I witnessed firsthand how a protocol could live with a live bug (and possibly never catch it) because there's no way to responsibly disclose these issues.
In a review with @QuillAudits_AI , an RWA project <redacted> had forked a portion of @DinariGlobal's code but requested we treat it as a black box.
(Un)fortunately, I tend to digress when not working with code I'm familiar with -- and stumbled on a sizeable vulnerability in their codebase
Thankfully it wasn't exploited before it was patched, but they had ~$3m at risk (which grew to $60m in less than 4 months), big liquidity injection in RWA's this year (and likely for the next few years)💰
While this isn't Yearn-scale, many small drops fill a barrel.
Josselin has been talk about the need to beef up internal security -- this awareness is something I expect to grow as well, and this exploit is another example why
(ty for your talk with Rajeev and Alex at DSS).
With Devcon coming up and attackers actively looking for opportunities through social engineering, it is important to have a security checklist before you travel, while you are there and after you come back.
Here is what I would keep in mind:
We’re starting Quill Findings 🥷
Detailed write-ups of real issues from client audits. What we caught, why it mattered, and what the fix was.
First one: Eligibility Replay in Tokenized Assets.
A gold-backed vault where the bar left and the custody certificate did not. That leftover NFT minted a second claim.
Full breakdown below 👇
This critical severity issue would have caused permanent asset loss. It proves really useful (time and time again) to not overlook an external audit before going to production.
ERC4626 vaults are interesting DeFi use-case. Adding on delays to make vault functionality asynchronous increases the surface of risk and trust assumptions.
For this audit, we consumed lots of resources on ERC7575 and ERC7540 to understand the tweaks made to the regular vault mechanism.
Happy to lend an unbiased pair of eyes to any developers pushing new changes. Reach out and I'll connect you to the best auditors on the team @QuillAudits_AI .
Getting licensed in Dubai is the easy part.
VARA doesn't shut down the projects that get hacked, it shuts down the ones that can't prove they were protected.
The 7 things that have to be in place before you go live👇
OpenAI is closing the door to new subscribers on its $200/month ChatGPT Pro plan.
Starting yesterday, September 10, @OpenAI is temporarily pausing new sign-ups and upgrades to Pro 20x. Existing subscriptions will continue to renew, and the $100 Pro plan remains available.
The catch: If you cancel or downgrade and let the change take effect, you can't get the $200 plan back until the pause is lifted. You can still reverse a scheduled cancellation before your billing cycle ends.
No reopening date is given. For anyone relying on the highest usage limits, that's a pretty consequential change.
RWA security is not an ERC-20 review with extra steps.
$38B already live. $355B represented. Almost all of it sits on three standards:
3643: identity + freeze/force
4626: share price + rounding
7518: partitions + lock math
This is the attack surface. Checklists in the thread 👇
On-chain RWAs have crossed $38B in distributed assets, representing $355B in assets and reaching 2.9M holders.
All of that value runs on a handful of token standards. Each one has a live attack surface, and the industry is short on people who can find the bugs.
We wrote the checklists. 🧵
August was one of those months where you just sit back and feel genuinely proud of the team.
Our audit team @QuillAudits_AI absolutely crushed it: ✅ 12 projects audited - all delivered on time
🔍 155 findings identified
Huge kudos to @kalp_eth, @Pro___King1,@phoenix244001, @cryptanu, and @turvec_dev for the exceptional work and relentless commitment to securing Web3.
Hats off to you all. On to the next one....
A good book sparks a new web of thinking and subsequently sponsors new actions.
If you're a frequent traveler this book here is a useful bite-sized read to improve your safety score.
Thanks to @_SEAL_Org and @theredguild
Bring Solana to your campus, help classmates ship, and build a community.
We're opening applications for the Solana University Ambassador Program.
Two undergrad ambassadors per campus will work directly with @SolanaFndn and receive hands-on training, funding, perks, swag, and access to a global community of peers.
Apply now: solana.com/university
Live in Dubai on September 10, we'll be hosting a working forum on Tokenized Finance.
web3, RWA, Fintech, Tokenization-focused builders and teams will benefit from practical, real-world signals.
Link to register in the comments.
The most expensive click in crypto was a multisig approval.
In February 2025, Bybit signers approved what looked like a routine transfer.
The transaction was a delegatecall that rewrote the Safe’s implementation.
$1.5 billion left in minutes.
No smart contract was exploited.
The signers were.
This pattern has continued.
Over $1.7B has left secure multisigs in the last 18 months through hidden delegatecalls, silent config changes, and thresholds that quietly drifted.
We’re going live on this exact problem.
This Thursday, we’re kicking off TheDAO’s monthly Ethereum security Spaces with OpSec.
Set your reminder and join us for a conversation on operational security and the risks that live outside the code.
nitter.net/i/spaces/1qxvveebjzlxB…
Ate straight out of the ocean and met some dolphins.
Crazy adventures this past week following the superb programming at Zanzalu.
Thanks to every mentor, facilitator and superb individuals I met I've lived life through a new set of eyes.
Asante sana! 🇹🇿