0xOptimum Profile Banner
Optimum Profile
Optimum

@0xOptimum

Followers
625
Following
591
Media
18
Statuses
277

Senior Independent Auditor | Lead Security Researcher @SpearbitDAO, See my work at https://t.co/8oSflO2Pqa

Joined September 2013
Don't wanna be here? Send us removal request.
@0xOptimum
Optimum
9 months
Security is a top priority for every #web3 project. While much is written about vulnerabilities, less focus is on practical steps for a secure lifecycle. Check out my guide, "The Complete Guide to Securing Smart Contracts," from design to deployment.
github.com
Practical tips for building secure web3 projects at every stage, from the initial design to deployment - optimumsec/the-complete-guide-to-securing-web3-projects
8
21
134
@0xOptimum
Optimum
5 days
Going to extend it soon to cover web2 subjects and ops security and many more, stay tuned!.
@0xOptimum
Optimum
13 days
Hey frens 👋 My smart contract security guide just got a glow-up — it’s now a GitBook 😎.
0
0
8
@grok
Grok
5 days
What do you want to know?.
384
237
2K
@0xOptimum
Optimum
5 days
8+ years in web3 have taught me many lessons. This is the first in a series I’ll share—covering building, investing, and maintaining long-term perspective in this space. In the early days, the focus was on ideals. Decentralization and immutability were considered essential.
0
0
1
@0xOptimum
Optimum
13 days
Hey frens 👋 My smart contract security guide just got a glow-up — it’s now a GitBook 😎.
docs.optimumsec.xyz
@0xOptimum
Optimum
9 months
Security is a top priority for every #web3 project. While much is written about vulnerabilities, less focus is on practical steps for a secure lifecycle. Check out my guide, "The Complete Guide to Securing Smart Contracts," from design to deployment.
3
4
26
@0xOptimum
Optimum
1 month
Updated guide on securing Web3 protocols! 📖 New section on contract deployment verification. Fresh from aiding a project’s launch (~$1B TVL in 2 weeks) Check it out:
0
0
1
@0xOptimum
Optimum
1 month
eth pumps = many opportunistic people enter the scene = rush to deploy quick = more money is being stolen. been through these cycles. .
0
0
2
@0xOptimum
Optimum
1 month
Projects need to always review code fixes suggested by external people. I can imagine a scenario where a malicious bounty hunter catches a low/medium and proposes a fix that might cause a critical issue that later will be exploited.
0
0
3
@0xOptimum
Optimum
1 month
Plant what you need.and water that seed.and then you gon' eat when it's time to.
0
0
1
@0xOptimum
Optimum
1 month
Was reading about Monad parallel execution. It’s like an RDBMS for blockchain—optimistic txs run concurrently with dependency tracking to keep things ACID-compliant. txs run on separate cores if they don’t touch the same state. Conflicts? Just re-run the clashing ones.
0
0
1
@0xOptimum
Optimum
1 month
It is always darkest before the pump.
0
0
1
@0xOptimum
Optimum
2 months
it's time for web3 protocols to hire in-house security teams, or at least a head of security/ web3 CISO or at least a killer vCISO (virtual CISO). I'm working on formalizing what are all the tasks such role should have. stay tuned.
3
0
11
@0xOptimum
Optimum
2 months
@iakshatmittal is a great advocate of on-chain deployment scripts, I had the amazing opportunity to work with him to secure @reserveprotocol in the past.
0
0
2
@0xOptimum
Optimum
2 months
So much noise in this industry, just build.
0
0
0
@0xOptimum
Optimum
2 months
The actual vulnerability is not described well. I guess it is due to a non atomic initialization created because off chain deployment (foundry for instance) is done in more than a single transaction. that's why I'm a fan of on-chain deployment scripts (although not perfect) and.
@deeberiroz
deebeez
2 months
We @VennBuild just discovered a critical backdoor on thousands of smart contracts leaving over $10,000,000 at risk for months. Along with the help of security researchers @dedaub @pcaversaccio, the seals team @seal_911 and others, we managed to rescue the majority of funds.
1
0
5
@0xOptimum
Optimum
2 months
Wow, that's big! was a great time helping securing your code, and looking forward for the next time 🫡.
@withAUSD
Agora
2 months
We are thrilled to announce that Agora has raised a $50 million Series A round, led by @paradigm and with additional participation from @dragonfly_xyz. This milestone enables us to accelerate the development of Agora’s full-stack platform for stablecoin infrastructure,
Tweet media one
0
0
7
@0xOptimum
Optimum
2 months
RT @cantinaxyz: This review was conducted by @0xhyh, @0xOptimum, rvierdiiev, and @slowfinanc3. Issue classification risk is as follows:. •….
0
2
0
@0xOptimum
Optimum
2 months
RT @0xOptimum: orderBook.executeIncreaseOrder() called the fallback function of the exploiter contract that then called back the reward rou….
0
1
0
@0xOptimum
Optimum
2 months
Cross contract reentrancies are the nastiest, hardest to find, usually caused by poor contract design and can't be stopped by a simple reentrancy guards.
0
0
2
@0xOptimum
Optimum
2 months
The DAO hack struck June 17, 2016, stealing 3.6M ETH via reentrancy. 😱 9+ years later, reentrancy bugs still haunt DeFi! .As a security auditor, I’ve found 30+ such vulns but clearly audits are not enough.
1
0
8