1/x Recently I started decompiling + analyzing MEV bots to sharpen my EVM skills - let me tell you, the amount of bots that rely on tx.origin checks for security is worrying.
It only takes one devious PoisonERC777☣️to wipe you out
Let me teach you better alternatives:
plotchy🔅
964 posts
open source
Joined January 2022
- Applying strategic solving for fun and profit I've been playing @playgigaverse on @AbstractChain and couldn't resist creating an optimal agent to win for me
00:00 - I created a complete walkthrough for solving ParadigmCTF's JOP challenge using Foundry. Come level up your bytecode skills and learn how to leverage the power of Foundry to solve even the hardest challenges:
- Baseline on Blast announced a migration plan due to a critical bug in the lending logic I was the reporter Here's the bug and how I found it 👇TL;DR: A capital inefficiency issue was found with YES. The team collaborated with researchers on a whitehat operation to secure the $YES premium for all holders and is working on YES v2. FUNDS ARE SAFU. The Protocol remains solvent. Details below 🧵
- MEV Bot 0xBEEFBaBE has insane account access control etherscan.io/address/0xbeef… Looking at the decompilation, there is a search tree checking msg.sender against 128 (!!!) different accounts for access to private functions
- 1/x So many pitfalls in DeFi development. Even a simple function that uses approve() on an ERC20 needs a flowchart decision + some consideration. What do I mean?
- The onchain game @kamigotchiworld has pulled me in like none before It's both a fun game and an onchain way to prove your hacker skills Here's how I've used my technological superiority to dominate 🧵👇
- onchain games will reward those that gather perfect information and know how to use it heres me playing @biomesAW while crunching coordinates to find the rarest resources in the realm here's how 🧵👇
00:00 - Gave a facelift to my bytecode reversing tool. Useful to understand the flow of unverified EVM contracts🕵️ github.com/plotchy/evm-cfg
- Yay! First solve! 🎉
00:07paradigm puzzle #1 AAMM: the AAMM Automated Market Maker problem statement in reply - Deep deep down on a fuzzing nerdsnipe and I want to think out loud on a reframing *Targeted Fuzzing* I'm not interested in fuzzing tests. I like the idea of finding vulnerabilities. Our state of the art fuzzers focus on reaching coverage but we should instead reach targets
- POV of me, @real_philogy and @sw0nt taking on Solady ICYMI, last week we held a seminar at @spearbit keying into the details of our review. Here's some byte sized snippets:
- I always knew REVM was cool but I have a new found respect for it after tinkering with it over the holidays playing with eGUI + revm to make a debugger that lets you change values in stack/memory/storage (anything!) on the fly
- The demo page of @ithacaxyz is awesome. Apple bio id wallets! Does anyone know how it works? The generated wallet on the webpage is a contract with a teeny tiny bytecode. On disassembly it looks like the opcodes aren't supported by heimdall. The transaction data is enormousCrypto needs to move faster. We started @ithacaxyz to accelerate the frontier, & have raised $20M from @paradigm. We’ve been collaborating with the developer community on some of crypto's hardest problems. Small teams = big impact. The future of crypto will be built together.



















