Register and share your invite link to earn from video plays and referrals.

Cosmin
@cosminm53
Security Researcher & Triager | EVM, Solana, Move| @KannAudits Intern | @PashovAuditGrp Triager | @CyfrinUpdraft alum | ZK enthusiast | @rektoff_xyz C4 Graduate
418 Following    125 Followers
Just completed building Yearn V2 on Zealynx Academy by @ZealynxSecurity
Excited to share that I completed the @KannAudits Internship Program. Over the course of the program, I audited both a Move codebase on Aptos and a Solidity one, uncovering vulnerabilities ranging from critical to medium and lower-severity issues. Grateful for the experience🔥🔥
Show more
Just finished the Building Uniswap V2 module on Zealynx Academy by @TheBlockChainer. Uniswap always felt a bit weird to me, even after watching explanations, but building it from scratch finally made it click.
Show more
Built Compound V2 from scratch on Zealynx Academy by @ZealynxSecurity . Best way to learn how to break protocols is to build them first 😅
Really nice initiative the Zealynx Academy, learned a lot of new things, and even got a refresher on things I just forgot.
Amazing bootcamp! I've learned a lot of things. I think I could've done a better job on the capstone if I didn't have exams at that time😅 But, still got graded A- which is pretty good. Thank you @rektoff_xyz for the opportunity and @m4rio_eth @danielkcumming for their mentoring!
Show more
Time for another giveaway! We will pick 6 winners to win one of the following: 1x Annual VIP @hackthebox_eu Licence 5x @PentesterLab 3 Month Licences To enter: 1️⃣ Follow us @BugBountyDefcon 2️⃣ Like this post ❤️ 3️⃣ Re-tweet this post 🔁 Giveaway open until Monday June 15th! GOOD LUCK!
Show more
0
99
464
336
Forward to community
🤯An AI security tool has 1st-place performance on security contests from just 1yr ago. Solidity-auditor v3 is out, FREE & Open Source. Thousands of Solidity developers are using the tool already. Upgrade your security baseline, use the tool🫡
Show more
0
96
508
122
Forward to community
What a fun challenge! Took me a bit of time to actually introduce a good bug in here. Props to @CertiK for this cool challenge!
A few weeks ago we threw CertiK's AI Auditor into the fire: hide a real, fund-draining bug inside a production-style DeFi contract, get multiple tries to tune it against the live tool, and see if you can sneak it past. The results are in. 🧵
Show more
You realize you’ve built Kann Audits into a respected name in Web3 security when major protocols start asking for your help on the architecture and design choices behind their most complex systems. We will continue helping, advising, and securing. Thanks for your trust 🫡
Show more
30/380 attempted so far. It's funny cause I do find the bugs, I just can't seem to land the exact lines, so my detection rate is worse than my aim in shooters😅😅Still, consistency is key and will keep doing these, I def see some improvements.
Show more
We’re seeing more and more protocols launch on mainnet without a security audit, then seek security help after users have already put their funds at risk, which is a critical mistake. If you want user trust and liquidity, security must come before deployment, not after.
Show more
Current Finance on @sherlockdefi was my first ever contest auditing Move architecture. I may have not earned, but I learned, and improved, and will continue to do so 🫡
10 Week Security Mentorship w/ @bichistriver & @pashov Second day as an intern at @KannAudits : - since this protocol that I've been auditing had no tests provided, I built a comprehensive Foundry integration test suite from scratch, covering 38 passing tests across full execution flows, edge cases, and access controls - executed a line-by-line deep parse of the core logic - analyzed the core architecture: highly interesting design where the protocol acts as a transient execution router rather than holding capital for extended periods Side note: Just came off an 8-day biological system reset to clear severe burnout. Feeling much better now, more relaxed, no sickness. Back on the board and operating sharper than before. 🫡
Show more
I have watched security researchers quit this year because X told them it was over. "Junior auditors are finished." "AI replaced you." "If you're not established, give up." I built Radcipher because I believe the opposite. Web3 needs many auditors. Real researchers - the ones who actually think are rarer than ever. And more needed than ever. If you're still trying to make it we have : - Audit Vault : roadmap, attack vectors, real exploit patterns. The foundation. - 220+ members community : your wins, your struggles, your questions. No gatekeeping. - Audit Arena : real contracts, every Monday. The reps that actually build skill. All free. Built for you. One of our researchers had their first critical confirmed on a live protocol. 3 months ago they found nothing. They just kept showing up. Discord link in bio.
Show more
10 Week Security Mentorship w/ @bichistriver & @pashov Contest #3# (Cantina) - Revert Finance Contest Wrap-up - went through all my tags across the core contracts, few interesting leads, but not strong enough. - filtered out my own High/Medium MEV findings (sandwich attacks/TWAP manipulation) after realizing Base's single sequencer and private mempool make them structurally impossible - formalized, verified and submitted one bug - went through all ERC4626 specific bugs and it seemed that all paths were properly blocked Side note: I'm taking a break for the rest of this week. Contest wrapped, I feel tired, and need to recharge.
Show more