DevDacian Profile Banner
Dacian Profile
Dacian

@DevDacian

Followers
6K
Following
49K
Media
444
Statuses
3K

Audit Team Leader @Cyfrin Protected $40,000,000,000+ on-chain TVL!

in your storage | 🇰🇷
Joined April 2021
Don't wanna be here? Send us removal request.
@DevDacian
Dacian
2 years
1 Hour with @PatrickAlphaC where I cover: 1⃣ how I break down stateful fuzz testing by invariant types and contract lifecycle 2⃣ my favorite general heuristics which I use to find all sorts of bugs in many different codebases 3⃣ mindset and ultimate recipe for success Link👇
9
21
217
@DevDacian
Dacian
5 hours
Useful heuristic for your AI Auditors: 1⃣ `payable` function receives ETH into contract 2⃣ check which uses `address(this).balance` without subtracting `msg.value` - check can be in modifier, function body or in child function 3⃣ subsequent `call` to external contract sending
Tweet card summary image
github.com
3
2
51
@DevDacian
Dacian
1 day
Shout out @0xRajkumar @jesjupyter @ctrusonchain @alexzoid AMAZING work on Solana DEX / Perps audit finding: * 20 High * 37 Med * 18 Low Large ambitious protocol with DEX/CLOB/Perps/DAO functionality, lots of attack surface very fun audit! @Cyfrin expanding Solana audits🚀
10
2
65
@OnboardArweave
Onboard.
5 months
Explore how @Inference_Labs leverages Arweave to tackle AI trust challenges and the future of decentralized AI.
0
1K
4K
@DevDacian
Dacian
2 days
At lunch today with group of 🇰🇷 k-mums one asked what I do for fun, since I don't have hobbies like normal people. I thought then answered "Success". My fun is to set goals, work hard to achieve them then set new goals, rinse & repeat. What do you do for fun?
14
0
44
@DevDacian
Dacian
2 days
The biggest talent shortage in web3sec is killer sales & business development.
9
1
54
@DevDacian
Dacian
3 days
When your AI reports fee-on-transfer, use SafeERC20 etc, report only one finding for each of these then within that finding list all affected lines. Reporting every affected line as its own finding inflates your stats and wastes tons of valuable human time.
1
1
34
@TheFellowship
The Fellowship
3 months
Please continue to pray for the protection of Israel and her people. 🙏
489
2K
8K
@DevDacian
Dacian
5 days
Epic December layoffs by all big tech giants & among numerous web3 protocols & firms too. Want to be safe or even get promoted? Prioritize directly contributing to growth, revenue & profit - be seen as a growth-maxing, money-making machine 💰
7
1
59
@DevDacian
Dacian
6 days
You're a professional smart contract dev or auditor making $100K+ p/y & you have chiselled abs with v-line, the body of a Greek God? Please be honest and if yes, please reply with your workout and diet program.
21
0
10
@GalloDaSballo
Alex the Entreprenerd
6 days
I’m looking to train a new invariants engineer If we worked together already in some capacity and you want to take the leap DM Small base salary + bonus for engagements and bounties
12
6
73
@DevDacian
Dacian
6 days
This is why we often recommend defensive measures in our private audits. The best defensive measures remove cards from the attacker's playbook without impacting normal users.
@WhiteHatMage
WhiteHatMage
7 days
Once again so close to a big Critical, but code is safe by an inch. I'll need to explore more ideas.
2
0
36
@UseQuanta
Quanta
13 days
Today we announced our $15M Series A, led by @Accel, and launched Prism — agentic reporting that can explain your finances. Prism gives you answers you can follow: what changed, why it changed, and the transactions behind it. It’s reporting that shows its reasoning.
12
27
94
@DevDacian
Dacian
7 days
Useful heuristic from recent Balancer hack: * function X has one rounding direction * X is called by multiple parent functions * is X's rounding direction correct for all parent callers? Easy, effective & perfect for AIs to automatically identify incorrect rounding.
2
0
45
@DevDacian
Dacian
8 days
Recent private audit client was thinking about launching fast after an audit by another firm produced only 1 Crit. But they postponed the launch after our on-going audit produced 6 Highs and counting! The last audit before mainnet should feel like it wasn't worth it.
3
2
75
@chrisdior777
chrisdior.eth
9 days
Wake up: Easy money in Web3 security is gone. If you don’t feel the shift, you’re already behind. The game now belongs to people who deliver real value, not hype. Adapt fast and raise your output. Natural selection is kicking in and only the best will stay.🔄
7
3
59
@DevDacian
Dacian
9 days
Many recent complaints by high-profile SRs about unfairness of existing bug bounty models; the space full of copycats seems ripe for disruption. Perhaps 2026 will be the year a new innovative fairer model appears with improved game theory to disrupt existing incumbents? 👀
4
1
51
@ProgrammerSmart
🐸Smart🐸Contract🐸Programmer🐸
12 days
Onchain Options Trading https://t.co/tSBmLmhcp4 via @YouTube
1
18
112
@DevDacian
Dacian
13 days
Our pond has frozen now, winter is really here 🇰🇷
4
0
39
@fund_defi
DeFi Education Fund
5 days
1/ Citadel got DeFi wrong. Today, DEF, @a16z, @DigitalChamber, @orca_so, @theblockprof, & @UniswapFND wrote to @SECGov in response to @citsecurities' letter misrepresenting how DeFi technology works. Why this group? Citadel blatantly miscited us, and we feel obligated to
41
81
296
@DevDacian
Dacian
14 days
Major competitive advantage: behaving professionally with clients especially during disagreements - which should always be kept private, never aired publicly on X. We are always on the same team with our clients, their partners working together towards win-win outcomes.
4
0
56
@DevDacian
Dacian
14 days
Beautiful view of the garden from my office, Winter in South Korea 🇰🇷 Very quiet and peaceful here far away from Seoul; great environment to work hard, raise children, have a great life🫰
8
0
97
@DevDacian
Dacian
16 days
@windhustler $200K is "Low Reward"? 😅 Relative to TVL maybe, but $200K is a lot of money to many people! The fact that auditors can work-from-home in their own time, find a cool bug and get paid $200K is a huge blessing and opportunity.
10
2
65
@AnthropicAI
Anthropic
16 days
New on our Frontier Red Team blog: We tested whether AIs can exploit blockchain smart contracts. In simulated testing, AI agents found $4.6M in exploits. The research (with @MATSprogram and the Anthropic Fellows program) also developed a new benchmark:
356
722
5K
@SanPietroCoffee
San Pietro Coffee Team
2 months
South Italian San Pietro Coffee beans have arrived on US ground.
0
11
31