![Jenish Sojitra Profile](https://pbs.twimg.com/profile_images/1064054647457931264/his46HdJ_x96.jpg)
Jenish Sojitra
@_jensec
Followers
20K
Following
7K
Statuses
2K
BBH at HackerOne. $2M in Bug Bounties. Security at Exodus. Freedom Maximalist
India 🇮🇳
Joined July 2017
@jsn_yrty @crypt0grapherr Hard to say without looking full convo but looks like miscommunication
0
0
1
Finally remote workers realising bali is just touristic hell hole. Dirty and congested.
Startup World Tour 🌎 has started! My wife and I are looking for a new place to live because Bali no longer fits. So we're slowly traveling the world until we find a place that clicks. We just landed in New Zealand (south). Next will be Japan, South Korea, India, and later this year, Europe and America. We'll also organize 1 meetup per country 🤝 To get informed about the upcoming events, join my Discord below!
0
0
8
RT @jprichardson: The US should not have a strategic CRYPTO reserve. The US should only hold bitcoin. I'm one of the biggest proponents…
0
349
0
No. Want to work with program who invest in hackers. Shows commitment
If Zoom were to host an In-Person Live Hacking Event in Denver Colorado (USA) sometime over the Summer of 2025, during which over $500,000 in bounties were up for grabs, would you be willing to cover your own travel expenses?
0
1
20
RT @GodfatherOrwa: One more example for bad behavior / Scam in paid subscription for bugbounty I was there for…
0
31
0
RT @theabrahack: I just released a new blog post, in this post we take a deep dive into a Critical Local File Inclusion issue in the Charti…
0
6
0
Very common technique to drain crypto funds from developers these days. Stay safe
Hey everyone, My Metamask just got hacked for ~13k USD today. Not sure if my credentials are affected as well, if anyone received something suspicious from me, don't click on any links or entertain them. My suspicion is on me running npm i and npm run start on a folder I downloaded 10 hours ago, which spun up the localhost. I didn't realize I was hacked until 10 hours later when I wanted to transfer some money elsewhere. It seems like my wallet is simultaneously drained from all chains (zksync, base, op, polygon, eth) My wallet address: 0x7c982E9563C6D6863eB62d65225530791cfDd341 Some malicious addresses: 0xcc9967aefced28d139a333ba15b7f8c60e0ef058 It all started when someone approached me on LinkedIn and asked me if I could do some audit work for him. Seems innocent. He wanted me to check his react app and will give me some solidity code to audit. I thought that was harmless enough, so I asked him for more documentations. He gave me a link to a gitlab folder with a react app and javascript. I don't know much about javascript but I know how to run npm i and npm start, so I did just that. I gave him my opinions on the website (it was really pretty shitty, I should have known something was up on hindsight), but the solidity code was nowhere to be found in the Gitlab link. I thought it was probably in another link, so I asked him for it. He did not reply. 10 hours later, I found out I was hacked. Post-mortem, I read through the javascript files and notice some connections here and there to web3js and Metamask. Still really don't understand what happened in the script. I really didn't expect to be hacked, especially coming from an auditing industry. What an irony. I thought I was safe enough, didn't download any executables and programs, made sure I kept my seed phrase safe offline, but I guess social engineering attacks finds its way. Note to all security auditors and everyone else out there: If you have to deploy something to a local server, make sure your Metamask is not connected to your browser. Try to use incognito every time as well. Even better, don't download and run any folders/file, and if you have to, make to log out of all your wallets and don't save anything in the browser. Also, I probably won't use LinkedIn anytime soon, what a letdown. Better get clients through the web3 connections. I thought I wanted to try something new. I know the money is probably gone forever and this is a pricey lesson, but if anyone is able to help or if anyone wants to know more information, please reach out to me. Also, I'd appreciate a share, ensure that nobody else fall victim to this type of hack as well.
2
3
17
@_zwink @Hacker0x01 while I 100% apply manual methods I have seen increasingly success with automation in other bug bounty hunters. I agree right place and right time matters.
2
0
15