MevRefund Profile
MevRefund

@MevRefund

Followers
7,572
Following
36
Media
220
Statuses
1,077

MEV searcher (mid-tier), whitehat, blockchain surveyor

The mempool
Joined October 2021
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@MevRefund
MevRefund
2 years
Nice! Was just awarded my first ever bug bounty, $50K from @opensea ! Was expecting the minimum payout of $1K, given the relatively small loss (10ish Eth), but perhaps the potential damages were larger. Here's how I discovered the bug:
33
76
694
@MevRefund
MevRefund
2 years
Block 15598565 belongs to me.
Tweet media one
Tweet media two
15
39
468
@MevRefund
MevRefund
2 years
A hacker got an assist from an MEV Bot today! The inimitable 0xeef (one of the best in the business) spotted a tx in the mempool which could be backrun for 180 Eth. Submitted to Flashbots with their customary sub 50% bribe, it was accepted, netting the bot 100 Eth 👍
10
37
307
@MevRefund
MevRefund
1 year
🚨 Revoke any approvals for Maestro Router 2 right now!
40
143
216
@MevRefund
MevRefund
2 years
What's this?! A Flashbots block donating 0.03 Eth to Tornado Cash?! Welp, seal's broken, might as well stop censoring now.
Tweet media one
17
34
241
@MevRefund
MevRefund
1 year
Timeline is flooded with auditoooors, and yet ...
Tweet media one
25
9
255
@MevRefund
MevRefund
2 years
An MEV bot just got drained for almost 200 Eth. @CapitalGrug 🧐 Always use protection on those callbacks, folks!
Tweet media one
8
28
234
@MevRefund
MevRefund
11 months
@spreekaway Was this truly necessary, my guy?
Tweet media one
7
6
196
@MevRefund
MevRefund
11 months
Bahahaha, Poloniex hacker just fat fingered $2.5M, sending a bunch of token to the token contract! Someone's probably not making it back to the North Korean barracks tonight 😬
9
15
172
@MevRefund
MevRefund
6 months
I have a confession to make. I ... am a phisher. 👇
12
5
134
@MevRefund
MevRefund
2 years
Hacktober continues 😢 Around 750 Eth has been extracted from EFLeverVault. Luckily the attacker's first transaction was frontrun by 0xa57 who has been known to return stolen funds. But second one got through, netting the attacker 268 Eth.
11
12
120
@MevRefund
MevRefund
2 years
I discovered a bug in @PrimitiveFi yesterday. As usual, by discover, I mean found someone on the blockchain actively exploiting the protocol. It was a fun bug - attacker couldn't drain everything, could only take ~ $2K every 30 minutes. Drama ensued.
6
15
113
@MevRefund
MevRefund
2 years
Found an artist on the blockchain: They find old arbitrage contracts, claim their UNI airdrop for them (usually ~ $2.5K) and then find a way to extract from the contract. So far they've hit up at least 5 contracts.
4
7
102
@MevRefund
MevRefund
8 months
Someone from the Arbitrum Foundation has apparently never transacted on Ethereum before. They deployed a contract to the ARB token address to rescue 60 Eth which had been mistakenly sent by some sad sack. With no authentication 🙄 And then a mempool rescue 🙄 ...
Tweet media one
8
10
101
@MevRefund
MevRefund
3 months
A very small number of users who lost millions of dollars. Quit downplaying the severity. You're lucky the attacker wasn't super competent and only grabbed half. You exposed $20M+ of your user's assets to theft.
Tweet media one
@lifiprotocol
LI.FI
3 months
A smart contract exploit earlier today has been contained and the affected smart contract facet disabled. There is currently no further risk to users. The only wallets affected were set to infinite approvals, and represented only a very small number of users. We are engaging
0
83
377
3
3
101
@MevRefund
MevRefund
10 months
Me immediately after making a bad trade:
Tweet media one
8
8
93
@MevRefund
MevRefund
2 years
Doesn't seem great that someone can buy out a whole block for a small amount of Eth. Farewell transaction throughput 😓
10
6
87
@MevRefund
MevRefund
2 years
MEV is never dull! So the horrible trade I just tweeted about was backrun by 0xbadc0de for 800 (!) Eth. It turns out, however, that the bot was aptly named, as someone else has exploited them, taking 1100 Eth!
3
6
87
@MevRefund
MevRefund
1 month
Looks like @beaverbuild has started backrunning bundles / private txs in their blocks. To make it easier to identify, I've helpfully labelled a few of their selectors. Tbh, I'm surprised the major builders have refrained from doing so for this long.
Tweet media one
10
7
88
@MevRefund
MevRefund
2 years
The canceller is coming for your Eth! 0xBB1D6b3BE1396a4b5CCb8D061b302250bB2b73Fd has been paying huge gas fees to cancel some ancient contracts. The contract appears to reimburse the canceller for gas fees, and send the remainder to the owner ...
8
12
82
@MevRefund
MevRefund
11 months
You see a small group of searchers, politely taking turns, sharing a bribeless, long-tail opp every 8 hours. Sure would be a shame if someone were to come along and:
Tweet media one
8
8
83
@MevRefund
MevRefund
1 year
Uhhhh ... @bloXrouteLabs am I reading this correctly? For the low, low price of $15K per month, you'll let me see everyone's private transactions?
Tweet media one
12
9
79
@MevRefund
MevRefund
1 year
Yikes, Mev Bot 0xe8 just got unbundled, losing 57 Eth.
Tweet media one
3
3
76
@MevRefund
MevRefund
2 years
Tweet media one
4
8
67
@MevRefund
MevRefund
19 days
Damn son! @beaverbuild 's new bot uses the exact same calldata as Jared! When asked for comment they said: "We would've gotten away with it, if not for those meddling function selectors!"
Tweet media one
Tweet media two
8
13
79
@MevRefund
MevRefund
2 years
In that same block however, someone else wasted 6 Eth in gas fees for a contract creation + failed transaction. This was an attempt to frontrun the original hacker with a higher gas price. It would have worked too, had 0xeef not lifted the original tx to the top of block!
4
2
71
@MevRefund
MevRefund
2 years
Ngmi: Someone paid $0.41 for this free information.
Tweet media one
8
3
72
@MevRefund
MevRefund
2 years
Are you sad because your MEV competitors are better than you? Well, you can work hard and try to improve ... or ... just mess with their function selectors. Eat 💩!
Tweet media one
4
5
74
@MevRefund
MevRefund
2 years
I have a bot whose purpose is to identify smarter, better bots. It basically scans finalized blocks and tries to find transactions which look like MEV. I then manually inspect these transactions on Etherscan and *ahem* borrow the ideas of some of the more interesting ones.
3
1
71
@MevRefund
MevRefund
11 months
Forget the ctf, you're missing the real drama - blackhat just got ingeniously counterhacked for 66 Eth! 0xcaa9 has been probing mev bots for a day or two now, with the Flashbots Discord looking on, enjoying the spectacle ...
@MevRefund
MevRefund
11 months
Man's running a live sandwich bot audit as we speak! If you get Ban'd, presumably you pass.
Tweet media one
4
1
42
3
8
71
@MevRefund
MevRefund
2 years
Uhhhh ...
Tweet media one
10
4
71
@MevRefund
MevRefund
1 year
Oops, posted in the FB discord about a funny tax shitcoin which accidentally let anyone BUT the dev withdraw the taxes. At the time, the token balance wasn't worth the gas fees to claim. Now someone's already cleared 0.2 Eth: You're welcome! 🫡
Tweet media one
2
6
65
@MevRefund
MevRefund
1 year
OK, I need some dev to explain why this dumb, buggy code keeps getting reused, costing 100s of Eth. If I set out to build some stupid shitfork, I'd be forking UniV2 directly. Make it make sense please.
Tweet media one
10
7
68
@MevRefund
MevRefund
1 year
Largest (and least bribe-y) arb I've seen in a while: 420 Eth arb, only 126 to the builder, and of that, only 22 to the validator! Get to work on those Curve pools, anon ...
6
4
61
@MevRefund
MevRefund
2 years
So, as best I can tell, an @airswap market maker is signing bad trades - in the worst case swapping $1M USDT for 0.0000001 Eth Code seems to be correctly verifying everything, 0x945 just seems to be allowing shitty trades. Who profited from this though ...?
3
11
58
@MevRefund
MevRefund
11 months
Daily PSA to double check your price before adding liquidity ... ... or don't 🫡
Tweet media one
Tweet media two
2
5
60
@MevRefund
MevRefund
2 years
Or just a whale? Who knows? I know nothing about bsc
9
1
54
@MevRefund
MevRefund
1 year
Lol, apparently even Bloxroute (quietly) acknowledges that they're doing something scummy. User's private trade tx is backrun (without user consent!) by Bloxroute. User complains, Bloxroute refunds their portion a day later. If everything's overboard, why issue a refund?
Tweet media one
Tweet media two
Tweet media three
5
5
59
@MevRefund
MevRefund
9 months
Switched from geth to nethermind and proposed a block just minutes later. Why didn't you guys tell me about the MINORITY_CLIENT_PROPOSER_BOOST parameter?!
5
2
60
@MevRefund
MevRefund
2 years
Turning to one of my favorite tools , we can look for anything suspicious in the internal calls. Lo and behold, a suspicious safeTransferFrom emerges!
Tweet media one
2
2
56
@MevRefund
MevRefund
2 years
Finally made it! I'm Etherscan famous, baby!
Tweet media one
2
0
56
@MevRefund
MevRefund
1 year
Oh, thank god!
Tweet media one
7
2
55
@MevRefund
MevRefund
1 year
Lol, the (presumably) initial Vyper exploiter appears to have sat on the exploit for almost 2 weeks, making sure everything would go perfectly ... still got frontrun 🤡
Tweet media one
4
0
51
@MevRefund
MevRefund
11 months
Just one step left! ✅ Onchain GSS ☐ Dominate MEV-Share
Tweet media one
3
2
53
@MevRefund
MevRefund
6 months
When you're so good at MEV, even your EOA gets tagged by @etherscan as an MEV bot:
Tweet media one
1
1
53
@MevRefund
MevRefund
9 months
And they said MEV couldn't be solved.
Tweet media one
4
8
51
@MevRefund
MevRefund
1 year
Hooray, your bot landed its first liquidation for 1 Eth (0.25 profit after bribe)! Q: Was it a large liquidation? A: Yes Q: Did you rebalance pools afterwards? A: ... No Q: Did you leave 100+ Eth behind for a builder bot? A: ... god damn it 😢
4
5
48
@MevRefund
MevRefund
1 year
Pro tip: if you run an MEV bot that gets hacked / does an oopsie, always be sure to mention your (presumably scary, well connected) investors. It worked for the jared donator, it worked for this guy, it can work for you too!
Tweet media one
1
3
51
@MevRefund
MevRefund
2 years
Thankfully the bug was fixed before too much damage was done. Only a handful of NFT sales were sniped, and it looks like most of them were unintentional generalized frontruns of legitimate sales.
0
0
45
@MevRefund
MevRefund
1 year
How's @CoWSwap work? Poor user just donated $140K to an MEV bot because of a bad Uniswap V1 leg. Did they specify some massive slippage?
Tweet media one
Tweet media two
7
3
46
@MevRefund
MevRefund
1 year
We have a new candidate for on-chain clown of the year: This (Binance funded) addr deploys not one but two hack contracts which are triggered by calling Start and Boom respectively. Guess who ends up taking the 6K Eth and 900 Eth? Not him.
6
1
48
@MevRefund
MevRefund
8 months
Generalized frontrunners really stepping up their game. 0xa19 stitches together calls from 2 separate txs in different blocks to walk away with $188K.
Tweet media one
0
2
46
@MevRefund
MevRefund
11 months
Man's running a live sandwich bot audit as we speak! If you get Ban'd, presumably you pass.
Tweet media one
@libevm
libevm
11 months
MEV bot got exploited via unprotected callback for 8.88 ETH (~$16k) with a NFT called "Agent Origin (viet_nam)" Lmao at the similarity to Agent Orange 0x0802cb621535999de2084b49f257d8bd0919cbfe03b186651689a74536e1a792
Tweet media one
2
8
96
4
1
42
@MevRefund
MevRefund
1 year
(One of?) the Flashbots builders seems to have malfunctioned recently and is currently including bundles with reverting txs. Some examples: Anyone happen to have some old Salmonella code lying around? 😆
3
0
44
@MevRefund
MevRefund
2 years
@0x4848 FB relay (and probably others) allow anyone to submit blocks:
1
1
43
@MevRefund
MevRefund
2 months
PSA: If you were liquidated in this recent crash, please contact this builder for a refund. 800ish Eth profit in just a few hours ... well done!
Tweet media one
4
1
44
@MevRefund
MevRefund
10 months
Had the absolute privilege today of discussing builder algorithms with one of the genius founders of Flashbots. Blown away by the intelligence, charm, wit, and raw sexual magnetism. Makes @GwartyGwart look like a chump.
Tweet media one
3
1
43
@MevRefund
MevRefund
9 months
This is the best timeline
@GaryGensler
Gary Gensler
9 months
The @SECGov twitter account was compromised, and an unauthorized tweet was posted. The SEC has not approved the listing and trading of spot bitcoin exchange-traded products.
28K
10K
30K
0
26
36
@MevRefund
MevRefund
6 months
Why are block builders granting access to their end of block state for so cheap?! Man's only forking over 20% of 113 Eth: Let me in on these backroom deals, I'll happily pay you 33%!
2
6
41
@MevRefund
MevRefund
2 years
Unsafe CEX-DEX bot? Someone just paid 50+ Eth in bribes in exchange for some pretty awful token swaps. The very next block had a validator bribe of 157 Eth as searchers scrambled to fix the various pools involved. Presumably a bug, but who knows?!
Tweet media one
2
7
42
@MevRefund
MevRefund
2 years
$20M stolen from sandwich bots 😱 Flashbots screwed up. How it's supposed to work: Relay sends some info (no txs!) to validator, who constructs a block and signs it. Relay broadcasts block and sends txs to validator so they can also broadcast. What actually happened:
@samczsun
samczsun
2 years
Block 16964664: A user managed to drain five MEV bots by exploiting a bug in mev-boost-relay. Here's the block: Here's the user: Here's the patch: Here's the longer explanation:
Tweet media one
79
504
2K
3
5
43
@MevRefund
MevRefund
2 years
Why is it so difficult to report hacks to crypto protocols in a timely fashion? Anyone with non-trivial TVL should have some kind of on-call emergency pager role in their Discord. Very annoying to watch a looting in progress and be left on read by the "online" team members.
2
0
39
@MevRefund
MevRefund
6 months
To watch for user approvals and immediately call the multicall contract before the bad guys. Managed to rescue ~ $12K before the phishers wised up and went back to a permissioned attack contract.
Tweet media one
2
1
41
@MevRefund
MevRefund
2 years
As it turns out, the arbitrage profits were so high because the tx was an exploit of Inverse Finance:
1
1
36
@MevRefund
MevRefund
11 months
Hi @beaverbuild , I sent you a late bundle, apparently not giving you and the other builders enough time to PGA the bribe into oblivion, and it seems you pocketed most of it. Where can I request a refund?
5
1
40
@MevRefund
MevRefund
9 months
Begging game has definitely leveled up:
Tweet media one
Tweet media two
0
20
37
@MevRefund
MevRefund
10 months
I can't stop watching this dumpster fire: Quick recap: - Dumped 180 Eth into some token, gifting a 70 Eth arb to some validator next block. - Sold tokens for 78 Eth. - Immediately rebought 10% less tokens for that same 78 Eth. ...
2
3
41
@MevRefund
MevRefund
9 months
Me after receiving just 0.01 Eth for my block proposal. This slot appears to be defective, may I have another please?
1
22
34
@MevRefund
MevRefund
11 months
First searchers profit post I've ever seen that looks roughly correct. Well done!
@libevm
libevm
11 months
No. 1 top searcher's all time profit is ~x2 the no.2
Tweet media one
20
15
163
5
2
37
@MevRefund
MevRefund
3 months
How to lose 300 Eth in 2 quick steps: 837 Eth -> 480 cbEth -> 513 Eth Think the searcher who cleaned up this mess also fumbled the bag, bribing 90% on some pretty obscure stuff 🤷‍♂️:
5
4
39
@MevRefund
MevRefund
2 years
Pretty nice looking scam. Reuters-y and everything. Though I suppose the title was a pretty big clue.🤦‍♂️ Went to check if I was sufficiently solvent. The tx which popped up would have made me much less solvent ...
Tweet media one
5
2
36
@MevRefund
MevRefund
11 months
Lol, guess that's one way of saying Flashbots only builds 10% of blocks now 😂
@SheaKetsdever
Shea Ketsdever
11 months
This button makes Flashbots 10x faster. Get MEV protection & speed in one click.
Tweet media one
3
4
64
5
2
36
@MevRefund
MevRefund
1 year
Speaking of better, mind explaining how bloxroute is monetizing their private flow? Just discovered that this address belongs to bloxroute. Appears to be profiting from private order flow without offering any user refunds ...
Tweet media one
@uriklarman
Uri // klarman.eth ⚔️
1 year
SURPRISE! bloXroute ETH Protect now *better* than Flashbot I'm genuinely surprised, since FB are good builders, even if I disagree with them about a bunch of stuff but FB Protect now share Tx hash with MEV-Share searchers, allowing to snipe this token launch
4
5
41
4
2
39
@MevRefund
MevRefund
2 years
Just realized my arb bot actually saw this tx, offering up a 22.2 Eth bribe out of a (spectacularly badly routed) profit of 23.4 Eth. I was almost the one pissing away millions! 🤣
@spreekaway
Spreek
2 years
Ok I think this may be taking it too far
Tweet media one
64
95
576
5
0
37
@MevRefund
MevRefund
2 years
Hack's looking a lot more likely:
Tweet media one
3
1
34
@MevRefund
MevRefund
10 months
Kyber probably: God damn it, why did we get the psycho? Kyber "Director":
Tweet media one
2
1
35
@MevRefund
MevRefund
2 years
Just stick with the standard ERC20 functions, please ... 🙄
Tweet media one
4
1
36
@MevRefund
MevRefund
9 months
I generally find working with Go pretty pleasant, but this ... abomination ... is making me reconsider all my life choices.
Tweet media one
2
8
35
@MevRefund
MevRefund
19 days
Most likely they've contracted Jared to backrun their blocks for them. Feels a little ... sketchy ... to hand that kind of info over to the most prolific sandwicher, can you really ensure they're not abusing it? More fun, tinfoil take: what if beaver ... *is* ... Jared?!
5
3
37
@MevRefund
MevRefund
11 months
How in the world do you see a competitor drained a week ago and not think 'hey wait a minute, don't we have the same vulnerability?' Degens deserve better devs.
@TeamUnibot
Unibot
11 months
We experienced a token approval exploit from our new router and have paused our router to contain the issue. Any funds lost due to the bug on our new router will be compensated. Your keys and wallets are safe. We will release a detailed response after investigations conclude.
356
245
996
2
9
33
@MevRefund
MevRefund
2 years
Dunno what SwapGuard is, but you've granted it an allowance, and it allows anyone to make arbitrary function calls 😢
Tweet media one
4
3
31
@MevRefund
MevRefund
6 months
Anyone feel like tracing some (probably) stolen funds? and keep performing weird, large sandwiches that only they see (i.e. no bribe)
Tweet media one
4
1
35
@MevRefund
MevRefund
1 year
How to lose $10K in 3 simple steps:
Tweet media one
Tweet media two
Tweet media three
4
0
34
@MevRefund
MevRefund
2 years
Guess it was just a massive psyop to make me waste a couple hours looking for a non-existant 55 Eth 🤨 Confirmed that the contract in question never lost weth, and that all the eth transfers were to miners, as god intended.
3
1
33
@MevRefund
MevRefund
2 years
You people need to stop swapping $1.8M for $500! Making me envious when I don't land the backrun 😢
Tweet media one
7
4
33
@MevRefund
MevRefund
9 months
Another day, another TG bot router hack: This one's pretty sus though - unverified router contract appears to have a function which just calls transferFrom on your behalf ... 🤔 Did someone discover a rug before it could be pulled?!
0
19
29
@MevRefund
MevRefund
1 year
Attacker made ~ $800K Why didn't Balancer hack themselves? 🤔
@Balancer
Balancer
1 year
Balancer is aware of an exploit related to the vulnerability below. Mitigation procedures have drastically reduced risks, but are unable to pause affected pools. To prevent further exploits, users must withdraw from affected LPs.
15
46
120
6
2
33
@MevRefund
MevRefund
2 years
Weird hack story incoming. Not entirely sure if it's been contained yet though, so I'll hold my fire ...
3
0
27
@MevRefund
MevRefund
11 months
... uh, guys ...? Think I just found the KyberSwap exploiter 🤔
@0xOwenThurm
Owen | Guardian
11 months
Nothing is more satisfying than removing all your debug logs after getting a PoC to work.😌
6
2
77
0
1
33
@MevRefund
MevRefund
7 months
Lol semi-private txs. Always make sure to read the fine print!
@shoucccc
Chaofan Shou
7 months
PSA: Do NOT trust @bloXrouteLabs 's protect RPC. We learned this the hard way today, with a loss of $150k+. @bloXrouteLabs publicly broadcast our white-hat rescue transaction for the @unizen_io deployment on Polygon, allowing MEV bots to frontrun it. What happens: We
Tweet media one
Tweet media two
16
39
172
2
0
33
@MevRefund
MevRefund
2 years
0xf6c does not own the NFT, so a safeTransferFrom call should fail, but 0x495 (OpenSea Shared Storefront) seems to allow it. The contract is unverified, so our detective work mostly ends here. I did try simulating a safeTransferFrom call to see if I could steal all the NFTs ...
2
1
28
@MevRefund
MevRefund
2 years
Lord forgive me, I knew not what I hath done. (I only tagged 2 bots, I wash my hands of these further crimes) Begun the bot tagging wars have.
Tweet media one
3
1
32
@MevRefund
MevRefund
10 months
Ever wished you could send txs from the 0x0 address? Now's your chance!
@CyversAlerts
🚨 Cyvers Alerts 🚨
10 months
🚨ALERT🚨Our system has detected an abnormal transaction related to the @KyberNetwork exploiter. The address funded by the @KyberNetwork exploiter has received $50M worth of $HXA from the 0x0..000dEaD $ETH address using transferfrom function! 🤯 Address: .
Tweet media one
Tweet media two
5
25
99
1
1
32