codehari662's profile picture. 🔍 Smart Contract Auditor | Sharing daily audit insights & lessons
🛡️ Blockchain & DeFi security | Real bugs, real mistakes, real learning

Hari Suthan

@codehari662

🔍 Smart Contract Auditor | Sharing daily audit insights & lessons 🛡️ Blockchain & DeFi security | Real bugs, real mistakes, real learning

In my recent audit, I missed a subtle detail. ⚠️ The contract used: currentTime - userJoinTime But the docs said rewards should start only after the campaign begins: If a user joined before the campaign, the wrong formula gives extra rewards.


Imagine trying to buy a concert ticket… 🎟️ Your transaction is pending, someone sees it, jumps ahead, and buys it first. That’s front-running in smart contracts. Attackers see your tx → act first → gain an unfair edge or cause user loss. #Web3 #SmartContracts #DeFi


💡 Dev Tip: Before letting an external contract (like Uniswap) pull tokens, don’t forget approve()! Skipping it = failed txs & broken contracts. ✅ Small step, big safety. #SmartContracts #DeFi #BlockchainDev


My Recent Auditing Mistake 🔍 I flagged a missing blocklist check in a transfer function ❌. Later realized the token contract already enforced it in _beforeTokenTransfer ✔️. I just missed it. Lesson: Always check the full flow before calling something a bug.


Starting something new 👇 I’m diving deep into smart contract security From tomorrow, I’ll be sharing real bugs I study from audits like Code4rena & Sherlock. Real lessons. Daily breakdowns. Follow to learn with me 💥 #web3 #auditing #bugbounty


United States Trends

Loading...

Something went wrong.


Something went wrong.