noah.eth (@noahmarconi) 's Twitter Profile
noah.eth

@noahmarconi

researcher & dev

Lead Security Researcher @SpearbitDAO. Former Spearbit Core.

@optimism Developer Advisory Board member (Season 6 & 7).

ID: 101131257

linkhttps://cantina.xyz/u/noah calendar_today02-01-2010 04:05:13

2,2K Tweet

2,2K Followers

1,1K Following

Cantina 🪐 (@cantinaxyz) 's Twitter Profile Photo

Consensus, we’re coming: Cantina Happy Hour Join us May 14 at Kellys Landing for focused conversation on how we fortify the security of today’s digital infrastructure, alongside the builders shaping its future. Space is limited, RSVP here: lu.ma/969r7ura

Palina (@palinatolmach) 's Twitter Profile Photo

An internal investigation revealed we still had something we hadn’t open-sourced — so we’re fixing that. Meet ERCx: a comprehensive test suite for ERC20, 721, 1155, and 4626 tokens, with _hundreds_ of Foundry tests: github.com/runtimeverific…. Pro tip: bookmark the online version

noah.eth (@noahmarconi) 's Twitter Profile Photo

We should be allocating auditor hours to testing. An untested/undertested repo is going to be lit up by highs and need a new audit anyway. At least with testing you get artifacts.

Cantina 🪐 (@cantinaxyz) 's Twitter Profile Photo

This week, we continued our ongoing series with @BuildOnBase, turning the spotlight toward users. 🪐 Cantina Lead Researcher @noahmarconi explored how to stay safe on Base, from link hygiene and transaction signing to avoiding subtle traps in everyday usage. Key takeaways below.

This week, we continued our ongoing series with @BuildOnBase, turning the spotlight toward users. 🪐

Cantina Lead Researcher @noahmarconi explored how to stay safe on Base, from link hygiene and transaction signing to avoiding subtle traps in everyday usage. Key takeaways below.
noah.eth (@noahmarconi) 's Twitter Profile Photo

PSA 🚨 Blind signing does *not* mean we can blindly sign. It just means calldata is not decoded. Still need to review those bytes! h/t Patrick Collins for the handy resource if you’re wondering how youtube.com/watch?v=9YmPWx…

Cantina 🪐 (@cantinaxyz) 's Twitter Profile Photo

On June 18 at 12:30 PM ET, Cantina Fellow Chris Smith returns for the fourth Based Security session with Cantina and @BuildOnBase. Joining him is Rui Maximo, Head of Blockchain Security at Coinbase 🛡️, bringing top-tier insight into what advanced user protection looks like.

On June 18 at 12:30 PM ET, Cantina Fellow <a href="/iamchrissmith/">Chris Smith</a> returns for the fourth Based Security session with Cantina and @BuildOnBase.

Joining him is <a href="/rui_maximo/">Rui Maximo</a>, Head of Blockchain Security at <a href="/coinbase/">Coinbase 🛡️</a>, bringing top-tier insight into what advanced user protection looks like.
noah.eth (@noahmarconi) 's Twitter Profile Photo

They say if you’re the smartest one in the room, you’re in the wrong room. I haven’t been in the wrong room in a very long time.

effectfully (@effectfully) 's Twitter Profile Photo

"We don't need to have a test, I can prove that this code works correctly" -- yeah, no shit Sherlock, can you also prove that no one in the next twenty years will change your code or any of its dependencies invalidating the assumptions behind your proof?

Josselin Feist (@montyly) 's Twitter Profile Photo

I am thinking of hosting a small, technical meetup at Devconnect ARG for security tools builders I want to gauge if there is enough interest to make it happen. Let me know here: forms.gle/4vRDHAnYRKJeUT…