@auditsbydanny Profile picture

danny

@auditsbydanny

@decentrabuidl | built 20+ projects on $TitanX | #BuildOnTitanX

Pinned

Web3 security stats for February: 1. Broke up with my girlfriend due to working too much. 2. Found a job as a SR at a firm. I think it's a win 💀


danny Reposted

Had the opportunity to audit @TitanLegends888's new MarketPlaceV2 contract alongside @auditsbydanny back in September. This updated contract builds on V1 by adding the ability to buy NFTs using ETH, integrating UniswapV3 for price quotes. Despite this small addition, we…


If you’re an auditor, please monitor your clients' deployments. Go the extra mile: check their deployment scripts, review the deployed contracts, and assist them post-deployment. This extra effort is truly valuable to a project. It might seem like a low ROI task, but it’s what…


The first private audit I ever did was on a Liquity V1 fork, and since then, Liquity has held a special place in my heart. I’m excited to see how V2 will perform. Check out this article I wrote on the interesting features V2 brings👇

Liquity V2 is here! Building on the success of V1, @LiquityProtocol V2 brings even more exciting features while staying true to decentralization and security. Ready to dive in? 👇 threesigma.xyz/blog/liquity-v2



I was today years old when I realized that if you have "testFailing" in the name of a Foundry test, it behaves as if you have vm.expectRevert(); and the test will actually fail if it doesn’t revert. Initially, I thought I was tripping, tried foundryup, and then I had the aha…


People hate on @sherlockdefi, but who else gives you free money nowadays?


Sometimes I just sit and tell myself that I can’t allow myself to do certain things that make me "happy" because I’m no smarter than you and the only thing left is to outwork you.


guys, guys, we have a new thing to tweet about, at least for the next 3 days

Introducing Real-Time Judging The final evolution of audit contest judging is here. "Polymarket meets Community Notes for Web3 Security" Get to mainnet 3x faster on average, only at Sherlock



Are there any decent security researchers that still do PPV solo audits?


Auditing company owners are so blessed. Such a company is 10x easier to manage than those providing development. Prove me wrong.


A few days ago, I saw a junior SR asking whether reentrancy bugs can still be found nowadays. The answer is yes—they are still present but in different forms. This exploit was caused by a read-only reentrancy combined with permissionless market deployment. I had some fun…

🚨 Our Exploit Deep-Dives series continues! 🚨 Learn how an attacker exploited a reentrancy bug to steal $27M in a massive breach from @Penpiexyz_io Curious for more? Dive into our 🧵 or check the full analysis on our blog 👇threesigma.xyz/blog/penpie-ex…



A rushed development process is just as bad as a rushed audit. While this isn’t a new thing, founders still prioritize fast releases to capitalize on hype. Unfortunately, this often leads to much worse outcomes. Either the process is delayed by numerous bugs found during the…


How many times have you seen deploy scripts included in the scope of an audit? And how many times was there a bug in them? I've actually found plenty of bugs there—especially when pools are deployed, liquidity is added, important parameters are set, or specific time-related…


I'm working on a Hyperliquid trading bot on the side, and this made me realize that almost no one provides security services beyond smart contracts. The bot takes custody of users' wallets, manages slippage, has a custom TWAP, handles token deployment, etc. Each of these topics…


Does this address look familiar to you? `0x1804c8AB1F12E6bbf3894d4083f33e07309d1f38` is Foundry's default fallback address for `msg.sender` when executing a script. There are circumstances where this address is used, but I've encountered it too many times not to highlight it in a…


if you are a protocol owner, why would you go for a bug bounty on C4, Sherlock, or Cantina when you have Immunefi?


i literally audit like that

Tweet Image 1

Dunno why I stayed in web2 that long

Tweet Image 1

I've never heard the fans on my MacBook scream so loud! The tools for Solidity (Wake) and its compilation are insaneeee

Tweet Image 1

United States Trends
Loading...

Something went wrong.


Something went wrong.