peakbolt(@peak_bolt) 's Twitter Profileg
peakbolt

@peak_bolt

Web3 Security Researcher
| #2 on @code4rena 90-days leaderboard (in Dec 23)
| Hunting bugs at @PashovAuditGrp
| Bug bounty triage with @SapphireWeb3Sec

ID:1502989460601901057

linkhttps://code4rena.com/@peakbolt calendar_today13-03-2022 12:47:28

840 Tweets

1,6K Followers

375 Following

Code4rena(@code4rena) 's Twitter Profile Photo

Introducing Code4rena Pro League 🏆

⭐ All-star auditors
🔒 Custom security services
🥇 The best security talent including cmichel, samczsun, cccz, 0x52, winnie, obront.eth, and more!

Read more: code4rena.com/blog/introduci…

account_circle
peakbolt(@peak_bolt) 's Twitter Profile Photo

Excellent point by Sergei K | cergyk.eth. Also, We as SRs need to understand that audit firms and contest platforms complements each other in the same way. It's not a zero-sum game.

account_circle
0xDjango(@0xDjangoOnChain) 's Twitter Profile Photo

In November, I submitted a critical bug to Cronos (Cronos) which they downplayed and have since been kicked off Immunefi. Here's some info about the bug and an example of how projects can simply not pay a fair amount.

Report: gist.github.com/fatherGoose1/6…

tl;dr:
- It's a…

account_circle
peakbolt(@peak_bolt) 's Twitter Profile Photo

The one tool I cannot live without is Solidity Visual Developer by tintinweb. Definitely at least 2X my auditing speed with it. Thanks tintinweb !

account_circle
peakbolt(@peak_bolt) 's Twitter Profile Photo

Listen in to my recent talk on OpenSense ₿ , where I shared my personal insights on how I levelled up my auditing skills and improved my performance within a few months!

account_circle
weiss.eth(@0xWeisss) 's Twitter Profile Photo

I am giving away 1000$ of my own money to the top 3 solo findings that 'save our a*s' in Tapioca Foundation contest in SHERLOCK and Code4rena

I will rank the findings and the splits will go as follows:

- 500$
- 300$
- 200$

Additionally, the top performers from both…

account_circle
deadrosesxyz(@deadrosesxyz) 's Twitter Profile Photo

To every SR spreading FUD about contests not getting enough coverage next couple of weeks.

I invite every single one of you to prove your claim and catch solo highs.

If you can't do it, respectfully, shut up and stop spreading FUD.

To every SR spreading FUD about contests not getting enough coverage next couple of weeks. I invite every single one of you to prove your claim and catch solo highs. If you can't do it, respectfully, shut up and stop spreading FUD.
account_circle
peakbolt(@peak_bolt) 's Twitter Profile Photo

Thanks to Pashov Audit Group, which gives me opportunities to perform team audits on interesting projects with talented auditors and learn from them!

Here's an audit report we did recently.

account_circle
peakbolt(@peak_bolt) 's Twitter Profile Photo

What makes one more suited to be a bug bounty hunter than an auditor? And vice versa?

I'm inclined to believe there are some underlying factors that determines it even though both have overlapping skill sets.

account_circle
peakbolt(@peak_bolt) 's Twitter Profile Photo

Don't waste too much time hunting Medium bugs on Immunefi.

Project can easily downgrade it. I learnt that from my submission.

If the Med bug was not spotted after being live for some time, then it's likely a small edge case that has low likelihood of affecting users.

account_circle
Ledger(@Ledger) 's Twitter Profile Photo

🚨We have identified and removed a malicious version of the Ledger Connect Kit. 🚨

A genuine version is being pushed to replace the malicious file now. Do not interact with any dApps for the moment. We will keep you informed as the situation evolves.

Your Ledger device and…

account_circle
peakbolt(@peak_bolt) 's Twitter Profile Photo

Competition is getting fiercer and more will come as the barrier to entry into web3 security is fairly low compared to web2.

account_circle
peakbolt(@peak_bolt) 's Twitter Profile Photo

Realized that I found 5 solo Highs this year on Code4rena, just behind the top of 6 solo Highs. Glad to make an impact to prevent fund loss.

I don't recommend one to aim for that.. It's not the right strategy for competitive audits, I realized much later in the year😆

Realized that I found 5 solo Highs this year on @code4rena, just behind the top of 6 solo Highs. Glad to make an impact to prevent fund loss. I don't recommend one to aim for that.. It's not the right strategy for competitive audits, I realized much later in the year😆
account_circle