carlitox477
@carlitox477
Followers
2K
Following
6K
Media
120
Statuses
1K
Web3 security researcher +36.000 USD in audits competitions
Joined October 2022
🤓🤓🤓
Awards have been announced for the $90,500 USDC @AragonProject competition! Top 5: 🥇 @carlitox477 - $17,746.25 USDC 🥇 @adrianromero - $17,746.25 USDC 🥈 V_B (@vladbochok1, barichek) - $8,058.25 USDC 🥉 0x52 - $7,985.81 USDC 🏅 @akshaysrivastv - $6,215.37 USDC (1/2)
4
2
44
USDX is becoming a 680m$ rug pull! Disabled discord, deafening silence and zero transparency Let’s dig into what’s becoming the biggest scam of 2025 👀 What is USDX? @StablesLabs describes USDX as “A delta-neutral synthetic stablecoin that offers: Delta-neutral stability with
21
33
163
@SiloFinance are banning people after stream finance exit SCAM. Team are not responding anymore and try to delete their profile. DM with no answer but i'll keep as memory hier the name of Ayham jaabari aka @ayham_eth Good behaviour guys, i appreciate Cc @arbitrum, @avax
0
2
6
we have an important problem with the curator ecosystem. there is a lot of documentation on "smart contracts", "security", "trading", etc.. but absolutely nothing on how do curators operate EXACTLY or what processes and methodologies they use to evaluate risk. this is not good.
1
1
3
Since Monday’s @Balancer v2 exploit, we’ve worked hand in hand with their team to develop the first root-cause analysis of the issue, identify all affected and potentially vulnerable pools, and determine whether v3 was susceptible to the same attack. Our analysis breaks down
certora.com
Certora’s in-depth analysis of the Balancer v2 exploit — what caused it, and how v3’s redesign prevents similar hacks.
8
39
189
stream finance loses $93 million of users' funds, writes this tweet, turns off comments and then goes radio silent until now 36 hours since the last tweet during high alert times one of the main responsible guys 0xlaw is talking about how he is suicidal. i have no sympathy for
30
11
248
I just got off a call with a large institution that told me: “Liquidity crunches like this are unacceptable. How could we ever justify that to our clients? They’d lose trust not only in crypto, but in us. Integrating a product means validating it.” That line hit me hard.
15
7
119
By the way Every single money market that allows hardcoded "stablecoin" oracles is guilty and complicit in the loss of user funds. The greed for more TVL is what lead to this Today it was Euler and Morpho with xUSD But tomorrow it can be Aave with USDe
So Stream will have $300-500M in liabilities instead of $60M because xUSD is hard coded on every money market like Euler and Morpho and will take weeks/months to liquidate while accruing bad debt. Good Job guys 👍
53
34
305
This is a screenshot I just took from Morpho on Arbitrum. It’s absurd that platforms promote curator vaults with almost zero liquidity but 40% APRs. The average DeFi user will jump in thinking their assets are “safe” without realizing their lent USDC is being exposed in the
2
2
12
SECURITY & INNOVATION IN DEFI A great session at DeFi Tuesday x @UniswapFND, where @GabrielGruber shared how @Exa_App is redefining onchain finance. After that, @carlitox477 joined builders for a talk on why security is a key pillar for sustainable growth in Web3.
1
3
15
DeFi Tuesday x @UniswapFND tomorrow at @crecimientoar Aleph Hub! 15:30 - @carlitox477 web3 security researcher and auditor 17:30 - @GabrielGruber Exa Labs (@ExactlyProtocol, @Exa_App) founder and CEO Must-attend talks this Tuesday!
1
2
15
@RealJohnnyTime 15 lows is a waste of everyone's time, 3 highs actually brings value.
4
3
76
🚨Yesterday’s markets put every chain to the test. Here’s how Ethereum performed compared to others under heavy load Ethereum processed over 2,835 TPS with less than 1% failure rate ⚡️ solana processed less than 1,800 true TPS, 99% TX failure rate leading to MASS LIQUIDATION🤮
55
48
442
to those who want to find similar bugs in all smart contracts, in seconds. now available to all whitehats.
19
47
379
The crates.io team was notified of two malicious crates (with similar names as legitimate crates) which were actively searching file contents for Etherum private keys, Solana private keys, and arbitrary byte arrays for exfiltration.
11
44
217
I don't know if any major protocols follow me. I'd like to develop relationships with major protocols before I look at their codebase, and sustain ongoing relationships after. This will ensure that I am providing the best "continuous security" service I can, and stop me wasting
4
3
65
La plataforma de juegos Steam tuvo durante más de dos meses un juego infectado en su store, el cual robaba contraseñas y otros activos de las computadoras donde se instalaba. Es por esto que siempre decimos que si estás en crypto o te importa tu seguridad, tenés que instalar la
11
17
155
Un delincuente targeteaba pacientes con cáncer para robarles crypto. Se juntaron un par, siguieron pistas y lo encontraron. El hijo de puta es un argentino viviendo en Miami. No me sorprende, la gran mayoría de los mersas que viven ahí billeteando, se dedican a cagar gente.
dawg, OSINT nerds found the guy who drained the cancer bro. hes an immigrant on a VISA from argentina currently living in miami, florida, USA the OSINT nerds reported him to ICE 😭 omfg 😭😭
18
45
500