Whitehat Bandit Profile Banner
Whitehat Bandit Profile
Whitehat Bandit

@banditx0x

Followers
4,408
Following
879
Media
103
Statuses
3,757

Security Researcher @OpenZeppelin Whitehat Initiate @ImmuneFi Sometimes submitting issues to code4rena and sherlockDefi

Joined October 2018
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@banditx0x
Whitehat Bandit
5 years
HOW TO GAIN STATUS (without doing work): The thread we really wanted from @naval
24
147
936
@banditx0x
Whitehat Bandit
5 years
To get rich, compound knowledge and use it to compound capital.
4
114
762
@banditx0x
Whitehat Bandit
5 years
A notebook is a hard drive for the brain.
5
67
521
@banditx0x
Whitehat Bandit
5 years
Procrastination happens when emotional incentives don’t match rational incentives
3
89
494
@banditx0x
Whitehat Bandit
5 years
This is the greatest time in history for turning dreams into reality
4
36
275
@banditx0x
Whitehat Bandit
5 years
If you avoid a job, obligations and addictions And devote yourself to your curiosity and passions First you will have a lot of time but too little opportunity Then you will find yourself with too little time and too much opportunity That's when you've escaped the rat race
2
37
247
@banditx0x
Whitehat Bandit
9 months
Last year I found a Critical vulnerability which could steal $40M from @perpprotocol . The team was dishonest about the bug severity and rewarded $30k. The experience was devastating and made me give up on web3 security for several months. Writeup:
@ChainLight_io
ChainLight
9 months
Draining $32M in 5 Minutes. On October 3rd, 2022, we discovered and reported a critical bug in @perpprotocol that could have drained $32M, the entire deposited USDC in the pool. The critical bug was discovered in the "AccountBalance" contract, which serves as the protocol's
18
14
131
20
21
212
@banditx0x
Whitehat Bandit
6 months
~1 year ago I had no idea how to code, and no college education, but had a dream of eventually becoming a top security researcher. @sjkelleyjr put out a tweet saying he was looking to fund junior auditors. I sent this DM to him. We never reached a deal, but he showed a lot of
Tweet media one
18
18
217
@banditx0x
Whitehat Bandit
8 months
@0xdoug @0xdoug 😅this is a variant of a known issue:
4
9
180
@banditx0x
Whitehat Bandit
5 years
Early retirement is a noble goal that needs a re-branding. People want to quit their career to escape tedium and pursue passion, adventure and curiosity. Its not about living life like you're 70.
3
30
177
@banditx0x
Whitehat Bandit
8 months
How I learned solidity from scratch: 1. CryptoZombies 2. Rewrite/type the simple contracts in 3. Watch @ProgrammerSmart videos on youtube From there I was ready to jump into contests. Made an average of ~$100 per contest for first few attempts.
10
15
175
@banditx0x
Whitehat Bandit
5 years
Most of the twitter accounts I follow are part of a vague intellectual cult around Taleb/ @naval /Munger/ @paulg I don't know if its an echo chamber or the most brilliant and interesting network of people on the internet i've encountered
9
9
165
@banditx0x
Whitehat Bandit
2 years
Thread🧵on what makes @Lifinity_io not just an AMM, but a money making machine 1/ Lifinity prioritises PROFITABILITY over gameable metrics such as volume and TVL 2/Lifinity pools gain market making profits rather than suffering impermanent loss.
1
26
129
@banditx0x
Whitehat Bandit
9 months
Just got paid for my Critical @immunefi submission 🚀 Special thanks to @0xMackenzieM and @0xDjangoOnChain who gave me some advice during an extended mediation process.
Tweet media one
16
8
122
@banditx0x
Whitehat Bandit
4 months
Looking for someone to mentor or collaborate with. If you: - Already have decent contest results (requirement) - Are interested in joining OpenZeppelin (optional) - Plan to be in security research long term Shoot me a DM 😎
20
7
117
@banditx0x
Whitehat Bandit
10 months
First place in @code4rena 's @Livepeer audit contest! 🥳
Tweet media one
16
0
113
@banditx0x
Whitehat Bandit
5 years
The greatest investors keep an empty calendar. Time and freedom are necessary to make good judgement
2
14
102
@banditx0x
Whitehat Bandit
1 month
Bug bounty paid 🥳 The project had reasons why the bug could have lower impact than the report claimed due to on-chain settings. However, they paid a reduced bounty that I am happy with. Thanks @immunefi and anon project 🫡
Tweet media one
@banditx0x
Whitehat Bandit
2 months
Just submitted a Medium to ImmuneFi. The coded POC was mainly written with ChatGPT :) I asked GPT for a simple foundry POC template, then to search up the token addresses for an LP pool and to deal them to the attacker. Then I wrote the remaining few attack steps.
9
4
74
6
2
97
@banditx0x
Whitehat Bandit
7 months
Started learning Rust. What makes people say that Solidity is "easy" and Rust "hard"?
19
3
73
@banditx0x
Whitehat Bandit
1 month
2 lessons from recent @immunefi experiences: 1. Before writing a POC, submit a basic transaction using the protocols web interface (not a hack or test related transaction). Then check on etherscan which contract you just interacted with. Sometimes the contracts in the scope page
3
4
75
@banditx0x
Whitehat Bandit
2 months
Just submitted a Medium to ImmuneFi. The coded POC was mainly written with ChatGPT :) I asked GPT for a simple foundry POC template, then to search up the token addresses for an LP pool and to deal them to the attacker. Then I wrote the remaining few attack steps.
9
4
74
@banditx0x
Whitehat Bandit
5 months
$3 million vulnerability just chilling in sherlock repo
@cawfree
63617766726565
5 months
Tweet media one
5
3
50
5
4
70
@banditx0x
Whitehat Bandit
8 months
🥉 3rd place for @aloecapital audit contests at @sherlockdefi behind 2 senior Watsons!
Tweet media one
7
0
66
@banditx0x
Whitehat Bandit
8 months
5 protocol types I feel comfortable with: 👍 AMM's 👍 Perpetuals 👍 Uniswap v3 Integrations 👍 Borrow/Lend 👍 Staking 5 protocol types I need to learn more about: 📖 Cross-Chain / LayerZero Integration 📖 Balancer Integrations 📖 've' sytems (veCrv, veFXS etc) 📖 Liquid
3
4
64
@banditx0x
Whitehat Bandit
2 months
My game theory model of why @code4rena has 300% to 500% more community audit coverage than @sherlockdefi 🌶️ Let's assume there are 2 contests running with the exact same Contest Pool, nSLOC, duration: - Code4rena - Sherlock Now let's say all the auditors are given a ELO rating
@jack__sanford
Jack Sanford 🛡️
2 months
I'm spilling some alpha here but I guess I'll tell the real story: Sherlock realized that smart contract coverage doesn't work if audits don't work. So Sherlock got really focused on auditing. Started doing traditional audits, then tried C4 for our own smart contracts and it
5
0
41
12
3
65
@banditx0x
Whitehat Bandit
5 years
Seek status, not money or wealth. Status is your place in the social hierarchy.Wealth is an unfair distribution of assets. Money is how we transfer status.
1
6
61
@banditx0x
Whitehat Bandit
3 months
Tweet media one
1
3
62
@banditx0x
Whitehat Bandit
5 years
Don't confuse cost of living with standard of living
0
4
58
@banditx0x
Whitehat Bandit
5 years
A tweet that will be relevant 50 years from now is a good tweet. But they don't make for popular tweets
0
7
57
@banditx0x
Whitehat Bandit
5 months
The upcoming Ethernaut CTF has great prizes ($7K over 2 days) 👀Theres a rumor that OpenZeppelin recruiters might look at the CTF leaderboards for Security Researcher candidates
@OpenZeppelin
OpenZeppelin
5 months
Get ready for the Ethernaut CTF! Do you have what it takes to secure first place? Starting 16/03, compete for: 💰 $7k cash prizes + Defender subscriptions 🔒 48h of unique blockchain challenges 🏆 A chance to earn special POAPs Register now at !
Tweet media one
4
54
194
4
6
55
@banditx0x
Whitehat Bandit
3 years
@Fiskantes a few months ago: its a crab market 🦀 @Fiskantes now: still a crab market 🦀
Tweet media one
1
4
47
@banditx0x
Whitehat Bandit
5 years
Writing is a lonely pursuit, except on twitter
1
3
49
@banditx0x
Whitehat Bandit
5 months
@trust__90 1st Invariant: Each operation changes the difference between two colours by either 3 or 0. Eg if you rub blue and green, result is 4 B, 12 R, 14G. Diff of blue and red is 5+3, Diff G and B is the same, Diff R and G is (5-3) 2nd Invariant: Theres no combination of adding or
6
1
50
@banditx0x
Whitehat Bandit
10 months
The OpenZeppelin v5.0.0 contains a fix for the ERC4626 Vault Inflation Attack. RIP beginner auditors🫡
5
1
48
@banditx0x
Whitehat Bandit
3 months
Why did you choose to be an auditor rather than a dev? (or vice versa)
32
3
48
@banditx0x
Whitehat Bandit
5 years
@PaulieCiceroG "If you would persuade, appeal to interest and not to reason" -Ben Franklin
2
14
43
@banditx0x
Whitehat Bandit
3 months
Tweet media one
1
2
47
@banditx0x
Whitehat Bandit
5 years
Pick an area where you can be an intolerant minority among a tolerant majority.
2
4
45
@banditx0x
Whitehat Bandit
6 months
@xuwinniexu won $500k auditing rust code without even knowing the language. "Hacking skill is independent from language"
Tweet media one
3
2
44
@banditx0x
Whitehat Bandit
8 months
Hey all im personally not interested in this role as the salary is pretty meh, but if any beginner auditors are interested in an entry-level salary hit up @SpearbitDAO
@SpearbitDAO
Spearbit
8 months
Spearbit is looking to hire 2 Lead Security Researchers paying up to $1,000,000 yearly each. We are looking to onboard for two positions: • Cosmos SDK + COSM/WASM Security Expert • Geth / Go + Node Security Expert The application is in the tweet below:
Tweet media one
28
76
259
5
0
42
@banditx0x
Whitehat Bandit
5 years
Don't read for advice Read to improve your thinking Then think for yourself
1
7
44
@banditx0x
Whitehat Bandit
2 months
2 months ago @0xSpearmint said in DM's that he was studying security 7 hours a day non-stop while still being in university. Here's what hard work and concentrating on a single contest can get you 👏
@0xSpearmint
Spearmint
2 months
🥈 #2 in my third security contest Some interesting points about this one: - I spent the whole 3 weeks on the codebase - I did this contest while studying for my medical school exams - I submitted my last issue around 3:45 AM on the last day (the contest ended at 4 AM), it ended
Tweet media one
24
5
148
1
1
44
@banditx0x
Whitehat Bandit
8 months
Smart Contract Auditing is a field where: - Skill is measurable - The variance in productivity is superlinear. @IAm0x52 can provide x100 the value in an audit contest compared to a mediocre auditor who puts in the same amount of time. So two things can simultaneously be true:
Tweet media one
8
1
41
@banditx0x
Whitehat Bandit
8 months
Things you DON'T need to be a great auditor: - being good at maths - knowing how to code - above room temperature IQ - being able to find bugs There are auditors with only $50 in @code4rena earnings providing MASSIVE VALUE to clients through solo security reviews, making web3
6
2
42
@banditx0x
Whitehat Bandit
4 years
@naval Did you extrapolate this from seeing people look forward to social events for the excuse to get drunk?
3
0
41
@banditx0x
Whitehat Bandit
3 months
Most common reasons to pick auditing over dev are: - It's more meritocratic. You can prove your skills without landing a job first. - Prefer breaking over building
3
5
39
@banditx0x
Whitehat Bandit
6 months
@sjkelleyjr To find the bugs without knowing how to code, I visualised how AMM's work and to come up with exploits. This picture from my most critical finding at the time:
Tweet media one
@asen_sec
0xasen.eth
6 months
@banditx0x @sjkelleyjr How did you find 3 separate bounties last year(2022) when you didn't know how to code 1 year ago?
1
0
3
2
2
40
@banditx0x
Whitehat Bandit
5 years
Top 5 regrets of the dying I wish I: 1. stayed true to myself 2. hadn't worked so hard 3. had the courage to express my feelings 4. stayed in touch with friends 5. let myself be happier Now invert, and go live your life!
0
6
39
@banditx0x
Whitehat Bandit
5 years
Understand that ethical wealth creation is not possible. If you publicly despise wealth, status will come to you.
2
2
37
@banditx0x
Whitehat Bandit
5 years
The only employer that will pay you what you're worth is yourself.
1
8
40
@banditx0x
Whitehat Bandit
5 years
Most "deep and existential" quotes are obvious truths stated in a way that arouses emotion
0
6
38
@banditx0x
Whitehat Bandit
5 years
Learn to sell. Learn to sell. If you can do both, you will be unstoppable.
1
5
39
@banditx0x
Whitehat Bandit
5 years
If you think for yourself you will eventually find nobody that thinks like you.
0
6
36
@banditx0x
Whitehat Bandit
3 months
The best audit firms have shorter reports. Someone with valuable findings won't put 20 pages of filler before them.
5
1
37
@banditx0x
Whitehat Bandit
27 days
Which audit firms are "tier 1"?
31
0
36
@banditx0x
Whitehat Bandit
5 years
Want novelty? Meet new people. Want connection? Spend time with those closest to you.
0
5
34
@banditx0x
Whitehat Bandit
5 years
An entire life can be wasted Solving insoluble problems Or pursuing the unattainable
4
2
34
@banditx0x
Whitehat Bandit
27 days
How often do audits make an entire dev team get replaced? 😮
@TickyCrypto
CryptoTicky
28 days
I have received payment for 9 reports from @AlchemixFi boost at @immunefi @AlchemixFi replaced the entire dev team that caused the issue and willingly paid for the mistakes they made. Thank you once again for the kind support @OddlySpecivik @0xMackenzieM @0xTimofey @Ov3rKoalafied
Tweet media one
15
3
220
3
1
30
@banditx0x
Whitehat Bandit
4 years
It is the eyes of other people that ruin us. If all but myself were blind, I should want neither a fine house nor fine furniture. -Benjamin Franklin
1
8
27
@banditx0x
Whitehat Bandit
1 month
Tweet media one
@milotruck
MiloTruck
1 month
ZKSync airdrop has audit contests as one of the eligibility criteria Ya'll might want to check
Tweet media one
12
9
96
3
0
32
@banditx0x
Whitehat Bandit
6 months
So many auditors expressed interest in learning ZK, so maybe I shouldn't learn it 🤔 I want to research something other people don't know is important yet.
8
0
32
@banditx0x
Whitehat Bandit
3 years
CYCLOS ENCYCLOPEDIA The most used protocol on any layer 1 is the Automated Market Maker. These threads will explain why Cyclos will be the undisputed king of AMM's
2
5
29
@banditx0x
Whitehat Bandit
5 months
>90% of attacks that people call "flashloan exploits" can be done without a flashloan
6
0
30
@banditx0x
Whitehat Bandit
5 years
Don’t play iterated games. All the returns in life, whether in wealth, relationships, or status, come from one off prisoners dilemma scenarios.
1
5
30
@banditx0x
Whitehat Bandit
5 years
Unspecific knowledge is found by pursuing what is hot right now rather than your genuine curiosity and passion.
1
5
30
@banditx0x
Whitehat Bandit
7 months
Running out of ideas during an audit? Listen to @BowTiedDravee 's "Mindsets of Auditing" video with @opensensepw
2
1
31
@banditx0x
Whitehat Bandit
5 years
Arm yourself with outrage, misinterpretation and unspecific knowledge.
1
7
29
@banditx0x
Whitehat Bandit
8 months
Thanks @immunefi ! Aiming for the Elite ImmuneFi Hoodie next year 🚀
@immunefi
Immunefi
8 months
A new INITIATE joins our ranks... Congratulations to @banditx0x ! Your special item(s) will be arriving in your inbox shortly. See you at the next tier! More about perks for Bug Hunters:
Tweet media one
3
1
32
1
4
31
@banditx0x
Whitehat Bandit
5 months
Contests are indeed much tougher since last year despite the bullrun. For example, "slot0 for uniswap is easily manipulated" paid $440 in Feb 2023. Now it is worth $1. Some other 1 liner issues paid $400 back then.
9
0
30
@banditx0x
Whitehat Bandit
5 years
Writing something great is 90% experiencing and thinking 10% writing. You're almost done, why not finish?
1
4
31
@banditx0x
Whitehat Bandit
5 years
Logic helps you dig deeper into a hole. Lateral thinking tells you where to dig.
0
4
30
@banditx0x
Whitehat Bandit
3 months
About to review 28 missed findings for the Salty-io contest 🫡
2
0
30
@banditx0x
Whitehat Bandit
1 month
Once the debate over which contest model is best, the next Shelock vs Audit Firm comparison/analysis will drop 🍿
6
1
30
@banditx0x
Whitehat Bandit
5 years
Status is relative. Pick partners with low intelligence, energy and, above all, integrity.
1
4
26
@banditx0x
Whitehat Bandit
7 months
The attacker mindset is far more important than any technical skill for success in smart contract security
3
0
28
@banditx0x
Whitehat Bandit
5 years
"Academia is a magical place where bright young narcissists forgo 6-8 years of present income in order to forgo a lifetime of future income." @eiaine 🤣
0
4
26
@banditx0x
Whitehat Bandit
5 years
Become the best in the world at being virtuous. Keep redefining virtue until this is true.
1
2
27
@banditx0x
Whitehat Bandit
2 months
Predicting that ImmuneFi announce the largest contest ever (again), bigger than the Fuel attackathon
@MitchellAmador
Mitchell Amador
2 months
I've got some vibes inbound security fam. Brace yourself.
Tweet media one
1
2
26
5
1
28
@banditx0x
Whitehat Bandit
7 months
Web3Sec Country Power Rankings: 1. Bulgaria 2. North Korea 3. Israel
2
0
26
@banditx0x
Whitehat Bandit
4 months
Great visual explanation of the EVM
1
3
26
@banditx0x
Whitehat Bandit
8 months
According to celebrity auditors, trying out Defi platforms is a good way to improve your understanding of the codebase But why I am getting poorer every day Someone help 🙏
Tweet media one
4
0
26
@banditx0x
Whitehat Bandit
26 days
In retrospect, participating in every $1mil + contest since last October would have been the best contest selection strategy.
1
0
25
@banditx0x
Whitehat Bandit
3 months
@SpearbitDAO and @RareSkills_io are both hiring technical content writers. Could be a good fit for contest auditors as your issue writeups can be used as a portfolio of work 👀
3
2
25
@banditx0x
Whitehat Bandit
5 years
Don’t ignore people playing wealth games. You gain status by attacking people playing wealth creation games
2
2
24
@banditx0x
Whitehat Bandit
8 months
tfw you're thinking through a critical attack path but its time for your pomodoro break
Tweet media one
5
0
23
@banditx0x
Whitehat Bandit
5 years
Finding a new purpose in life often comes with the pain of admitting that you were directionless and unhappy before you found your passion.
0
3
24
@banditx0x
Whitehat Bandit
2 months
It was incredibly fun meeting everyone at @OpenZeppelin
@gtocagni
galo
2 months
Just wrapped an incredible week in Porto with the @OpenZeppelin team! We're pushing boundaries to take OpenZeppelin to every corner of crypto: • The OZ Ecosystem Stack is now available across four ecosystems, with more on the way—stay tuned for updates! • Our Research Team
Tweet media one
Tweet media two
Tweet media three
4
14
66
1
0
23
@banditx0x
Whitehat Bandit
5 years
Notes from Michael Mayer and Erik Torenberg podcast: In schooling you can get 4.0 GPA without a unique thought. In real life you get rewarded for what is plausible and impactful/interesting.
@eriktorenberg
Erik Torenberg
5 years
Spoke w/ @micjm about how to be great at Twitter, pseudonymity, education, and more.
1
2
29
3
4
21
@banditx0x
Whitehat Bandit
9 months
And 11 of them are auditors
@naruto11eth
Naruto11.eth
9 months
Bro, there are like only 10 people left in web3. This is the new bottom💀💀
60
3
177
3
0
23
@banditx0x
Whitehat Bandit
26 days
Great article by @xb0g0 He picks 4 instructive findings and reverse engineers the auditor's thought process. When reviewing findings, you should ask yourself about the thought process that lead to the bug 🧐, not just the technical details
@xb0g0
bogo
26 days
Analyzing the reports from past contests is probably the most important skill that will turn you into a GREAT auditor IF you do it PROPERLY I have invested a week and ALL of my experience to create the ultimate deep dive on the subject. I break down
15
32
164
1
0
19
@banditx0x
Whitehat Bandit
4 years
A filter for quality, by definition, has a high rate of rejection
0
1
22
@banditx0x
Whitehat Bandit
5 years
Clear thinkers talk clearly.
1
1
22
@banditx0x
Whitehat Bandit
5 months
@PatrickAlphaC USDC to $2 🚀
3
1
23
@banditx0x
Whitehat Bandit
5 years
The antidote to delusion is experience
0
1
22
@banditx0x
Whitehat Bandit
5 months
🚨 Sherlock twitter account hacked
4
2
23
@banditx0x
Whitehat Bandit
5 years
Don't climb an imaginary ladder. Find your niche in the ecosystem.
0
6
21
@banditx0x
Whitehat Bandit
9 months
> Leaves note - "this is really important to look at" > Never look at it again > Miss 2 highs
Tweet media one
2
0
22
@banditx0x
Whitehat Bandit
5 years
The Internet has massively broadened the possible space of status games. Most people haven't figured this out yet.
1
2
22