Oualidpro (@oualidpro1) 's Twitter Profile
Oualidpro

@oualidpro1

Blockchain Security Pro šŸ›”ļø | Top 5 @Code4Rena Bot Racer šŸ | Discovering Smart Contract Secrets 🌐 | Let's Secure Crypto Together šŸš€ | DM for Insights šŸ“©

ID: 1127740350796390401

calendar_today13-05-2019 01:00:26

343 Tweet

64 Followers

323 Following

Oualidpro (@oualidpro1) 's Twitter Profile Photo

šŸ“Š Gas optimization is important but not at the cost of security. Efficient code should also be secure code. #SmartContractDevelopment #GasOptimization

Oualidpro (@oualidpro1) 's Twitter Profile Photo

šŸ‘„ Peer reviews in smart contract audits can provide invaluable insights. Different perspectives uncover different issues. #PeerReview #CollaborativeSecurity

dravee.eth (@bowtieddravee) 's Twitter Profile Photo

"Scenarios", "Flows", "State Transitions", "Stories", "Threats", "Paths", "Levers". The used word doesn't matter: our ultimate ambition should be to identify all weird/edge/unexpected cases in the time we have on a security review. These words are just helpful representations.

dravee.eth (@bowtieddravee) 's Twitter Profile Photo

Gotta recommend this extension again: marketplace.visualstudio.com/items?itemName… . With it, you can visually tell which line is fully covered, which line is partially covered, and which line isn't covered at all. Try `forge coverage --report lcov` and then use this extension to see what I mean

@bytes032.xyz (@bytes032) 's Twitter Profile Photo

USDC has 18 decimals instead of 6 on the following chains: - Oasys - BNB - OKX Chain - Sora - Kucoin Chain - Telos - Conflux - Bitgert

dravee.eth (@bowtieddravee) 's Twitter Profile Photo

Alpha alert: Speed boost I've been using this for years, and I know some others have their own ways with macros, but lots just copy-paste the tags. This is how I write the audit tags and other things (cmd + a number). Do Cmd+Shift+P, open keyboard shortcuts (JSON), and add those.

Alpha alert: Speed boost
I've been using this for years, and I know some others have their own ways with macros, but lots just copy-paste the tags.
This is how I write the audit tags and other things (cmd + a number).
Do Cmd+Shift+P, open keyboard shortcuts (JSON), and add those.
@bytes032.xyz (@bytes032) 's Twitter Profile Photo

"There's plenty for everyone." That’s my mantra for sharing everything that worked out for me so far. I didn’t just scale from $0 to +300K by gatekeeping knowledge. I honestly believe none of my success would be here if I hadn't shared my ups and downs. By putting myself in

pashov (@pashovkrum) 's Twitter Profile Photo

3 mandatory checklists to go through before doing a smart contract security audit on your codebase: 1. The Solcurity Standard - github.com/transmissions1… 2. Weird ERC20 tokens list - github.com/d-xo/weird-erc… 3. Solodit aggregated checklists - solodit.xyz/checklist

dravee.eth (@bowtieddravee) 's Twitter Profile Photo

Recommended Read 🧐 The following comprehensive article on "Exchange Rate Manipulation in ERC4626 Vaults" from Euler Labs co-authored with the legendary alcueca euler.finance/blog/exchange-…

Mr Anon (@shieldifyanon) 's Twitter Profile Photo

If you're auditing a protocol that uses Compound V3, you should read these papers! RareSkills 🫔 1. The Architecture of the Compound V3 Smart Contract Link: rareskills.io/post/compound-… 2. DeFi Interest Rate Indexes Link: rareskills.io/post/defi-inte… 3. Understanding Collateral,

dravee.eth (@bowtieddravee) 's Twitter Profile Photo

ddimitrov22 Even rounding in the right direction could be exploited (stealth donation). I very, very much encourage everyone to read this: euler.finance/blog/exchange-…

Oualidpro (@oualidpro1) 's Twitter Profile Photo

The chart on theblock website left me stunned. The surge in stolen funds between 2020 and 2023 is alarming, indicating a pressing need for heightened security measures. Employing both manual and automated scans could help mitigate the risks effectively. theblock.co/data/decentral…

The chart on theblock website left me stunned. The surge in stolen funds between 2020 and 2023 is alarming, indicating a pressing need for heightened security measures. Employing both manual and automated scans could help mitigate the risks effectively.
theblock.co/data/decentral…
dravee.eth (@bowtieddravee) 's Twitter Profile Photo

Ever tried to deal USDC with Foundry and seeing it revert? Well, 3 weeks ago, the support for USDC was added. Update Foundry frequently everyone! github.com/foundry-rs/for…

Ever tried to deal USDC with Foundry and seeing it revert? Well, 3 weeks ago, the support for USDC was added. Update Foundry frequently everyone!  github.com/foundry-rs/for…
Oak Security (@securityoak) 's Twitter Profile Photo

For those serious about account abstraction in Ethereum this 4-part series authored by @agfviggiano is a must: šŸ’”A deep dive into the main components of #ERC4337 Account Abstraction Using Alt Mempool; addressing common questions, misconceptions, and security considerations.

Sev (@00xsev) 's Twitter Profile Photo

One way to speed up PoC is to load data from external sources instead of from the chain Here’s an example btw don't forget to allow Foundry to read it in foundry.toml book.getfoundry.sh/cheatcodes/par…

One way to speed up PoC is to load data from external sources instead of from the chain

Here’s an example

btw don't forget to allow Foundry to read it in foundry.toml
book.getfoundry.sh/cheatcodes/par…