@HectorCuesta Profile picture

Hector Cuesta

@HectorCuesta

"As our circle of knowledge expands, so does the circumference of darkness surrounding it" Security at @MoonPay. Formerly at @Sensepost.

Joined May 2011
Similar User
Axel Souchet photo

@0vercl0k

KevinLu photo

@K3vinLuSec

Ole André V. Ravnås photo

@oleavr

Jesús 🍟 photo

@HackingPatatas

Uri Kolodny photo

@ukolodny

Markus Vervier photo

@marver

Idle DAO photo

@idlefinance

Sablier photo

@Sablier

Cesar Cerrudo photo

@cesarcer

Manuel Blanco photo

@dialluvioso_

nour photo

@NourHaridy

vf.at photo

@vfat0

Borja Martínez photo

@Qm9yamFN

Eduardo Arriols photo

@_Hykeos

maru.eth photo

@wasserpest

Hector Cuesta Reposted

Hacking GTA V RP Servers Using Web Exploitation Techniques by @blastbots nullpt.rs/hacking-gta-se…

Tweet Image 1

Hector Cuesta Reposted

Gameboy cold wallet demo: seed phrase is generated by talking to an NPC using a hash of your previous 500 button presses as you walk around and do quests.


Hector Cuesta Reposted

We are now sharing the technical write-up of the vulnerability in @bnbchain that @_fel1x (a security researcher at @jump_) discovered and responsibly disclosed earlier this week: jumpcrypto.com/helping-secure…


Hector Cuesta Reposted

Did you read all of the post-mortems of 2022? Well, I did it for you and tried to boil it down into a single article. Made for web3 auditors and bug hunters. No SEO/marketing bs, just one giant blogpost for you to review at your own pace. Merry christmas! ventral.digital/posts/2022/12/…


Hector Cuesta Reposted

Thread: How thousands of Slope wallets were hacked and how other wallets can avoid this 👇

Tweet Image 1

Hector Cuesta Reposted

In one of our recent engagements with a customer, we were asked to audit some code which depended on BokkyPooBah's DateTime library. The contract calculates the day of the month from block.timestamp, and it does this to ensure an operation happens only up to once a month.

Tweet Image 1

Hector Cuesta Reposted

A story about bad compilers, the sad state of ETH contracts RE tooling, and a potential vuln on @optimismPBC To be clear, they were never vulnerable. In short, anyone can submit L2 transactions from eth mainnet by calling enqueue() on the CanonicalTransactionChain contract. 1/?


Hector Cuesta Reposted

Want to learn how to hack smart contracts? We're excited to release our introduction to Solana (from an auditor's perspective)! osec.io/blog/tutorials…


Hector Cuesta Reposted

Are you a CodeQl/Joern user? I wrote a quick blog post where I compare the usability of these two tools and show some use cases. Check it out! elmanto.github.io/posts/sast_der…


Hector Cuesta Reposted

Last week, I discovered (and reported) a critical bug (which has been fully patched) in @optimismPBC (a "layer 2 scaling solution" for Ethereum) that would have allowed an attacker to print arbitrary quantity of tokens, for which I won a $2,000,042 bounty. saurik.com/optimism.html


Hector Cuesta Reposted

How did the @wormholecrypto exploit work? I joined forces with @gf_256 and @ret2jazzy to reverse engineer the exploit, and now that it's been patched we can finally share it with you👇

Tweet Image 1

Hector Cuesta Reposted

I've been playing around with Cairo, and came across a nice new foot-gun/ bug class. tl;dr Stay safe and use memory-safe functions such as update_dict()

Tweet Image 1

Hector Cuesta Reposted

Boom! We're thrilled to announce our $555M Series A, valuing us at $3.4B! 🦄💥 A 🧵 on the raise…


Hector Cuesta Reposted

Curious about exploiting #Microsoft #ActiveDirectory? @slazar0 & @xpirabit will teach you how to obtain a foothold, perform recon, escalate privs, achieve #Windows auth, target #Kerberos, and more! Register for this class at #CATCH2022ringzer0.training/active-directo…

Tweet Image 1

Hector Cuesta Reposted

What would you do if you found an 0day in @etherscan? I decided to build a pinball machine. paradigm.xyz/2021/11/hiding…


Hector Cuesta Reposted

Do you like mobile security and cryptos? My team at @MoonPayHQ is looking for Product Security Engineers with experience securing mobile applications to join us helping developers deliver secure products at scale! More info at boards.greenhouse.io/moonpay/jobs/4… RTs are welcome 🙏🏻


Hector Cuesta Reposted

Wrote some words on my recent experience with burnout. I was burnt out. Everyone else is too. We're about to have a moment. mayakaczorowski.com/blogs/burnout


Hector Cuesta Reposted

I published an article about remote code execution in cdnjs that could allow tampering of 12.7% of all websites on the internet. blog.ryotak.me/post/cdnjs-rem…


Loading...

Something went wrong.


Something went wrong.