giraffe (@giraffe0x) 's Twitter Profile
giraffe

@giraffe0x

Security Researcher @GuardianAudits |
Sharing about the EVM, Solidity and Security |

Ex-Air Force Pilot 🚁

ID: 496634018

linkhttps://github.com/giraffe0x/portfolio calendar_today19-02-2012 04:45:03

1,1K Tweet

1,1K Followers

2,2K Following

Jeffrey Scholz (@jeyffre) 's Twitter Profile Photo

300 likes and I’ll host a high-signal dev/auditor-focused event in Bali. Maybe we’ll have a week at a resort where I teach ZK. Maybe side-events only, no one event can cater to everyone. Since many of my Indonesian friends are restaurant/hotel owners, I can get the EOs insider

Guardian (@guardianaudits) 's Twitter Profile Photo

The new Permissionless Podcast by Guardian is here! Learn how top DeFi builders got their start, the design of their protocol, & (of course) how security plays a role. 🔒 Our first episode is a chat with YieldNest founder DeoBrands 🏰 listen below👇 youtube.com/watch?v=5l6-r3…

Guardian (@guardianaudits) 's Twitter Profile Photo

Want to learn how to audit like a Guardian? Part two of Owen | Guardian's advanced web3 security course has everything you need to sharpen your edge. Link below! 🍿

Want to learn how to audit like a Guardian?

Part two of <a href="/0xOwenThurm/">Owen | Guardian</a>'s advanced web3 security course has everything you need to sharpen your edge.

Link below! 🍿
giraffe (@giraffe0x) 's Twitter Profile Photo

Team audits can be incredibly rewarding. In a recent one with Osman Özdemir, I started with an innocent question about slippage. That led us down a few rabbit holes — and eventually to a subtle quirk in the Uni V3/V4 routers: it hardcodes sqrtPriceLimitX96

Team audits can be incredibly rewarding.

In a recent one with <a href="/osmanozdemir1/">Osman Özdemir</a>, I started with an innocent question about slippage. That led us down a few rabbit holes — and eventually to a subtle quirk in the Uni V3/V4 routers: it hardcodes sqrtPriceLimitX96
giraffe (@giraffe0x) 's Twitter Profile Photo

Did a c4 contest recently and was pleasantly surprised by the change to focus more on client outcomes instead of obscure findings (not gotcha-hunts 😂) This however places a greater responsibility on the judge to determine the threshold for 'value'

Did a c4 contest recently and was pleasantly surprised by the change to focus more on client outcomes instead of obscure findings (not gotcha-hunts 😂)

This however places a greater responsibility on the judge to determine the threshold for 'value'
Owen | Guardian (@0xowenthurm) 's Twitter Profile Photo

I couldn’t be prouder of the team behind this. It takes the best DeFi security minds in the world working around the clock to uphold the utmost confidence in everything we ship. Every day we’re giving everything we’ve got, it’s what DeFi deserves. 🫡

AmoW (@armormadeofwoe) 's Twitter Profile Photo

Almost 600 days ago, the very first First Flight on Cyfrin CodeHawks concluded. Decided to observe the top 100 participant out of curiosity to see who stuck around: - #29 MrPotatoMagic - Certora SR - #36 Elhaj 🇵🇸 - Spearbit ASR - #59 Tigran Piliposyan - Certora SR - #89 giraffe -

Tenderly (@tenderlyapp) 's Twitter Profile Photo

After the ByBit hack, clear signing is more important than ever. So we took steps to ensure you know what to expect when simulating txs on Safe.eth with Tenderly. You can now inspect domain, message, and Safe tx hashes as they appear on Ledger Nano. 🧵 blog.tenderly.co/changelog/comp…

Guardian (@guardianaudits) 's Twitter Profile Photo

Guardian is built around the best security researchers in the world— With $10B+ secured and top finishes in the most competitive audit contests in Web3. Here are just a few of their standout placements ⤵️

Guardian (@guardianaudits) 's Twitter Profile Photo

A new proxy attack is putting millions at risk. It hijacks contracts mid-deploy, resets initialize(), and silently routes users to malicious logic - while block explorers show everything as normal. Here’s how it works, and how to stop it 🧵

A new proxy attack is putting millions at risk.

It hijacks contracts mid-deploy, resets initialize(), and silently routes users to malicious logic - while block explorers show everything as normal.

Here’s how it works, and how to stop it 🧵
Guardian (@guardianaudits) 's Twitter Profile Photo

Today, auditors put their money where their mouth is. Announcing, Guardian Defender. → Post-audit bounty coverage, funded by Guardian. → 30-day contest to find critical bugs in the Guardian-secured codebase. The first $100,000 Defender contest with Ethena Labs is live!

giraffe (@giraffe0x) 's Twitter Profile Photo

WLFI’s USD1 token uses frozen() to expose blacklist status rather than the conventional isBlacklisted(). This deviation could break integrations that expect standard blacklist interfaces etherscan.io/token/0x8d0d00…

Owen | Guardian (@0xowenthurm) 's Twitter Profile Photo

Guardian is setting the Web3 security standard for a global economy day after day. I’m proud to share that we are looking for new decorated Lead Researchers to join the Guardian team. Total Comp is $250K-$400K+ There's a $20,000 referral bounty, DM me for details/intros!

Owen | Guardian (@0xowenthurm) 's Twitter Profile Photo

Guardian is creating the Web3 security standard for a new financial world. We're looking for an Account Executive to join us and cultivate lasting partnerships in DeFi and financial services. Total Comp is $120-200K+ There's a $10K referral bounty, DM me for details/intros!