Independent Smart Contract Researcher & Researcher at @ShieldifySec My mission is to find vulnerabilities in smart contracts for a safer Web3 Space!

Made $60k last month from audit 😎 What about you?
23
139
10,835
Jeff Security retweeted
Client: "We've made some small changes to the contract, shouldn't affect the audit scope" The small change: - added 2000 lines of code - new oracle - new bridge - upgradeable now
3
4
17
731
Bridges are still where the money leaks. Message verification, relayer trust, replay across chains. If you can't explain who can forge a message and why they can't, you haven't finished the review.
14
597
Jeff Security retweeted
Want to connect with more auditors in our circle 🫡 If you do security reviews, comment below and tell us your main stack (Solidity, Rust, Move, something else)?
29
4
61
2,025
Jeff Security retweeted
Building on Robinhood Chain? 🤔 Almost no protocols running bug bounties. If you’re launching on a new chain, security should be part of the launch. Fortunately, there have been no protocol hacks on RH Chain so far. We’re working with teams across the eco to keep it that way.
2
7
313
Jeff Security retweeted
Every exploit postmortem starts with "We take security very seriously" Ours start with "Found Critical before launch" 😈
1
3
14
635
AI finds the bugs that look like bugs. Auditors still find the ones that look like features. Use both, trust neither blindly, and keep a human on the final sign-off.
1
4
414
The most expensive line in a smart contract is usually the one the dev called "just a helper". Untested, unaudited, called from three places, holding the whole invariant together.
16
1,061
Invariant tests catch what unit tests can't: the bug that only shows up after 400 random calls in an order nobody wrote down. If a protocol ships without a fuzz suite, that's a finding on its own.
1
26
1,106
Jeff Security retweeted
The bear market is over, be ready! ✌🏻
3
3
36
1,497
Jeff Security retweeted
New audit in the Hyperliquid ecosystem: @pear_protocol 🤝 We reviewed their ERC-4626 vault and the off-chain logic behind it. Vault accounting, share math, access control, and how off-chain and on-chain interact. Reports are out. Great working with the Pear team👇 1) github.com/shieldify-securit… 2) github.com/shieldify-securit…
7
11
39
5,380
The exploit you'll read about next month is sitting in a repo right now, deployed, unaudited, TVL climbing. Someone is going to find it. Might as well be you, on the right side of it.
5
47
1,812
Most "auditors" are running a linter with extra steps. If your report has no PoC and no severity reasoning, you're not auditing, you're describing.
1
22
976
Jeff Security retweeted
Next bull run is going to be huge for security researchers 🫡
6
7
50
1,546
Every top security researcher you follow was once a nobody with a Foundry install and a broken PoC. The gap isn't talent. It's reps. Do the reps.
2
4
53
2,912
Jeff Security retweeted
Downgrading a finding doesn't downgrade the risk. The label changes; the attack path doesn't
1
4
10
698
Jeff Security retweeted
How should a new, self-funded protocol approach security? 1. Internal audit 2. Document everything + fuzz test 3. Run multiple AI agents, triage findings 4. Get our experienced researchers to handle the manual audit 5. Fix everything & deploy safely
1
11
429
Nobody gets good at auditing by reading about auditing. You get good by staring at code for six hours, finding nothing, and coming back tomorrow. The finding is on day four. Keep going.
2
26
903
Want to level up your auditing? Read real reports. 160+ public security reviews from @shieldifysec across Solidity, Rust, Move, covering Account Abstraction, RWAs, DEXes, LPs, GameFI, Launchpads and more. github.com/shieldify-securit…
3
10
61
2,349
Jeff Security retweeted
POV: You're a security researcher and the bull run just started. Your DMs: 47 "urgent audit needed" messages. Every single one launches next week.
5
4
35
1,181
Jeff Security retweeted
A duplicate report means you were right, just not first. That's closer than most ever get. Skill isn't your bottleneck. Speed is. Pick a strategy, optimize ruthlessly for speed, and never "just try" 👍
2
9
432