Mel Profile
Mel

@x0sauce

Followers
158
Following
136
Media
9
Statuses
83

Independent Web3 Security Researcher | Available for hire (DMs open)

Portfolio →
Joined August 2023
Don't wanna be here? Send us removal request.
@x0sauce
Mel
11 days
I just found a confirmed bug on @immunefi
3
1
25
@x0sauce
Mel
1 month
impactful work is built on on top of boring work
0
0
3
@x0sauce
Mel
1 month
small win. just gonna flaunt it to improve my chances of getting hired at a firm 😹 much more to do though
12
1
84
@x0sauce
Mel
1 month
Many people would not understand the time, sacrifice and amount of focus it takes to be a good SR
0
1
6
@x0sauce
Mel
2 months
Not that this information is useful in auditing but it really helped me to understand how storage slots work in solidity
0
0
1
@x0sauce
Mel
2 months
- address 0x3B0AAf6e6fCd4a7cEEf8c92C32DFeA9E64dC1862 in the private mapping `members` nested in - the struct `RoleData` which is mapped to default admin role 0x0 in the mapping(bytes32 => RoleData) private _roles within the StakedUSDeV2 contract?
1
0
1
@x0sauce
Mel
2 months
While preparing for a SR interview, I recently learnt more about storage in EVM. Heres an exercise 👇
1
0
3
@x0sauce
Mel
2 months
Some wins in Jul and Aug~ Still trying to better myself everyday. One thing I learnt from notional comp is that Im not proficient enough to audit two codebases at once 😹.
0
0
4
@x0sauce
Mel
3 months
Stop being on discord frequently and stop checking your phone first thing in the morning Start internalising the code in your head
1
0
14
@x0sauce
Mel
3 months
More practical tips for SRs: “Just read the code” really means read + understand so you can question it. Jot down your takeaways from reading the codebase, then bring in external info (from the same/external codebases or docs) to question them.
1
0
13
@x0sauce
Mel
3 months
Missed a bug? Do this: 1. Study it deeply. 2. Boil it down to a 1 line heuristic. 3. Without reference, reimagine the code in your head + apply heuristic to "find" the bug This form of information retrieval has helped me to lock the heuristic into my long term memory
0
0
22
@x0sauce
Mel
3 months
Every small win should be celebrated 😁 Behind this small amount earned is the immense amount of knowledge you gained from missing bugs the hard way.
4
0
47
@x0sauce
Mel
3 months
Another win~ Thanks to @sherlockdefi and @Allbridge_io for the opportunity 😸
1
0
27
@sherlockdefi
SHERLOCK
3 months
Welcome back to Sherlock's Vulnerability Spotlight, where we highlight an impactful vulnerability uncovered during a Sherlock audit. This week, we have an Unvalidated Cross-Chain token swap. It was uncovered by @0xekkoo, @0xapple_, @elolpuer, @x0sauce, @patitonar, @sepyke,
2
10
42
@x0sauce
Mel
5 months
Theres a lot of AI FUD nowadays in the auditing space. Better to ignore the noise and keep getting better.
1
1
4
@x0sauce
Mel
5 months
3rd Contest win on @sherlockdefi with 100% high coverage Still missed a lot of bugs despite submitting 30+ findings. A lot more work to be done.
8
1
94
@x0sauce
Mel
5 months
forge test —mt test_POCISpendTooLongToWriteBecauseIHaveNo80RepOr0.68Signal .. passes in one try with no reverts 🥜🥜
0
0
2
@x0sauce
Mel
5 months
Audit alpha? Read as many lines of code as you can -> understand the code -> question it 10 times or more (a lot more actually) -> find a lead -> think about an impact -> validate the lead Thats it. Takes me forever to achieve these few steps
0
2
7
@x0sauce
Mel
6 months
Wrote down a lead and pursued it for 2 days but decided against submitting it and it turns out to be a low dupe bug. Painful lesson to learn 😿.
0
0
2