Register and share your invite link to earn from video plays and referrals.

CharlesWang
@0xCharlesWang
Auditing Sensei | Over 400 audits conducted | Trusted by the largest protocols | Outperforming all competitors | Lead Auditor @bailsecurity
925 Following    16.8K Followers
I had the exact same opinion, on top of that, I thought that it doesn’t make sense to build something if someone else is already doing it since > 1 year. I then reminded myself that most audit companies are not providing great audit services and I translated that into the option that the corresponding tools might not be great either. Started working on something and so far at N=6 it turns out it wasnt really hard at all to build something which is around 10x better than the rest.
Show more
First of all: It will always be important to have human auditors. Intuition and logical sense of chaining bugs to specific impacts cannot be replaced. BUT, what would be if: There is an AI tool which is legitimately great and finds more than most traditional audit companies while no one knows about it just yet, while at the same time there is heavy marketing about all other AI tools that do not even remotely come close? All @bailsecurity audits now just got an upgrade which is at least adding ON TOP of the two team audit the full coverage of traditional audit companies, for free of charge. Instead of replacing human auditors and relying more on AI, we will add AI on top of the process to increase the coverage without any extra cost.
Show more
Many researchers were laid off recently. We are always looking for top tier talent at @bailsecurity but the onboarding test is quite a challenge.
I will be upfront and compact: - our AI tool has already better coverage than most audit companies (and no false-positives) - every @bailsecurity audit will now include our AI tool as component Everyone who knows me, knows I’m not talking any bullshit.
Show more
Over the past few weeks, some SR were able to pass the @bailsecurity onboarding test. Congratulations! Some others were removed due to insufficient performance. It’s similar as the SP500, always going up over time due to rebalance. Unfortunately I cannot say the same about many „competitors“.
Show more
The true beauty of smart contract auditing, explained to the non-technical reader: Smart contract auditing is like reading a book from every possible angle. At first, you check the obvious things: spelling mistakes, grammar issues, missing words, broken sentences. In code, these are the simple bugs: missing validations, incorrect conditions, unsafe assumptions, wrong arithmetic, or access control mistakes. But a real audit goes much deeper. You are not only reading the words. You are questioning the entire story. You read the book from the beginning to see whether the plot makes sense. You read it from the end and ask whether the conclusion could have been reached in an unexpected way. You compare the introduction with the final chapter and ask whether the promise of the protocol matches what the code actually enforces. You check whether chapter three quietly contradicts chapter seven. You ask whether a side character introduced on page ten can suddenly take control of the ending. Then the conditions become harder. You read the book at midnight, when visibility is low. This is like auditing obscure edge cases: low liquidity, unusual token decimals, empty states, paused markets, stale prices, zero amounts, maximum values, or rare execution paths that most users will never touch. You read the book while one page is burning. This is like analyzing the protocol under stress: a liquidation cascade, a governance change, an oracle failure, a reentrancy attempt, a malicious token transfer, or a sudden market move. The question is not whether the system works when everything is calm. The question is whether the story still holds together while parts of it are actively breaking. You read the book while someone else is rewriting a chapter. This is governance risk, upgradeability, admin intervention, parameter changes, and external dependencies. A function may be safe today, but unsafe tomorrow if a trusted role changes a fee, replaces an oracle, modifies a whitelist, or upgrades an implementation. You read the book while two readers are racing to finish the same sentence. This is MEV, frontrunning, sandwiching, transaction ordering, and state-dependent execution. A line of code may be correct in isolation, but exploitable when another transaction can arrive before it. You read the book in a language where some words look identical but mean different things. This is token behavior: fee-on-transfer tokens, rebasing tokens, tokens with unusual decimals, ERC20s that return no boolean, or balances that can change without the protocol explicitly updating its own accounting. You read the book with missing pages, duplicated pages, and pages that only appear if you take a very specific path. This is control-flow analysis. The auditor has to follow every branch, every modifier, every external call, every state update, and every assumption. A bug often does not live in a single line. It lives in the gap between two lines that were never meant to interact. The deeper skill is not just finding mistakes. It is learning how to attack the narrative. What must always be true? Who is allowed to change it? What happens if this value is stale? What if this balance was manipulated? What if this state was deleted before being read? What if the protocol updates accounting before confirming the external effect? What if the user receives slightly less due to rounding? What if the system silently assumes a condition that is never actually enforced? Smart contract auditing is therefore not only code review. It is adversarial reading. You read forward, backward, sideways, under pressure, in the dark, and while the pages are moving. You are trying to understand the protocol’s intended story so precisely that you can discover every place where the code tells a different one.
Show more
Some security firms severely underestimate how fragile trust is. In this industry, reputation is not separate from the service. It is the service. Clients are not only buying technical output. They are buying judgment, reliability, discretion, and confidence that the team will not become a liability. Over the last year, I have seen examples where public perception shifted so sharply that, in my opinion, the reputational damage became commercially difficult to ignore. That is what happens when trust stops compounding in your favor and starts compounding against you. At @bailsecurity , you can be ensured that we will always keep providing the worlds-best service and will NEVER EVER become sloppy in our quality.
Show more
What can you expect when you book a @bailsecurity audit: - At least 2 teams a 2 auditors (4 auditors in total), sometimes up to 6 - Hand crafted auditor selection by me, fitting your protocol type - 24/7 communication - A masterpiece report - Fair pricing What you cannot expect when you book a @bailsecurity audit: - 2 random auditors that don’t even have the required expertise - lazy communication - a report that feels ChatGPT could have done it better - rip-off pricing
Show more
For all teams who are migrating to CCIP, we can offer end to end solutions for the whole process, as we have very strong engineers that have incredibly large expertise in this process. If you need help in that, feel free to hit us up.
Show more
Im super paranoid when it comes to auditor allocation for audits. I always want 99.9% coverage and sometimes even overshoot with the allocation. When I then look at other audit companies and what they do, I get a bit more relaxed because I know that our coverage is 5x better.
Show more
One of the biggest reasons so many projects still get hacked is that they hire audit teams that are not real audit teams. Most are not buying security. They are buying a stamp, and usually the cheapest one they can get. For small projects, that may be understandable since they have no money. But even 90%+ of protocols with billions in TVL do the same: compare all offers and choose strictly on price. That is not a security mindset. That is a checkbox mindset. Real security requires a serious audit and proper consultation on what it actually takes to design and write robust smart contract code. And the uncomfortable truth is simple: a large part of the market today is filled with providers that sell the label of an audit, not the quality of one. It takes a while to understand what „true security“ means and it’s a deep rabbit hole. Only those who digged into it will be able to understand the industry and realize that a lot of what’s ongoing in the security industry is just blatant money extraction
Show more
I cannot promise that we find all bugs. But I can promise the best price <> quality relation in the whole industry.