ljj (@ljjeth) 's Twitter Profile
ljj

@ljjeth

Security Researcher @NethermindEth
making web3 secure
specialized in DeFi

ID: 1696290204330364931

linkhttp://github.com/utkuerkin calendar_today28-08-2023 22:34:41

64 Tweet

201 Followers

106 Following

ljj (@ljjeth) 's Twitter Profile Photo

Theft is theft and theft should not be rewarded. However, protocols must reply to whitehats honestly and rapidly and must avoid being greedy. Make whitehat hacking and bug reporting a more rewarding and hassle free experience so less hackers choose the blackhat route.

ljj (@ljjeth) 's Twitter Profile Photo

Lack of contests got platforms bored and fighting each other. At the end of the day, all the platforms lack certain things, none is perfect and they all can be better either through communicating with each other or giving valid criticism. Otherwise: 🍿

ljj (@ljjeth) 's Twitter Profile Photo

Good read overall even though some parts feel cherry picked. As someone that has been in the competitive auditing contests and private audits scene, the value private audits and contests provide are not 1:1 and their findings shouldn't be compared as such. In order to understand

tpiliposian (@tpiliposian) 's Twitter Profile Photo

hey SRs, be aware this guy is writing that they want a security audit then sending an NDA to sign and asking for a call to go over the details they send a Microsoft Teams link, but of course, not the official one, and you can't join the meeting from the browser so you need to

hey SRs, be aware

this guy is writing that they want a security audit
then sending an NDA to sign and asking for a call to go over the details

they send a Microsoft Teams link, but of course, not the official one, and you can't join the meeting from the browser
so you need to
Ethereum Foundation (@ethereumfndn) 's Twitter Profile Photo

0. Announcing the Trillion Dollar Security (1TS) initiative: an ecosystem-wide effort to upgrade Ethereum’s security to help bring the world onchain.

ljj (@ljjeth) 's Twitter Profile Photo

Need productive activities for my free time, does anyone have book recommendations to become better in one of these: -Maths, Cryptography, ZK -Coding/Auditing -Blockchain -Economy Or shall I start hunting on Immunefi finally?

ljj (@ljjeth) 's Twitter Profile Photo

I will never blame auditors on missing bugs as shit happens and everyone can miss bugs. But if bugs are being missed due to the design of the platform, the audit scopes are being hidden from the public and things are handled behind closed doors, it looks really bad. It feels

ljj (@ljjeth) 's Twitter Profile Photo

According to Coinbase, Cypherpunk is when you: Sponsor US Military Take no responsibility for getting private user data leaked Freeze peoples accounts whenever you feel like.

Ulaş Anıl (@_ulasanil) 's Twitter Profile Photo

Just got a confirmed bug on Immunefi immunefi.com/s/ss/?severity… BUT..It wasn't a smooth ride. Not at all. Constantly got ignored by Immunefi. Questions were left unanswered. Mediation was concluded with 0 explanation to me. Not a good start for me. Hope the next one will be better.

ljj (@ljjeth) 's Twitter Profile Photo

I wasted my time reading this nonsense. I'm only sharing it to spread awareness about this company that must be avoided.

Patrick Collins (@patrickalphac) 's Twitter Profile Photo

Hot takes that I think shouldn’t be hot, and should be “the default” 1. The contest platform is ultimately responsible for the payout. It is the contest platform that promises payout, so if a platform doesn’t pay out, no matter the drama, it is the platform’s fault. 2. The

ljj (@ljjeth) 's Twitter Profile Photo

"Funny how confidentiality never seems to prevent marketing materials from advertising security expertise, but suddenly kicks in when it's time to show the actual work." Preach transperancy, remove trust.

Nethermind Security (@nethermindsec) 's Twitter Profile Photo

Congratulations to Ulaş Anıl, one of our expert auditors, for earning a $150,000 bug bounty for a critical vulnerability report on Immunefi. Our team lives and breathes security. This kind of work happens behind the scenes every day through audits, deep research, and

WhiteHatMage (@whitehatmage) 's Twitter Profile Photo

Owen | Guardian Auditors and audit firms have it hard. The ONLY acceptable minimum output of any audit should be NO Criticals. The project’s life can go on with tens of Mediums unnoticed, and a bunch of Highs. It may be somehow painful, but solvable with upgradeable contracts, or cutting a