1/10
Today we are open-sourcing the entirety of the first ZK Auditing Fellowship that just concluded
👉 You can go through the entire fellowship:
- Sessions
- Discussions
- Quizzes & puzzles
- Audit reports
- ..
A few highlights from the fellowship..
Dearest shadowy super coders, builders, and degens:
With our 3rd block slated for June, we'd like to formally introduce yAcademy:
Let's learn, teach, and protect our ecosystem together 🤝 💪
🚨 Application for the 2nd ZK Fellowship is now open!
🏃♀️ Deadline: Dec 15th
✉️ Decision: late December
⚽️ Kick off: Jan 15th 2024
🙇♂️ Duration: 3-4 months
👨💻 Codebase: Summa from the
@PrivacyScaling
group (Halo2/Rust)
Apply here 👉:
We are excited to announce that the third block of yAcademy's fellowship program will be starting in June. If you or someone you know wants to test their auditing skills and learn from the best security minds in the industry apply here:
🛡️ Coming Soon: yAcademy's Fellowship Block V 🛡️
🗓️ From April 10th to May 12th
📜 Applications are open for a limited time:
Ready to level up your smart contract security skills? It's time to suit up 💪
🛡️ Announcing yAcademy's Fellowship Block IV 🛡️
Mark your calendars: Nov. 14 - Dec. 16
Applications open!
Interested in learning web3 security? More details:👇
Every weekend carries hard decisions. Should you:
a) Get outdoors to enjoy the sunshine
b) Meet up with IRL friends
c) Make a repo of common DeFi forked protocol bugs
Just joking, that's not a hard decision. Of course you'd choose c)
Our fellowship program is a public good.
In the past 22 months, we:
👩👩👦👦 Ran 6 fellowships
🐞 Uncovered 259 serious bugs in the process
🧑🎓 On-boarded 104 sec talent to the ecosystem
📜 Published original security research
Learn more & support us here:
Ready to level up to ZK security auditing? Building privacy dApps?
We are thrilled to announce yAcademy’s ZK Auditing Fellowships! 🚀🔥🚀
Our pilot ZK fellowship: May 22nd to late June 2023.
Ready to rumble? Applications are now open:
The first guest speaker video from the latest yAcademy Fellowship Block is online!
To start Block V,
@devtooligan
shares security alpha on what he wish he knew before the yAcademy fellowship block started. 🚀🚀
Smart contract security is hard. It's good to learn from experts on twitter, but better to learn side-by-side with experts with real code
For a limited time only, apply for yAcademy's Block 6 Fellowship:
🚨 The 6th yAcademy Fellowship application is now open! 🚨
🗓️ You have 1 week to apply, this block starts on March 4 2023. Acceptance emails go out before Feb 27
✏️ Already applied? Check your inbox and buckle up...
📽️ Our next video:
Features
@gpersoon
, a prominent web3 security researcher, who goes over a collection of high-risk findings, along with tips you can apply to your own audits. Enjoy!
Today we release an inspirational talk by
@tinchoabbate
who pulls from previous experiences, best practices, and ethereum culture to dive deep into the spirit of security auditing + ecosystem safety. Enjoy!
Application to speak at the 2nd ZK Auditing Fellowship is open.
We are prioritizing bottom-up bite-sized technical talks where you can share something you're working on or something you learned.
For more details and to apply:
New year, new vid! 📽️ Happy 2023!
@leonardoalt
gives a very special demo-driven walkthrough using formal verification tooling on the solidity stack.
Lots of tips here -- put on your security researcher hats and enjoy!
We introduced a new entry requirement for the upcoming yAcademy Fellowship Block: stake 0.25 ETH. This adds incentive to engage for the full block or lose some ETH 💰
We thought this ask would add friction...
but ALL accepted fellows staked their ETH before the deadline! 🤯
Most of the Block 5 fellowship acceptance emails have been sent out 🖅👀
But the rejection emails have not been sent yet, because it's possible a few slots for the block may still be available. The suspense...
Please give a warm welcome to yAcademy's guest,
@storming0x
.
Storm is an auditor and core dev at
@iearnfinance
. He established Yearn's Safe Farming Committee and security standard they follow today.
He will be overseeing the fellows audit a new rebalancer strategy for Yearn!
To stop hacks, you must first understand them🧠
@_iphelix
gives a master class on how blockchain threat intel is evolving. Lots of good advice, including a new list of the 10 most common attack vectors:
Block 5 of yAcademy's Fellowship starts tomorrow! We have our largest number of fellows ever (25), but the acceptance rate for this block was the lowest (about 10%) 😮
It's time to reveal who the fellows in this block are so you can follow their progress...
yAcademy fellows are slicing and dicing their way through solidity challenges this week!
They're making very quick work of everything. These are no mere security students, these are black belt ninjas 🥷
All acceptance and rejection emails for Block 5 have been sent out now. 📨
Absolutely amazing to see the huge interest in the space! 🚀
Absolutely devastating to send out rejection emails 😥
If you didn't make it this time, try, try again!
Most of the Block 5 fellowship acceptance emails have been sent out 🖅👀
But the rejection emails have not been sent yet, because it's possible a few slots for the block may still be available. The suspense...
That's a wrap! Those 4 weeks flew by but yAcademy's first Fellowship is complete!
BIG thanks to
@AndreCronjeTech
for being our guest this week and thanks to all the fellows, guest auditors and yAcademy staff for all your hard work.
We can't wait for the next round!
Over 100 applicants completed the technical screening for the next
@yAcademyDAO
fellowship block in the first 48 hours! 🤯
These numbers are intense even compared to late 2022. We're happy to be part of moving this space forward 🚀
🛡️ Coming Soon: yAcademy's Fellowship Block V 🛡️
🗓️ From April 10th to May 12th
📜 Applications are open for a limited time:
Ready to level up your smart contract security skills? It's time to suit up 💪
The warm-up week of our 4th fellowship program is underway, starting with some quizzes to get fellows hot n' ready for the first audit next week
Should we open-source everything at the end of the block? quizzes, talks, audit reports, write ups of high severity bugs?
#YABlock4
Shadowy super-coder looking to become an auditor? yAcademy is starting its pilot program September 15th. Use your coding skills to audit live smart contracts alongside
@iearnfinance
's core devs. Check out our website for more details and to sign up
yAcademy has been doing smart contract security reviews since 2021, but today we have a big announcement 📢
We're rebranding our professional audits to yAudit! Give us a follow at
@yAuditDAO
and check out 🚀
yAcademy fellowships will continue as usual 👍
Devconnect recap:
- It was amazing for the team to meet many fellows from past blocks 🎉
- The conversations all week were very energizing 🗲
- But the most asked question was:
"WEN NEXT BLOCK?!?"
Stay tuned... 👀👀
Due to EXTREMELY high demand, we will soon close the application for the next yAcademy block in April. If you haven't completed the action(s) in the "next steps" email, do it today!
A retrospective into yAcademy's pilot fellowship program that was just held Sept 15 - Oct 16
Thank you fellows, organizers, devs, contributors, guest auditors and speakers for making a success 🤝
Our fellowship program is a public good.
In the past 22 months, we:
👩👩👦👦 Ran 6 fellowships
🐞 Uncovered 259 serious bugs in the process
🧑🎓 On-boarded 104 sec talent to the ecosystem
📜 Published original security research
Learn more & support us here:
The 3rd guest speaker video from Block V features an interview and AMA with
@zachobront
🚀🚀
Highlights include the improvement process of a top auditor - great alpha for anyone aiming to level up!
We love it when devs are just as focused on the small details of contracts as our resident auditors are. 🧐
@origami_fi
met that high bar. Bravo! 👏👏
Reports are live:
1.
2.
Backstage, things are so calm you could hear a pin drop. Everything is in place, all checks pass, blast off Monday.
Acceptance emails will start going out tomorrow👩🎓
The team and ZK mentors can't wait to meet accepted fellows ☺️
Ready to level up to ZK security auditing? Building privacy dApps?
We are thrilled to announce yAcademy’s ZK Auditing Fellowships! 🚀🔥🚀
Our pilot ZK fellowship: May 22nd to late June 2023.
Ready to rumble? Applications are now open:
Have you ever stressed about your project's security? Fear not,
@alcueca
talks through how to stay level-headed.
The 4th guest speaker video from Block V: Zen and the Art of Blockchain Security
🚨 Application for the 2nd ZK Fellowship is now open!
🏃♀️ Deadline: Dec 15th
✉️ Decision: late December
⚽️ Kick off: Jan 15th 2024
🙇♂️ Duration: 3-4 months
👨💻 Codebase: Summa from the
@PrivacyScaling
group (Halo2/Rust)
Apply here 👉:
Acceptance emails to the ZK Auditing Fellowship started going out. A few more tomorrow.
Please read the acceptance offer carefully .. there are time sensitive items because the Fellowship kicks off Monday 22nd.
Ready to level up to ZK security auditing? Building privacy dApps?
We are thrilled to announce yAcademy’s ZK Auditing Fellowships! 🚀🔥🚀
Our pilot ZK fellowship: May 22nd to late June 2023.
Ready to rumble? Applications are now open:
Free giveaway: we have 1 extra ticket for
@ethbelgrade
. If you want it, like this message and comment with "pick me!" ✋
We will announce the winner in 12 hours, at 20:00 UTC today. We will send a twitter dm for the details we need to get you the ticket. 🎟️
Need eyes on your code's security? 👀
There may be an open audit slot in the upcoming yAcademy block April 10 - May 12, with dozens of Fellows and our security expert Residents reviewing your code. Submit soon if interested
The 2nd guest speaker video from yAcademy Fellowship Block V is online!
@fabgenovese
gives a technical deep dive on economic modeling of complex systems in DeFi 🎲🖩
Shout out to
@yAcademyDAO
which was basically the start of my practical web3 security journey together with code4rena. Learned a ton, did my first audits and reports, met smart and cool people - 10/10 experience
You know the excitement is off the charts for the next fellowship block when MULTIPLE applicants enter invalid email addresses because they're rushing to apply 😏
Over 100 applicants completed the technical screening for the next
@yAcademyDAO
fellowship block in the first 48 hours! 🤯
These numbers are intense even compared to late 2022. We're happy to be part of moving this space forward 🚀
It's the final sprint...
Under 48 hours remaining until the Block 6 smart contract fellowship application is closed! Last call to join our smart contract security dojo in March 2024 🥷
But wait, there's more! The 5th and final guest speaker video from Block V is now online 👀
@aliatiia_
examines where security in this space is moving so that you can skate to where the puck is going and prepare for future demand 🏒
@samczsun
was kind enough to demo this to our Block IV participants! We've uploaded it onto our Youtube channel here:
In the beginning, he also demos his eth txn viewer and contrasts it vs existing options. The vscode ext is ~18 mins in. Enjoy!
The Block V application is now closed! If you applied, you will get an email in a few days saying whether you were accepted. 📨
If you missed the deadline, fill the application form to be notified when the next block application opens later in 2023
🛡️ Coming Soon: yAcademy's Fellowship Block V 🛡️
🗓️ From April 10th to May 12th
📜 Applications are open for a limited time:
Ready to level up your smart contract security skills? It's time to suit up 💪
🚨 The 6th yAcademy Fellowship application is now open! 🚨
🗓️ You have 1 week to apply, this block starts on March 4 2023. Acceptance emails go out before Feb 27
✏️ Already applied? Check your inbox and buckle up...
Fellowship Block applications are now closed! Thank you to all that applied 🙏
You can still apply, but will be placed for next block.
*We are still working through our fellowship pipeline. All applicants will receive an acceptance decision email by Nov 16th at the latest.
gm.
we're looking for someone to help us scale our ops and comms operation:
- do u have people and communication skills?
- do u eat the whole apple, seeds and all?
- are u a proactive chad?
- do u like hanging out with other uber-chads?
Join us here:
Still catching up on recent conference talks?
Last month,
@bl4ckb1rd71
spoke about improving the quality of blockchain security work at
@ethbelgrade
, the first time this topic has been discussed. Don't miss:
Fellows accepted to the yAcademy Fellowship work side-by-side with our expert yAcademy Residents, learning from the best and auditing real contracts.
This lasts for 4 weeks (+1 warm-up week) and provides unparalleled hands-on security experience.
It's the final sprint...
Under 48 hours remaining until the Block 6 smart contract fellowship application is closed! Last call to join our smart contract security dojo in March 2024 🥷
🚨 Application for the 2nd ZK Fellowship is now open!
🏃♀️ Deadline: Dec 15th
✉️ Decision: late December
⚽️ Kick off: Jan 15th 2024
🙇♂️ Duration: 3-4 months
👨💻 Codebase: Summa from the
@PrivacyScaling
group (Halo2/Rust)
Apply here 👉:
We are excited to kick off our second fellowship iteration tomorrow; it's gonna be a juicy month:
- auditing sprints
- group collabs
- 1-on-1 discussions
- retreat sessions with world-class security experts
Even after an audit is done, the task isn't always over. We still get questions from devs well after the audit is complete.
This past week, twice. And once with a 7 minute time from ask to resolution 🔥🔥
So how can you find the correct storage slot?
(Bonus question: does your approach work for unverified contracts?)
In 24 hours we will release our how-to explainer, stay tuned...😁
Engines r roaring.
Our 3rd Fellowship starts June 6th:
14 overexcited fellows
6 resident auditors
1 rock-star guest auditor
4 experts speaking
20 security-gods lurking
Do you have a codebase you want them to audit for you?
Submit it here: 👇
yAcademy fellows audited this Yearn strategy in a week-long spring, which included online and offline discussions with
@_tonkers
@storming0x
and others from Yearn.
Summary of the issues reported and fixed in this PR:
10/10
And finally super special thanks to friends who supported us with advice and help in prepping for this fellowship 🙏💚:
Barry
@barrywhitehat
,
Kyle
@kcharbo0
,
and the amazing Kobi
@kobigurk
This week was the launch of yAcademy’s Pilot Fellowship Program. Twelve devs will begin their month long fellowship that will include a rockstar panel of guests (announcements to come). We will be providing updates and summaries throughout the month!
As usual, yAcademy's Fellowship training is free as long as you are active and engaged during the fellowship. And if you make it into the block, you definitely want to make the best of the opportunity!
We have a winner from our
@ethbelgrade
ticket raffle and it is
@vladimir_elesin
! Please dm me (or open dms) to claim, otherwise we will choose a new winner tomorrow
Free giveaway: we have 1 extra ticket for
@ethbelgrade
. If you want it, like this message and comment with "pick me!" ✋
We will announce the winner in 12 hours, at 20:00 UTC today. We will send a twitter dm for the details we need to get you the ticket. 🎟️
Thank you to everyone who applied. The decision will be emailed to everyone in ~1 week. The fellowship block starts shortly after on the 14th.
Please be patient 🙂
🛡️ Announcing yAcademy's Fellowship Block IV 🛡️
Mark your calendars: Nov. 14 - Dec. 16
Applications open!
Interested in learning web3 security? More details:👇
We have amazing guest speakers from the space sharing alpha with the fellows, so you get the latest info from the experts. Some of our past talks are online
For additional info and further reading:
- you can read through our previous articles:
- review our previous public reports:
or (also includes previous Block reports)
This idea is used for free trainings at Ethereum conferences, so we only borrowed the idea. But the 100% number shows:
1. The high demand for (free!) quality training in the smart contract security ecosystem
2. More people know about the career options in smart contract security