P.M Profile Banner
P.M Profile
P.M

@p_misirov

1,870
Followers
588
Following
874
Media
2,833
Statuses

InfoSec, Web3 Dev & UX Research. ex-ForEx trader. Interdisciplinary script kiddie & polyglot 🇪🇸, 🇺🇲, 🇷🇺, 🇫🇷, 🇳🇱 Building @SpearbitDAO @cantinaxyz

🇪🇺
Joined February 2020
Don't wanna be here? Send us removal request.
Pinned Tweet
@p_misirov
P.M
3 years
Extremely happy of having my article published by @immunefi ! Hard work pays off! Take your #web3 OpSec game to a new level and remember; "Stay safe in the #crypto space!"
@immunefi
Immunefi
3 years
This is the EXHAUSTIVE guide to securing your crypto wallet on a virtual machine and preventing bots front-running your transactions. By @P_Misirov . Well done, sir! If you follow the guide, you'll be in the top percentile of crypto power users.
1
21
47
5
4
37
@p_misirov
P.M
2 years
2
6
622
@p_misirov
P.M
8 months
when you've been grinding for hours without results and are about to quit but the chinese beaver is there to motivate you
12
45
408
@p_misirov
P.M
1 year
Am I doing this right?
Tweet media one
12
22
181
@p_misirov
P.M
1 year
I feel that I should make the ultimate security course and just make it free for everyone…
20
2
137
@p_misirov
P.M
3 years
#DeFi + #Security related content of interest: - (I recommend as starting point) - (Incident List) - (DeFi attacks compilation) - (Threat Matrix) -
Tweet media one
6
36
121
@p_misirov
P.M
3 years
⚙️ Reverse Engineering Smart Contracts ⚙️ Missing source code? Want to RE a MEV bot or suspicious contracts? Fear not! Learn how to do it yourself! 👇🧵
4
36
109
@p_misirov
P.M
1 year
We need more of these kind of challenges! Much better than your regular CTF
4
24
110
@p_misirov
P.M
2 years
Submitted a project about AI using whisper AI to transcribe interviews, stable diffusion to generate all visuals and chatGPT to write 80% of the essay. Explained the lecturer how I did it and conclusion is that faculties in Europe are not ready for this tech.
10
3
101
@p_misirov
P.M
2 years
As a developer &/or security researcher, you are a sexy target for phishing campaigns! We love sharing, cloning repos, testing code and installing dependencies until we get rekt This is a POC for a phishing campaign targeting devs who don't know the consequences of enabled FFI
3
15
84
@p_misirov
P.M
7 months
at @ETHGlobal london hackathon, someone approaches us: - "what are you guys building?" - me: oh just hooks on uniswapV4 - "cool! what do they do?" - me: incentivizing concentrated liquidity at specific tick ranges by rewarding liquidity providers with dynamic fees during high
11
6
79
@p_misirov
P.M
10 months
November has been the most profitable month yet! Blessed 🙏
Tweet media one
13
1
76
@p_misirov
P.M
1 year
👉UX tip: Using GitHub web IDEs👈 If you are looking at a GitHub repository, change the top level domain from: - to - for a web IDE view. Its much faster and easier to navigate!
Tweet media one
14
7
69
@p_misirov
P.M
1 year
If you don't have a multi-session terminal open to - run foundry unit tests - python for quick math (Leo don't kill me) - chisel for memory dumps - anvil node for block inspection and general testing - chatGPT cli API to ask questions Are you a 2023 blockchain dev?
8
3
70
@p_misirov
P.M
1 year
Past Friday 1st of September at around 19:15 I helped arrest a shooter right next to my house. It was the most insane experience I ever had in my life 🧵/n
Tweet media one
11
0
72
@p_misirov
P.M
7 months
not paying attention to @cantinaxyz is like fumbling bitcoin in 2012 - lower competition than on other platforms - massive ROI: financially, socially and professionally - you can start a whole career by doing well on cantina CANTINA is making security researchers rich
Tweet media one
10
4
69
@p_misirov
P.M
2 years
Next security trend will be the rise of smart contract Reverse Engineers who got into it because of an increase in low level understanding powered by tools and langs like Huff More effective Incident Response Obfuscation services will emerge Improved behavioral analysis tools
6
6
69
@p_misirov
P.M
1 year
1/5 One of my fav moments at @summit_defi was when @SagivMooly came running to the entrance looking for @tarunchitra who was late for his panel. We look outside and see Tarun trying to park the lime scooter in a forbidden area so Mooly dashes toward him, grabs the scooter...
3
5
61
@p_misirov
P.M
2 years
Redoing all @the_ethernaut challenges using @huff_language and arrived to Magic Number, the one where we had to write bytecode to pass the level! This is why HUFF is so cool! 👈Left: Write runtime + initialization then compile 👉Right: Write runtime then compile
Tweet media one
Tweet media two
8
4
54
@p_misirov
P.M
3 years
@olekshyn
Olek Shyn 申武松
3 years
This is as tragic as it is funny. Watch till the end.
103
875
3K
2
11
51
@p_misirov
P.M
6 months
Taylor Swift has recently revealed her concern about the state of smart contract development practices on Late Night. " ...we do know that assembly comes with trade-offs, and I think it is in everyone's interest to maintain immutable code efficient and accessible to everyone.
Tweet media one
3
7
50
@p_misirov
P.M
1 year
inb4
Tweet media one
@yacineMTB
kache
1 year
hey kid. wanna buy some illegal darknet market neural weights?
Tweet media one
34
55
1K
3
2
46
@p_misirov
P.M
1 year
You need to approach writing MEV bytecode as if you were writing malware (disclaimer, this is red teaming 101*) - Build your own obfuscation tools, never use open source ones. - Create psychological traps for researchers, the most valuable asset they have is their time
1
4
46
@p_misirov
P.M
1 year
@SpearbitDAO portfolio ABC's: A) Each and every one of our clients is working on world changing apps B) Each and every L/S/A/J Researcher at @SpearbitDAO is making a world changing impact C) Saluting the best 🫡 Name a sexier security portfolio than this
0
10
47
@p_misirov
P.M
2 years
Who is a reputable expert on Zero Knowledge Proofs? Would love to reach out for a seminar! Have any references? #zkEVM
16
5
44
@p_misirov
P.M
7 months
hands down the most "useful + educational" merch i saw at @EthereumDenver for now is @zksync 's "explain zk like im 5" book. great way to onboard new ppl into zero knowledge! hats off to their growth-marketing department
Tweet media one
1
2
42
@p_misirov
P.M
9 months
Let's start 2024 with some honesty. Mana bad.
Tweet media one
10
1
44
@p_misirov
P.M
6 months
ask him about his secret fragrance modeling career
Tweet media one
@ProofOf_Podcast
Proof Of Podcast
6 months
In a few days we will be interviewing the one and only @_hrkrshnn , co-founder of @SpearbitDAO and Cantina. It’s been a big year for them and it has barely started 👀 What should we ask him?
6
3
34
8
0
41
@p_misirov
P.M
1 year
The “move fast break things” philosophy is good for product iteration but does not make sense when working with smart contracts holding user funds. Want to do it still? Fine, sign a damages compensation agreement in advance, let’s see how strong your philosophy really is ;)
4
1
38
@p_misirov
P.M
2 years
@nicksdjohnson @gf_256 But not this one 👀
@p_misirov
P.M
2 years
- Others: using writing tests, fuzzing, formal verification, static and dynamic analysis tools... - Me:
Tweet media one
3
1
37
0
2
35
@p_misirov
P.M
2 years
- Others: using writing tests, fuzzing, formal verification, static and dynamic analysis tools... - Me:
Tweet media one
3
1
37
@p_misirov
P.M
11 months
Tweet media one
4
2
37
@p_misirov
P.M
2 years
Ok hear me out: "Dynamically Linked Huff libraries at compile time" 1⃣ What do we need to do to make it happen? 2⃣ Any directions? shameless ping cc @huff_language @solidity_lang @_hrkrshnn @alexberegszaszi @jtriley_eth @devtooligan @Maddiaa0 @refcells
Tweet media one
4
1
33
@p_misirov
P.M
1 year
Oh yes, you know it Free alpha drops for the community
Tweet media one
1
0
34
@p_misirov
P.M
3 years
@thedefiedge Those sticking around during this markdown cycle:
1
2
32
@p_misirov
P.M
8 months
that once in a lifetime feeling
Tweet media one
1
2
32
@p_misirov
P.M
7 months
what is she pointing at?
4
4
32
@p_misirov
P.M
1 year
How to kill all gas findings once and for all ⛽️ - via_ir = true - optmitizer = true - optimizer_runs = 100_000_000 - save_money = yes - compile_fast = yes Thank you for coming to my Ted Talk, have a great day
3
0
32
@p_misirov
P.M
2 years
Finally solved the first ever @curta_ctf puzzle made by the MVP @fiveoutofnine 🫡 Thank you for the headache, please make more!! Also shout out to the bitwise chads at the Hackers Delight Book club server for sharing cool resources!
Tweet media one
3
4
31
@p_misirov
P.M
1 year
🧵/6 I am used to the feel of adrenaline because of skydiving, extreme sports and martial arts. But this adrenaline rush is something I have never ever experienced, took me hours to calm down.
4
0
28
@p_misirov
P.M
6 months
real footage of a security researcher walking down the street after finding a critical vulnerability
2
1
29
@p_misirov
P.M
10 months
When I join a random discord server full of newcomers who just got into security and the admin goes off at me after I ask him for his credentials
2
0
30
@p_misirov
P.M
1 year
Provide extra value during a security engagement by creating architectural diagrams. It will improve your understanding, help fellow researchers, the protocol team will appreciate it and it will expand their documentation. All security reviews should have one!
@gpersoon
Gerard Persoon
1 year
For anyone joining in the @code4rena contest for @lukso_io . I've made the following drawing to help understand the Universal Profiles and KeyManager.
Tweet media one
37
62
345
4
4
30
@p_misirov
P.M
6 months
t̴̢̢̻̮͎̯͉̙̱̦͌̏ę̷̡̧͉͎̠̘̜̂̆̔͠s̵̡̢͇̲̗̥̤̗̯͓̓̋͆t̸̰̻̰̺̞̑͂́͗͝͠ ̵̙̫̗̖̮̅̈́̾̈́́́͊f̶̹̺͇͖̤̯̜̼̐̽͛͋̌͛͛̾̐â̴̟̺̲̲̔͛̋̀̉̆͐̽ì̴̬̫̗͓͚͂̿̕l̵̳̦̯̪̋e̴̘͓̪̺̓͛d̵̨̳̠̻̼͒̓͊̀
Tweet media one
1
0
27
@p_misirov
P.M
1 year
rm
Tweet media one
1
0
28
@p_misirov
P.M
2 years
The best security researchers are the ones with a strong moral compass. We should give credit to the positive side of human condition more often.
2
2
27
@p_misirov
P.M
9 months
no POC == skill issue so ngmi
2
2
28
@p_misirov
P.M
1 year
@apoorvlathey @Uniswap It must have been a mistake, let’s open a new issue.
0
0
24
@p_misirov
P.M
11 months
You are fine, you are still early on web3 sec. When the web2 InfoSec megabrains start joining the space that's when you will need to find new edge, because those chad-nerds can take on 5 complex projects at once without taking a toilet break (they are just not interested yet)
6
2
26
@p_misirov
P.M
3 years
Patrick from @FuzzingLabs showing how EVM disassembly works and how to reconstruct the control flow graph (CFG) of an Ethereum smart contract when you only have access to the bytecode (closed-source). -
1
7
26
@p_misirov
P.M
10 months
🌶️ take: Displaying the slightest positive reaction toward the Kyber (or any criminal) hacker is an example of lack of critical thinking and how people tend to romanticise outlaws. What's next, asking him to go on a podcast and hire him as a "solo auditor"?
1
4
25
@p_misirov
P.M
2 years
The amount of high quality guests that come do seminars at @SpearbitDAO is just unbelievable.
3
0
26
@p_misirov
P.M
10 months
We need an Offensive Security playbook for web3, so accounting for the whole cyber kill chain. Who is working on this? (If you make it happen, your long term engagement farming will skyrocket x100 so def a good incentive! Also let me read it first pls)
4
0
24
@p_misirov
P.M
8 months
is this real life @cantinaxyz ?
Tweet media one
2
1
25
@p_misirov
P.M
1 year
I see you like stories, here is another one! 1/8 @cmichelio , @Deivitto and I walk into a bar (yes this is how it starts) because @functi0nZer0 posted a tweet with an address close to Notre Dame so we decided to drop by and say hi...
@functi0nZer0
laurence
1 year
Fuck it, open invite Pub Saint-Michel, 19 Quai Saint-Michel, 75005 Paris Let's pack out a pub with the worst people in finance Open until 6am
23
5
223
3
1
24
@p_misirov
P.M
1 year
Imagine not attending @summit_defi and @EthCC this year..
5
1
22
@p_misirov
P.M
3 years
Thank you to @SCBuergel from @hoprnet for giving us the guest lecture at @KoiosDAO today! Great insights on HOPR both technical and DAO wise, passionate talk about data privacy and someone very approachable to ask questions to! Hope to see you again and GL! Go HOPR! #HOPR
0
3
22
@p_misirov
P.M
1 year
Beta is live! Lots of amazing features coming soon 👀 And yes, we rang the bell!
Tweet media one
@cantinaxyz
Cantina 🪐
1 year
We have some exciting news... Cantina Beta is Live! Before you dive in - let's talk about what all of this means for protocols and researchers today 🪐 ( Read to the end for researcher access codes 👀 ) 🧵👇
Tweet media one
11
101
148
5
0
23
@p_misirov
P.M
2 years
Tweet media one
1
2
22
@p_misirov
P.M
7 months
this is the second time cantina breaks a historic record in the security contests space in less than 3 months. impressive, considering it is only a 5 months old product
Tweet media one
@cantinaxyz
Cantina 🪐
7 months
Welcome... to the new largest competition in history with @eulerfinance ! 💰 $1,250,000 USDC 🗓️ May 20th - June 17th 📍 @cantinaxyz Invite only. Don't have one? Details below:
97
155
294
1
1
22
@p_misirov
P.M
6 months
🚨BREAKING🚨- Unedited footage of the North Korean Hacker editing his GitHub profile moments before rugging the project for +$60m
Tweet media one
@0xCygaar
cygaar
6 months
This is the Github profile of the North Korean dev that hacked Munchables on Blast. Here are all the red flags🚩 for those of you looking to hire in the future: 1) Clear logo farming, very unlikely any dev is super proficient in all of these languages/tools. There are more
Tweet media one
208
92
875
2
0
22
@p_misirov
P.M
1 year
If there is any life advice i can ever give you, is to do martial arts. I did both boxing and muay thai. My cousin was a regional boxing champion and all his latino friends would beat the f* out of me each time we sparred. Truly priceless life lessons beyond simple exercise
4
1
23
@p_misirov
P.M
1 year
This is why you should be afraid of the Discord links feature...
5
0
23
@p_misirov
P.M
1 year
@pcaversaccio @Uniswap We all approved that PR. When are you merging @Uniswap ?
0
0
20
@p_misirov
P.M
1 year
I've been following @danielvf for a long while and learned so much from him. His posts are so motivating, they always nerd snipe me and make me want to go investigate. Now seeing him live, is a whole new level of awesome
Tweet media one
2
0
23
@p_misirov
P.M
2 years
@0xtuba After certain amount, the money / happiness curve becomes logarithmic. In an (debatable) abundant (western) society, in contrast to previous centuries, money is actually less valuable than free time or personal development. Life experiences > $. Ask your elders.
Tweet media one
1
2
20
@p_misirov
P.M
11 months
Do you know what "Contract-Oriented-Programming" is, anon? @vyperlang
Tweet media one
1
4
22
@p_misirov
P.M
1 year
I was supposed to be studying
2
0
22
@p_misirov
P.M
2 years
I cant take this anymore. every day I am checking the @SpearbitDAO discord and there is alpha. And now @brockjelmore is coming on Thursday 26th to drop more alpha on practical security-focused guides and checklists for smart contract development! Can sec pros do something!?
Tweet media one
1
5
22
@p_misirov
P.M
1 year
People and Nations will soon realize that crypto technology (incl zk) solves a much deeper problem than creating an accessible worldwide financial operating system. In a world where we are sharing the digital space with AI, proof of personhood will become critical You will see
1
2
21
@p_misirov
P.M
9 months
Once again in the weird math side of the internet. This is regarding the 2+2=5 argument, point is fair but most people miss it, especially if they don't care about math or have never suffered by the hands of cryptographers redefining terms. proposition is that words and symbols
Tweet media one
33
2
18
@p_misirov
P.M
11 months
There's a lot of foundry functionality available people don't yet know about. HariGPT is good but not available 24/7. We should have a custom chatGPT specialized on foundry docs! Is anyone working on this already?? @gakonst - -
@_hrkrshnn
Hari
11 months
@emo_eth `forge inspect ContractName methodIdentifiers`
4
1
40
2
0
20
@p_misirov
P.M
11 months
If you believe money is the primary driver of action, you're in for a wild ride. Wait until you come across: - Idealists - Dark triad personalities - Unconscious destructive behavior - People prone to negative affectivity Knowing how to identify these will give you edge in life
2
0
21
@p_misirov
P.M
2 years
Like and RT if you want @alexberegszaszi to do an #EVM seminar in the @SpearbitDAO discord server.
2
6
20
@p_misirov
P.M
1 year
Love this loop comment in Huff! Very clear, very informative, very based. -
Tweet media one
3
0
20
@p_misirov
P.M
7 months
if you are a high TVL protocol leader you should invest in opsec, counter-intel and threat-intel. security is so much more than just code review, i literally walked into most high profile events by cutting the line and not showing any QR code (speaking spanish helped). imagine
2
0
19
@p_misirov
P.M
10 months
"meh, I should be able to do this in a few minutes" 1: How it started vs 2: How is it going
Tweet media one
Tweet media two
2
0
19
@p_misirov
P.M
3 years
@foldfinance Plot twist: the searcher changed his strategy and faked retirement. The repo has vulnerable dependencies which pop a reverse shell as soon as you install them.
0
0
18
@p_misirov
P.M
1 year
@gf_256 Captain here, 9 GAG has been dead for ages!! *no potato because post is small, flies away*
0
0
19
@p_misirov
P.M
1 year
@AC01000101 @Uniswap I call this open source responsible disclosure
0
0
17
@p_misirov
P.M
8 months
Tweet media one
@_hrkrshnn
Hari
8 months
LLMs x Security An AI bot, code-named 📎 helps @cantinaxyz triage bug submissions. It is very good at classifying duplicate bug reports, and we're constantly making it do more. This is a good one 🤯
Tweet media one
2
1
68
3
0
19
@p_misirov
P.M
7 months
will need to name every clippyAI update to something with substance
Tweet media one
@p_misirov
P.M
8 months
Tweet media one
3
0
19
0
2
18
@p_misirov
P.M
1 year
Now it’s a race to see how much can be exploited across the whole space
@vyperlang
Vyper
1 year
PSA: Vyper versions 0.2.15, 0.2.16 and 0.3.0 are vulnerable to malfunctioning reentrancy locks. The investigation is ongoing but any project relying on these versions should immediately reach out to us.
73
457
967
0
0
16
@p_misirov
P.M
1 year
3/5 ... and ask him: "If the screen locks, what is the password to unlock it?!" "Don't worry about it" - replies Mooly - "I work in security, there is no password" I exchange an LMFAO look with @0xRajeev who was standing next to us and ...
1
0
17
@p_misirov
P.M
7 months
i'm in Denver! hit me up if you want to connect and have a pint to talk about security / markets / AI / eAcc / bluecifer... or all the above!
0
0
16
@p_misirov
P.M
1 year
m'lady
Tweet media one
1
0
17
@p_misirov
P.M
1 year
I am going to be at ethCC
Tweet media one
@WilsonCusack
wilson
1 year
I’m not going to be at ethCC
Tweet media one
4
1
30
2
0
16
@p_misirov
P.M
1 year
Not sure who needs it but here is a complete MathJax cheat sheet for Markdown [1] [1]
0
1
17
@p_misirov
P.M
1 year
And we are only getting started! A paradigm shift in web3 security is coming @cantinaxyz
@TechCrunch
TechCrunch
1 year
Spearbit raises $7M to improve security audits in crypto through its open marketplace by @jacqmelinek
1
12
50
2
1
17
@p_misirov
P.M
1 year
5/5 ...sitting in the front row, and return the phone. "Mission... accomplished?" Needless to say i spent the whole day laughing. @SagivMooly and @tarun are absolute MVPs PS: @tarunchitra told you i would tweet this story ;)
1
1
17
@p_misirov
P.M
9 months
Real World Assets will be a powerful narrative in 2024, it is therefore that I introduce the first RWEI or Real World Ethereum Inscription (a.k.a ethscription) to trade AMSterdam city shares in a permissionless and decentralised way.
Tweet media one
1
3
17
@p_misirov
P.M
6 months
at what point can someone add "AI / ML dev" to its profile? 👀
15
0
16
@p_misirov
P.M
10 months
Report the vulnerability, act rightly and achieve excellence, you grey-hat wannabe
Tweet media one
2
0
17
@p_misirov
P.M
1 year
@BrianRoemmele Ive got to say that this is very cool and def a step forward! Couple caveats: 1) This is the equivalent of chat gpt 2.5 2) Make it easier to tune and train on local!
1
0
16
@p_misirov
P.M
8 months
you know what's coming: - an historic moment - an opportunity for glory - $1.2 million on the table @Blast_L2 on @cantinaxyz only
0
0
16