…
16
21
241
45,603
🐸Smart🐸Contract🐸Programmer🐸 retweeted
🚨 Web3 security researchers, STOP SCROLLING. This entire playlist is FREE. 8 deep dives into auditing, stateful fuzzing, formal verification, L2 + bridge security, ZK circuits and more. This is hours of serious security education. SAVE IT. piped.video/playlist?list=PL…
4
35
209
9,373
In Solidity, is it possible to craft a memory array of length 2**256 - 1? Yes -> if function that creates the array is an internal call No -> if function call is external. Reverts with out of gas error. Code github.com/t4sk/notes/blob/m…
2
4
64
3,680
🐸Smart🐸Contract🐸Programmer🐸 retweeted
What the fuck is up with contest platforms??
7
8
113
6,519
🐸Smart🐸Contract🐸Programmer🐸 retweeted
The single most powerful habit in Web3 Security Reading the code I’ve spent 2+ years and read +220.000 lines of DeFi & Blockchain code finding the most effective way to uncover bugs Here’s what I’ve found:
6
22
179
8,290
Math for vault and rebase token (like SUSDS and aToken) calculate the same redeemable amount with different mechanisms. But in code, precision loss causes these 2 ways of calculations to diverge. Notes github.com/t4sk/notes?tab=re… Code github.com/t4sk/notes/blob/m…
5
19
130
5,137
🐸Smart🐸Contract🐸Programmer🐸 retweeted
Found a bug that allows 2,677 CVX loss, about $6,000 depositors funds at risk. Anyone can: 1. Manipulate the protocol zap contract 2. Call a permissionless function 3. Reverse the price and walk away with $6k I responsibly disclosed the bug to the team, guess what happened?
11
8
136
12,757
txgraph.org/ - Visualize transaction - Compiles and visualizes Solidity contracts - Code navigation if contract compiled
4
10
101
6,152
I've received a fake job recruitment email from zendarox Here are some things I do before clicking on any link. 1. Background check (google the company) 2. Hover over link to see if it matches text 3. Open links in browser's private mode Stay safe
17
4
67
4,914
🐸Smart🐸Contract🐸Programmer🐸 retweeted
we are interested in talking to exceptional candidates for the following roles: ∙ Platform Engineer ∙ Systems Engineer, Transaction Landing ∙ Senior MEV Research Engineer ∙ Data Engineer, Accounting apply here: go.temporal.xyz/apply
3
8
101
8,484
🐸Smart🐸Contract🐸Programmer🐸 retweeted
I’m looking for a react native engineer fully remote US/Europe. 250k-300k usd + equity And a back end engineer who’s an expert in building trading terminals or trading platforms. Node, typescript and (rust or go). 250-300k USD base + equity DMs open
33
9
191
10,240
🐸Smart🐸Contract🐸Programmer🐸 retweeted
🚨 Beware of scams! @ensdomains
1
1
16
942