banditx0x's profile picture. Security Researcher @OpenZeppelin

Whitehat Initiate @ImmuneFi

Whitehat Bandit

@banditx0x

Security Researcher @OpenZeppelin Whitehat Initiate @ImmuneFi

Any good side events at Devcon Argentina?


What are some good learning materials or frameworks to start building an AI auditing agent or audit assistant?


After the 1 week @RareSkills_io bootcamp I can convert tweets into ZK Circuits 🫡

Here's a ZK Circuit in Circom to check whether you are qualified to DM @nisedo_ Input your skills (1 indicates you have this skill, 0 to indicate you don't) and the output shows whether you can DM Nisdeo. zkrepl.dev/?gist=6e1b9e77…

banditx0x's tweet image. Here's a ZK Circuit in Circom to check whether you are qualified to DM @nisedo_ 

Input your skills (1 indicates you have this skill, 0 to indicate you don't) and the output shows whether you can DM Nisdeo.

zkrepl.dev/?gist=6e1b9e77…


Whitehat Bandit 已轉發

RareWeek -- where lead auditors at tier-1 firms study.

RareSkills_io's tweet image. RareWeek -- where lead auditors at tier-1 firms study.

Whitehat Bandit 已轉發

This isn’t an exaggeration — RareSkills is education at the highest level. For RareWeek ZK, I was very intentional about making the learning aspect efficient: - regular use of recall exercises to enforce memorization of key ideas - lots of hands-on practice with rapid feedback…

RareWeek -- where lead auditors at tier-1 firms study.

RareSkills_io's tweet image. RareWeek -- where lead auditors at tier-1 firms study.


Jane Street's India options trade is a price oracle exploit but you only get banned instead of arrested once caught.


Rust has soooo many rules compared to Solidity


I'm 40% through the @RareCodeAI Rust course

banditx0x's tweet image. I'm 40% through the @RareCodeAI Rust course

It’s really competitive getting into an audit firm nowadays 👀

We have manually reviewed all the applications and will be sending out 20 interview invites soon. To give an idea of the quality, the people who have made the cut have had 50+ H/M bugs in audit contests, multiple top finishes, private audit portfolio.



Cork protocol also had a bug bounty on Cantina with a max bounty that was <1% of funds at risk. It makes me think that the exploiter found the issue when hunting bug bounties and preferred taking $12m illegally over maybe getting a 100k bounty.

So he steals 12M, observes the whole drama AND then comments on it 😅 I’m wondering who that is now .. the chance is very high we all know him



Why are there smart contracts written in Lisp now ?


AMM’s aren’t complex enough, let’s add another dimension

Orbital extends concentrated liquidity to pools of three or more stables by drawing tick boundaries as orbits around the $1 equal price point. Unlike 2D concentrated AMMs, even if one stablecoin depegs to 0, an Orbital tick can still use its reserves to trade the others. 4/8



Which lending protocol is forked more often? Compound or Aave?

Compound %43.1
Aave %56.9

109 票 · 最終結果


PancakeSwap lottery is actually beatable on some days 👀


Theres a common misconception that AMM spot price manipulation attacks require low liquidity pools. Swapping to an imbalanced price, doing some exploit with the manipulated price, then swapping back only costs the swap fee.


Uniswap V2 LP tokens are ERC4626 tokens that are comprised of 2 assets. ERC4626 tokens maintain a consistent asset/share ratio upon deposits and withdrawals. Rewards can be distributed to shareholders by increasing assets without increasing the number of shares. In Uniswap V2,…


One of the most well known bugs is the ERC4626 first depositor inflation attack. It's so common that it would earn $0.00 when reported in a public contest. The bug actually exploits a really cool bug pattern and understanding this pattern can be used to discover unique high…

Yesterday's complete hack of Wise Lending was far more complex than reported. Very worth examining. The protocol had added explicit defenses against this style of attack, which the attack then either bypassed or used against the protocol. 🧵 1/21

danielvf's tweet image. Yesterday&apos;s complete hack of Wise Lending was far more complex than reported. Very worth examining.

The protocol had added explicit defenses against this style of attack, which the attack then either bypassed or used against the protocol.    🧵 1/21


Loading...

Something went wrong.


Something went wrong.