Pengun Profile
Pengun

@dot_pengun

Followers
191
Following
868
Media
36
Statuses
317

Penguin Blockchain Security Researcher. Not just Penguin. Pengun.

Joined January 2023
Don't wanna be here? Send us removal request.
@dot_pengun
Pengun
2 years
Finally, the payout on @Blast_L2 from @cantinaxyz has been revealed.πŸ’° Exploring Geth nodes and building a poc was very insightful. I didn't find many vulnerabilities, but I'm satisfied that I found high vulnerabilities in the most popular L2.
2
1
14
@popular_12345
p0pular
2 years
hope you didn't need `tx.origin == msg.sender`
@0xCygaar
cygaar
2 years
EIP-3074 was just approved to go live in the next Ethereum hard fork. This EIP will forever change how users interact on EVM chains, making wallet UX simpler, cheaper, and more powerful. Here's a high level overview of EIP-3074 and how it'll change the game 🧡:
0
2
9
@dot_pengun
Pengun
2 years
@SSS_HQ exploit (whitehat rescue) root cause was simple transfer logic bug. transferFrom(me, me, amount) will multiply your balance They audited token contract. Audit catch only 1 low issue πŸ˜… SSS token is non upgradable this can't be fix. Don't swap and remove all liquidity.
@SSS_HQ
Super Sushi Samurai Reloaded | SSS
2 years
We have been exploited, it's mint related. We are still looking into the code. Tokens were minted and sold into the LP. Transaction: https://t.co/F4XeqdyJu2 the exploited funds are in this wallet:
0
1
1
@cantinaxyz
Cantina πŸͺ
2 years
Welcome... to the new largest competition in history with @eulerfinance! πŸ’° $1,250,000 USDC πŸ—“οΈ May 20th - June 17th πŸ“ @cantinaxyz Invite only. Don't have one? Details below:
94
142
296
@dot_pengun
Pengun
2 years
another million contest πŸš€
@cantinaxyz
Cantina πŸͺ
2 years
Welcome... to the new largest competition in history with @eulerfinance! πŸ’° $1,250,000 USDC πŸ—“οΈ May 20th - June 17th πŸ“ @cantinaxyz Invite only. Don't have one? Details below:
0
0
0
@dot_pengun
Pengun
2 years
Sherlock twitter compromised. DO NOT CLICK
0
1
3
@dot_pengun
Pengun
2 years
LFGπŸ”₯
@cantinaxyz
Cantina πŸͺ
2 years
Welcome @Curvance to the @cantinaxyz as we kick off the 2nd largest competition of the year! πŸ’° $375,000 USDC πŸ—“οΈ February 26th, 20:00 PM UTC (6 Weeks) πŸ“ (Competition Link Provided Below) Loading... Need an invite? Details Below πŸ’ΎπŸͺ
0
0
1
@kankodu
Kankodu
2 years
A 🧡 on how yesterday's @MIM_Spell attack worked. The protocol did everything right. They rounded in the protocol's favour whenever they should but one additional function, meant to only reduce the user's funds, ended up enabling the attack. How?
15
94
466
@dot_pengun
Pengun
2 years
Thanks to @Official_Chonii quick fix, we can now safely use Raffle Machine again As a member of the community, I'm proud to have kept our product safe. Always put security first!
0
0
4
@dot_pengun
Pengun
2 years
Today @KonguNFT launched Raffle Machine. However, the feature contained vulnerabilities that could be manipulated by an arbitrary user. I reached out to @SilverbackAvi and fortunately we communicated right away.
2
1
9
@MatthewLilley
I'm Software πŸ¦‡πŸ”Š
2 years
🚨🚨🚨 RED ALERT 🚨🚨🚨: Do not interact with ANY dApps until further notice. It appears that a commonly used web3 connector has been compromised which allows for injection of malicious code affecting numerous dApps.
493
3K
6K
@dot_pengun
Pengun
2 years
Awesome checklist
@sherlockdefi
SHERLOCK
2 years
Using checklists can be a real lifesaver when you're gearing up for a security review or diving into protocol audits. There's a variety out there – some cover the basics, while others zero in on specific protocols. Take a look at these checklists, they're like your secret weapon
0
0
1
@dot_pengun
Pengun
2 years
My first Top 5 in @code4rena Next goal is Top 3 Let's Go πŸš€
0
0
2
@dot_pengun
Pengun
2 years
I totally agree
@33audits
Lee | 33Audits
2 years
Tell yourself you’ll grow a little bit everyday and stop comparing your sucesso to others. Everyone’s path is different. These are the things that help you stay on track when your learning something new. And don’t forget to journal and have check ins. Check in with myself once
0
0
2
@dot_pengun
Pengun
2 years
What truly matters is focusing on your daily growth and development. Keep in mind, when you focus on improving yourself every day, success and results will naturally follow. To me and other security researchers: Let's be better today than we were yesterday!
0
0
5
@dot_pengun
Pengun
2 years
For instance, you might hear about someone earning a five-figure payout with private audit in a month, or someone else reporting a bug every week. These comparisons, however, aren't necessary. They often distract us from our own paths and potential achievements.
1
0
5
@dot_pengun
Pengun
2 years
πŸš€ Ever feel like you're not moving forward or growing anymore? It might be time to consider if you're caught up in comparing yourself to others too much. It's easy to look at others and measure their success against our own.
1
1
9
@dot_pengun
Pengun
2 years
C4 account compromised DO NOT CLICK
0
0
1
@dot_pengun
Pengun
2 years
I'm currently doing an appchain security review. This vulnerability gave me a good insight πŸ™‚
@opensensepw
OpenSense β‚Ώ
2 years
Vulnerability in Cosmos SDK allows attackers to force upgrade of blockchain binary. Attackers can inject malicious string into stdout log to trigger Cosmovisor to upgrade to malicious binary. Explore a real blockchain RCE with @Dooflin5 πŸ‘€ https://t.co/CgbxD7WGUT
1
0
5
@opensensepw
OpenSense β‚Ώ
2 years
Vulnerability in Cosmos SDK allows attackers to force upgrade of blockchain binary. Attackers can inject malicious string into stdout log to trigger Cosmovisor to upgrade to malicious binary. Explore a real blockchain RCE with @Dooflin5 πŸ‘€ https://t.co/CgbxD7WGUT
0
6
18