Web3 enthusiast & Solidity dev crafting secure smart contracts. Solidity & Security Journey | @CyfrinUpdraft alumni

.eth
I'm building LogicProbe. An AI assisted system for detecting vulnerabilities in modern Solidity smart contracts. I've been building quietly, but today I'm starting to share the journey publicly. Here's what I've built from Day 1 to today ๐Ÿงต
1
1
3
147
๐€๐›๐›๐š.๐ž๐ญ๐ก retweeted
4 ways to get audit experience with zero clients: โ€ข Free audits you ask teams for โ€ข Bug bounties, paid or not โ€ข Public contests โ€ข CTFs Collect your real bugs in one public portfolio. Then message the firms yourself.
3
5
54
1,336
๐€๐›๐›๐š.๐ž๐ญ๐ก retweeted
โœ… [New DualDefense Audit Contest] A fresh challenge just dropped on HackenProof! The DualDefense Audit Contest with @DOI_Ecosystem is now live. Reward pool: Up to $3,000 End Date: October 26, 2026 Scope: Smart contract Last Audit: by @hackenclub Join the contest now! hackenproof.com/audit-prograโ€ฆ
3
14
1,337
๐€๐›๐›๐š.๐ž๐ญ๐ก retweeted
This article is very interesting for designing your own AI tooling for BB hunting: use /goal instead of the attack vector. Use the impacts accepted by the BB program and create a goal around reaching them. Instead of going from attack vector โ†’ impact. Try going from impact โ†’ attack path. Go from zoomIn instead of zoomOut. blog.trailofbits.com/2026/07โ€ฆ
2
17
128
5,111
๐€๐›๐›๐š.๐ž๐ญ๐ก retweeted
If I started auditing from zero tomorrow: I wouldn't read more reports. I wouldn't wait for a contest. I wouldn't DM firms. I'd do these 4 things:
4
8
122
4,767
Day 8 of Building LogicProbe Today I worked deeper on the hardest part of smart contract vulnerability detection: semantics. A simple rule like: external call + state write = reentrancy creates too many false positives. So Iโ€™m teaching LogicProbe to distinguish: โ€ข State changing interactions โ€ข Read only calls โ€ข Read only calls used for control flow โ€ข Persistent storage writes โ€ข Reentrancy guards โ€ข Call/write ordering I also tested multiline require, assert, if, while, compound conditions, and caststyle ERC20 calls. the regression tests passed the goal isn't just to build a model with a good score. the goal is to build a system whose security evidence actually makes sense to a human auditor Still building
18
Day - 7 Back to building after being offline for a couple of days because I was on transit. What I have achieved so far today for the LogicProbe โ€” AI Business Logic Vulnerability Detector. Continued Phase 2B reentrancy research and built V4.7 as a controlled development experiment. ๐Ÿ”น Improved nested Solidity storage-write detection ๐Ÿ”น Detected previously missed nested mapping writes ๐Ÿ”น Filtered obvious read-only calls like balanceOf() from reentrancy interaction signals ๐Ÿ”น Ran targeted regression tests across 5 reviewed cases ๐Ÿ”น Ran the full 2,395 contract Solidity 0.8 compatible development population ๐Ÿ”น Kept the frozen V4.6 baseline untouched Current V4.7 inventory: โ€ข 2,395 contracts โ€ข 134,918 functions analyzed โ€ข 324 records with persistent writes โ€ข 252 records with guards โ€ข 0 source records missing Indeed the these numbers are detector evidence, not proof of improved vulnerability detection. One step at a time... LogicProbe continues.....
1
1
57
๐€๐›๐›๐š.๐ž๐ญ๐ก retweeted
๐ŸšจSOLIDITY-AUDITOR V4 IS NOW OPEN SOURCE (MIT LICENSE) A single command now gets up to 85% recall on High severity findings from multi-week contests from last year. This used to cost protocols tens of thousands - we made it FREE, so any dev can build more safely. by PAG team๐Ÿซก
48
67
516
44,519
๐€๐›๐›๐š.๐ž๐ญ๐ก retweeted
็ป™ Claude ๆณจๅ…ฅ็‰นๅฎš็š„ SKILL.md๏ผŒๅฎƒๅฐฑ่ƒฝไปŽๆ™ฎ้€š็š„่ŠๅคฉๅŠฉ็†๏ผŒๅ˜่บซ็ฒพ้€š SQLiใ€EDR ็ป•่ฟ‡ๅ’ŒๆผๆดžๆŒ–ๆŽ˜็š„็บข้˜Ÿไธ“ๅฎถใ€‚ ่ฟ‘ๆœŸๅœจ GitHub ๆ–ฉ่Žท 6.2k Stars ็š„ๅผ€ๆบ้กน็›ฎ claude-red๏ผŒไธ“้—จไธบ Claude ๅปบ็ซ‹ไบ†ไธ€ไธชโ€œ่ฟ›ๆ”ปๆ€งๅฎ‰ๅ…จๆŠ€่ƒฝๅบ“โ€ใ€‚ๅฎƒ้€š่ฟ‡็ป“ๆž„ๅŒ–็š„ๆ็คบ่ฏๆ–‡ไปถ๏ผŒ่ฎฉ AI ๆŽŒๆกๆทฑๅบฆ็š„ๆธ—้€ๆต‹่ฏ•ๆ–นๆณ•่ฎบใ€‚ ๆ ธๅฟƒ็‰นๅพ๏ผš โ€ข 78 ไธช็‹ฌ็ซ‹ๆŠ€่ƒฝ๏ผŒ่ฆ†็›– 23 ไธชๅฎ‰ๅ…จ้ข†ๅŸŸ๏ผšๅŒ…ๅซ Web ๅบ”็”จๆธ—้€ใ€Active Directory ๆปฅ็”จใ€ๆ— ็บฟๅฎ‰ๅ…จใ€็”š่‡ณๅบ•ๅฑ‚็š„ๆผๆดžๅผ€ๅ‘๏ผˆROPใ€ๅ †ๆ ˆ็ ดๅ๏ผ‰ๅ’Œๅฎนๅ™จ้€ƒ้€ธใ€‚ โ€ข ๅณๆ’ๅณ็”จ๏ผŒๆŒ‰้œ€ๅŠ ่ฝฝ๏ผšๆฏไธชๆŠ€่ƒฝ้ƒฝๆ˜ฏ็‹ฌ็ซ‹็š„ SKILL.mdใ€‚ๅฏ็›ดๆŽฅ้…ๅˆ Claude Code ๅ‘ฝไปค่กŒไฝฟ็”จ๏ผŒๆˆ–ๆ‹–ๅ…ฅ Claude ็š„ Project ไธญไฝœไธบ System Prompt๏ผŒไธไผšๆตช่ดนๅคšไฝ™็š„ไธŠไธ‹ๆ–‡ใ€‚ โ€ข ไธ“ไธšๆ“ไฝœๅ‘˜่ง†่ง’๏ผšๅ†…ๅฎนๆ‘’ๅผƒไบ†้€š็”จ็ง‘ๆ™ฎ๏ผŒไธ“ๆณจไบŽๅ…ทไฝ“ๆ”ปๅ‡ป้ข็š„ๆŠ€ๆœฏ็ป†่Š‚ใ€็‰นๅฎšๅทฅๅ…ท้“พ็š„ไฝฟ็”จใ€่พน็ผ˜็”จไพ‹ๅ’Œๆๆƒ่ทฏๅพ„ๆŒ‡ๅผ•ใ€‚ ๅฏนไบŽๅฎ‰ๅ…จ็ ”็ฉถๅ‘˜ใ€Bug Bounty ็ŒŽไบบๆˆ–็บข้˜Ÿไบบๅ‘˜ๆฅ่ฏด๏ผŒ่ฟ™็›ธๅฝ“ไบŽ็ป™ AI ่ฃ…ๅค‡ไบ†็ป†ๅˆ†้ข†ๅŸŸไธ“ๅฎถ็š„็Ÿฅ่ฏ†ๅบ“๏ผŒ็›ดๆŽฅๅฐ†ๅ…ถ่ฝฌๅŒ–ไธบๅฎžๆˆ˜ๅˆ†ๆž่พ…ๅŠฉๅทฅๅ…ทใ€‚ github.com/SnailSploit/claudโ€ฆ
5
51
300
18,895
Day 6 building LogicProbe today was about something more important than training a model: trusting the data. i completed a 60 contract manual review of the arbitrary send vulnerability category. results: โ€ข 60 reviewed โ€ข 2 confirmed access control cases โ€ข 58 not access control โ€ข 0 unresolved the key lesson: an upstream vulnerability label โ‰  automatically the same vulnerability class in my dataset. so arbitrary send โ†’ access control remains REVIEW, not AUTO. i also froze the 420 record population and sampling artifacts. i am building LogicProbe one experiment at a time i ve started finding it funny and curious building a model
2
60
๐€๐›๐›๐š.๐ž๐ญ๐ก retweeted
It's an increasingly common take that AI hacking means cybersecurity is doomed. I disagree. I think cybersecurity is naturally defense-favoring once people get their shit together. And anyone who continues to hold cryptocurrency (including me, ~90% of my net worth) is implicitly making that bet. Here's why I am making that bet. First, the oversimplified punchy one-line statement: If AI can prove Navier-Stokes and FLT, then AI can prove the statement "this program is secure" as a mathematical theorem. Even if the program is very complicated. Now, the nuance: (See also: vitalik.eth.limo/general/202โ€ฆ ) The word "secure" is hiding all kinds of skeletons in the closet in terms of what it actually means. What does it mean for Signal (the encrypted messenger) to be "secure"? The most basic definition you might think of is: no one who doesn't hold the recipient's secret key can read the contents of the message. But: * Did you remember to include _other_ critical forms of security? Can the adversary forge messages? Can the attacker prevent messages from reaching the recipient? Can they cause your client to crash by sending malformed messages? * Have you made sure that your model of the adversary includes attackers that interfere with the protocol actively and not just passively? And attackers that interfere by replaying messages to you or the recipient that either of you sent over the wire at any point earlier? * What if the adversary hacked (or _is_) the Signal server? * How did you learn which public key belongs to the recipient in the first place? What if that process was tampered with? * What if your device gets hacked at some point in the past or future - is your message still safe then? * What if your key leaks because of a bug in your operating system? Or because you got a bugged version of the Signal client? Or what if the database is corrupted? * Or the libraries, interpreter or compiler of the programming language you wrote it in? * What if your key leaks because tiny perturbations in perceptible signals generated by the hardware leak mathematical relationships that can extract the key a few hundredths of a bit at a time? * Are you hiding the *size* of the payload? Does that matter? * You're definitely not hiding the identity of the sender and the recipient, and the exact time each message was sent (think: not just time-of-day, but also time deltas between one message and the next). Is that not enough to deduce a lot of important facts about what relationships you have, and what *kinds* of conversations you are having? So ... even definitions can be over a thousand lines of code, and need deep careful thought to figure them out. Working on making definitions more human-readable is of extreme importance - it's perhaps the only "high-level language" that matters right now. But even still, even despite all of the above, for security-critical components, the definition is a much smaller attack surface than the implementation. Verifying that the definition is adequate is a much more tractable task than scanning over the code directly - and can become even more tractable with better tooling. Definitions are also _additive_: if two groups have two different definitions A and B, then, well, you can just prove that the program satisfies both A and B. Code is not additive in this way: if a program is A + B, a bug in A _or_ B can sink the whole thing. Definitions are additive. And if you can't satisfy A and B at the same time, you've isolated the most important philosophical issue for your project to spend its next few weeks grappling with. Sometimes, definitions are not much smaller than the implementation - UI components might be one example. But for many of the most critical components - message-passing protocols, sandboxes, cryptography like SNARKs and FHE - the asymmetry is real. Historically, a large class of failures with this approach have come from people only verifying a small portion of their code, that they self-declared to be the security-critical portion, and ignoring the rest - and it turns out that something in the rest of the code is security-critical too. This was reasonable back when verification was difficult and scarce. The solution today: sorry, you have to verify over literally your entire program, including database, networking, any caching layers, everything. Modern AI can do it. So it's not about "the good guys find all the vulnerabilities before the bad guys do" - that could maybe work too, after all a finite program only has a finite number of vulns, but it's riskier - it's specifically an asymmetric strategy of making code that is much more resilient in the first place. This is the kind of direction that Ethereum is going in for the next few years. There is no future for blockchains - especially blockchains with scalability and privacy - without doing this. We need to make software actually secure. And we have already made a lot of progress.
374
424
3,234
813,788
Day 5 of building LogicProbe Today I did something that sounds simple but is actually critical in vulnerability detection: Labels. I started reviewing upstream SWC 104 findings for my Solidity dataset. And I found something important: An upstream vulnerability label โ‰  automatically a valid LogicProbe label. Some SWC 104 findings were genuinely unchecked external calls. Others were: โ€ข try/catch handled calls โ€ข internal function calls โ€ข return values that were actually captured and used โ€ข annotations that needed more context So instead of blindly importing the labels, I'm manually validating them. 27 SWC-104 findings reviewed. Result: 18 confirmed positives 9 confirmed negatives 0 unresolved This is making one thing clear: Good security ML starts with good ground truth. Tomorrow, we continue
2
31
๐€๐›๐›๐š.๐ž๐ญ๐ก retweeted
I'm 23. For years, I was scared of auditing Solana & Rust. Learn from my mistake. How going deep on Solana changed everything:
5
6
167
6,171
LogicProbe #Day 4 v0.6 is officially frozen. Today I started Phase 2: Dataset Expansion & Independent Evaluation. The goal is simple: make the experiments more rigorous, not just make the numbers look better. So far: โ†’ Documented the Phase 2 dataset protocol โ†’ Reviewed SmartBugs Curated โ†’ Found it is primarily Solidity 0.4.x, so it won't enter the primary 0.8.x dataset โ†’ Started reviewing a much larger vulnerability dataset โ†’ Added provenance, deduplication, leakage control & independent-test rules to the methodology โ†’ Currently downloading the dataset through Git LFS One important lesson: A bigger dataset โ‰  a better dataset. For LogicProbe, I care about ground truth, diversity, provenance and genuinely unseen evaluation data. Slowly building. Carefully testing. Next โ†’ expand the dataset, establish the development/validation split, and protect the independent test set. #Solidity #SmartContracts #Web3 #CyberSecurity #MachineLearning #BuildInPublic
16
๐€๐›๐›๐š.๐ž๐ญ๐ก retweeted
๐Ÿšจ Web3 security researchers, STOP SCROLLING. This entire playlist is FREE. 8 deep dives into auditing, stateful fuzzing, formal verification, L2 + bridge security, ZK circuits and more. This is hours of serious security education. SAVE IT. youtube.com/playlist?list=PLโ€ฆ
5
35
210
9,518
Day 3 of building LogicProbe๐Ÿ” Today I moved from feature engineering to actually testing whether the new features help. Built and evaluated LogicProbe v0.4: โ€ข 50 Solidity contracts โ€ข 32 structural features โ€ข 4 vulnerability labels โ€ข Random Forest baseline โ€ข 80/20 train-test split The result: Hamming Loss: 0.175 โ†’ 0.100 Biggest improvement: External Call Handling F1 0.00 โ†’ 0.67 Reentrancy F1 0.50 โ†’ 0.67 But the interesting part wasn't the score. I performed error analysis and found 4 remaining mistakes. One showed that my current feature extractor doesn't fully understand external calls hidden inside internal helper functions. Another showed that detecting the presence of access control isn't the same as detecting broken access control. That's exactly what I wanted to uncover. Next: turn these failure cases into hypotheses for v0.5. Building, testing, breaking, learning. #Solidity #SmartContractSecurity #MachineLearning #Web3 #AI #BuildInPublic
2
23
LogicProbe โ€” Day 2 ๐Ÿ”ฌ First ML baseline is running. 50 Solidity contracts โ†’ 32 features โ†’ 4 vulnerability labels โ†’ Random Forest. The interesting part wasn't the accuracy. Error analysis revealed that some regex-based contextual features don't reliably capture call โ†’ state change ordering. So I'm improving the representation before touching the model. That's the research #Solidity #SmartContractSecurity #AI #ML #Web3
3
56
I'm building LogicProbe. An AI assisted system for detecting vulnerabilities in modern Solidity smart contracts. I've been building quietly, but today I'm starting to share the journey publicly. Here's what I've built from Day 1 to today ๐Ÿงต
1
1
3
147
6/ LogicProbe combines: Blockchain Smart Contract Security AI Machine Learning Security Research I'm building this project while learning and researching. ๐Ÿš€ LP031 next.
1
9
My long term goal is to develop LogicProbe into a useful AI assistant that helps smart contract security researchers and auditors identify suspicious patterns faster. I'm also documenting this project as part of my research portfolio for my future academic journey. From today, I'll be sharing my progress as I build. Build โ†’ Test โ†’ Document โ†’ Share. Let's see where this journey goes. ๐Ÿš€ #SmartContractSecurity #Solidity #Web3Security #MachineLearning #AI #Blockchain #BuildInPublic
9