Jeff Security
@jeffsecurity
Independent Smart Contract Researcher & Researcher at @ShieldifySec My mission is to find vulnerabilities in smart contracts for a safer Web3 Space!
My May/July/June 2023 update from private audits: - $48900 earned - 10 high, 14 Medium, 26 Low, 50+ Info severity vulnerabilities found - 7 solo smart contract security audits done for clients
Great discussion with DevDacian covering his approach to auditing and the business of security: m.youtube.com/watch?v=AiNneU…
ERC4337 Audit Checklist !!! - Wallet Account Factory - Wallet Account - Paymaster - Bundler - Signature Validator github.com/aviggiano/secu…
We've completed our second audit for @multiplifi — this time focusing on their RC-4626 Vault module. Always a pleasure to collaborate 🤝 Read the report below👇 github.com/shieldify-secu…
@cal_nix 's approach to explaining Circom makes it look much less intimidating that it actually is 😄 !! All his notes are a great read for zk-focused security researchers! calnix.gitbook.io/zk-notes/circo…
You can call `eth_getLogs` only so much times :D. Subgarphs are among the most solid ways to index on-chain data and this video walks us through: - what are subgraphs - how to deploy them youtube.com/watch?v=7zfTXG…
Reproduce ZKP vulnerabilities. This repo includes 89 vulnerabilities in the following DSLs: I’d appreciate a retweet, spread the knowledge 🫡 github.com/zksecurity/zkb…
The Move Book 📕🚀 A comprehensive guide to the Move programming language and the Sui blockchain. move-book.com
Technical article on Solidity metadata and how to decode it: jmcph4.dev/posts/decoding…
Amazing List of zkVMs & its research papers! 🫢 github.com/rkdud007/aweso…
Recipe for a supply chain attack: - pick a tool targeted at web3 devs and open a PR - add two lines of code reversinglabs.com/blog/malicious…
A threat simulation platform from The Red Guild designed to help crypto users identify and defend against social engineering, phishing, scams, and other notorious threats in the crypto ecosystem. phishingdojo.com
An attack vector hidden in plain sight ❗ Here is how the CPIMP threat was identified and stopped from stealing more than 10 million USD across various protocols. dedaub.com/blog/the-cpimp…
Just published a new Solidity security audit report — this time for @GluexProtocol 🤝 Quick 2-day review — still uncovered valuable issues. Even short reviews can be worth it with the right team🫡 Read the report below👇 github.com/shieldify-secu…
Primers for Specialist AI Smart Contract Auditors: github.com/devdacian/ai-a…