Mr Anon Profile Banner
Mr Anon Profile
Mr Anon

@ShieldifyAnon

5,172
Followers
485
Following
121
Media
1,488
Statuses

Co-Funder of @ShieldifySec 🛡️Blockchain security audits. Your security partner, for the long term. We have audited Lido, IPOR, Colb, Ion, Kroma, Pear and more.

Joined March 2023
Don't wanna be here? Send us removal request.
@ShieldifyAnon
Mr Anon
2 years
How to become an ALPHA smart contract auditor from zero 🥇👊 I’d appreciate a retweet, spread the knowledge 😎 Now follow the thread 👇
27
189
547
@ShieldifyAnon
Mr Anon
1 year
List of 32 Smart Contract Vulnerabilities Which every Alpha Smart Contact Auditor should know immediately 😈 l’d appreciate a retweet, spread the knowledge 🫡
11
171
474
@ShieldifyAnon
Mr Anon
8 months
This is gold! 🪙 How to become a Smart Contract Security Researcher in 2024 - Roadmap!! I’d appreciate a repost, spread the knowledge 🫡 Now follow the thread 👇
22
128
354
@ShieldifyAnon
Mr Anon
1 year
My Smart Contract Auditor Roadmap from where I started learning Web3 Security 😈 I’d appreciate a retweet, spread the knowledge 🫡
12
110
270
@ShieldifyAnon
Mr Anon
10 months
List of Some Attack Vectors/Smart Contract Vulnerabilities! 🗒️ - Reentrancy - Reentrancy via Modifier - Read-Only Reentrancy - Cross-Function Reentrancy - Cross-Contract Reentrancy - Front-Running - Front-Running - Unprotected withdraw - Front-Running - Sandwich attack -
12
84
272
@ShieldifyAnon
Mr Anon
1 year
TOP 20 public smart contract audit repositories by TOP audit companies, You Must Go Through. 🥇 Everyone chooses whether to be the Alpha Guardian of the smart contracts, Make your choice now! 👊 Retweet this post and let us all become Alpha 😈Guardians Now follow the thread 👇
5
33
245
@ShieldifyAnon
Mr Anon
9 months
In one post - Bookmark % Repost 🫡 You must read these papers if you're auditing ________ 1. Lending Protocol - Lending and Borrowing: Link: - Liquidations: Link: - Rewards: Link: - Typical
11
92
263
@ShieldifyAnon
Mr Anon
1 year
All About DeFi and Future of Finance - Full Course in 4 playlists (80 YT Videos): LINKS 👇 1. Course I: DeFi Infrastructure: 2. Course II: DeFi Primitives: 3. Course III: DeFi Deep Dive: 4. Course IV: DeFi
6
77
255
@ShieldifyAnon
Mr Anon
7 months
If you want to learn Uniswap V2 read this book: Link: If you want to learn Compound V3 read this book: Link: If you want to learn Zero Knowledge read this book: Link: If you want to learn Gas Optimization
10
65
249
@ShieldifyAnon
Mr Anon
1 year
Smart Contract Audit Process 1. First read the f*cking docs 2. Read the code line by line 3. Add comments to the code (I use Inline bookmarks) 4. Back to docs again 5. Run the tests 6. Try to find vulnerabilities and write a PoC
9
44
236
@ShieldifyAnon
Mr Anon
10 months
Black Hat Rust You are a developer and want to learn security? You want to learn real-world and idiomatic rust practices? You want to start making money with bug bounty programs? You are a security engineer and want to learn Rust programming? LINK:
Tweet media one
10
53
234
@ShieldifyAnon
Mr Anon
4 months
This is gold! 🪙 Solana/Rust Auditing and Security Resources: A collection of resources to study Solana smart contract security, auditing, and exploits. I’d appreciate a retweet, spread the knowledge 🫡
5
57
230
@ShieldifyAnon
Mr Anon
1 year
Web3 Security Checklists for Ethereum Smart Contract Development Patterns And Best Practices! Link pdf:
Tweet media one
6
54
212
@ShieldifyAnon
Mr Anon
1 year
I remember when I was working at my 8 hour job and I dreamed of becoming an Independent Smart Contract Auditor, yes I was afraid to take that risk... But, in the end, I did, I quit my job and why? - To focus 100% in Web3 Security and give my best! Was It Worth It? - Haha that
19
13
203
@ShieldifyAnon
Mr Anon
9 months
if you're auditing AMM(Automated Trading) Protocol you must read this paper! This is Gold! 🪙
4
35
196
@ShieldifyAnon
Mr Anon
9 months
If you're auditing Lending Protocol you must read these papers! 🪙 1. Lending and Borrowing: Link: 2. Liquidations: Link: 3. Rewards: Link: 4. Typical vulnerabilities: Link: 5.
8
43
200
@ShieldifyAnon
Mr Anon
1 year
Smart Contract Auditor Tools And Techniques: Table of Contents: 👇 1. Roadmap 2. Tools (Monitoring, Analysis, .......) 3. Fuzzing Resources 4. Techniques and Best Practices 5. Audit Reports And Findings 6. ZK Security 7. Blogs 8. PoCs And More:
10
70
198
@ShieldifyAnon
Mr Anon
1 year
The Auditor book- Sherlock and Code4rena findings All Findings in one place: - 100+ Auditors - 150+ Audits - 5000+ Findings Download from here:
Tweet media one
2
59
198
@ShieldifyAnon
Mr Anon
10 months
A Curated List of Web3 Security - Wargames, Challenges, and Capture the Flag (CTF) competitions and solution writeups! All Web3 Security resources to learn are absolutely free and shared daily All you need is a desire to learn!
2
45
193
@ShieldifyAnon
Mr Anon
10 months
A good paper when auditing Cross-chain/Bridge: Open problems in cross-chain protocols Link:
Tweet media one
4
39
182
@ShieldifyAnon
Mr Anon
1 year
Smart Contract Security This article serves as a mini course on smart contract security and provides an extensive list of the issues and vulnerabilities that tend to recur in Solidity smart contracts.
4
38
170
@ShieldifyAnon
Mr Anon
1 year
List of 16 Known Solidity Compiler Vulnerabilities + Preventative Techniques which every Alpha Smart Contract Auditor should know very well 😈👇 l’d appreciate a retweet, spread the knowledge 🫡
6
45
175
@ShieldifyAnon
Mr Anon
11 months
It's best learned by examples - Web3 Security By Example: For smart contract researchers only! 13 Common Attack Vectors: 1/ Integer Underflow 2/ Reentrancy 3/ Reentrancy via Modifier 4/ Cross-Function Reentrancy 5/ Cross-Contract Reentrancy 6/ Integer Overflow 7/ Phishing With
4
58
171
@ShieldifyAnon
Mr Anon
1 year
Web3 Security is one of the few space where everyone shares knowledge, helps others and motivates, it's just amazing Аll stuff you need to learn to become a Аlpha are free on Twitter/Github/Medium and Youtube but most people just don't realize it I'm glad to be a part of it
11
16
172
@ShieldifyAnon
Mr Anon
9 months
If you're auditing AMM Protocol you must read these papers! 🫡 1. Decentralised Finance and Automated Market Making: Link: 2. AMM Integration Tips: Link: 3. Understanding the Vulnerabilities Link: 4. Typical
6
36
163
@ShieldifyAnon
Mr Anon
9 months
Stop thinking about it, just quit your job and become a Smart Contract Researcher/Auditor. That's it!
24
11
168
@ShieldifyAnon
Mr Anon
10 months
Amazing List of Foundry Resources! - Tools (Frameworks, plugins and utilities for Foundry) - Solidity templates, libraries or utilities that use Foundry - Tutorials - Projects Using Foundry I’d appreciate a repost, spread the knowledge! 🫡
0
44
169
@ShieldifyAnon
Mr Anon
9 months
If you're auditing ZK (Zero Knowledge) Protocol you must read these papers! 🪙 1. A curated list of awesome ZK resources, libraries, tools and more Link: 2. Security Reviews Link: 3. ZK Bug Tracker - Common Vulnerabilities Link:
2
38
166
@ShieldifyAnon
Mr Anon
11 months
Flash Loans and how to hack them: a walk through of ERC 3156 This article describes the ERC 3156 flash loan specification as well as the ways flash lenders and borrowers can be hacked Thanks @RareSkills_io
2
30
158
@ShieldifyAnon
Mr Anon
10 months
If you're doing an audit of ERC-4337(Account Abstraction) you must read: 1. All About ERC-4337 (Account Abstraction): Link: 2. Account Abstraction Security Guide: Link: 3. ERC4337 Audit Checklist Link:
6
27
156
@ShieldifyAnon
Mr Anon
1 year
SOLC(solidity compiler) Internals in three parts: Part 1: Calling Conventions: Link: Part 2: Data Locations Link: Part 3: Quirks & Optimizations: Link:
4
39
161
@ShieldifyAnon
Mr Anon
1 year
Become a Blockchain Dev and then an Independent Smart Contract Auditor... Wrong.... Become an Independent SM Auditor directly and don't waste your time because you might miss the Unique opportunity right now! 😈
14
19
154
@ShieldifyAnon
Mr Anon
1 year
Easy question: When you call the `anon` function, what will it return and why? 1. The address of the caller(user wallet) 2. The address of the contract A 3. The address of the contract B
Tweet media one
29
15
152
@ShieldifyAnon
Mr Anon
8 months
The big mistake of everyone who starts Web3 Security Don't chase money! Knowledge will help you find the vulnerabilities and the money will come by itself, Knowledge is power!
15
13
149
@ShieldifyAnon
Mr Anon
9 months
Learn RUST in 2024. - copy
14
8
143
@ShieldifyAnon
Mr Anon
9 months
Rethink whether you should start learning Rust 🧐
Tweet media one
12
8
145
@ShieldifyAnon
Mr Anon
3 months
What is a Merkle Tree? Merkle tree is a generalisation of a hash list or a hash chain. It has “leaf” nodes, each of them have a cryptographic hash of a data black they’re accossiated with. Every node that is not a “leaf” (they’re called branch or inner node) is labelled with the
Tweet media one
Tweet media two
Tweet media three
6
20
146
@ShieldifyAnon
Mr Anon
7 months
ZK(Zero Knowledge) Proofs Learning Resources 🪙🫡 1⃣ Getting started with Zk 1⃣ ▶️ Introduction to Zero-Knowledge Proofs: 🔗 ▶️ How To Create a ZK Smart Contract: 🔗 ▶️ Zk Playground examples: 🔗 ▶️
3
34
148
@ShieldifyAnon
Mr Anon
1 year
Being an Independent Smart Contract Auditor is the amazing thing, but... But few can take that risk, to quit their 8 hour job and focus 100% on Web3 Security Are you ready to take that risk?
24
6
139
@ShieldifyAnon
Mr Anon
1 year
Exploring Security Practices Of Smart Contract Developers! Must Be Read 🫡 Link pdf:
Tweet media one
1
38
136
@ShieldifyAnon
Mr Anon
10 months
1. You're a Blockchain Dev 2. You're a Smart Contract Auditor/Researcher We need you: 1. To build really cool protocols 2. To secure these cool protocols The only way for Web3 Space to grow!
13
9
136
@ShieldifyAnon
Mr Anon
11 months
If you are doing an audit of DeFi protocol (CDP/Lending, LSD, AMM). You should read these articles: Typical vulnerabilities in lending and CDP protocols: Link: Typical vulnerabilities in LSD protocols: Link: Typical
4
31
133
@ShieldifyAnon
Mr Anon
9 months
There is no easy money made from Web3/Web3 Security - A lot of hard work required - Sometimes sleepless nights - Work almost every weekend minimum 5/6 hours Would you sacrifice your time for a more secure Web3 Space?
12
10
133
@ShieldifyAnon
Mr Anon
11 months
How was your weekend? Me: 20+ hours of auditing and reading articles 😈
Tweet media one
16
5
133
@ShieldifyAnon
Mr Anon
9 months
Ahh soon LOL😏 Just kidding... Maybe 😎
Tweet media one
9
4
130
@ShieldifyAnon
Mr Anon
1 year
My favorite VS Code extensions ✌️
Tweet media one
9
62
130
@ShieldifyAnon
Mr Anon
1 year
ALPHA Roadmap for starting your career as Smart Contract Auditor 🔥 By @QuillAudits 🫡 👇
5
26
127
@ShieldifyAnon
Mr Anon
10 months
If you're doing an audit of Liquid Staking protocol you must read: 1. Staking withdrawals Link: 2. How Do Ethereum Withdrawals Work Link: 3. EIP-4895: Beacon chain push withdrawals as operations Link: 4.
5
29
123
@ShieldifyAnon
Mr Anon
11 months
ZK Journey Journey into learning ZK. It is NOT a list of awesome resources; it’s the path I’ve taken in demystifying ZK - Core Beginner Resources - Theoretical Deep Dives - Practical Deep Dives - ZK Vulnerabilities
1
26
127
@ShieldifyAnon
Mr Anon
9 months
If you're auditing protocol integrates with external Oracle smart contracts you must read these papers! 1. All about Oracles Link: 2. The Dangers of Price Oracles in Smart Contracts: Link: 3. TWAP Oracle Manipulation Risks, Mudit
6
17
122
@ShieldifyAnon
Mr Anon
8 months
That's how I'll do an audit - already! 🤨👀 Ahh sorry a security review...
Tweet media one
22
5
123
@ShieldifyAnon
Mr Anon
11 months
Common ERC20 token Vulnerabilities: - ERC20: Fee on transfer - ERC20: rebasing tokens - ERC20: ERC777 in ERC20 clothing - ERC20: Not all ERC20 tokens return true - ERC20: Address Poisoning - ERC20: Just flat out rugged What will you add?
8
16
122
@ShieldifyAnon
Mr Anon
1 year
If You Want to Learn More about EVM bytecode with the Huff Language. This github repo is for you! A series of puzzles that go from very easy to more difficult so that you can have a hands-on introduction
5
24
121
@ShieldifyAnon
Mr Anon
1 year
And on Saturday I work hard, no time to break! Someone else? 😈
Tweet media one
19
0
119
@ShieldifyAnon
Mr Anon
1 year
A very useful Resource for ZK Bug Tracker + Common Vulnerabilities - for Alpha Smart Contract Researchers who will be participating in C4's upcoming $1,100,000 Audit Competition - (ZK Circuits) 🫵✌️
2
37
120
@ShieldifyAnon
Mr Anon
1 year
Daily habits 1. Workout 2. Learn new things - past reports/vulnerabilities/articles/YT videos 3. Do an audit 4. Two again 5. Sleep
5
5
118
@ShieldifyAnon
Mr Anon
1 year
Understanding Smart Contract Metadata! When solidity generates the bytecode for the smart contract to be deployed, it appends metadata about the compilation at the end of the bytecode. We will examine the data contained in this bytecode.
0
25
117
@ShieldifyAnon
Mr Anon
1 year
Smart Contract Audit Checklist 🗒️🕵️‍♀️ 1. General Review Approach 2. Variables 3. Structs 4. Functions 5. Modifiers 6. Code 7. External Calls 8. Static Calls 9. Events 10. Contract 11. Project 12. DeFi
4
24
117
@ShieldifyAnon
Mr Anon
10 months
If you're doing an audit of Cross Chain Protocol ( LayerZero) protocol you must read: 1. Best Practice Link: 2. A Deeper Look Into DeFi's Cross-Chain Tech Link: 3. LayerZero Omnichain Contract Examples Link: 4.
7
18
114
@ShieldifyAnon
Mr Anon
10 months
List of Top 28 DeFi Attack Vectors: If you don't know them, learn them now, you still have a little time until 2024🤨
6
25
114
@ShieldifyAnon
Mr Anon
6 months
Smart Contract Audit Process in 2023 1. First read the f*cking docs 2. Read the code line by line 3. Add comments to the code (I use Inline bookmarks) 4. Back to docs again 5. Run the tests 6. Try to find vulnerabilities and write a PoC In 2024, what changed for you?
10
11
116
@ShieldifyAnon
Mr Anon
1 year
Exploring Security Practices of Smart Contract Developers - pdf format 👇
Tweet media one
3
24
117
@ShieldifyAnon
Mr Anon
11 months
Nice Book About - How to DeFi: Advanced - What is DeFi and their differences with traditional finance - What is Ethereum and its role in DeFi - Step-by-step guides in using the various DeFi applications - Real-life use cases of DeFi And more PDF LINK:
Tweet media one
2
19
115
@ShieldifyAnon
Mr Anon
1 year
KnowledgeLists 🗒️ Ethereum Smart Contracts Security Recommendations and Best Practices: l’d appreciate a retweet, spread the knowledge 😈
2
38
113
@ShieldifyAnon
Mr Anon
8 months
Another paper Audit, yeah, I'm Cooler Are you Cooler?
Tweet media one
16
6
111
@ShieldifyAnon
Mr Anon
1 year
Being a full-time independent Smart Contract Auditor, that's the good life I love the Web3 security space
4
5
116
@ShieldifyAnon
Mr Anon
10 months
Every Web3 Researcher should have watched this YT video about -> EVM: From Solidity to byte code, memory and storage! 🙃 I’d appreciate a repost, spread the knowledge! 1/ Stack: - EVM Opcodes pop information from and push data onto the stack. 2/ CallData: - Transaction
1
35
110
@ShieldifyAnon
Mr Anon
1 year
Alpha Resource For Smart Contracts Security: Table of Contents: 👇 1. Blogs 2. Papers 3. Books 4. Trainings 5. Tools 6. Labs 7. Capture the Flag and Wargames 8. Talks 9. Misc 10. Podcasts 11. Cheat Sheets 12. Solidity Auditing Checklistt 13. Bug Bounty & Writeups 14. Bug Bounty
11
43
110
@ShieldifyAnon
Mr Anon
1 year
Why be a full-time Independent Smart Contract Researcher? A combination of many things: - Decentralization - Lifestyle - Community - Innovative technology - Protection of a lot of money - Business opportunities - Valuable protocols - learn new things every day - Much work
5
13
112
@ShieldifyAnon
Mr Anon
11 months
Challenge #3 : 🦠 Find a High Severity Vulnerability when a user tries to withdraw their funds?
Tweet media one
12
8
103
@ShieldifyAnon
Mr Anon
1 year
How to become a Better Smart Contract Auditor? It's simple, put maximum time into it and do it willingly, every single day, no Excuses First is learning, then the first letter of the word Learn is removed
11
6
109
@ShieldifyAnon
Mr Anon
3 months
Oracle Manipulation 🧐 It is one of the most common attack vectors in DeFi, so both auditors and protocols need to learn what it is and how to deal with it, so get your notepads out and dive into our thread. 📍Oracle Manipulation: Theory Firstly, let’s figure out how and why
Tweet media one
Tweet media two
Tweet media three
Tweet media four
2
24
112
@ShieldifyAnon
Mr Anon
9 months
There will be so many opportunities in Web3 Security/Web3 space this year, just don't miss them! That's why @ShieldifySec already works with nearly 10-13 Top Smart Contract Auditors in the Web3 Space for Solidity, Vyper, Rust/Solana, Go and Cairo!
9
4
109
@ShieldifyAnon
Mr Anon
1 year
I remember when my colleagues at my last 8 hour job told me that very few people succeed in becoming Independent Smart Contract Auditors... - It is very difficult... - Why do you want to do that... - You will fail... Never listen to other people's opinions. Just because they
13
13
110
@ShieldifyAnon
Mr Anon
11 months
If you want to become a Smart Contract Researcher and make $100K+ per month, you only need one thing: 👉 Persistence
5
7
104
@ShieldifyAnon
Mr Anon
9 months
Stress doesn't come from hard work, the stress primarily comes from not taking action over something that you can have some control over Stress comes from working hard on something that u don't want to work on Stress comes from ignoring things that shouldn't be ignoring
10
19
103
@ShieldifyAnon
Mr Anon
4 months
Inflation Attack - examples + code We will deep dive into the third high-severity finding in @code4rena 's KelpDAO contest. In simple terms, wardens had to audit a vault, node delegators (they’re used to invest in strategies), rsETH token (vault token) and oracle to calculate
Tweet media one
Tweet media two
Tweet media three
Tweet media four
4
16
104
@ShieldifyAnon
Mr Anon
1 year
Typical Vulnerabilities in Lending and CDP protocols⚔️ Еxplains the security of a popular pattern in the decentralized finance — the CDP(collateralized debt position) l’d appreciate a retweet, spread the knowledge 🫡
2
32
105
@ShieldifyAnon
Mr Anon
1 year
List of Bridge Hacks 🗒️ Must be read! I’d appreciate a retweet, spread the knowledge for a safer Web3 Space🫡
2
34
98
@ShieldifyAnon
Mr Anon
11 months
Repository Reproduces ECDSA Signature Vulnerabilities: This repo contains different chapters each focusing on one attack: - ECDSA signatures are malleable. - ECDSA signatures are not unique. - ECDSA signatures can reveal your private key if you use the same random number (aka
2
24
100
@ShieldifyAnon
Mr Anon
8 months
hmm, that's only true for Top Web3 Researchers
Tweet media one
10
5
101