Founder @ gingersec.xyz, JohnnyTime @ Youtube, Securing Web3 @ smartcontractshacking.com & cairo.smartcontractshacking.โ€ฆ

Joined February 2012
1,760 Photos and videos
Smart contract security pays WELL. ๐Ÿ’ฐ Top auditors make $500K per year ๐Ÿ’ฐ Bug bounties can 10x that ๐Ÿ’ฐ Even โ€œmidโ€ auditors make six figures BUTโ€ฆ Only if you actually put in the work. No shortcuts here.
17
28
334
28,225
Hey @Ledger we need a way to hide near-zero-value transfers, and we need it soon. Address poisoning is flooding the transaction history with dust from lookalike addresses, and it's making the wallet UI almost unusable. A simple "hide dust transfers" toggle would solve this.
1
319
JohnnyTime ๐Ÿค“๐Ÿ”ฅ retweeted
Relistening to @arsen_bt podcast with @RealJohnnyTime Repetition is the mother of skills by @PatrickAlphaC
1
1
24
711
While everyone is running agents and optimizing token usage, i went to touch some sand. Dont forget to live ;)
4
39
719
JohnnyTime ๐Ÿค“๐Ÿ”ฅ retweeted
The live discussion is now on YouTube. How to actually earn $ as a web3 security researcher in 2026 @RealJohnnyTime, @sammyaudits, @GuildAcademy_ and the Remedy team on bug bounties vs contests vs going in-house, picking targets that pay, and what AI agents are doing to researcher economics. Watch now: youtu.be/Pp74H8j77Jg
1
14
769
๐Ÿ”ฅ Mythos might be launching today ๐Ÿ”ฅ I recommend revoking every approval across every wallet you own.
4
21
1,570
JohnnyTime ๐Ÿค“๐Ÿ”ฅ retweeted
oh yeah weโ€™re all fucked for sure lmao
bro basically said "look for bugs that could exploit zcash" that's the prompt that found an exploit in a 10 billion dollar protocol
15
21
433
65,831
What do you do when stablecoins yields suck in defi? Convert your USDC to BTC and thank me later
1
4
580
๐Ÿ‘€
I just bought @RealJohnnyTime smart contract course so you donโ€™t have to. I have good knowledge so itโ€™ll be easy for me to navigate but Iโ€™ll give an honest review when I complete it and let you know if heโ€™s the real deal or not.
2
328
This is such a great opportunity to buy bitcoin at $60K. I promise you if youโ€™re not gonna do it youโ€™re gonna regret it later.
7
415
JohnnyTime ๐Ÿค“๐Ÿ”ฅ retweeted
We just shipped something at Glacient I wish had existed when I was building stablecoin and tokenization infra at Paxos: an easy-to-use canvas for creating DeFi and wallet monitoring and automation workflows visually, plus an AI chatbot that turns plain English into complex multi-protocol logic. No more fragile AI-generated scripts babysat on a dedicated machine that has to stay online. No waiting on a dev to find time to write a production-ready script and then update it every time an API changes. Here is a real example. You can type: "Monitor the Morpho Vaults Steakhouse USDC, Gauntlet USDC V1 Vault, PayPal Main Vault, and the cbBTC/USDC Morpho market on Ethereum. Add the Aave markets USDG, PYUSD, and USDT on Ethereum. Notify me when real-time Supply APY (net rewards) drops below 3% and liquidity is above 10M. Send it to Telegram, email, and a webhook to my OpenClaw Asset Strategy box." [See live demo in the attached video] And it builds the whole thing. Multi-venue. Layered data filters. Always-on, multi-channel delivery. No code required. No API updates to maintain. No dedicated machine. One more example: "Alert me on Telegram when my Aave loan tied to Ledger Wallet #1 is going to have a health factor below 1.5, a debt of more than 1k, and an LTV above 50%." And it automatically finds your loan and creates a multi-layered filter based on your criteria, then delivers to whatever notification medium you choose. No code required. No API keys. Always running. Today the actions are alerts and webhooks. Safe, non-custodial onchain execution is coming next. I am reaching out to vault curator strategists (or soon-to-be), crypto ops teams, teams trying to grow new stablecoins, treasurers holding crypto on their balance sheet, and DeFi users. If that is you, I want to talk. DM me and I'll send an invite code so you can try Glacient(.)ai for free.
11
4
31
3,015
We're live! :) Talking about how to make money in Web3 Security in 2026
How to actually earn $ as a web3 security researcher in 2026 x.com/i/broadcasts/1NGarrMVnโ€ฆ
14
722
JohnnyTime ๐Ÿค“๐Ÿ”ฅ retweeted
Today at 14:00 UTC How to earn $ as a web3 security researcher in 2026 With @GuildAcademy_, @sammyaudits and @RealJohnnyTime Join us here:
1
8
65
3,200
Most Web3 code fails security reviews for a simple reason: It was written to pass happy-path tests, not adversarial behavior. "Looks secure" usually means: - clean architecture - passing unit tests - no obvious compiler warnings "Is secure" means you can answer: - what an attacker can control - which invariant fails first - how value can be extracted in one path Auditors who can think in the second list get hired. The rest stay stuck reviewing surface-level code. The fastest way to level up: drill the same attack class until the variant feels obvious before you finish reading the code. smartcontractshacking.com/
9
700
JohnnyTime ๐Ÿค“๐Ÿ”ฅ retweeted
15 minutes a week. Here's the exact workflow: - open the hacks dashboard - choose one attack technique - review two related incidents - write one control to add in your codebase Do this every week. After a month, security becomes a reflex, not a last-minute checklist. smartcontractshacking.com/toโ€ฆ
1
6
33
1,424
People treat fuzzing like magic. Itโ€™s not. Itโ€™s disciplined adversarial testing: โ†’ Define one invariant โ†’ Generate ugly inputs โ†’ Let the machine try to break your assumptions at scale Start with one property. Depth comes from repetition. What invariant would you fuzz first in a lending protocol?
2
15
866
Looking forward to spill some Alpha ๐Ÿคซ
How to actually earn $ as a web3 security researcher in 2026 We're getting @RealJohnnyTime, @sammyaudits, and @GuildAcademy_ together with the Remedy team to talk through it honestly: โ†’ Bug bounties vs contests vs going in-house - what's worth your time โ†’ How to pick targets that'll actually pay you โ†’ Competing when everyone has the same AI agents โ†’ Where independent researchers go from here We see this differently, so come ready to push back. June 4, 14:00 UTC Live discussion on @xyz_remedy
1
8
710
JohnnyTime ๐Ÿค“๐Ÿ”ฅ retweeted
Curious how much smart contract auditors make? Or maybe not sure how much to ask in your next job interview? We built this for you ๐Ÿ‘‡ (Link in the comment)
2
2
12
1,523
JohnnyTime ๐Ÿค“๐Ÿ”ฅ retweeted
๐Ÿ” Just earned my Smart Contract Hacking certification from Blockchain Security Academy with a score of 93/100! ๐ŸŽฏ Huge shoutout to @RealJohnnyTime for building one of the most practical Web3 security courses out there โ€” highly recommend it to anyone getting into smart contract auditing! The exam covered everything from EVM internals to real-world DeFi exploits: โšก Integer overflow/underflow attacks โšก Reentrancy & gas griefing โšก Oracle manipulation โšก Proxy storage collisions โšก Signature replay attacks โšก Flash loan exploits Web3 security isn't just a skill โ€” it's what stands between users and billions lost to exploits. The journey into smart contract auditing has just begun ๐Ÿš€ #Web3Security #SmartContracts #Solidity #BlockchainSecurity #DeFi #Ethereum #Hacking #CyberSecurity #Audit
1
3
1,137
The irony lol
May 29
๐Ÿ˜‚๐Ÿคฆโ€โ™‚๏ธ Oddly Enough, the website of this โ€œboycott Israeli goodsโ€ campaign, is built entirely on Elementor - Israeli technology developed by an Israeli company in Israel ๐Ÿ‡ฎ๐Ÿ‡ฑ.
1
409