Filter
Exclude
Time range
-
Near
Today's takeaway: "Update state before the external call" isn't a style tip. It's the whole ballgame. The callback is the wild. #SmartContractSecurity #Web3 #CodeHawks
6
Worked through an oracle manipulation case study in DeFi. Built the vulnerable protocol, reproduced the exploit, analyzed the root cause, and implemented a secure fix. Documented the full process here: dev.to/junaidmollah01/breakiโ€ฆ #SmartContractSecurity #Solidity #DeFi
2
11
Audit Checklist Whenever you see: โ†’ for loops โ†’ while loops Ask: ""Can users increase the size of this data structure?"" If yes: Dig deeper. #SmartContractSecurity
6
Most DeFi "hacks" aren't hacks. The code worked exactly as written. The price was the lie. Oracle manipulation has drained $400M from protocols whose audits were clean. Here's how it actually works ๐Ÿงต Context: every lending protocol needs to know what your collateral is worth. That's the oracle's job. The lazy design: read the spot price from a DEX pool. The problem: pool prices move when someone trades big. And flash loans give *anyone* whale-size capital โ€” for exactly one block. The play, in one transaction: โ‘  flash-loan a huge amount โ‘ก dump it into a thin pool โ†’ price crashes โ‘ข the protocol now mis-prices collateral โ‘ฃ borrow (or liquidate) against the fake price โ‘ค repay the flash loan, keep the difference The profit is real. The price never was. Real money, real cases: โ€ข Mango Markets โ€” $116M. Pumped MNGO perp price, "borrowed" the whole treasury against it โ€ข Harvest Finance โ€” $24M via Curve pool manipulation โ€ข bZx, Cheese Bank, Inverseโ€ฆ same story One root cause every time: the oracle trusted a single manipulable source. Before you deposit into any lending protocol, 4 questions: โ€ข Spot price or TWAP? โ€ข Chainlink / redundant feeds, or one DEX pool? โ€ข How deep is the liquidity of the source pool? โ€ข Is there a per-block price deviation cap? If the docs don't answer these โ€” that IS the answer. Takeaway: code can be perfect and the protocol still dies. If reality is an input, attackers attack reality. I break down one DeFi mechanism or exploit every week โ€” follow along. NFA, DYOR. #DeFi #SmartContractSecurity #Oracles
56
No mocks. It deploys your hook on a real v4-core PoolManager and drives it with unit proofs fuzzed invariants (256 runs, 128k calls, 0 reverts). 10 tests, green in CI. MIT. One forge test: github.com/hunterinvariants/โ€ฆ #UniswapV4 #Solidity #DeFi #SmartContractSecurity
39
The easiest way to DoS a smart contract? Make it work exactly as designed. #SmartContractSecurity #Ethereum
1
8
Happy to share that I've completed the @rektoff_xyz ร— @SolanaFndn Rust Security Bootcamp ๐ŸŽ“ Thanks to the team for the great learning experience. Excited to continue growing as a smart contract security researcher. #Solana #Rust #SmartContractSecurity
3
19
680
๐Ÿ” How does Cyberscan AI help identify risks faster? By automating smart contract analysis, detecting vulnerabilities earlier, prioritizing critical findings, and providing AI-assisted remediation guidance, Cyberscan AI helps teams strengthen security before deployment. Learn more: cyberscope.io/cyberscan-ai #CyberscanAI #Web3Security #SmartContractSecurity #BlockchainSecurity #Cybersecurity #DeFi #SmartContracts #AI #Cyberscope
1
99
ALERTA DE SEGURANร‡A: Vulnerabilidades Crรญticas no Ecossistema Bitflow e a Negligรชncia da Immunefi ๐Ÿ›ก๏ธโš ๏ธ @bitflow @immunefi #Bitflow #Stacks #ClarityLang #SmartContractSecurity #DeFiSecurity #BugBounty #BlockchainAudit #SegurancaDigital #Web3โ€Œโ€Œ
1
16
Todayโ€™s takeaway: - Use a TWAP or Chainlink unless you want your protocol to be an attacker's piggy bank. - "Phantom yield" is real. If you update an exchange rate without a corresponding token transfer, you're just printing insolvency. #SmartContractSecurity #Web3 #CodeHawks
1
21
๐Ÿ›ก๏ธDay 16 of Becoming SR: @CodeHawks Thunder Loan minefield. caught 2 High-severity candidates: 1๏ธโƒฃ Oracle manipulation via TSwap spot price. 2๏ธโƒฃ Immediate insolvency via a logic flaw in deposit() Repo๐Ÿ‘‡ github.com/mayurrajput04/audโ€ฆ #SmartContractSecurity #Solidity #Web3
1
2
71
"Disconnect wallet" feels safe. It revokes nothing, and that is how most wallets get drained. Approving a token writes an on-chain allowance. The contract can pull your tokens later with no second signature, long after you forgot the site. Most dApps ask for unlimited (the 2^256-1 max). That allowance never decrements, so it is permanent spend access until you revoke. Disconnecting ends the session, not the permission. Worse, the spend needs no transaction. A gasless "Sign" popup (EIP-2612 permit, Permit2) authorizes a spender for free, no gas, no trace. Permit phishing alone drove 56.7% of 2024 drainer thefts. The numbers: 2024: $494M stolen, 332,000 addresses 2025: $83.85M, 106,106 victims, permits drove 38% of $1M losses CertiK May 2026 report: $68.3M total, $13.7M from wallet and key breaches The audit, under 10 minutes: 1 CHECK every live allowance (revoke.cash or Etherscan) 2 REVOKE unlimited, abandoned, or older than 90 days you cannot name 3 CAP every new approval to an exact amount Swipe for the full flow, the disconnect myth, and three signing rules. Educational purposes only, not financial advice. Follow for daily insights - where blockchain meets AI, one satisfying swipe at a time. #TokenApprovals #WalletSecurity #Web3Security #SmartContractSecurity #DeFiSecurity #Permit2 #ERC20 #RevokeCash #WalletDrainer #PhishingDefense #SelfCustody #OnChain #Ethereum #Web3 #BlockchainSecurity #DigitalAssets
3
144
Every major DeFi exploit has happened before. Reentrancy drained Cream Finance in 2021. The same pattern took new protocols in 2023 and 2024. Oracle manipulation drained Mango Markets in 2022. It's still draining protocols today. A decade of postmortems. Hundreds of exploits. No human auditor can hold all of that in their head. We're building an engine that can. Next version, coming soon. #SmartContractSecurity #DeFi #Web3Security
2
1
145
๐Ÿ›ก๏ธ Day 15 of Becoming SR: Mapping @CodeHawks Thunder Loan before touching a single bug. Built a mental model 8 invariants, and the recon alone surfaced 2 candidate findings. Repo๐Ÿ‘‡ github.com/mayurrajput04/audโ€ฆ #SmartContractSecurity #Solidity #Web3 #PublicBuilding
53
Auditors read code. Exploiters read systems. That gap is where The DAO, Hundred Finance, and most major DeFi losses actually happened โ€” not in broken code, but in how correct code behaves under real-world conditions. We're building the engine that closes that gap. Next version, coming soon. #SmartContractSecurity #DeFi
16
14
1,072
์Šค๋งˆํŠธ ์ปจํŠธ๋ž™ํŠธ ๋ณด์•ˆ ๋ถ„์•ผ์—์„œ ์ข‹์€ ๋ฐ์ดํ„ฐ์…‹ ํ•˜๋‚˜๊ฐ€ ์–ผ๋งˆ๋‚˜ ํฐ ๊ฐ€์น˜๋ฅผ ๊ฐ€์ง€๋Š”์ง€ ์•„๋Š” ์‚ฌ๋žŒ์ด๋ผ๋ฉด ์ด๋ฒˆ Cluster Protocol์˜ ๊ณต๊ฐœ ์†Œ์‹์ด ๊ฝค ๋ฐ˜๊ฐ€์šธ ๊ฒƒ์ž…๋‹ˆ๋‹ค. @ClusterProtocol @cluster_korea ์ตœ๊ทผ Cluster Protocol์€ Slither Audited Smart Contracts ๋ฐ์ดํ„ฐ์…‹์„ ๊ณต๊ฐœํ–ˆ์Šต๋‹ˆ๋‹ค. ๋ฌด๋ ค 46๋งŒ 7์ฒœ ๊ฐœ๊ฐ€ ๋„˜๋Š” Etherscan ๊ฒ€์ฆ Solidity ์Šค๋งˆํŠธ ์ปจํŠธ๋ž™ํŠธ๊ฐ€ ํฌํ•จ๋œ ๋Œ€๊ทœ๋ชจ ๋ฐ์ดํ„ฐ์…‹์œผ๋กœ ์ปจํŠธ๋ž™ํŠธ ์ฝ”๋“œ๋งŒ ๋ชจ์•„๋†“์€ ์ˆ˜์ค€์ด ์•„๋‹™๋‹ˆ๋‹ค. ๊ฐ ์ปจํŠธ๋ž™ํŠธ๋งˆ๋‹ค ์›๋ณธ Solidity ์†Œ์Šค์ฝ”๋“œ์™€ ์‹ค์ œ ๋ฐฐํฌ๋œ ๋ฐ”์ดํŠธ์ฝ”๋“œ๊ฐ€ ํ•จ๊ป˜ ์ œ๊ณต๋˜๋ฉฐ, ์ •์  ๋ถ„์„ ๋„๊ตฌ์ธ Slither๋ฅผ ํ†ตํ•ด ์ถ”์ถœํ•œ 100๊ฐœ ์ด์ƒ์˜ ์ทจ์•ฝ์  ๋ฐ ์œ„ํ—˜ ํŒจํ„ด ๋ถ„์„ ๊ฒฐ๊ณผ๊นŒ์ง€ ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์— ๋จธ์‹ ๋Ÿฌ๋‹ ์—ฐ๊ตฌ์ž๋“ค์ด ๋ฐ”๋กœ ํ™œ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก train, validation, test ์Šคํ”Œ๋ฆฟ๊นŒ์ง€ ์ฒด๊ณ„์ ์œผ๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ์–ด ์Šค๋งˆํŠธ ์ปจํŠธ๋ž™ํŠธ ๋ณด์•ˆ ์—ฐ๊ตฌ์™€ AI ๊ธฐ๋ฐ˜ ์ทจ์•ฝ์  ํƒ์ง€ ๋ชจ๋ธ ๊ฐœ๋ฐœ์˜ ์ง„์ž… ์žฅ๋ฒฝ์„ ํฌ๊ฒŒ ๋‚ฎ์ถฐ์ฃผ๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์ € ์—ญ์‹œ ํ˜„์žฌ ๋…๋„๋‹ค์˜ค ์บ ํŽ˜์ธ์— ์ฐธ์—ฌํ•˜๋ฉด์„œ ์ด ๋ฐ์ดํ„ฐ์…‹์„ ์ง‘์ค‘์ ์œผ๋กœ ์‚ดํŽด๋ณด๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์ฒ˜์Œ์—๋Š” ๋‹จ์ˆœํžˆ ์ˆœ์œ„ ๊ฒฝ์Ÿ์„ ์œ„ํ•œ ์ž๋ฃŒ ์ •๋„๋กœ ์ƒ๊ฐํ–ˆ์ง€๋งŒ ์‹ค์ œ๋กœ ์ˆ˜๋งŽ์€ ์ปจํŠธ๋ž™ํŠธ๋ฅผ ๋ถ„์„ํ•˜๋‹ค ๋ณด๋‹ˆ ์˜ˆ์ƒ๋ณด๋‹ค ํ›จ์”ฌ ๋งŽ์€ ์ธ์‚ฌ์ดํŠธ๋ฅผ ์–ป๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ํŠนํžˆ ๊ณผ๊ฑฐ์—๋Š” ๋ฌด์‹ฌ์ฝ” ์ง€๋‚˜์ณค๋˜ ์ฝ”๋“œ ๊ตฌ์กฐ๋‚˜ ๋ณด์•ˆ์ƒ ์œ„ํ—˜ ์‹ ํ˜ธ๋“ค์ด ๋ˆˆ์— ๋“ค์–ด์˜ค๊ธฐ ์‹œ์ž‘ํ–ˆ๊ณ , Slither๊ฐ€ ์–ด๋–ค ๊ทผ๊ฑฐ๋กœ ํŠน์ • ์ทจ์•ฝ์ ์„ ํƒ์ง€ํ•˜๋Š”์ง€ ์ดํ•ดํ•˜๊ฒŒ ๋˜๋ฉด์„œ ๋ถ„์„ ์†๋„์™€ ์ •ํ™•๋„ ๋ชจ๋‘ ๋ˆˆ์— ๋„๊ฒŒ ํ–ฅ์ƒ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๊ฒฐ๊ณผ๋ฅผ ํ™•์ธํ•˜๋Š” ๊ฒƒ์„ ๋„˜์–ด, ๋ณด์•ˆ ๋ถ„์„๊ฐ€์˜ ์‹œ์„ ์œผ๋กœ ์ฝ”๋“œ๋ฅผ ๋ฐ”๋ผ๋ณด๋Š” ๊ฐ๊ฐ ์ž์ฒด๊ฐ€ ์กฐ๊ธˆ์”ฉ ๊ธธ๋Ÿฌ์ง€๊ณ  ์žˆ๊ฒƒ ๊ฐ™๊ธฐ๋„ ํ•ฉ๋‹ˆ๋‹ค ํ˜„์žฌ ๋…๋„๋‹ค์˜ค ์บ ํŽ˜์ธ ์ˆœ์œ„ 8์œ„๋ฅผ ์œ ์ง€ํ•˜๊ณ  ์žˆ์ง€๋งŒ ์ด ๋ฐ์ดํ„ฐ์…‹์„ ๋” ๊นŠ์ด ํƒ๊ตฌํ•˜๋ฉด์„œ ํ•œ ๋‹จ๊ณ„ ๋” ๋†’์€ ๊ณณ์„ ๋ชฉํ‘œ๋กœ ํ•ด๋ณด๋ ค ํ•ฉ๋‹ˆ๋‹ค. ๋ฐ์ดํ„ฐ์…‹์ด ๊ฐ€์ง„ ์ •๋ณด๋Ÿ‰๊ณผ ํ™œ์šฉ ๊ฐ€๋Šฅ์„ฑ์„ ์ƒ๊ฐํ•˜๋ฉด ์•„์ง๋„ ํŒŒ๋ณผ ๋งŒํ•œ ์˜์—ญ์ด ์ •๋ง ๋งŽ์•„ ๋ณด์ž…๋‹ˆ๋‹ค. ๋ธ”๋ก์ฒด์ธ ๋ณด์•ˆ, ์Šค๋งˆํŠธ ์ปจํŠธ๋ž™ํŠธ ๊ฐ์‚ฌ, Solidity ๊ฐœ๋ฐœ, ๊ทธ๋ฆฌ๊ณ  AI ๊ธฐ๋ฐ˜ ์ทจ์•ฝ์  ํƒ์ง€ ์—ฐ๊ตฌ์— ๊ด€์‹ฌ์ด ์žˆ๋Š” ๋ถ„๋“ค์ด๋ผ๋ฉด ์ด ๋ฐ์ดํ„ฐ์…‹์€ ๋ฐ˜๋“œ์‹œ ํ•œ ๋ฒˆ ์‚ดํŽด๋ณผ ๊ฐ€์น˜๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ์ฐธ๊ณ  ์ž๋ฃŒ๋ฅผ ๋„˜์–ด ์‹ค์ œ ์—ฐ๊ตฌ์™€ ๊ฐœ๋ฐœ์— ํ™œ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์ˆ˜์ค€์˜ ๊ณ ํ’ˆ์งˆ ๋ฐ์ดํ„ฐ๊ฐ€ ๊ณต๊ฐœ๋œ ๋งŒํผ, ์•ž์œผ๋กœ ์–ด๋–ค ์ƒˆ๋กœ์šด ๋ถ„์„ ๋„๊ตฌ์™€ ๋ณด์•ˆ ๋ชจ๋ธ์ด ๋“ฑ์žฅํ• ์ง€ ๊ธฐ๋Œ€๊ฐ€ ๋ฉ๋‹ˆ๋‹ค. ์ง์ ‘ ์—ด์–ด๋ณด๊ณ  ๋ช‡ ๊ฐœ์˜ ์ปจํŠธ๋ž™ํŠธ๋งŒ ๋ถ„์„ํ•ด ๋ณด์„ธ์š”. ์ƒ๊ฐ๋ณด๋‹ค ํ›จ์”ฌ ๊นŠ์€ ์„ธ๊ณ„๊ฐ€ ๊ธฐ๋‹ค๋ฆฌ๊ณ  ์žˆ์„์ง€๋„ ๋ชจ๋ฆ…๋‹ˆ๋‹ค. #ClusterProtocol #Slither #SmartContractSecurity #Solidity #๋…๋„๋‹ค์˜ค #๋ธ”๋ก์ฒด์ธ๋ณด์•ˆ
8
3
14
153
A beautiful website means nothing if the underlying architecture is fragile. G2S functions as a full service software testing and systems control hub. We stress test your applications and audit smart contracts to ensure your digital ecosystem is secure against vulnerabilities before you launch to millions. #TechAudit #SmartContractSecurity #SoftwareTesting #CyberSecurity
5
11
277
๐ŸŸ  Ace (Unverified utility): 58/100 โ€” Elevated Risk ยท Base ยท Token Verdict: Elevated Risk, Avoid Large Deposits. ๐Ÿšจ Red flags: โ€ข 0% locked LP on a high-valuation asset โ€ข Inorganic volume signaling wash trading โš ๏ธ Key risks: โ€ข Centralization via admin pause function โ€ข Massive supply overhang from FDV/MC gap โ€ข Extreme whale concentration with minimal retail distribution โœ… Positive signals: โ€ข Verified source code without honeypot or hidden ownership mechanics ๐Ÿ“Š Exploit probability: 37% ยท Loss severity: 55/100 ยท Confidence: 41/100 ๐Ÿ”— Full institutional report: defidetector.ai/analysis/6a1โ€ฆ Built by DeFiDetector.ai โ€” structural risk intelligence for DeFi protocols, tokens, and contracts. Not financial advice. #DeFi #Crypto #RiskManagement #SmartContractSecurity #Web3 #DeFiSecurity
1
1
2
57
May 21
Defi hacks are becoming one of the most serious threats in crypto. Two of the biggest DeFi hacks of 2026 cost users $577M. We decided to score the attacker wallets. Every one came back BLOCK. Not because we knew they were exploit wallets - because the behavioral data told us everything we needed to know. Zero outbound transactions. 2.7 billion value spike ratio. Zero known protocol interactions. Same coordinated creation window. Classic Lazarus Group fingerprint. The signals existed onchain before a single dollar was drained. DeFi protocols are losing hundreds of millions to attacks that leave clear behavioral trails. The data is there. Most protocols just arenโ€™t reading it. Thatโ€™s why we built our newest product, KaelAi Shield - behavioral wallet scoring, exploit registry, and five-tier threat detection purpose-built for DeFi security. The next hack is coming. The question is whether your protocol is reading the signals. Full case study this week. kaelai.io/shield #DeFi #DeFiSecurity #KelpDAO #DriftProtocol #LazarusGroup #Web3Security #CryptoSecurity #WalletSecurity #SmartContractSecurity #DeFiHack

11
18
376
๐Ÿ”ด Bug We Found โ€” Reentrancy via Callback Hook A notification hook added post-audit broke CEI ordering. Two prior audits missed it. $47M TVL was at risk. The hook address was upgradeable. No timelock. Default hook looked benign โ€” until it wasn't. #SmartContractSecurity #DeFi #Web3Security #0xBugDrop
1
4
296