@danielem33

Building @Immunefi Studio. On a mission to 10x hunting productivity & impact.

Europe
Joined January 2013
Security first 🫡
1
10
🫡
Happy weekend to all the security researchers out there hunting
3
119
How does this change the "pace the frontier" claim? 🤔
After co-inventing ChatGPT, I kept asking myself: why have superhuman chat models not led to AGI? I’ve spent the last 2 years in stealth building a new way to train models (RLCD), and a new type of frontier AI model that we are releasing today: Jev • 20-200x faster • 40-400x cheaper (w/ output tokens free) • Frontier composable intelligence optimized for decisions AFAICT the shortest path to AI-based economic revolution
2
2
165
ACM's new TechBrief on AI and open source names the pressure point: AI makes it cheap to produce code, not cheap to judge it. The volume lands on whoever reviews. Same shape in web3 security. That's what we built Studio Review for. eurekalert.org/news-releases…
1
11
This is HUGE!
Today we are announcing that S&P Global has entered an agreement to acquire OpenZeppelin. Onchain finance is growing from an emerging market into core financial infrastructure, and the standards and rails our team and community built are becoming the rails of global finance. OpenZeppelin smart contracts facilitated over $37 trillion in value transferred, with the vast majority of the largest DeFi protocols, blockchain networks, stablecoins and tokenized funds relying on them. With S&P Global, we expect to accelerate the impact of onchain finance, backed by more than a century of trust in global markets, benchmarks, and risk frameworks. To our clients and to all the users of OpenZeppelin open source tools: • OpenZeppelin Contracts and all our open source applications and tools remain open source, free, and publicly maintained on GitHub. Building open source standards stays a core priority. • Audits, engineering work, and ecosystem programs continue with the same team, brand, quality, and customer experience, with what will be the added benefit of S&P Global's research capacity, market data, and institutional reach. For the last decade, OpenZeppelin has set the security standard for onchain finance. Today begins a new chapter for that mission, together with one of the most trusted names in global markets. Read the full announcement: openzeppelin.com/news/spglob…
3
75
Studio is growing every day based on YOUR feedback 🔥 What do you want to see more here?
SRs, wanna see known issues and out-of-scope conditions right next to the code you’re investigating? Coming soon to Immunefi Studio 👀 Click a highlight to see when it applies and what may still be in scope. Would this help your research?
2
89
According to The Pragmatic Engineer, AI harnesses are replacing IDEs. Usage is down this year. Curious how that plays out in Web3 security hunting. Researchers, are you still using an IDE, and how has that changed since last year? newsletter.pragmaticengineer…
1
12
"Production code written by Claude should have a higher bar than if it was written by a human." Is this happening, in your experience?
Replying to @bcherny
Hey ████, I think there is room for both. 1. Prototypes and other throw-away code can be treated as totally black box. If you’re going to throw it away anyway, and if the blast radius of it breaking is low, it doesn’t need to be perfect. 2. Production code written by Claude should have a higher bar than if it was written by a human. At Anthropic, we have many guardrails in place to make sure this is happening: lots of lint rules, lots of tests, Claude-driven end to end tests, Claude-powered fuzzers running daily, automated code reviews and security reviews, automated code refactoring, and so on. Without these, you can end up with a mess that is hard to maintain down the line. Luckily, the model makes it increasingly easy to do these well — run a few daily routines, use Claude Code Review, etc. Your job is to hold the bar on code quality. If Claude’s code doesn’t meet the bar, try: - Using the latest frontier model (Opus 5 or Fable 5.1) - Increase effort to high or xhigh - Invest in your CLAUDE.md and skills to succinctly teach Claude how to work in your codebase If all else fails, steer Claude more when you work with it, or have Claude fix accumulated debt and rewrite your codebase to make it easier to work with. Or, wait for the next model. Best, Boris
2
57
Daniele retweeted
Hey ████, I think there is room for both. 1. Prototypes and other throw-away code can be treated as totally black box. If you’re going to throw it away anyway, and if the blast radius of it breaking is low, it doesn’t need to be perfect. 2. Production code written by Claude should have a higher bar than if it was written by a human. At Anthropic, we have many guardrails in place to make sure this is happening: lots of lint rules, lots of tests, Claude-driven end to end tests, Claude-powered fuzzers running daily, automated code reviews and security reviews, automated code refactoring, and so on. Without these, you can end up with a mess that is hard to maintain down the line. Luckily, the model makes it increasingly easy to do these well — run a few daily routines, use Claude Code Review, etc. Your job is to hold the bar on code quality. If Claude’s code doesn’t meet the bar, try: - Using the latest frontier model (Opus 5 or Fable 5.1) - Increase effort to high or xhigh - Invest in your CLAUDE.md and skills to succinctly teach Claude how to work in your codebase If all else fails, steer Claude more when you work with it, or have Claude fix accumulated debt and rewrite your codebase to make it easier to work with. Or, wait for the next model. Best, Boris
148
123
57
2,480
378,595
Daniele retweeted
This is now live for selected programs, and some of you already have access! Right now, it’s a rich reader. As mentioned, we’ll keep adding features to make it more useful for our SRs. Want an invite? DM me, but only if you bring a feature request 😏
Security researchers, we’re prototyping InstaScope V3 directly inside Immunefi Studio. The idea is that you can open an Immunefi bug bounty and immediately explore its verified in-scope contracts, organized by chain and deployed target. You can inspect proxy and implementation source, navigate the complete file tree, review source snapshots and ABI functions, and generate a Foundry project when you’re ready. But the editor is only the base layer. What security context or protocol modeling would make this genuinely useful for your investigations? Live on-chain state? Call graphs? Storage layouts and inheritance? Privileged roles and access control? Cross-chain relationships? Duplicates map? Known attack surfaces? Something else entirely? Please share your ideas, including ambitious ones. I’ll try to add the feasible suggestions in weekly iterations until this becomes somewhere you spend more time investigating than in your local editor. Honest feedback is very welcome, including “I wouldn’t use this,” as long as you tell me why 🙂
4
7
1
13
3,555
Daniele retweeted
Immunefi Studio helps security researchers turn good findings into stronger reports before they reach your inbox. Studio Review checks reports for PoC clarity, impact framing, completeness, and duplicate risk, then gives researchers specific feedback they can use to improve the report before submitting. This gives projects clearer reports to assess, and it stops real vulnerabilities from getting buried in weak write-ups. When you list your bug bounty on Immunefi, you get access to researchers finding 40 to 50 confirmed criticals a month across the biggest crypto protocols, along with the tools that help them prove it. Studio Review is in invite-only beta.
7
5
1
40
3,471
Daniele retweeted
Don't guess why your bug submission might be weak. Test it. @immunefi Studio review now scores four parts of your claim and surfaces graded submission gaps for you to improve. Have you tried it yet?
1
2
1
9
4,575
This feature turns Signal into an absolute BEAST. Better get in.
Each scope change, each commit, the attack surface moves. Immunefi Signals now keeps a timeline of both. A new page for your morning coffee brief.
1
2
37
3,249
Daniele retweeted
We announced one audit competition this morning, but it doesn't stop there. Two more are on the way! For every security researcher who locked in this summer, it’s time to put everything you learned to the test. Our gift to you for the final month of SR Summer.
22
15
13
226
24,412
Daniele retweeted
The eagle has landed 🦅 Implemented the new UI for @immunefi Studio Review alongside some internal refactoring. Starting this week, running a review will give you an escalation/closure confidence. What do you want to see next?
5
6
1
30
2,847
Daniele retweeted
Been deep in the trenches today. A revamp based on your feedback coming out soon. @immunefi Studio Reviews getting a facelift. Can't wait!
2
6
1
16
4,187
Daniele retweeted
You asked for scope change alerts. Your bug bounty scraper has earned its retirement. Immunefi Studio can now shoot a webhook your way the moment a program updates scope. Repost and tell me how you plan to use it in your workflows to get in.
4
7
14
746
Daniele retweeted
Keep being an inspiration so all together we improve crypto security. 93% us, 7% the rest combined 🫡
8
16
381
Daniele retweeted
It’s official: security researchers on @Immunefi have found 169 critical-severity bugs in the last 90 days. If you are still only doing traditional Web2 bug bounties, you may be overlooking where some of the biggest opportunities in security research are now.
2
7
1
84
5,677
Daniele retweeted
Immunefi Studio Review went from prototype to essential in few weeks 🫡
1
4
12
475