Calcifer
@calc1f4r
Followers
346
Following
2K
Media
23
Statuses
299
Secutity researcher || 100 H/M + found in private + public audits || researcher proficient in rust, move and solidity audits
127.0.0.0:8585
Joined November 2021
If you wanna learn move for auditing on @SuiNetwork or @Aptos, you can use these resources π https://t.co/CY6b8112rv π https://t.co/U3JedRxKOr π https://t.co/h1MSSeqlTt π https://t.co/a5P4bMZlva π https://t.co/Az6pni0ebY π π Reports
ottersec.notion.site
Hosted by Notion Sites β The easiest way to get a website up and running.
1
5
50
We ran a blind, empirical test on most AI audit agents in the web3 space, using real contests. The results? Most tools missed critical flaws, drowned users in false positives or fail to run at all. Thread π
14
27
107
Heyyy all, Remember my vulnerability clustering project? Fixed the broad clustering issue - new approach gives much better granularity. Beeing the good person i am, here is the repo link: https://t.co/B4Apjx2ng6 Note: still tweaking the algorithm, can be some issues
0
1
19
π₯A little late and a small win , stood first at C8ntinuum Dual Defense audit at @HackenProof
3
0
15
π₯To all struggling to understand vulnerabilities in the @steller smart contract ecosystem: We wrote an article explaining issues, beyond logical vulnerabilities, that can lead to your contract being exploited. https://t.co/boh60ew8Fm
arjunasec.xyz
Top-ranked blockchain security firm specializing in Solana smart contracts, Rust ecosystems, and advanced invariant testing. Proven track record in major competitions.
3
6
24
Solana validators patch zero-day bug that could have led to unlimited minting of certain tokens
theblock.co
It is unclear who reported the bug, and whether or not the individual or group will be entitled to a bug bounty from the Solana Foundation.
16
3
20
quit brainrot. unfollow trolls. read essays. go down rabbit holes. have a calendar. maintain a todo list. read old books. watch old movies. turn on dnd. walk with intent. eat without youtube. chew more. train without music. plan for 15 mins. execute. organise your desk. take
309
7K
40K
If you wanna learn move for auditing on @SuiNetwork or @Aptos, you can use these resources π https://t.co/CY6b8112rv π https://t.co/U3JedRxKOr π https://t.co/h1MSSeqlTt π https://t.co/a5P4bMZlva π https://t.co/Az6pni0ebY π π Reports
ottersec.notion.site
Hosted by Notion Sites β The easiest way to get a website up and running.
1
5
50
Iβm working closely with top Lead Security Researchers during audits. They all have a few things in common: > They understand things quickly > They dive really deep into the codebase > They take an enormous amount of notes > They work hard β fully locked in - My personal view?
3
9
128
Smart contract security is one of the only fields where a 17-18 y/o can legitimately become a millionaire. No degrees. No suits. Just skills. I personally know a couple of these guys. Itβs wild.
8
13
219
Send us those vibe-coded Solana contracts π at @arjuna_sec. Weβd love to explain how these vibe-coded contracts make you lose money on critical, juicy issues π©βπ There are still many issues that Claude and ChatGPT write about Solana on the first try.
0
0
3
π¦ Presenting the most up-to-date @solana best practices checklist to enhance your Solana expertise and auditing journey. π¦Go hunt those Solana bugs out in the wild πͺ #web3 #web3security #solanasecurity #web3community #solana Check out:
3
8
62
Seeing that the majority doesn't believe kick-off meetings are useful, let me add my 2 cents why this is completely wrong. A kick-off is not for the benefit of the researcher. The client gave a hell of a lot of $$$ to you or your company for the audit. He is anxious and under
Do you find introductory kick-off calls before the audit useful for devs & researchers? I've been on both sides, and my hunch is that developers find kick-off calls useful, but researchers not so much. Devs, drop your opinion in the commentsβ¬οΈ
4
1
32
Are you looking for Rust-Audit-Roadmap? π§ Here is the link: https://t.co/1NZW7FRipr And Bonus -> Awesome Rust Security π«‘ https://t.co/7GBniTMh4u
github.com
Curated list of awesome projects and resources related to Rust and computer security - osirislab/awesome-rust-security
2
11
64
And with this, I am dropping out of college and joining web3sec full-time, Thank you @cantinaxyz for getting me out of a place where I didn't learn anything. π«More to come from @arjuna_sec and Thanks to the @ctrusonchain for being on the same journey together.
You've waited, we've deliberatedβthe results are in for the Inclusive Finance competition. πͺ Your top 3 ranked researchers are: π₯ @KupiaSecurity: $10,984.57 π₯ Team Arjuna ( @calc1f4r / @ctrusonchain): $6,723.92 π₯ @zigtur: $3,500.66 Thank you to everyone that
5
1
71
0
1
3
Want to dive into CosmWasm smart contract security? This CosmWasm Audit Roadmap provides a structured guide for auditing and identifying vulnerabilities in CosmWasm π https://t.co/U9NcfdTRfQ
github.com
Roadmap to get up to speed with CosmWasm smart contract audits and security vulnerabilities - jcsec-security/CosmWasm-audit-roadmap
2
7
61
I spent past 6 months reading countless articles and docs about Solana mechanism design and architecture. I have collected the most important info in single long read. That includes mechanism design, fee markets, MEV, and more. Here are the answers to all your questions: β
10
41
230