Manuel Profile
Manuel

@xmxanuel

Followers
535
Following
973
Media
10
Statuses
175

security researcher, LSR @spearbit | prev. @radicle @centrifuge

Berlin, Germany
Joined March 2012
Don't wanna be here? Send us removal request.
@xmxanuel
Manuel
1 year
I am now an LSR (lead security researcher) at @SpearbitDAO. Thrilled and honored.
10
1
135
@xmxanuel
Manuel
8 months
kudos to @cantinaxyz for evolving into the perfect partner to launch the record-breaking @Uniswap v4 bug bounty.
@cantinaxyz
Cantina 🪐
8 months
The biggest bug bounty in history is now live. @Uniswap just raised the standard of building in public 🪐. With $15.5M on the line, it's an unprecedented testament to the rigorous security of v4. Think you can find a critical bug? Give it a shot. 🔗 Bounty link below
0
0
11
@xmxanuel
Manuel
1 year
It was really interesting to take a deep dive into the @safe contracts and @Optimism. Thanks for the opportunity.
@cantinaxyz
Cantina 🪐
1 year
What better way to start the week than with another batch of competition results! The @optimism Safe Extensions results are here 🪐. Here are your top 3 ranked researchers:.🥇 @zdravkohristov0: $9,549.86.🥈 @0xSimao: $7,510.19.🥉 @xmxanuel: $6,710.48. Full leaderboard below:
Tweet media one
0
2
23
@xmxanuel
Manuel
2 years
Are you using GPT-4 for coding?. Add a custom instruction to always include the code snippet first.
Tweet media one
0
1
9
@xmxanuel
Manuel
2 years
👀.
@GalloDaSballo
Alex the Entreprenerd
2 years
0
1
3
@xmxanuel
Manuel
2 years
@LeonSixt @joranhonig also created an awesome list about the topic.
@joranhonig
Joran Honig
2 years
I'm diving a bit deeper into AI + smart contract security. First Project:. DM me if you know some cool links I should add!.
0
0
2
@xmxanuel
Manuel
2 years
We need a database of bugs and a common evaluation to measure the progress of AI to find vulnerabilities in Solidity/EVM bytecode. @LeonSixt and I started with building a dataset. DM me if you are interested in collaborating.
1
0
1
@xmxanuel
Manuel
2 years
Can this be improved? How good are models like GPT-4 if you build a prompt pipeline? Which shoots thousands of prompts against a few hundred lines of code. Then try to build a scoring system and present the top bug candidates out of the sea of false positives.
1
0
0
@xmxanuel
Manuel
2 years
Trail of Bits also wrote a nice blog post about their experiments:.
1
0
0
@xmxanuel
Manuel
2 years
Early research has shown that LLMs can detect vulnerability types in DeFi smart contracts with a success rate of 40%, but they also have a high false positive rate. @HatforceSec.
1
0
1
@xmxanuel
Manuel
2 years
Sure. I might have pointed GPT-4 a bit into the right direction or the model got an upgrade. GPT-4 also generates a lot of noise and wrong answers but nevertheless, it can find and explain vulnerabilities.
1
0
0
@xmxanuel
Manuel
2 years
Asking GPT-4 to think step-by-step and to reason about input validation and require statements can find the bug.😽.
@zellic_io
Zellic
2 years
Can ChatGPT audit smart contracts?. Surprise: The answer is "No". Here's why:👇🧵
Tweet media one
1
1
4
@xmxanuel
Manuel
3 years
Sehr guter Thread. Kann ich auch aus eigenen Erfahrungen mit internationalen Kollegen in Berlin bestätigen.
0
0
2
@xmxanuel
Manuel
3 years
RT @joranhonig: Smart contract security is not just about Solidity. It's math, economics, game theory, distributed systems, computer scien….
0
74
0
@xmxanuel
Manuel
3 years
RT @carlbildt: It’s difficult not to be moved by this. A still sunny days outside the opera in Odessa.
0
2K
0
@xmxanuel
Manuel
3 years
RT @jimmy_wales: What's wrong with twitter in a single screenshot.
0
359
0
@xmxanuel
Manuel
4 years
Try it out and play around with it. 5/.
0
0
1
@xmxanuel
Manuel
4 years
Our focus is not entirely on open source projects. We try to build basic building blocks for streaming, membership and redistribution of funds 💦 4/.
1
0
1
@xmxanuel
Manuel
4 years
If your project found a way to make enough money, you should start sharing profits with your dependencies, which made that possible. Our vision is to establish a new cultural norm of giving. 3/.
1
0
1
@xmxanuel
Manuel
4 years
Imagine, you can add a file next to your README with a list of projects to distribute a share of your incoming funds. Together, with tools which can help to analyse your project dependencies. 2/.
1
0
1