Joined October 2012
64 Photos and videos
Pinned Tweet
26 Nov 2025
Blessed to have earned my second certification from @CyfrinUpdraft! Now, Iโ€™m officially a QWS (Qualified Web3 Signer) certified along with SSCD . A huge thank you to the @cyfrin team and @PatrickAlphaC for creating such amazing tools like Safe Hash and Wise Signer.
35
5
110
19,262
Usman retweeted
The `private` keyword in Solidity doesn't mean what you think it means. Marking a variable as `private` only restricts other contracts from reading it. Anyone can still read it directly from the blockchain. This misunderstanding has led to real security vulnerabilities. ๐Ÿงต
3
11
35
1,137
Usman retweeted
Only 2.5% of crypto holders use a hardware wallet๐Ÿซจ The rest are trusting exchanges, soft-wallets or "I'll do it later". Please use a hardware wallet. For BTC & ETH, I'd recommend @Keycard_ but honestly, any reputable hardware wallet is better than none.
9
2
13
1,133
Usman retweeted
Apr 29
The seed phrase was already in the box. Had so much fun scratching it off! Amazing customer service. Very time efficient. โธ Except this is exactly how people lose everything. 10/10 scam experience.
81
109
845
95,910
Make your favorite protocol get SEAL Certificates, so you can rest easy knowing your funds are in good hands.
It's finally happening! SEAL Certifications are now open for business. ๐ŸŽ‰
1
3
55
Usman retweeted
It's finally happening! SEAL Certifications are now open for business. ๐ŸŽ‰
15
24
130
26,852
Usman retweeted
Really wild for audit firms to target their private audit clients with bug bounties. At @cyfrin outside of private audit engagements we disclose bugs directly to our private audit clients for free with no expectation of bounty. Always doing our best to protect our clients ๐Ÿค
9
3
76
3,696
Usman retweeted
Certora is hiring! We're looking for a Blockchain Validator Infrastructure Engineer to own, operate, and expand our validator infrastructure. โœ… Hands-on experience with @solana or @SuiNetwork validators is a strong plus. Apply โฌ‡๏ธ
9
13
125
10,409
Usman retweeted
You would hope that after we wrote up our findings for multiple live criticals on the Zodiac modules at @therealgregoAI months ago, that PERHAPS if one's company used these modules in a live, deployed, project the CISO would want to have another audit done (last one was 6 years ago with many changes since then) Instead what happened is Gnosis has split into multiple different entities and neither one of them wants to own something that is widely used and directly affects their core product and brand If a hacker reported this bug he would have received no bounty Unfortunately, again, it looks like DeFi will only improve through pain
Unfortunately, there is a hack related to @gnosispay and the "delay module". Please be patient while we try to contain the damage. Rest assured, Gnosis will cover all user losses.
5
4
78
7,603
Support the battle if you can. Free Roman Storm (.) com
By the way - Iโ€™m behind on legal bills, and this battle isnโ€™t over. We may face a second trial. We may need to go through appeals. There are a lot of unknowns ahead, and every one of them costs money. If you can help, please donate at freeromanstorm.com. No amount is too small. Donโ€™t hesitate to reach out.
71
141
596
107,700
Usman retweeted
May not seem like it now, but glory days for DeFi & smart contract security are coming. Teams rapidly embracing emerging tech will build safer, more defensive & hardened protocols than previously possible with lower total spend. It's always darkest before dawn.
6
4
65
1,933
Usman retweeted
100% I would love to see Mythos in the hands of @SEAL_911
2
1
8
407
Usman retweeted
Another day another hack... As a @thedaofund Fund badge holder, Iโ€™m wondering whether weโ€™ve had any conversations with @AnthropicAI Project Glasswing / Mythos teams around @ethereum security. anthropic.com/glasswing If frontier AI systems are now capable of identifying vulnerabilities across critical software infrastructure, should Ethereum be proactively applying similar approaches to core libraries, clients, ERCs, wallets, bridges, staking infra, and major DeFi contracts? Ethereum secures ~$250B in value. It feels like this should at least be part of the conversation around long-term security strategy. cc @VitalikButerin @drakefjustin @dannyryan
May 27
๐Ÿ›ก๏ธ The results for the @thedaofundโ€™s Ethereum Security QF Round are LIVE! This historic round is closing with a HUGE last minute contribution: @wintermute_t has added $200K to the matching pool ๐Ÿ”ฅ Wintermute is a well known liquidity provider, and one of the leading supporters of Ethereum security, in fact exactly a year ago today they donated $1M to @_SEAL_Org. This year they teamed up with TheDAO, @Quantstamp & several other community partners to allocate over $1.6M worth of funding to Ethereum Security Public Goods ๐Ÿ‘‡
1
3
7
1,270
Usman retweeted
edgecase: tvl == 0 && s_totalShares > 0 solution: emergency donation function but its permissionless and can be used even if there's no emergency
1
2
62
May 27
wise signer by @cyfrin is the most underrated tool in all of web3. everyone, i repeat, everyone new to web3 should train their wallet skills here before they start interacting onchain.
1
1
6
134
May 27
normalising putting money in browser extensions and keys in plaintext is the greatest sin of web3. and this has to change.
1
34
May 27
yeah wtf, there is no point using a safe multisig if the keys are stored in a software wallet. and i would argue, there is no point even using a hardware wallet for signers if you don't understand the threat vectors correctly (bybit hack). please for the love of God, learn how to securely manage money onchain or at least consult someone who knows before you put your money at risk.
He rotated all the env variables but not his private keys, thinking they were safe. Spoiler: they were not. The attacker installed a keylogger and when he opened his metamask Monday early afternoon, they got the decryption key and turns out the two keys were there (wtf?!)
2
819
Usman retweeted
Donโ€™t leave sensitive data in plaintext
๐Ÿšจ BREAKING: Active supply chain attack across npm, PyPI, and Crates.โ€‹io. Socket detected TrapDoor, a crypto stealer campaign hitting 34 malicious packages and 384 versions and artifacts, with attackers repeatedly pushing new releases across ecosystems. TrapDoor targets #crypto, #DeFi, AI, and security developers, stealing wallets, SSH keys, cloud credentials, GitHub tokens, browser data, env vars, and API keys. Socket detected releases with a median detection time of 5 minutes, 27 seconds. The fastest detection occurred 58 seconds after publication.
15
8
90
21,334
Usman retweeted
Introducing Chainlink Developer Agent Skills Chainlink Agent Skills are AI tools for building with Chainlink. Each skill teaches your AI agent how to code with a specific Chainlink product. One command to install Skills. Start prompting right away. Go build something awesome!
9
13
63
4,467
Usman retweeted
ERC-8213 is probably one of my top favorite ERCs up to date Please Im looking forward to wallets supporting this!!
Who will be next to support ERC-8213? Who is the next wallet that cares about verifying calldata??
1
7
257