CharlesWang (@0xcharleswang) 's Twitter Profile
CharlesWang

@0xcharleswang

Securing web3 since 2020 | Over 300 audits conducted | Trusted by the largest protocols | Outperforming all competitors | Lead Auditor @bailsecurity

ID: 1376152818004951041

linkhttp://bailsec.io calendar_today28-03-2021 12:43:01

6,6K Tweet

16,16K Followers

942 Following

CharlesWang (@0xcharleswang) 's Twitter Profile Photo

The best way to find all bugs in a codebase is to simply make notes for every little detail which seems to smell just not right. Then once you got full understanding, revisit these notes and validate the details.

CharlesWang (@0xcharleswang) 's Twitter Profile Photo

As the ecosystem matures, so does its competition. Each new protocol iteration must differentiate itself, through novel mechanics, optimization algorithms, or intricate incentive models, to attract capital and sustain community engagement. Projects that do not follow this,

Bailsec (@bailsecurity) 's Twitter Profile Photo

Our audit report for Parallel Protocol is ready! BailSec was tasked with an audit of the V3 Core. Thank you for your continued trust in BailSec. Link to the report on Github👇: github.com/bailsec/BailSe…

Our audit report for <a href="/ParallelMoney/">Parallel Protocol</a> is ready!    

BailSec was tasked with an audit of the V3 Core.

Thank you for your continued trust in BailSec.    

Link to the report on Github👇:
github.com/bailsec/BailSe…
CharlesWang (@0xcharleswang) 's Twitter Profile Photo

Here’s a true hack to find unique issues: Whenever you audit a math-heavy function, you are already aware that roundings often result in edge cases. That means, you may be able to find a good issue by checking rounding cases. Now comes the trick: The next step is to combine

CharlesWang (@0xcharleswang) 's Twitter Profile Photo

Do we have a security crisis due to today’s Balancer exploit? Is the defi space considered as completely high risk now? In my opinion, this is not true and I collected some facts and thoughts. This appears to be a very sophisticated exploit, not a trivial oversight. We don’t

Do we have a security crisis due to today’s Balancer exploit? Is the defi space considered as completely high risk now? 

In my opinion, this is not true and I collected some facts and thoughts.

This appears to be a very sophisticated exploit, not a trivial oversight. We don’t
CharlesWang (@0xcharleswang) 's Twitter Profile Photo

Giving you a very simple example so you can see what has changed in code quality. Back then: - Goal was to find the general lack of replay protection Nowadays: - Replay protection is existing but there could be an edge-case to bypass it

CharlesWang (@0xcharleswang) 's Twitter Profile Photo

Give it at most 1 year and then the best auditors will be these that are the most creative/intuitive in combination with LLMs.

Balancer (@balancer) 's Twitter Profile Photo

In connection with the recent Balancer V2 stable-pool incident, a new value-extraction path was identified in V2 meta-stable pools. In coordination with Certora and Security Alliance , Balancer team initiated a whitehat recovery around 7PM UTC and has secured ~$4.1M to controlled