osec_io Profile Banner
OtterSec Profile
OtterSec

@osec_io

Followers
19K
Following
2K
Media
207
Statuses
1K

Audits that protect blockchain ideas.

Joined February 2022
Don't wanna be here? Send us removal request.
@osec_io
OtterSec
14 hours
Our community CTF is now live at @SolanaConf 🔥 Come by the Dev Cave on the mezzanine level, hosted by OtterSec, @anza_xyz, @asymmetric_re, @jump_firedancer, and @raikucom. ​ Drop by to work, meet other builders, and grab some swag.
1
10
42
@osec_io
OtterSec
4 days
This structure gives projects a single direction across the full security stack while still working with the teams they trust. Full press release ↓ https://t.co/xUSCIEV3CX
globenewswire.com
NEW YORK, Dec. 08, 2025 (GLOBE NEWSWIRE) --  Asymmetric Research, a specialized security firm focused on long-term partnerships with L1s, L2s, and DeFi...
0
0
7
@osec_io
OtterSec
4 days
We’re excited to announce a shared leadership structure with @asymmetric_re! Teams today face risks that span audits, research, engineering, and incident response, and clear coordination is important.
5
9
69
@osec_io
OtterSec
10 days
NEW: ERC-4337 paymasters unlock powerful UX by abstracting gas costs, but they also add complexity and subtle bugs. We break down common pitfalls in real-world implementations and how to design production-ready paymasters. https://t.co/YLoWOdXq4T
Tweet card summary image
osec.io
ERC-4337 paymasters unlock powerful UX by abstracting gas costs, but they also add complexity and subtle bugs. Explore some common pitfalls in real-world implementations and learn how to design...
0
6
37
@UH_RE_Institute
UH Research & Education Institute
1 month
At University Hospitals, discovery drives everything we do. From AI to genomics, our researchers are advancing innovation and patient care through collaboration and clinical excellence. Together, we’re shaping the science of tomorrow—today.
0
0
3
@osec_io
OtterSec
14 days
We have just completed our thorough audit of @jup_lend, and we are happy with @JupiterExchange and @0xFluid’s attention to detail and security!
@jup_lend
Jupiter Lend
20 days
BREAKING: The fourth independent audit of Jupiter Lend’s smart contracts has been successfully completed by @osec_io. • 4 audits completed • 1 additional audit in progress • Up next: open-sourcing the code followed by a @code4rena review We remain committed to improving
3
15
82
@osec_io
OtterSec
1 month
Our research team achieved client RCE on Minecraft Bedrock Edition via a heap overflow to bypass ASLR and sidestep CFG. Writeup to come.
61
287
3K
@CetusProtocol
Cetus🐳
1 month
Cetus DLMM continues to evolve. 🌊 Since its beta launch, it has grown into a powerful product and essential tool for active LPs across the Sui ecosystem — especially shining during new asset launches with its dynamic liquidity design. 🐳 As we keep optimizing & maturing Cetus
34
30
178
@osec_io
OtterSec
2 months
Excited to work with the @SolanaFndn to help host the new security bounty program for Anchor.
@SolanaFndn
Solana Foundation
2 months
We've launched a new security bounty program for Anchor, offering rewards of up to $100k for vulnerabilities that affect production code. If you think you’ve found an issue, we want to hear from you. Details on scope and eligibility below ↓
9
3
30
@osec_io
OtterSec
2 months
NEW: OAuth misconfigurations show how common dev settings can lead to account takeovers. Our second deep dive breaks down real cases where overlooking differences between desktop and mobile environments left SDKs, exchanges, and wallets open to exploits. https://t.co/QWABEOXcSU
Tweet card summary image
osec.io
OAuth misconfigurations show how common dev settings can lead to account takeovers. Explore real cases where failing to account for differences between desktop and mobile environments left SDKs,...
2
17
72
@osec_io
OtterSec
2 months
Proud to work with @kamino and @y2kappa to formally verify critical invariants for Kamino Lend, pushing the boundaries of what secure DeFi looks like on Solana
@kamino
Kamino
2 months
1/ Excited to announce that Kamino Lend has been formally verified by @osec_io — bringing our total formal verifications to 4 This further establishes Kamino as the gold standard for safety and security in @solana DeFi Open source. 18x audits. 4x formal verifications.
1
0
12
@immunefi
Immunefi
3 months
Stablecoins are now at $200b, Wall Street is ready, and trillions are waiting to come onchain, but they’re SCARED. This is why the Immunefi Foundation (@immunefiFdn) just launched today. Visit the Foundation site below to watch the upcoming livestream announcement that will
@ImmunefiFdn
Immunefi Foundation
3 months
Hello world. Please check out our website. https://t.co/oB3d2gzgM9
26
55
170
@osec_io
OtterSec
3 months
NEW: The recent supply-chain attack on NPM exposed a fundamental vulnerability in the open-source ecosystem and the risks that lurk within our dependencies. We break down how the malware worked and practical defenses every dev should know ↓ https://t.co/ZeqAkFR2jo
Tweet card summary image
osec.io
The recent supply-chain attack on NPM showed how easily trusted dependencies can become delivery vectors for malware. Learn how the attack worked and practical defenses developers can implement to...
2
9
38
@osec_io
OtterSec
4 months
NEW: Proof of Reserves you can verify yourself. We teamed up with @Backpack to build PoRv2, a zero-knowledge system for fast, transparent solvency checks. More on how we designed it ↓ https://t.co/dfyVlrceRW
Tweet card summary image
osec.io
Here, we explore zk-proofs, Merkle trees, and our new open-source implementation, PoRv2. Our proof-of-reserve enables users to verify exchange liabilities without relying on external auditors,...
23
26
142
@Backpack
Backpack 🎒
4 months
Starting today, Backpack will begin publishing its Proof of Reserves once a day, every day. Built and verified by @osec_io.
169
144
811
@osec_io
OtterSec
4 months
NEW: What looks like a normal Solidity compilation ends in a crash. In our latest post, we trace the issue to a 12-year-old G++ bug and explain exactly how this can happen. Full breakdown + recommended fixes 👇 https://t.co/8XIC7uNnT0
Tweet card summary image
osec.io
A subtle G++ bug from 2012, C++20's new comparison rules, and legacy Boost code can collide to crash Solidity's compiler on valid code. We unpack the surprising chain reaction and how to fix it.
3
15
80
@zi0Black
zi0Black
4 months
@AptosLabs + @osec_io are bringing #Move challenges to the @AppSec_Village CTF at #DEFCON33. 🗓 Starts Aug 8, 10 AM 🔗
0
4
10
@osec_io
OtterSec
4 months
Happening tomorrow, Aug 8th. Catch @brunomodificato speak about off-chain exploitation in Web3.
@BugBountyDEFCON
Bug Bounty Village
6 months
We’re excited to announce that Bruno Halltari (@BrunoModificato) will be speaking at the Bug Bounty Village at DEF CON 33! Stay tuned for more details on their talk, you won’t want to miss it. #BugBounty #DEFCON #BBV #BugBountyVillage
1
1
10
@0xRayDar
Daryl (blind optimism arc)
6 months
Some personal news: I will be transitioning to lead special projects at @osec_io. Been with the team for >3 years now doing everything from ops to BD, and I'm very proud of the work we've been doing with teams across various ecosystems - and will keep on doing so. 🦦/acc
5
5
45
@Maverik
Maverik, Inc.
29 days
At Maverik, we take being Adventure’s First Stop seriously. We’ve got you covered for all your fuel, food and drink needs!
0
3
20
@osec_io
OtterSec
6 months
NEW: Building on Cosmos? We uncovered hidden bugs commonly overseen by developers, backed by real-world examples. Our latest blog explores these vulnerabilities and how you can address them. Read the breakdown 👇 https://t.co/AYTeE3lbYr
Tweet card summary image
osec.io
From infinite loops and map determinism to AnteHandler missteps and storage key collisions, we highlight real-world vulnerabilities and actionable advice for building safer Cosmos-based projects.
0
17
57