Marco Croc Profile
Marco Croc

@malicator

Followers
552
Following
42
Media
3
Statuses
101
Explore trending content on Musk Viewer
@malicator
Marco Croc
24 days
🐞I reported a vulnerability in @CurveFinance and I am thrilled to share that I've been awarded a bug bounty of $250,000. 🧵
41
68
1K
@malicator
Marco Croc
24 days
3️⃣ After thorough evaluation, the @CurveFinance team recognized the severity of the vulnerability and awarded me the maximum bug bounty of $250,000! Their professionalism and generosity were truly commendable.
1
0
81
@malicator
Marco Croc
24 days
5️⃣ To shed light on this fascinating journey, I've written an in-depth article that dives into the nitty-gritty details of the vulnerability. Don't miss it!
3
4
72
@malicator
Marco Croc
24 days
4️⃣ I want to express my sincere gratitude to the amazing team at @CurveFinance , especially @newmichwill , for their prompt response and collaborative approach throughout the process. It was a pleasure to work with them.
1
0
48
@malicator
Marco Croc
24 days
6️⃣ I'm a lead security researcher at @KupiaSecurity . Follow me for more updates on my cybersecurity explorations and future bug bounty endeavors.
1
0
46
@malicator
Marco Croc
24 days
1️⃣ The vulnerability could cause an inconsistency between the actual balance and the balance state variable by calling the withdraw_admin_fees inside the fallback of remove_liquidity_imbalance. (reentrancy)
1
0
39
@malicator
Marco Croc
24 days
2️⃣ I submitted a report with a written PoC and they swiftly acknowledged my findings. I engaged in a fruitful exchange of emails, discussing the potential impact and possible mitigations directly with @newmichwill .
1
0
33
@malicator
Marco Croc
23 days
@0xMackenzieM @CurveFinance Studied Curve some time ago and this time, filtering Avalanche projects on ImmuneFi lead me back to Curve. Because it was a fork of Curve 😉
1
1
10
@malicator
Marco Croc
24 days
@usmannk @CurveFinance Checking reentrancy using "claim_admin_fees" is a common practice as recommended by @chain_security "withdraw_admin_fees" does the same but in this case, it didn't have a reentrancy lock. There are many types of Curve pools, some use claim, some use withdraw.
1
0
2
@malicator
Marco Croc
23 days
0
0
2
@malicator
Marco Croc
5 months
@windhustler Wonderful! a Q, in Layer Zero token bridge, is it possible to get the sender address from destination tx only?
1
0
1
@malicator
Marco Croc
5 months
@DebbieTungArt can you please share colored version?
0
0
0
@malicator
Marco Croc
4 months
@auditsbydanny the top guy learnt rust 3 days before the contest?
1
0
1
@malicator
Marco Croc
5 months
@ProofOf_Podcast @bytes032 Cool Jumpman, Air Jordan
1
0
1
@malicator
Marco Croc
5 months
@nisedo_ @davidjmalan what event is this?
1
0
1
@malicator
Marco Croc
21 days
0
0
1
@malicator
Marco Croc
24 days
@usmannk @CurveFinance @chain_security Curve team has it internally as I saw they quickly applied emergency patches to all affected pools. Haven't found public DB though. I can browse various types of pools in Curve UI.
1
0
1
@malicator
Marco Croc
4 months
@Discovery Why is it all mute?
0
0
1
@malicator
Marco Croc
4 months
@dev_chinmayf I like the way book is zipped
0
0
1
@malicator
Marco Croc
5 months
@nisedo_ @zachobront you are funny, i don't like you 😀😀😀
0
0
1
@malicator
Marco Croc
4 months
@TeraboxE white lie?
0
0
0
@malicator
Marco Croc
5 months
@nisedo_ Write up or Protocol name, please
1
0
1