R4ZN1V Profile Banner
razniv.eth Profile
razniv.eth

@R4ZN1V

Followers
681
Following
743
Media
39
Statuses
238

Joined December 2021
Don't wanna be here? Send us removal request.
@R4ZN1V
razniv.eth
16 days
This is the kind of bug that keeps protocol teams up at night. A $5M exploit on ZKSwap, enabled by a single statement left in the wrong place. Here’s a deep dive into how it happened, and how onchain monitoring could’ve stopped it. 🧵
Tweet media one
39
53
439
@R4ZN1V
razniv.eth
12 days
This is the vulnerable function that enabled this exploit - the check in the first line should actually be:. require(msg.sender == owner() || msg.sender == address(. )). Instead, the current version makes it possible for anyone to pass the verification and claim ownership.
Tweet media one
@blockaid_
Blockaid
12 days
🚨 Our real-time exploit detection systems had identified malicious transactions targeting one of the staking contracts used by @SuperRare . The attacker had deployed an exploit contract - but the actual attack was performed by a frontrunner one block later. Updates in 🧵
Tweet media one
4
6
44
@R4ZN1V
razniv.eth
15 days
RT @blockaid_: .@CetusProtocol is now secured by Blockaid. - Cetus processes the highest volume and trading demand on @SuiNetwork. - Bloc….
0
24
0
@R4ZN1V
razniv.eth
16 days
9/ So what’s the lesson?. • Emergency code is still production code. • Fallback paths don’t help if they don’t work. • Real-time monitoring isn’t optional, it’s survival-critical.
1
1
12
@R4ZN1V
razniv.eth
16 days
8/ Here’s what should’ve triggered alarms:.• Exodus Mode being triggered after long dormancy.• Dozens of withdrawal calls happening all at once.• Sudden spike in balancesToWithdraw changes. All of it was visible and could’ve been stopped with real-time onchain monitoring.
Tweet media one
1
0
12
@R4ZN1V
razniv.eth
16 days
7/ This wasn’t some obscure edge case. This was the core logic for asset recovery, left completely open. And because Exodus Mode is rarely triggered, the broken path went unnoticed… for months.
1
0
12
@R4ZN1V
razniv.eth
16 days
6/ The attacker didn’t need fancy exploits - just repeated calls to exit() with made-up data. They bypassed balance checks, withdrew across multiple tokens, and abused weak nullifier logic to avoid detection. All while the contract said: ✅
Tweet media one
1
1
23
@R4ZN1V
razniv.eth
16 days
5/ The result? Every withdrawal “proof” (no matter how fake) passed validation. The contract accepted arbitrary claims about token balances…and credited them as if they were real. It turned a trustless fallback mechanism into an unguarded faucet.
2
1
13
@R4ZN1V
razniv.eth
16 days
4/ Here’s the code that should’ve stopped the attack 👇. At first glance, it looks like a real zk-proof verifier. But look closely at the first line: return true;. That’s it. Nothing else runs.
Tweet media one
2
2
22
@R4ZN1V
razniv.eth
16 days
3/ Exodus Mode lets users manually prove they owned tokens in the last verified L2 state. It’s a fallback mechanism: trustless, self-custodial, non-interactive. But ZKSwap's implementation had one fatal flaw: The function responsible for verifying proofs didn’t verify anything.
1
1
12
@R4ZN1V
razniv.eth
16 days
2/ ZKSwap is a zk-rollup built on Ethereum. Like many rollups, it uses a bridge to move assets between L1 and L2. As a safeguard, the bridge includes an “Exodus Mode”, a way for users to reclaim funds without needing the operator. In theory, that’s a great idea. In practice….
1
1
13
@R4ZN1V
razniv.eth
16 days
1/ On July 9th, GMX was hacked for $42M. But something else happened that day and barely anyone noticed: ZKSwap's bridge was quietly drained for $5M. The interesting part? There was no fancy exploit involved. Just a critical function that did… nothing.
Tweet media one
2
1
23
@R4ZN1V
razniv.eth
3 months
1
6
17
@R4ZN1V
razniv.eth
3 months
*First* AI Generate multiplayer game. Well Played ;).
@j0nathanj
Jonathan Jacobi
3 months
Introducing Multiverse: the first AI-generated multiplayer game. Multiplayer was the missing piece in AI-generated worlds — now it’s here. Players can interact and shape a shared AI-simulated world, in real-time. Training and research cost < $1.5K. Run it on your own PC. We
0
0
9
@R4ZN1V
razniv.eth
3 months
RT @j0nathanj: Introducing Multiverse: the first AI-generated multiplayer game. Multiplayer was the missing piece in AI-generated worlds —….
0
198
0
@R4ZN1V
razniv.eth
4 months
RT @blockaid_: Blockaid 🤝 LOBSTR.
0
8
0
@R4ZN1V
razniv.eth
4 months
RT @blockaid_: 🚨 Our exploit detection system had identified multiple malicious transactions targeting @btcmapp contracts. The attack is….
0
36
0
@R4ZN1V
razniv.eth
4 months
Excited to support Ronin Wallet and the amazing Ronin ecosystem.
@Ronin_Network
Ronin
4 months
Ronin Wallet updates are LIVE!. New security features and more ⚔️. There are so many things happening on Ronin that it’s hard to keep up — and also stay 100% safe. The latest update to YOUR Ronin Wallet fixes this. Update your wallet now 👇. 🔗 : Here’s
Tweet media one
0
0
8