Security Researcher Rust, Solidity, C , Go

Joined April 2024
137 Photos and videos
Pinned Tweet
Found a Medium-severity vulnerability in Zebra, @zcash's Rust full-node implementation, and reported it through the Zcash Bounty Program for a $37,500 bounty. Already patched and shipped in v4.5.0 โ€” disclosure below. github.com/ZcashFoundation/zโ€ฆ @ZcashCommGrants Had some duplicates too. Feels good ๐Ÿ˜
17
9
107
8,827
Age is an Illusion 1
1
1
97
๐•‹๐•™๐•– ๐”น๐•–๐•ค๐•ฅ ๐•Š๐•ฅ๐•ฃ๐•’๐•ฅ๐•–๐•˜๐•ช
For those asking why I focus more on blockchain projects/DLT than smart contracts, itโ€™s simply opportunity cost and attack surface. Blockchain projects are usually much larger and more complex than smart contracts. They have more moving parts, more interactions, and more room for mistakes as (particularly cos devs are constantly introducing new code changes) The probability of finding a critical bug in a complex blockchain codebase is often higher than in a typical smart contract. Many blockchain projects also donโ€™t audit their entire stack. Audits may cover specific components, while large parts of the infrastructure remain less scrutinized. More complexity. More attack surface. More opportunities to find impactful bugs. Itโ€™s simply a strategy.
2
123
Very true!! But now I find the concept of private bug bounties better as most times when protocols in general hosts bug bounty program on a web3 bug bounty platform, they end up not fully maximizing the use of it because of the number of spam submissions/AI slop that eventually end up getting the protocol team frustrated and then pausing their bounty program
If this hasn't convinced absolutely everyone that running a bug bounty program is critical in this new AI age, I don't know what will. Whatever bugs are in your code will inevitably be found. You need to ensure they are found by friendlies. Only a bug bounty program will.
3
267
Antics Decoded retweeted
Almost every bug I report is on a code base audited by "top firms". Some were math issues in code written and reviewed by BigTech alumni with PhDs in cryptography from Stanford/Ivy-League. Everyone misses bugs. I miss too. AI misses bugs. Let's stop talking about finding bugs missed by lots of experts as something new and unheard of. It's so common I've been making a living off of it for 5 years straight. I'm not the only one.
Can we stop using terms like top security firms, top auditors, or top whitehats to indicate how difficult a exploit was after they missed it? > the vulnerability had evaded years of scrutiny by many of the worldโ€™s best cryptographers. lol
4
6
120
6,055
Antics Decoded retweeted
Jun 4
๐ŸคฏAn AI security tool has 1st-place performance on security contests from just 1yr ago. Solidity-auditor v3 is out, FREE & Open Source. Thousands of Solidity developers are using the tool already. Upgrade your security baseline, use the tool๐Ÿซก pashov.com/solidity-auditor-โ€ฆ
98
127
492
41,085
Large Language Models > Self training :))
2
87
Just keep auditing and verifying that AI slop till you get a response from your LLM saying: "If you don't believe me then forget"
1
84
Antics Decoded retweeted
Huge win for my bug hunting buddy There are not many opportunities in web3 that could currently earn you $37,500 This guy did it by submitting one bug via @Zcash $1M bounty program Big congratulations ๐Ÿ‘
Found a Medium-severity vulnerability in Zebra, @zcash's Rust full-node implementation, and reported it through the Zcash Bounty Program for a $37,500 bounty. Already patched and shipped in v4.5.0 โ€” disclosure below. github.com/ZcashFoundation/zโ€ฆ @ZcashCommGrants Had some duplicates too. Feels good ๐Ÿ˜
2
2
10
1,024
Congratulations brother ๐Ÿ˜๐Ÿ‘ We keep winning!!!
Discovered a high-severity vulnerability in Zebra, @zcashโ€™s Rust full-node implementation, together with @ipwning through the Zcash Bounty Program, earning a $75,000 bounty. Fix has already been patched and rolled out in v4.5.0 release github.com/ZcashFoundation/zโ€ฆ @ZcashCommGrants
9
558
It will eventually be crazily worth the sleepless nights, just keep at it... See you at the top :)))
2
2
9
361
After almost five years, I'm no longer at @immunefi I built and led the Managed Triage Service from the ground up. Hired the team. Wrote the playbooks. Triaged thousands of vulnerability reports and helped mediate one of the largest payouts in the history of Web3 security, and plenty more behind closed doors. I'm proud of what we built and grateful to everyone I worked with. Now I'm looking for what's next. I'm looking for a leadership position in security. Joining an existing team, or building one from zero. Triage, bug bounties, Web3 security, or anything that helps secure a project or the wider org. I'm also open to consulting. Helping teams spin-up an internal security function, or advising on what a project actually needs, especially on the internal side. I know how to run triage that's operationally efficient and doesn't miss the false negatives that matter. If you're hiring or know someone who is, I'd like to hear from you. My DMs are open

ALT Game Of Thrones My Watch Has Ended GIF

38
19
220
26,750
Got a valid low in my first audit contest on Jupiter lend on c4arena. Quite proud despite the fact it was downgraded because I got this using my workflow. ๐Ÿ˜ More to come. Inshallah ๐Ÿ™๐Ÿฝ
8
1
25
1,185
A privacy meetup at the most corporate Bitcoin conference is exactly where it should be, just to remind people what actually matters. See you at Bar Luca.
Apr 21
Heading to Bitcoin 2026? Join Edge and @zano_project's Privacy Meetup Tuesday the 28th at Bar Luca for drinks, swag, and some love for privacy, self-custody, and financial sovereignty. Head over to the conference after with us to remind everyone that privacy is a right! ๐Ÿ’ช Details and RSVP at luma.com/v3rbulkc
2
281
Antics Decoded retweeted
IMPORTANT Watch this simple video guide on how to correctly deposit ZANO and fUSD into AEON Pay to avoid loss of funds. Access the AEON Pay Telegram bot here: t.me/AEON_Pay_bot?profile Credit @Lil__Kingg
8
21
30
805
Big upgrade. Making privacy easy to integrate is what actually moves adoption forward, not just stronger tech, but fewer barriers to using it.
Hardfork 6 is one of the most important upgrades in Zano's history. Gateway Addresses allow CEXes, DEXes, and bridges to integrate $ZANO using standard workflows, no custom infrastructure needed. Same privacy for users. Simple integration for services. Also shipping: ๐Ÿ”น Refined decoy selection for stronger privacy ๐Ÿ”น Improved transaction uniformity This isn't a small step. It's Zano removing the biggest barrier between privacy and mainstream adoption. ๐Ÿ”’
3
193
Three types of crypto users think they're private. Only one actually is. Some think they are private because they hold crypto, not fiat. Others think they are private because their blockchain has a privacy mode they switch on. Both get it wrong. The first group gets it wrong because they hold crypto on transparent chains where every transaction, every move is visible to anyone. The second group gets it wrong because every activity before they flipped that switch is already visible on-chain. And the moment they forget to turn it on, thatโ€™s another data point added to their public history. The real private ones never had to think about any of this. They use Zano. Privacy here isnโ€™t a mode you switch on, itโ€™s how the chain works from the first block. And when itโ€™s time to spend, they extend that same privacy into the real world through AEON Pay, Zebec Card, and other options like @shopinbit, @DFX_swiss, and @BitcoinCom. No exposure. Just private. End to end. $ZANO
1
6
212
Integrations like this donโ€™t just extend functionality. They unlock possibility. Making it possible to move assets between ecosystems without exposing positions, strategies, or balances, while still accessing shared liquidity. I donโ€™t have to choose between access and privacy.
Zano on @THORChain would also mean that Confidential Assets like $fUSD, $BTCX, $ETHX, and others could be swapped permissionlessly through their platform, as long as there is sufficient demand to set up liquidity pools. The sky is the limit with integrations like these!๐Ÿš€
1
1
160
Still chasing a repeatable AI auditing workflow that goes beyond โ€œgood prompts.โ€ (Day 3) Iโ€™m trying to build something that actually holds up across codebases, not a setup that works once and falls apart the moment the repo gets weird. That means: -> better methodology -> better tooling -> deeper research -> tighter skills -> and agents that can challenge each other instead of blindly agreeing After a lot of hours training my agents and refining the workflow, I still havenโ€™t landed a payout-grade submission yet. But one thing has clearly improved my results: running Claude Opus 4.7 Max side by side with Codex GPT-5.4 The difference has been real. Not just in raw findings, but in: - comparing outputs - stress-testing assumptions - making one model critique the other - catching weak reasoning before it turns into wasted time Iโ€™d genuinely recommend using both if youโ€™re serious about AI auditing. Funny part is I almost accidentally exploited a protocol on mainnet before I snapped back into audit mode ๐Ÿ˜‚ Still refining. Still learning. Still pushing for a workflow that is actually reliable. #Immunefi #AIAuditing
4
170
So still in the pursuit of getting a perfect automated Auditing workflow/methodology beyond just using prompts that works/does not work at times depending on the codebase but also leveraging on tools, intense research, and skills.... (Day 2) After scanning over 10 different program contracts with my current flow and not getting a single payout-grade submission candidate (found a ton of leads but later died in production/mainnet), I decided to use the whole day in feeding my AI with tons of research papers from arxiv.org and some articles too published by other AI Auditors to compare with my current workflow to see what i am doing wrong, what i might be missing, and so much more... Then make improved/better changes to my workflow and implement them. So i would try this for another 5 - 10 different program contracts, see how it goes and update you all in Day 3 (Tomorrow). Also now making use of Etherscan & Alchemy API Keys for a faster production reach/test. Thank you @unsafe_call for the tip โค๏ธ #Immunefi #AIAuditing
2
2
191