1. X
  2. Josselin Feist
Log inSign up
Josselin Feist
Aave
1,526 posts
user avatar
Josselin Feist
Aave
@Montyly
Working on blockchain security & program analysis. Ex @trailofbits. Contributing to @Aave security
seceureka.com
Joined January 2010
1,054
Following
5,021
Followers
RepliesRepliesMediaMedia

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
  • Pinned
    user avatar
    Josselin Feist
    Aave
    @Montyly
    May 12, 2025
    I finally launched my landing page: montyly.github.io Would love your thoughts and feedback
    seceureka.com
    Josselin Feist
    Blockchain Security Researcher
    26K026K
  • user avatar
    Josselin Feist
    Aave
    @Montyly
    Mar 7, 2025
    Today was my last day at @trailofbits. After 8 amazing years, I decided it was time for me to do something different. Over the years, I have learned so much working there — from a technical standpoint, where I worked on all layers of blockchain security (L1/L2, DeFi, bridges,
    14K014K
  • user avatar
    Josselin Feist
    Aave
    @Montyly
    Jun 19, 2025
    The web3 security community right now:
    Image
    9.1K09.1K
  • user avatar
    Josselin Feist
    Aave
    @Montyly
    Nov 13, 2025
    (Personal update, so skip if you are only interested in technical content) At the beginning of the year, I decided to leave ToB. It was not an easy choice. I was in a comfortable position, but it felt like time for a change Usually, someone with my experience would go for a
    7.8K07.8K
  • user avatar
    Josselin Feist
    Aave
    @Montyly
    Sep 12, 2025
    I have been looking at @aave v4 over the past weeks. The new hub <> spoke architecture is neat: it makes the code simpler and improves isolation aave.com/blog/understan… They now use explicit rounding directions in all operations, which reduces risks and should be a standard
    Image
    27K027K
  • user avatar
    Josselin Feist
    Aave
    @Montyly
    Nov 7, 2025
    My main takeaway from the recent rounding hacks is that every incorrect rounding needs to be considered a bug Most of them are not exploitable, or not even vulnerabilities, but they are still bugs Think of it as: bug → vulnerability → exploit. Every exploit starts from a
    21K021K
  • user avatar
    Josselin Feist
    Aave
    @Montyly
    Jan 30, 2025
    Image
    19K019K
  • user avatar
    Josselin Feist
    Aave
    @Montyly
    Nov 2, 2023
    If you want to learn fuzzing, watch our 10+ hours workshop: youtube.com/watch?v=QofNQx… You will learn how to setup a fuzzer, define invariants & tackle complex systems. Ready to upskill your team? We offer invariant development as a service: trailofbits.com/services/softw…
    Image
    Learn how to fuzz like a pro: Introduction to fuzzing
    From youtube.com
    14K014K
  • user avatar
    Josselin Feist
    Aave
    @Montyly
    Nov 3, 2025
    If you're not sure about the root cause of an exploit, there's a simple solution: don't tweet I get that everyone wants to be first, but it will hurt your credibility and it won't help anyone to spread wrong analyses
    3.9K03.9K
  • user avatar
    Josselin Feist
    Aave
    @Montyly
    Oct 6, 2023
    I love the positive relationships among blockchain sec competitors. I always have great discussions with the folks from @dedaub . The people from @ConsensysAudits  are always easy to talk to. @chain_security  even invited us to a dinner during EthCC. However, I am seeing an
    12K012K
  • user avatar
    Josselin Feist
    Aave
    @Montyly
    Jul 23, 2025
    Some of my best chats about security, tooling, and career growth happen casually at conferences I'm opening a calendar slot to recreate that vibe online No pitches, no business proposals, just genuine discussion if you want to pick my brain on anything: calendar.app.google/3XYr7MsSyekpzT…
    19K019K
  • user avatar
    Josselin Feist
    Aave
    @Montyly
    May 29, 2025
    Might be a hot take but “More audits, contests, or bigger bounties” is not always the best advice What protocols often need the most is internal security A 7-figure bounty w/o in-house expertise is inefficient. External help is great, but you can’t outsource all your security
    6.5K06.5K
  • user avatar
    Josselin Feist
    Aave
    @Montyly
    Sep 22, 2025
    Announcing W3ST: Web3 Security Tools Seminar at @EFDevcon A small, technical event for builders of blockchain security tools Details and CFP:
    seceureka.com
    Web3 Security Tools Seminar (W3ST) 2026
    A highly technical seminar for builders of blockchain security tools
    12K012K
  • user avatar
    Josselin Feist
    Aave
    @Montyly
    Jun 20, 2025
    As a general rule, comparing security reports by the number or severity of findings is about as meaningful as comparing them by page count Every team has its own categorization standards. I have seen “medium” issues flagged for things I would consider informational, or that I
    5.4K05.4K
Advertisement
Advertisement