Joined June 2023
108 Photos and videos
Pinned Tweet
28 Aug 2024
Proud to win this one! We haven't previous stableswap math experience, but we always want to challenge us, so we can improve.
27 Aug 2024
πŸ† The results of the Basin competitive audit are in! Congrats to everyone who submitted valid findings, especially to @EgisSec (@nmirchev8 and @dethSCA) for a landslide win in their second team showing! Respect to @basinexchange for their solid commitment to the highest security outcomes. Full list of winners in thread πŸ‘‡
11
1
104
9,062
I bet you've forgotten about the following Solana constraint: You can't initialize an account larger than 10 KiB in a single instruction via CPI.
1
11
1,198
For regular accounts, the client just pre-creates it at full size But PDAs? Only your program can sign for them. So you're stuck: - Init at ≀10 KiB - realloc 10,240 bytes per ix - Repeat across txs until you hit your target
1
70
V2 released right after C4 shut down... consequence, or? 🀫
For the longest time node clients were gatekept and untouched by free AI auditing tools, but that is NO MORE! πŸš€πŸ’« Not only is your AI subscription auditing for you, but you can even choose which one! 🀯 More deterministic, more precise. BETTER πŸ† "Plamen" V2 is live πŸ˜ˆπŸ€–
1
2
669
nmirchev8 retweeted
Do you need any other proof?
2
1
48
1,401
When initiatives meet initiatives = progres x 100 Always be proactive like @p_tsanev and @MartinMarchev, and you'll be rewarded Thank you, guys, or your effort
2
2
23
2,421
nmirchev8 retweeted
claudit is one of the projects accepted into the Ethereum Security QF round on Giveth. 500 ETH matching pool, split across Ethereum security projects. Quadratic funding scores projects by (Ξ£ √cα΅’)Β² - small donations from many people massively outweigh big ones from few. If claudit saved you time, this is the ask πŸ™ The round ends May 14. Quick walkthrough on how to support πŸ‘‡
1
7
36
6,942
nmirchev8 retweeted
so excited for this. been cooking on it for the past few months and can’t wait to officially launch soon and bring on-chain prediction market parlays. we spent countless nights building this - including a purpose-built L1 just for settlement. private beta will launch in a few days. mainnet hopefully in May.
Parlays. On Everything.
18
5
179
15,627
nmirchev8 retweeted
And this folks, is why risk assessment and trust assumptions are key during audits. And at @Certora we do E2E security btw (reach out) And stop doom-posting the end of DeFi and enjoy watching the phoenix rise from the ashes πŸ¦β€πŸ”₯ πŸ”₯β˜„οΈπŸ¦β€πŸ”₯
1
3
27
1,332
So damn much attack surfices that can harm "secured" protocols... so much work to do
Apr 19
Everything you need to know about the rsETH exploit ($292 million): attacker targets insecure bridge configuration Verifier setup: Only one approval is required, and this is the single point of failure. Attacker forges cross-chain message. Tricks Bridge into Release: 116,500 fake $rsETH worth ~$292 million About 36% of total supply Unbacked ETH tokens created from thin air by the attacker (minted) Attacker receives fake rsETH on Ethereum Immediately deposits it into Aave as collateral then borrows: 106,467 ETH (~$250M) Started selling and swapping rsETH. bad debt created of more than $177 million. WETH pool utilisation hits 100% Aave freezes rsETH market exploit was not in core rsETH backing exploit hit bridged rsETH version attacker wallet publicly tracked funded via Tornado Cash one of the biggest bridge failures of 2026
1
2
627
nmirchev8 retweeted
It all started with a one-line email in 2019. @StaniKulechov, @The3D_ and the whole Aave team have always put security first. This is the story of how one of the deepest security partnerships in DeFi was built.
1
22
1,000
nmirchev8 retweeted
🚨 If your Solana program uses instruction introspection (Sysvar1nstructions) to enforce control β€” you need to also block CPI calls and here's why:
3
1
20
2,401
🚨 If your Solana program uses instruction introspection (Sysvar1nstructions) to enforce control β€” you need to also block CPI calls and here's why:
3
1
20
2,401
A concrete example β€” scanning for forbidden flash loan providers: When your program calls load_current_index() it gets 0, scans ix[0] β€” sees only attacker_wrapper, no forbidden program β†’ passes. The flash loan happened entirely inside CPI, invisible to your check.
1
2
224
The fix: You don't have control over nested CPIs in other instructions included in the transaction, but you can still detect and block suspicious behavior:
3
130
nmirchev8 retweeted
I am turning 25, so here are some personal lessons for you: - Enjoy being yourself - you are unique, your qualities, experience, mindset distinguishes you from the others and you got to love it - Do the right thing - you can spend your whole life lying and bypassing rules, but what really matters is not visible - caring, believing, doing good - Don't be afraid of committing too soon to a family - I became father at 24 and I feel grateful that I will have the opportunity to to "the things I haven't done" together with my little one and demonstrate her how to chase your dreams - Be open for the life - Till 4 years ago I thought I will do sports professionally, but then I found web3 and I felt comfortable diving into a new chapter of life. - Be active - You should move your body in this world, if you love yourself. No matter the sport, just enjoy the movement - Travel as much as you can - then travel more - Be honest with yourself - you got to accept your weaknesses and don't deny them, only then you can work of changing them - Be curious - read stuff, talk to people, break stuff, fix stuff - Learn how to love - it is not Π° coincidence that love is mentioned so many times in books, the Bible, movies, song - it is the most powerful and purifying emotion - Find your purpose - the same purpose may look different in different stages in your life, but you should know what fires you - The family that you build is more important than the family that you come from - you don't have any control over the second one, but your action may change next generations. You should know that every successful person had parents. You could be one
10
3
104
3,396
nmirchev8 retweeted
Do you want me to post this meme?
1
2
12
425