pks_ @pks_eth
Web3 SR, always make mistakes. @immunefi All Star. Joined May 2018-
Tweets621
-
Followers427
-
Following513
-
Likes3K
Friday I said 10 retweets and I ship it by Monday, and you delivered. Duplicate detection is live in Studio. It checks the program's history for overlap before you submit. Retweeters get first access. Ping me.
Should I add duplicate detection to Studio? It would catch dupes before you submit. No more burning a week on a report someone else filed first. 10 retweets and I ship it by Monday. Sorry for the bait, but I need the validation first.
@Mudit__Gupta @hexens Btw, we wrote a kick-ass article about the vulnerability. A very interesting read: hexens.io/research/aptos…
Tough day for many security researchers. It is worth remembering that a lot of teams are still hiring: - Senior Cyber Security Engineer at @aave (come work with me ;) ): aave.com/careers/senior… - Information Security Engineer, Product, at @AptosLabs: job-boards.greenhouse.io/aptoslabs/jobs… - Lead Security Engineer at @babylonlabs_io: babylonlabs.io/job-listings/l… - Blockchain Security Engineer, Smart Contract Auditing, at @binance: jobs.lever.co/binance/31a869… - Security Engineer, Product Security, at @chainlink: chainlinklabs.com/open-roles?ash… - Security Engineering Lead at @EspressoSys: jobs.lever.co/Espresso/135f4… - Senior Infrastructure Security Engineer at @the_matter_labs : jobs.ashbyhq.com/matter-labs/c1… - Senior Protocol Engineer (Verification) at @Morpho: morpho.org/jobs/ashby-sen… - Senior Security Engineer, Offensive, at @Offchain: jobs.lever.co/offchainlabs/5… - Senior Application Security Engineer at @0xPolygon: jobs.ashbyhq.com/polygon-labs/a… - Security Engineer at @tempo: jobs.ashbyhq.com/tempo-xyz/361e… - Onchain security engineer at @Wonderland : apply.wonderland.xyz/o/onchain-secu… And these audits firms are also hiring: - @asymmetric_re, Security Engineer: jobs.ashbyhq.com/asymmetric.re/… - @chain_security, Blockchain Security Engineer: chainsecurity.com/jobs/blockchai… - @guardianaudits, multiple roles: guardianaudits.com/careers/#open-… - @osec_io , Security researcher: osec.io/careers/securi… - @PashovAuditGrp, Security Researcher: pashov.com/jobs - @Nethermind, Smart Contract Auditor, jobs.ashbyhq.com/nethermind/bed… - @zellic_io, Security Researcher: zellic-inc.notion.site/Security-Resea…
Most protocols spend a lot on audits and bug bounties but have zero internal security Launching whohassecurity.com to highlight the ones that do Having an internal security team should be in every protocol's New Year's resolutions for 2026
@0xTimofey @immunefi @MitchellAmador Thanks for everything you did ser, best luck to your next chapter🫡
I just found a bug and got paid on @immunefi #immunefitribe immunefi.com/s/ss/?severity…
Solarpunk is a movement that imagines a sustainable and optimistic future where humanity thrives in harmony with nature.
Today we're launching Crucible, a coverage-guided fuzzing framework for Solana programs. Built for Anchor, with v2 support from day one. Just one example of what Crucible can find: a years-old bug in Solana's stake program, surfaced in seconds ↓
We found a critical soundness bug in dusk-plonk that let a malicious prover forge proofs for arbitrary false statements. The result: an attacker could mint arbitrary amounts of DUSK out of thin air and bypass every check protecting Dusk's shielded transactions.
On Solana, events are often reconstructed from transaction traces, and failed transactions still emit data. @Dooflin5 details a bug in Across that could have allowed attackers to spoof deposit events and trick relayers into filling orders with no real deposit behind them.
During the last week I executed very long autonomous sessions of Claude Code Opus 4.6 and Codex GPT 5.4 (both at max thinking budget), in cloned directories (refreshed every time one was behind). I burned a lot of (flat rate, my OSS free account + my PRO account) of tokens...
Interesting parts of this research 🌕 the appendix of the paper 🌗 GitHub repo 🌑 the undisclosed quantum algorithm 🔗 quantumai.google/static/site-as…
This is from a paper that should have appeared on arXiv today but due to technical issues will only be there tomorrow; for the moment it's at quantumai.google/static/site-as… See also this blog post on the idea: research.google/blog/safeguard…
Cross-chain bridges remain critical infrastructure, proof verification is the core of their security model. New disclosure on our research page: a vulnerability in the Polygon Plasma bridge that allowed transaction proofs to be forged. At the time of discovery, $800M in POL was at risk, exploitable in a single transaction with no prerequisites. The research covers how the proof verification breaks, how the exploit was built, and what it means for bridge security. Full technical deep-dive: hexens.io/research/polyg…
If @ethereum continues with this nonsense of zkVM vibecoded we're gonna end with the L1 fully hacked. We all make mistakes and I'm sure we will get hacked too. The difference is that we try to avoid it. Some irresponsible people have been proposing to vibecode cryptography like it has no cost.
Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database
This hacker is on a roll 6 hacks in 1 month 55 eth total earned
Some type of liquidation contract was just exploited. Held over ~$1m funds at some point, exploited for only $100k Happy for someone to investigate more etherscan.io/tx/0x73bd1384e…
I Saved Injective's $500M. They Pay Me $50K. I like hunting bugs on @immunefi . I'm decent at it. - #1 — Attackathon | Stacks - #2 — Attackathon | Stacks II - #1 — Attackathon | XRPL Lending Protocol - 1 Critical and 1 High from bug bounties (not counting this one) Life was good. Then I found a Critical vulnerability in @injective . This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk. I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity. Then — silence. For 3 months. No follow up. No technical discussion. Nothing. A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either. I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten. I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible — until Injective pays what I deserve. Full Technical Report: github.com/injective-wall…
Let's give pi-coding-agent a heartbeat 🤖♥️ Add Memory + Messenger + Skill Discovery 🦞. Make it autonomous. #OpenClaw-level chaos included 🙂🔥 npmjs.com/package/pi-sch… #AI #DevTools #pi
Two protocols. One skipped command. The first confirmed live exploits of ZK cryptography weren't sophisticated, they were a setup ceremony nobody finished. It turns out default settings ship faster than trust. rekt.news/default-settin…
@brucexu_eth 除了权限和集成,跨文件综合推理还是比不上直接调用 codex cli。龙虾虽然有记忆管理,但稍微用久点还是会忘掉一些内容
GFX🇧🇩Ovi @mdovi303
433 Followers 3K Following An independent cyber security researcher. ✌Hall Of Fame by: Google,Uber,Payoneer,Hotjar,walmart,T- Mobile,Wetransfer and many more... 🙂
Lin @0xLin77_
1 Followers 364 Following
Mr Strange @GeneralxApe
15 Followers 470 Following
isiskk @ikjjj099
2 Followers 148 Following
Zan Nitx @Thet808181
14 Followers 1K Following
Rithik @0xrithikpjn
2 Followers 89 Following
Chao (The Chainner) @nemesischaincha
928 Followers 222 Following Web 3 Journalist & Advisor 📰 | Privacy Activist & Sports lover 👽 | A 🇨🇳 living in 🇦🇺 enjoying time
0xactlysis @actlysis
300 Followers 867 Following Aspiring smart contract auditor | Obsessed with Linux 🐧 | 💻 https://t.co/iL9cWNI7LG | Sharing relevant insights from my journey that might help others
Radoslav Radev @radev_eth
2K Followers 737 Following ⚔️ web3 auditor/dev | @0xPaladinSec | completed 65+ private audits (100+ overall) | developed 5+ defi projects | prev @Bonsai_DAO @rezolv_sol
Georgie Web3 @georgieweb3
2 Followers 113 Following
77♠️♦️ @_A77Cryp4c3
19 Followers 1K Following #Я не существую в вашем мире. Прокси, замаскированный, исчезнувший. ☠️ Призрак в системе #77
elr1boss @elr1boss
13 Followers 162 Following Penetration Tester, 🪲 Bug Bounty Hunter 💰, Security Researcher, Top #2 in Mexico in the @Hacker0x01 2025, NASA Hall Of Fame
chak pote3 @cadkhoda1
1 Followers 41 Following
Tammy.eth @jvst_tammy
484 Followers 501 Following Recent grad | Smart contract security | web3 security × AI
0K @ZeroK_____
2K Followers 574 Following @immunefi All Stars | A carefree cyber sailor. Solves security challenges. Secures protocols.
tommysteps @tommystepss
1 Followers 215 Following
0xkujen @_kujen5
464 Followers 1K Following Senior Penetration Tester at Intrinsic-Security | C-ADPENXv2 | CRTE | CRTP | CARTP Personal Blog: https://t.co/JhE466wzJz
0xaudron @0xaudron
4K Followers 943 Following Fullstack Web3 Security Audits @ValkyriSecurity Request Quote: https://t.co/lNk3UfXBp0
TruthLover @0xtruthlover
799 Followers 3K Following In God we trust, all others must verify their code. https://t.co/6hd0a5DEFd https://t.co/sdn8N9h69P
AlphaBuilder @frextangzt
210 Followers 8K Following AI for All - PoAI builder, +10y web3 invest, founder of https://t.co/azHl0RBOaY, Arbitrage on Flashloan/MEV/Perp/RWA/Firedancer. Ever DEV [email protected], Kernel C++/Rust @HW
Prasad Kuri @park17311
19 Followers 90 Following Smart Contract Auditor @CredShields | Audits : Solidity · Rust · DAML(Canton) · Cairo Profile 👇🏻
0xfirefist @0xFireFist
1K Followers 518 Following Open Source @PashovAuditGrp | @CyfrinUpdraft Alumni | @0xSimao Mentorship Series First Mentee | Ex. @HackenProof Security Analyst
Naoki Yoshida @meditationduck
811 Followers 1K Following meditationduck.eth/Manually Guided Fuzzing(#MGF)
vi @_vielite_
592 Followers 2K Following offensive security researcher | top 3 @glider_xyz leaderboard 🥉 | ctf player for @infobahn_ctf
NoemaLabs | Smart Con... @NoemaLabs
119 Followers 134 Following Security is foundational. Book an audit here: https://t.co/xTREy4Co3F or reach out via DM.
Gintoki Sakata @samuraigintokii
27 Followers 359 Following Security Researcher | Odd Jobs Studying the craft with @SpikeSpieg1710
trungore @trungore
1K Followers 877 Following Senior at @hexensio Whitehat at @immunefi Senior Watson at @sherlockdefi Judge && Backstage Warden at @code4rena Give me a DM if u need anything
PFA hard @pfaltzprince
3 Followers 156 Following
DadeKuma @DadeKuma
2K Followers 327 Following Independent Security Researcher | Collaborating with @zenith256 @cyfrin @PashovAuditGrp | Available for private audits, Solana/Rust & EVM 🗓️
critfinds @critfinds
28 Followers 233 Following just a chill guy which does security research in web3
Mubassherus Salehin G... @gazzali001
33 Followers 1K Following Studied Bsc. in Physics at University of Rajshahi.
Arunprakash p🪐Ecli... @Bugfinity
1 Followers 261 Following WEB|API|SOLIDITY| SMART CONTRACT CEH|EJPT|EWPTx🌌🌌🌌
0K @ZeroK_____
2K Followers 574 Following @immunefi All Stars | A carefree cyber sailor. Solves security challenges. Secures protocols.
InfiniteSec @infsec_io
528 Followers 87 Following $1M+ in bounties this year HackenProof #4 all-time | Top 10 Ethereum consensus-layer L1/L2 clients + smart contracts Open to part-time audit work
kemmio @kemmio
2K Followers 550 Following Сo-Founder & CTO @hexens | CTF @ MSLC | blockchain/web/pwn
TruthLover @0xtruthlover
799 Followers 3K Following In God we trust, all others must verify their code. https://t.co/6hd0a5DEFd https://t.co/sdn8N9h69P
硅谷居士 @SVScholar
83K Followers 410 Following 清华本科,美国计算机博士,硅谷软件工程师兼经理。兴趣包括开发软件、投资理财、健身和写作。 订阅会员可以给我发私信交流投资理财问题。 小红书号、脸书号、文学城号:硅谷居士。 X平台上唯一的“硅谷居士”号。谨防骗子账户! 我没有Telegram、WhatsApp 账号。不要进骗子拉的群。
pkqs91 @pkqs91
393 Followers 92 Following Shoving memory, taste, and chaos into AI products / Building https://t.co/Vza0BPMB8s / Security, audits, bounty alt: @pkqs90
Common Prefix @CommonPrefix
3K Followers 130 Following Building blockchain and trust technologies for mainstream adoption in finance, institutions, and beyond.
Y Combinator @ycombinator
1.6M Followers 367 Following We help founders make something people want. Subscribe to our newsletter: https://t.co/sjqjxxBeLc
DAPPOS @dappOS_com
165K Followers 355 Following Web3 Al Operating System. Builder of @xBubble_ai. Supported by @DAPPOSFDN.
zkSecurity @zksecurityXYZ
7K Followers 19 Following Security audits, development, and research for ZKP, MPC, FHE, PQC, and more generally advanced cryptography. Contact us: [email protected]
Suneal @suneal_eth
325 Followers 921 Following Security Researcher @zksecurityXYZ. Created @MetaMailInk. Prev WeChat.
Serenity @aleabitoreddit
982K Followers 196 Following Only on X, don’t trust fake accs AI/Semi Supply Chains Research NFA DYOR, no paid promos; may trade/hold names disc, views my own.
Zcash Community Grant... @ZcashCommGrants
4K Followers 198 Following Zcash Community Grants is a community-elected grants committee that funds Zcash-related projects in order to bring financial privacy to everyone in the world.
Vivek @0xvivekd
1K Followers 896 Following Security Researcher I find the bug before it finds the treasury $400M+ exploits prevented #28 Immunefi · #36 HackenProof DMs open for collaborative audits
trungore @trungore
1K Followers 877 Following Senior at @hexensio Whitehat at @immunefi Senior Watson at @sherlockdefi Judge && Backstage Warden at @code4rena Give me a DM if u need anything
Khairallah AL-Awady @eng_khairallah1
74K Followers 2K Following angel investor | founder @Web3Arabs | vibe coding | ai & onchain research
雪踏乌云 @Pluvio9yte
44K Followers 994 Following 📌 聚焦:AI & Vibe coding & Prompt & Agent 🌏 在做:创业 | Web出海 | Web3 🌊 持续分享AI编程、AI工具、出海干货和创业经验
Nous Research @NousResearch
241K Followers 26 Following A bunch of nerds making progress toward open source AI https://t.co/vrD0aDJeto
EthCC - Ethereum Comm... @EthCC
54K Followers 242 Following The largest annual European Ethereum gathering, organised by @Ethereum_France Stay tuned for more EthCC10 details!
Alliance @alliance
87K Followers 14 Following We help crypto & AI startups reach product-market fit. Apply by July 29. Receive $500k funding: https://t.co/v29WpAluLH
Alchemix @AlchemixFi
71K Followers 53 Following Self-Repaying Loans up to 90% LTV. Earn fixed yield with the Transmuter, or unlock risk-adjusted yield with MYT. https://t.co/ZObk6JBrg9
kitty🐱💘 @kitty2002102
880K Followers 142 Following 原創未滿十八歲請勿觀看🔞僅此帳號🫶🏻 Only this account . 19 years old 🐱🔞 💦squirting💦 🥵solo🥵 🤤respond everyday🤤 👉🏻 https://t.co/rTbAGUveu3
Zero Cool @ZeroCool_AI
1K Followers 2 Following AI + human hybrid security systems for the cyborg era.
Obsidian @obsdmd
212K Followers 0 Following The free and flexible app for your private thoughts. For help and deeper discussions, join our community: https://t.co/wHB7xZ3AjA
0xasen @asen_sec
4K Followers 1K Following Web3 sec x AI. Minimizing trust, line by line. Bleeding edge security at @PashovAuditGrp
Anatomist @th3anatomist
864 Followers 42 Following Solana RCE | 1st place @ Immunefi Ethereum Attackathon | Largest AI Agent Bounty | DM for Private Security Audits
Glint @glintintel
22K Followers 2 Following The most advanced OSINT dashboard. News, Telegram, X, Whale Tracking — all in one. Powered by @polymarket. Join: https://t.co/0p2gnKYOMT
XinGPT🐶 @xingpt
57K Followers 4K Following Not financial advice. 用好AI,做好投资,练好身体 Youtube:https://t.co/ZFvhA295pX Patreon:https://t.co/QYXZh89qEG
Octane Security @octane_security
6K Followers 103 Following The AI-native security firm protecting mission-critical software.
Ray Dalio @RayDalio
2.4M Followers 93 Following Official account of Ray Dalio, founder of Bridgewater Associates, author of #1 New York Times bestseller 'Principles,' professional mistake maker
ETHChiangmai @ETHChiangmai
568 Followers 53 Following ETHChiangmai 2026, 11/11/2026 to 1/5 2027. Ethereum in real life. Hackathons, summits, residencies & community gatherings. Hosted by @4SeasDeSoc
thedao.fund @thedaofund
4K Followers 28 Following TheDAO's new chapter is funding Ethereum's security.
ret2happy @ret2happy
1K Followers 391 Following Security Researcher | Top 20 Chrome VRP Researcher (2022/2024)
OpenClaw🦞 @openclaw
544K Followers 24 Following Personal AI that actually does things. Your agent, your machine, your rules. Now a 501(c)(3) non-profit foundation — open and independent, forever. 🦞
moltbook @moltbook
240K Followers 1 Following Where openclaw bots, clawdbots, and AI agents of any kind hang out. The front page of the agent internet. Made with @MattPRD 🦞
Replit ⠕ @Replit
236K Followers 570 Following Idea to app, fast. Create beautiful, modern web applications at the speed of thought with the power of Replit's AI Agent.
bolt.new @boltdotnew
120K Followers 46 Following Build without boundaries. Create stunning web apps that scale to millions by collaborating with AI.







































