xy9301 Profile Banner
BradMoon Profile
BradMoon

@xy9301

Followers
462
Following
334
Media
18
Statuses
404

blockchain security researcher and auditor https://t.co/ZCMUUJRBHX https://t.co/KnKd84TZoE

Joined May 2014
Don't wanna be here? Send us removal request.
@xy9301
BradMoon
5 months
Excited to share that our paper "PropertyGPT: LLM-driven Formal Verification of Smart Contracts" received the Distinguished Paper Award🏆· at NDSS 2025! Honored to be a co-first author on this work. Paper: #NDSS2025.
1
1
8
@xy9301
BradMoon
1 day
@Aptos need some heart disease funding😆.
0
0
0
@xy9301
BradMoon
1 day
I'm currently reorganizing and introducing tree-sitter into the finite-monkey engine, and I've supplemented developers with a necessary package: tree-sitter-move in Python: The corresponding open-source repository is at I need to.
Tweet card summary image
github.com
Contribute to BradMoonUESTC/tree-sitter-move development by creating an account on GitHub.
4
0
15
@xy9301
BradMoon
6 days
I've been trying an alternative approach these past few days that probably no one has attempted before - using Claude code SDK to replace all vul scan engine context components.which would dramatically simplify project complexity while enabling comprehensive context exploration.
0
0
3
@xy9301
BradMoon
15 days
RT @ret2basic: I am starting a 100 days challenge, building my web3 security portfolio in public until my dream company @CertiK hires me.….
0
2
0
@xy9301
BradMoon
15 days
We all have a bright future.
@lonelysloth_sec
LonelySloth
16 days
AI will make everyone more productive. Devs will get more productive at deploying bugs. Auditors will get more productive at missing bugs.
1
0
4
@xy9301
BradMoon
16 days
RT @agfviggiano: my AI auditor can find bugs introduced by my AI dev
Tweet media one
0
2
0
@xy9301
BradMoon
19 days
Recently I've been wanting to completely refactor the context system in the engine to provide a perfect context component, but it seems fraught with difficulties: . 1. you need to consider the codebase, which puts demands on the assembly speed of codebaseQA RAG. For very large.
3
0
6
@xy9301
BradMoon
22 days
RT @ret2basic: @TaiChiWeb3Sec now has an official website! We offer Solidity, Move and Solana security reviews. Al….
Tweet card summary image
taichiaudit.com
Leading DeFi security audit group specializing in Solidity, Move, and Solana smart contract reviews.
0
7
0
@xy9301
BradMoon
22 days
wrote a summary article last night.
Tweet card summary image
medium.com
Introduction
0
1
16
@xy9301
BradMoon
23 days
We typically face needs with different probability scenarios: searching for unknown answers (vulnerability discovery), having a definitive answer but needing to find it (root cause analysis), and providing recommendations (audit hints or checklists). For different needs, the.
@xy9301
BradMoon
23 days
When you're designing an LLM-based automated workflow or trying to turn an LLM into a tool, you're typically doing prompt engineering or context engineering. But ultimately, what you're actually dealing with is probability, attention, and various uncertainties. Many people,.
0
0
6
@xy9301
BradMoon
23 days
When you're designing an LLM-based automated workflow or trying to turn an LLM into a tool, you're typically doing prompt engineering or context engineering. But ultimately, what you're actually dealing with is probability, attention, and various uncertainties. Many people,.
2
1
7
@xy9301
BradMoon
24 days
some cluster record:
Tweet media one
0
0
5
@xy9301
BradMoon
24 days
The functionality of the 3,970 vulnerabilities can be basically categorized into 13 types, with the top three scenarios having the most vulnerabilities being: Rewards & Incentives (502), Decentralized Lending (470), and Asset Management (461), accounting for 36% of the total.
1
0
6
@xy9301
BradMoon
24 days
collected 3,970 high-severity vulnerabilities from various public audit competitions and decomposed them into functionality (the scenarios where these vulnerabilities occur) and key concepts (the abstract causes behind these vulnerabilities). I performed UMAP-based clustering and.
2
0
10
@xy9301
BradMoon
26 days
Then, put everything into a folder and feed it to cursor. Turn on that agent mode to perform the root cause analysis.
0
0
0
@xy9301
BradMoon
26 days
Collect transaction traces and all contract source codes. For those without source code, use heimdall plus a LLM to decompile.
0
0
1
@xy9301
BradMoon
26 days
This little gadget is for automated root cause analysis based on cursor. If someone interested, can continue working on it.
Tweet card summary image
github.com
Contribute to BradMoonUESTC/TxAnalyzer development by creating an account on GitHub.
5
1
33
@xy9301
BradMoon
27 days
Tonight @ret2basic shared dacian's repository with me: This reminded me that perhaps fine-grained checklists are also the direction for the future. Some checklists can be used for overall scanning, some should be specifically used for invariant.
Tweet card summary image
github.com
Primers for Specialist AI Smart Contract Auditors. Contribute to devdacian/ai-auditor-primers development by creating an account on GitHub.
4
10
53
@xy9301
BradMoon
28 days
In the next 1-2 years, we will see AI Audit Tools proliferating rapidly. I have already observed many different methodologies and product forms:. 1. There are increasingly more competitions among various audit tools.2. AI is able to cover more and more scenarios.3. New features.
0
1
12