Łukasz M
@0xluk3
Followers
1K
Following
4K
Media
40
Statuses
1K
Security Researcher, EVM | Move | Rust | Web2 ASR @spearbit | CTO @Monethic_io
monethic.io
Joined October 2017
We are proud to announce that we partnered with @NeonyExchange to conduct a security audit of their complex Perp DEX, written in MOVE. Neony is a decentralized exchange that supports spot and perpetual trading with non-custodial, on-chain settlement. The protocol enables
4
1
11
Cedra × @Monethic_io Monethic, a cybersecurity company specializing in Web3 technologies, is joining the Cedra ecosystem to support builders with security audits and advisory. With expertise across smart contracts, blockchains, wallets, and off-chain systems, Monethic helps
0
3
12
It was great to be part of this event! Lfg @SuperteamPOL 🔥
SOLANA ON TOUR ██████ 100% KATOWICE & KRAKÓW closed the tour... and closed it right! Big shoutout to @mihalwojtas (@superteamPOL), @0xluk3 (@Monethic_io), @zk_kirol (@nori_zk), and @norbertbodziony (@NeonyExchange) for sparking the evenings. POLAND IS SOLANA
1
0
1
Cloudflare spent years restricting scrapers and selling anti-bot protection. Now they offer /crawl endpoint that can fetch HTML, convert pages to Markdown, extract links, and scrape page elements programmatically.
Introducing the new /crawl endpoint - one API call and an entire site crawled. No scripts. No browser management. Just the content in HTML, Markdown, or JSON.
76
233
3K
I feel like there is more AI security tools emerging than actual projects they should be run against.
4
0
24
Codex Security—our application security agent—is now in research preview. https://t.co/JG2uwGUJFv
openai.com
Codex Security is an AI application security agent that analyzes project context to detect, validate, and patch complex vulnerabilities with higher confidence and less noise.
360
285
3K
A password like G7$kL9#mQ2&xP4!w looks strong. Every password checker rates it "excellent." But researchers at Irregular just published something worth knowing: that exact string appeared 18 out of 50 times when Claude was asked to generate a password. The reason: LLMs are
32
365
2K
Fun fact: if you ask Banana model for explaining a JS encryption routine (like me by accident), it will politely explain it and additionally propose to draw a related image. Truly versatile
0
0
3
Assume the contests are back and everyone and their mothers jump in with all the AI scanners in existence. They end up having 0.02$ per each high severity bug because of 1000 dupes. We will be back to the point where real creativity and finding edge cases prevails.
2
1
49
The internet is literally full of such resources. The problem is not lack of knowledge but lack of priority, and "claude audit" will not replace a security oriented development.
Smart contract auditors didn't want to figure out how to build secure open-source toolchains for smart contract development. Instead, now AI will do it for us, and we can finally get rid of auditors.
0
0
7
Built a small extension for myself - stops me from paranoid domain checking every time I visit a bank or exchange. It simply maintains trusted sites in local storage to don't have to investigate every letter in the URL. https://t.co/Pgjt1CEpc0
github.com
Stop falling for fake websites. Chrome extension that shows a green padlock for your trusted domains. - 0xluk3/scamaway
2
1
10
here's an index of 460 common solidity vulnerabilities across 31 unique protocol types scraped from over 10000 solodit findings optimized for LLMs https://t.co/3Wh3CyFzOf
github.com
Index of the most common vulnerabilities per protocol type, with 460 vulnerabilities across 31 protocol types - kadenzipfel/protocol-vulnerabilities-index
16
39
366
Prediction markets are current big narrative. Great overview of what can go wrong there in terms of security
I've audited more prediction markets than I can count If you’re shipping a prediction market in the next 90 days, these are the bugs that will blow you up (all from real audits, not theory). https://t.co/tPLLMcTF9c
1
0
5
What are your preferences to model for certain tasks? Looking for best choices in terms of price/performance. For example to me kimi k2 looks best for now for tasks that require agentic approach (do a serie of tasks), deepsek hangs a lot (or is it just me?)
0
0
1
Not sure who needs a reminder but this is the official solana skill for agents: https://t.co/FpnNBpTMpi Don't trust everything out there. We did an official version to save you time and skip getting mugged
github.com
Claude Code skill for modern Solana development (Jan 2026 best practices) - solana-foundation/solana-dev-skill
37
47
450
We collected some of most common sins of dApp frontends spotted during engagements, and here is the complete guide to recognize and completely get rid of them: https://t.co/49Aa1t45Et
medium.com
DApps do often mimic traditional web applications with frontend and backend layer, just in blockchain space often the backend is primarily…
1
0
3
Interoperability between web2 and web3 increases
ERC-8128: Signed HTTP Requests with Ethereum. A signature-based authentication standard that cryptographically binds identity and intent to every request. The missing primitive to securely verify humans, machines, and AI agents on the web, built on Ethereum.
0
0
8