
phil
@philbugcatcher
Followers
2K
Following
6K
Media
26
Statuses
682
Security Researcher, Resident, and Judge @cantinaxyz
Joined December 2022
🏅 4/735, and my largest payout so far. Hella ride. I looked at everything in the code, but looking != seeing. Once again, the gem is in the missed findings. Smol 🧵👇
38
12
385
RT @tpiliposian: Hey chat, we’re hiring Formal Verification Engineers at Certora. I’ve noticed many security researchers in the space alre….
0
11
0
RT @Votre_Inc: Our code has passed rigorous audits (proof): – Written + audited by our skilled team: ex‑OpenZeppel….
0
1
0
This is one of the codebases that I have reviewed the most times. Go see if you can find anything that I missed!.
A new testbed is open: @Votre_Inc has launched a new bug bounty with rewards up to $100,000. 🪐. Votre brings liquidation free loans to crypto’s top borrowers with high LTV, low rates, and tax efficient design. Their contracts and frontend are now open for review.
0
0
38
Auditing complex codebases feels like trying to comprehend an unknown creature while blindfolded. It's challenging, but not impossible. 99% of success comes from believing you *can* make sense of it, and refusing to give up until you do.
I like the shift that happens a couple of days into a complex codebase. You start out overwhelmed, having no clue how everything fits together. Towers of abstraction everywhere. Continuous confusion. Then suddenly it clicks and you're actually seeing how everything fits.
3
7
101
> If I could give one advice, if you're young, join a winning team. Nothing teaches you more about winning than studying how winning teams win. You'll never be able to guess why from the outside.
Working inside Solidity taught me something counterintuitive about building successful products. Solidity has around 90% market share for smart contracts, effectively a monopoly. This puzzles people. How did a language modeled after JavaScript, often considered "inferior" to.
1
3
57
RT @_hrkrshnn: This is how you win. Everyone new to crypto security should learn from Phil. He's an example of a security researcher who d….
0
2
0