Co-Founder @ShieldifySec Taking your smart contracts' security seriously!

Client: "We've made some small changes to the contract, shouldn't affect the audit scope" The small change: - added 2000 lines of code - new oracle - new bridge - upgradeable now
3
2
17
755
Martin retweeted
Building on Robinhood Chain? 🤔 Almost no protocols running bug bounties. If you’re launching on a new chain, security should be part of the launch. Fortunately, there have been no protocol hacks on RH Chain so far. We’re working with teams across the eco to keep it that way.
2
7
314
Want to connect with more auditors in our circle 🫡 If you do security reviews, comment below and tell us your main stack (Solidity, Rust, Move, something else)?
29
4
61
2,031
Every exploit postmortem starts with "We take security very seriously" Ours start with "Found Critical before launch" 😈
1
3
14
638
Martin retweeted
We’ve worked with around 15 BDs. What separates the ones who deliver? Constant dedication, knowing they’ll get rejected. The losers quit after the first round of refusals. The BDs who win on our team make 5 figures. The ones who quit don’t. 🫡
2
1
4
339
New audit partnership with @shroomsdotfun 🤝 Shrooms Fun gives token and NFT communities a home on Robinhood, with holder gated rooms, in-app trading, tipping and a launchpad built in 🍄 Audit report coming soon! 🤫
1
3
31
5,462
"We'll get an audit after launch" Famous last words, right up there with "the admin key is safe on my laptop" and "nobody's going to call that function directly" 🫤
1
3
15
935
The bear market is over, be ready! ✌🏻
3
3
36
1,498
New audit in the Hyperliquid ecosystem: @pear_protocol 🤝 We reviewed their ERC-4626 vault and the off-chain logic behind it. Vault accounting, share math, access control, and how off-chain and on-chain interact. Reports are out. Great working with the Pear team👇 1) github.com/shieldify-securit… 2) github.com/shieldify-securit…
7
11
39
5,397
Martin retweeted
Solid Audit by Shieldify , Take a look 👀
A new audit report for @TopazDex, but this time for their V2 🫡 This one covers the multichain xTOPAZ extension: veTOPAZ wrapped into a fungible share token on BNB, a LayerZero OFT mesh, and spoke chains voting for local gauges with staked xTOPAZ. Read the full report 👇 github.com/shieldify-securit…
1
6
17
360
A new audit report for @TopazDex, but this time for their V2 🫡 This one covers the multichain xTOPAZ extension: veTOPAZ wrapped into a fungible share token on BNB, a LayerZero OFT mesh, and spoke chains voting for local gauges with staked xTOPAZ. Read the full report 👇 github.com/shieldify-securit…
4
4
16
1,192
Building systems that help with security and prevent protocols from being drained. That's it.
1
4
305
Next bull run is going to be huge for security researchers 🫡
6
7
50
1,547
Downgrading a finding doesn't downgrade the risk. The label changes; the attack path doesn't
1
4
10
698
How should a new, self-funded protocol approach security? 1. Internal audit 2. Document everything + fuzz test 3. Run multiple AI agents, triage findings 4. Get our experienced researchers to handle the manual audit 5. Fix everything & deploy safely
1
11
429
Two security reports submitted today. 109 and 29 pages packed with insights and bugs that could have put real user funds at risk. Stay safe. Invest in security 🫡
1
9
385
Another one for the Robinhood ecosystem. Shieldify's audit report for @offyield is now public. Thanks for the trust, keep shipping 🫡 🟡 For more details, check out the report at 👇 github.com/shieldify-securit…
New audit partnership with @offyield 🤝 OffYield is the first neobank on Robinhood where your yield pays the bills, not you ☝️ Audit report coming soon!
1
2
12
2,603
Martin retweeted
Wrong target, SRs are good at catching bugs, scammers too 🫡
Got targeted today by what looks like a fake audit/recruitment campaign. They opened the conversation by linking my Cantina profile and asking if I was looking for new opportunities. At first it looked like a normal audit lead. They said they were building an RWA protocol and needed a smart contract auditor. I asked what chain. “EVM” I told them I mainly audit Solana/Rust, so I probably wasn’t a good fit. A minute later it became “actually multi-chain,” and they sent me a tech stack full of Solana/Rust, Anchor, SPL, PDA/CPI, Metaplex, etc. They were also very pushy about getting on a call immediately, followed by NDA signing and private GitHub access. I kept asking for the company/project details first. Eventually they gave me chainvisita.tech. ChainVisita has already been publicly documented in a fake developer recruitment campaign where targets were given malicious repositories that downloaded a second-stage stealer targeting browser credentials and crypto wallets. So if you get a similar audit offer, especially one tailored around your public security profile and quickly leading to a private repo, be careful. blog.nivel4.com/investigacio…
1
12
574