AstraSec
@AstraSecAI
Followers
571
Following
4K
Media
15
Statuses
116
Blockchain security auditing, trusted by Magpie, 1inch, Paraswap, Kodiak, ... (https://t.co/74XaWrdj3c)
Web3
Joined December 2023
Just shipped our 8th consecutive security audit report for @Listapiexyz_io ! Proud to continue securing top-tier DeFi infrastructure and supporting their ecosystem. Read the full report here: π https://t.co/mEqEIh4tnC
github.com
AstraSec audit reports. Contribute to astrasecai/audit-reports development by creating an account on GitHub.
0
0
1
Great working with @HyacinthAudits to lock down @liquidroyaltyX. π¬ Scope: ProtocolVault We dug deep into the vault logic to ensure everything is watertight. π
github.com
AstraSec audit reports. Contribute to astrasecai/audit-reports development by creating an account on GitHub.
Another protocol secured π Our friends at @liquidroyaltyX have successfully completed their second audit with Hyacinth β
Ready to secure your protocol? Get your audit with Hyacinth today π https://t.co/LAV9GrlZmU
0
2
6
We are pleased to release the security audit report for Pandora @HeyAnonai, a decentralized prediction market built for EVM-based blockchains. Weβve verified the security of their trading engine to ensure safe, efficient markets for all users. Read the full report:
github.com
AstraSec audit reports. Contribute to astrasecai/audit-reports development by creating an account on GitHub.
5
16
72
π‘οΈ Exploit Analysis: YO Protocol (~$3.7M Loss) YO Protocol (@yield) suffered a slippage loss in a vault rebalance swap (3.84M stkGHO β only ~$112K USDC via Uniswap V4 pool). We decompiled the calldata: seems @yield blindly trusted the quote from @odosprotocol without confirming
0
0
2
π‘οΈ Securing the Move Ecosystem We are incredibly excited about the rapid growth of the @movementlabsxyz ecosystem! π‘ AstraSec is proud to release the audit report for @LayerBankFi's ULAB. Our team conducted a deep-logic review to ensure a secure foundation for Move DeFi. π
github.com
AstraSec audit reports. Contribute to astrasecai/audit-reports development by creating an account on GitHub.
0
0
3
@TMXTribe @waveX_fi Example transactions: (1) https://t.co/ylNG6cLRo0 (2) https://t.co/XOt1Je8HZX (3) https://t.co/NKGsYRZeAG (4) https://t.co/Zlm103mtMa
0
0
1
@Truebitprotocol It is a classic integer overflow in the purchase/mint pricing logic of an old smart contract (deployed ~5 years ago).Most calculations used safe math (mul/sub/div), but the final addition step was done with an unsafe add β when the attacker inputs an extremely large mint amount,
2
0
5
π‘οΈ Exploit Analysis: TMXTribe (~$1.4M Loss) On Jan 5-6, 2026, @TMXTribe on Arbitrum was exploited due to a flawed TLP token price calculation (p = AUM / total_TLP). The vulnerability shares the similar root cause as the recent @waveX_fi ( https://t.co/NAWYGiusVT) exploit. Swapping
Hello, this is the waveX Team. On December 6, we detected an abnormal transaction that made use of a vulnerability within part of our protocol logic. We immediately initiated a thorough investigation and mitigation procedure. We sincerely apologize for the delay in issuing this
1
0
3
π‘οΈ Exploit Analysis: Truebit Protocol (~$26M Loss) @Truebitprotocol A reminder that one missed check is all it takes. As shown in the image, the purchase function utilized SafeMath for most operations but missed the final addition step. The Vulnerability: The missing safe-add
5
0
19
2 years ago today, we launched AstraSec with a mission to secure the most complex logic in Web3. Today, we celebrate our 2nd Anniversary! A massive thank you to the founders and protocols who have trusted us to safeguard their infrastructure. To our partners @magpiexyz_io
1
0
6
AstraSec has successfully completed the security audit for @FriendSpaceApp. Big kudos to their team for their professionalism and commitment to building a secure ecosystem. π€ π View the findings:
github.com
AstraSec audit reports. Contribute to astrasecai/audit-reports development by creating an account on GitHub.
1
0
9
1/ The total loss amounts to approximately $1 million. The @USPD_io attack exploited a known attack vector in the deployment of ERC1967Proxy contract. The attacker front-ran the initialization call post-deployment, injecting a malicious implementation. Initially, he masked his
We @VennBuild just discovered a critical backdoor on thousands of smart contracts leaving over $10,000,000 at risk for months Along with the help of security researchers @dedaub @pcaversaccio, the seals team @seal_911 and others, we managed to rescue the majority of funds
0
1
6
β οΈ Another approval-misuse vulnerability exploited. collectInterestRepayment() can be called by anyone to forcibly pull USDC from any address that once approved the contract, boosting share price and redistributing the stolen funds as fake βinterest.βIf you ever approved USDC to
2
0
2
Weβre excited to release our latest security audit for @AethonSwap. Big thanks to the Aethon team for their collaboration and trust throughout the process. Read the full report: https://t.co/1LZUiVE7Uy
github.com
AstraSec audit reports. Contribute to astrasecai/audit-reports development by creating an account on GitHub.
1
1
12
Weβre excited to announce the completion of our audit for Candylabs (@candylabs)! π Candy Forge is an innovative on-chain NFT customization protocol on Solana, and itβs been a pleasure working closely with the team to help secure their platform.
Another audit in the books β
@candylabs has completed a full audit for their platform. Need an audit for your project? Build trust and audit with Hyacinth π‘οΈ
0
0
3
β
The @orbs_network Spot Audit Report is now live! Weβre glad to have worked with such a strong and talented development team. Check out the full report here π π
github.com
AstraSec audit reports. Contribute to astrasecai/audit-reports development by creating an account on GitHub.
0
0
3