carlos__alegre Profile Banner
0xCharlesCheerful Profile
0xCharlesCheerful

@carlos__alegre

Followers
436
Following
1K
Statuses
605

History's most influential philosopher protecting blockchain for a living. 😄 Expand bio to learn about my philosophy 😄 ⏬ 🕵️ Check audit portfolio here 🕵️⏬

My audits 📜 →
Joined September 2023
Don't wanna be here? Send us removal request.
@carlos__alegre
0xCharlesCheerful
3 months
Reading @Uniswap results from @cantinaxyz I'm sad and thrilled, as #141 is my issue, so close to a Medium😎 So close to a @deadrosesxyz and @cergyk1337 finding! Found the root cause, couldn't explain better how to weaponize it. Just wait leaderboard... the duck-horse is coming!
Tweet media one
2
1
26
@carlos__alegre
0xCharlesCheerful
8 hours
@0xKaden Devops security
0
0
2
@carlos__alegre
0xCharlesCheerful
11 hours
RT @pxmme1337: Don’t go out of scope
Tweet media one
0
46
0
@carlos__alegre
0xCharlesCheerful
14 hours
Wen more airdrops for auditors like @zksync did??? #airdrop #web3
0
0
3
@carlos__alegre
0xCharlesCheerful
16 hours
0
0
3
@carlos__alegre
0xCharlesCheerful
16 hours
@0xFlint_ Does it get easier?? I tried morning gym for 4 days and it was just not my thing xd
1
0
2
@carlos__alegre
0xCharlesCheerful
2 days
@0xGondarxyz Dont worry it was written wrong on purpose
0
0
1
@carlos__alegre
0xCharlesCheerful
2 days
@0xSCSamurai I guess this is the modern way of saying the classic: People are stupid. xd
0
0
2
@carlos__alegre
0xCharlesCheerful
3 days
@0xFlint_ Is this a private gym just for you? xd
1
0
2
@carlos__alegre
0xCharlesCheerful
3 days
@0xGondarxyz If number big should be cuz offer small, demand high. 🥸
1
0
1
@carlos__alegre
0xCharlesCheerful
4 days
POV: fuzzing smart contracts, ping pong version
@dammiedammie35
Oyindamola🙄
5 days
This is absolutely !nsane man 🤯🏓
0
1
1
@carlos__alegre
0xCharlesCheerful
4 days
@m4rio_eth Me when not:
0
0
3
@carlos__alegre
0xCharlesCheerful
4 days
RT @m4rio_eth: Me when the code i review is nicely written and has a bunch of tests.
Tweet media one
0
2
0
@carlos__alegre
0xCharlesCheerful
4 days
The announcement is being seen by more people than the thing itself xddd Here is the tweet:
@carlos__alegre
0xCharlesCheerful
4 days
- Hey #Web3 projects, wanna spend your security budget more wisely? 🤑 - Hey 90% of #auditors, wanna sell some private audits? Here are your answers. --- ## How to Secure Your #Web3 Project Without Breaking the Bank: The Anime War Strategy 🐉💥 Securing your project is like an epic battle straight out of an anime—where the good guys (auditors) face off against the bad guys (bugs). But just like in anime, not every hero fights the final boss. It’s all about matching the right hero to the right villain. In any anime war: - The Main Hero faces the Big Bad Villain. - Side Characters handle mid-level threats. - Weaker Allies defeat the smaller enemies. Now, imagine if the main hero had to fight every villain—he’d be overwhelmed and lose. The same logic applies when securing your project. You don’t want to hire a top-level auditor to spend time fighting small, easy-to-find bugs. That’s expensive, inefficient, and a waste of their elite skills. --- ## The Battle Plan to Secure Your Project: 1. Strengthen Your Defenses First: Before calling in any heroes, have your dev team write solid tests and run automated bug-finding tools on the code. Also, documenting what the code is meant to do is a must—you can't defeat your enemy if you don't know him well. 2. Deploy Mid-Level Auditors: Hire mid-level auditors to take down the weaker bugs and clear the way. 3. Bring in the Top-Tier Heroes: Once the path is clear, top auditors or firms can focus on hunting the final boss-level vulnerabilities. 4. Launch a Public Auditing Contest: After the dust settles, let everyone finish off the weakened big guys with a combined final attack! A community of ethical hackers will take their shot at any sneaky villains that escaped. 5. Public Bug Bounty: After the public auditing contest, you can launch a public bug bounty program to keep your project secure. This is like the anime hero training the future generation to keep an eye on evil if it ever returns. If your budget is limited you might want to execute steps 1 and 2 and then only 1 of the following ones: 4,5 or 6. --- ## Why This Is Just Cheaper and Works: Top auditors are expensive and often an overkill in the early stages. As of February 7, 2025, here’s the percentage of auditors who have surpassed $10K in earnings on different platforms: - Cantina Leaderboard: - Only 133 out of 633 auditors (21%) have ever made more than $10K. - CodeHawks Leaderboard: - Only 51 out of an estimated 1,000 auditors (5.1%) have ever made more than $10K. (Their leaderboard only shows the top 100, but their Discord has 8,000 members, so conservatively assuming 1,000 active auditors.) - Code4Arena Leaderboard: - Only 332 out of 2,609 auditors (12.7%) have ever made more than $10K. (And this is the longest-running platform!) And keep in mind—some auditors appear on multiple leaderboards, meaning the true percentage of auditors earning over $10K is even lower. So what does this mean for your project? These auditors, positioned in the top 5-20%, have proven their ability to find unique and rare bugs. Yet, if you pay one of them just $10K, you could double their all-time earnings and still eliminate critical bugs for a fraction of the cost of hiring a top-tier auditor, firm, or running an expensive contest. Spending a small amount of $5-10K dollars can clean up the way for a really cheap price compared to current standards while granting you way better results when you spend the big bucks on the strongest heroes. You know, good luck finding a top-tier auditor, firm, or contest to eliminate weaker bugs for just $10K. 😅 --- ## TL;DR: Secure smart to save on costs without compromising quality. Strengthen your defenses, deploy the right heroes at the right time, and optimize your budget by hiring mid-level talent first. 🛡️ And hey, what are you waiting for? Test your code, hire me for a review 😉, and let’s fight those bugs together! 🐉💥 (Act fast—I’m leveling up every day and aiming to become a top auditor soon! 😎) Okay, you can also check the leaderboards to find more people with this cheap, good and useful level of skills. 😉 To the fellow auditors reading this, most of you are not in the top 5% just by definition, let's like and retweet this so projects realize we are also useful! And to projects reading, spread the word to cheapen #Web3Security costs! --- Now, if you’re bored, you can watch an anime war in action: - Naruto’s Fourth Great Ninja War: [
Tweet media one
0
1
1
@carlos__alegre
0xCharlesCheerful
4 days
🚨 Alright, tweeted it. This is the tweet on how to save THOUSANDS of dollars on #web3 projects' security and how to help auditors make a living out of this. 😎 Win win for all. Let's spread the word!
@carlos__alegre
0xCharlesCheerful
4 days
- Hey #Web3 projects, wanna spend your security budget more wisely? 🤑 - Hey 90% of #auditors, wanna sell some private audits? Here are your answers. --- ## How to Secure Your #Web3 Project Without Breaking the Bank: The Anime War Strategy 🐉💥 Securing your project is like an epic battle straight out of an anime—where the good guys (auditors) face off against the bad guys (bugs). But just like in anime, not every hero fights the final boss. It’s all about matching the right hero to the right villain. In any anime war: - The Main Hero faces the Big Bad Villain. - Side Characters handle mid-level threats. - Weaker Allies defeat the smaller enemies. Now, imagine if the main hero had to fight every villain—he’d be overwhelmed and lose. The same logic applies when securing your project. You don’t want to hire a top-level auditor to spend time fighting small, easy-to-find bugs. That’s expensive, inefficient, and a waste of their elite skills. --- ## The Battle Plan to Secure Your Project: 1. Strengthen Your Defenses First: Before calling in any heroes, have your dev team write solid tests and run automated bug-finding tools on the code. Also, documenting what the code is meant to do is a must—you can't defeat your enemy if you don't know him well. 2. Deploy Mid-Level Auditors: Hire mid-level auditors to take down the weaker bugs and clear the way. 3. Bring in the Top-Tier Heroes: Once the path is clear, top auditors or firms can focus on hunting the final boss-level vulnerabilities. 4. Launch a Public Auditing Contest: After the dust settles, let everyone finish off the weakened big guys with a combined final attack! A community of ethical hackers will take their shot at any sneaky villains that escaped. 5. Public Bug Bounty: After the public auditing contest, you can launch a public bug bounty program to keep your project secure. This is like the anime hero training the future generation to keep an eye on evil if it ever returns. If your budget is limited you might want to execute steps 1 and 2 and then only 1 of the following ones: 4,5 or 6. --- ## Why This Is Just Cheaper and Works: Top auditors are expensive and often an overkill in the early stages. As of February 7, 2025, here’s the percentage of auditors who have surpassed $10K in earnings on different platforms: - Cantina Leaderboard: - Only 133 out of 633 auditors (21%) have ever made more than $10K. - CodeHawks Leaderboard: - Only 51 out of an estimated 1,000 auditors (5.1%) have ever made more than $10K. (Their leaderboard only shows the top 100, but their Discord has 8,000 members, so conservatively assuming 1,000 active auditors.) - Code4Arena Leaderboard: - Only 332 out of 2,609 auditors (12.7%) have ever made more than $10K. (And this is the longest-running platform!) And keep in mind—some auditors appear on multiple leaderboards, meaning the true percentage of auditors earning over $10K is even lower. So what does this mean for your project? These auditors, positioned in the top 5-20%, have proven their ability to find unique and rare bugs. Yet, if you pay one of them just $10K, you could double their all-time earnings and still eliminate critical bugs for a fraction of the cost of hiring a top-tier auditor, firm, or running an expensive contest. Spending a small amount of $5-10K dollars can clean up the way for a really cheap price compared to current standards while granting you way better results when you spend the big bucks on the strongest heroes. You know, good luck finding a top-tier auditor, firm, or contest to eliminate weaker bugs for just $10K. 😅 --- ## TL;DR: Secure smart to save on costs without compromising quality. Strengthen your defenses, deploy the right heroes at the right time, and optimize your budget by hiring mid-level talent first. 🛡️ And hey, what are you waiting for? Test your code, hire me for a review 😉, and let’s fight those bugs together! 🐉💥 (Act fast—I’m leveling up every day and aiming to become a top auditor soon! 😎) Okay, you can also check the leaderboards to find more people with this cheap, good and useful level of skills. 😉 To the fellow auditors reading this, most of you are not in the top 5% just by definition, let's like and retweet this so projects realize we are also useful! And to projects reading, spread the word to cheapen #Web3Security costs! --- Now, if you’re bored, you can watch an anime war in action: - Naruto’s Fourth Great Ninja War: [
Tweet media one
0
0
3
@carlos__alegre
0xCharlesCheerful
4 days
Indeed we are missing that. I think we also miss attention from projects. They think only the top ones are useful and then they throw big money at them without thinking much. I think awareness and making projects aware of this is also a must. The more people are aware the better. And probably someone eventually decides to build that platform or tool.
0
0
1
@carlos__alegre
0xCharlesCheerful
4 days
@0xAlexSR indeed! or even with $ 4K to clear the path could work. I just see win win relationship 🤠
1
0
1