0xparthdev's profile picture. Smart Contracts Developer @yieldnestfi. prev @aave @_VaporFi @amazon

Parth

@0xparthdev

Smart Contracts Developer @yieldnestfi. prev @aave @_VaporFi @amazon

Next goal for me is to understand sUSDe. Thanks for high level overview.

1/ Over the past month, I audited two protocols connected to USDe: • a fork of USDe • a protocol deploying capital into sUSDe That experience convinced me of one thing: if you audit Ethereum DeFi protocols, you should understand how USDe / sUSDe works. Here’s why 🧵



congrats to @codeandledger for successfully delivering this. Looking forward to mainnet

Cedra x @ApeBond Cedra has partnered with ApeBond, a multi-chain bonding protocol committed to building a sustainable DeFi future for projects and communities. As part of this collaboration, the Move port was handled by @codeandledger, ensuring a robust and seamless…

cedranetwork's tweet image. Cedra x @ApeBond 

Cedra has partnered with ApeBond, a multi-chain bonding protocol committed to building a sustainable DeFi future for projects and communities.

As part of this collaboration, the Move port was handled by @codeandledger, ensuring a robust and seamless…


good article on design decisions to take regarding liquidations for onchain exchanges by @0xTripathi 0xtripathi.substack.com/p/exchange-liq…


started learning math from @_MathAcademy_ to expand my skillset on understanding complex defi math and ZK

0xparthdev's tweet image. started learning math from @_MathAcademy_ to expand my skillset on understanding complex defi math and ZK

Parth đã đăng lại

We found an insolvency bug in RAI's liquidation engine. Through returndata-bombing, attackers could abuse a registered callback and make it unliquidatable. Immunefi mediation confirmed the issue and recommended payout. Then they reversed course after project pushback. 🧵🧵

trust__90's tweet image. We found an insolvency bug in RAI's liquidation engine. Through returndata-bombing, attackers could abuse a registered callback and make it unliquidatable.

Immunefi mediation confirmed the issue and recommended payout.

Then they reversed course after project pushback.

🧵🧵

TIL that you can concat two string literals just by doing ("literal1" "literal2") P.S. This will only work for string literals and not variables. So, best way is to use string.concat() function

I think my usage of abi.encodePacked will drop significantly after finding this out :D Credit to @ali_shehab121 for showing it to me

zdravkohristov0's tweet image. I think my usage of abi.encodePacked will drop significantly after finding this out :D 

Credit to @ali_shehab121 for showing it to me


Commit to a habit, not an outcome. Outcomes are downstream of habits. Your current life is largely the outcome of your habits up until this point. Summarized "Atomic habits" book in great way.

If you are going to make a New Year's resolution: 1) Consider not committing. If you have a habit of breaking promises to yourself, you are only continuing a vicious cycle. 2) Commit only to January, then see how things are working out. 3) If you do decide to commit, don't…



Parth đã đăng lại

Very concerned about the second-order effects of advances in AI auditors. The direct consequences are well understood by most: lower cost of entry, higher bar for exploits, bounty hunters and blackhats retroactively auditing old codebases, etc. There will come a point (expect…


Amazed by the attacks happening in the space. Good to have learned about CPIMP backdoor attack. Due to this, always ensure that your proxy deployment + initialization happens in one transaction. hackmd.io/@Deivitto/Skf6… (h/t @Deivitto ) Video from DSS youtube.com/watch?v=RShnWs…

0xparthdev's tweet card. The CPIMP Backdoor: Anatomy of a Multi-Chain Proxy Attack

youtube.com

YouTube

The CPIMP Backdoor: Anatomy of a Multi-Chain Proxy Attack


Good read with summarized tldr: Treat every division as a potential vulnerability. Ask the two questions above, test the zero case, and you’ll be catching many more bugs than before


Parth đã đăng lại

This weekend I analyzed EIP-712 implementations across major protocols so you don't have to! The main trade-off: should you compute the domain separator on demand or apply caching optimization to reduce hash operations? Let's check industry best practices 🧵👇


didn't got any @megaeth allocation. Still very bullish on chain


how to connect @iSafePal wallet with @Rabby_io or @MetaMask ?


May the @megaeth allocation be with you! 🙏

Tweet này không còn khả dụng.

ready for day 1 🫡 @monad

0xparthdev's tweet image. ready for day 1 🫡 @monad

Loading...

Something went wrong.


Something went wrong.