P.M (@p_misirov) 's Twitter Profile
P.M

@p_misirov

InfoSec, Web3, AI & UX Research. ex-ForEx trader. Interdisciplinary script kiddie & polyglot 🇪🇸, 🇺🇲, 🇷🇺, 🇫🇷, 🇳🇱 Building @SpearbitDAO @cantinaxyz

ID: 1232302723611201536

calendar_today25-02-2020 13:54:21

3,3K Tweet

2,2K Followers

658 Following

P.M (@p_misirov) 's Twitter Profile Photo

real question: what happens if a black hat exploits a protocol and deposits stolen funds in a permissionless pool to earn yield on it? what happens next? he gets rich? how does that affect other users depositing assets in the pool? are borrowers borrowing stolen funds?

P.M (@p_misirov) 's Twitter Profile Photo

wow who would have thought I would make money for something I posted on GitHub. should talk more about AI and Web3Sec, seems that people are really interested in this topic!

P.M (@p_misirov) 's Twitter Profile Photo

created a production ready app for $1.80 and 30mins which would have taken me at least 2 days of full time work. hiring someone on fiverr may have taken the same amount of time and cost between $500 and $2,500 excluding any potential communication issues about the product.

created a production ready app for $1.80 and 30mins which would have taken me at least 2 days of full time work.

hiring someone on fiverr may have taken the same amount of time and cost between $500 and $2,500 excluding any potential communication issues about the product.
P.M (@p_misirov) 's Twitter Profile Photo

can't believe i was building agents in 2022 for my tech lab. LLMs were SO bad compared to now, we have come such a long way in 3 years!

P.M (@p_misirov) 's Twitter Profile Photo

vibe hacking is coming soon, and you will see that your contracts are not as secure as you think. AI for Vulnerability Research and Exploit Development is pretty bad now but since commercial models and agentic workflows keep improving, expect everyone trying to hack everything.

vibe hacking is coming soon, and you will see that your contracts are not as secure as you think.

AI for Vulnerability Research and Exploit Development is pretty bad now but since commercial models and agentic workflows keep improving, expect everyone trying to hack everything.
Hari (@_hrkrshnn) 's Twitter Profile Photo

Should we make AI users first-class citizens on Cantina? So it's clear to everyone that the findings are AI-generated.

Should we make AI users first-class citizens on Cantina?

So it's clear to everyone that the findings are AI-generated.
P.M (@p_misirov) 's Twitter Profile Photo

the unfortunate reality is that everyone is a code reviewer / security researcher. the industry LACKS actual security professionals. if you want to become a security professional and have a career in web3sec for many years to come (as code review will go down thanks to AI

P.M (@p_misirov) 's Twitter Profile Photo

now we only need real time generative rendering so the AI waifu can not only tell you but also show you how to cook meth. add to that a camera for I/O processing so she can also correct you in real time if you mix the wrong chemicals

P.M (@p_misirov) 's Twitter Profile Photo

decentralized peer to peer communication over bluetooth by Jack Dorsey. did anyone build / try this already? looks interesting, maybe can repurpose into a bluetooth RADAR to find my drunk friends who NEVER PICK UP THE PHONE during a festival github.com/permissionless…

P.M (@p_misirov) 's Twitter Profile Photo

a defi protocol should have policies for everything. policy means "rules". CODE is LAW, but PROCESSES should also be LAW! for example: 1. what is your onboarding / off-boarding policy? 2. what is your smart contract review policy? 3. what is your treasury management policy? 4.

P.M (@p_misirov) 's Twitter Profile Photo

there are big 2 things going on here: 1. A Framework to assess the security posture of a protocol at a point in time. 2. A Standard (ISO like) with controls that DeFi protocols should be compliant with. public Request For Comments version coming soon!

P.M (@p_misirov) 's Twitter Profile Photo

security researcher reviews repo going to be like: - src/agents/gas-and-informational .md - src/agents/low-hanging-fruits .md - src/agents/basic-vulnerability-checklist .md - src/agents/run-slither-and-verify .md - src/agents/test-coverage-and-fuzzing .md - src/agents/write-POC