Whitehat Bandit (@banditx0x) 's Twitter Profile
Whitehat Bandit

@banditx0x

Security Researcher @OpenZeppelin

Whitehat Initiate @ImmuneFi

ID: 1056899649389256706

calendar_today29-10-2018 13:24:47

3,3K Tweet

4,4K Takipçi

956 Takip Edilen

Whitehat Bandit (@banditx0x) 's Twitter Profile Photo

I'm going to learn ZK Auditing this year starting with zero formal maths background. Will use RareSkills ZK Book, bootcamp and LLM's. I believe going from high school level maths to understanding cutting edge ZK maths/cryptography papers and bug hunting ZK circuits should

Whitehat Bandit (@banditx0x) 's Twitter Profile Photo

In Uniswap V2/V3/V4, liquidity deposits need slippage protection to prevent frontrunning attacks but liquidity withdrawals don't. Reasoning below: First let's explore why this statement is true: Withdrawing liquidity when the pool is deviated from equilibrium gives more

Whitehat Bandit (@banditx0x) 's Twitter Profile Photo

One of the most well known bugs is the ERC4626 first depositor inflation attack. It's so common that it would earn $0.00 when reported in a public contest. The bug actually exploits a really cool bug pattern and understanding this pattern can be used to discover unique high

Whitehat Bandit (@banditx0x) 's Twitter Profile Photo

Uniswap V2 LP tokens are ERC4626 tokens that are comprised of 2 assets. ERC4626 tokens maintain a consistent asset/share ratio upon deposits and withdrawals. Rewards can be distributed to shareholders by increasing assets without increasing the number of shares. In Uniswap V2,

Whitehat Bandit (@banditx0x) 's Twitter Profile Photo

Theres a common misconception that AMM spot price manipulation attacks require low liquidity pools. Swapping to an imbalanced price, doing some exploit with the manipulated price, then swapping back only costs the swap fee.

Whitehat Bandit (@banditx0x) 's Twitter Profile Photo

Cork protocol also had a bug bounty on Cantina with a max bounty that was <1% of funds at risk. It makes me think that the exploiter found the issue when hunting bug bounties and preferred taking $12m illegally over maybe getting a 100k bounty.