Zigtur Profile Banner
Zigtur Profile
Zigtur

@zigtur

1,463
Followers
588
Following
50
Media
519
Statuses

I break Rust, Solidity & Go | Security Researcher @spearbitDAO | #2 all-time on @cantinaxyz ๐Ÿช | RareSkills student & instructor | prev @quarkslab

Joined January 2022
Don't wanna be here? Send us removal request.
Pinned Tweet
@zigtur
Zigtur
1 year
Hi there, Here is a little thread about how a "hacker" tried to pwn me. As I am into crypto, he probably thought that he has something to win... ๐ŸšจDisclaimer: I am a cybersecurity professional. If you are not, do not try this at home!๐Ÿšจ
15
29
143
@zigtur
Zigtur
2 months
I'm thrilled to announce that I'm starting my @RareSkills_io instructor journey! ๐ŸŽ“ As an alumni of the Solidity bootcamp, I'm excited to give back to the community that helped shape my skills. I will give my best to teach Rust with a focus on security! ๐Ÿฆ€
Tweet media one
16
7
210
@zigtur
Zigtur
2 months
Thrilled to announce that I've joined @SpearbitDAO as a Security Researcher! Excited and ready to contribute and learn with the best in the industry! @cantinaxyz is the way ๐Ÿช
Tweet media one
37
2
208
@zigtur
Zigtur
2 months
2nd rank ๐Ÿฅˆ in the @babylon_chain competition on @cantinaxyz I learned a ton on this one about Bitcoin and Go language. I missed one High, but found some cool solo medium ๐Ÿ˜Ž
@cantinaxyz
Cantina ๐Ÿช
2 months
What better way to start the week than with @babylon_chain 's competition results ๐Ÿช Here are your top 3 ranked researchers: ๐Ÿฅ‡ @n4nika_ : $62,387.16 ๐Ÿฅˆ @zigtur : $56,390.91 ๐Ÿฅ‰ @0xDontonka : $10,754.09 Thank you to everyone that participated! Full leaderboard below.
Tweet media one
2
1
45
18
0
117
@zigtur
Zigtur
4 months
Blast results are out! I managed to rank in the top10๐Ÿช Happy about the payout, but I missed a lot of issues. Need to level up. ๐Ÿซก Thank you @cantinaxyz & @Blast_L2
Tweet media one
@cantinaxyz
Cantina ๐Ÿช
4 months
It's official. ๐Ÿš€๐Ÿช The results are in for our massive $1.2M @Blast_l2 security competition: Here are your top 3 ranked researchers: ๐Ÿฅ‡ @zachobront : $201,484.57 ๐Ÿฅˆ @Guhu95 : $119,941.96 ๐Ÿฅ‰ @tinchoabbate & @saucecri ( @theredguild ): $74,729.62 Amazing work. Leaderboard below:
Tweet media one
8
10
107
22
3
115
@zigtur
Zigtur
6 months
Ranked 2nd in @eigenlayer competition on @cantinaxyz ๐Ÿ”ฅ Hard work seems to be the way ๐Ÿ‘€๐Ÿซก
Tweet media one
15
1
108
@zigtur
Zigtur
14 days
July was a pretty cool month, I worked on several cool audits with @LoreFinance & @Cod3xOrg ! I updated my portfolio with some of the private audit reports. Wanna see cool findings? Take a look ๐Ÿ‘€
4
9
83
@zigtur
Zigtur
2 months
And another #2 rank on a Solana competition ๐Ÿ˜Ž Rust, Go, Solidity... No matter the language, security research is a mindset ๐Ÿคซ
@cantinaxyz
Cantina ๐Ÿช
2 months
Letโ€™s wrap up the week with one more batch of competition results! Hereโ€™s @getgrass_io โ€™s ๐ŸŒฟ Your top 3 ranked researchers are: ๐Ÿฅ‡ @J4X_98 : $6,355.65 ๐Ÿฅˆ @zigtur : $2,475.93 ๐Ÿฅ‰ @jonataspvt : $1,881.74 Happy Friday, and thanks to everyone that took part! Full leaderboard below.
Tweet media one
1
0
22
10
0
81
@zigtur
Zigtur
3 months
Damn, this Cantina shout-out is amazing! ๐Ÿ”ฅ Thank you for this @cantinaxyz , see you soon ๐Ÿช๐Ÿช๐Ÿช Oh... Btw... Dark Zigtur... More grinding... Soon.
Tweet media one
@cantinaxyz
Cantina ๐Ÿช
3 months
Cantina Researcher Spotlight: @zigtur ๐Ÿช A perfect example of someone who ventured into the dark forest of web3 security, grinded his way through and never looked back. Starting only at the beginning of last year, Zigtur has amassed $100,000+ in rewards at @cantinaxyz .
2
3
61
7
1
75
@zigtur
Zigtur
4 months
Top 3 on AAVE v3.1๐Ÿฅ‰ 2 good results in 2 days!
Tweet media one
@cantinaxyz
Cantina ๐Ÿช
4 months
Itโ€™s announcement season, the results for @aave โ€™s v3.1 competition are in! ๐Ÿช Here are your top 3 ranked researchers: ๐Ÿฅ‡ @StErMi : 14,285.71 GHO ๐Ÿฅˆ @krikoeth : 8,285.71 GHO ๐Ÿฅ‰ @zigtur : 6,285.71 GHO Congratulations to all those that participated. Full leaderboard below:
Tweet media one
3
3
27
7
0
70
@zigtur
Zigtur
11 days
Probably nothing ๐Ÿคซ
Tweet media one
@cantinaxyz
Cantina ๐Ÿช
12 days
Well look who we have here! The one and only @zigtur ๐Ÿช We'll be chatting to him this Wednesday 1pm Eastern Time about becoming a security researcher, how he leveled up his game, and more. Don't miss it!
Tweet media one
16
3
96
5
2
66
@zigtur
Zigtur
6 months
Look mom! I'm on TฬถVฬถ a @cantinaxyz tweet! ๐Ÿ”ฅ
@cantinaxyz
Cantina ๐Ÿช
6 months
The results of the @eigenlayer competition are officially in and we have some massive payouts to report. Out of 182 participants - only two Security Researchers placed. Big kudos to: ๐Ÿฅ‡ @10xhash - $82,750 USDC ๐Ÿฅˆ @zigtur - $20,250 USDC Excellent work! Full details below:
Tweet media one
7
6
85
6
1
60
@zigtur
Zigtur
12 days
Join me in this @cantinaxyz seminar! ๐Ÿช We will talk about my journey and how I went from Zero to Hero in web3 security in a couple months. No secret kept, pure alpha ๐Ÿซฃ๐Ÿ”ฅ
@cantinaxyz
Cantina ๐Ÿช
12 days
Well look who we have here! The one and only @zigtur ๐Ÿช We'll be chatting to him this Wednesday 1pm Eastern Time about becoming a security researcher, how he leveled up his game, and more. Don't miss it!
Tweet media one
16
3
96
7
3
59
@zigtur
Zigtur
5 months
2nd rank!๐ŸฅˆAnother week, another good result. The "prepare, work, improve from feedback, repeat" process is the way. ๐Ÿซก
@cantinaxyz
Cantina ๐Ÿช
5 months
Congratulations to all those that participated in the @VenusProtocol competition! ๐Ÿช Here are your top ranked researchers: ๐Ÿฅ‡ SBSecurity ( @Slavcheww ): $15,750.71 ๐Ÿฅˆ @zigtur : $13,250 ๐ŸฅˆEgisSec ( @dethSCA / @nmirchev8 ): $13,250 ๐Ÿฅˆ @TamayoNft : $13,250 ๐Ÿฅ‰ @thepantherplus : $1,250
Tweet media one
1
0
34
7
2
58
@zigtur
Zigtur
19 days
Zigtur + Tourism = Zigturism? ๐Ÿค”
Tweet media one
5
0
53
@zigtur
Zigtur
21 days
Zigtur in NY, ready for @cantinaxyz @UniswapFND hackerhouse ๐Ÿ‘€
Tweet media one
2
2
51
@zigtur
Zigtur
5 months
First rank ๐Ÿฅ‡ Next to some of the bests in the field ๐Ÿซฃ
@cantinaxyz
Cantina ๐Ÿช
5 months
Congratulations to all those that placed in our private @3dns_inc competition! The top 3 placements were: ๐Ÿฅ‡ @zigtur - $10,847.5 ๐Ÿฅˆ @m4rio_eth - $9,350.3 ๐Ÿฅ‰ @gpersoon - $6,542.42 Excellent work all! ๐Ÿช
Tweet media one
1
3
39
7
0
44
@zigtur
Zigtur
2 months
It's Friday, let's have some fun! Show me your best gym moves ๐Ÿ‹๏ธโ€โ™‚๏ธ I go first ๐Ÿ™‚ Here are 5 muscle-ups. Not clean ones, but still fun!
4
0
45
@zigtur
Zigtur
9 days
Did you miss the seminar? No worries, @cantinaxyz has you covered! ๐Ÿช๐Ÿ”ฅ Catch the full recording on YouTube now! ๐Ÿ“บ
@cantinaxyz
Cantina ๐Ÿช
12 days
Well look who we have here! The one and only @zigtur ๐Ÿช We'll be chatting to him this Wednesday 1pm Eastern Time about becoming a security researcher, how he leveled up his game, and more. Don't miss it!
Tweet media one
16
3
96
3
6
50
@zigtur
Zigtur
19 days
This event was amazing! Thank you @cantinaxyz @UniswapFND ๐Ÿ”ฅ I had the pleasure of meeting the @SpearbitDAO core team. Such kind and genuine people! ๐Ÿซถ
@cantinaxyz
Cantina ๐Ÿช
1 month
ATTENTION: โ€‹Calling all Security Researchers ๐Ÿช Cantina, @Uniswap , and @UniswapFND will be hosting a HackerHouse for the massive $2.35M Uniswap v4 competition on @cantinaxyz . Full access to Uniswap's team. All meals provided. No costs. Just show up. Seats Limited. RSVP Below:
Tweet media one
7
9
59
1
1
44
@zigtur
Zigtur
2 years
Actually learning Solidity security auditing, and @code4rena has amazing contents for it! ๐Ÿคซ The TraderJoe v2 report has some easy to understand vulnerabilities like this one that allows user to transfer tokens to itself and improve its own balance ! Good job @BowTiedDravee ๐Ÿฆพ
Tweet media one
3
0
43
@zigtur
Zigtur
5 months
@cantinaxyz leaderboard is now up-to-date ๐Ÿช I rank 3rd on the platform next to (really) big names! ๐Ÿซฃ
Tweet media one
9
2
41
@zigtur
Zigtur
4 months
Wait? What? Really? Yep, 2 results in the same day. I ranked #1 on Alchemix contest ๐Ÿซก๐Ÿฅ‡
@sherlockdefi
SHERLOCK
4 months
๐Ÿ† @AlchemixFi Audit Contest Results ๐Ÿ† Congrats to: 1. @ge6a_bg , @zigtur , Bauer, jasonxiale - $2,125.00๐Ÿฅ‡ 2. @xiaoming9090 - ๐Ÿฅˆ @xiaoming9090 made $7,000.00 fixed pay! $16,500.00 rewards โžก๏ธ $8.2M+ paid out in rewards.
1
1
19
5
0
40
@zigtur
Zigtur
1 year
For those working on the @OndoFinance audit on @code4rena , here is a little diagram of the rUSDY contract. I'm open to feedback ๐Ÿ™Œ Other contracts and external calls are coming soon ! (This Drawio drawing is heavily based on @14si20 recent work)
Tweet media one
5
1
32
@zigtur
Zigtur
1 year
Last week, I discovered @curta_ctf . They released the Puzzle #17 created by @_hrkrshnn . After a few tries, I managed to complete it and I had a lot of fun doing it๐Ÿ˜ Here is my write-up for this challenge:
1
4
29
@zigtur
Zigtur
1 year
Defi Security Summit 2023! ๐Ÿ”ฅ๐Ÿ”ฅ @summit_defi
Tweet media one
1
3
23
@zigtur
Zigtur
5 months
See you in Thailand ๐Ÿซข๐Ÿ‡น๐Ÿ‡ญ
@summit_defi
Defi Security Summit
5 months
Early Bird Round 1 has SOLD OUT! That was fast ๐Ÿ’จ Next round will be coming up soon + application for discounted student tickets Click the bell in our profile to get notified when we tweet ๐Ÿฅณ๐Ÿฅณ๐Ÿฅณ
Tweet media one
4
1
21
6
0
25
@zigtur
Zigtur
5 months
Managed to rank in the @Optimism contest on @sherlockdefi despite busy schedule ๐Ÿฅณ
@sherlockdefi
SHERLOCK
5 months
@Optimism @trust__90 @GalloDaSballo @milotruck @zachobront @0xStiglitz @Guhu95 @0xdeadbeef____ @bin2chen ๐Ÿ† @Optimism Audit Contest Results ๐Ÿ† 6. @0xf1b0 - $2,203.03 6. haxatron - $2,203.03 6. @niroh30 - $2,203.03 6. tallo - $2,203.03 6. @zigtur - $2,203.03
0
0
4
2
0
25
@zigtur
Zigtur
1 year
Almost done implementing ERC-1155 in pure Yul! Next step doing it in Huff ??? ๐Ÿคช
4
2
24
@zigtur
Zigtur
16 days
@cantinaxyz
Cantina ๐Ÿช
16 days
Introducing the Cantina Fellowship Program ๐Ÿช Get bonus payouts, private access to opportunities, the chance to share in the upside of Cantinaโ€™s growth, and more. More information below.
27
19
104
1
0
24
@zigtur
Zigtur
1 month
Wanna get good at security research? Be strong.
@tpiliposian
Tigran Piliposyan
1 month
As promised to @windhustler a month ago, when @zigtur did muscle-ups, I was on vacation and found a bar where I couldnโ€™t do them because it wasnโ€™t straight. But Iโ€™m ready for ROUND 2 OF THE PULL-UPS CHALLENGE. Last time I maxed out on pull-ups was during last year's challenge,
12
1
53
6
0
24
@zigtur
Zigtur
2 years
Learning Solidity at @RareSkills_io is ๐Ÿ”ฅ๐Ÿ”ฅ๐Ÿ”ฅ Smart contract auditing, I'm coming ๐Ÿ˜ˆ๐Ÿค–
0
3
22
@zigtur
Zigtur
28 days
@tpiliposian is a beast, 30 pull-ups is a crazy performance. ๐Ÿ’ช I was able to only do ~20, and not as clean as he did.
@tpiliposian
Tigran Piliposyan
1 month
As promised to @windhustler a month ago, when @zigtur did muscle-ups, I was on vacation and found a bar where I couldnโ€™t do them because it wasnโ€™t straight. But Iโ€™m ready for ROUND 2 OF THE PULL-UPS CHALLENGE. Last time I maxed out on pull-ups was during last year's challenge,
12
1
53
4
0
23
@zigtur
Zigtur
3 months
I've been holding steady at 3rd place on @cantinaxyz for a few weeks now. Where do you think I should focus my grinding next? ๐Ÿค”
1st on Cantina
68
LSW on Sherlock
49
Top10 on C4 (90-day)
16
Else?
20
5
0
20
@zigtur
Zigtur
1 year
Just started auditing the @caviarAMM project with @code4rena ! ๐Ÿ˜ˆ Hoping to uncover any vulnerabilities and contribute to improving the project's security. Enjoying the process so far! #audit #security #blockchain
4
1
20
@zigtur
Zigtur
10 days
See you in 10 minutes! ๐Ÿซก๐Ÿ”ฅ
@cantinaxyz
Cantina ๐Ÿช
10 days
Going live in 10 minutes with @zigtur ! See you there ๐Ÿช
5
0
8
2
1
23
@zigtur
Zigtur
3 months
So, results are clear! 44% think I should continue eating bugs at the @cantinaxyz . @sherlockdefi is not that far with 32%. What surprise me the most is that 13% of "Else?". Do you expect Zigtur's private audit services? ๐Ÿ‘€
@zigtur
Zigtur
3 months
I've been holding steady at 3rd place on @cantinaxyz for a few weeks now. Where do you think I should focus my grinding next? ๐Ÿค”
5
0
20
4
0
20
@zigtur
Zigtur
1 year
Really happy to get accepted in DeFi Security 101! ๐Ÿ”ฅ๐Ÿซก @summit_defi
Tweet media one
2
2
20
@zigtur
Zigtur
4 months
@jack__sanford Clearly, sharing submissions with clients has positive impacts, for both clients and researchers. Take my first experience on Sherlock with Mento. I report a solo High finding, with a valid PoC and valid impact, but my root cause description is incorrect. More explanations are
0
0
19
@zigtur
Zigtur
1 month
@pashovkrum Well, I can tell it is a good investment ๐Ÿคญ
0
0
18
@zigtur
Zigtur
1 year
Security part of @RareSkills_io Solidity Bootcamp : DONE! โœ… Halfway through the bootcamp, and I learned a ton! Next : diving into assembly with @Jeyffre Udemy courses about Yul and Gas optimization ๐Ÿซก #solidity #smartcontract
2
0
19
@zigtur
Zigtur
1 month
An Optimistic rollup adding ZK? Is this an hybrid rollup? Can't wait to see @zachobront 's work on this ๐Ÿ”ฅ
@cantinaxyz
Cantina ๐Ÿช
1 month
This Friday at 12pm ET, we'll be going live on this account with @zachobront ๐Ÿช The agenda? Diving into the work he did with @SuccinctLabs to turn the OP Stack into a ZK chain using SP1. Don't miss it!
Tweet media one
3
2
54
0
0
17
@zigtur
Zigtur
7 months
I have seen this trend everywhere. @RareSkills_io Top1, should I really be surprised?
Tweet media one
0
2
15
@zigtur
Zigtur
4 months
Amazing podcast, I really enjoyed the procrastination discussion. If you are playing long-term, you need to find what best fits with you in terms of environment, process and methodology. I would add: Don't copy what others do. Do your own mistakes, create your own way and
@DeGatchi
DeGatchi
4 months
Your strongest weapon is leveraging your knowledge. Join myself and @Jeyffre on @ScrapingBits to talk about: ๐Ÿ“š How to break into a new field ๐Ÿง Effectively researching ๐Ÿ‘จโ€๐Ÿซ Teaching and education w/ @RareSkills_io โ‰๏ธ And so much more... Out now!
0
8
64
0
1
14
@zigtur
Zigtur
4 months
@pashovkrum "holiday", wtf is that
0
0
14
@zigtur
Zigtur
1 year
23/23 Whatever, crypto friends: please stay safe. Do not click every links and do not trust everyone!
1
0
14
@zigtur
Zigtur
4 months
Several months ago, our @quarkslab team reviewed part of KUKSA.val. We showed that even if Rust is a secure language, it still has limitations. ๐Ÿ˜Ž If you want to learn more about Rust, JWT and gRPC, give a read to the full report and blogpost!
@quarkslab
quarkslab
4 months
Imagine if Software Defined Vehicles ran on open source components! Recently our engineers had the opportunity to have a glimpse of the future and audit the KUKSA.val databroker thanks to the support of @OSTIFofficial and @EclipseFdn Here is the summary:
Tweet media one
0
14
31
1
0
14
@zigtur
Zigtur
5 months
20/96 ๐Ÿซก
@TheSecureum
SฮžCURฮžUM
5 months
๐ŸŽ‰ Secureum RACE-29 Results ๐ŸŽ‰ ๐Ÿ’จ Number of Runners: 96 โš–๏ธ Median Score: 3.5/8 ๐Ÿฅ‡ Top Score: 7.5/8 ๐Ÿ™ Designer: @kamensec ๐Ÿ† Top 32 Leaderboard ๐Ÿ†
Tweet media one
1
4
21
0
0
13
@zigtur
Zigtur
8 months
Unexpected 32nd rank, Vyper is fun I guess ๐Ÿ˜…
@TheSecureum
SฮžCURฮžUM
8 months
๐ŸŽ‰ Secureum RACE-26 Results ๐ŸŽ‰ ๐Ÿ’จ Number of Runners: 73 โš–๏ธ Median Score: 3/8 ๐Ÿฅ‡ Top Score: 7.5/8 ๐Ÿ™ Designer: @luksgrin ๐Ÿ† Top 32 Leaderboard ๐Ÿ†
Tweet media one
1
6
27
0
0
12
@zigtur
Zigtur
1 year
I'm currently learning Huff to deeply understand EVM. The @RareSkills_io Huff puzzles are really efficient to learn it fast!
0
0
11
@zigtur
Zigtur
2 months
@14si20 @cantinaxyz @babylon_chain @n4nika_ @0xDontonka I missed, I miss and I will miss! But in every case, I learn ๐Ÿซก
0
1
10
@zigtur
Zigtur
2 months
Once again, a reminder to never trust anyone. Be parano. Some months ago, I had a similar scenario. It was less elaborated compared to this one. See Spear phishing can be even more easy in Web3 with all the transparency that it brings. Attackers are
@trust__90
Trust
2 months
Found myself one click away from falling to a spear phishing attack today! If you're giving services in the web3 space, be VERY careful with who you interact and how the initial exchanges of information are done. 2 weeks ago, @nftbigsummer approached for security services for
Tweet media one
Tweet media two
Tweet media three
Tweet media four
10
30
144
0
1
11
@zigtur
Zigtur
1 year
Really had a good time sharing my Post-Quantum Blockchain project at @sstic cybersecurity event!!
Tweet media one
2
4
10
@zigtur
Zigtur
9 months
First time in the @TheSecureum TOP 10 with a score of 7.7/8! That's a nice start of 2024 for me ๐Ÿฅณ RACE-25 designed by @zachobront was a really nice one!
Tweet media one
0
0
8
@zigtur
Zigtur
1 year
If you are looking for a good Yul ressource, this Udemy course is a must-have ๐Ÿ˜‰ 100% recommended by Zigtur !๐Ÿฆพ
@Jeyffre
Jeffrey Scholz
1 year
@Mr_Chonky @doychinovKrasii Yul course (which I created):
3
0
12
0
1
9
@zigtur
Zigtur
9 months
7/146 ๐Ÿซก
@TheSecureum
SฮžCURฮžUM
9 months
๐ŸŽ‰ Secureum RACE-25 Results ๐ŸŽ‰ ๐Ÿ’จ Number of Runners: 146 โš–๏ธ Median Score: 5.7/8 ๐Ÿฅ‡ Top Score: 8/8 ๐Ÿ™ Designer: @zachobront ๐Ÿ† Top 32 Leaderboard ๐Ÿ†
Tweet media one
2
3
22
2
0
10
@zigtur
Zigtur
18 days
@10xhash @sherlockdefi @SkyEcosystem Sad to hear that. This type of scenario happens sometimes. I don't know who is right or wrong, or even if there is a correct output to this situation. However, you are a beast and your work is always so valuable for projects ๐Ÿซก
1
0
10
@zigtur
Zigtur
16 days
0
0
10
@zigtur
Zigtur
1 year
My @heymintxyz ERC1155 smart contract audit is wrapped up! ๐Ÿซก Auditing this project was really funny! ๐Ÿ”ฅ No critical findings, but some high ones! All results can be found here: #solidity #SmartContracts #ERC1155
1
1
9
@zigtur
Zigtur
2 months
Maybe, maybe not... ๐Ÿซฃ
@_hrkrshnn
Hari
2 months
0
0
7
2
0
9
@zigtur
Zigtur
11 months
@zksync Era contest on @code4rena was insanely hard. It was definitely not for entry-level security researchers! ๐Ÿ˜ณ If you had trouble understanding zkSync Era's inner working, we tried to make it affordable for you! ๐Ÿซก๐Ÿš€
@quarkslab
quarkslab
11 months
Confused about zk-Rollups? Whether you took part in the zkSync @Code4rena challenge or are just curious about @zkSync Era's magic, we've got you covered! ๐Ÿš€Unravel the intricacies of a Layer2 transaction alongside experts @zigtur , turt and @0xdeadc0de___
Tweet media one
1
13
31
0
0
5
@zigtur
Zigtur
15 days
@J4X_Security
J4X
15 days
Guys, who will build an app where we can bet on SR's market value, and which platform are they signed to? With the platforms' moves in the last months, we are entering a similar scenario to that of top soccer players. It could be just a few poly-markets, but this stuff will
8
1
39
0
0
8
@zigtur
Zigtur
1 year
I am currently auditing an #ERC1155 variant for the @heymintxyz project! This is the second audit I do for this project, thank you for your trust ๐Ÿซก
0
0
7
@zigtur
Zigtur
1 year
22/23 5. Conclusion Being targeted by an attacker is a strange feeling. The scam that the "hacker" created was really clean, and I think that a lot of people could have been tricked. Hopefully, Windows Defender detects the malware. Users will most likely not be infected.
1
0
8
@zigtur
Zigtur
3 months
0
0
8
@zigtur
Zigtur
1 year
Just solved @curta_ctf #17 , and damn that chall was crazy! Congrats @_hrkrshnn for creating this chall ๐Ÿซก
0
0
7
@zigtur
Zigtur
3 months
@fede_intern @sherlockdefi @immunefi @code4rena The @sherlockdefi LSW role is one of the best feature from my POV. It ensures project a really good quality no matter what. On the other side, with the judging rules on this platform being strict (if not changing after the contest), I feel like it can lead to situations where
0
0
7
@zigtur
Zigtur
1 year
Almost wrapped up auditing the @heymintxyz Solidity project and had a blast! Managed to optimize gas usage, identified a potential security issue in the presale mechanism, and explained a bug in delegatecall. Thank you @Intenex for the opportunity!
0
1
7
@zigtur
Zigtur
1 year
Currently working on the evm-puzzles created by @fvictorio_nan ! 6/9 done ๐Ÿ‘€๐Ÿ”ฅ These challenges are absolutely amazing, thank you for the brain workout! #EVM #Solidity
2
0
7
@zigtur
Zigtur
10 months
Gm, life is good. That's it.
0
0
7
@zigtur
Zigtur
1 year
Write-up almost done! Will publish it on X once challenge phase 2 has started
@zigtur
Zigtur
1 year
Just solved @curta_ctf #17 , and damn that chall was crazy! Congrats @_hrkrshnn for creating this chall ๐Ÿซก
0
0
7
0
0
6
@zigtur
Zigtur
3 months
@Spearbit_Intern It is (1) because I want to learn about the NSR role (Not a Security Researcher) ๐Ÿ˜‚
0
0
6
@zigtur
Zigtur
1 month
Wanna see some cool findings in smart contracts written for Stellar Soroban? See this blogpost from @quarkslab ๐Ÿ˜Ž The Soroban platform allows writing Rust smart contracts. Its authorization framework is pretty strange, a sort of mix between EVM and Solana. ๐Ÿ˜ตโ€๐Ÿ’ซ
@quarkslab
quarkslab
1 month
In June 2024, Quarkslab engineers Turt and @zigtur audited the DeFi product developed by Airswift that "optimizes funds flow" between buyers and suppliers. We would like to thank the Stellar Development Foundation for supporting this project. Report here:
Tweet media one
0
3
15
0
0
6
@zigtur
Zigtur
3 months
@nisedo_ @cantinaxyz @sherlockdefi "PRANK: I EXPLOIT A 10M$ PROJECT TO SEE THEIR REACTION"
3
0
6
@zigtur
Zigtur
1 year
21/23 hse.exe starts reading all browsers data such as cookies, local storage... It then sends all data to the hacker's server using TCP connection. For crypto guys, this is where your metam @sk data are all stored (such as private keys).
Tweet media one
1
0
6
@zigtur
Zigtur
1 year
Special message to my mates @bertrandmart1 @LostAquilae who worked on the project : "Love u guys! ๐Ÿ”ฅ"
1
0
5
@zigtur
Zigtur
1 year
Little update about this: here is the final user workflow for @OndoFinance audit. ๐Ÿค– Had fun working on this @code4rena contest! Note: here the bridge contracts are calling the same USDY contract, which is not the case on practice (they are different chains ๐Ÿ˜‰).
Tweet media one
@zigtur
Zigtur
1 year
For those working on the @OndoFinance audit on @code4rena , here is a little diagram of the rUSDY contract. I'm open to feedback ๐Ÿ™Œ Other contracts and external calls are coming soon ! (This Drawio drawing is heavily based on @14si20 recent work)
Tweet media one
5
1
32
1
0
6
@zigtur
Zigtur
7 months
RACE-27: 12/140 ๐Ÿซก
@TheSecureum
SฮžCURฮžUM
7 months
๐ŸŽ‰ Secureum RACE-27 Results ๐ŸŽ‰ ๐Ÿ’จ Number of Runners: 140 โš–๏ธ Median Score: 3.2/8 ๐Ÿฅ‡ Top Score: 6.5/8 ๐Ÿ™ Designer: @GalloDaSballo ๐Ÿ† Top 32 Leaderboard ๐Ÿ†
Tweet media one
1
2
29
0
0
6
@zigtur
Zigtur
2 months
@_hrkrshnn @babylon_chain @cantinaxyz Thank you! Now I guess, I have the prerequisites ๐Ÿซก
0
0
6
@zigtur
Zigtur
1 year
Just diving into the world of @solana and its @solanamobile Saga to create a @0xTicketCoin ! Excited to be working on the Solana programs and can't wait to see where this project takes me ๐Ÿ˜ #web3 #Solana
2
2
5
@zigtur
Zigtur
5 months
Here is a big difference between Web2 and Web3. You can't rely on "external party security". Protect your project from untrusted parties, but also from trusted parties when possible. Defense in depth is mandatory. My message to Web3 devs: Please listen when a SR warns you about
@windhustler
GiuseppeDeLaZara
5 months
I see a lot of competent solidity devs carrying the web2 mindset where: > External integrations are not your business. > If something breaks elsewhere, you will just point fingers in that direction. This does not apply to web3. Itโ€™s your business if something breaks externally
1
2
27
0
0
5
@zigtur
Zigtur
2 months
@trust__90 I don't understand how such project can survive. How could we get rid of this type of behavior and get an healthy ecosystem? For me, the only way would be to set security as a marketing argument. Maybe a reputation platform/standard for projects?
2
0
5
@zigtur
Zigtur
2 months
@0xSpearmint @RareSkills_io Nice! May the crab power be with you ๐Ÿฆ€
0
0
5
@zigtur
Zigtur
1 year
Just got my ticket to the @summit_defi event in July! ๐Ÿซก Excited to learn about the latest in #DeFi security and network with other professionals in the field. #blockchain #cryptocurrency
1
0
5
@zigtur
Zigtur
4 months
@_hrkrshnn I really like to see more Rust into the Ethereum ecosystem. Best language for security imo
1
0
5
@zigtur
Zigtur
1 month
@theweb3hacker @NoahMarconi See you there ๐Ÿ˜Ž
0
0
5
@zigtur
Zigtur
13 days
1
0
5
@zigtur
Zigtur
2 months
@_hrkrshnn Finally found some time to read this report. Really nice findings! Good job @ralexstokes & @mattsse_ ๐Ÿซก The recent Babylon competition shows similar issues (especially for memory consumption issues). Nice to see Rust being more and more used for this type of application ๐Ÿฆ€
0
0
5
@zigtur
Zigtur
1 year
@Jeyffre Amazing! Your set theory blog post is really smooth and accessible to web3 dev, good job @RareSkills_io team ๐Ÿฆพ
1
0
4
@zigtur
Zigtur
10 months
@solidityauditor Hi, I was targeted several weeks ago. And yes, they were trying to get me download a malware, which I did. 'cause I like risk :D I explained it here:
@zigtur
Zigtur
1 year
Hi there, Here is a little thread about how a "hacker" tried to pwn me. As I am into crypto, he probably thought that he has something to win... ๐ŸšจDisclaimer: I am a cybersecurity professional. If you are not, do not try this at home!๐Ÿšจ
15
29
143
1
1
4
@zigtur
Zigtur
2 months
@cergyk1337 @cantinaxyz @cergyk1337 wen LSR? ๐Ÿ‘€๐Ÿ
2
0
5
@zigtur
Zigtur
3 months
@bbl4de_xyz @cantinaxyz @_hrkrshnn said that 5 top-3 were required (see here: ). I currently have 4 top-3. No shortcuts needed. ๐Ÿซก
1
0
4
@zigtur
Zigtur
1 year
Those days, I am looking at @zksync era for the @code4rena contest. I am learning a lot! And damn, that tech is crazy! ๐Ÿ˜ณ
0
0
1
@zigtur
Zigtur
3 months
@windhustler Update: I took a breakfast this morning, and damn my concentration is gone. I didn't eat a lot (around 200kcal) but that is killing my productivity.
3
0
4
@zigtur
Zigtur
4 months
1
0
4
@zigtur
Zigtur
2 months
@thepantherplus @RareSkills_io I'll be teaching Rust ๐Ÿฆ€
0
0
4
@zigtur
Zigtur
5 months
@_hrkrshnn Thank you for the kind words ๐Ÿ”ฅ
1
0
4
@zigtur
Zigtur
1 year
@RealJohnnyTime Where is @curta_ctf in your list?
0
0
4
@zigtur
Zigtur
1 year
@7Ragnarok7 Thank you, that was a lot of fun!
0
0
2