
Adri
@adrianromero
Followers
1K
Following
1K
Media
37
Statuses
794
independent security researcher | resident auditor @electisec (prev @yAuditDAO) | top warden @code4rena
See my work →
Joined April 2009
Funds were successfully rescued, the issue has been patched and contracts are now secure. Special thanks to @cove_fi, @1inch, @seal_911 and @devops199fan in particular for their exemplary professionalism throughout this entire process.
0
1
10
In particular, @cove_fi used the FarmingPlugin contract to distribute incentives for their new CoveUSD protocol. The implementation of farmed() uses an integer type to offset the user's rewards. By shifting this negatively it would be possible to fake an invalid distribution.
1
0
5
The token-hooks ( contracts developed by @1inch are in essence an ERC20 implementation that notifies hooks on balance changes.
Security researcher @adrianromero recently found a potential security issue in 1inch smart contract code deployed by @cove_fi. The affected version was never deployed within 1inch’s own infrastructure. Patching began immediately & is now complete. No user funds were ever at.
1
0
5
A critical vulnerability I found in code forked from @1inch could have drained ~650k COVE tokens from @cove_fi contracts. Here's how the attack worked and how it was responsibly disclosed 🧵.
On June 12, 2025, a critical reentrancy vulnerability was identified by @adrianromero @yAuditDAO @electisec in Cove’s liquidity mining program and promptly neutralized. No user funds were lost, and 652,565 non-transferable COVE tokens were secured as a precaution. The.
9
18
195
RT @cove_fi: On June 12, 2025, a critical reentrancy vulnerability was identified by @adrianromero @yAuditDAO @electisec in Cove’s liquidit….
0
8
0
RT @electisec: New security report is out! 🥷. You think @OlympusDAO is cool? Well, it got cooler 😎. We reviewed Olympus Cooler V2, a lendin….
0
2
0
RT @electisec: Just dropped a new report 📝. This one covers @origami_fi's hOHM, a cross-chain solution built on top of @OlympusDAO’s Cooler….
0
5
0
RT @twynexyz: Audits are necessary, but not all are equal. Twyne got audited by @electisec (prev. yAudit). The only team to find critical i….
0
4
0
RT @electisec: ⚡Electisec has shaped many security gigabrains… but we're not done!. We're soon kicking off our Smart Contract fellowship to….
0
17
0
RT @electisec: New audit report is live! 🔍. We've been securing @vfat_io since 2023, and we're excited to continue this partnership. Bugs….
0
5
0
RT @electisec: ⚠️ Attention @Uniswap V4 Integratoors ⚠️. Creating and managing liquidity positions that involve native ETH on Uni V4? Read….
0
32
0