Volodya Profile
Volodya

@0xVolodya

Followers
2K
Following
1K
Media
87
Statuses
356

Smart contract security researcher Currently available for projects πŸ—“

Joined October 2015
Don't wanna be here? Send us removal request.
@SoloditOfficial
Cyfrin Solodit πŸŸͺ
2 years
🚨 The ULTIMATE auditing and smart contract security research checklist is officially out! We've aggregated over a myriad of sources, compiled the industry's best practices, and have prepared a systematic approach to auditing contracts. Here's how it works:
23
101
416
@milotruck
MiloTruck
2 years
Took a break from staring intensely at Solidity to write a blog. I bring you: "A year of Competitive Audits" - my learnings from competing in contests for a year, and an honest review of the opportunities it gave me. Do check it out, it's full of alpha: https://t.co/DukbxO0Fn0
milotruck.github.io
A look into audit contests from the eyes of a competitive auditor in 2023.
59
53
404
@0xVolodya
Volodya
2 years
An awesome finding, congratulations! πŸŽ‰
@zellic_io
Zellic
2 years
The dangers of integer truncation: How the Zellic team found a critical vulnerability in the @AstarNetwork. This bug allowed an attacker to drain certain LP contracts on the Astar-EVM, with no bugs required in the contracts. Read more: πŸ§΅πŸ‘‡
0
0
7
@0xVolodya
Volodya
2 years
Even the GitHub UI is not perfect.
0
0
9
@0xVolodya
Volodya
2 years
Taken from ebtc cantina report https://t.co/0MshQJEEte
0
0
2
@0xVolodya
Volodya
2 years
In solmate ERC20 token does not decrease the allowance of the spender when such allowance has been set to the max value - type(uint256).max, thus approved to max value at one point in the future will revert πŸ’‘
2
0
5
@0xVolodya
Volodya
2 years
Here is a medium issue in the code?
9
0
29
@code4rena
Code4rena
2 years
Here it is: a technical blog breaking down everything you need to know for the upcoming $1.1M+ audit with @zksync 🀝 Read it now: https://t.co/Gmygtf8H09 (1/2)
2
18
92
@portport255
porter | ZKsync ∎
2 years
Here's what I recommend to study: 1. Practice Rust. The circuits are all written in Rust. 2. Get familiar with common ZK terminology such as circuits, constraints, and gates. 3. Learn about common ZK bugs:
Tweet card summary image
github.com
A community-maintained collection of bugs, vulnerabilities, and exploits in apps using ZK crypto. - 0xPARC/zk-bug-tracker
5
14
71
@0xVolodya
Volodya
2 years
Incorrect block period constant πŸ’‘ Since zk is so popular now. This is a finding from a year ago on a zksync contest which received a whooping $70,985.01
2
6
35
@0xVolodya
Volodya
2 years
Wow, is that the biggest hack in 2023? $200 million ☹️
@MixinKernel
Mixin Kernel
2 years
[Announcement] In the early morning of September 23, 2023 Hong Kong time, the database of Mixin Network's cloud service provider was attacked by hackers, resulting in the loss of some assets on the mainnet. We have contacted Google and blockchain security company @SlowMist_Team
1
0
8
@0xVolodya
Volodya
2 years
πŸ’‘WETH contracts differ on different chains: transferFrom will work without allowance on the Ethereum chain if the sender is an address that executes the function. But it will revert on some other chains like polygon due to the fact that they always subtract the allowance
2
3
43
@0xVolodya
Volodya
2 years
It looks incredible @sherlockdefi πŸ‘
1
1
14
@0xVolodya
Volodya
2 years
80SLOC - seems like this will be one of the smallest codebases in history at @code4rena
6
0
44
@0xVolodya
Volodya
2 years
Openzeppelin contracts v5 pre-release is out: ERC1155Receiver: Removed in favor of ERC1155Holder. ERC2771Forwarder: Added deadline for expiring transactions, batching, and more secure handling of msg.value ERC20, ERC721, ERC1155: Deleted _beforeTokenTransfer and
4
7
64
@0xVolodya
Volodya
2 years
"20 min read". It took me almost a whole day to understand this article by @0kage_eth. It was awesome to read his thoughts! https://t.co/nwJptutZN3
Tweet card summary image
medium.com
β€œβ€ is published by 0Kage.
4
10
68