Doing my best to protect web3 protocols.

Joined August 2025
4 Photos and videos
Got my first CVE: CVE-2026-48100 🎉 Over the last few months I’ve been heavily investing in AI-driven research workflows for Web3 security. It’s been exciting to see those workflows consistently translate into real-world findings. So far that journey has led to accepted High/Critical vulnerabilities across ecosystems including Polkadot, Celestia, Trezor, Chainflip, XRPL, Payy and others. This CVE comes from a critical soundness vulnerability in a ZK rollup that could have enabled the theft of roughly $3.5M USDC under the protocol’s intended prover model. Big thanks to the @payy_link team and specially for the smooth disclosure process. Advisory: github.com/polybase/payy/sec… Looking forward to the next one.
1
2
31
1,844
LoopGhost retweeted
I also have another theory about duplicates: some projects and platforms abusing nonsense slop submissions. You disclose an e2e-proven exploit, but it gets marked as a duplicate because of the "root cause". The slop report contains the vulnerable lines but no actual proof or has invalid claims. With enough slop, you cover all the lines where a reasonable bug could exist. Then the project reopens the invalid slop submission, pays it as Low, and avoids paying the actual Critical. That’s my worst nightmare. That shouldn’t happen ever.
I’d say that getting too many duplicates in old bug bounty programs is a sign that your hunting strategy needs improvement. Duplicates should be rare.
22
8
111
10,055
LoopGhost retweeted
Louder for the people at the back 💯💯
Replying to @LoopGhost007
🧵[5/6] What I am saying is that security culture is revealed by actions, not marketing. If a project wants experienced researchers to spend weeks looking for severe vulnerabilities before attackers find them, it has to create incentives that make that work rational.
1
1
17
1,936
🧵[1/6] Last week I privately disclosed a valid vulnerability affecting Alephium’s Wormhole bridge integration. The issue was confirmed by the team. It allowed a permissionless attacker to drain the entire balance of a live mainnet contract.
Replying to @alephium
The cause of the exploit has been identified. The exploit was NOT caused by a compromise of the guardian keys, contrary to some early external reports. The team is now fully focused on recovery and remediation efforts. We are working around the clock to address the impact of this incident and support affected users. Our next update will be shared on Monday. Throughout next week, we will provide additional information regarding the recovery process for users with ALPH locked in the bridge, further details on the exploit and its cause, and a comprehensive postmortem. We sincerely thank our community for its patience and support while we work through this situation.
2
7
40
5,667
🧵[5/6] What I am saying is that security culture is revealed by actions, not marketing. If a project wants experienced researchers to spend weeks looking for severe vulnerabilities before attackers find them, it has to create incentives that make that work rational.
1
15
2,551
🧵[6/6] Researchers notice. Attackers do too.
1
6
575
LoopGhost retweeted
Is it just me, or does Immunefi mediation often feel ineffective? I’ve never really had a good outcome from mediation. It feels like the process heavily favors the protocol, bending toward their demands while ignoring the researcher’s side. I guess it’s true that attention tends to go to the party paying the bill.
5
3
32
2,472
LoopGhost retweeted
🚨 Cantina Apex is officially the top spammer in web3 security. 65 reports to MetaMask, 5 valid. 19 to Coinbase, 8 valid. 40 to Anthropic, 4 valid. 24 valid out of 167 closed: 14.37% accuracy. This is the future? A Spammertozoa?
29
11
194
42,013
LoopGhost retweeted
May 16
Replying to @banditx0x
By checking their findings, not pointing to anyone, but check what their ai found and then you know if they do what they claim, this if they even have any public proof. Ai agents like gregoAI and kritt ai is good example of how good ai agent should be.
1
6
388
Hello @MitchellAmador. I am currently involuntarily withholding a severe vulnerability affecting a protocol listed on Immunefi because my account is banned, and the project does not provide any alternative private disclosure channel. Please lift my ban. Funds are at risk.
Hey @immunefi @MitchellAmador @0xjonah1 I would like to formally request that my Immunefi account be reinstated. I want to sincerely apologize for the times I violated platform rules in the past.
1
2
12
3,031
Hey @immunefi @MitchellAmador @0xjonah1 I would like to formally request that my Immunefi account be reinstated. I want to sincerely apologize for the times I violated platform rules in the past.
1
2
2,959
I respectfully ask you to reconsider my case. Excluding legitimate researchers who are willing to act in good faith and comply with the rules runs counter to the principles of responsible disclosure and ultimately reduces security for everyone.
1
239
Thank you for your time and consideration.
222