_RustyRabbit's profile picture. non fungible dad
security researcher

RustyRabbit

@_RustyRabbit

non fungible dad security researcher

RustyRabbit reposted

‼️‼️Please share for visibility.‼️‼️ ONGOING Open Source Phishing attack!! There is a new scam running around. You get a fake grants github tag by fake bot which says that it targets OS projects for a gitcoin grant. They create a fake github account with a fake project and…

m4rio_eth's tweet image. ‼️‼️Please share for visibility.‼️‼️
ONGOING Open Source Phishing attack!!
There is a new scam running around. 

You get a fake grants github tag by fake bot which says that it targets OS projects for a gitcoin grant.

They create a fake github account with a fake project and…
m4rio_eth's tweet image. ‼️‼️Please share for visibility.‼️‼️
ONGOING Open Source Phishing attack!!
There is a new scam running around. 

You get a fake grants github tag by fake bot which says that it targets OS projects for a gitcoin grant.

They create a fake github account with a fake project and…
m4rio_eth's tweet image. ‼️‼️Please share for visibility.‼️‼️
ONGOING Open Source Phishing attack!!
There is a new scam running around. 

You get a fake grants github tag by fake bot which says that it targets OS projects for a gitcoin grant.

They create a fake github account with a fake project and…
m4rio_eth's tweet image. ‼️‼️Please share for visibility.‼️‼️
ONGOING Open Source Phishing attack!!
There is a new scam running around. 

You get a fake grants github tag by fake bot which says that it targets OS projects for a gitcoin grant.

They create a fake github account with a fake project and…

RustyRabbit reposted

It gets even more fancy: the way Etherscan was tricked showing the wrong implementation contract is based on setting 2 different proxy slots in the same frontrunning tx. So Etherscan uses a certain heuristic that incorporates different storage slots to retrieve the implementation…

pcaversaccio's tweet image. It gets even more fancy: the way Etherscan was tricked showing the wrong implementation contract is based on setting 2 different proxy slots in the same frontrunning tx. So Etherscan uses a certain heuristic that incorporates different storage slots to retrieve the implementation…

We @VennBuild just discovered a critical backdoor on thousands of smart contracts leaving over $10,000,000 at risk for months Along with the help of security researchers @dedaub @pcaversaccio, the seals team @seal_911 and others, we managed to rescue the majority of funds…



RustyRabbit reposted

So someone contacts you on LinkedIn with a promising job opportunity. Sounds nice, innit? They seem legit (after checking them for 1 min) and after some short convo they send you a GitHub repo with a simple Next.js "recruiting task". You clone it, run it… and 10 mins later, your…

pcaversaccio's tweet image. So someone contacts you on LinkedIn with a promising job opportunity. Sounds nice, innit? They seem legit (after checking them for 1 min) and after some short convo they send you a GitHub repo with a simple Next.js "recruiting task". You clone it, run it… and 10 mins later, your…
pcaversaccio's tweet image. So someone contacts you on LinkedIn with a promising job opportunity. Sounds nice, innit? They seem legit (after checking them for 1 min) and after some short convo they send you a GitHub repo with a simple Next.js "recruiting task". You clone it, run it… and 10 mins later, your…
pcaversaccio's tweet image. So someone contacts you on LinkedIn with a promising job opportunity. Sounds nice, innit? They seem legit (after checking them for 1 min) and after some short convo they send you a GitHub repo with a simple Next.js "recruiting task". You clone it, run it… and 10 mins later, your…

RustyRabbit reposted

you are not serious people

real_philogy's tweet image. you are not serious people
real_philogy's tweet image. you are not serious people

This is the problem that needs to be solved. If you've been on both sides of this you understand why it's not easy to solve.

patience + escalation mastery = top ranks ⚔️ I had findings disputed/confirmed/rejected multiple times in Velvet. soul-draining but unavoidable. you have to learn the game of escalations. stand your ground with solid evidence, never reply with emotions - analyze critically,…



RustyRabbit reposted

We have published our post-mortem on the exploit in the wstUSR market as well as the recovery plan. Please use the links below. Post-mortem: mirror.xyz/0x521CB9b35514… Recovery Plan: gov.resupply.fi/t/resupply-rec…


RustyRabbit reposted

1/4 Big progress for #Telcoin Network We’ve completed a full audit of core infrastructure with @lovethewired and @_RustyRabbit of @cantinaxyz - a major step toward mainnet!

TelcoinTAO's tweet image. 1/4 Big progress for #Telcoin Network

We’ve completed a full audit of core infrastructure with @lovethewired and @_RustyRabbit of @cantinaxyz - a major step toward mainnet!

RustyRabbit reposted

I recently read some comments here by security researchers and noticed a severe lack of empathy for customers. Within the Cantina core team, I make sure everyone hears directly from our customers. This is crucial for building empathy and understanding customer needs. Without…


RustyRabbit reposted

@code There is a new solidity extension impersonating mine, my name etc. This extension has just been published today, and has managed to even fake a whopping 20 million downloads. This might include malware.

juanfranblanco's tweet image. @code There is a new solidity extension impersonating mine, my name etc. This extension has just been published today, and has managed to even fake a whopping 20 million downloads.  This might include malware.

RustyRabbit reposted

Recently I was targeted by an extremely sophisticated phishing attack, and I want to highlight it here. It exploits a vulnerability in Google's infrastructure, and given their refusal to fix it, we're likely to see it a lot more. Here's the email I got:

nicksdjohnson's tweet image. Recently I was targeted by an extremely sophisticated phishing attack, and I want to highlight it here. It exploits a vulnerability in Google's infrastructure, and given their refusal to fix it, we're likely to see it a lot more. Here's the email I got:

RustyRabbit reposted

folks, can we please fucking stop normalising `curl | bash` as an installation method (yes, I'm also looking at you Foundry)? It's a _massive_ footgun that blindly executes remote code with zero verification. You're literally giving arbitrary internet bytes root access to your…


RustyRabbit reposted

Meet Nick Franklin @0xNickLFranklin - Blockchain Security Engineer…. or RGB operative hacking for DPRK? Seemingly this guy has had the entire industry fooled for years.

tanuki42_'s tweet image. Meet Nick Franklin @0xNickLFranklin - Blockchain Security Engineer…. or RGB operative hacking for DPRK? Seemingly this guy has had the entire industry fooled for years.

RustyRabbit reposted

Security’s about to get pumped up. The biggest Solana competition in history has landed in the Cantina 🪐 @pumpdotfun just dropped a massive $2,010,000 prize pool to help secure PumpSwap, their new DEX. 💰 $2,010,000 USDC 📅 Live now - April 4th 🔗 Below


RustyRabbit reposted

how to gain code execution on millions of people and hundreds of popular apps and of course, firebase was (partially) the cause kibty.town/blog/todesktop/


RustyRabbit reposted

1/ On the EU Giving Up I watched a panel on AI (machine learning) at a conference hosted by the European Commission. 9 people on the panel Everyone agreed that the USA was 100 miles ahead of EU in machine learning and China was 99 miles ahead except for those who believed...


RustyRabbit reposted

When we say crypto takes security seriously, this is what we mean 🪐 @Eigenlayer is relentlessly pursuing the pinnacle of security standards with the largest-ever, $2,500,000 code review competition starting in February. More info coming soon.


RustyRabbit reposted

This is pretty interesting Never thought of using the identity precompile to bypass external checks that expect the function selector to be returned Also, this is the first time I've seen a precompile used in an exploit

ALERT! Our system detected a series of attacks targeting the @odosprotocol protocol on #ETH #Base, resulting in ~$50k in losses. The root cause is arbitrary call vulnerability caused by unverified user input. We notice that the attacker exploited the precompile contract (0x4)…

Phalcon_xyz's tweet image. ALERT! Our system detected a series of attacks targeting the @odosprotocol protocol on #ETH #Base, resulting in ~$50k in losses. 

The root cause is arbitrary call vulnerability caused by unverified user input. We notice that the attacker exploited the precompile contract (0x4)…


RustyRabbit reposted

Building secure smart contracts is tough—risks are high, audits are costly, and your treasury is at stake. Sablier has 5+ years of hack-free operations, billions in volume, and rigorous audits. Trust the proven standard, don't use a custom vesting contract.


RustyRabbit reposted

🚨 Heads up all—some dudes have a slick, new way of dropping some nasty malware. Feels infostealer-y on the surface but...its not.🫠 It'll really, deeply rekt you. Pls share this w/ your friends, devs, and multisig signers. Everyone needs to be careful + stay skeptical. 🙏

tayvano_'s tweet image. 🚨 Heads up all—some dudes have a slick, new way of dropping some nasty malware.

Feels infostealer-y on the surface but...its not.🫠

It'll really, deeply rekt you.

Pls share this w/ your friends, devs, and multisig signers. Everyone needs to be careful + stay skeptical. 🙏

RustyRabbit reposted

I've worked closely with @tayvano_ for... *checks notes* over seven years. Each and every day, without fail, for the entirety of those seven years, she has ONLY worried about the wellbeing of those around her, including her family, her friends, her employees, the users of her…


Loading...

Something went wrong.


Something went wrong.