#web3 dev auditor | @SpearbitDAO LSR, @immunefi bug hunter, sage of AAVE codebase :D

Joined April 2008
296 Photos and videos
Pinned Tweet
23 Jun 2024
During the next few days, I will share some of my private security research work that I have done in the last year. ​ All those projects are @aave related, and I feel very proud to have been chosen as one of the security partners to review them. I'm pretty sure that the dedication and knowledge that I have demonstrated on their codebase has been a pretty good investment 😁 ​ Those projects were very challenging, but at the same time it was fun and a pleasure because you always feel motivated and engaged when the quality of documentation, specifications and code is high quality. ​ When @avara or @bgdlabs contacts you, you know that you are going to enjoy it. They are both a top-notch team to work with. ​ The first one that I want to share is a.DI (Aave Delivery Infrastructure) It's a cross-chain communication abstraction layer for decentralised systems like the Aave DAO to communicate across networks, minimising the risk of underlying individual bridge provider failures, via consensus rules.
8
6
107
16,082
Jun 15
Do I have any Italian/european Apple dev that can enlighten me on availability of Siri AI at least for the beta development version of iOS?
1
1
328
Jun 14
The new Siri AI, as far as I can tell, pulls data/context from a Spotlight index, which is built with data "donated" by apps. Apps like WhatsApp, Telegram, and so on will probably never donate those entry points. Why would they? Users will have access to that information via Siri AI instead of opening their app (fewer ad views, fewer premium features paid, and less data/behavior harvested from the user to be later on sold). I guess that maybe we could try to build apps that will ingest exports of the chat backups from those apps and donate those chats (on behalf of the original app) to the Spotlight index? I'm not sure if the result would be the same. Also I assume that Apple needs to have some security logic/mechanism to prevent to get the Spotlight index from being spammed by fake donated data? Any iOS/Apple dev that can enlighten me on these topics? I think that 99% of the non-US users have zero usage of the iMessage system.
323
Jun 14
Correct me if I'm wrong, but from what I get, every context index in the new Apple OS 27 will be built with the data that is available on that device and won't be merged/shared across devices. This means that if I don't have an app installed (or it's not available) on a device but it's available on another one, those two devices will have different contexts/memories, and so they will provide a different experience, one less relevant to me. I understand the privacy reason but it does feel quite wrong and will be super confusing to the end user that won't understand why a chat "works" on a device but not on another that is connected to the same Apple Account. Users are expected to be in a synched ecosystem when using their Apple devices. This behavior is breaking Apple's ecosystem magic.
251
Jun 13
Since yesterday I was trying to build a small macOS electron app that would allow me to take quick screen captures and chat with them... With codex gpt-5.5 xhigh I have burned for 2 times the 5h window token limit without being able to get the app request and approve the needed system permission on macOS. I don't get if the problem is the electron docs, the macOS docs, or codex itself but it really doesn't get to make it work. It's really really frustrating as an experience. At this point the only option is to just take control and manually check what the hell is not working and see if the electron docs have a solution. I mean, I assume that it's a common problem for any electron app that needs to request any kind of system permission, right? It should be well covered by docs or even by stackoverflow questions.
1
729
Jun 13
And I'm 100% sure that because it was stuck in that situation without really knowing how to solve it, it has tried any kind of shitty workaround to make it work, making the code a mess. After 25 years of coding experience as a fullstack developer you can feel it just by looking at the reasoning and what he's trying to do. It's like looking at a junior dev that does not know what to do and trying to stitch ugly code together to make it work in some way 😄
1
482
Jun 12
I feel like that harnesses are basically just poorly stitched-together workarounds to make a model seem to work? I would really love to see what's behind the scenes and how they have been implemented.
2
2
729
Jun 12
For what I can see the model is the core block that can't be changed and the harness needs to work around the model's behavior. If something does not work, you can't change the model (even if the problem is there), you need to find a workaround.
1
2
415
Jun 12
That maybe won't be needed or won't work with the next model.
213
Jun 10
It's fascinating to realize that in the world of AI, nothing is known and written in stone. New terms are created and replace "old" terms and concepts, no one knows anything, and everyone is experimenting, no one knows how these "things" work and so how to properly use them.
1
2
413
Jun 10
It's very difficult when you want to learn a new topic/technology and your "old" approach in learning can't be applied.
1
4
346
Jun 10
I have not yet figured out if it's because it's an "always-evolving-tech", if it's because multiple players are building it and there's not a standard or because even those players don't know what's going on.
192
Jun 9
How much of all the new AI features presented by Apple will come to Europe? Probably close to zero. Nice.
173
Jun 7
I need to transcribe an audio file and recognize speakers. What's the best AI service/mac app for doing that? I'm using MacWhisper and trying both WhisperKit Large v3 Turbo and Parakeet v3 but they don't seem very reliable at least when they have to deal with Italian audio.
1
414
Jun 1
Am I the only one that thinks that sharing links between the iphone and mac trought airdrops is a mess and never works even if both my iPhone and Mac are 1 inch from each other connected to the same wifi? it never works. So frustrating 🥲
3
6
1,526
Jun 6
Can confirm, it basically never works. So, so annoying. I truly hope that @Apple fixes it with iOS 27.
125
StErMi retweeted
May 21
I'm looking for open and engaging discussions with protocols, clients, and fellow security researchers on how you're actually using (or planning to use) AI, LLMs, and Agents in smart contract security audits and day-to-day workflows. If you're experimenting with them (or thinking about it), DM me and let's chat. Topics I'd love to cover: - Which model providers and models are you using? - What tools or services have you integrated into your workflow? - Where do they fit in your workflow and day-to-day work? - Are you planning to adopt new tools or build internal solutions? - Real results: have they helped find vulnerabilities, improve architecture, or improve code quality? Any concrete examples? - What problems, frictions, or pitfalls have you encountered when using or integrating them? - How much do you trust the outputs? Any concerns around over-reliance, bias, or becoming less thorough? - How do you feel about the current state of the art and what's coming in the next 6–12 months? Looking forward to hearing your real experiences and swapping thoughts on where AI is taking our industry. DMs open, let's chat!
1
1
9
1,476
May 29
@nikitabier there's something wrong in my "Following" timeline. I'm starting to see posts from people that I do not follow and there's no context attached to the post. Usually it would happen (in this timeline) if those posts were retweeted/fav/commente by someone that I already follow. But that information is not bound to the post I'm seeing. We have two options: the timeline alg is picking from the "For you" feed or you are not showing "why" I'm seeing those posts (who from my follow list has interacted with that post and how) anymore. In both cases there's a bug to fix.
2
1
307
Jun 1
@grok seems to confirm it as a "known bug". It still has not been fixed 🥲
1
151
May 31
Does Codex share knowledge with ChatGPT or is it completely isolated? Because I like the Codex UI/UX more than ChatGPT but I have a history in the chat and I would like to leverage that memory.
2
3
1,952
StErMi retweeted
My first blog post for @monad's security team is out. We spent a month building an AI system to hunt vulnerabilities in the Monad blockchain here's what we learned
38
20
242
36,529
May 26
I have so much that I want to learn, experiment with and build but so little time and energy after working hard all day long 🥲 Any labs that wants to sponsor me? 😄
3
394