marcotnunes Profile Banner
Marco Nunes Profile
Marco Nunes

@marcotnunes

Followers
595
Following
2K
Statuses
327

security researcher & hacker • securing the frontier, forging new realities ~ aka ciphermarco

🇪🇺
Joined August 2023
Don't wanna be here? Send us removal request.
@marcotnunes
Marco Nunes
1 day
🧵 Vulnerability Disclosure Time: Wormhole Alright, you aren’t only here for my memes and jokes, are you? So let’s switch it up and dive into a vulnerability disclosure for Wormhole. One overlooked detail landed me a $50K reward 💸👇
Tweet media one
1
12
86
@marcotnunes
Marco Nunes
7 hours
The PR diff:
0
0
0
@marcotnunes
Marco Nunes
7 hours
@defilearner1 Thank you for asking, maybe I wasn’t very clear. Quote-reposted it in case others also didn’t fully understand it from my writing. This Articles thing sucks hard in visibility, it's very disconnected from the rest of X
@marcotnunes
Marco Nunes
7 hours
For some reason (I assume from bootstrapping days), the first two Guardian sets had only ONE specific key. Turns out these Guardian Sets were never expired (i.e., they have `expirationTime == 0`). Thus, the VAA verification logic assumed they were valid unexpired Guardian sets, just like the current 19 Guardians set. This meant that having this one specific key would allow the holder to bypass the need for a quorum of 13 Guardians. Their immediate fix might help with understanding:
Tweet media one
0
0
3
@marcotnunes
Marco Nunes
7 hours
@0xch301 Thank you, sir. My pleasure (and a little pain using the articles features 😁)
0
0
1
@marcotnunes
Marco Nunes
19 hours
RT @marcotnunes: 🧵 Vulnerability Disclosure Time: Wormhole Alright, you aren’t only here for my memes and jokes, are you? So let’s switch…
0
12
0
@marcotnunes
Marco Nunes
22 hours
I honestly didn’t like using the X Articles features. It feels so disconnected from the rest of the experience that I think I’ll avoid it next time But generating the post’s header image with DALL-E was very fun and satisfying ⛓️🌌 I might actually use one of these or tweak it a bit for my profile header
Tweet media one
Tweet media two
0
0
3
@marcotnunes
Marco Nunes
22 hours
0
7
0
@marcotnunes
Marco Nunes
23 hours
RT @marcotnunes: Before I forget, don’t DM for audits
0
1
0
@marcotnunes
Marco Nunes
24 hours
Before I forget, don’t DM for audits
0
1
10
@marcotnunes
Marco Nunes
1 day
@0jovi0 Thank you! Btw this repost already has more likes than the op 💀🤣
1
0
3
@marcotnunes
Marco Nunes
1 day
RT @0jovi0: Read this writeup, anon. Read it everyday like your life depends on it.
0
1
0
@marcotnunes
Marco Nunes
1 day
@sentient_x Thank you, sir! Details matter after all
0
0
1