🐸Smart🐸Contract🐸Programmer🐸 retweeted
Some news: I’m no longer at Aztec following the recent restructuring I’m on the hunt for a new role in DevRel or technical sales, so if you’re hiring, reach out! In the meantime, I will be getting back to making videos again after a much needed rest 🩷
28
17
295
19,822
🐸Smart🐸Contract🐸Programmer🐸 retweeted
If you don't know the current situation in @code4rena, here is the brief: Code4rena hosted K2 competition, which was the last one before announcing a winding down. After distributing rewards to participants and sending judging fees, two SRs, @MaxZuvex and @0xArav, found what appears to be a Sybil attack. They found that two wardens created their accounts days before the competition ended and submitted findings clearly copied from other wardens' work. One submission belonged to a less-duplicated issue group, which increases their profit, and the other one was a QA report that resembles another warden's QA report and got 1st place. Code4rena Team believes that the Judger is the one responsible for this, as he was one of the few people who had access to the submission before closing. Code4rena was able to recover funds from these 2 newly created accounts (propabbly as KYC process and newly created account payout delays). Code4rena asked the Judger to return the funds, but he has not responded to date. C4 head judge will review the issues, remove duplicate sybil issues, review QA reports, and post the final result, and wardens will receive the amount deducted from their reward.
9
4
101
10,211
🐸Smart🐸Contract🐸Programmer🐸 retweeted
Every SR who's ever submitted a finding in contests/bounties has operated on the same quiet assumption - *hope the privileged roles dont rip you off* this was one of those rare incidents that showed.. such assumptions are assumptions after all K2 was Code4renas' last ever contest, hours after the report was made public - @MaxZuvex and I observed some things - that were too good to be just coincidences after some digging, we found more and more undeniable proofs that all pointed to an exploit by none other than - the judge of the contest this contest also had one of the highest Judging rewards $9.5k - and apparently that wasnt enough we'll withdraw from sharing further as this could've been a rare mistake by the individual. In truth however- this is more than any single person, recording such incidents in public is how better systems can evolve. Respect to the C4 team (esp Cloudellie / Bytes32) for being supportive throughout and handling it with real transparency "The happy ending we want to celebrate is that in the end, it was members of the Code4rena community who stood up and called out misbehaviour, and helped us make things right." peace _/\_
1
4
46
1,993
🐸Smart🐸Contract🐸Programmer🐸 retweeted
We just can't stop learning new stuff every day 🤯 ... I thought my list of forcefully sending ETH to smart contract was complete, but apparently not: 1. SELFDESTRUCT opCode — can select a smart contract to receive the ETH balance of another smart contract. No receive() triggered. 2. Pre-deployment — If we are able to calculate the smart contract address before the deployment time we can fund it with ETH. Deploying with non-zero balance isn't going to revert. 3. Crediting the block priority fees — the validator who is the current block producer can place a smart contract address to receive the block priority fees. No receive() triggered. And now adding 4. as explained by @ProgrammerSmart's tweet. thank you ser 🫡
How to send ETH to any address without SELFDESTRUCT? 1. Deposit 32 ETH, create a validator with withdraw credential set to the target address 2. Exit the validator (not EIP 7002 request) 3. 32 ETH + rewards sent to target (silently, no fallback triggered)
2
1
703
🐸Smart🐸Contract🐸Programmer🐸 retweeted
Replying to @windhustler
They should investigate all team mates that had access to the reports Not only dadekuma. Cos why do you assume he is the culprit. Protocol team can be the one because what stops them from doing this to dilute the pot. We have seen instances that teams downplay just no to pay
2
2
10
1,915
How to send ETH to any address without SELFDESTRUCT? 1. Deposit 32 ETH, create a validator with withdraw credential set to the target address 2. Exit the validator (not EIP 7002 request) 3. 32 ETH + rewards sent to target (silently, no fallback triggered)
5
8
132
11,147
using a validator as a transfer rail is insane overhead just to dodge a fallback. 32 ETH min is a lot of extra steps to send what you could just send, but i respect the spite lol
1
2
709
Unlike selfdestruct, this won't be recorded as a transaction on etherscan
1
11
747
Is this chart the least biased metric to answer "should I get into web3 security or is it too late" ? Feb: 4200 laid off May: 690 June: 1029 July: 944 -- August: 27 September: 60 What do you think?
1
4
933
I see the data as which companies to be wary of applying for a job Should you became a web3 SR? I would ask 2 questions What skills do I need? Read the descriptions for the open SR roles to understand the skills in demand. How much time and money do I have?
4
387
🐸Smart🐸Contract🐸Programmer🐸 retweeted
We are hiring a security researcher at @aave Join us to review our smart contracts, build our AI-assisted tools, and help secure the ecosystem You will work directly with me, have room to experiment, and develop new approaches as our industry evolves aave.com/careers/protocol-se…
16
21
241
45,612
🐸Smart🐸Contract🐸Programmer🐸 retweeted
🚨 Web3 security researchers, STOP SCROLLING. This entire playlist is FREE. 8 deep dives into auditing, stateful fuzzing, formal verification, L2 + bridge security, ZK circuits and more. This is hours of serious security education. SAVE IT. piped.video/playlist?list=PL…
4
35
209
9,381
In Solidity, is it possible to craft a memory array of length 2**256 - 1? Yes -> if function that creates the array is an internal call No -> if function call is external. Reverts with out of gas error. Code github.com/t4sk/notes/blob/m…
2
4
64
3,681
Bound-checking only at the external entry point misses this. Anything downstream that trusts the array size inherits the same false state.
1
1
90
🐸Smart🐸Contract🐸Programmer🐸 retweeted
What the fuck is up with contest platforms??
7
8
113
6,521
🐸Smart🐸Contract🐸Programmer🐸 retweeted
The single most powerful habit in Web3 Security Reading the code I’ve spent 2+ years and read +220.000 lines of DeFi & Blockchain code finding the most effective way to uncover bugs Here’s what I’ve found:
6
22
179
8,293
Math for vault and rebase token (like SUSDS and aToken) calculate the same redeemable amount with different mechanisms. But in code, precision loss causes these 2 ways of calculations to diverge. Notes github.com/t4sk/notes?tab=re… Code github.com/t4sk/notes/blob/m…
5
19
130
5,139
you are one of the best persons I know in the world of smart contract and defi,thanks so much,would love to have a conversation with you sir
1
1
35
🐸Smart🐸Contract🐸Programmer🐸 retweeted
Found a bug that allows 2,677 CVX loss, about $6,000 depositors funds at risk. Anyone can: 1. Manipulate the protocol zap contract 2. Call a permissionless function 3. Reverse the price and walk away with $6k I responsibly disclosed the bug to the team, guess what happened?
11
8
136
12,758
txgraph.org/ - Visualize transaction - Compiles and visualizes Solidity contracts - Code navigation if contract compiled
4
10
101
6,153