Security Audits for EVM and Solana protocols • Learn more at MacroAudits.com

🪐
Audit reports have never looked better
3
26
7,771
Friends don't let friends rely on AI audits 👮
AI is really good but evidence tells me it's still just advanced pattern matching rather than deep understanding There's an extra layer of mental modeling humans are doing that LLMs don't achieve yet Which I guess that means my job is still safe (for now)
4
408
We love auditing interesting DeFi projects 🫡
Firelight has completed security audits by @OpenZeppelin, @0xMacroSecurity and @coinspect. We have a bug bounty program by @immunefi, adding another layer of ongoing security review. The next audit competition launches tomorrow with a 20K reward pool. Learn more. 👇
1
3
24
1,472
Macro Security retweeted
Openstock is live. You can now subscribe to a Hong Kong AI IPO with USDC and a wallet. Deposits open on @ethereum, @base and @solana. First vault: SDMC. $877M HKEX listing. $3M cap. 10 hour window.
25
21
149
46,923
Always great to see our clients succeed. The future of defi is still bright!
We are proud to announce our $5.5M fundraise from Turkish giants FRWRD Ventures by @YapiKredi, @isportfoy alongside @circle_ventures @Consensys @ParibuCom @will__price @izebel_eth ahead of the launch of ITRY, offering ~45% APY backed by Turkish Lira MMFs, on April 20th.
3
349
One of these fake accounts sent an NDA to our team to sign. Be careful about impersonators, including those who impersonate us. You can always see our official telegram handles on our team page: macroaudits.com/team
There are fake Telegram accounts impersonating Turtle team members. If someone reaches out to you on Telegram claiming to represent Turtle, verify their identity through our X profiles before engaging. When in doubt, confirm here: @turtledotxyz
1
3
412
Returning investment money is the ultimate sign of integrity. We did the same when we decided to focus on being the best audit and development firm. It's just the right thing to do.
Given some rumors, wanted to post a few clarifications: Farcaster is not shutting down. The protocol works and will continue to work. There were 250,000 MAU in December and over 100,000 funded wallets. The acquirer, Neynar, is a venture-backed startup and plans to shift Farcaster in a more developer-focused direction. As for Merkle, we’re planning to return the full $180M raised back to investors. Over the last 5 years, we tried to be a good steward of investor capital. Finally, I bought my house with Coinbase IPO proceeds.
4
677
Macro Security retweeted
Our Revenue Tokenizer Audit by @0xMacroSecurity is now public: 0xmacro.com/library/audits/p… Get ready for next week 💦 We also updated our tokenizer page to show you all the tools we are building around revenue tokenizer: pool.fans/tokenizer
19
4
26
2,288
Most security teams use this chart to determine the severity of a found issue. But do you really want a "high" issue on your audit report, when it's not even relevant to your protocol? 🤔 At Macro, our high/critical issues are more impactful than others 💪 We don't just mechanically assign a severity based on impact and likelihood. We look at relevance to protocol, actively avoid inflating impact, and weigh the importance of fixing the issue against the requirements and trust model of the project. If you see a high on our report, it really is a high 😤
1
1
7
935
Macro Security retweeted
Had a ton of fun talking @withAUSD on this one!
On TLD this week, @dirty_digs sits down with @drakeevans, CTO of Agora @withAUSD, to unpack what it takes to build a modern, institution-ready stablecoin platform. The man has wisdom to share, and we know you'll benefit from listening 👇
3
7
2,231
Solana (SVM) vs EVM: Part 4 🤭
Solana devs don't verify their programs on explorers, unlike EVM devs. I can't reason why this is a thing.
7
445
Solana (SVM) vs EVM: Part 3 Solana programs cannot contain state. This is different from EVM, where a smart contract *exclusively* controls the (theoretically infinite) storage associated with its address. In contrast, Solana programs store data in separate data accounts, most often Program-Derived Addresses (PDAs). These are accounts that: - Have no private key - Contain data written by the program - Can still hold lamports - Can still participate as signers in CPIs (!) Like any other account, PDAs follow the same account rules that require paying for rent, refund behavior, etc. And like any other account, PDAs are openly readable by any other program. Interestingly, this is why Solana doesn't have onchain data encapsulation.
Solana (SVM) vs EVM: Part 2 There is no `msg.sender` on Solana. In fact, you can have multiple "senders" on Solana. This is properly known as "signers", or mutable signers, as mutable allows you to modify that account's data. If you need something similar to msg.sender on Solana, you should consider using a signer. Note that Solana does not require a signer to be mutable. This allows you to check authorization from a user without modifying their account.
18
1,279
Solana (SVM) vs EVM: Part 2 There is no `msg.sender` on Solana. In fact, you can have multiple "senders" on Solana. This is properly known as "signers", or mutable signers, as mutable allows you to modify that account's data. If you need something similar to msg.sender on Solana, you should consider using a signer. Note that Solana does not require a signer to be mutable. This allows you to check authorization from a user without modifying their account.
Building on the Solana virtual machine (SVM) is very different than building on the EVM. Differences include: - Data cannot be encapsulated - External call depth capped at 4 - All account reads and writes must be known ahead of time and much more (tighter transaction limits, built-in upgradability, program-derived accounts and their ability to be signers, and so on). If you're looking to build on Solana and could use an expert opinion to accelerate your development, contact us via telegram, or via inquiry form on our website. Up to 50% of your pre-audit security reviews can be applied to a future audit (limited time only). Stay secure out there 👊 - Macro Security team
6
9
40
6,824
Not enough devs – especially not enough web3 devs – take dependency security seriously enough. This is a good step in the right direction.
Do yourself a favor and set this in your pnpm config
2
7
908
Building on the Solana virtual machine (SVM) is very different than building on the EVM. Differences include: - Data cannot be encapsulated - External call depth capped at 4 - All account reads and writes must be known ahead of time and much more (tighter transaction limits, built-in upgradability, program-derived accounts and their ability to be signers, and so on). If you're looking to build on Solana and could use an expert opinion to accelerate your development, contact us via telegram, or via inquiry form on our website. Up to 50% of your pre-audit security reviews can be applied to a future audit (limited time only). Stay secure out there 👊 - Macro Security team
3
6
36
9,500
Here's a list of resources for diving deeper into Solana security: github.com/0xMacro/awesome-s…
7
412
Here's to another 10 more!
1
9
376
Originally inspired by:
only ethereum
2
239
Macro Security retweeted
12/ Important beta details: Our CLOB is fully audited by @0xMacroSecurity @octane_security Report: 0xmacro.com/library/audits/p… 0xmacro.com/library/audits/p… During beta, limit orders are capped at $20,000 USD per trade. We'll gradually increase limits as the system proves stable. Big size? Our AMM handles it already.
3
1
14
1,428
Backed by audits from @PashovAuditGrp & @0xMacroSecurity and constant monitoring from @hexagate_, Level v2 brings composable yield and battle-ready protection to stablecoin DeFi. Try it at level.money 🛡️
1
3
154