oot2k Profile
oot2k

@oot2k1

Followers
784
Following
2K
Media
52
Statuses
1K

Security researcher / bug hunter. Senior Security Researcher @sherlockdefi Building: @scauditstudio

ETH
Joined October 2022
Don't wanna be here? Send us removal request.
@oot2k1
oot2k
27 days
You can now browse bug bounties and vulnerabilities on your phone. When critical payout using only phone and manual review??? . Check it out.
@SCAuditStudio
SC Audit Studio
27 days
Our App works now on mobile!.Check the security score of any Web3 company today at:.
Tweet media one
0
0
9
@oot2k1
oot2k
13 hours
RT @SCAuditStudio: in just 1st half of 2025 more than $2.47 billion has been lost to hacks, rug pulls, scams surpassing all of 2024's total….
0
2
0
@oot2k1
oot2k
2 days
very late to the trend but I have 31 smart followers on kaito ai! .That's 4%!
Tweet media one
0
0
5
@oot2k1
oot2k
3 days
RT @oot2k1: I was recently targeted by a very sophisticated spear phishing attack. An @DraperDragon employees twitter account got compromi….
0
4
0
@oot2k1
oot2k
3 days
Please report the accounts. Tagging @zachxbt for exposure.
0
0
0
@oot2k1
oot2k
3 days
What can we learn from this?.- never trust, always verify.- attackers create alt accounts to not raise suspicion on real compromised accounts.- twitter or even telegram "symbols / verification" does not verify anything. If you are interested in security check out @SCAuditStudio.
1
0
1
@oot2k1
oot2k
3 days
To summarize:.@drapervc account is not compromised.@DraperDragon account is most likely not compromised."AiDiato" account is compromised."SilenceInOrbit" is a scam account."matthuang@draperdragon.capital" is not a real email."matthuang.dd@gmail.com" is not a real email.
1
0
1
@oot2k1
oot2k
3 days
After asking where they got my contact they mentioned @sherlockdefi, and send screenshots of dms to @jack__sanford . Why did I initially not suspect anything? The attacker mentioned they found my contact over a "platform". I recently applied to @OVioHQ, so the timing was.
1
0
0
@oot2k1
oot2k
3 days
After noticing this it was obvious that this is a scam. But I wanted to research a step further. So I created a tracking link that redirects to my companies pitch deck. This reveled that the attacker is based in Latvia (or uses a vpn) but the message times would fit the
Tweet media one
1
0
1
@oot2k1
oot2k
3 days
After some further investigation the domain draperdragon dot capital redirects to the real .com domain. But the dot captial domain is registered using Hostinger. This is not the same provider as the real dot com site.
Tweet media one
1
0
1
@oot2k1
oot2k
3 days
At some point I ask if they could verify if they are the real person. Of course they can, they send me an email with an real looking domain. But the email looks already very much like scam.
Tweet media one
1
0
1
@oot2k1
oot2k
3 days
The conversation continued as usual, they did not send any files or links, only to the real .website. But this was weird. Why would an VC that invested into coinbase waste there time with random messages and not just take a call?.
Tweet card summary image
draperdragon.com
Founded by Larry Li, Andy Tang, Bobby Chao, and Tim Draper in 2006, Draper Dragon is a cross-border venture fund that connects Silicon Valley and Asia.
1
0
1
@oot2k1
oot2k
3 days
After noticing this I engaged in the discussion. They quickly redirected me to a telegram account which does not belong to the real matt. The questions where not too far away from what an actual VC would say, but something seemed off.
Tweet media one
1
0
0
@oot2k1
oot2k
3 days
As you might think I first started to suspect something to be off, because why would someone contact me with an alt account. But after checking the followers the account seemed legit. The real matt huang ("AiDiato") is following the alt account, @DraperDragon is following.
1
0
0
@oot2k1
oot2k
3 days
Matt Huang is a partner at Draper Dragon. Based on one of his previous colleges, he does not work at the fund anymore, but not 100% sure about this. But who is "SilenceInOrbit" ? The twitter profile writes its an alt account of matt, suspicious?.
1
0
0
@oot2k1
oot2k
3 days
I was recently targeted by a very sophisticated spear phishing attack. An @DraperDragon employees twitter account got compromised, which then contacted me to invest in my company @SCAuditStudio .A thread on how you can avoid this:
Tweet media one
Tweet media two
5
4
27
@oot2k1
oot2k
5 days
The main reason btc has started to gain more attention in recent times is the increased financial censorship in developed countries (this is my opinion).
0
0
0
@oot2k1
oot2k
13 days
How much ram do I need for solidity development? .4 gb?.8gb?.32?.
9
0
14
@oot2k1
oot2k
18 days
ETH at 3.3k . are we back?.
0
0
4
@oot2k1
oot2k
19 days
RT @SCAuditStudio: Top AI auditing/security tools on the market rn:. - @octane_security .- @Olympix_ai .- @QuillAudits_AI .- . which one….
0
4
0
@oot2k1
oot2k
20 days
RT @SCAuditStudio: Unfortunately many great protocols suffered losses by security breaches recently:. - @GMX_IO V1: - $40M.- @ArcadiaFi….
0
1
0