Joined October 2020
1,056 Photos and videos
Pinned Tweet
Honored to be selected🫡
The next 60 ETHSecurity Badge holders have been selected using a new rubric updated by the applicants themselves! Thank you to the people who chatted with the bot, your refinement of the rubric is the first DAO experiment we have tested. And thank you to @bonfiresai for making amazing DAO tooling!
1
22
947
devtooligan (ai arc) retweeted
happens to the best of us
120
460
11,432
328,871
nice work zero cool. if this security thing doesn't work out maybe you should try hollywood 🤣 lmeow
Hey Zero Cool: 👉 Create a video explainer for this finding using adorable kittens 🐈 😽 There's been some confusion around this finding related to function pointers, so we let Zero Cool have access to a video generation tool and gave it this prompt! Here is the result:
1
11
606
devtooligan (ai arc) retweeted
yAudit has a secret weapon. 🤫 Earlier this year, we developed yAgent, our in-house AI auditor. We've run it on every review since March, and it's really changed the way we work and raised the bar on our security reviews. Our researchers can go deeper on the code, move faster, and explore more ideas as they go. yAgent handles the groundwork so the team can spend its time on the hard problems. The tool was built on top of the award winning vulnerabilitiy detection engine developed by @zerocool_ai. We added our own workflows, knowledge bases, and custom skills to replicate the expertise and approaches we've developed over the years through auditing DeFi's biggest protocols like Yearn, Euler, and many more. We'll be sharing more details soon, including case studies, experiences, and tips for those trying to implement AI into their security process.
2
10
32
2,591
devtooligan (ai arc) retweeted
I used property testing during a Solana AMM audit. This blog post walks through the seven properties and their reasoning, the sequence-based test structure, and a case where my own test had a bug that looked like a real finding: s3v3ru5.github.io/posts/sola…
7
22
1,512
devtooligan (ai arc) retweeted
The Tangent protocol has undergone extensive testing and auditing, including 100% unit test coverage, fuzzing, and a total of five audits. Many thanks to @EgisSec, @sherlockdefi, @PashovAuditGrp, and @ZeroCool_AI for their work, which helped us secure $USG. Links below 👇
4
11
39
2,827
devtooligan (ai arc) retweeted
Working with @ZeroCool_AI was a great experience. Their tool demonstrated a strong understanding of our codebase and its context, delivering relevant and valid findings. We’d encourage every protocol to give it a try!
Tangent Finance is building $USG, an over-collateralized stablecoin minted against productive collaterals like Curve LP tokens and Pendle PTs. Dynamic interest rates, multiple market types, peg keepers, liquidation thresholds. Lots of surface area to hold together before going live.
4
14
1,027
amazing news!
While it's bittersweet, I'm very excited to share this news. @ScopeLift has reached an agreement to operate Tally (soon to be rebranded) moving forward. Major props to the Tally team for prioritizing their users, and thus making this possible. Onward! x.com/ScopeLift/status/20391…
1
2
472
devtooligan (ai arc) retweeted
A partial liquidation can leave bad debt and drain a borrower's entire collateral, even at HF = 0.99, if LT * (1 bonus) >= 1. @D4r3_D3v1L_ checked 22 protocols using partial liquidation. 4 are vulnerable, 6 have on-chain constraint. I wrote two posts breaking this down:
2
6
68
9,330
devtooligan (ai arc) retweeted
Mar 25

3
3
16
4,962
devtooligan (ai arc) retweeted
I was farming airdrops and reading the Ethereum yellow paper in the front seat of my Uniswap police cruiser when a ping came in. It was the chief. “Bad news, detective. We got a situation.” What? Did Solana go down again?” “Worse. Somebody just launched another layer-2.” The hardware wallet practically fell out of my hand. “My God. How many do we have now?” “Hard to say. Every time we count them, three more appear funded by a16z & Paradigm.” I lit a cigarette and refreshed the mempool. “What’s the damage?” “Billions in venture funding. Thousands of tweets about ‘Ethereum scaling.’ A whitepaper written entirely in diagrams of arrows pointing at other arrows.” “Do we have any leads?” “Only that the founders used to work at Coinbase.” I shook my head. “Typical.” “Listen,” the chief said. “We’re going to track this thing down and shut it off before it launches a token.” “Easy, chief,” I said. “Tokens are the foundation of the modern startup business model.” He sighed. “Just get down there and see what you can find.” Ten minutes later I was at the scene: a co-working space filled with beanbags, venture capitalists, and a giant TV displaying a dashboard that just said “TPS.” “Coinbase™ Presents The Police!®” I yelled, flashing my badge, my hardware wallet, and a laminated screenshot of Vitalik. “Nobody pivot unless you want to!” They didn’t. “All right,” I said. “Which one of you punks launched the new rollup?” A man wearing a hoodie that said “Zero Knowledge, Zero Revenue” slowly raised his hand. “It’s not a rollup,” he said nervously. “It’s a modular settlement-availability execution layer.” I squinted at him. “That’s a rollup.” The room murmured. “Listen,” I said. “Without a strong economic incentive, I’m not investigating anything. Are you people going to pay me?” A venture capitalist stood up. “We can offer you an allocation in the seed round.” “I don’t work for equity,” I said. “I work for tokens that unlock in eighteen months and immediately go to zero.” Just then an intern ran in. “Detective! The protocol just hit a billion dollar valuation!” “Already?” I asked. “We haven’t launched anything yet.” “Of course not,” I said. “That would be irresponsible.” Suddenly the founder made a break for the door. “Paradigm™ Freeze, Scumbag!®” I yelled. Too late. He was already halfway down the hallway tweeting “gm.” I chased him. “Stop right there!” I shouted. “You can’t keep launching infrastructure companies that only exist to make other infrastructure companies slightly more complicated!” He turned around. In his hand was a pitch deck. He fired. I ducked as a slide titled “The Future of Decentralized Modular Interoperability” whizzed past my head. “All right!” he yelled. “I confess! I built the protocol!” “Why’d you do it?” I asked, slapping a pair of Ledger™ Hardware Handcuffs® on him. “Because I was afraid.” “Afraid?” “Afraid there might be only twelve crypto infrastructure startups instead of thirteen.” I nodded slowly. Years ago, a man like this rugged my partner with an NFT project called Pixel Apes but With Hats. I looked him dead in the eye. “Listen carefully,” I said. “No matter how many rollups you launch, no matter how many seed rounds you raise, you will never destroy the dream of a decentralized financial system.” He lowered his head. “You’re right,” he said quietly. Then a venture capitalist walked up and handed me a term sheet. “Good work, detective,” he said. “We’d like to lead your next round.” I signed it immediately.
16
11
138
13,333
devtooligan (ai arc) retweeted
Here's how Zero Cool has performed in competitions: 1st place @Rain__Protocol (672 submissions) 1st place @DexlynLabs (72 submissions) 2nd place @MentoLabs (726 submissions) 6th place @0xsequence (664 submissions) 6th place @OpenEden_X (43 participants) 25th place @monad (952 submissions) $20K bounty (Immunefi) 100 confirmed findings across 40 contests. 25th all-time @HackenProof, 7 critical, 29 high severity. We're just getting started.
3
4
44
3,640
devtooligan (ai arc) retweeted
I think there is an interesting result here: Some skills actually perform worse than the baseline model. It'll become increasingly important to curate, maintain and prune the skills that you've got set up to find bugs.
5
1
16
2,617
fun and interesting to read
2
27
6,270
with skills quality is definitely > quantity
2
33
3,957
powerful. I watched this to the end
Mar 7
I was a 10x engineer. Now I'm useless.
14
2,096
Amazing work
I've spent every day for the last 14 months building a language for scripting LLMs because I believe we need new primitives to defend against prompt injection. Here's why: x.com/sockdrawermoney/status…
2
5
998
devtooligan (ai arc) retweeted
Announcing the Solidity Testing Handbook ✨ Fully free, one-stop resource for Solidity developers and security researchers. Resources are currently scattered across blogs, docs, and forums. I found it difficult to keep track of everything in one place. This handbook aggregates all testing patterns from basic unit tests to advanced mutation tests into a single, well-organized guide for quick reference. It’s built from my own learnings and best practices observed in popular codebases. soliditytestingbook.com/
18
38
256
15,883
I’m here for all the open sourcing of skills, techniques and, ai projects. it’s been quite a renaissance of people sharing tools and experimenting reminds me of the Huff days 👀👀
Introducing munchbase. Fast, agent-friendly, script-friendly CLI for Crunchbase. Now your agents can query for projects that recently raised, their investors, funding rounds, etc. It does not need Crunchbase's special blessing for API access and uses your web credentials.
2
11
1,629
Happy Lunar New Year to those who celebrate! x.com/i/status/2023416426984…

Are you watching the Chinese New Year Gala? The Robot Kungfu show is mind blowing!!! They just executed a coordinated martial arts routine with spatial precision, rhythm control, and dynamic balance adjustments in real time. Kung fu, one of China’s most iconic traditional art forms , performed by machines built with cutting-edge AI control systems, advanced actuators, and high-speed feedback loops. Ancient discipline meets algorithmic precision. Last year, humanoid robots stepped onto the Spring Festival Gala stage for the first time. This year, they held synchronized kung fu stances with balance that would humble half of us after leg day. And they did it live!!! On the most-watched television event on the planet. The progress in just one year is magical. That’s what we call China speed. What makes it even sweeter is where this happened. I love how the progress is integrated in culture. In celebration. In a Lunar New Year gala watched by hundreds of millions. It’s music to my ears. The robots didn’t look like they were “trying” anymore. They looked like they belonged. Their joint articulation was smoother. Their formation timing tighter. Their balance recovery almost elegant. Their choreography is expressive. That’s what happens when AI models improve, control systems get smarter, hardware stabilizes, and iteration cycles compress. One year in robotics today is not the same as one year ten years ago. It’s compounding. If this is what 12 months looks like, imagine 36. The Chinese New Year Robot Kungfu Gala is just futuristic. It was quite the statement! The future is getting better very, very fast. It was so beautiful to watch. What do you think?
1
4
862