forkforkdog Profile Banner
FORKFORK DOG Profile
FORKFORK DOG

@forkforkdog

Followers
628
Following
3K
Media
188
Statuses
2K

ECHIDNA BE LIKE WHAT HAPPENS IF YOU TRANSFER ZERO TOKENS FROM ZERO ADDRESS TO ZERO ADDRESS WITH ZERO APPROVAL AS ZERO ADDRESS AND TOKEN IS THE ZERO ADDRESS

FUZZING ENGINEER AT
Joined November 2022
Don't wanna be here? Send us removal request.
@forkforkdog
FORKFORK DOG
9 hours
Absolute chad and super helpful guy who carries the lion's share of fuzzing tooling development on his shoulders.Emilio the Echidna King follow with haste @0x310f1sh.
0
0
3
@forkforkdog
FORKFORK DOG
9 hours
@Montyly Actually this is Emilio, follow him with haste @0x310f1sh.
0
0
0
@forkforkdog
FORKFORK DOG
17 hours
Pro tip: For being on the frontier thou must assemble the circle of wise men such as @Montyly and @emilio4995 around a perimeter table, and decree how ye shall circumvent the law of fuzzing this time.
2
0
1
@forkforkdog
FORKFORK DOG
18 hours
🐝.
@KrisRenzo
Kris RenZo
18 hours
I’ll always favor contests over private reviews for obvious reasons. But there are certain firms that you can't deny go the extra mile just from reading their reports. Three that come to mind now. @GuardianAudits .@bailsecurity .Trust Sec.
0
0
2
@forkforkdog
FORKFORK DOG
1 day
0
1
0
@forkforkdog
FORKFORK DOG
2 days
FUzz it.
0
1
3
@forkforkdog
FORKFORK DOG
4 days
9/10 That why we are doing fuzzing setup at Guardian for every single engagement. When we do fuzzing, we are building that lifecycle machine and running it as long as possible to protect the protocol.
0
0
4
@forkforkdog
FORKFORK DOG
4 days
8/10 Or with the goal to block it. Or drain it. An infinite evil machine. No restrictions, no rules, no bias, only the goal. Here where most unexpected, most 0.0001% vulnerabilities appears. From that unbiased fuzzing bot.
1
0
2
@forkforkdog
FORKFORK DOG
4 days
7/10 Now fuzzing. Full stateful fuzzing is not a randomized calldata thrown into your function. It's a bot, that lives on pretty powerful machine, which has infinite time to interact with your protocol in unrestricted ways, looking to get as much money as possible out of it.
1
0
3
@forkforkdog
FORKFORK DOG
4 days
6/10 Average auditing companies ate up all medium-high complexity vulnerabilities market, that type of audit you can get anywhere.
1
0
2
@forkforkdog
FORKFORK DOG
4 days
5/10 On the other side there are ultra-sophisticated one-of-a-kind state-of-the-art hacks, where protocol hacked went 4 steps audit and 0.001% of SRs can actually see this marginal case, if and only if they really care.
1
0
2
@forkforkdog
FORKFORK DOG
4 days
4/10 Look at the hacks happening. There are either ultra-dumb, like, latest hack return true; left in the beginning of the function, or something like require(msg.sender != owner, "Only owner can update"); type of human errors.
1
0
2
@forkforkdog
FORKFORK DOG
4 days
3/10 This all just to find something experienced auditors already uncovered? No way fuzzing is any good for you, right? Let's see.
1
0
2
@forkforkdog
FORKFORK DOG
4 days
2/10 local deployment, local deployment of integrated protocols (10s of k sloc sometimes!), make handlers, make a correct state capture, think invariants, then debug it etc etc.
1
0
2
@forkforkdog
FORKFORK DOG
4 days
1/10 Is fuzzing a worst EVM auditing tool? .The most common myth about fuzzing is that it just one of the ways to find vulnerabilities. If so, it would be the worst way to do it. Instead of going through the code from day one applying your high exp, you should do the setup, then
Tweet media one
1
0
11
@forkforkdog
FORKFORK DOG
4 days
RT @0xOwenThurm: Guardian is where the best SRs in the world go to become the best SRs in the universe.
0
1
0
@forkforkdog
FORKFORK DOG
5 days
Share a piece of your web3 sec lore
Tweet media one
0
0
5
@forkforkdog
FORKFORK DOG
5 days
CTO, but for a token
Tweet media one
@0xcuriousapple
curiousapple
5 days
Maybe each crypto protocol should have chief token officer. You are not actually responsible for chart going down with boat per say,.You are just responsible to make sure that if product is good, token structures are not responsible for its underperformance. Since just good.
0
0
5
@forkforkdog
FORKFORK DOG
8 days
Been waiting for it years and years.
@sepyke
pyk
9 days
HOLY MOLY, lets try it bros
Tweet media one
0
0
4
@forkforkdog
FORKFORK DOG
8 days
RT @0xOwenThurm: $200,000 total up for grabs now, show us a Crit 🫡.
0
2
0