I don’t normally make personal asks of the
@code4rena
community, but I have a big one to make.
I’ve really pushed the C4 team so hard this year and especially this quarter. It’s been a wild last couple months. There’s so much stuff happening behind the scenes to get ready for an
Average days to awarding on
@Code4rena
over the last 22 months.
Getting faster all the time. Our judges and CAs kick ass.
@cloudellie
and
@itsmetechjay
just keep driving things faster.
Looking forward to seeing these numbers after the optimizations
@0xtotem
’s work has added.
💯💯 to
@zksync
for competitive auditor airdrop
If your project wants to incentivize tons of security pros to care about your protocol and ecosystem security, reach out to
@code4rena
— we’d love to help you do this, too.
Looking forward to helping make more of this happen.
@TheWavexyz
@0xMackenzieM
@0xnirlin
@jack__sanford
I’d prefer not to spend any energy debating this as I see no merit in it and the extremely narrow audience can make up their own minds, but I can fast forward it.
I can point to evidence that LSW alters competition incentives without even guaranteeing meaningful participation;
If you want to get really good at something, do it competitively.
Be uncomfortable. Allow yourself to make mistakes. Measure your growth. Study what the best do.
That’s why
@code4rena
works and has helped grow scores of top tier auditors and bounty hunters.
This is 100% why
@code4rena
didn’t drop lows even after competitors created marketing narrative that they only focus on serious issues.
Not allowing low-severity issues in a competitive audit is a convenience to the platform, NOT an improvement of security outcomes for customers
Sunday reflection: contest that won't pay for low/info findings and why I think they shouldn't do that.
Context: I'm participating in a contest that follows this rule. Unfortunately, I discovered it only once I had already submitted some of them (totally my fault to not have
@trust__90
Main thing the world is full of is untapped talent :)
Names we don’t know today will be leaders tomorrow.
I’m excited for the opportunities people are getting who’ve been overlooked cos they had to claw over piles of bodies to drink at the awards fountain.
Feeling grateful today for
@code4rena
's community. What a privilege to be part of this. There's always challenges, but I don't take it for granted for a second.
When web3 exploits happen, quick coordination among good actors is essential.
SEAL 911 is a collaborative initiative by the web3 security community designed to provide support for incident response.
Please bookmark and share:
🌶️ The DSS venue and the industry is full of auditors who made their name competing on
@code4rena
.
Logically incongruent when people imply that those without a name aren’t good auditors when C4 has been one of the primary talent pipelines for the field for >2 years
#DSSspice
None of my intelligent (130+ IQ) friends argue in PJQA/escalations regularly. They only discuss selectively and rarely e.g. when a judge misunderstands the implications of their finding, but almost never argue spontaneously in their own time. This has been a long term consistent
@milotruck
Among technical careers, this is not unique to auditing, but it is unique in the way that the market really wants to pay for mature talent to keep playing a role that is mostly indistinguishable from entry level work (aside from expectations).
🌶️ Audits in general simply aren’t designed to find all bugs, but in web3 we NEED to find more bugs faster than traditional methods and keep them out of deployed contracts.
That’s what
@code4rena
’s been incentivizing for two and a half years and 231 audits.
#DSSspice
I never worry about auditor churn on
@Code4rena
.
Why?
I believe 95% of people who get exceptionally good at pure bug-finding won’t do it at that level indefinitely.
Great talent always seeks higher leverage, more meaningful impact. Bug-finding is security expert table stakes.
In the beginning, I dreamed of being constantly booked with solo and team audits. Now, I dream of getting free from any engagements and not doing any audits for a few months. Neither is easy to achieve.
@milotruck
So there’s this funny dynamic where people start out doing work they love so much they’d do it for free and then they basically do it until you couldn’t pay them enough to keep doing it 😂
“Scamming the judge” is what
@GalloDaSballo
calls it.
@code4rena
just invested $90k in three Supreme Court Judges meticulously standardizing rules to cover these scenarios based on past case law.
Take a look at their extensive work:
Audit Contests Alpha: Audit contests are a game of reporting and negotiating for medium-severity findings.
Highs are usually black and white and rarely solos, but almost all of the top researchers' findings that I've read are very nuanced and in places that no one even looks at.
💥 BREAKING: The results of the Arbitrum competitive audit are in!
Props to
@xuwinniexu
for finding both high-risk vulnerabilities in this audit and running away with $105,573.46!
Much respect to
@arbitrum
for their commitment to the highest security outcomes
More 👇
@milotruck
This is the journey of nearly every auditor I have ever known for my entire time in the field.
Some find new ways to make it interesting, but many move on to better ways to leverage the skill and wisdom they’ve amassed, like consulting or management or entrepreneurship.
I’m lucky to call Tré a mentor and friend.
@Code4rena
is better because of him. I’ve spent many insomniac chats hearing his insight about how C4 can better serve customers.
He’s the best—wise, honest, extremely hardworking, & cares about customers and his teammates as people.
Today marks my 2 year anniversary at
@code4rena
I will be eternally grateful to
@sockdrawermoney
and
@_ninek
especially for taking a chance on me, and giving me the platform to thrive through their leadership style.
Also extremely grateful to be able to work with people like
This is a fantastic product.
@gasbot_xyz
gets you gas where you need it from the balance where you have it.
From a
@code4rena
security legend, no less.
Hear ye! Hear ye! Quick announcement for
@gasbot_xyz
📜
We're reducing the Gasbot fee to FREE from now until the end of ETHDenver (March 3rd). Test it out without any fees and see if you like it ⛽
Ridiculous cyber security numbers from JPMorgan just dropped
• Spends $15 billion annually on IT defense
• Experiences 45 billion hacker attempts per day
• Carries 62,000 tech specialists to protect system
They're making those hackers work for it
Having worked alongside
@trust__90
for the better part of the last year through C4, I believe very strongly:
1. his actions were in good faith
AND
2. he will personally help make the space better in terms of processes because of this incident.
People are saying all kinds of terrible things while being uninformed so allow me to share more details.
I've initiated coordination privately with Immunefi officials 3 hours before the white-hack. 90 minutes later, I realized the asset is currently used by the frontend and
Kudos go to
@CloudEllie1
@itsmetechjay
and the
@code4rena
civics team. This is what they’re always optimizing for, but it’s mostly thankless work.
No one praises trains for running on time. But if you’re a train, it’s is your
#2
job behind moving people from point A to B.
@0xKaden
Best experience and most reasonable rules by far is at
@code4rena
. The rest decent but have got some work cut out for them. Not gonna go into details here. Just my two cents.
Happy Valentine’s Day to all of web3, thanks to the leadership of
@samczsun
who has turned competitors into collaborators to better secure our ecosystem.
Before
@_SEAL_Org
, web3 security community coordination looked more like this:
@jack__sanford
Jack, I am always and forever too tired to argue with you.
I apologize for using offensive language. I’m just explaining my own thinking as to why we didn’t adopt the model.
I won’t apologize for the criticism of the culture your approach has contributed to competitive audits,
We’re installing flood lights in the Dark Forest.
Intel coordination is going to make it much harder to be a bad actor.
Thanks for your leadership,
@samczsun
Today, we're launching the latest
@_SEAL_Org
initiative, and it's going to change crypto security forever. It's called SEAL-ISAC, and this is why we need it
I think I’m not alone here when I say
We all have days where it feels like we’re a hundred year-old man with our grinning decapitated head glued to the front of a train
My next article discusses the different contest platforms and I'm trying to visualize each platform in one image and phrase.
@code4rena
: Gentle Giant
What do you think? 😁
New competitive audit dropping August 31st!
$100,000 up for grabs to auditors with valid findings in the Wildcat V2 codebase
Biggest prizes go to the most unique, highest severity vulnerabilities
Let’s go 🤝
@WildcatFi
5 highs, 11 meds
nice wins all around for
- security
- public goods
- competitive audits
- dark horses
- winners
kudos again to all participants and especially
@zachobront
as the volunteer judge on this one
🏆 The results of the
@Optimism
OP Superchain competitive audit are in!
This was an intense competition on live deployed code that had previously been audited several times
The 2v2 Pro League teams together found 4 high-risk issues + 4 mediums. But the big surprise is around
Seriously
@0xtotem
is a gem.
It’s been a blast working with him and seeing all the great ideas he has come to light at
@code4rena
.
- AI deduplication
- audit docs bot
- what’s next?
Sorry, but S-tier is being married to your cofounder so you’re never alone in whatever keeps you up at night and always having your most brilliant collaborator and advisor ready to talk through ideas and problems.
AOL Keyword:
#OddlySpecificHumblebrag
@Guhu95
I think accelerated pools are bad and inherently trend toward unfairness.
We did it first and I was even the one who suggested the idea to OpenSea.
BUT
I regret the model, its impact, and the subsequent pressure it has unleashed to do this even on smaller pools.
Mea culpa 😩
A friend of mine suggested that I clarify the nature of the danger of woke AI, especially forced diversity.
If an AI is programmed to push for diversity at all costs, as Google Gemini was, then it will do whatever it can to cause that outcome, potentially even killing people.
This was the thing that immediately made the competitive audit model a clear win in my mind.
The best auditors I know sense the gravity of the responsibility and have the humility to know how easy it is for one person to miss something.
@zachobront
Always good advice to follow what you’re fascinated by! Best long term investment is aligning what you do with what you actually *want* to do.
So, alternatively: *If you’re interested in ZKPs* it’s a v cool opportunity to audit AND learn.
(2/3 of scope’s .sol anyway)
The sweetest and kindest people I’ve met in the crypto/web3 space are security auditors. I consider it a privilege to get to work alongside them in
@code4rena
.
Thanks to everyone who’s been part of the community from sponsors to judges and wardens and DAO members and advisors and everyone who’s supported C4 along the way.
It’s been an honor and a privilege to serve.
See you in the arena!
I super love open data but pls be careful with charts based on lagging intel.
Same chart now shows July with >270 different
@code4rena
wardens finding valid high quality bugs that bots couldn't find.
SorrynotSorry to say competition remains pretty fierce on c4 :)
I super love open data but pls be careful with charts based on lagging intel.
Same chart now shows July with >270 different
@code4rena
wardens finding valid high quality bugs that bots couldn't find.
SorrynotSorry to say competition remains pretty fierce on c4 :)
⚡️ Announcing the first public goods competitive audit ⚡️
We’re bringing the highest security outcomes to the OP Superchain
Top projects are teaming up to incentivize the most eyes on the code, as well as the most elite security talent 👇
Everyone's focused on what returns you can get in the upcoming bull market, but be sure to manage a portion of your investment portfolio in mind of long-term value.
A 2003 vintage proprietary Nikon USB adapter graded as Flawless could pay your grandchildren's tuition someday.
After 488 days of highs & lows on
@code4rena
, I've finally secured my first win on a C4 contest 🏆
11 out of 15 H/M (including a solo finding) helped me secure the Top Hunter & Gatherer + Top QA report.
Now in the all-time Top
#100
!
Thank you
@code4rena
and
@phi_xyz
for this
🏆 The 200,000 $OP Superchain competition is not only the first public goods competitive audit
It’s also the first time TWO 2-player Pro League teams battle it out alongside our 9,527+ warden community
This brings up two essential questions 👇
Security is simply allocating your pain and inconvenience budget.
Would you like to be run over by a semi at random OR smash your hand with hammer once a week and maybe STILL get run over by a semi someday because you didn’t smash your hand with a hammer *twice* a week?
For 69 minutes on Monday, this account was hijacked via sim swap and used to send a phishing link.
We hold Code4rena to high security standards: we have policies in place requiring 2FA on all staff accounts.
Unfortunately, access control for Twitter was missed based on
Real ones already know
@aramas95
is an S-tier marketer, C4 staff member, and teammate.
But she also had *literally under one minute* response time to Monday’s simswap incident. Living out a show-don’t-tell example of our principle that *everyone* is on the security team.
Personal vulnerability disclosure:
I made a stupid comment in a 3am tweet which came off as flippant and passive aggressively critical of a c4 customer.
This is against my principles and beliefs about security being a constant process and shame undermining security outcomes.
Reserving hard-to-get talent in competitive audits is a great and smart thing to do—but tricky to do fairly!
Pro League + Dark Horse is how we're doing this at
@code4rena
and this
@Optimism
Superchain audit is our first go at it.
Here's how we think about it.
🐎 ENTER THE DARK HORSE ERA OF C4
In the OP Superchain audit, EVERYONE is invited to compete against the 2v2 Pro League teams
The DARK HORSE BONUS lets you maximize your winnings by matching or outperforming one or both teams
How it breaks down 👇
🌶️ Bottom line when comparing competitive vs trad audits:
“More auditors, more issues found” is how
@banescusebi
put it in 2021 ethcc talk—but doesn’t have to mean mo money, mo audits.
@code4rena
gives you more brains per dollar in a code review
scheduled on demand.
#DSSspice
@shunduquar
Builder team would’ve prolly been able to ship this like a year ago if they weren’t having to clean up my slammed-together JSON / CSV and awkward GitHub-as-database ball of mud architecture while still making everything keep working lol
“This is the true joy in life, being used for a purpose recognized by yourself as a mighty one.
Being a force of nature instead of a feverish, selfish little clod of ailments and grievances, complaining that the world will not devote itself to making you happy.
I am of the
@0xcastle_chain
No, C4 is still independent.
No requirement at all to work with Zellic if you want to work with C4. We totally intend to keep collaborating with other firms—it's essential for how C4 works.
This is a signal consultative and competitive audits are not opposed, but complementary.
What’s funny is I agree it’s not a venture scale business!
Trying to scale security offerings to meet ambitious venture returns often means compromising on security.
🌶️ There’s poor allocation of security budgets cos of immaturity of the space + high stakes
Success as an industry looks like projects spending LESS on audits
/ bounties BECAUSE they invest MORE in process / consulting / dev education / architecture review early on
#DSSspice
@pashovkrum
@CharlesWangP
Yeah, C4 makes it pretty hard for common exploits to get through.
It’s just untenable to expect any single auditor to find everything, but the average auditor can miss 60% of common HMs in C4 and the diversity of perspectives / volume of auditors makes for a fat safety net.
@CharlesWangP
Code4rena was born in the height of the bull market *because* demand pushed trad audit timelines out 3-6 months.
Legends and fortunes were made because there were only 8-15 wardens per competitive audit that first year.
Surges just bring in more wardens to fuel the next surge.
It feels emotional tbh, seeing all of these incredible auditors whose careers have been boosted by C4 in this lineup.
One of my favorite things about C4 is how we've built -- and are continuing to build -- a platform where talented people get opportunities based on performance.