I’ve been researching @Zcash security as part of our internal work at @osec_io. Today, I’m happy to share that the total amount I’ll be receiving in bug bounties from @Zcash has finally been confirmed at $972K. I’m really proud of what came out of this research. More importantly, I’m glad our work contributed to improving Zcash’s security and got more security researchers interested in Zcash. It’s especially great to see that many researchers are still looking into Zcash, finding and reporting bugs, and keeping an eye on its security. Huge thanks to the teams across the Zcash ecosystem, including @Zcash, @zodl_co, @ZcashFoundation, @ValarGroup, @ShieldedLabs, @TachyonZcash, and @ZcashCommGrants, for taking security seriously and rewarding researchers, and to the entire Zcash community for all the support. I’ll keep doing my best to find more bugs.
80
46
906
62,054
Really appreciate all the support from Zcash coinholders!
Zcash coinholders have approved retroactive funding for 17 proposals covering Protocol Security, Infrastructure, Wallet R&D, Business Integrations & more.
1
1
17
1,773
너무 귀여워
2
35
1,357
gss1 retweeted
4th? Cold Fusion have come a long way!
3
39
1,894
my contribution in the qualifiers was mostly ctrl+c and ctrl+v😅, so hoping the finals have some aI-resistant challenges
SCAN 2026 Online Qualifier Results Are In! Congratulations to the Top 20 Teams advancing from the SCAN 2026 Online Qualifier! 🎉 Thank you to everyone who participated. scan.sx/ #SCAN2026 #KBW #CTF
2
21
2,274
make ctf great again with ↓
CTF始まっていきなりシュレッダーで切り刻まれた紙を渡されて人力で復元させられたの、本当に泣きそうになった
4
106
14,456
just found a drain vulnerability, but I realized it had already been exploited a few hours earlier☠️
1
31
2,449
gss1 retweeted
We're launching a $100,000 fund to save CTFs.
17
104
647
65,840
gss1 retweeted
If you were affected, DMs are open. We're hiring still!
🤯One of the big web3 security companies (Certora) has just laid off a BIG portion of their staff. Security Researchers, Sales, Management, even C-level positions. That's a shock, yesterday they were still hiring elite talent. Insane. Wish everyone to find the right new jobs🙏
2
7
140
18,810
👀
Korea’s #1-ranked hacker on HackerOne is back with a follow-up post! 👀 Hyunseo Shin (KU, 4th year) previously shared how he uncovered open-source 0-days using LLM agents. Now, he breaks down the AI-based vulnerability detection workflow behind those findings. Full post below 🔥 🔗 blog.cykor.kr/2026/06/Buildi… #CyKor #AI #hackerone
2
12
2,685
I believe this makes many security researchers participate in zcash bug bounty
I recently reported multiple vulnerabilities to @Zcash and Zebra, and several GHSAs have been published github.com/ZcashFoundation/z… github.com/zcash/zcash/secur…
2
13
2,074
gg
I participated in DEF CON CTF with Cold Fusion again this year! I’d like to thank all of our teammates who worked so hard throughout the competition. Also, I probably won’t be playing CTFs after these finals. I’m truly honored that what may be my last CTF is DEF CON. Thank you to BBB for creating such great challenges, and to all the organizers for running the event. Anyway, see you in Vegas if everything goes smoothly!
18
1,396
I recently reported multiple vulnerabilities to @Zcash and Zebra, and several GHSAs have been published github.com/ZcashFoundation/z… github.com/zcash/zcash/secur…
4
1
74
8,185
gss1 retweeted
We found a critical soundness bug in dusk-plonk that let a malicious prover forge proofs for arbitrary false statements. The result: an attacker could mint arbitrary amounts of DUSK out of thin air and bypass every check protecting Dusk's shielded transactions.
Made with AI
8
13
120
15,874
dropped my first public cve 🤠
Zebra 4.3.1 contains critical security fixes for a number of vulnerabilities. 🚨All node operators are strongly encouraged to upgrade immediately. Additionally, it introduces a Dockerized mining setup, automated checkpoint management, and a number of CI hardening improvements. zfnd.org/zebra-4-3-1-critica…
1
1
26
1,525
gss1 retweeted
The pre-release version of Anchor v2 is out. v2 is over 90% smaller and 3-6x faster than v1, and represents months of work focused on speed, extensibility, and security. This is a major architectural change from a dense macro-based framework to a more easily extensible trait system, with security built in from day one. Excited for teams to give it a try. Still a few rough edges, but please DM/comment with any feedback!
11
47
215
27,844