Register and share your invite link to earn from video plays and referrals.

Adrian โ›ฉ๏ธ Hetman ๐Ÿบ | ๐Ÿ““+๐Ÿ–‹๏ธ+โ˜•๏ธ
@adrianhetman
Weekly intelligence for Web3 security operators | Crypto News: | Former Head of Triage at Immunefi
2.7K Following    6.9K Followers
This was already obvious back then to any hunter. We've built insecure systems with questionable audits. Most firms aren't even aware of the majority of exploits they missed, only later caught by whitehats, or blackhats. And now weโ€™re seeing lower bounties because of AI ๐Ÿคก
Show more
Many researchers were laid off recently. We are always looking for top tier talent at @bailsecurity but the onboarding test is quite a challenge.
๐ŸคฏOne of the big web3 security companies (Certora) has just laid off a BIG portion of their staff. Security Researchers, Sales, Management, even C-level positions. That's a shock, yesterday they were still hiring elite talent. Insane. Wish everyone to find the right new jobs๐Ÿ™
Show more
In case you missed it
New issue of Burn Notice #5# ๐Ÿ”ฅ Two disclosure programs went dark in the last week. Zcash Community Grants closed its vulnerability bounty program, and THORChain is in an open dispute with a researcher over a retired one, both pointing at the volume of AI-generated reports. I know exactly what that volume does to a program, the days lost reading plausible nonsense to find the one real report underneath. The instinct to close the program is something I could understand but is never a valid response. The cost of finding a bug in old, forgotten code is dropping fast, because decompilation is good now and models are cheap, and the paid channel that routes an honest finding back to you is the part getting cut at the same moment. This was the week Aztec Connect lost $2.19M on a contract nobody could pause and Verus fell to a bridge-failure class that Wormhole and Nomad already paid for in 2022. You can read more about what happened in the last week of crypto security in the newest issue of Burn Notice down below.
Show more
New issue of Burn Notice #5# ๐Ÿ”ฅ Two disclosure programs went dark in the last week. Zcash Community Grants closed its vulnerability bounty program, and THORChain is in an open dispute with a researcher over a retired one, both pointing at the volume of AI-generated reports. I know exactly what that volume does to a program, the days lost reading plausible nonsense to find the one real report underneath. The instinct to close the program is something I could understand but is never a valid response. The cost of finding a bug in old, forgotten code is dropping fast, because decompilation is good now and models are cheap, and the paid channel that routes an honest finding back to you is the part getting cut at the same moment. This was the week Aztec Connect lost $2.19M on a contract nobody could pause and Verus fell to a bridge-failure class that Wormhole and Nomad already paid for in 2022. You can read more about what happened in the last week of crypto security in the newest issue of Burn Notice down below.
Show more
AI is just a tool, an extremely powerful tool. But human expertise and intuition is what turns it into a massive security advantage. Deep dive here -
New issue of Burn Notice #5# ๐Ÿ”ฅ Two disclosure programs went dark in the last week. Zcash Community Grants closed its vulnerability bounty program, and THORChain is in an open dispute with a researcher over a retired one, both pointing at the volume of AI-generated reports. I know exactly what that volume does to a program, the days lost reading plausible nonsense to find the one real report underneath. The instinct to close the program is something I could understand but is never a valid response. The cost of finding a bug in old, forgotten code is dropping fast, because decompilation is good now and models are cheap, and the paid channel that routes an honest finding back to you is the part getting cut at the same moment. This was the week Aztec Connect lost $2.19M on a contract nobody could pause and Verus fell to a bridge-failure class that Wormhole and Nomad already paid for in 2022. You can read more about what happened in the last week of crypto security in the newest issue of Burn Notice down below.
Show more
certik hired all those who got laid off from immunefi team, are they starting their own bug bounty platform? ๐Ÿ˜ฎ
Career update; I'm excited to share that I've joined @CertiK as Ecosystem Manager. I've spent my first days here getting a closer look at the work happening behind the scenes, and it's been a lot to take in. AI Auditor is making smart contract audits faster, more efficient, and more precise, and it's only one of several things the team is building. There's also one project I can't say much about yet. What I will mention, though, that it's a big part of why I joined, and it has the potential to become something huge for all the security researchers out there. More to come. Follow @CertiK so you don't miss it.
Show more
For fun, I launched an extension to called Cryptoccino TV. I know, clever... anyway, it's an extended news aggregator in a form of a terminal with news on the right from Market/Business/Security/Policy, updating every 3 hours. Main news from the day in the middle with an explainer why the market behaves like it is right now and on the right some nerdy charts. NOW...I want to extend this to have a virtual anchor actually reading the news, just to try mimic a real tv broadcast. Anyone knows any good models, tools, APIs I could use to generate this? It doesn't need to be super highly realistic news anchor, I would most likely keep it artificial just to avoid uncanny valley. link if anyone wants to checkout current version is
Show more
The jailbreak that got Fable 5 pulled, by Anthropic's own account, is asking it to read a codebase and fix the flaws. The same thing every defender does daily and other models already do. I've found bugs by hand for twenty years and nobody called it a national security threat.
Show more
0
96
3.1K
107
Forward to community
If this is true then multiple tech bros are willing to hand over secrets that can be used to abuse you and others to the fucking US Government than to the other tech bros who can fix this shit. What in the actual fucking simp world are we living in.
Show more
Fable feels like a polish freelancer. Shows up, speaks in its own dialect, writes the best code you've ever seen, and then disappears
0
48
2.5K
146
Forward to community
No matter the industry, everyone eventually learns the value of permissionless access and censorship resistance.
JUST IN: Anthropic says a โ€œhuge percentageโ€ of its own employees are now barred from accessing Fable 5 & Mythos 5 under U.S. restrictions.
0
460
10.4K
685
Forward to community