OtterSec
@osec_io
Followers
19K
Following
2K
Media
207
Statuses
1K
Audits that protect blockchain ideas.
Joined February 2022
Our community CTF is now live at @SolanaConf 🔥 Come by the Dev Cave on the mezzanine level, hosted by OtterSec, @anza_xyz, @asymmetric_re, @jump_firedancer, and @raikucom. Drop by to work, meet other builders, and grab some swag.
1
10
42
This structure gives projects a single direction across the full security stack while still working with the teams they trust. Full press release ↓ https://t.co/xUSCIEV3CX
globenewswire.com
NEW YORK, Dec. 08, 2025 (GLOBE NEWSWIRE) -- Asymmetric Research, a specialized security firm focused on long-term partnerships with L1s, L2s, and DeFi...
0
0
7
We’re excited to announce a shared leadership structure with @asymmetric_re! Teams today face risks that span audits, research, engineering, and incident response, and clear coordination is important.
5
9
69
NEW: ERC-4337 paymasters unlock powerful UX by abstracting gas costs, but they also add complexity and subtle bugs. We break down common pitfalls in real-world implementations and how to design production-ready paymasters. https://t.co/YLoWOdXq4T
osec.io
ERC-4337 paymasters unlock powerful UX by abstracting gas costs, but they also add complexity and subtle bugs. Explore some common pitfalls in real-world implementations and learn how to design...
0
6
37
At University Hospitals, discovery drives everything we do. From AI to genomics, our researchers are advancing innovation and patient care through collaboration and clinical excellence. Together, we’re shaping the science of tomorrow—today.
0
0
3
We have just completed our thorough audit of @jup_lend, and we are happy with @JupiterExchange and @0xFluid’s attention to detail and security!
BREAKING: The fourth independent audit of Jupiter Lend’s smart contracts has been successfully completed by @osec_io. • 4 audits completed • 1 additional audit in progress • Up next: open-sourcing the code followed by a @code4rena review We remain committed to improving
3
15
82
Our research team achieved client RCE on Minecraft Bedrock Edition via a heap overflow to bypass ASLR and sidestep CFG. Writeup to come.
61
287
3K
Cetus DLMM continues to evolve. 🌊 Since its beta launch, it has grown into a powerful product and essential tool for active LPs across the Sui ecosystem — especially shining during new asset launches with its dynamic liquidity design. 🐳 As we keep optimizing & maturing Cetus
34
30
178
Excited to work with the @SolanaFndn to help host the new security bounty program for Anchor.
We've launched a new security bounty program for Anchor, offering rewards of up to $100k for vulnerabilities that affect production code. If you think you’ve found an issue, we want to hear from you. Details on scope and eligibility below ↓
9
3
30
NEW: OAuth misconfigurations show how common dev settings can lead to account takeovers. Our second deep dive breaks down real cases where overlooking differences between desktop and mobile environments left SDKs, exchanges, and wallets open to exploits. https://t.co/QWABEOXcSU
osec.io
OAuth misconfigurations show how common dev settings can lead to account takeovers. Explore real cases where failing to account for differences between desktop and mobile environments left SDKs,...
2
17
72
Proud to work with @kamino and @y2kappa to formally verify critical invariants for Kamino Lend, pushing the boundaries of what secure DeFi looks like on Solana
1/ Excited to announce that Kamino Lend has been formally verified by @osec_io — bringing our total formal verifications to 4 This further establishes Kamino as the gold standard for safety and security in @solana DeFi Open source. 18x audits. 4x formal verifications.
1
0
12
Stablecoins are now at $200b, Wall Street is ready, and trillions are waiting to come onchain, but they’re SCARED. This is why the Immunefi Foundation (@immunefiFdn) just launched today. Visit the Foundation site below to watch the upcoming livestream announcement that will
Hello world. Please check out our website. https://t.co/oB3d2gzgM9
26
55
170
NEW: The recent supply-chain attack on NPM exposed a fundamental vulnerability in the open-source ecosystem and the risks that lurk within our dependencies. We break down how the malware worked and practical defenses every dev should know ↓ https://t.co/ZeqAkFR2jo
osec.io
The recent supply-chain attack on NPM showed how easily trusted dependencies can become delivery vectors for malware. Learn how the attack worked and practical defenses developers can implement to...
2
9
38
NEW: Proof of Reserves you can verify yourself. We teamed up with @Backpack to build PoRv2, a zero-knowledge system for fast, transparent solvency checks. More on how we designed it ↓ https://t.co/dfyVlrceRW
osec.io
Here, we explore zk-proofs, Merkle trees, and our new open-source implementation, PoRv2. Our proof-of-reserve enables users to verify exchange liabilities without relying on external auditors,...
23
26
142
NEW: What looks like a normal Solidity compilation ends in a crash. In our latest post, we trace the issue to a 12-year-old G++ bug and explain exactly how this can happen. Full breakdown + recommended fixes 👇 https://t.co/8XIC7uNnT0
osec.io
A subtle G++ bug from 2012, C++20's new comparison rules, and legacy Boost code can collide to crash Solidity's compiler on valid code. We unpack the surprising chain reaction and how to fix it.
3
15
80
@AptosLabs + @osec_io are bringing #Move challenges to the @AppSec_Village CTF at #DEFCON33. 🗓 Starts Aug 8, 10 AM 🔗
0
4
10
Happening tomorrow, Aug 8th. Catch @brunomodificato speak about off-chain exploitation in Web3.
We’re excited to announce that Bruno Halltari (@BrunoModificato) will be speaking at the Bug Bounty Village at DEF CON 33! Stay tuned for more details on their talk, you won’t want to miss it. #BugBounty #DEFCON #BBV #BugBountyVillage
1
1
10
Some personal news: I will be transitioning to lead special projects at @osec_io. Been with the team for >3 years now doing everything from ops to BD, and I'm very proud of the work we've been doing with teams across various ecosystems - and will keep on doing so. 🦦/acc
5
5
45
At Maverik, we take being Adventure’s First Stop seriously. We’ve got you covered for all your fuel, food and drink needs!
0
3
20
NEW: Building on Cosmos? We uncovered hidden bugs commonly overseen by developers, backed by real-world examples. Our latest blog explores these vulnerabilities and how you can address them. Read the breakdown 👇 https://t.co/AYTeE3lbYr
osec.io
From infinite loops and map determinism to AnteHandler missteps and storage key collisions, we highlight real-world vulnerabilities and actionable advice for building safer Cosmos-based projects.
0
17
57