Zero Cipher Profile
Zero Cipher

@zerocipher002

Followers
1K
Following
220
Media
13
Statuses
173

Senior Blockchain Security Researcher. Move/EVM/Rust. #15 All time Cantina Leaderboard. Founder @VulsightSec

Joined December 2014
Don't wanna be here? Send us removal request.
@zerocipher002
Zero Cipher
2 months
Here is the bug writeup of my 50,000 USDC bounty on @cantinaxyz This is supposed to be one of my many articles on BBP. If this original article post gets 100 reposts, I will publish a step-by-step playbook for SRs transitioning from audit contests to BBPs and how to succeed in
5
48
278
@zerocipher002
Zero Cipher
10 hours
How to save your Web3 Sec Career from AI? Its quite simple. Learn and gain expertise in niche skills in demand. The more niche a web3 Sec skill is, the worse the training data exists for it in AI. For example, I was writing an Article on the Move Language recently. Most of the
6
5
59
@zerocipher002
Zero Cipher
6 days
People at DevConnect had been asking me how I was able to secure 103% of the H/M pot (65,000 USDC) in the USDaf Contest on Cantina which was a Liquity v2 Fork and how did I spot a vulnerability that every single person missed. There are a multitude of reasons for this. I can
19
9
314
@VulsightSec
VulSight
9 days
Our Lead Security Research @zerocipher002 gave a talk on Move Security in @summit_defi This talk focused around on building a solid audit mindset for Move Contracts. The speaker used their own real-world Move Security experience in discussing solid approaches related to Move
2
2
15
@zerocipher002
Zero Cipher
17 days
Top 3 Hardest things in life: 1. Trying to get a girlfriend. 2. Preventing the protocol from lowballing your critical finding. 3. Trying to buy and recharge a sim card as a tourist in Buenos Aires Argentina.
8
0
30
@zerocipher002
Zero Cipher
21 days
Will be Landing in Buenos Aires for @EFDevcon Devconnect / DSS in the next 2 days. I’ll be speaking about Move Security at @summit_defi from the angle of real world exploits. If you are building DeFi / CDPs / anything on Aptos or Sui and want a security brain to stress-test
1
0
19
@zerocipher002
Zero Cipher
25 days
How to know that you are ready for BBP for a person who typically competes on competitions: 1. You have secured 3 top 3s on competitions that are >60k USD. 2. You have found solo highs in competitions. 3. You chose relatively complex protocols for your competitions. 4. You have
3
2
63
@VulsightSec
VulSight
27 days
Our Lead Security Researcher would be speaking on Move Security in DSS. The VulSight team would be present at @EFDevcon Buenos Aires for the entire devconnect week. Feel free to connect with us.
@summit_defi
Defi Security Summit
27 days
Move was designed to prevent common smart contract bugs, yet real incidents show old risks returning in new forms. At DSS, @zerocipher002 from @VulsightSec shares attack patterns unique to Move and how EVM auditors can adapt their mindset for auditing Aptos and Sui securely.
0
2
19
@zerocipher002
Zero Cipher
29 days
Well attacks like balancer v2 solidify my such viewpoints even more.
@zerocipher002
Zero Cipher
2 months
Web3 Security has to evolve and be better. I would not be comfortable putting even a quarter of my life savings in a defi protocol after the stuff that I have seen in my Web3 Security career.
0
0
4
@zerocipher002
Zero Cipher
29 days
Today I announce the next step in my career. Reply "Plumbing" to enroll.
16
3
51
@zerocipher002
Zero Cipher
1 month
If your AI tool is so good that it can detect the balancer vulnerability, why didn't it detect it before the hack?
@aviggiano
Antonio Viggiano
1 month
If your audit firm is so great to publish a balancer postmortem why didn’t you prevent the hack
1
1
24
@zerocipher002
Zero Cipher
1 month
Thank you @monad and @SuiNetwork Lambo soon.
3
0
33
@zerocipher002
Zero Cipher
1 month
SUI blockchain launched in 2023. You didn't hear much about covid after 2023. Coincidence? I think not.
@KhanAbbas201
Abbas Khan ⟠
1 month
Move will cure cancer, move will cure covid, move will fix frontend bugs and hacks automatically, move will reverse hacks because of how secure it is. These are all claims made by @Rahatcodes and he's been begging me over the past few days to get someone on a panel to debate EVM
1
0
9
@zerocipher002
Zero Cipher
1 month
Here is a very simple Alfa that could 10x the earnings of any person struggling in Web3 Security Competitions: Before even auditing the code, understand the code so deeply such that you are able to implement it from scratch if needed. Resist any urge to analyze any part of the
5
4
69
@zerocipher002
Zero Cipher
1 month
If you as an SR would need to choose one particular tech to master for the maximum +EV from one of these which would it be and why? 1. ZK 2. Move 3. Rust for Solana 4. Infra
16
0
52
@zerocipher002
Zero Cipher
2 months
It was great meeting you. Definitely shared some very interesting ideas.
@0xnirlin
nirlin
2 months
Great day meeting @zerocipher002 IRL. Took too long to find out we live in same city.
2
0
11
@zerocipher002
Zero Cipher
2 months
More Alfa on Move. If the articles gets 40 reposts. I will do a Part 3 of this article.
1
2
17
@zerocipher002
Zero Cipher
2 months
Web3 Security has to evolve and be better. I would not be comfortable putting even a quarter of my life savings in a defi protocol after the stuff that I have seen in my Web3 Security career.
5
0
59
@zerocipher002
Zero Cipher
2 months
If you want to make good payouts in BBPs and Contests. Having good Security Research Skills is only 50% of the work. You most of the time need very good negotiating and arguing skills to get either prevent your bugs from getting invalidated or get them a reasonable payout.
2
1
16
@zerocipher002
Zero Cipher
2 months
Here is my personal Top 4 tips for anyone transitioning from Audit Contests to BBP. 1. Hunt mainly for criticals and highs. Mediums are not usually worth it in BBP. 2. Audit both the on-chain state of the smart contracts as well as the contracts in the GitHub repo. 3. Think of
12
8
150