MSF (beta)
@0xMSF14
Followers
597
Following
4K
Media
29
Statuses
998
Security researcher | DM for private audits.
(e/acc)
Joined July 2023
It's December, most workers will be taking a break or holiday. Most auditors too, but those who know the grind know this is when to lock in and redefine your new year.
1
0
2
This is the truth
Are you entering SR/auditing career path for money ? It's cool. But you think you can make it without putting on the hours, don't even think. You have to put in immense hours, constantly updating yourself on new topics/upgrades, always looking at minute details, always pushing
0
0
4
Balancer and Yearn are wake up calls. We need to get our shit together as an industry. The black hats aren't waiting for us to figure it out. They are ramping up their efforts.
5
13
115
Within the first 2 minutes of the talk Mitchell confirms that bounty hunters are getting a worse deal over time
3
3
60
If you're wondering why hacks are increasing recently here is your reason, projects are not compelled to honor any agreements, and are mostly shameless. Until money is stolen most DeFi companies treat user funds as expendable because we're a fundamentally unserious industry.
Just got lowballed from one of the biggest protocols in the space. It's looking like the end of my bug hunting career. It's simply not worth the time and struggle anymore
2
0
19
I laugh when people say this and think it's a flex. Hungry unemployed upskilling "white-hats" + AI with infinite time to look at your code, we're not even there yet and top protocols are getting hacked left and right. It is almost imperative to make sure this doesn't happen.
2
0
19
You know it's a bear market when @aave cannot hold a 7 figure contest for an already heavily audited codebase. Simply terrible ev for highly skilled auditors, so they won't participate. Less eyes on code is always a bad idea, ask Balancer.
Ready to help secure one of the most trusted protocols in DeFi? The @aave V4 Contest starts Monday, December 1st, with rewards up to $300k. V4 introduces a Hub and Spoke architecture, bringing new design paradigms to Aave, each with its own set of benefits. Just audit Aave.
0
0
30
Learning things fast is a skill It requires balancing relentlessness and self knowledge - Push through your limits - Force yourself to move fast - Set delusional goals - Stop and recharge **before** burning out
7
11
109
Centralised rails held the door shut while the chains kept running. When the web went dark, “decentralisation” didn’t fail, everything built on top did
Routine database change at @Cloudflare killed 20% of the web for 3 hours. Crypto exchanges froze. Twitter died. No blockchain failures reported, but some front-ends went dark. Decentralized protocols, centralized pipes. The irony wasn't subtle. Story Below.
5
9
50
Friendly reminder that the balancer hack should never have happened, we have to find out why, and I am not talking about a post-mortem write-up. Nobody takes security seriously and everyone is paying the price.
1
0
3
Centralized "Admin" roles, in Decentralized Finance.
Governments are clamping down on Crypto and now everyone is talking about privacy for BTC, zcash, etc. It is important to remember that Crypto is war-time technology If your code is centralized or upgradeable/malleable you will eventually be arrested or forced to rob your users
0
0
2
Governments are clamping down on Crypto and now everyone is talking about privacy for BTC, zcash, etc. It is important to remember that Crypto is war-time technology If your code is centralized or upgradeable/malleable you will eventually be arrested or forced to rob your users
0
0
4
Study Futarchy.
ok @polymarket is literally the most up only company i have ever witnessed first hand in my life literally just mainstream society now wow
0
0
1
We don't need 100 more contest platforms, just the right one (a contest platform made by auditors for auditors) For most of these current companies it's all about extraction.
4
0
16
Cheatcode to Outcompete all current contest platforms 1. How long does it take to Judge a contest ? Can't be arbitrary, people audit for a living (2 weeks max) 2. How long does it take to pay after Judging ? (Immediately is better) 3. Do you treat your researchers like trash
📢 Calling all Web3 security researchers Our first audit contest will start soon⚡️ 🗓️ 17/11 → 23/11 — 18:00 CET Protocol: @Alignerz_ Type: Token launchpad Solidity (~1500 nSloc) 💰 Prize Pool: 45,000 USDT H/M: 20k • L: 3k LSG1: 6k • LSG2: 6k Winner Bonus: 7.5k • Judge:
2
0
15
Tip for hunters who want to do this as a full-time job: 30 minutes of investigating a project before auditing its code can save you from weeks of research, lengthy mediation processes, and lower rewards than promised. For example: If @InterlayHQ's current financial situation
1
6
94
It should be impossible for a protocol like Balancer to be hacked, we need to come up with a comprehensive security framework for protocols securing the heart of DeFi, it might be costly but not nearly as costly as losing money and trust.
0
0
1
Every big hack sets web3 adoption back like 10 years, we need to compel every big protocol in the space to adopt an air-tight security framework. It can't be audits alone, white-hats need to be looking at your code around-the-clock, because black-hats are. We need more auditors.
1
2
24
You just need to open linkedIn, boomers are fascinated with web3 like they just heard of it yesterday, trillions of dollars are coming onchain and you're blackpilling ?
0
0
1