kuprum (@kuprumxyz) 's Twitter Profile
kuprum

@kuprumxyz

I am a security and formal methods researcher with expertise in security audits, protocol and architecture analysis, testing and verification. Get in touch!

ID: 1816825556987518976

calendar_today26-07-2024 13:20:14

42 Tweet

288 Takipçi

93 Takip Edilen

kuprum (@kuprumxyz) 's Twitter Profile Photo

A personal milestone: my first competitive audit not with a team, but by myself. Not bad, but deftly a space to grow. A personal goal: first place in a contest by end of year. A note to self: don't over-complicate PoCs. Thanks optimism.eth and Code4rena!

A personal milestone: my first competitive audit not with a team, but by myself. Not bad, but deftly a space to grow. A personal goal: first place in a contest by end of year. A note to self: don't over-complicate PoCs. Thanks <a href="/Optimism/">optimism.eth</a> and <a href="/code4rena/">Code4rena</a>!
kuprum (@kuprumxyz) 's Twitter Profile Photo

Unexpectedly got 5th in a contest from only 2 days participation with 3 findings.. But learnt a great lesson from the project dev on reentrancy (more on that later). Also great (and last) Sherlock's escalation discussions with the community and Wang Security. Go SHERLOCK!!!

Unexpectedly got 5th in a contest from only 2 days participation with 3 findings.. But learnt a great lesson from the project dev on reentrancy (more on that later). Also great (and last) Sherlock's escalation discussions with the community and <a href="/WangSecurity_/">Wang Security</a>. Go <a href="/sherlockdefi/">SHERLOCK</a>!!!
kuprum (@kuprumxyz) 's Twitter Profile Photo

What a day: C4 results arrived almost simultaneously with Sherlock's; this time I am 3rd! 😎A really great work from MrPotatoMagic in this contest👏 Thanks Code4rena and the sponsor, Phi! (a personal note: my future 1st place, I am coming x.com/kuprumxyz/stat…)

What a day: C4 results arrived almost simultaneously with Sherlock's; this time I am 3rd! 😎A really great work from <a href="/MrPotatoMagic/">MrPotatoMagic</a> in this contest👏 Thanks <a href="/code4rena/">Code4rena</a> and the sponsor, <a href="/phi_xyz/">Phi</a>! (a personal note: my future 1st place, I am coming x.com/kuprumxyz/stat…)
kuprum (@kuprumxyz) 's Twitter Profile Photo

I keep forgetting that Code4rena is Zellic now... I should remember that more firmly -- it has far-reaching consequences...

kuprum (@kuprumxyz) 's Twitter Profile Photo

A great retrospective into the address collision finding from MakerDAO contest at Sherlock github.com/sherlock-audit…; I've also dived a bit into this topic. Good self-analysis on how to "learn to learn", as well as on the escalation process. I am sure Sev will achieve a lot 🚀

kuprum (@kuprumxyz) 's Twitter Profile Photo

Extremely proud to share that I came 1st in Sherlock's Flayer audit contest! It was tough: lots of great researchers, lots of findings; only my solo High helped to achieve that ranking. Congrats to all fellow SRs who participated! My next personal goal: Senior Watson at Sherlock.

Extremely proud to share that I came 1st in Sherlock's Flayer audit contest! It was tough: lots of great researchers, lots of findings; only my solo High helped to achieve that ranking. Congrats to all fellow SRs who participated! My next personal goal: Senior Watson at Sherlock.
kuprum (@kuprumxyz) 's Twitter Profile Photo

What can be better than after you win a contest to receive from the LSW the comment in dm "congrats, deserved win!" Thanks zzykxx, it is a pleasure to compete, discuss, and chat with you on SHERLOCK

kuprum (@kuprumxyz) 's Twitter Profile Photo

I am 2nd at predict.fun lending market audit contest by SHERLOCK with a solo Medium🎉 Congrats to PUSH0 who nailed the other solo Med🔥 I almost got this one as well, but failed to dig the last mile to the true impact. Next time will dig deeper; lesson learned😁

I am 2nd at <a href="/predictdotfun/">predict.fun</a> lending market audit contest by <a href="/sherlockdefi/">SHERLOCK</a> with a solo Medium🎉 Congrats to <a href="/PUSH0audits/">PUSH0</a> who nailed the other solo Med🔥 I almost got this one as well, but failed to dig the last mile to the true impact. Next time will dig deeper; lesson learned😁
kuprum (@kuprumxyz) 's Twitter Profile Photo

Have you wondered how SHERLOCK leaderboard points are calculated? So did I... I thought I understand; then I realized I don't. So I've created this Sherlock points calculator: docs.google.com/spreadsheets/d… Feel free to copy, and use it to track your Sherlock performance; enjoy!

Have you wondered how <a href="/sherlockdefi/">SHERLOCK</a> leaderboard points are calculated? So did I... I thought I understand; then I realized I don't. So I've created this Sherlock points calculator: docs.google.com/spreadsheets/d… Feel free to copy, and use it to track your Sherlock performance; enjoy!
kuprum (@kuprumxyz) 's Twitter Profile Photo

Got a pretty good start at Cantina: 2 findings submitted, 2 accepted. 1 unique: this becomes a good tradition:) Congrats to everyone; Haxatron is a beast with his unique High! Thank you Cantina 🪐 and Omni Network; happy to help making Web3 a secure place.

Got a pretty good start at Cantina: 2 findings submitted, 2 accepted.  1 unique: this becomes a good tradition:) Congrats to everyone; <a href="/Haxatron1/">Haxatron</a> is a beast with his unique High! Thank you <a href="/cantinaxyz/">Cantina 🪐</a> and <a href="/OmniFDN/">Omni Network</a>; happy to help making Web3 a secure place.
kuprum (@kuprumxyz) 's Twitter Profile Photo

Just completed two collaborative audits with Sherlock - audits.sherlock.xyz/watson/kuprum: - IBC V2 implementation (codename IBC Eureka) - Lombard Finance LBTC solutions integration with IBC V2 I have thoroughly enjoyed working on these two engagements with SHERLOCK (the leading

kuprum (@kuprumxyz) 's Twitter Profile Photo

Here is the proof of the unique power of public audit contests: github.com/Layr-Labs/eige…. Context: - the fix PR for a High sev bug found by multiple SRs in EigenLayer's comp on Cantina 🪐; - the bug was missed by fuzzing, audits, and formal verification. Scroll for details.

Here is the proof of the unique power of public audit contests: github.com/Layr-Labs/eige…. Context:

- the fix PR for a High sev bug found by multiple SRs in <a href="/eigenlayer/">EigenLayer</a>'s  comp on <a href="/cantinaxyz/">Cantina 🪐</a>;
- the bug was missed by fuzzing, audits, and formal verification.

Scroll for details.
The Inter-Blockchain Communication Protocol (@ibcprotocol) 's Twitter Profile Photo

IBC Eureka is live — enabling fast, secure Ethereum ↔ Cosmos bridging. IBC Eureka offers fast, affordable, 1-click transactions between Ethereum and Cosmos chains. It's also the canonical usage of the v2 of @ibcprotocol. Key product info🧵

kuprum (@kuprumxyz) 's Twitter Profile Photo

A well-seasoned view on the real value of model checking as complementary to testing/fuzzing. I love this: > By all means, write tests. Please, do. Write many.