Sock Profile Banner
Sock Profile
Sock

@sockdrawermoney

2,452
Followers
4,649
Following
120
Media
1,925
Statuses

@code4rena cofounder. scaling smart contract security and rooting for everyone in the arena

PST but insomnia
Joined February 2021
Don't wanna be here? Send us removal request.
Pinned Tweet
@sockdrawermoney
Sock
9 months
always asking the big questions
Tweet media one
10
8
129
@sockdrawermoney
Sock
9 months
so many audits
@uncledoomer
doomer
9 months
what the hell even goes on here
Tweet media one
902
251
7K
5
9
108
@sockdrawermoney
Sock
10 months
If you want to get really good at something, do it competitively. Be uncomfortable. Allow yourself to make mistakes. Measure your growth. Study what the best do. That’s why @code4rena works and has helped grow scores of top tier auditors and bounty hunters.
8
14
106
@sockdrawermoney
Sock
10 months
When web3 exploits happen, quick coordination among good actors is essential. SEAL 911 is a collaborative initiative by the web3 security community designed to provide support for incident response. Please bookmark and share:
3
15
71
@sockdrawermoney
Sock
11 months
🌶️ The DSS venue and the industry is full of auditors who made their name competing on @code4rena . Logically incongruent when people imply that those without a name aren’t good auditors when C4 has been one of the primary talent pipelines for the field for >2 years #DSSspice
3
8
65
@sockdrawermoney
Sock
10 months
I’m in the arena clicking stuff
Tweet media one
0
2
55
@sockdrawermoney
Sock
11 months
If you want to say hi, look for Sneppy
Tweet media one
2
1
55
@sockdrawermoney
Sock
11 months
🌶️ Audits in general simply aren’t designed to find all bugs, but in web3 we NEED to find more bugs faster than traditional methods and keep them out of deployed contracts. That’s what @code4rena ’s been incentivizing for two and a half years and 231 audits. #DSSspice
3
5
56
@sockdrawermoney
Sock
6 months
I never worry about auditor churn on @Code4rena . Why? I believe 95% of people who get exceptionally good at pure bug-finding won’t do it at that level indefinitely. Great talent always seeks higher leverage, more meaningful impact. Bug-finding is security expert table stakes.
@GeorgeHNTR
George Hunter
6 months
In the beginning, I dreamed of being constantly booked with solo and team audits. Now, I dream of getting free from any engagements and not doing any audits for a few months. Neither is easy to achieve.
6
1
92
5
1
53
@sockdrawermoney
Sock
7 months
“Scamming the judge” is what @GalloDaSballo calls it. @code4rena just invested $90k in three Supreme Court Judges meticulously standardizing rules to cover these scenarios based on past case law. Take a look at their extensive work:
@GeorgeHNTR
George Hunter
7 months
Audit Contests Alpha: Audit contests are a game of reporting and negotiating for medium-severity findings. Highs are usually black and white and rarely solos, but almost all of the top researchers' findings that I've read are very nuanced and in places that no one even looks at.
14
7
136
6
5
50
@sockdrawermoney
Sock
9 months
? DID YOU KNOW ? there are only two (2) auditors EVER
10
3
49
@sockdrawermoney
Sock
6 months
ok yeah but has anyone thought of doing simswap4rena
0
1
43
@sockdrawermoney
Sock
6 months
for every person who likes this tweet, I will use ChatGPT
1
0
40
Want to know how accessible indexes make DeFi? My 9 year-old put his birthday money into @PieDAO_DeFi and keeps looking at its performance.
Tweet media one
3
6
40
Having worked alongside @trust__90 for the better part of the last year through C4, I believe very strongly: 1. his actions were in good faith AND 2. he will personally help make the space better in terms of processes because of this incident.
@trust__90
Trust
1 year
People are saying all kinds of terrible things while being uninformed so allow me to share more details. I've initiated coordination privately with Immunefi officials 3 hours before the white-hack. 90 minutes later, I realized the asset is currently used by the frontend and
76
76
723
1
2
42
@sockdrawermoney
Sock
10 months
Gonna go out on a limb and say I may have the best views of anyone on this Twitter space today 🏔️ See y’all soon!
Tweet media one
@TheSecureum
SΞCURΞUM
10 months
🎉 Excited to host our 1st Security GigaSpace! 🧐 What: The Future of Web3 Security Reviews ⏰ When: 1430 UTC, Friday, 18th August 🔗 Where: 🧠 Who: @GNSPS @_hrkrshnn @jack__sanford @Montyly @ethzed @MitchellAmador @sockdrawermoney & @0xRajeev (moderator)
Tweet media one
2
38
118
1
0
39
Putting together a nice little crew of sailors @TheBirdHouseNFT
Tweet media one
Tweet media two
Tweet media three
Tweet media four
4
6
34
@sockdrawermoney
Sock
8 months
Sorry, but S-tier is being married to your cofounder so you’re never alone in whatever keeps you up at night and always having your most brilliant collaborator and advisor ready to talk through ideas and problems. AOL Keyword: #OddlySpecificHumblebrag
@denk_tweets
Tyler Denk 🐝
8 months
being single is one of the best competitive advantages as a startup founder
407
272
4K
3
1
37
The sweetest and kindest people I’ve met in the crypto/web3 space are security auditors. I consider it a privilege to get to work alongside them in @code4rena .
0
2
33
@sockdrawermoney
Sock
8 months
@zachobront Always good advice to follow what you’re fascinated by! Best long term investment is aligning what you do with what you actually *want* to do. So, alternatively: *If you’re interested in ZKPs* it’s a v cool opportunity to audit AND learn. (2/3 of scope’s .sol anyway)
1
2
31
Good way to start the day. Thanks, ⁦ @alcueca
Tweet media one
3
1
27
@sockdrawermoney
Sock
9 months
I super love open data but pls be careful with charts based on lagging intel. Same chart now shows July with >270 different @code4rena wardens finding valid high quality bugs that bots couldn't find. SorrynotSorry to say competition remains pretty fierce on c4 :)
Tweet media one
Tweet media two
5
2
27
@sockdrawermoney
Sock
9 months
Just want to underscore in the context of pointing this out that I have mad respect and gratitude for folks who build and contribute things like @0xSulpiride ’s @AuditCrew , @GalloDaSballo ’s , and @hansfriese ’s @SoloditOfficial Yes, C4 could have
@sockdrawermoney
Sock
9 months
I super love open data but pls be careful with charts based on lagging intel. Same chart now shows July with >270 different @code4rena wardens finding valid high quality bugs that bots couldn't find. SorrynotSorry to say competition remains pretty fierce on c4 :)
Tweet media one
Tweet media two
5
2
27
3
2
31
@trust__90 Just another relaxing weekend playing StarCraft, I see
2
0
28
@sockdrawermoney
Sock
8 months
@thebensams @0xcuriousapple @alpeh_v “Defenders think in lists. Attackers think in graphs. As long as this is true, attackers win.” — @JohnLaTwC
1
1
28
@sockdrawermoney
Sock
8 months
Horrific to see. Sending hopes for safety and peace for our friends in Israel.
2
1
27
Man. The dark mode in @rainbowdotme makes me want to open the app just to look at all these gorgeous ugly charts.
Tweet media one
0
2
25
@sockdrawermoney
Sock
10 months
Add me on and I will tell you if @IAm0x52 👇
Tweet media one
5
1
26
@sockdrawermoney
Sock
6 months
Thank you @zachxbt @samczsun @FrankieIsLost @caitlinxyz and all who assisted in resolving this swiftly and significantly minimizing the impact.
@code4rena
Code4rena
6 months
For 69 minutes on Monday, this account was hijacked via sim swap and used to send a phishing link. We hold Code4rena to high security standards: we have policies in place requiring 2FA on all staff accounts. Unfortunately, access control for Twitter was missed based on
11
5
76
0
0
26
@sockdrawermoney
Sock
6 months
Real ones already know @aramas95 is an S-tier marketer, C4 staff member, and teammate. But she also had *literally under one minute* response time to Monday’s simswap incident. Living out a show-don’t-tell example of our principle that *everyone* is on the security team.
@aramas95
aramas
6 months
Last week marked my 1-year anniversary of working at @code4rena 💜 🧵
6
0
62
1
2
25
@sockdrawermoney
Sock
11 months
Never ask: - a woman her age - a man his salary - the Baha Men who let the dogs out
2
0
26
Personal vulnerability disclosure: I made a stupid comment in a 3am tweet which came off as flippant and passive aggressively critical of a c4 customer. This is against my principles and beliefs about security being a constant process and shame undermining security outcomes.
0
1
25
@sockdrawermoney
Sock
6 months
Man, I feel for @KyberNetwork team and community :(
0
1
25
Hi. This is my alt account. I’m looking for interesting, thoughtful people in the DeFi space. I love DAOs and coops and long scrolls on the tweets.
0
0
7
@sockdrawermoney
Sock
11 months
🌶️ Bottom line when comparing competitive vs trad audits: “More auditors, more issues found” is how @banescusebi put it in 2021 ethcc talk—but doesn’t have to mean mo money, mo audits. @code4rena gives you more brains per dollar in a code review scheduled on demand. #DSSspice
Tweet media one
@summit_defi
Defi Security Summit
11 months
We like our panels spicy 🌶️ 🌶️ Join the debate between conventional and community audits 🔥 🔥 Moderated by @0xRajeev and the fearless panelists @GNSPS @_hrkrshnn @jack__sanford @Montyly @ethzed @mitchellamador @sockdrawermoney Tune in at 15:25 CET
Tweet media one
4
8
43
2
0
23
@sockdrawermoney
Sock
10 months
Been checking out @farcaster_xyz and I'm a fan. I have some invites. DM me if you'd like one.
11
1
22
@shunduquar Builder team would’ve prolly been able to ship this like a year ago if they weren’t having to clean up my slammed-together JSON / CSV and awkward GitHub-as-database ball of mud architecture while still making everything keep working lol
1
0
21
@sockdrawermoney
Sock
9 months
Great moments in human typo history
Tweet media one
2
1
21
@sockdrawermoney
Sock
9 months
“This is the true joy in life, being used for a purpose recognized by yourself as a mighty one. Being a force of nature instead of a feverish, selfish little clod of ailments and grievances, complaining that the world will not devote itself to making you happy. I am of the
2
1
20
@sockdrawermoney
Sock
11 months
🌶️ There’s poor allocation of security budgets cos of immaturity of the space + high stakes Success as an industry looks like projects spending LESS on audits / bounties BECAUSE they invest MORE in process / consulting / dev education / architecture review early on #DSSspice
1
1
21
@sockdrawermoney
Sock
6 months
if you love productivity, wait ’til you hear about naps
@GalloDaSballo
Alex the Entreprenerd
6 months
If you enjoyed the Pomodoro Technique, go read about Circadian and Ultradian rhythm
2
0
22
4
2
21
WOW. In November’s @feiprotocol @code4rena contest, 21 wardens competed and NO high or medium severity issues were found—that’s never happened even with a half-dozen wardens competing. Just seriously wow. Hats off to the Fei team, @joey__santoro .
0
1
21
@sockdrawermoney
Sock
7 months
@pashovkrum @CharlesWangP Yeah, C4 makes it pretty hard for common exploits to get through. It’s just untenable to expect any single auditor to find everything, but the average auditor can miss 60% of common HMs in C4 and the diversity of perspectives / volume of auditors makes for a fat safety net.
0
1
21
Yes. Often, HMs = Ls + creativity Tonnnns of evidence in @code4rena results for this☝️ Also why you want many unique perspectives involved in auditing your code.
@asen_sec
0xasen.eth
1 year
If you got an audit done for your project - fix ALL the vulnerabilities not only the high/medium ones Just because the auditor marked a vulnerability as Low doesn't mean it is not important It may mean that he just didn't know how to exploit it but a blackhat could know🤷‍♂️
8
3
28
1
2
19
@sockdrawermoney
Sock
8 months
@hake_stake That’s very kind of you. My contribution is less from me *personally* and more me being a “human insight aggregator” that’s resulted from prioritizing building high-trust, high-candor relationships with a ton of amazing people I’m constantly learning from.
2
1
21
@sockdrawermoney
Sock
10 months
down bad
Tweet media one
2
0
19
Woo $canto almost back to my initial entry point of .40 😜
2
0
18
There’s a lot I love about @rainbowdotme but my absolute favorite feature is that they don’t use red for negative 24h. Second favorite feature is the ability to hide balances that make you feel a bit ill when you look at them. Mental health features A++++
1
3
17
@sockdrawermoney
Sock
11 months
Yes. The idea that humans will ever run out of work is kind of hilarious. We’ll just keep inventing more todos. Just as much as AI has the potential to eliminate jobs if also has the potential to turn every person into Da Vinci who creates whole worlds of new work to be done.
@scottbelsky
scott belsky
11 months
What the “AI will only destroy jobs” pundits don’t understand: Higher IPP “Ingenuity Per Person” leads to hiring more people as companies become more ambitious. Amidst time with customers, journalists, and industry analysts discussing the implications of AI, a common stream of
20
38
208
1
0
19
@sockdrawermoney
Sock
10 months
Click here if you aren’t redirected in a few seconds.
0
0
19
@sockdrawermoney
Sock
6 months
@pashovkrum I absolutely respect the intent but I don’t super love it as a policy because it effectively implies auditors bear liability for vulnerabilities. You are responsible for what you deploy. Good faith teams know this and rely on rigorous review, but don’t look to pass the buck.
0
0
18
@colleenklein Out of curiosity, have you sent letters articulating this viewpoint to progressive dems? Or are you part of any lobbying groups? This message is so smart, compelling, and clear. Thank you.
1
0
16
Still waiting for @0xzak to get his glasses but I have to say they look great on @scott_lew_is
Tweet media one
1
0
14
@sockdrawermoney
Sock
6 months
@cmichelio In all seriousness, my theory is the incentive to identify the highest arguable impact for a given issue leads to much better security outcomes, which is the ultimate goal.
1
0
18
the @ArcInternet 's live easel feature is so nice for throwing together a quick dashboard from multiple sites. also: $canto tvl keeps climbing 📈
Tweet media one
1
0
18
security is the most inherently human among all tech domains. fear and shame are the two most visceral human emotions and almost everything in security is dominated by the interplay of these two in one way or another.
3
2
17
Yessss @PoolTogether_ is one of the use cases that I see helps people unfamiliar with DeFi to “get it”
@lay2000lbs
Leighton 🛡
3 years
tl;dr prize savings is still the most compelling and slept on use case to bring DeFi mainstream Read the full paper here:
2
5
54
0
1
17
@sockdrawermoney
Sock
7 months
let’s, as the kids say, fg
@delitzer
Dan Elitzer
7 months
I've been looking forward to sharing this news for a long time! @NascentSecurity is a new type of security team incubated by @nascentxyz It does NOT do: ❌ portfolio services ❌ private bookings It DOES do: ✅ public competitions (e.g. @code4rena @immunefi ) ✅ public goods
18
10
198
2
1
17
@sockdrawermoney
Sock
10 months
I joined but I am still old Not financial advice: idk if I am a security or a commodity or a currency or a secret fourth thing Some codes: ft-1hn84f4a ft-mzl0o1y4 ft-gg28lo8u ft-74kbor6p ft-otktkz34 ft-p1x2e7q3 ft-qqswqgm6 ft-09bcydm3 ft-twv4qww0
4
0
16
@sockdrawermoney
Sock
11 months
🌶️ We need to drive down the price of known bugs and make complex bugs cost less than 10% of user funds so we can solve harder problems. Pushing things this direction is one of @code4rena ’s key contributions to the space. We’re gonna go ahead and keep doing that. #DSSspice
1
3
17
@QuintenFrancois $DIP is definitely what I’d buy
0
0
13
@jacksondame Our 16yo son is a very web native creator (has a YT channel with 2000 subscribers and a bunch of projects earning Roblox $) and he doesn’t think the NFT criticism is valid BUT won’t touch it because creators in his world who do get punished by mobs.
2
0
15
@sockdrawermoney
Sock
10 months
@KoolexC @code4rena The competitive audit model and formula was designed by C4 cofounder @scott_lew_is , one of the best mechanism designers in crypto :)
2
0
16
@sockdrawermoney
Sock
6 months
I think the world of @0xleastwood . Looking forward to watching this
@ProofOf_Podcast
Proof Of Podcast
6 months
Is having an auditing process overrated? Tune in to brake the mould with @0xleastwood , an LSR at @SpearbitDAO , and top @code4rena warden who has no auditing process and just follows his curiosity. Follow @web3sec_news to get exclusive summaries of this podcast 🗒️ Link for
6
7
81
2
0
15
@sockdrawermoney
Sock
11 months
🌶️ Collaboration is valuable. Diversity is more valuable. (🤫 Psst: teams compete on @code4rena , too.) #DSSspice
0
1
14
@sockdrawermoney
Sock
9 months
just found this video from May 17, 2011 that one time @evilpacket hacked mtgox... like a month before __the__ BTC hack.
6
1
12
@sockdrawermoney
Sock
7 months
@agfviggiano @GalloDaSballo @code4rena code4rena always aims to create more value than we capture
2
0
14
@scott_lew_is @ZukoWick @how1337itis @functi0nZer0 @0xfoobar seems to have canonized this terrifying watermelon as the canto mascot
Tweet media one
1
1
13
@sockdrawermoney
Sock
11 months
@trust__90 @code4rena Love collaborating with you. Thanks for being such a great community member and representative of C4.
0
0
14
@sockdrawermoney
Sock
10 months
imo 10% of **user funds** as the presumptive default commonly advocated as the golden rule by security researchers is primarily an indicator of the immaturity of the overall space send ransom bounties to zero* ——— * by building better processes, tools, education, and incentives
@ernestognw
ernestognw.eth
10 months
Do we agree offering a 10% bounty AFTER the hack has happened is probably a wrong precedent? How many Immunefi critical reports are paid at ~10% amount in risk? Perhaps we may need to reconsider the incentives if you can turn whitehat anyway
5
0
19
2
2
14
Revoke as a Service 🧠
@Scott_eth
Scott
1 year
How much would you pay per month to have a whitehat revoke your approvals when they find potential exploits?
9
0
32
2
0
14
@sockdrawermoney
Sock
9 months
well, it’s 50 cups of coffee and you know it’s on
2
0
12
luv 2 revisit code I wrote 2 years ago and find this todo
Tweet media one
0
0
13
@sockdrawermoney
Sock
6 months
the most important part of my incentive package is posts like this and wins from wardens
@aramas95
aramas
6 months
To be a part of a team that genuinely acts out its values through its culture, processes, and everyday team/community interactions is a dream. Each day I learn something new, and that alone makes me so enthusiastic about the next.
1
0
7
0
0
13
@sockdrawermoney
Sock
11 months
@akshaysrivastv @0xDaksh @code4rena <3 All credit to the hardworking team behind the scenes, judges, and exceptional wardens like yourself for sure. It’s been one of the coolest and most gratifying experiences of my life to be along for the ride and watching so many amazing people get the opportunities they
1
0
13
@sockdrawermoney
Sock
11 months
@deadrosesxyz Trivial to do, but haven’t ever seen anyone complain that C4 judges are expressly biased for/against individuals, and there is real utility for transparency and for participants to names to be discoverable. Seems like a defensive response to someone else’s marketing point.
5
1
12
@sockdrawermoney
Sock
11 months
@agfviggiano @RedTigerAuditor @code4rena My background is open source and open standards, so I agree with a lot of that in theory. One of my personal core principles comes from the Picasso quote: “To begin, you should have an idea of what you want to do, but it should be a vague idea.” To that end, the missing piece
1
0
14
@sockdrawermoney
Sock
8 months
@realgmhacker Wait for the absolutely humbling experience of having teenagers. Nothing like the crushing sense of your own powerlessness in the face of their adversities and trauma.
4
0
11
@danielvf Check out what we’re doing at @code423n4 . We run audit contests, not spec work bounties. Contests pay for valid bugs even if multiple people report the same one. Recently one top auditor told me it’s the best “job” they’ve ever had :)
0
0
11
@sockdrawermoney
Sock
11 months
@bytes032 What principles do you follow in your life that has helped you become the kind and generous person you are today?
1
0
12
@sockdrawermoney
Sock
9 months
@GiuseppeDeLaZa @code4rena Two prior zksync audits weren't announcement enough? 😂
1
0
12
@sockdrawermoney
Sock
8 months
@GalloDaSballo @code4rena you’re always first place in our hearts
0
0
11
@sockdrawermoney
Sock
9 months
@bytes032 @code4rena In general our team’s #1 goal is to add considerably more value than our fee. I believe in every solo C4 has booked we have gotten the warden paid their full requested rate. We’ve also advised auditors on market pricing and gotten several paid more than they quoted.
2
0
12
@sockdrawermoney
Sock
6 months
I just re-read this, and I want to clarify that by “level” I meant “sustained volume” Obviously people only get better at identifying bugs; the point is not that they get worse—that would be silly. It’s that they inevitably want to deploy insight they’ve gained differently.
1
0
10
found the slope db
Tweet media one
1
0
11
Statement on recent events: I was involved with a team that operated a highly profitable trading strategy last week. Got a Charizard for a Bulbasaur.
2
0
11
@sockdrawermoney
Sock
11 months
Meanwhile @code4rena adds hundreds of new auditors per month, new heroes end up on top, and projects keep coming back saying the results perform. #DSSspice
1
0
11
@0xzak @josephdelong I hired a real estate developer to build me a dapp and all I got is this lousy strip mall.
2
1
11
@sockdrawermoney
Sock
9 months
“In the depths of ‘security review’ summer, I finally learned that within me there lay an invincible ‘audit’.” —Albert Camus, basically
@0xAuditism
auditism
9 months
The term "audit" has sparked controversy, and while alternatives like "Web3 security reviews" are clear, "Web3 security reviews contests" don't have the same catch to it. Until a better alternative comes along the way, we are probably gonna stick to audit.
2
0
9
2
0
10
@sockdrawermoney
Sock
9 months
@abarbatei @alcueca @DevABDee @0xnirlin @HollaWaldfee100 @code4rena Alberto is correct; no need to run a survey because we talk to sponsors all the time. In general, sponsors would prefer higher quality / higher confidence submissions backed by POCs.
3
0
11
This thread is an amazing breakdown of $LINK and $ETH value. An absolute must-read.
@FriedWatts
D⬡N Shillingt⬡n
3 years
1/ One day, I believe $LINK will flip $ETH both in terms of market cap and value proposition. I don’t believe this based on hype, or because I’m awesome - which I am. I believe this based on evidence and logic. Crazy? Maybe. Possible? Definitely. Here’s how.
45
191
753
0
1
8
@sockdrawermoney
Sock
9 months
If you were at Defi security summit, take this quick survey to help make next year’s event even better.
0
2
10
@TwoKiloGlobal @TheKittyButts @TheBirdHouseNFT @GSA_nft ^ @TheBirdHouseNFT is already >0.1 floor for several species. Best art, community, and one of the most clever NFT strategies in the game.
Tweet media one
0
1
10
@sockdrawermoney
Sock
9 months
### COMPENSATION DATA #### the really good one makes $23,527,600 per year. the really bad one makes $123,527,601 per year.
1
0
11
Happy with this @larvalabs meebits pull
Tweet media one
0
0
8
My sweetie is a wiser, more experienced investor than me and today she’s gone from dipping her toe in crypto in a CEX to putting her spare change into #DeFi thanks to @rainbowdotme . Her picks: — $DEFI++ from @PieDAO_DeFi — $ALPHA — $RSR — $ETH
2
1
11
@sockdrawermoney
Sock
8 months
@CharlesWangP @HollaWaldfee100 3-5% is my guess as well. High Twitter visibility certainly but it really can’t be more than a sliver of the full market.
0
0
10