Finally got around to doing a write-up: Breaking GitHub Private Pages for $35k
This was my first and biggest bounty. Found with @ginkoid on @Hacker0x01 :) #togetherwehitharder
Robert Chen
483 posts
Joined September 2018
- I've spent hundreds of hours auditing Uniswap v3 implementations ๐ฆ Here are my top 3 takeaways from v4 ๐งต github.com/Uniswap/v4-corโฆ
- in light of the recent Bybit hack, what can Solana teams do to be more secure? Solana has a unique signature model, that is arguably safer for multisigs. I wrote a quick post exploring this model, proposing a procedure for safe signing.
- I helped with the @vyperlang whitehat and recovery. Here's a timeline and postmortem for what happened. In both cases, we lost the race to the hacker(s) by less than 10 minutes.
- How can you trust a program without understanding it? We (.@GSfilatino) upgraded our Solana reverse engineering framework for this month's [REDACTED] hackathon. We integrated an MCP client into our decompiler plugin, automating parts of the reverse engineering process like type
00:00 - Coming to Solana Accelerate? I'll be speaking at the Scale or Die conference on May 19-20. Shoot me a DM if you're interested in talking about decompiling Solana programs :)
- ever wanted to run @solana programs directly in the browser? introducing OtterVM, a Chromium-native @jump_firedancer wrapper. please report any bugs to ctf.dicega.ng. ddg.mc.ax
- Weโve been doing a ton of cool Solana research lately, and Iโll be sharing some of it at #breakpoint2023! Will be giving a talk on "Fuzzing, Formal Verification, and a Loss of Funds". Hope to see you in Amsterdam :)
- I'll be in Singapore this year talking about some cool bugs we found :)
- How do we make smart contracts structurally safer? An exploration into some of Move's key features: Type safety and formal verification. osec.io/blog/tutorialsโฆ
- Excited to be sharing our research into decompiling close-source @solana programs -- and shoutout to @hgarrereyn for writing it :)Closed source @solana programs used to be safe. Weโve changed that. Learn how to hack Solana programs with our open-source #BinaryNinja plugin ๐ osec.io/blog/tutorialsโฆ









