Joined June 2025
75 Photos and videos
Pinned Tweet
May 13
Need an audit? You shouldn’t need 20 intros, Telegram groups, and weeks of back-and-forth just to find the right security firm. @Procur3 now has 50 security firms live on the platform, including some of the biggest names in Web3 security. Find the right fit faster.
10
4
21
1,174
If you're looking for @_SEAL_Org Certifications for your protocol, you can now request if from accredited firms on @procur3 Book your certification now from @ConsensysAudits @hackenclub @HackenProof @Quantstamp @sigp_io more on the platform today!
It's finally happening! SEAL Certifications are now open for business. πŸŽ‰
2
3
423
Jun 15
7 private keys. 1 infected developer laptop. $32 million gone. Humanity Protocol β€” a $50M-funded Worldcoin rival β€” was drained on June 9. The code was never touched. Details below
1
2
728
Jun 15
A 3-of-6 Gnosis Safe means nothing if 3 keys live on the same device. Multisig is about distributed trust β€” not just distributed signatures. Each signer should be: β€” On a separate hardware device β€” Air-gapped for privileged ops β€” Onboarded with documented key hygiene
1
18
Procur3 retweeted
In Web3, who should be getting a pentest? Answer: Everyone. The largest exploits aren't smart contract related. Pentesting covers what audits miss: β†’ Wallet connectors β†’ Frontend & API vulnerabilities β†’ Node & RPC misconfigurations β†’ Key management & access control β†’ Off-chain infrastructure One RFP on @Procur3 gets you quotes from vetted pentest firms alongside your smart contract auditors. Same platform. Full coverage. Free to use.
1
4
413
Procur3 retweeted
A protocol posted a RFP on Procur3 for a Daml audit on @CantonNetwork 15 quotes. 3 days. $6k to $48k range. This is what security audit procurement should look like. Fast - Transparent - Competitive
2
5
1,323
Procur3 retweeted
Last week StablR lost $10.4M to a multisig exploit. This week, Superfortune lost $15.18M when a multisig execution silently swapped the recipient address β€” and nobody caught it until the tokens were gone. Multisig is the leading exploit cause in value. Details below.
1
1
5
1,134
How to protect against the Superfortune vector: - Air-gap your signing device - Never approve a destination from the browser UI alone - Verify the full tx payload on your device (Ledger / Trezor)
1
64
When you've paid for the best audit firms to secure your smart contracts, use procur3.io to source: - Multisig configuration audits / reviews - Cloud infrastructure and deployment reviews - Front-end testing - Penetration testing and more from 50 verified firms.
1
48
Also this weekend: β†’ Squid Router Module: $3.2M β€” 86 Gnosis Safe wallets drained. Auth was a public constant string. β†’ Stake DAO: $91K β€” deployer key compromised, LayerZero bridge config altered, 5.4T tokens minted. β†’ SKP/WUSD/MoneyMon: ~$500K across contract flaws.
1
1
80
An audit doesn't tell you what your signers see when approving a tx at midnight. It doesn't test whether the destination can be swapped between signing and execution. It doesn't verify your signers use hardware devices that independently render the destination address.
1
1
28
May 2026 major incidents: β†’ StablR: 1-of-3 minting β†’ Superfortune: Destination tampered β†’ THORChain: Validator key β†’ Gravity Bridge: Signing β†’ Polymarket: Private key β†’ Stake DAO: Deployer key 5 of 6: key management failures.
2
1
59
May 28. DxSale. $7.3M. Legacy LP lockers from 2021, emptied. Owner privileges used to set fees near-zero, backdate unlock times to 1970, withdraw 1,400 positions. On-chain links suggest team involvement. Project silent.
1
6
70
This is a multisig address substitution attack. The signers approved. The contract executed correctly. But the destination was changed between signing and execution. If you're not verifying the destination on your hardware device, you're trusting a screen you can't trust.
1
45
Also in the news: May 30. Gravity Bridge β€” cross-chain between Ethereum and Cosmos. Compromised signing key. $5.4M drained in USDC, ETH, and USDT. ~2,102 ETH still in the attacker's wallet, being laundered via mixers. No official statement.
3
114