arsen_bt Profile Banner
Arsen Profile
Arsen

@arsen_bt

Followers
3K
Following
1K
Media
166
Statuses
709

Security Researcher at @zenith256 & @GuardianAudits +$100M of Assets Secured |

Newsletter πŸ‘‰πŸΌ
Joined February 2024
Don't wanna be here? Send us removal request.
@arsen_bt
Arsen
4 months
432 days ago i've entered Web3 Security. - I had 0 coding experience.- I wasn't math guy.- I wasn't technical nerd. Today, i finally achieve my first contest win. - Never stop believe in yourself.- Never quit.- Grind every single day. - Really love it. It's just a beginning.
@cantinaxyz
Cantina πŸͺ
4 months
Good news! The results from our first @ton_blockchain competition are in. See who topped the leaderboard in @ChorusOne's competition. Your top 3 ranked researchers are:. πŸ₯‡ @arsen_bt: $8,825.80. πŸ₯ˆ @n4nika_: $3,692.62. πŸ₯‰ Boy2000: $2,571.82. Thank you to everyone that
Tweet media one
92
41
666
@arsen_bt
Arsen
47 minutes
Want to dive deep into Web3 Security?. Every week, I share simple security stories you can study. Under 5 minutes to read. Join me here πŸ‘‡πŸ».
0
0
2
@arsen_bt
Arsen
47 minutes
Top 6 Questions to better understand EIP712
Tweet media one
1
0
3
@arsen_bt
Arsen
3 days
Want to dive deep into Web3 Security?. Every week, I share simple security tips you can use. Under 5 minutes to read. Join me here πŸ‘‡πŸ».
0
0
1
@arsen_bt
Arsen
3 days
Top 7 EIP's you need to know in 2025:
Tweet media one
1
12
87
@arsen_bt
Arsen
4 days
Security auditing is about creativity. It isn't straightforward process. Auditors are real magicians. Understanding code can be boring . But finding bugs β€” Never. > Thinking out of the box.> Brainstorm sessions.> Flash cards.> Stepping outside for a reset.> Hunting bugs in your.
0
8
74
@arsen_bt
Arsen
5 days
Want to dive deep into Web3 Security?. Every week, I share simple security tips you can use. Under 5 minutes to read. Join me here πŸ‘‡πŸ».
0
0
3
@arsen_bt
Arsen
5 days
Top-7 Sentences to understand Lending-Borrowing better
Tweet media one
2
4
83
@arsen_bt
Arsen
6 days
Want to dive deep into Web3 Security?. Every week, I share simple security tips you can use. Under 5 minutes to read. Join me here πŸ‘‡πŸ».
0
0
5
@arsen_bt
Arsen
6 days
Overall, how to spot such bugs?. Firstly, define critical callbacks. Questions like:. > What access control they have?.> Can reach them via "relayer"?. Can help auditors sniff such bugs.
1
0
3
@arsen_bt
Arsen
6 days
Recent $1M Bug found in a Scroll. Brilliant example of the "Spoofing" vector. It happens due to upgrade. Malicious L2 message created and sent to L1 Gateway. Previosly, it was highly protected. After upgrade = no. Malicious calldata from L2 forced L1 Gateway to initiate a call,
Tweet media one
1
0
2
@arsen_bt
Arsen
6 days
Fake onRevert() call. In case of a cross-chain revert, msg is transmitted back to dApp. And onRevert() interface is executed with custom logic. Issue: Attacker can craft malicious onRevert() and send it directly to dApp. Basically "spoof" the revert call and trigger unintended
Tweet media one
1
0
2
@arsen_bt
Arsen
6 days
Here's the most overlooked pattern in a cross-chain projects. It's called "spoofing attack". Here's how it works 🧡.
1
2
32
@arsen_bt
Arsen
7 days
0
0
4
@arsen_bt
Arsen
7 days
Defendor is the best Web3 Security News Channel. Made from heart, for those who value their time. Subscribe below πŸ‘‡.
@0xRiz0
0xRiz0
7 days
Been using this for a week, one of these best. if not the best alpha you can get. Highly recommended πŸ”₯. Thanks again @arsen_bt 🀝.
1
0
7
@arsen_bt
Arsen
7 days
How to structure your day as Auditor?. First 4 hours is pure gold. Real work is done here:. β€’ Audit of the complex logic.β€’ Study of novel attack vectors. Tasks, which require sharp concentration. Remaining 3-4 hours depends on audit stage. β€’ Continue exploring the codebase.β€’.
3
8
89
@arsen_bt
Arsen
8 days
4 ways I utilise AI as Security Auditor. β€’ Research (Perplexity).β€’ Protocol Analysis (Cursor).β€’ Hack distillation (ChatGPT).β€’ Integration's audit (Github copilot).
3
11
138
@arsen_bt
Arsen
10 days
Golden rule of Security Audit. Personal obervations:. Once I feel drained.Once I think audit is done.Once I think I found everything.Once I don't have any new ideas. I wake up from the chair, and:. > Audit the code at a standing desk.> Go outside and think about the code. It.
7
6
127
@arsen_bt
Arsen
11 days
Advice to myself 2 years ago:. If you want to break Defi, Blockchains projects and be good at it. You must have a balls to break your way of thinking first. Security Auditor faces challenges every day. > Complex systems.> New technologies.> Belief that there's no bugs. First of.
3
7
118
@arsen_bt
Arsen
12 days
Want to dive deep into Web3 Security?. Every week, I share simple security tips you can use. Under 5 minutes to read. Join me here πŸ‘‡πŸ».
0
0
7
@arsen_bt
Arsen
12 days
Just wrapped up 3 weeks audit of Light Client on Rust. Here’s what I learn: . - Rust.- C++.- Bitcoin, Zcash, Dogecoin.- PoW native vulnerabilities.- Merged mining .- How PoW works under the hood.- Merkle Trees Bugs on PoW.- Chain reorg . The best audits are the ones, where you.
3
5
93