deth Profile Banner
deth Profile
deth

@dethSCA

2,018
Followers
339
Following
98
Media
1,373
Statuses

I help secure web3. Part of @EgisSec . DM me for an audit:

๐Ÿ“… Book an audit ๐Ÿ‘‰
Joined December 2022
Don't wanna be here? Send us removal request.
Pinned Tweet
@dethSCA
deth
7 months
Announcing @EgisSec . @nmirchev8 and I are combining our strengths to provide better security services than we could ever do alone. We have just finished our first private engagement with @TrotelCoin and will post the report very soon. ๐Ÿ‘€
Tweet media one
6
11
78
@dethSCA
deth
2 months
Around a year ago I started web3sec and it changed my life. My story. I first learned about auditing and the world of web3sec in 2022 from @pashovkrum 's Bulgarian discord server. At the time I was getting ready to change jobs and I was studying NodeJS hard, preparing a
60
51
485
@dethSCA
deth
2 months
This is what started my web3 journey...
Tweet media one
23
24
270
@dethSCA
deth
6 months
To all junior/beginner web3 security researchers. I'll give you an alternative to a 30h+ course. Watch @ProgrammerSmart 's Solidity 0.8 and Hack Solidity playlists, then jump straight into Solodit. โฌ‡
7
31
212
@dethSCA
deth
11 months
Stats from my first 4 months of active auditing. - 9 High severity issues found - 19 Medium severity issues found - ~10, 000$ in rewards from contests All of this with a full time dev job. I still have a lot to learn and I'm extremely grateful to everyone that has helped me.
19
14
205
@dethSCA
deth
1 year
Got 4th place on my 4th ever contest. This was also my 1st contest on @sherlockdefi . Thank you for the opportunity. I'm just getting started. ๐Ÿ”ฅ
Tweet media one
36
5
175
@dethSCA
deth
10 months
Decided to take a look at a small BB on @immunefi , after 2 hours I got the report done for a small bug. Yesterday it got confirmed. It got downgraded to Low, but it's still my first confirmed BB.
Tweet media one
16
4
165
@dethSCA
deth
11 months
For 3 hours of auditing @KelpDAO I made close to Bulgaria's monthly average wage. Web3 is insane.
Tweet media one
11
5
139
@dethSCA
deth
2 months
Can't believe I've been in web3sec for 1 year now. Your whole life can change in such a short period of time if you put your mind towards a goal.
4
7
108
@dethSCA
deth
5 months
3rd contest result for @EgisSec and a few stats: ๐Ÿ’ฐ$19,771 in winnings for April, we are waiting on a few more results. ๐Ÿฅ‡First contest win and 3rd consecutive Top 2 finish. Thank you @sherlockdefi and @useteller for the opportunity.
Tweet media one
12
2
103
@dethSCA
deth
4 months
May stats for @EgisSec . ๐Ÿ† ๐Ÿ“…2nd month of contests as a team โš’7 completed contests ๐Ÿ’ฐ$24,333 in winnings ๐Ÿ†Placements: ๐Ÿฅ‡๐Ÿฅ‡๐Ÿฅ‡๐Ÿฅ‡๐Ÿฅ‰ ๐Ÿ”2 Highs, 10 Mediums found Recaps will be dropping everyday for the next week, so keep an eye out for alpha. ๐Ÿ‘€
6
2
102
@dethSCA
deth
1 year
How I audit. - CTRL + K + 0 to collapse all functions, so I can get a quick overview of the code - First pass of the contracts, quickly go through everything, adding @audit tags to anything important - Write lots of notes, explaining complex logic, variables, etc. - After I get a
8
10
100
@dethSCA
deth
5 months
Do you want to learn a deceptively simple vulnerability? ๐Ÿ‘€ This vulnerability yielded us ( @EgisSec ) 1st place in the recent @useteller contest on @sherlockdefi .๐Ÿ† Let me explain. ๐Ÿ’ญ
3
10
102
@dethSCA
deth
1 year
Stats for my first month of active auditing. ๐Ÿ’ป - Received 2,300$ rewards from 3 contests on @CodeHawks and 1 contest on @sherlockdefi . ๐Ÿ’ต - Uncovered 5 High and 6 Medium severity vulnerabilities. ๐Ÿ› - Doubled follower count since beginning of the month. I've improved so much
10
6
99
@dethSCA
deth
6 months
A much better auditor than me once told me: "The difference between a good and an elite auditor, is not the technical knowledge, it's about how many questions they can ask." Learn to question everything, that's the best way to find critical vulnerabilities.
4
12
97
@dethSCA
deth
1 year
Do you want to get better at auditing? Go to @SoloditOfficial and filter by: User: @IAm0x52 Number of finders: At most 1 You'll be left with 91 unique issues, reported by one of the best auditors in the space.
1
16
92
@dethSCA
deth
3 months
You don't understand Solidity's try-catch. This article from @RareSkills_io is the best one I've ever seen on the topic. An absolute must read for anyone who wants to level up their Solidity game. Kudos to RareSkills for the great article!
2
18
97
@dethSCA
deth
1 year
Insanity going on in @code4rena . One of the biggest contests ever. Planning on taking 1 week off from work to completely focus on this contest. See you in the arena auditors.
Tweet media one
5
5
93
@dethSCA
deth
6 months
First contest results for @EgisSec . Thank you to @cantinaxyz and @VenusProtocol for the opportunity. Expect more results in the upcoming weeks. ๐Ÿ’ช
Tweet media one
15
2
85
@dethSCA
deth
5 months
April stats and recap for @EgisSec is here. ๐Ÿ† Read the whole thread for a recap of all contests and alpha. ๐Ÿงต Stats: ๐Ÿ“…1st month of contests as a team โš’5 completed contests ๐Ÿ’ฐ$24,632 in winnings ๐Ÿ†Placements: ๐Ÿฅ‡๐Ÿฅˆ๐Ÿฅˆ ๐Ÿ”21 High's (1 solo), 18 Medium's (2 solo) found Recap โฌ‡
6
7
89
@dethSCA
deth
7 months
This is where my web3sec journey started. A lot of people have told me they never read it or that it's too boring, but I got hooked the moment I started reading it.
Tweet media one
7
2
82
@dethSCA
deth
8 months
Not a bad result for only ~10 hours of work.
Tweet media one
3
1
83
@dethSCA
deth
4 months
People constantly ask me: "What tips can you give me to be a better auditor?" My tips are these: - Patience - Discipline If you have these two traits, you will succeed in whatever you put your mind to.
4
9
83
@dethSCA
deth
10 months
The first of many.
Tweet media one
6
2
79
@dethSCA
deth
1 year
I have a little cheat sheet that contains all the things I SHOULD do when I do an audit. - Passing high/low/no value to a function - Break the developers assumptions based on docs, comments, messages from them. - Look through all possible contract states (is the contract paused,
5
9
81
@dethSCA
deth
7 months
Big news on my end. Today I gave my notice at work. In a couple of weeks I'll be all in in web3sec. The past months were just warmup, now the real work begins. On a side note, @nmirchev8 and I have something to cool to show you. More on that, soon.๐Ÿ‘€
Tweet media one
16
5
81
@dethSCA
deth
6 months
Every auditor needs this tool in his toolkit. CodeSlaw is a search engine, that will search your keyword on Ethereum, Polygon, Arbitrum and more. This can be an incredibly helpful tool for bug hunters especially, as a bug in one codebase can usually be found in others as well.
2
9
81
@dethSCA
deth
6 months
Junior auditors, do NOT overcomplicate things when you audit. Instead of: creating complex diagrams, writing a whole test suite, etc... Focus on: thinking as a blackhat and deep understanding of the codebase and it's external integrations. That's the meaning of "I read code".
6
8
80
@dethSCA
deth
6 months
It's time. I officially left my web2 dev job to pursue web3sec full-time. I'll post my stats for the whole time I've been doing web3sec part time in a couple of days. Now this tattoo's meaning is truly coming to life.
Tweet media one
11
1
73
@dethSCA
deth
3 months
We are pleased to announce that @EgisSec is now offering smart contract security reviews for Rust protocols. ๐Ÿฆ€ We are expanding our knowledge and expertise constantly, so we can help secure more and more of web3. ๐Ÿ”’
Tweet media one
4
5
73
@dethSCA
deth
2 months
The CTF challenge has officially began! ๐Ÿ‡ Anyone that wants to participate, please read the README and submit your issues correctly. Remember, there are 3 challenges each worth $200!๐Ÿ’ฐ Submissions will be open until 16/08 at 16:00 UTC. gl & hf!
2
14
72
@dethSCA
deth
28 days
Only strong guys in @EgisSec .
Tweet media one
4
2
73
@dethSCA
deth
3 months
To all Solana, Cosmos & Cairo auditors/developers out there. ๐Ÿ‘€ @trailofbits has a list of common security vulnerabilities to watch for in your next audit/project.
3
12
73
@dethSCA
deth
11 months
Incredible learning resource, that all web3 security researchers should know. Link. โฌ‡
7
14
71
@dethSCA
deth
4 months
I don't know who these @EgisSec dudes are, but they are doing alright. ๐Ÿฅ‡
Tweet media one
6
1
70
@dethSCA
deth
6 months
If you see a method that takes an array as a parameter, always ask yourself: - What if there is a default value element? - What if there are duplicate elements? - What if the array is empty? - Does the order of elements matter?
2
8
71
@dethSCA
deth
7 months
After doing 2 private audits, I can say without a doubt, that private work > contests. As @DevDacian put it: "Contests suit people who love arguing with strangers on the Internet"
5
1
68
@dethSCA
deth
1 year
Quick breakdown of the issue that netted me a 2,000$ reward from the Cooler contest on @sherlockdefi . ๐Ÿงตbelow.
7
6
65
@dethSCA
deth
1 year
Learning from real world exploits and hacks is one of the best ways to learn how to identify them. Identifying past mistakes, in the code you are currently auditing, is a fantastic way to provide that much more value to a protocol. This repo has over 300 real world hacks with
4
8
66
@dethSCA
deth
7 months
To be the best you have to learn from the best. @xiaoming9090 has a staggering 5 pages of unique issues on Solodit. If you want to learn from someone, learn from him.
4
3
67
@dethSCA
deth
2 months
Nailed the #14 spot on @code4rena 90 day leaderboard with our recent win in the Basin contest. Proud to achieve such a high only from 1 contest on the platform!๐Ÿ† @EgisSec
Tweet media one
4
4
66
@dethSCA
deth
1 year
Yesterday, the @WildcatFi contest ended on @code4rena . I decided to not read the docs during the contest at all. I wanted to experiment with this "methodology" and see if it fits me. I have to say, the first few days of the contest were hard, but after the 3-4 days, I started
7
0
66
@dethSCA
deth
1 year
To all the beginner auditors out there, this is for you. Your first audit will be hard, you probably won't understand the codebase, you probably will think that the code and the devs are perfect and no issues can be found. I was where you are a month ago. It was hard and I felt
1
6
62
@dethSCA
deth
1 year
To all the newbie auditors out there, the current @ensdomains contest on @code4rena seems like a good first contest to jump into. ~200 sloc in just 1 file. If this is your first contest, try to get a deep understanding of the protocol and how it works. If you get to a point
4
1
64
@dethSCA
deth
6 months
Why bug bounties aren't a good starting point for beginner web3 security researchers. I recently had a chat with a beginner, who told me he is completely new and asked if starting with bug bounties is a good idea. My take. โฌ‡
5
7
64
@dethSCA
deth
1 year
Every auditor needs this tool in his toolkit. The full precision calculator will help you quickly visualize large numbers and grasp more complex math equations.
2
10
59
@dethSCA
deth
3 months
We @EgisSec placed second on the recent @chainlink CCIP contest on @CodeHawks .๐Ÿฅˆ Very happy with the result, we learned a lot from this contest and it was a pleasure auditing it. More results soon.๐Ÿ‘€
Tweet media one
2
3
64
@dethSCA
deth
5 months
Have you ever wondered if the bug you just found, can appear in other codebases? You don't know how to query the blockchain to find similar issues?๐Ÿค” Glider is a query engine built by @xyz_remedy , which lets you create in-depth search queries for the blockchain. ๐Ÿ‘‡
2
8
64
@dethSCA
deth
1 year
How did I learn Solidity in a week? Easy, I watched the Solidity 0.8 playlist by @ProgrammerSmart at 2x speed. I watch everything now at 1.5x speed at least, most at 2x. This will speed up your progress immensely.
11
5
63
@dethSCA
deth
7 months
Daily reminder that CREATE2 used in an assembly block, doesn't revert on failure. Instead it returns address(0).
3
7
63
@dethSCA
deth
1 year
Update for goals for September 2023. Make 1000$ from auditing contests. โœ”๐Ÿ’ต Made ~2300$ already. Find a unique. โŒGot very close to this, got 1 issue with just 1 duplicate. Participate in a contest with a team. โœ” ๐Ÿ‘จโ€๐Ÿ’ป๐Ÿ‘จโ€๐Ÿ’ปParticipated with @B353N & @catscanaudit on the Ondo
4
0
61
@dethSCA
deth
1 year
A lot of people have asked me how to learn/use Foundry. Here is the way I learned it. - I started off with @ProgrammerSmart 's playlist on YouTube. - Watched a video, after that I wrote what was shown on the video and a bit extra, just to play around. - After finishing the
4
5
58
@dethSCA
deth
7 months
Using address.codehash != bytes32(0), is a bad way to check if an address has any deployed code. Let me explain. โฌ‡
2
6
60
@dethSCA
deth
4 months
Another small win for @EgisSec on the recent OP contest on @cantinaxyz . ๐ŸŽ‰ Expect results and recap for May in a couple of weeks. ๐Ÿ‘€
Tweet media one
1
4
60
@dethSCA
deth
11 months
Want to learn from the best? In this video, @samczsun showcases several real life exploits he found in the wild. Link. โฌ‡
1
3
58
@dethSCA
deth
11 months
Stay tuned for more.
@MartinMarchev
Martin Marchev
11 months
We managed to secure 2nd place at the PartyDAO contest! Really happy with our result! I'm so proud of my teammates @MarinaPironeva and @dethSCA . Such a great teamwork, fellas! This has been such an invaluable experience. Thanks for the opportunity, @code4rena & @prtyDAO ๐Ÿซก
Tweet media one
23
2
80
6
3
58
@dethSCA
deth
5 months
These are @EgisSec 's stats from 2 out of the 5 contests we did in April. ๐Ÿ’ฐ15,900$ in winnings. ๐ŸฅˆSecond place finishes in both contests. We are waiting for 3 more results to come out. Stay tuned. ๐Ÿ‘€
8
2
58
@dethSCA
deth
5 months
Are your Foundry tests taking minutes to run? Got to ๐—ณ๐—ผ๐˜‚๐—ป๐—ฑ๐—ฟ๐˜†.๐˜๐—ผ๐—บ๐—น and add this line: ๐™ซ๐™ž๐™–_๐™ž๐™ง = ๐™›๐™–๐™ก๐™จ๐™š This will make Foundry opt-out of Solidity's IR compilation. You can read more about Solidity's IR complication here.
2
8
58
@dethSCA
deth
1 year
How do I get into auditing? This is the most asked question I get in my dm's. There is no "best" way to start, in terms of steps, but I'll give you a short summary of the beginning of my journey and what things I would change, if I was starting again from zero. ๐Ÿงตbelow.
1
15
55
@dethSCA
deth
1 year
"How do I learn Solidity?" If you've never programmed before and have 0 knowledge, @PatrickAlphaC 's course has got you covered. If you already know a programming language or you are a quick learner, @ProgrammerSmart 's Solidity 0.8 playlist is the way to
4
4
52
@dethSCA
deth
2 months
Second contest on @code4rena and first ๐Ÿ†for @EgisSec on the platform. The code was very fun to audit and it was very bulletproof. Thank you @basinexchange for the opportunity it was a pleasure working with you!๐Ÿค
@code4rena
Code4rena
2 months
๐Ÿ† The results of the Basin competitive audit are in! Congrats to everyone who submitted valid findings, especially to @EgisSec ( @nmirchev8 and @dethSCA ) for a landslide win in their second team showing! Respect to @basinexchange for their solid commitment to the highest
Tweet media one
3
4
39
4
2
56
@dethSCA
deth
1 year
For the past 2 auditing contests I decided to not read any documentation related to the code. Here are some pros and cons: ๐Ÿ”ดCons: - The first few days are a pain, especially if the code is badly written or is very complex/big. - In rare cases, what seems like a bug is 'by
6
4
56
@dethSCA
deth
6 months
Looking for a great tool to put in your web3 toolkit? has a calldata encoder/decoder, storage slot search engine and more. Shoutout to @bytes032 , as I found the tool a while ago thanks to him.
0
9
42
@dethSCA
deth
1 year
What helped me the most to start finding issues on audit contests? - Thinking like a blackhat. - Deep understanding of the protocol. - Creative and out-of-the-box thinking. - Persistence and not giving up. - Knowledge of external contracts that the protocol interacts with. What
6
6
52
@dethSCA
deth
5 months
We @EgisSec have uncovered > 100 High/Medium severity vulnerabilities. ๐Ÿ› We won't stop doing what we do best anytime soon. ๐Ÿ’ช
Tweet media one
3
3
51
@dethSCA
deth
11 months
Decent little reward from @WildcatFi on @code4rena . Let's see what the next one brings.
Tweet media one
2
2
50
@dethSCA
deth
7 months
Every auditor needs this tool in his toolkit. The full precision calculator will help you quickly visualize large numbers and grasp more complex math equations.
5
10
52
@dethSCA
deth
5 months
Give some love to @MartinMarchev . With a family and a full-time job, he still won. What's your excuse?
@immunefi
Immunefi
5 months
1/14 Time for a new #WhitehatSuccess Story! @MartinMarchev is a hands-on hacker who started web3 security only a year ago, getting serious only in Dec '23. But that didn't stop him from bagging first place in the recent Immunefi Arbitration Boost with over $13,000 in earnings.
Tweet media one
9
12
137
2
1
50
@dethSCA
deth
3 months
We @EgisSec have uncovered > 50 High and Medium severity vulnerabilities just in the last 3 months. You can view all our achievements below. ๐Ÿ‘‡
1
5
49
@dethSCA
deth
4 months
Another๐Ÿ†added to @EgisSec 's trophy room.๐Ÿฅ‡ This was a fun contest with some cool vulnerabilities. Thanks @sophon and @sherlockdefi for the opportunity.
Tweet media one
4
2
51
@dethSCA
deth
5 months
Are you struggling with understanding proxies? @yAcademyDAO have all the information that you need. What is a proxy? Common vulnerabilities with proxy implementations? All this and more, you can find below. โฌ‡
3
4
48
@dethSCA
deth
1 year
First-week stats: - 39 hours studying, writing code, and consuming information. - Finished Mastering Ethereum, Ethereum 101. - Finished Solidity 0.8 playlist from Smart Contract Programmer. - Started Solidity 101. "The journey of a thousand miles begins with a single step."
5
3
45
@dethSCA
deth
1 year
Got second place on the Cooler contest on @sherlockdefi . Next time Iโ€™m aiming for first. ๐Ÿ’ช
@sherlockdefi
SHERLOCK
1 year
๐Ÿ† Cooler Audit Contest Results Are Live ๐Ÿ† Congrats to: 1. @IgniteLikeAFire - $2,010.70๐Ÿฅ‡ 2. deth - $1,985.86๐Ÿฅˆ 3. @0xjimmyk - $1,522.80๐Ÿฅ‰ @0xjimmyk made $4,500.00 fixed pay + $1,522.80 from the contest pot! $17,000.00 rewards โžก๏ธ $5.3M+ paid out in rewards.
3
1
12
13
2
48
@dethSCA
deth
4 months
Another one.๐Ÿฅ‡
@HatsFinance
Hats.Finance ๐Ÿฆ‡๐Ÿ”Š
4 months
๐Ÿ†Winners๐Ÿ† ๐Ÿฅ‡ $4,500 - 1 Medium, 1 Low - @EgisSec ( @nmirchev8 & @dethSCA ) ๐Ÿฅˆ $4,000 - 1 Medium - 0x5a73...102e ๐ŸŽ–๏ธ $1,500 - Lead Auditor @p_tsanev
1
2
11
6
0
47
@dethSCA
deth
3 months
Having a good way to create randomness in web3 is very difficult. Luckily @officer_cia has created an amazing article on the subject. ๐Ÿค
1
10
47
@dethSCA
deth
1 year
Stop pattern matching when participating in an auditing contest. You'll make 50 cents when reporting such an issue. The best auditors are the ones that find the unique issues, no one else found. Do you want to be the best? Be creative, don't pattern match.
5
3
47
@dethSCA
deth
1 year
Are your Foundry tests taking minutes to run? Got to ๐—ณ๐—ผ๐˜‚๐—ป๐—ฑ๐—ฟ๐˜†.๐˜๐—ผ๐—บ๐—น and add this line: ๐™ซ๐™ž๐™–_๐™ž๐™ง = ๐™›๐™–๐™ก๐™จ๐™š This will make Foundry opt-out of Solidity's IR compilation. You can read more about Solidity's IR complication here.
2
8
45
@dethSCA
deth
14 days
New security audit report is published for @Convergence_fi ๐Ÿซก The code was very solid and it was great working with the Convergence team ๐Ÿค Read the full report below ๐Ÿ‘‡
Tweet media one
4
5
47
@dethSCA
deth
1 year
Goals for September 2023. Make 1000$ from auditing contests. โŒ Find a unique. โŒ Participate in a contest with a team. โŒ Get 400 followers. โŒ Work 4 hours a day, everyday. โŒ I have bigger plans for the end of the year. One of them will be quitting my full-time job so I can
8
3
45
@dethSCA
deth
1 year
Beginners focus too much on preparation. Reading old reports from @SoloditOfficial , doing Ethernaut, Damn Vuln Defi, reading medium posts. Basically they do everything, just not auditing. Your first audit is going to suck, but it's the only way to truly progress. The quicker
8
2
45
@dethSCA
deth
6 months
Put some respect on @arabadzhiev_ โ€™s name. 3 contest wins in a row. ๐Ÿ†
@arabadzhiev_
Arabadzhiev
6 months
Ladies and gents, I recently took on what was probably my greatest Web3 security challenge to date - A Solana Rust contest, without any prior knowledge on any one of those two. And it looks like I did it againโ€ฆ Thanks for the opportunity @code4rena !
Tweet media one
32
5
203
5
0
46
@dethSCA
deth
1 year
Having to learn assembly (YUL) for the contest that I'm auditing. Definitely a new experience and at first glance it's really difficult, but I'll pull through. Do you know assembly (YUL) and if yes, can you recommend some good resources to learn more?
9
4
45
@dethSCA
deth
4 months
May recap for @EgisSec 1/7 ๐Ÿ“ @Convergence_fi on @HatsFinance ๐Ÿ†Placement: ๐Ÿฅ‡ ๐Ÿ’ฐ$4500 ๐Ÿ›1 M, 1 L Prosโœ… - Found 1/2 M's and the only L in the contest. - The team started to click. ConsโŒ - Didn't focus on the correct part of the codebase at the start. Thoughts๐Ÿ’ญ The team
3
2
46
@dethSCA
deth
1 year
Those first few days of auditing a new codebase, what a magical time. Man they suck.
5
3
41
@dethSCA
deth
1 year
Well, this was fun. Thank you again @marchev and @MarinaPironeva . Couldn't have done it without you.
Tweet media one
12
3
43
@dethSCA
deth
6 months
Want to expand your audit toolbox? As security researchers it is inevitable that we will face YUL (Assembly) during our audits. You don't need to memorize everything about YUL now, this thread will aggregate resources on the topic, so you can look them up when you need them. โฌ‡
1
4
44
@dethSCA
deth
1 year
The Tornado Cash hack is one of the most unique exploits that happened in the last couple of months. This video, by @ProgrammerSmart , explains the explains the exploit in-depth and how the attacker managed to pull it off. Next time you are auditing a similar protocol, keep an
5
5
41
@dethSCA
deth
5 months
April was a very good month for @EgisSec . Multiple top place finishes, tens of High and Medium severity vulnerabilities uncovered. ๐Ÿ› We'll post stats and a full retrospective for April in the coming week. Keep an eye out.๐Ÿ‘€
Tweet media one
1
3
44
@dethSCA
deth
1 year
Foundry tests and PoC's have leveled up my auditing game so much. Instead of having to do complex function flows in your head and keep track of everything there, just write a simple test and see if what you were thinking is actually true. Your mind might deceive you, but code
1
3
42
@dethSCA
deth
26 days
New security audit report is published for Volt๐Ÿซก The audit was only a few days, but we still uncovered a High and a few Low severity issues๐Ÿ’ช Read the full report bellow๐Ÿ‘‡
Tweet media one
0
1
42
@dethSCA
deth
1 year
Momentum is key in auditing. If I'm on fire on an audit I'll continue to grind it hard, but If I'm feeling confused/lost at some part during work , I'll take a short break and come back. I don't believe in the "beat your head against the wall for 5 hours straight". Most of the
7
1
42
@dethSCA
deth
1 year
People often ask me: "What roadmap did you follow to start auditing?", "What resources do you recommend?", "What's the fastest way of getting into auditing?". There is no roadmap for web3 auditing. The space is so vast and there is so much information to consume. People get
4
0
42
@dethSCA
deth
1 year
The @BrahmaFi protocol that is currently having a contest on @code4rena is integrating @safe in a very interesting way. In order to fully understand what the protocol is supposed to do, I highly recommend reading the Safe docs and watching this video, to understand the modular
3
9
39
@dethSCA
deth
1 year
Hear me out. Instead of doing CTF, you can participate in audit contests.
10
3
42
@dethSCA
deth
1 year
I'm no prodigy and I'm not gifted in auditing in any way. I work hard, optimize my time and never give up. In the span of 2 years, I: Learned C# and got my first ever dev job. After 10 months, got a mid position offer with C#. 4 months after that, I learned Node and React (with
4
0
41
@dethSCA
deth
1 year
Parallel data structures, should set off alarms in your head, during a smart contract audit. They usually consist of two data structures: Example: Mapping that holds some kind of record for an address. ๐™ข๐™–๐™ฅ๐™ฅ๐™ž๐™ฃ๐™œ(๐™–๐™™๐™™๐™ง๐™š๐™จ๐™จ => ๐™๐™š๐™˜๐™ค๐™ง๐™™) ๐™ฅ๐™ช๐™—๐™ก๐™ž๐™˜ _๐™ง๐™š๐™˜๐™ค๐™ง๐™™๐™จ;
1
3
39
@dethSCA
deth
1 year
Another goal met. โœ… Just looked at my profile and I saw that I got 413 followers. My goal for this month was 400, starting at ~300 in the beginning of the month. I surpassed this goal and it's still not even the middle of the month. Thank you all for the support and thank you
4
1
38