Dacian
@DevDacian
Followers
6K
Following
49K
Media
444
Statuses
3K
Audit Team Leader @Cyfrin Protected $40,000,000,000+ on-chain TVL!
in your storage | 🇰🇷
Joined April 2021
1 Hour with @PatrickAlphaC where I cover: 1⃣ how I break down stateful fuzz testing by invariant types and contract lifecycle 2⃣ my favorite general heuristics which I use to find all sorts of bugs in many different codebases 3⃣ mindset and ultimate recipe for success Link👇
9
21
217
Useful heuristic for your AI Auditors: 1⃣ `payable` function receives ETH into contract 2⃣ check which uses `address(this).balance` without subtracting `msg.value` - check can be in modifier, function body or in child function 3⃣ subsequent `call` to external contract sending
github.com
3
2
51
Read the full report: https://t.co/0H4gFf2MjL Formal Verification report coming soon by @alexzoid
github.com
A list of public audit reports conducted by the Cyfrin team - Cyfrin/cyfrin-audit-reports
0
0
7
Shout out @0xRajkumar @jesjupyter @ctrusonchain @alexzoid AMAZING work on Solana DEX / Perps audit finding: * 20 High * 37 Med * 18 Low Large ambitious protocol with DEX/CLOB/Perps/DAO functionality, lots of attack surface very fun audit! @Cyfrin expanding Solana audits🚀
10
2
65
Explore how @Inference_Labs leverages Arweave to tackle AI trust challenges and the future of decentralized AI.
0
1K
4K
At lunch today with group of 🇰🇷 k-mums one asked what I do for fun, since I don't have hobbies like normal people. I thought then answered "Success". My fun is to set goals, work hard to achieve them then set new goals, rinse & repeat. What do you do for fun?
14
0
44
The biggest talent shortage in web3sec is killer sales & business development.
9
1
54
When your AI reports fee-on-transfer, use SafeERC20 etc, report only one finding for each of these then within that finding list all affected lines. Reporting every affected line as its own finding inflates your stats and wastes tons of valuable human time.
1
1
34
Please continue to pray for the protection of Israel and her people. 🙏
489
2K
8K
Epic December layoffs by all big tech giants & among numerous web3 protocols & firms too. Want to be safe or even get promoted? Prioritize directly contributing to growth, revenue & profit - be seen as a growth-maxing, money-making machine 💰
7
1
59
You're a professional smart contract dev or auditor making $100K+ p/y & you have chiselled abs with v-line, the body of a Greek God? Please be honest and if yes, please reply with your workout and diet program.
21
0
10
I’m looking to train a new invariants engineer If we worked together already in some capacity and you want to take the leap DM Small base salary + bonus for engagements and bounties
12
6
73
Today we announced our $15M Series A, led by @Accel, and launched Prism — agentic reporting that can explain your finances. Prism gives you answers you can follow: what changed, why it changed, and the transactions behind it. It’s reporting that shows its reasoning.
12
27
94
Useful heuristic from recent Balancer hack: * function X has one rounding direction * X is called by multiple parent functions * is X's rounding direction correct for all parent callers? Easy, effective & perfect for AIs to automatically identify incorrect rounding.
2
0
45
Recent private audit client was thinking about launching fast after an audit by another firm produced only 1 Crit. But they postponed the launch after our on-going audit produced 6 Highs and counting! The last audit before mainnet should feel like it wasn't worth it.
3
2
75
Wake up: Easy money in Web3 security is gone. If you don’t feel the shift, you’re already behind. The game now belongs to people who deliver real value, not hype. Adapt fast and raise your output. Natural selection is kicking in and only the best will stay.🔄
7
3
59
Many recent complaints by high-profile SRs about unfairness of existing bug bounty models; the space full of copycats seems ripe for disruption. Perhaps 2026 will be the year a new innovative fairer model appears with improved game theory to disrupt existing incumbents? 👀
4
1
51
Onchain Options Trading https://t.co/tSBmLmhcp4 via @YouTube
1
18
112
1/ Citadel got DeFi wrong. Today, DEF, @a16z, @DigitalChamber, @orca_so, @theblockprof, & @UniswapFND wrote to @SECGov in response to @citsecurities' letter misrepresenting how DeFi technology works. Why this group? Citadel blatantly miscited us, and we feel obligated to
41
81
296
Major competitive advantage: behaving professionally with clients especially during disagreements - which should always be kept private, never aired publicly on X. We are always on the same team with our clients, their partners working together towards win-win outcomes.
4
0
56
Beautiful view of the garden from my office, Winter in South Korea 🇰🇷 Very quiet and peaceful here far away from Seoul; great environment to work hard, raise children, have a great life🫰
8
0
97
@windhustler $200K is "Low Reward"? 😅 Relative to TVL maybe, but $200K is a lot of money to many people! The fact that auditors can work-from-home in their own time, find a cool bug and get paid $200K is a huge blessing and opportunity.
10
2
65
New on our Frontier Red Team blog: We tested whether AIs can exploit blockchain smart contracts. In simulated testing, AI agents found $4.6M in exploits. The research (with @MATSprogram and the Anthropic Fellows program) also developed a new benchmark:
356
722
5K
South Italian San Pietro Coffee beans have arrived on US ground.
0
11
31