Zach Katz Profile
Zach Katz

@__katz__

Followers
57
Following
246
Media
9
Statuses
92

blockchain security researcher https://t.co/pt7aRDecrD

Joined October 2014
Don't wanna be here? Send us removal request.
@__katz__
Zach Katz
8 days
Arrived in Buenos Aires! Me: - prev Google SWE - Blockchain Security Researcher - Socially adept - 1x Kenyan jail survivor - All around good dude - Open to work! If you’re interesting and/or building something interesting, let’s meet up! DMs are open.
1
1
7
@__katz__
Zach Katz
6 days
Best party favor I’ve ever received — thanks @OpenZeppelin ! #devconnect
0
0
2
@binji_x
binji
2 months
The countries with the most crypto adoption adjusted by population:
45
9
127
@__katz__
Zach Katz
3 months
Learning a lot every time Need to spend longer in the codebase/take a 2nd and 3rd pass — missed some easy ones here Going to the jungle for the next month to get some extra focus 🇨🇷 Next goal: 4-figure payout @mellowprotocol @sherlockdefi #believeinsomETHing
0
0
0
@__katz__
Zach Katz
3 months
10th in @symbioticfi contest. It’s good but not good enough. Gonna start trying soon.
0
0
4
@__katz__
Zach Katz
3 months
Idk yet if I’ll make my career as a smart contract auditor However, this path offers the best technical foundation you can build in Web3, and I need to keep getting better at it Maybe some interesting opportunities will pop up at the Argentina World’s Fair HMU if you’re going
1
0
3
@__katz__
Zach Katz
4 months
This is a simpler excerpt from my "Vulnepaedia". In it, I summarize all my missed bugs in contests. Paragraph 1: What was the issue? Paragraph 2: Why did I miss it? Paragraph 3: How will I find similar ones next time? It's amazing how much this exercise will teach you.
0
0
1
@sherlockdefi
SHERLOCK
4 months
🏆 @debankdefi Audit Contest Results 🏆 Congrats to: 1. @ObsidianAudits - $15,957 🥇 2. @4mj3x - $1,016 🥈 3. @__katz__ - $695 🥉 $30,000 rewards ➡️ $15.8M+ paid out in rewards.
1
4
36
@__katz__
Zach Katz
4 months
💭’s on impending ETH craze, courtesy @ethereumJoseph: 1. ETH has come a long way in throughput/composability, BUT 2. There’s a shortage of smart developers, can’t onboard talent quickly bc it’s too complex. 3. Still not secure — large hacks will be a consistent headwind.
0
0
1
@__katz__
Zach Katz
5 months
Great feeling to be rewarded as a security researcher for the first time after finding both of the high severity issues in @Superfluid_HQ’s new locker system contest on @sherlockdefi. This was after ~2.5 months of learning and it’s only up from here!
2
0
4
@sherlockdefi
SHERLOCK
5 months
@Superfluid_HQ @0xSimao @newspacexyz 🏆 @Superfluid_HQ Audit Contest Results 🏆 4. 0rpse - $752 4. @zxriptor - $752 5. @hopeman1102 - $578 6. Artur - $451 6. @algizsec - $451 7. @__katz__ - $451 7. @roy_ay0 - $451
2
1
3
@panditdhamdhere
Pandit | Ξ🦇🔊
5 months
Just provided liquidity to 2 protocols.
5
1
30
@__katz__
Zach Katz
5 months
0
0
0
@__katz__
Zach Katz
5 months
How could I miss the WORLD’S FAIR?
1
0
0
@__katz__
Zach Katz
5 months
📈[GOING FORWARD] Now I know that the VanillaRegistry is quite primitive and can be used to exploit other validators. Whenever I see its usage in the future, or any validators for that matter, I will put the code under the microscope to see if ownership can be manipulated.
0
0
0
@__katz__
Zach Katz
5 months
🚨[WHY I MISSED IT] I knew nothing about validators. If this post makes 0 sense to you, I felt the same way when first reading the bug report and had to educate myself on what off-chain validators are and how they work.
1
0
0
@__katz__
Zach Katz
5 months
🪲[THE BUG] Off-chain validators' rewards can be front-run by spoofing a receiver in the VanillaRegistry. Pubkey is checked in VanillaRegistry before EigenLayer. If a validator is only in EigenLayer, attacker can redirect rewards by front-running and staking in VanillaRegistry.
1
0
0
@__katz__
Zach Katz
5 months
🧵I missed a high-severity bug in a recent contest. In brief, here's the bug, how I missed it, and how I'll spot it in the future: https://t.co/yC5zGi3FfY
1
0
1
@__katz__
Zach Katz
6 months
~7 weeks of learning smart contract security full time. Did a simulated audit on a previous contest repo. Thrilled to learn that some of my findings would have earned real money! Now I'll begin participating in the upcoming contests. report: https://t.co/2j3oohsXJI
Tweet card summary image
github.com
Contribute to zakatz36/audit-reports development by creating an account on GitHub.
0
0
3
@pashovkrum
pashov
6 months
POV: web3 security researcher trying to think of a Critical severity vulnerability in a Solidity smart contract
13
20
238