On a mission to build next sustainable web3 brand. Builder during day, Whitehat during night.

Metaverse
Grateful for this one. Thanks @immunefi and the program. Onto the next.
This security researcher just earned $150k from a single report. That’s 2.5 years of Harvard tuition or a Porsche 911, however you like to spend your money. The payout pushes them to #5 on the 90-day leaderboard and #22 on the 2026 leaderboard. There’s still a lot on the table in 2026 for security researchers hungry enough to go after it. Congrats @SagaKrypto 🎉
15
3
216
6,414
Happy New Year. Hope this year brings more of what you’re working toward.
1
1
12
1,418
This was one of my favorite findings in the Ordinals Explorer. The issue is now fixed and live. Full postmortem coming soon with a deep dive into all affected programs.
Alright guys, much delayed, but feast your eyes on a new release of EVERYONES FAVORITE ORDINALS INDEXER, WALLET, and BLOCK EXPLORER: ORD 0.23.0 (and, ahem, 0.23.1). github.com/ordinals/ord/rele… github.com/ordinals/ord/rele… This one was kind of a mess 😂 read on 🧵
5
2,488
My @immunefi #ImmunefiWrapped for 2023. Quite happy with part-time work. The total bounty consists only from web apps bugs. I need to start looking for Smart Contracts bugs for better outcome.
2
3
39
7,002
Sagamore retweeted
Web 2 with 9x emmy award winning studio, 2 games in development enters web 3 and gets Fudded hard. Meanwhile some owls enter and is about the flip the web 2 in a day. “Mass adoption is coming Bruh”
54
23
201
22,343
Since the inception of application meta in NFT space, many projects launched in last 6 months utilized application to curate allowlist. I analyzed almost 20 projects and the results are scary. Here is what I have found so far from security and privacy perspective. A thread 🧵
2
2
8
1,475
5/6 Project founders and developers need to realize that users security and privacy should be the focus area. Whatever we are building needs to go through testing before going into production. In race of providing utility to our community, the security is somewhere missing.
1
4
465
6/6 Let me know what's the community thought or take on this. Like and retweet to spread the word to make a change Also follow me for more data and pivots points in NFT space security.
5
351
We are excited to release our new security bot with a host of never before seen features that allow you to not only secure your discord to new heights but also customise to suit your specific needs.
100
103
145
Stay safe @pudgypenguins holders. Seems like a new scam website. Using a similar username and domain as official one.
3
Sagamore retweeted
Finally, here is the blog for the prototype pollution research we did. "A tale of making internet pollution free" - Exploiting Client-Side Prototype Pollution in the wild pwn.af/research/pp
11
323
711
Its shocking to see that same bug got assigned different CVSS by different @Hacker0x01 triage team over the span of 2 years. And surprisingly, the program never gave a thought of reassessing the cvss.
2
1
19
Just demonstrated 300k+ users PII including email and physical address to a program @Hacker0x01 using data from @internetarchive. This bug affects every single user on the program. Estimating it to be in millions.
3
6
52
This stuff makes me feel better about the shit i'm reporting hackerone.com/reports/116590…
5
1
30
This.
I think platform Analysts shouldn't set the severities on reports. Let companies decide as they know their application better than them. I know they says final severity will change but how often it changes? I see ~90% of the time it remains same. #bugbounty
4