Mathriel (@mathrielx) 's Twitter Profile
Mathriel

@mathrielx

Securing Web2 today, building Web3 trust tomorrow
On a mission to transition into blockchain & decentralized security

ID: 1334084541321981953

calendar_today02-12-2020 10:38:52

21 Tweet

11 Followers

307 Following

Mathriel (@mathrielx) 's Twitter Profile Photo

Today all of my leads got invalidated - most turned out to be related to protocol design assumptions rather than real exploitable issues. These leads didn’t hold up under deeper analysis, so I’m closing them and refocusing. Still moving forward - we continue! 0xSimao

Mathriel (@mathrielx) 's Twitter Profile Photo

Today I’m finishing the Contest. I didn’t manage to find a solid attack path that I can prove, and time felt a bit tight for me. Starting today, I’m taking on a new bug bounty approach suggested by WhiteHatMage - I’ll be diving deep into this process and seeing how it goes.

Mathriel (@mathrielx) 's Twitter Profile Photo

First day switching to bug hunting - I researched different types of protocols because a brutally good bug hunter once advised that it’s always good to pick something interesting to you so you don’t get bored. I’ve started compiling a list of promising targets, which I’ll finish

Mathriel (@mathrielx) 's Twitter Profile Photo

Picked an interesting protocol type the last two days and found a target to hunt bugs on - way more confusing than your typical “git clone the repo” contests style. All the forks & stuff made it a real challenge 😅 0xSimao

Mathriel (@mathrielx) 's Twitter Profile Photo

Spent the last couple of days deep-diving into past bounty write-ups and lessons from impactful bugs - starting to really get the program I’m hunting on. It’s super interesting looking for bugs that actually matter in real deployed systems - everything feels so different 0xSimao

Mathriel (@mathrielx) 's Twitter Profile Photo

Bug bounty feels a lot slower - there’s way more lines of code, flows and contracts to go through than contests. It’s a very interesting approach, but you have to dedicate much more time to see any results. Let’s see where this journey goes 0xSimao

Mathriel (@mathrielx) 's Twitter Profile Photo

Still reading through a lot of code and haven’t found a bug yet, but learning tons along the way. A few beginner tips that helped me: Focus on one type of flow at a time and study how it works and if there are any pitfalls Take notes and stay organized Read write-ups and reports

Mathriel (@mathrielx) 's Twitter Profile Photo

In the past couple of days I’ve been digging deeper into blockchain infrastructure. I can’t even begin to imagine how much there is to learn in this field, it’s unbelievable... and so interesting! 0xSimao

Mathriel (@mathrielx) 's Twitter Profile Photo

Decided to deep dive into one feature and take it slow - bug bounty really isn’t a sprint, it’s a marathon. It feels way different from Contests. Honestly? I’m enjoying this style more. The only downside is you never know if you’ll find something, but I’m trying to keep the

Mathriel (@mathrielx) 's Twitter Profile Photo

The workload outside of web3 has been crazy this past week - so much on my plate. Still grinding, staying consistent, and learning every single day. Next week we’re coming back with 100% power 💪. I truly believe in the topic I’ve committed to and the results will show soon 🤞

Valves Security (@valvessec) 's Twitter Profile Photo

🚨FREE AUDIT + GIVEAWAY🚨 If you're building a Solidity protocol and want to protect your protocol and the users that trust you, you're in the right place. We're exclusively opening 1 slot for a FREE audit. • Your protocol should be solidity-based • The codebase contains