andyfeili Profile Banner
Andy Li Profile
Andy Li

@andyfeili

Followers
9K
Following
5K
Media
167
Statuses
1K

security assessment manager, engineer @sigp_io

Joined July 2021
Don't wanna be here? Send us removal request.
@andyfeili
Andy Li
3 months
Found a live bug in EigenLayer (this was a few days before the cantina contest). It was discovered during reviewing the offchain sidecar rewards calculation.
6
12
146
@andyfeili
Andy Li
3 days
M4ML completed
Tweet media one
Tweet media two
8
0
63
@andyfeili
Andy Li
4 days
interview invites will be going out soon, stay tuned!.
2
1
45
@andyfeili
Andy Li
9 days
We have manually reviewed all the applications and will be sending out 20 interview invites soon. To give an idea of the quality, the people who have made the cut have had 50+ H/M bugs in audit contests, multiple top finishes, private audit portfolio.
@andyfeili
Andy Li
12 days
270 applications so far, reviewing them this week.
15
2
90
@andyfeili
Andy Li
12 days
270 applications so far, reviewing them this week.
@andyfeili
Andy Li
16 days
We will be taking on 3-4 security interns this round. 6-8 weeks paid internship. I will be acting as one of the mentors . Apply here.
4
2
74
@andyfeili
Andy Li
16 days
We will be taking on 3-4 security interns this round. 6-8 weeks paid internship. I will be acting as one of the mentors . Apply here.
@sigp_io
Sigma Prime
17 days
Sigma Prime is hiring ๐Ÿš€. Weโ€™ve just added 3 roles to our GitHub. - Blockchain Security Intern.- Rust Engineer.- DevOps Engineer. Help shape the future of web3 with us ๐Ÿ‘‡.
14
4
177
@andyfeili
Andy Li
18 days
0
2
17
@andyfeili
Andy Li
18 days
wrote a blog post for this.
@sigp_io
Sigma Prime
18 days
A critical division-by-zero vulnerability was discovered by our team in EigenLayerโ€™s sidecar rewards calculation that could have caused DoS for AVSs and operators. The issue was fixed before exploitation by adding explicit checks onchain and in the sidecar.
1
0
18
@andyfeili
Andy Li
30 days
planning out a more structured internship intake - security engineers and an internal LLM role, will post more details when it gets finalized.
4
0
50
@andyfeili
Andy Li
1 month
Some sparring at the local dojo in Osaka ๐Ÿ‡ฏ๐Ÿ‡ต
3
1
28
@andyfeili
Andy Li
2 months
Finished dm course, over 400 hours in total now
Tweet media one
15
1
102
@andyfeili
Andy Li
3 months
Just had a review with this number of findings. Ideally a second round of review should be done with different testers. There are certain biases that build up as you become more familiar with a code base that makes it harder to check all your assumptions the second time round.
Tweet media one
3
0
34
@andyfeili
Andy Li
3 months
The protocol could try to protect you by refusing to testify or give evidence on court? But it won't make a difference since there will be plenty of public blockchain data as evidence to make the conviction.
0
0
0
@andyfeili
Andy Li
3 months
A negotiated white harbour agreement post hack, at best might serve some purpose of protecting you from a civil case, but the protocol has no power deciding whether you get charged criminally by the state, that agreement between you and the protocol have no sway here. It is the.
5
0
23
@andyfeili
Andy Li
3 months
Hack a protocol, negotiate to return 90% of the funds and keep 10% as a "bug bounty". Same as hacking a database of PII and negotiating a "bug bounty" for the deletion of PII. It is literally demanding a ransom payment.
1
0
9
@andyfeili
Andy Li
3 months
If going by case law, the current precedent is that you 100% can get prosecuted even if you return the funds under a negotiated safe harbour agreement post hack. Shakeeb Ahmed: 8.8 million stolen from Crema Finance, returned most funds with agreement protocol will not report.
@1_00_proof
100proof.org
3 months
After the DAO hack in 2017, the idea that โ€œcode is lawโ€ was called into question. The notion of blockchain as an infallible, self-governing system seem quaint at best. But what if we embraced an adversarially hardened blockchain, where hacks were seen as the cost of improving.
6
0
27
@andyfeili
Andy Li
3 months
This required a immediate patch to sidecar and is now also fixed onchain after the slashing update. Fortunately, this issue hadn't been exploited before detection.
0
0
13
@andyfeili
Andy Li
3 months
The only validation onchain was:. ๐˜ณ๐˜ฆ๐˜ฒ๐˜ถ๐˜ช๐˜ณ๐˜ฆ(๐˜ฅ๐˜ถ๐˜ณ๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ % ๐˜Š๐˜ˆ๐˜“๐˜Š๐˜œ๐˜“๐˜ˆ๐˜›๐˜๐˜–๐˜•_๐˜๐˜•๐˜›๐˜Œ๐˜™๐˜๐˜ˆ๐˜“_๐˜š๐˜Œ๐˜Š๐˜–๐˜•๐˜‹๐˜š == 0, ๐˜๐˜ฏ๐˜ท๐˜ข๐˜ญ๐˜ช๐˜ฅ๐˜‹๐˜ถ๐˜ณ๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ๐˜™๐˜ฆ๐˜ฎ๐˜ข๐˜ช๐˜ฏ๐˜ฅ๐˜ฆ๐˜ณ());. Which allowed zero duration.
1
0
7
@andyfeili
Andy Li
3 months
The risk was that if any AVS submits any reward type with 0 duration, it can halt the rewards calculation in the sidecar and lead to a denial of service.
1
0
7
@andyfeili
Andy Li
5 months
Growing up, when entering a new class environment she was always below average. When exiting, she was able to achieve above average or near the top. Though she was never a top student. Parents encouraged her to set goals, she incrementally did so building confidence in her.
@jenzhuscott
Jen Zhu
5 months
DeepSeek Principal Researcher: Luo Fuli. Grew up poor in the countryside of Sichuan. Went to Beijing Normal University (not a top tier) to study EE, changed to CS (as โ€œa bad studentโ€ she claims). Post-graduate at Peking U & thought sheโ€™d be a product manager at one point ๐Ÿ˜…
1
1
15