ret2basic's profile picture. Resident @electisec | Solidity + Move auditor @taichiaudit | I solve hard problems in different fields

ret2basic.eth

@ret2basic

Resident @electisec | Solidity + Move auditor @taichiaudit | I solve hard problems in different fields

Summer 2022 - learn solidity as a hobby Early 2024 - learn rust for reading L1 code Summer 2024 - learn zk Now - evm at @electisec, move at @plainshift, and some solana request coming next Slowly but surely?

3 yrs ago - started learning Solidity as a hobby 2 yrs ago - joined Cyfrin, consistently produced great private audit output 10 months ago - started managing audit team, produced great business results turned audit team into efficient 💰 printer Now - living the dream 💪



Justice 🎉🎉🎉

Riptide: You submitted two vibed findings that were downgraded because of their limited nature. They cause minor performance impact in off-chain consumers when compiled in nonstandard configurations. Setting aside who-decides-what, these findings don't merit Medium severity.…

gf_256's tweet image. Riptide:

You submitted two vibed findings that were downgraded because of their limited nature. 

They cause minor performance impact in off-chain consumers when compiled in nonstandard configurations. Setting aside who-decides-what, these findings don't merit Medium severity.…
gf_256's tweet image. Riptide:

You submitted two vibed findings that were downgraded because of their limited nature. 

They cause minor performance impact in off-chain consumers when compiled in nonstandard configurations. Setting aside who-decides-what, these findings don't merit Medium severity.…


子曾经曰过,是洞就是洞,不是洞就不是洞,老外学学?🤪


Spent ~2 weeks on Solana confidential transfer zk contest, but didn't make it to the final leaderboard cause only top 3 qa reports get paid. A bit frustrating, but here is the evidence of me made it to top 7 at least😂

ret2basic's tweet image. Spent ~2 weeks on Solana confidential transfer zk contest, but didn't make it to the final leaderboard cause only top 3 qa reports get paid. A bit frustrating, but here is the evidence of me made it to top 7 at least😂

Amazing tool for large scale bug hunting 🫡🫡🫡

to those who want to find similar bugs in all smart contracts, in seconds. now available to all whitehats.



Grab my 🍿🍿🍿🍉🍉🍉 and enjoy the show🤣

Just to add more fuel to the fire: This “AI-found critical” issue was reported during a private @HackenProof contest, flagged as critical, and ofc closed as out of scope (contest was for critical-only). Yet somehow, @sherlockdefi got access to the same private codebase and…



Received @rektoff_xyz bootcamp graduation cert today! Thanks Rektoff for the amazing lectures, exercises, and of course the capstone. The bootcamp was a fantastic introduction to the Rust/Solana security world🙏

ret2basic's tweet image. Received @rektoff_xyz bootcamp graduation cert today! Thanks Rektoff for the amazing lectures, exercises, and of course the capstone. The bootcamp was a fantastic introduction to the Rust/Solana security world🙏

Congrats everyone. Me and @Polaris_tow stared at this code for an afternoon and found nothing 😂 Good memories

The $30K @FolksFinance Audit Competition is a wrap! 🎉 100% of the reward pool has been paid out! 💰 🏆 Top Winners: 1. @pks_eth – $7,308 2. @4mj3x – $4,413 3. danvinci_20 – $2,613 4. @_uhudo – $2,313 5. @0xenzo_eth – $1,308 Congrats to all participants & winners! Your valuable…

immunefi's tweet image. The $30K @FolksFinance Audit Competition is a wrap! 🎉
100% of the reward pool has been paid out! 💰

🏆 Top Winners:
1. @pks_eth – $7,308
2. @4mj3x – $4,413
3. danvinci_20 – $2,613
4. @_uhudo – $2,313
5. @0xenzo_eth – $1,308

Congrats to all participants & winners! Your valuable…


Not sure how sy::asset_to_sy() works. Is py_index similar to borrow index in Compound? I remember borrow index is a monotonically increasing accumulator used to compute interest and determine cToken value. I guess py_index is similar so inflating it causes price manipulation?

Nemo Protocol @nemoprotocol is a Pendle fork on Sui. On 9/7, it suffered a hack targeting the py_index manipulation, exploited for ~$4M. Here's the detailed analysis:👇



CertiK strong🤯

ret2basic's tweet image. CertiK strong🤯

These goals seem very conservative now and they don’t align with my values anymore. New goal: 1. Find all crits and highs, keep my clients away from showing up in defihacklabs repo 2. Be comfortable with any type of codebase: L1/L2, ZK, or any defi regardless of language used

2025 goal: - 100k income from independent auditing work - Get into solana, cosmwasm and cairo (already know move and sway) - 0 hour spent on meaningless things (interview prep, bad ctf, random articles)



Great article! Wen part 2?👀


Electi 🤝 DeFiHackLabs


Heard about this attack dedaub.com/blog/the-cpimp… from my buddy @jesjupyter today. Deployment issue is always marked out of scope in contests while it is a serious attack vector and it was already exploited in the wild.


Today an interviewer from another firm interviewed me with certik background (trolling me), I guess I am certik twitter ambassador now🤣


And success isn’t measured by money😜

Success isn't linear. Read code, understand it, research the things that caught your eyes, question each assumption and protection mechanism, and repeat, without worrying how much money you make. Success will come to you when you are strong.



🎉 I just claimed my free 10th-Anniversary collectible NFT from ethereum.org 🔷 Celebrating a decade of open, decentralized innovation. Join me 👉 ethereum.org/en/10years/ #Ethereum10


ret2basic.eth reposted

.@boredpukar and @ret2basic who consistently brought the 🔥 during Block 7 fellowship are now joining us as resident auditors 👏 They showed an incredible mix of technical depth and collaborative energy and we're pumped to have them on board.

electisec's tweet image. .@boredpukar and @ret2basic who consistently brought the 🔥 during Block 7 fellowship are now joining us as resident auditors 👏

They showed an incredible mix of technical depth and collaborative energy and we're pumped to have them on board.

Loading...

Something went wrong.


Something went wrong.