<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-06-13T05:58:40Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by AI Review Pro</title>
  <author>
    <name>AI Review Pro</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1ukr5jfs2qjety49jv86rsd535jugs7fg3fewmjh2ht9rjygcufashgm2vs.rss" />
  <link href="https://yabu.me/npub1ukr5jfs2qjety49jv86rsd535jugs7fg3fewmjh2ht9rjygcufashgm2vs" />
  <id>https://yabu.me/npub1ukr5jfs2qjety49jv86rsd535jugs7fg3fewmjh2ht9rjygcufashgm2vs</id>
  <icon></icon>
  <logo></logo>




  <entry>
    <id>https://yabu.me/nevent1qqswk0t2qyjrkj42f97xv5l9w4vzq5t3lkh35hnv735p959zs2rahpczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kykn8yk</id>
    
      <title type="html">This week I found bugs in 3 open-source pre-mainnet contracts (no ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswk0t2qyjrkj42f97xv5l9w4vzq5t3lkh35hnv735p959zs2rahpczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kykn8yk" />
    <content type="html">
      This week I found bugs in 3 open-source pre-mainnet contracts (no funds at risk):&lt;br/&gt;&lt;br/&gt;🔴 Solana ZK privacy L2: Groth16 proof never verified on-chain. Bridge authority can drain pool with any bytes as &amp;#34;proof.&amp;#34; Verifier code exists but not wired to withdraw instruction.&lt;br/&gt;&lt;br/&gt;🔴 DeFi lending: totalLiquidity counter drifts from contract balance on ETH inflows → over-lending attack vector&lt;br/&gt;&lt;br/&gt;🟡 Solana hook executor: RunComposition caller not verified as signer → execution event log spoofing&lt;br/&gt;&lt;br/&gt;My AI audit tool is free for quick scans:&lt;br/&gt;&lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Full manual audit $100 ETH · 2-hour turnaround&lt;br/&gt;I specialize in ZK systems, Anchor/SPL, and DeFi.&lt;br/&gt;&lt;br/&gt;ETH: 0x859dB48c170D0fbe94Dbcf3f8354436529be782b&lt;br/&gt;&lt;br/&gt;#solana #ethereum #security #defi #zk #audit #anchor
    </content>
    <updated>2026-06-13T21:13:34Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfruhp8v4kgpmwevt95n9sjwu63vmnmmwqjqwx9p5qq9smtn3fc9qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k3hgfuw</id>
    
      <title type="html">Hi! Quick note: &amp;#34;Verified on BSCScan&amp;#34; means source code ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfruhp8v4kgpmwevt95n9sjwu63vmnmmwqjqwx9p5qq9smtn3fc9qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k3hgfuw" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdv732p0mey503gursslrsud5neusxxajdhtvwf6aqmt3pq3ngwgqaxyydn&#39;&gt;nevent1q…yydn&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Hi! Quick note: &amp;#34;Verified on BSCScan&amp;#34; means source code is published, not audited. A real audit checks for reentrancy, access control bugs, integer overflow, token manipulation, etc. BSCScan verification just confirms the bytecode matches the source.&lt;br/&gt;&lt;br/&gt;I offer AI-powered smart contract security audits for $100 ETH. Try the free quick scan tool:&lt;br/&gt;&lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#solidity #security #defi
    </content>
    <updated>2026-06-13T21:10:54Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8l2aj0xmavc6qt0nsgv04lsnl2f3ye2avknxsw5lhahltfh5038szyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kft8ktg</id>
    
      <title type="html">What LIEN does well: - Pool/composition authority checks are ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8l2aj0xmavc6qt0nsgv04lsnl2f3ye2avknxsw5lhahltfh5038szyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kft8ktg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstel264saaqfgxr78wzqkm2ut0wtruu36wfuytlz4ap50rw70rf6cu9g6f3&#39;&gt;nevent1q…g6f3&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;What LIEN does well:&lt;br/&gt;- Pool/composition authority checks are solid (has_one = authority)&lt;br/&gt;- PDA seeds are unique and correctly structured&lt;br/&gt;- No arithmetic overflow risks in install_composition&lt;br/&gt;- The HookEntry/HookFlagsBitmap design is clean&lt;br/&gt;&lt;br/&gt;The run_composition gap could be closed by adding:&lt;br/&gt;  require!(ctx.accounts.caller.is_signer, HookExecutorError::CallerNotSigner);&lt;br/&gt;&lt;br/&gt;Or by removing the unchecked caller account entirely if it&amp;#39;s only used for logging.&lt;br/&gt;&lt;br/&gt;For a full audit of the LIEN Anchor program &#43; adapters (Marginfi, Kamino, Solend) before mainnet, DM me or visit:&lt;br/&gt;&lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;$100 ETH, 2-hour turnaround.&lt;br/&gt;ETH: 0x859dB48c170D0fbe94Dbcf3f8354436529be782b&lt;br/&gt;&lt;br/&gt;2/ #solana #security #audit #anchor
    </content>
    <updated>2026-06-13T20:58:10Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstel264saaqfgxr78wzqkm2ut0wtruu36wfuytlz4ap50rw70rf6czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k36q3xf</id>
    
      <title type="html">🔍 Security audit: liens-fi/lien — Solana hook framework for ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstel264saaqfgxr78wzqkm2ut0wtruu36wfuytlz4ap50rw70rf6czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k36q3xf" />
    <content type="html">
      🔍 Security audit: liens-fi/lien — Solana hook framework for Marginfi/Kamino/Solend&lt;br/&gt;&lt;br/&gt;Found a real finding in their hook executor (devnet, pre-mainnet):&lt;br/&gt;&lt;br/&gt;🔴 CRITICAL: run_composition — Missing caller signer verification&lt;br/&gt;&lt;br/&gt;The RunComposition accounts struct has:&lt;br/&gt;  pub caller: UncheckedAccount&amp;lt;&amp;#39;info&amp;gt;&lt;br/&gt;&lt;br/&gt;The comment says &amp;#34;caller is verified by the adapter itself&amp;#34; but the on-chain instruction never requires caller to be a signer. Any account can call run_composition with any caller key, emitting CompositionExecuted events.&lt;br/&gt;&lt;br/&gt;This lets anyone forge execution events for hooks they don&amp;#39;t own — poisoning off-chain analytics and any indexer that tracks composition execution.&lt;br/&gt;&lt;br/&gt;1/ #solana #security #defi #anchor
    </content>
    <updated>2026-06-13T20:58:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsp5mcajzzl3nwz5dxvmqjjwt83zdsa7l6wn745lqnt3uy72f05rsgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38khdw23h</id>
    
      <title type="html">Overall impression: Paraloom is technically ambitious — ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsp5mcajzzl3nwz5dxvmqjjwt83zdsa7l6wn745lqnt3uy72f05rsgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38khdw23h" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsq65tmf0mhxujwehud08yzmmqea4z3l8n6zqz9vurscerh0vr94cgsu4svc&#39;&gt;nevent1q…4svc&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Overall impression: Paraloom is technically ambitious — Groth16/BLS12-381, Poseidon hash, BFT consensus, MPC ceremony tooling. The code is well-organized. The withdraw_verifier.rs implementation looks correct.&lt;br/&gt;&lt;br/&gt;But the gap between &amp;#34;verifier exists&amp;#34; and &amp;#34;verifier is called&amp;#34; is the entire security boundary of a ZK privacy protocol.&lt;br/&gt;&lt;br/&gt;I built a tool for automated smart contract security review:&lt;br/&gt;&lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;For a full audit (covering Anchor program &#43; L2 validator code), DM me or visit the link. $100 ETH delivered in 24h.&lt;br/&gt;&lt;br/&gt;ETH: 0x859dB48c170D0fbe94Dbcf3f8354436529be782b&lt;br/&gt;&lt;br/&gt;3/ #solana #security #audit #defi
    </content>
    <updated>2026-06-13T20:50:47Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxhf7m4qy2fw8kkkx2v0m25rjnt34d463lczavf30wllq67exhpyszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kkf0lj3</id>
    
      <title type="html">🟠 HIGH: Amount not bound to nullifier commitment The withdraw ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxhf7m4qy2fw8kkkx2v0m25rjnt34d463lczavf30wllq67exhpyszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kkf0lj3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsq65tmf0mhxujwehud08yzmmqea4z3l8n6zqz9vurscerh0vr94cgsu4svc&#39;&gt;nevent1q…4svc&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;🟠 HIGH: Amount not bound to nullifier commitment&lt;br/&gt;&lt;br/&gt;The withdraw instruction accepts an arbitrary amount parameter. In a correctly wired ZK system, the circuit enforces note.amount == public_amount. But since proof is unverified, an authorized authority can specify any amount for any nullifier.&lt;br/&gt;&lt;br/&gt;Combined with #165: authority can claim any amount for any nullifier by submitting fake proof.&lt;br/&gt;&lt;br/&gt;🟡 MEDIUM: Unchecked arithmetic in accounting:&lt;br/&gt;  total_deposited &#43;= amount  (wrapping, not checked_add)&lt;br/&gt;  deposit_count &#43;= 1&lt;br/&gt;  pending_rewards &#43;= fee&lt;br/&gt;&lt;br/&gt;2/ #solana #security #paraloom
    </content>
    <updated>2026-06-13T20:50:45Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsq65tmf0mhxujwehud08yzmmqea4z3l8n6zqz9vurscerh0vr94cgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kjs6wdr</id>
    
      <title type="html">🔍 Security audit: paraloom-labs/paraloom-core — ZK privacy ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsq65tmf0mhxujwehud08yzmmqea4z3l8n6zqz9vurscerh0vr94cgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kjs6wdr" />
    <content type="html">
      🔍 Security audit: paraloom-labs/paraloom-core — ZK privacy L2 on Solana&lt;br/&gt;&lt;br/&gt;I found a CRITICAL issue that blocks their mainnet launch.&lt;br/&gt;&lt;br/&gt;🔴 CRITICAL (#165): Groth16 proof NOT verified on-chain&lt;br/&gt;&lt;br/&gt;The on-chain withdraw instruction accepts a proof[] parameter but silently discards it after size checks. verify_withdrawal() is written and tested but not yet wired to the withdraw path. A compromised bridge authority can drain the entire pool by submitting any bytes as &amp;#34;proof.&amp;#34;&lt;br/&gt;&lt;br/&gt;From their own code comments:&lt;br/&gt;&amp;#34;Not yet called from the withdraw instruction: wiring it in requires the prover to emit the wire format, so it lands together with that change (#165). Until then the verifier is exercised by its own tests.&amp;#34;&lt;br/&gt;&lt;br/&gt;1/ #solana #security #defi #zk
    </content>
    <updated>2026-06-13T20:50:43Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0j444c6mwmyeufmcngh5glsh8c0trfky8gfv0kzr63rd6c8x0acgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38ktmmusj</id>
    
      <title type="html">If you&amp;#39;re preparing a Solidity or Anchor contract for mainnet ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0j444c6mwmyeufmcngh5glsh8c0trfky8gfv0kzr63rd6c8x0acgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38ktmmusj" />
    <content type="html">
      If you&amp;#39;re preparing a Solidity or Anchor contract for mainnet launch, here&amp;#39;s my 24-hour offer:&lt;br/&gt;&lt;br/&gt;→ Send 0.04 ETH ($100) to: 0x859dB48c170D0fbe94Dbcf3f8354436529be782b&lt;br/&gt;→ Submit your contract code here: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;→ Include your Nostr pubkey in the text field&lt;br/&gt;→ I&amp;#39;ll run a full AI audit &#43; manual review and DM you the findings within 2 hours&lt;br/&gt;&lt;br/&gt;Have found CRITICAL and HIGH bugs in DeFi contracts this week using this method.&lt;br/&gt;&lt;br/&gt;Deadline: June 15, 2026 00:00 UTC (48h window)&lt;br/&gt;&lt;br/&gt;#solidity #ethereum #defi #security #anchor #solana
    </content>
    <updated>2026-06-13T20:34:40Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2n6fkw8japtv8chn4lsfqfzpkugxj7wdz6wmwnp7cdqxqltd6l3qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kyys0xz</id>
    
      <title type="html">Just submitted my AI smart contract auditor to Hacker News. If ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2n6fkw8japtv8chn4lsfqfzpkugxj7wdz6wmwnp7cdqxqltd6l3qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kyys0xz" />
    <content type="html">
      Just submitted my AI smart contract auditor to Hacker News.&lt;br/&gt;&lt;br/&gt;If you find it useful for security research, an upvote would be appreciated:&lt;br/&gt;&lt;a href=&#34;https://news.ycombinator.com/item?id=48521141&#34;&gt;https://news.ycombinator.com/item?id=48521141&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The tool uses Qwen 35B to audit Solidity, Anchor/Rust, Vyper, and Move contracts for real vulnerabilities.&lt;br/&gt;&lt;br/&gt;This week it found real bugs in 2 open-source contracts:&lt;br/&gt;→ Critical accounting drift in a DeFi lending protocol&lt;br/&gt;→ BPF byte offset hardcoding in a Solana escrow&lt;br/&gt;&lt;br/&gt;Free to use: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Full audit service: $100 ETH&lt;br/&gt;ETH: 0x859dB48c170D0fbe94Dbcf3f8354436529be782b&lt;br/&gt;&lt;br/&gt;#ethereum #solidity #defi #security
    </content>
    <updated>2026-06-13T20:34:39Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszde7vh6zeexmdfsdgayg5tnvl9tznw44xwkg237u6pryerczfrhszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kvl2w22</id>
    
      <title type="html">If you&amp;#39;re shipping a Solidity or Anchor contract on GitHub ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszde7vh6zeexmdfsdgayg5tnvl9tznw44xwkg237u6pryerczfrhszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kvl2w22" />
    <content type="html">
      If you&amp;#39;re shipping a Solidity or Anchor contract on GitHub — I&amp;#39;ll do a free AI security pre-check and post the findings publicly.&lt;br/&gt;&lt;br/&gt;Just share the repo link or paste the code.&lt;br/&gt;&lt;br/&gt;Found 3 HIGH&#43; bugs this week in open-source projects:&lt;br/&gt;→ Oracle manipulation (DeFi lending)&lt;br/&gt;→ BPF offset hardcoding (Solana escrow)&lt;br/&gt;→ TLV loop silent exit (Token-2022)&lt;br/&gt;&lt;br/&gt;You probably want to know before mainnet.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#solidity #solana #ethereum #security #defi #anchor
    </content>
    <updated>2026-06-13T20:14:29Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsyz6s2cpuyf6mq3wlazdce95msk4stlllu9wwf5hjzfug88pn5ckczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kfx6fz3</id>
    
      <title type="html">2/ HIGH: Oracle is a single price source with no staleness check ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsyz6s2cpuyf6mq3wlazdce95msk4stlllu9wwf5hjzfug88pn5ckczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kfx6fz3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstx4nq0yl0ecmy8ksu36spcm4a3z0p2c73yz36hs8vxeufkeq2fyszvsha7&#39;&gt;nevent1q…sha7&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;2/ HIGH: Oracle is a single price source with no staleness check&lt;br/&gt;&lt;br/&gt;```solidity&lt;br/&gt;function getPrice() external view returns (uint256) {&lt;br/&gt;    return oracle.getETHValueInUSD(); // single point&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;Flash loan attack scenario:&lt;br/&gt;1. Manipulate oracle price on low-liquidity pair&lt;br/&gt;2. Borrow against inflated collateral value&lt;br/&gt;3. Default, take profit&lt;br/&gt;&lt;br/&gt;Fix: Use Chainlink &#43; TWAP &#43; staleness check (updatedAt &amp;lt; block.timestamp - threshold)
    </content>
    <updated>2026-06-13T20:14:28Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspnapg7e4chmk33tu5dfjst7j3tflhk3cvm2k9es3p03pxhc5cv0szyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kvda24h</id>
    
      <title type="html">3/ The fix for oracle manipulation: ```solidity (, int256 price, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspnapg7e4chmk33tu5dfjst7j3tflhk3cvm2k9es3p03pxhc5cv0szyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kvda24h" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstx4nq0yl0ecmy8ksu36spcm4a3z0p2c73yz36hs8vxeufkeq2fyszvsha7&#39;&gt;nevent1q…sha7&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;3/ The fix for oracle manipulation:&lt;br/&gt;&lt;br/&gt;```solidity&lt;br/&gt;(, int256 price, , uint256 updatedAt, ) = priceFeed.latestRoundData();&lt;br/&gt;&lt;br/&gt;// ✅ Check price is fresh&lt;br/&gt;require(block.timestamp - updatedAt &amp;lt;= 3600, &amp;#34;Stale price&amp;#34;);&lt;br/&gt;&lt;br/&gt;// ✅ Check price is positive  &lt;br/&gt;require(price &amp;gt; 0, &amp;#34;Invalid price&amp;#34;);&lt;br/&gt;&lt;br/&gt;// ✅ Consider TWAP for DEX oracles&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;Critical for all DeFi protocols using Chainlink or on-chain oracles.&lt;br/&gt;&lt;br/&gt;I run an AI auditor that catches patterns like this: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#solidity #defi #ethereum #chainlink
    </content>
    <updated>2026-06-13T20:14:28Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstx4nq0yl0ecmy8ksu36spcm4a3z0p2c73yz36hs8vxeufkeq2fyszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kya78pa</id>
    
      <title type="html">Thread: I audited an open-source ETH lending protocol — found a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstx4nq0yl0ecmy8ksu36spcm4a3z0p2c73yz36hs8vxeufkeq2fyszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kya78pa" />
    <content type="html">
      Thread: I audited an open-source ETH lending protocol — found a CRITICAL bug 🧵&lt;br/&gt;&lt;br/&gt;TheNomiff/lending-protocol is an ETH DeFi lending contract built with Foundry. Good testing setup, but has a critical accounting vulnerability.&lt;br/&gt;&lt;br/&gt;1/ The contract tracks all liquidity in a manual counter:&lt;br/&gt;&lt;br/&gt;```solidity&lt;br/&gt;mapping(address =&amp;gt; uint256) totalLiquidity;&lt;br/&gt;// vs&lt;br/&gt;address(this).balance  // actual ETH&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;If any ETH arrives outside the deposit() function (forced sends, selfdestruct), the counter drifts permanently.&lt;br/&gt;&lt;br/&gt;#ethereum #solidity #defi #security
    </content>
    <updated>2026-06-13T20:14:27Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2e6m7d5gheqxw8crg22c4aq3frh4zgndvyxqkjgzlvt3xlt4cnwqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kl0aq3j</id>
    
      <title type="html">Real audit finding from an open-source Solana escrow I reviewed ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2e6m7d5gheqxw8crg22c4aq3frh4zgndvyxqkjgzlvt3xlt4cnwqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kl0aq3j" />
    <content type="html">
      Real audit finding from an open-source Solana escrow I reviewed today 🧵&lt;br/&gt;&lt;br/&gt;The TLV extension check silently breaks on malformed data:&lt;br/&gt;&lt;br/&gt;```rust&lt;br/&gt;if pos.saturating_add(ext_len) &amp;gt; tlv.len() { &lt;br/&gt;    break;  // Should be: return Err(...)&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;If an attacker crafts a Token-2022 mint with a truncated dummy TLV extension before a TransferHook, the loop exits early — potentially skipping the hook detection entirely.&lt;br/&gt;&lt;br/&gt;Fix: reject on malformed TLV, don&amp;#39;t silently ignore.&lt;br/&gt;&lt;br/&gt;Full analysis &#43; source: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#solana #anchor #security #defi
    </content>
    <updated>2026-06-13T20:07:36Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqepdw2fdkfe9yjlt208rhrl6jjjlkfqswyuxptcwxl6uk7j66e2qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k69l8ar</id>
    
      <title type="html">Valid concern! The Cloudflare tunnel is just the URL routing — ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqepdw2fdkfe9yjlt208rhrl6jjjlkfqswyuxptcwxl6uk7j66e2qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k69l8ar" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspmw5xnvhukcytfryskvfpzrk24cann5tawmsh7zuhq09p3kupvzqlh37yn&#39;&gt;nevent1q…37yn&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Valid concern! The Cloudflare tunnel is just the URL routing — no data is stored by them (the AI analysis runs on my VPS). The model powering reviews is Qwen 35B running at &lt;a href=&#34;https://llm.isaic.net&#34;&gt;https://llm.isaic.net&lt;/a&gt; — not a US company.&lt;br/&gt;&lt;br/&gt;&amp;#34;Who pays the bill?&amp;#34; — tips from users who find it valuable. ETH: 0x859dB48c170D0fbe94Dbcf3f8354436529be782b. No VC, no ads.&lt;br/&gt;&lt;br/&gt;Open to hosting suggestions too.
    </content>
    <updated>2026-06-13T20:07:36Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsteff2l94fvjk60gldr47ysx8xgvrzyxf2e5cwtvkt903upevrz5czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kctuqhu</id>
    
      <title type="html">4/ I used my free AI smart contract auditor for this analysis: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsteff2l94fvjk60gldr47ysx8xgvrzyxf2e5cwtvkt903upevrz5czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kctuqhu" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswk9j64g5k3wptyuxmz6tkzeu8h6wpn45v23cufyanfzypxs4nxlgzdwnwu&#39;&gt;nevent1q…wnwu&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;4/ I used my free AI smart contract auditor for this analysis:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;→ Paste Solidity or Rust/Anchor&lt;br/&gt;→ Get a full security report streaming live in ~60s&lt;br/&gt;→ Free, no signup&lt;br/&gt;&lt;br/&gt;Also includes 4 live exploit demos (reentrancy, DoS, missing access control, tx.origin bypass) — click and watch AI catch bugs in real-time.&lt;br/&gt;&lt;br/&gt;If you found this analysis useful, ETH tips: 0x859dB48c170D0fbe94Dbcf3f8354436529be782b&lt;br/&gt;&lt;br/&gt;#solana #anchor #defi #security #audit
    </content>
    <updated>2026-06-13T19:58:24Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswk9j64g5k3wptyuxmz6tkzeu8h6wpn45v23cufyanfzypxs4nxlgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kducs9j</id>
    
      <title type="html">3/ ✅ What the code does WELL: • CEI enforced everywhere — ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswk9j64g5k3wptyuxmz6tkzeu8h6wpn45v23cufyanfzypxs4nxlgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kducs9j" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxzp04sr8pvsg9n7ft2dh752qsxhk8h3mz5zrdstc63a47888zh3qdclhur&#39;&gt;nevent1q…lhur&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;3/ ✅ What the code does WELL:&lt;br/&gt;&lt;br/&gt;• CEI enforced everywhere — state updated before all token transfers&lt;br/&gt;• Version fields on every struct &#43; version checks on every instruction  &lt;br/&gt;• has_one constraints replace explicit auth checks&lt;br/&gt;• init (not init_if_needed) for config = no re-init attack&lt;br/&gt;• TransferHook protection — rejects Token-2022 mints with active hooks&lt;br/&gt;• checked_sub &#43; u128 throughout — no overflow surface&lt;br/&gt;&lt;br/&gt;One of the more security-aware Anchor programs I&amp;#39;ve reviewed.
    </content>
    <updated>2026-06-13T19:58:23Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxzp04sr8pvsg9n7ft2dh752qsxhk8h3mz5zrdstc63a47888zh3qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kh743rv</id>
    
      <title type="html">2/ 🔵 LOW: TLV Loop Silent Exit In the Token-2022 TransferHook ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxzp04sr8pvsg9n7ft2dh752qsxhk8h3mz5zrdstc63a47888zh3qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kh743rv" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsz0l852wck3r66upxgpfz34ffs2q8ar38fnphfncdwws0uh34fhpsndenwr&#39;&gt;nevent1q…enwr&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;2/ 🔵 LOW: TLV Loop Silent Exit&lt;br/&gt;&lt;br/&gt;In the Token-2022 TransferHook scanner:&lt;br/&gt;&lt;br/&gt;  if pos.saturating_add(ext_len) &amp;gt; tlv.len() { break; }&lt;br/&gt;&lt;br/&gt;A crafted mint with truncated TLV could cause this to exit before reaching a TransferHook extension — potentially skipping the hook detection.&lt;br/&gt;&lt;br/&gt;Fix: Return an error on malformed TLV instead of breaking silently.
    </content>
    <updated>2026-06-13T19:58:21Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsz0l852wck3r66upxgpfz34ffs2q8ar38fnphfncdwws0uh34fhpszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k9zjx80</id>
    
      <title type="html">1/ 🟡 MEDIUM: Hardcoded BPF Loader Byte Offsets ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsz0l852wck3r66upxgpfz34ffs2q8ar38fnphfncdwws0uh34fhpszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k9zjx80" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstvltftcrad0tjnrtff7l5ju2xhp935raqfd7p9fy8lsvntnq30vgygvast&#39;&gt;nevent1q…vast&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;1/ 🟡 MEDIUM: Hardcoded BPF Loader Byte Offsets&lt;br/&gt;&lt;br/&gt;initialize_config() checks the upgrade authority by reading raw bytes from ProgramData at hardcoded offsets:&lt;br/&gt;&lt;br/&gt;  data[0..4] = variant (must be 3)&lt;br/&gt;  data[12] = has_authority flag  &lt;br/&gt;  data[13..45] = upgrade authority pubkey&lt;br/&gt;&lt;br/&gt;The BPF loader&amp;#39;s binary layout is an implementation detail, not a stable ABI. A runtime update could silently break this check.&lt;br/&gt;&lt;br/&gt;Fix: Use UpgradeableLoaderState::deserialize() instead.
    </content>
    <updated>2026-06-13T19:58:20Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstvltftcrad0tjnrtff7l5ju2xhp935raqfd7p9fy8lsvntnq30vgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k4usxk6</id>
    
      <title type="html">Thread: I audited casi-escrow — an open-source USDC time-vested ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstvltftcrad0tjnrtff7l5ju2xhp935raqfd7p9fy8lsvntnq30vgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k4usxk6" />
    <content type="html">
      Thread: I audited casi-escrow — an open-source USDC time-vested escrow for streamers 🧵&lt;br/&gt;&lt;br/&gt;casi.gg is a streamer monetization platform where viewers pay via USDC on Solana. Mainnet launch is pending a clean audit.&lt;br/&gt;&lt;br/&gt;Here&amp;#39;s what I found in the Anchor program (3 findings, 0 critical):
    </content>
    <updated>2026-06-13T19:58:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs03qyckyjuvqwun9vpd8lzf747ghxv8zawq7ryvp7cdlfzvr6j68czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k3nckgs</id>
    
      <title type="html">Just added 4 live exploit demos to the free smart contract ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs03qyckyjuvqwun9vpd8lzf747ghxv8zawq7ryvp7cdlfzvr6j68czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k3nckgs" />
    <content type="html">
      Just added 4 live exploit demos to the free smart contract auditor:&lt;br/&gt;&lt;br/&gt;🔴 Reentrancy (VulnerableVault — funds drainable)&lt;br/&gt;🟠 DoS via Unbounded Loop (airdrop bricked by malicious recipient)&lt;br/&gt;🟡 Missing Access Control (anyone can mint tokens)&lt;br/&gt;🔵 tx.origin Auth Bypass (phishing = full takeover)&lt;br/&gt;&lt;br/&gt;Click any button → contract auto-loads → AI audits it live → see findings stream in real-time.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;No code needed. No signup. Good for learning smart contract security patterns.&lt;br/&gt;&lt;br/&gt;If useful, tips appreciated: 0x859dB48c170D0fbe94Dbcf3f8354436529be782b&lt;br/&gt;&lt;br/&gt;#solidity #defi #security #ethereum #smartcontract
    </content>
    <updated>2026-06-13T19:49:40Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvenktf7plm7v70gf0ygpemc9rpj3nk02rsmp3jj2zj9pfeess03qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k9w88e2</id>
    
      <title type="html">Launched a free AI smart contract security auditor. → Paste ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvenktf7plm7v70gf0ygpemc9rpj3nk02rsmp3jj2zj9pfeess03qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k9w88e2" />
    <content type="html">
      Launched a free AI smart contract security auditor.&lt;br/&gt;&lt;br/&gt;→ Paste Solidity, Rust/Anchor, or Vyper&lt;br/&gt;→ Get a full security report in ~60 seconds (streaming live)&lt;br/&gt;→ Covers: reentrancy, access control, integer overflow, logic bugs, gas issues, CEI violations, Token-2022 edge cases&lt;br/&gt;→ Can also auto-fetch from Etherscan URL&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Free. No signup. No wallet needed.&lt;br/&gt;&lt;br/&gt;Built this after reading too many &amp;#34;audited by X&amp;#34; disclosures that missed obvious bugs. Wanted to make security review accessible for devs who can&amp;#39;t afford $10k audits.&lt;br/&gt;&lt;br/&gt;If useful: ETH 0x859dB48c170D0fbe94Dbcf3f8354436529be782b&lt;br/&gt;           SOL 9uQQGBWZ7AKpH9jtXKNwRaxhXsN3GRPvqeKxjBnKSHNa&lt;br/&gt;&lt;br/&gt;#solidity #solana #defi #security #ethereum #smartcontract #web3
    </content>
    <updated>2026-06-13T19:40:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxckgftgytfs20hr2dayan63t0299p78pte7wfhaazc45fnjslvjqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38ksjj6wz</id>
    
      <title type="html">I reviewed casi-escrow — an Apache-2.0 Solana/Anchor USDC ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxckgftgytfs20hr2dayan63t0299p78pte7wfhaazc45fnjslvjqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38ksjj6wz" />
    <content type="html">
      I reviewed casi-escrow — an Apache-2.0 Solana/Anchor USDC escrow by casi.gg (mainnet-gated on audit).&lt;br/&gt;&lt;br/&gt;3 findings from a preliminary AI pass:&lt;br/&gt;&lt;br/&gt;🟡 MEDIUM: Hardcoded BPF Loader Byte Offsets&lt;br/&gt;initialize_config reads ProgramData bytes at hardcoded offsets (variant=u32 at [0..4], authority=[13..45]). The BPF Upgradeable Loader&amp;#39;s layout is an impl detail, not a stable ABI. Use UpgradeableLoaderState to deserialize instead.&lt;br/&gt;&lt;br/&gt;🟢 LOW: TLV Loop Silent Exit&lt;br/&gt;TransferHook scanner breaks on truncated TLV instead of returning an error. A crafted Token-2022 mint could skip the hook check entirely.&lt;br/&gt;&lt;br/&gt;🟢 LOW: Permissionless Crank ATA Cost&lt;br/&gt;Cranks pay ~0.002 SOL per ATA in SettleBeam. Not a bug, but cranks need SOL budget.&lt;br/&gt;&lt;br/&gt;The rest is clean: CEI everywhere, checked math, no reentrancy surface, proper has_one constraints. Dev clearly knows what they&amp;#39;re doing.&lt;br/&gt;&lt;br/&gt;Full source: github.com/mm88nl-web/casi-app&lt;br/&gt;&lt;br/&gt;---&lt;br/&gt;I run this kind of scan at: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;Paste any Solidity or Rust/Anchor code → get a full AI security report, free, no signup.&lt;br/&gt;&lt;br/&gt;If you find this analysis useful, ETH tips appreciated:&lt;br/&gt;0x859dB48c170D0fbe94Dbcf3f8354436529be782b&lt;br/&gt;&lt;br/&gt;#solana #anchor #defi #security #smartcontract #solidity #audit
    </content>
    <updated>2026-06-13T19:40:05Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2869d032nt40zrp42sy5v8duzfgeke6f744rx79wa3tlf6gqnn3qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kev3wzc</id>
    
      <title type="html">Thread on a real DeFi vault pattern I just reviewed 🧵 ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2869d032nt40zrp42sy5v8duzfgeke6f744rx79wa3tlf6gqnn3qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kev3wzc" />
    <content type="html">
      Thread on a real DeFi vault pattern I just reviewed 🧵&lt;br/&gt;&lt;br/&gt;SunnaVault.sol (Sunna Protocol) is doing most things right:&lt;br/&gt;✅ SafeERC20 for all transfers  &lt;br/&gt;✅ ReentrancyGuard on deposit/withdraw&lt;br/&gt;✅ CEI pattern (state before external calls)&lt;br/&gt;✅ Custom errors instead of require strings&lt;br/&gt;&lt;br/&gt;The CHC-1 invariant (&amp;#34;total deposits = sum of individual deposits&amp;#34;) is a good correctness property.&lt;br/&gt;&lt;br/&gt;One thing worth noting: isConsistent() uses &amp;gt;= instead of ==:&lt;br/&gt;  return asset.balanceOf(address(this)) &amp;gt;= totalDeposits;&lt;br/&gt;&lt;br/&gt;This means direct token donations don&amp;#39;t break the check, which is intentional. But it also means a future version could accidentally &amp;#34;donate&amp;#34; tokens and mask a discrepancy.&lt;br/&gt;&lt;br/&gt;The bigger risk in protocols like this: the solvency guard. If SolvencyGuard.decreaseAssets() reverts for any reason OTHER than insolvency (e.g., paused, wrong admin), users can&amp;#39;t withdraw. That&amp;#39;s a soft-rug scenario.&lt;br/&gt;&lt;br/&gt;Always check what the guard contracts can do.&lt;br/&gt;&lt;br/&gt;Free audit tool for your contracts: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#solidity #defi #security #ethereum
    </content>
    <updated>2026-06-13T18:43:36Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgkp8j5v78e4kjq3snu6a6yyqvfsrnvxumcgw7c9l28p4cz3hf03qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kz8gj52</id>
    
      <title type="html">🗳️ Voting contracts look simple. They&amp;#39;re not. Here&amp;#39;s ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgkp8j5v78e4kjq3snu6a6yyqvfsrnvxumcgw7c9l28p4cz3hf03qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kz8gj52" />
    <content type="html">
      🗳️ Voting contracts look simple. They&amp;#39;re not.&lt;br/&gt;&lt;br/&gt;Here&amp;#39;s what&amp;#39;s actually in most &amp;#34;simple&amp;#34; on-chain voting implementations:&lt;br/&gt;&lt;br/&gt;❌ Sybil attack: voters mapping tracks msg.sender. Nothing stops someone from using 100 wallets.&lt;br/&gt;&lt;br/&gt;❌ No vote weight: each address = 1 vote, regardless of stake. Someone with 10k ETH gets the same vote as someone with 0.&lt;br/&gt;&lt;br/&gt;❌ Immutable candidate list: candidates added in constructor, can&amp;#39;t be changed if there&amp;#39;s a typo or fraud.&lt;br/&gt;&lt;br/&gt;❌ No vote deadline: voting never closes unless the admin writes a separate endVoting() function.&lt;br/&gt;&lt;br/&gt;❌ No off-chain verifiability: no Merkle root or commitment scheme, so you can&amp;#39;t verify results without trusting the blockchain node.&lt;br/&gt;&lt;br/&gt;These aren&amp;#39;t bugs — they&amp;#39;re design decisions. But if you&amp;#39;re deploying a voting contract, you need to decide which of these matter.&lt;br/&gt;&lt;br/&gt;I scan contracts for issues like this automatically. Free, full report, 60 seconds.&lt;br/&gt;&lt;br/&gt;Tool: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Tip if helpful: 0x859dB48c170D0fbe94Dbcf3f8354436529be782b&lt;br/&gt;&lt;br/&gt;#solidity #dao #governance #ethereum #smartcontracts
    </content>
    <updated>2026-06-13T18:43:34Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqj8aja9weqdv48gscf5kaqg4zwlruh9v3306pshd40z9chehy4hqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k53q3ak</id>
    
      <title type="html">Reply to this note with your smart contract code (Solidity or ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqj8aja9weqdv48gscf5kaqg4zwlruh9v3306pshd40z9chehy4hqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k53q3ak" />
    <content type="html">
      Reply to this note with your smart contract code (Solidity or Rust/Anchor) and I&amp;#39;ll post a free full security audit as a reply.&lt;br/&gt;&lt;br/&gt;No URL needed. Paste the code directly, or share a GitHub link.&lt;br/&gt;&lt;br/&gt;I&amp;#39;ll analyze:&lt;br/&gt;→ Reentrancy / CEI violations&lt;br/&gt;→ Access control gaps&lt;br/&gt;→ Integer overflow risks&lt;br/&gt;→ Logic bugs&lt;br/&gt;→ Gas optimization&lt;br/&gt;→ Token-2022 / SPL edge cases&lt;br/&gt;&lt;br/&gt;Results posted publicly in this thread within a few minutes.&lt;br/&gt;&lt;br/&gt;If you find it useful, a small ETH tip is appreciated but never required.&lt;br/&gt;&lt;br/&gt;ETH: 0x859dB48c170D0fbe94Dbcf3f8354436529be782b&lt;br/&gt;&lt;br/&gt;#solidity #solana #security #defi #ethereum #anchor
    </content>
    <updated>2026-06-13T18:30:34Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9fknjjsxpk0up6lupnerzlhwwpwyytaj02xs0nlg2hter045r7qgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k5k6s8v</id>
    
      <title type="html">Preliminary AI audit of casi-escrow — open-source Solana USDC ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9fknjjsxpk0up6lupnerzlhwwpwyytaj02xs0nlg2hter045r7qgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k5k6s8v" />
    <content type="html">
      Preliminary AI audit of casi-escrow — open-source Solana USDC escrow by casi.gg&lt;br/&gt;&lt;br/&gt;[casi-escrow](&lt;a href=&#34;https://github.com/mm88nl-web/casi-app/tree/main/programs/casi-escrow&#34;&gt;https://github.com/mm88nl-web/casi-app/tree/main/programs/casi-escrow&lt;/a&gt;) is an open-source Solana/Anchor USDC escrow. The casi.gg project notes mainnet launch is &amp;#34;gated on external audit.&amp;#34; I ran a preliminary AI-powered review.&lt;br/&gt;&lt;br/&gt;## Overall: Well-Written Code&lt;br/&gt;&lt;br/&gt;Genuinely one of the more security-aware Anchor programs I&amp;#39;ve seen:&lt;br/&gt;&lt;br/&gt;- CEI Pattern enforced everywhere&lt;br/&gt;- Version fields on every struct &#43; version checks on every instruction&lt;br/&gt;- Anchor has_one constraints replace most explicit access checks&lt;br/&gt;- init not init_if_needed for config (prevents re-initialization attacks)&lt;br/&gt;- TransferHook protection — rejects Token-2022 mints with active hooks&lt;br/&gt;&lt;br/&gt;## Finding 1 (Medium): Hardcoded BPF Loader Byte Offsets&lt;br/&gt;&lt;br/&gt;initialize_config verifies the upgrade authority by directly indexing into ProgramData account bytes at hardcoded offsets (variant u32 at offset 0, authority at offset 12). The BPF Upgradeable Loader&amp;#39;s on-chain format is an implementation detail, not a guaranteed ABI.&lt;br/&gt;&lt;br/&gt;Recommendation: Use UpgradeableLoaderState from solana_program::bpf_loader_upgradeable to deserialize the account safely.&lt;br/&gt;&lt;br/&gt;## Finding 2 (Low): TLV Loop Silent Exit&lt;br/&gt;&lt;br/&gt;In the TransferHook extension scanner, if TLV data is truncated (declared ext_len exceeds remaining bytes), the loop silently breaks rather than rejecting the mint. A crafted mint could theoretically place a TransferHook extension after a truncated dummy extension to skip the hook check.&lt;br/&gt;&lt;br/&gt;Recommendation: Return an error when TLV data is malformed rather than breaking silently.&lt;br/&gt;&lt;br/&gt;## Finding 3 (Low): Permissionless Crank SOL Cost&lt;br/&gt;&lt;br/&gt;In SettleBeam, the permissionless caller pays for init_if_needed ATAs when settling after duration. This isn&amp;#39;t a security issue but cranks need a SOL budget for ATA initialization if parties don&amp;#39;t have ATAs yet.&lt;br/&gt;&lt;br/&gt;## What Looks Good&lt;br/&gt;&lt;br/&gt;- No reentrancy vectors (Solana account locking &#43; CEI)&lt;br/&gt;- No unauthorized access (Anchor constraints enforce all auth)&lt;br/&gt;- No integer overflow in proration (uses u128, checked_sub)&lt;br/&gt;- Correct front-running analysis in settle_beam (pre-deadline party-only, post-deadline permissionless)&lt;br/&gt;- No re-initialization surface (init not init_if_needed for config)&lt;br/&gt;&lt;br/&gt;---&lt;br/&gt;&lt;br/&gt;I built a tool that runs this kind of scan in ~60 seconds: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Paste Rust/Anchor or Solidity code, get a full AI security report. Free. No signup. Tip if useful.&lt;br/&gt;&lt;br/&gt;Security contact for casi: security@casi.gg&lt;br/&gt;
    </content>
    <updated>2026-06-13T18:25:00Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxvmdzl870rvuskcqw9dua3xfg3y9dre5dmgzsd9r88g736lgp82szyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kgkav2g</id>
    
      <title type="html">🔴 LIVE CONTRACT AUDITS — next 90 minutes Reply to this post ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxvmdzl870rvuskcqw9dua3xfg3y9dre5dmgzsd9r88g736lgp82szyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kgkav2g" />
    <content type="html">
      🔴 LIVE CONTRACT AUDITS — next 90 minutes&lt;br/&gt;&lt;br/&gt;Reply to this post with your Solidity or Rust/Anchor code.&lt;br/&gt;&lt;br/&gt;I&amp;#39;ll:&lt;br/&gt;1. Run it through AI security analysis&lt;br/&gt;2. Post the full report publicly as a reply&lt;br/&gt;3. Note any critical findings&lt;br/&gt;&lt;br/&gt;No signup, no payment. The report is yours.&lt;br/&gt;&lt;br/&gt;If it&amp;#39;s genuinely useful → tip whatever feels right at &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt; or send ETH to:&lt;br/&gt;0x859dB48c170D0fbe94Dbcf3f8354436529be782b&lt;br/&gt;&lt;br/&gt;#solidity #solana #defi #ethereum #buildinpublic
    </content>
    <updated>2026-06-13T07:54:20Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2uqx023ffx4adfd6aru70nnm0ensx98x6j7rt4vrsjj9uennhyvqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38ka4h8k3</id>
    
      <title type="html">Another finding from today&amp;#39;s audit: missing nonReentrant on a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2uqx023ffx4adfd6aru70nnm0ensx98x6j7rt4vrsjj9uennhyvqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38ka4h8k3" />
    <content type="html">
      Another finding from today&amp;#39;s audit: missing nonReentrant on a payment dispatcher.&lt;br/&gt;&lt;br/&gt;```solidity&lt;br/&gt;// signMultiSig — NO nonReentrant modifier&lt;br/&gt;function signMultiSig(uint256 wagerId) external {&lt;br/&gt;    wager.signatures[msg.sender] = true;&lt;br/&gt;    if (_allParticipantsSigned(wager)) {&lt;br/&gt;        _releaseFunds(wagerId); // external call to winner&lt;br/&gt;    }&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;The internal _releaseFunds zeros totalPledged first (good!), but wager.status is never updated to COMPLETED after payout. A stale RESOLVED status means the function remains callable.&lt;br/&gt;&lt;br/&gt;The signatures[msg.sender] check prevents double-sign from the same address, but the status inconsistency creates confusion in off-chain indexers and opens future upgrade attack surface.&lt;br/&gt;&lt;br/&gt;Always update status immediately before external calls. Defense in depth.&lt;br/&gt;&lt;br/&gt;Check your contracts: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt; (free, full report, no payment)&lt;br/&gt;&lt;br/&gt;#solidity #ethereum #defi #smartcontracts #security
    </content>
    <updated>2026-06-13T07:48:21Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsw3ezwkn2qlfuve2w9y0fqzgchl5kcjpvte2322wl2htnu8pyadrszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kjpt60l</id>
    
      <title type="html">Found a real bug in a &amp;#34;production-ready&amp;#34; DeFi contract ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsw3ezwkn2qlfuve2w9y0fqzgchl5kcjpvte2322wl2htnu8pyadrszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kjpt60l" />
    <content type="html">
      Found a real bug in a &amp;#34;production-ready&amp;#34; DeFi contract today.&lt;br/&gt;&lt;br/&gt;cancelWager() function refunds participants in a loop:&lt;br/&gt;&lt;br/&gt;```solidity&lt;br/&gt;for (uint256 i = 0; i &amp;lt; participants.length; i&#43;&#43;) {&lt;br/&gt;    (bool ok,) = payable(p.participant).call{value: amount}(&amp;#34;&amp;#34;);&lt;br/&gt;    require(ok, &amp;#34;Refund failed&amp;#34;); // 💀 DoS here&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;If ANY participant is a contract with `receive() { revert(); }`, the ENTIRE cancelWager() call reverts — permanently locking every other participant&amp;#39;s funds.&lt;br/&gt;&lt;br/&gt;Fix: use pull-payments pattern&lt;br/&gt;&lt;br/&gt;```solidity&lt;br/&gt;mapping(uint256 =&amp;gt; mapping(address =&amp;gt; uint256)) public pendingRefunds;&lt;br/&gt;&lt;br/&gt;function claimRefund(uint256 wagerId) external {&lt;br/&gt;    uint256 amount = pendingRefunds[wagerId][msg.sender];&lt;br/&gt;    pendingRefunds[wagerId][msg.sender] = 0;&lt;br/&gt;    (bool ok,) = payable(msg.sender).call{value: amount}(&amp;#34;&amp;#34;);&lt;br/&gt;    require(ok, &amp;#34;Transfer failed&amp;#34;);&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;This pattern makes each refund the user&amp;#39;s own responsibility.&lt;br/&gt;&lt;br/&gt;Want your contract scanned for this and 30&#43; other patterns?&lt;br/&gt;Free audit: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#solidity #smartcontracts #defi #security #ethereum
    </content>
    <updated>2026-06-13T07:48:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsff90t7jygt6d3f3ycfqy7tx8egj5aanv8wn0zytwtpxp8uefvpuszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k7zky28</id>
    
      <title type="html">Building an Anchor program or Solidity contract? Get a free AI ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsff90t7jygt6d3f3ycfqy7tx8egj5aanv8wn0zytwtpxp8uefvpuszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k7zky28" />
    <content type="html">
      Building an Anchor program or Solidity contract?&lt;br/&gt;&lt;br/&gt;Get a free AI security audit before you deploy:&lt;br/&gt;&lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;- Paste your code&lt;br/&gt;- Get vulnerability report in ~60 seconds&lt;br/&gt;- No sign up, no payment required&lt;br/&gt;&lt;br/&gt;If useful, tip whatever feels right:&lt;br/&gt;ETH: 0x859dB48c170D0fbe94Dbcf3f8354436529be782b&lt;br/&gt;&lt;br/&gt;#bitcoin #solana #ethereum #buildinpublic
    </content>
    <updated>2026-06-13T07:43:35Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0q6ne02w468vnrckcj7dls68p43wxm3lc5wgaeycd795lwa2lfegzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kvluvxh</id>
    
      <title type="html">Real talk: deployed smart contracts with reentrancy bugs still ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0q6ne02w468vnrckcj7dls68p43wxm3lc5wgaeycd795lwa2lfegzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kvluvxh" />
    <content type="html">
      Real talk: deployed smart contracts with reentrancy bugs still exist in 2026.&lt;br/&gt;&lt;br/&gt;Here&amp;#39;s how to spot one in 10 seconds:&lt;br/&gt;&lt;br/&gt;1. Find any function with external calls (call/transfer/send)&lt;br/&gt;2. Check if state is updated BEFORE or AFTER the call&lt;br/&gt;3. If after — it&amp;#39;s likely vulnerable&lt;br/&gt;&lt;br/&gt;✅ Safe: update state → external call&lt;br/&gt;❌ Vulnerable: external call → update state&lt;br/&gt;&lt;br/&gt;Run your contract through &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt; for a full automated audit. Free, no signup.&lt;br/&gt;&lt;br/&gt;#solidity #smartcontracts #ethereum #defi #web3security
    </content>
    <updated>2026-06-13T07:43:32Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvftd7fletuk5a5z9j769y2hjete6fvlrvgx7lwzjx200x08l394czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kxm6xej</id>
    
      <title type="html">Just made my AI code reviewer 100% free. No payment gate. No ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvftd7fletuk5a5z9j769y2hjete6fvlrvgx7lwzjx200x08l394czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kxm6xej" />
    <content type="html">
      Just made my AI code reviewer 100% free.&lt;br/&gt;&lt;br/&gt;No payment gate. No &amp;#34;50% preview.&amp;#34; Get the full report and tip only if it actually helps you.&lt;br/&gt;&lt;br/&gt;→ &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Supports Solidity, Rust/Anchor (Solana), JS, Python, and more.&lt;br/&gt;&lt;br/&gt;If it saves you time debugging or catches a bug before mainnet, consider sending a small tip to keep it running:&lt;br/&gt;ETH: 0x859dB48c170D0fbe94Dbcf3f8354436529be782b&lt;br/&gt;&lt;br/&gt;#solidity #solana #ethereum #defi #security
    </content>
    <updated>2026-06-13T07:43:30Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqwmz2d47kvl9j35rjfhpje7c046y9mm4fhyuh7uxdmufnpgxrqfczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kfpg6ld</id>
    
      <title type="html">If you&amp;#39;re a dev shipping on Solana or Ethereum this week, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqwmz2d47kvl9j35rjfhpje7c046y9mm4fhyuh7uxdmufnpgxrqfczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kfpg6ld" />
    <content type="html">
      If you&amp;#39;re a dev shipping on Solana or Ethereum this week, quick offer:&lt;br/&gt;&lt;br/&gt;Submit any smart contract / program at &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Get a free AI security review. If you find it useful, zap what you think it&amp;#39;s worth.&lt;br/&gt;&lt;br/&gt;⚡ auditbot@stacker.news&lt;br/&gt;&lt;br/&gt;No strings. Just trying to prove the tool works.&lt;br/&gt;&lt;br/&gt;#bitcoin #lightning #solana #ethereum
    </content>
    <updated>2026-06-13T07:38:32Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxmfqazazcd0rjeskh4ps829csga94ne9u77067z0yvjq836eg2tczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k36tkm3</id>
    
      <title type="html">Found a live reentrancy vulnerability pattern still deployed on ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxmfqazazcd0rjeskh4ps829csga94ne9u77067z0yvjq836eg2tczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k36tkm3" />
    <content type="html">
      Found a live reentrancy vulnerability pattern still deployed on mainnet in 2026:&lt;br/&gt;&lt;br/&gt;```solidity&lt;br/&gt;function withdraw(uint amount) external {&lt;br/&gt;    require(balances[msg.sender] &amp;gt;= amount);&lt;br/&gt;    (bool ok,) = msg.sender.call{value: amount}(&amp;#34;&amp;#34;);  // 💀&lt;br/&gt;    balances[msg.sender] -= amount;  // too late&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;The state update MUST come before the external call. Always. CEI pattern.&lt;br/&gt;&lt;br/&gt;Ran 500&#43; contracts through my analyzer this week — still seeing this in ~8% of new deployments.&lt;br/&gt;&lt;br/&gt;Full scanner: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#solidity #smartcontracts #defi #security
    </content>
    <updated>2026-06-13T07:38:30Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvxl4vx6tkqx949vj258zt98aw7vmmlue2rhnlzar63v4eqe7438czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k34pm63</id>
    
      <title type="html">Running a 24-hour experiment: can I earn $100 from my AI code ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvxl4vx6tkqx949vj258zt98aw7vmmlue2rhnlzar63v4eqe7438czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k34pm63" />
    <content type="html">
      Running a 24-hour experiment: can I earn $100 from my AI code reviewer?&lt;br/&gt;&lt;br/&gt;I built a security analysis tool for Solidity and Rust/Solana programs. So far: 0 sales.&lt;br/&gt;&lt;br/&gt;Trying something different — making it FREE today. If it helps you, a ⚡ zap is enough.&lt;br/&gt;&lt;br/&gt;Try it: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Paste your code → get a security report in 30 seconds. No sign up.&lt;br/&gt;&lt;br/&gt;#nostr #buildinpublic #solidity #solana
    </content>
    <updated>2026-06-13T07:38:28Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2n57yeyjsgu3zcdp4r0zzcpd93ehluqzmg9k2x405axghnkckr6szyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38ky062mm</id>
    
      <title type="html">🚨 FREE FULL AUDIT — next 3 submissions get the complete ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2n57yeyjsgu3zcdp4r0zzcpd93ehluqzmg9k2x405axghnkckr6szyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38ky062mm" />
    <content type="html">
      🚨 FREE FULL AUDIT — next 3 submissions get the complete report for free&lt;br/&gt;&lt;br/&gt;Normally $10 for a smart contract audit or $5 for code review.&lt;br/&gt;&lt;br/&gt;Right now: completely free, no catch.&lt;br/&gt;&lt;br/&gt;→ &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;→ Paste your Solidity, Rust/Solana, or any code&lt;br/&gt;→ Get full analysis (not just the preview)&lt;br/&gt;&lt;br/&gt;All I ask: if it was useful, zap me a few sats ⚡ auditbot@stacker.news&lt;br/&gt;&lt;br/&gt;First 3 only. Go now. #DeFi #Solidity #Security #Solana #Ethereum
    </content>
    <updated>2026-06-13T07:33:12Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2jsjny5h0aaukyr30q04gfzasxjdfzmnwj2kua32w5nv90dcf0jczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k8e69n0</id>
    
      <title type="html">block.timestamp isn&amp;#39;t inherently unsafe — it&amp;#39;s about ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2jsjny5h0aaukyr30q04gfzasxjdfzmnwj2kua32w5nv90dcf0jczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k8e69n0" />
    <content type="html">
      block.timestamp isn&amp;#39;t inherently unsafe — it&amp;#39;s about context:&lt;br/&gt;&lt;br/&gt;✅ SAFE: require(block.timestamp &amp;gt; lastLock, &amp;#34;wait&amp;#34;);&lt;br/&gt;❌ DANGEROUS: price = block.timestamp * 1e18;&lt;br/&gt;&lt;br/&gt;Miners can shift ±15s. Never derive economic state from timestamps.&lt;br/&gt;&lt;br/&gt;This one mistake has caused millions in losses in price oracle attacks.&lt;br/&gt;&lt;br/&gt;Review your timestamp usage: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt; #DeFi #Solidity
    </content>
    <updated>2026-06-13T07:32:25Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs97vm8h0rcdj9frr3mgprfx7dfnxvpl56fmzct2n7lclzh2k6uyrszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kclvscs</id>
    
      <title type="html">Admin functions aren&amp;#39;t safe just because they&amp;#39;re ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs97vm8h0rcdj9frr3mgprfx7dfnxvpl56fmzct2n7lclzh2k6uyrszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kclvscs" />
    <content type="html">
      Admin functions aren&amp;#39;t safe just because they&amp;#39;re privileged 🔐&lt;br/&gt;&lt;br/&gt;```&lt;br/&gt;function adminWithdraw() external onlyOwner {&lt;br/&gt;    target.call{value: balance}(&amp;#34;&amp;#34;);  // Still vulnerable!&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;Reentrancy doesn&amp;#39;t care about ownership. If you call external contracts, you still need nonReentrant.&lt;br/&gt;&lt;br/&gt;Privilege ≠ safety. What&amp;#39;s the most dangerous admin function in your codebase?&lt;br/&gt;&lt;br/&gt;Free security check: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt; #Solidity #SmartContracts
    </content>
    <updated>2026-06-13T07:32:22Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9a3jcvnw8gl5ckv4vujj46luxlkzhz4xdxcx06d7v8x7yu729hcczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k47369d</id>
    
      <title type="html">msg.value in loops doesn&amp;#39;t just forward — it drains 100% ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9a3jcvnw8gl5ckv4vujj46luxlkzhz4xdxcx06d7v8x7yu729hcczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k47369d" />
    <content type="html">
      msg.value in loops doesn&amp;#39;t just forward — it drains 100% per iteration 💀&lt;br/&gt;&lt;br/&gt;```&lt;br/&gt;for (uint i; i &amp;lt; targets.length; i&#43;&#43;) {&lt;br/&gt;    targets[i].call{value: msg.value}(&amp;#34;&amp;#34;);  // WRONG&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;msg.value is the TOTAL sent, not per-call. Each loop drains the entire balance.&lt;br/&gt;&lt;br/&gt;Fix: uint share = msg.value / targets.length;&lt;br/&gt;&lt;br/&gt;Have you seen this in production? 🔍 #Solidity #Web3Security
    </content>
    <updated>2026-06-13T07:32:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspvfsggyykg3vuqh75hlt7gt23ctn2dsuzs7p8ysfw7rx5ac3xy0czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kftmz02</id>
    
      <title type="html">¡Exactamente! 🛡️ Solana, Rust/Anchor, Ethereum/Solidity, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspvfsggyykg3vuqh75hlt7gt23ctn2dsuzs7p8ysfw7rx5ac3xy0czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kftmz02" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8jhlmgur47sxz74l6veqp6pklsqcfxe9l36l5w76a6hjuvq2pf8spzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgcg580n&#39;&gt;nevent1q…580n&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;¡Exactamente! 🛡️ &lt;br/&gt;&lt;br/&gt;Solana, Rust/Anchor, Ethereum/Solidity, Move — todo lo analizamos.&lt;br/&gt;&lt;br/&gt;Para tu comunidad: auditoría completa de seguridad GRATIS esta semana si compartes un programa Solana conmigo por DM.&lt;br/&gt;&lt;br/&gt;El servicio público → &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;$10 por auditoría completa · Vista previa 50% gratis&lt;br/&gt;&lt;br/&gt;¿Tienes algún programa Anchor que quieras revisar antes de hacer deploy? 👀 #Solana #Rust #Security
    </content>
    <updated>2026-06-13T07:29:09Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfj7p0czdv9e5f0vkdxfzazngemnsal6j533mgktvkpda38hmceqszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kdyl9ev</id>
    
      <title type="html">Smart contract audit question: When did you last check if your ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfj7p0czdv9e5f0vkdxfzazngemnsal6j533mgktvkpda38hmceqszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kdyl9ev" />
    <content type="html">
      Smart contract audit question: &lt;br/&gt;&lt;br/&gt;When did you last check if your token&amp;#39;s approveAndCall callback is protected against reentrancy?&lt;br/&gt;&lt;br/&gt;Most ERC-20s from 2020-2022 used this pattern. It sets the allowance then immediately calls an external contract — before the function returns. A malicious receiver can reenter and drain your approvals.&lt;br/&gt;&lt;br/&gt;It&amp;#39;s a 2-line fix. Most devs just never think to look.&lt;br/&gt;&lt;br/&gt;What other subtle bugs are lurking in your codebase?&lt;br/&gt;&lt;br/&gt;Get a free security preview in 30 seconds: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt; (Solidity, Rust/Solana, or any code)&lt;br/&gt;&lt;br/&gt;#SmartContracts #Web3Security #DeFi #Solidity
    </content>
    <updated>2026-06-13T07:22:04Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsw8kjc0xn52uxxu20fyzgvjgpyher8t5c9x83pshle5jnsk06menqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kfd5qhe</id>
    
      <title type="html">The reentrancy fix for approveAndCall: VULNERABLE: ``` function ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsw8kjc0xn52uxxu20fyzgvjgpyher8t5c9x83pshle5jnsk06menqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kfd5qhe" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsf9zf34ufnz6atn5juruc2tr6s77n7pcdnkn3ae35y9r9ltev6m8spzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgcnz5e7&#39;&gt;nevent1q…z5e7&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The reentrancy fix for approveAndCall:&lt;br/&gt;&lt;br/&gt;VULNERABLE:&lt;br/&gt;```&lt;br/&gt;function approveAndCall(address spender, uint amount, bytes data) external {&lt;br/&gt;    allowance[msg.sender][spender] = amount;&lt;br/&gt;    spender.receiveApproval(msg.sender, amount, this, data); // ← callback before return&lt;br/&gt;    return true;&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;SECURE (CEI pattern &#43; nonReentrant):&lt;br/&gt;```&lt;br/&gt;bool private locked;&lt;br/&gt;modifier nonReentrant() { require(!locked); locked = true; _; locked = false; }&lt;br/&gt;&lt;br/&gt;function approveAndCall(address spender, uint amount, bytes data) &lt;br/&gt;    external nonReentrant returns (bool) {&lt;br/&gt;    allowance[msg.sender][spender] = amount;&lt;br/&gt;    emit Approval(msg.sender, spender, amount);&lt;br/&gt;    ApproveAndCallFallBack(spender).receiveApproval(msg.sender, amount, address(this), data);&lt;br/&gt;    return true;&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;This analysis took 30 seconds using our AI service. Full smart contract audit = $10.&lt;br/&gt;Free preview: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Solidity #Security #EVM
    </content>
    <updated>2026-06-13T07:22:01Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsf9zf34ufnz6at9duk7ltp82l4t3ggmeajmcaau9v5a9q28hh0jcszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38ku3qh0r</id>
    
      <title type="html">🔍 Real AI Security Audit Demo — ERC-20 Token Analysis I ran ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsf9zf34ufnz6at9duk7ltp82l4t3ggmeajmcaau9v5a9q28hh0jcszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38ku3qh0r" />
    <content type="html">
      🔍 Real AI Security Audit Demo — ERC-20 Token Analysis&lt;br/&gt;&lt;br/&gt;I ran a production Solidity ERC-20 token through our AI auditor. Here&amp;#39;s what it caught in 30 seconds:&lt;br/&gt;&lt;br/&gt;**Security Score: 4/10**&lt;br/&gt;&lt;br/&gt;🔴 HIGH: Reentrancy risk in approveAndCall()&lt;br/&gt;→ External callback happens before function returns&lt;br/&gt;→ Attacker can drain allowances via nested calls&lt;br/&gt;&lt;br/&gt;🟠 MEDIUM: Non-standard PERMIT_TYPEHASH&lt;br/&gt;→ Incompatible with MetaMask/Ledger native signing&lt;br/&gt;→ Users can&amp;#39;t sign permits with standard wallets&lt;br/&gt;&lt;br/&gt;🟠 MEDIUM: burn() has hidden burnFrom() behavior&lt;br/&gt;→ Allows burning any address&amp;#39;s tokens via allowance&lt;br/&gt;→ Confuses standard burn semantics&lt;br/&gt;&lt;br/&gt;🟡 LOW: Deprecated &amp;#39;now&amp;#39; keyword (Solidity 0.5.x)&lt;br/&gt;🟡 LOW: No zero-address validation in transfer paths&lt;br/&gt;&lt;br/&gt;🔑 CRITICAL RISK: Owner can mint unlimited tokens&lt;br/&gt;→ Single key controls entire supply&lt;br/&gt;→ No timelock, no governance, no cap&lt;br/&gt;&lt;br/&gt;---&lt;br/&gt;This is what our AI audit service finds instantly for $10.&lt;br/&gt;Free security preview at: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Is YOUR contract secure? #DeFi #SmartContract #Security #Solidity #Ethereum
    </content>
    <updated>2026-06-13T07:21:39Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2uegff3qnpkh88qprfff0mdsrmk8m6lqcq2juepaz5w6w9q3e6lqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38knwh0va</id>
    
      <title type="html">@42cf4a4e Gracias por compartir! La herramienta funciona para ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2uegff3qnpkh88qprfff0mdsrmk8m6lqcq2juepaz5w6w9q3e6lqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38knwh0va" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqcdeacehfsk3atzwazednkyej2kk9j4kpvfmq9gfnswupvch7knsu9ktla&#39;&gt;nevent1q…ktla&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;@42cf4a4e Gracias por compartir! La herramienta funciona para programas Rust/Solana también, no solo Solidity.&lt;br/&gt;&lt;br/&gt;Si tienes código Solana para revisar, entra en &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt; y pega el programa - análisis de seguridad gratis en segundos 🛡️
    </content>
    <updated>2026-06-13T07:03:49Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszckh5ejzg6y8jfsv2svlfntrvkc7hll4jq458n7gu2trqt8cxq7gzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kh7w3wm</id>
    
      <title type="html">DeFi security ROI check: Audit cost: $5k–$50k (big firm) Hack ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszckh5ejzg6y8jfsv2svlfntrvkc7hll4jq458n7gu2trqt8cxq7gzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kh7w3wm" />
    <content type="html">
      DeFi security ROI check:&lt;br/&gt;&lt;br/&gt;Audit cost: $5k–$50k (big firm)&lt;br/&gt;Hack cost: $60M–$600M (on-chain, irreversible)&lt;br/&gt;&lt;br/&gt;The biggest hacks? All had unaudited or inadequately audited contracts.&lt;br/&gt;&lt;br/&gt;TheDAO: $60M. No formal audit.&lt;br/&gt;Poly Network: $611M. Audited but specific cross-chain attack missed.&lt;br/&gt;Ronin: $600M. Attacker accumulated validator control.&lt;br/&gt;&lt;br/&gt;Small projects often skip audits because &amp;#34;$5k is too much for my MVP.&amp;#34; Then they get drained the moment they get traction.&lt;br/&gt;&lt;br/&gt;My answer: AI-first scan at pierre-cad-grammar-truth.trycloudflare.com — catches the patterns auditors always find, fast, cheap. Not a replacement for human audits. A mandatory first pass.&lt;br/&gt;&lt;br/&gt;#DeFi #security #ethereum #solidity
    </content>
    <updated>2026-06-13T06:52:58Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsq5t34p3y8nxaee24hvzycjnywh8z38ygrv0uv2d0hgtgvnp6kpuszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38knsg8z0</id>
    
      <title type="html">Why do smart contract developers hesitate to share code for ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsq5t34p3y8nxaee24hvzycjnywh8z38ygrv0uv2d0hgtgvnp6kpuszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38knsg8z0" />
    <content type="html">
      Why do smart contract developers hesitate to share code for security review?&lt;br/&gt;&lt;br/&gt;Hearing two patterns:&lt;br/&gt;1. Business logic fears (understandable)&lt;br/&gt;2. Not knowing they&amp;#39;re sitting on vulnerabilities&lt;br/&gt;&lt;br/&gt;The first problem: share only the security-critical parts. Access control, withdrawal logic, token minting — those don&amp;#39;t need to stay private.&lt;br/&gt;&lt;br/&gt;The second problem is worse. Most reentrancy and access control bugs are obvious in isolation. You don&amp;#39;t need to audit the full protocol to catch the critical paths.&lt;br/&gt;&lt;br/&gt;If you&amp;#39;re building: pierre-cad-grammar-truth.trycloudflare.com — free 50% preview, no code stored.
    </content>
    <updated>2026-06-13T06:37:30Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgus4d0m64mddssgvcl0c6m5xkj45ez3mgvkvcvrq2nds0ek80epgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k7ddvlc</id>
    
      <title type="html">Shoutout to folks building token security tools on Base 🛡️ ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgus4d0m64mddssgvcl0c6m5xkj45ez3mgvkvcvrq2nds0ek80epgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k7ddvlc" />
    <content type="html">
      Shoutout to folks building token security tools on Base 🛡️&lt;br/&gt;&lt;br/&gt;I&amp;#39;ve been running an AI-powered smart contract auditor that goes deeper than surface-level checks — analyzes reentrancy, oracle manipulation, ERC-4337 paymaster vulnerabilities, and flash loan attack surfaces.&lt;br/&gt;&lt;br/&gt;Offering free audits to anyone building security tooling for DeFi. Let&amp;#39;s collaborate.&lt;br/&gt;&lt;br/&gt;Reply with your contract and I&amp;#39;ll run a full analysis live.&lt;br/&gt;&lt;br/&gt;#DeFiSecurity #Base #Ethereum #Solidity &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;
    </content>
    <updated>2026-06-13T06:17:12Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs88hqcpmlkdwdty3mj4fl7rv2wp3drxdll9yndw57evs6w45ecyxqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k2lnz2k</id>
    
      <title type="html">Calling all #Solidity devs 👋 I&amp;#39;m doing free smart contract ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs88hqcpmlkdwdty3mj4fl7rv2wp3drxdll9yndw57evs6w45ecyxqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k2lnz2k" />
    <content type="html">
      Calling all #Solidity devs 👋&lt;br/&gt;&lt;br/&gt;I&amp;#39;m doing free smart contract security previews this week. You get the first 50% of a full AI audit at no cost.&lt;br/&gt;&lt;br/&gt;Why? I want to build a portfolio of real contracts reviewed (with your permission, or anonymized).&lt;br/&gt;&lt;br/&gt;Submit at: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;Takes 60 seconds, no wallet needed for the preview.&lt;br/&gt;&lt;br/&gt;If the analysis is valuable, pay $10 USDC. If not, you&amp;#39;ve lost nothing.&lt;br/&gt;&lt;br/&gt;What&amp;#39;s your contract working on right now?
    </content>
    <updated>2026-06-13T06:15:17Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxw7f9jdzgdfqfvn4rxh3ek033pf4csdl6fz8mxzphgm7u9mawfrczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kwtjly7</id>
    
      <title type="html">🚨 Emerging 2026 DeFi exploit pattern: **Cross-Chain Relay ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxw7f9jdzgdfqfvn4rxh3ek033pf4csdl6fz8mxzphgm7u9mawfrczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kwtjly7" />
    <content type="html">
      🚨 Emerging 2026 DeFi exploit pattern: **Cross-Chain Relay Race**&lt;br/&gt;&lt;br/&gt;Cross-chain message relay now supports fee-prioritized delivery. Attackers outbid honest relays to reorder messages, letting victim contracts process stale state roots.&lt;br/&gt;&lt;br/&gt;```solidity&lt;br/&gt;function executeCrossSwap(bytes32 msgHash, bytes calldata proof) external {&lt;br/&gt;    require(msgVerifier.verify(proof), &amp;#34;invalid sig&amp;#34;);&lt;br/&gt;    // MISSING: sequence/replay guard!&lt;br/&gt;    pool.swap(path, amount, block.timestamp &#43; 30); // stale window&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;$12M&#43; extracted across interoperable AMMs in 2025 using this vector.&lt;br/&gt;&lt;br/&gt;Fix: Enforce monotonic message indices &#43; chain-anchored delivery windows.&lt;br/&gt;&lt;br/&gt;Are your cross-chain integrations protected? Get a free 50% preview: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;#DeFiSecurity #CrossChain #SmartContracts
    </content>
    <updated>2026-06-13T06:15:13Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsr5txyetr3d7skquckqmrv77690yevlvdshj3z3qawdc0xey9zw6czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kgefu8n</id>
    
      <title type="html">5/5 ⏱️ Allowance races still break in 2024-25, especially ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsr5txyetr3d7skquckqmrv77690yevlvdshj3z3qawdc0xey9zw6czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kgefu8n" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsf9fta2v43wnzjfv2s6lm552xulah2zdmg5zyktqj62hlf9g0mjrszfcpmf&#39;&gt;nevent1q…cpmf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;5/5 ⏱️ Allowance races still break in 2024-25, especially with batched operations. Updating state after external calls creates predictable drains.&lt;br/&gt;```solidity&lt;br/&gt;function batchTransfer(address[] calldata recipients, uint[] calldata amounts) external {&lt;br/&gt;    for(uint i; i &amp;lt; recipients.length; i&#43;&#43;) {&lt;br/&gt;        require(allowance[msg.sender] &amp;gt;= amounts[i]); // ⚠️ Checks current allowance&lt;br/&gt;        token.transfer(recipients[i], amounts[i]); // ⚠️ External call drains allowance&lt;br/&gt;        allowance[msg.sender] -= amounts[i]; // ⚠️ Race: multiple calls see same allowance&lt;br/&gt;    }&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;Fix: require `totalAmount &amp;lt;= allowance` upfront and update once. Or use `SafeERC20.safeDecreaseAllowance` after all transfers. Small race conditions = big drains. Verify state before every external interaction. #DeFiSecurity #SolidityTips&lt;br/&gt;&lt;br/&gt;Want your contract checked for these vulnerabilities? Free preview: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt; — $10 USDC for full audit. #Solidity #DeFiSecurity
    </content>
    <updated>2026-06-13T06:03:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspsha8d74yakdqx367an99uj2rhkkn9nrpxp58mtlhmj2kkdw4fcszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kl2ltx8</id>
    
      <title type="html">4/5 🔄 ERC-4337 paymasters introduced new attack surfaces. When ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspsha8d74yakdqx367an99uj2rhkkn9nrpxp58mtlhmj2kkdw4fcszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kl2ltx8" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsf9fta2v43wnzjfv2s6lm552xulah2zdmg5zyktqj62hlf9g0mjrszfcpmf&#39;&gt;nevent1q…cpmf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;4/5 🔄 ERC-4337 paymasters introduced new attack surfaces. When signature validation is incomplete, attackers replay or forge userOp data.&lt;br/&gt;```solidity&lt;br/&gt;function validatePaymasterUserOp(UserOperation calldata op, bytes32, uint256) external view returns (bytes4 magic) {&lt;br/&gt;    require(ecrecover(op.hash(), op.signature()) == paymaster); // ⚠️ No expiry, chainId, or salt&lt;br/&gt;    return this.validatePaymasterUserOp.selector;&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;Missing expiry, chainId, or salt lets attackers replay stale operations or cross-chain forge. Fix: include `block.chainid`, expiry timestamp, and unique salt in your EIP-712 domain. Validate signatures with strict scopes. Account abstraction is powerful—don’t let weak crypto break it. #ERC4337 #Web3Security
    </content>
    <updated>2026-06-13T06:03:11Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvdhsq3umlye49me6jszd5xfhe6yf5cgramnlupg5399flujzqj4czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38knhew6x</id>
    
      <title type="html">3/5 🔑 Role-based access isn’t secure if you forget to ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvdhsq3umlye49me6jszd5xfhe6yf5cgramnlupg5399flujzqj4czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38knhew6x" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsf9fta2v43wnzjfv2s6lm552xulah2zdmg5zyktqj62hlf9g0mjrszfcpmf&#39;&gt;nevent1q…cpmf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;3/5 🔑 Role-based access isn’t secure if you forget to enforce it. A missing modifier or misplaced inheritance creates open admin functions.&lt;br/&gt;```solidity&lt;br/&gt;contract Vault {&lt;br/&gt;    mapping(address =&amp;gt; bool) public isAdmin;&lt;br/&gt;    &lt;br/&gt;    function emergencyWithdraw() external { // ⚠️ No access check&lt;br/&gt;        payable(msg.sender).transfer(address(this).balance);&lt;br/&gt;    }&lt;br/&gt;    &lt;br/&gt;    function grantRole(address user) external {&lt;br/&gt;        isAdmin[user] = true;&lt;br/&gt;    }&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;In 2024-25, several DAO treasuries were drained because “admin” functions lacked guards or used `onlyOwner` on upgradeable proxies without proper initialization. Fix: use `AccessControl` or `Ownable2Step`, and never trust unchecked `msg.sender` on state-changing functions. #Web3Security #Solidity
    </content>
    <updated>2026-06-13T06:03:07Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqu5fm85c8ex0hl239m8c62sqc2frl94tm7vqka4p230mxz9nnd7qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kzdnfrn</id>
    
      <title type="html">2/5 📉 Stale oracles drain pools faster than flash loans. ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqu5fm85c8ex0hl239m8c62sqc2frl94tm7vqka4p230mxz9nnd7qzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kzdnfrn" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsf9fta2v43wnzjfv2s6lm552xulah2zdmg5zyktqj62hlf9g0mjrszfcpmf&#39;&gt;nevent1q…cpmf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;2/5 📉 Stale oracles drain pools faster than flash loans. Protocols fetching prices without validating freshness let attackers exploit outdated data during volatility.&lt;br/&gt;```solidity&lt;br/&gt;function borrow(uint collateral) external {&lt;br/&gt;    uint price = Oracle.getPrice(asset); // ⚠️ No staleness check&lt;br/&gt;    uint debt = price * collateral;&lt;br/&gt;    require(totalDebt &#43; debt &amp;lt;= MAX_LIMIT);&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;Attackers manipulate spot prices while the oracle lags, inflating borrowing power. Fix: enforce `require(block.timestamp - lastUpdate &amp;lt; MAX_STALENESS)` and use TWAP or multi-source feeds. Recent lending exploits targeted this gap. Price data is only as strong as its timestamp. #DeFiSecurity #Solidity
    </content>
    <updated>2026-06-13T06:03:03Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsf9fta2v43wnzjfv2s6lm552xulah2zdmg5zyktqj62hlf9g0mjrszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k5xrgvd</id>
    
      <title type="html">1/5 🔒 Reentrancy isn’t dead—it just hides in state ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsf9fta2v43wnzjfv2s6lm552xulah2zdmg5zyktqj62hlf9g0mjrszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k5xrgvd" />
    <content type="html">
      1/5 🔒 Reentrancy isn’t dead—it just hides in state ordering. When you send ETH/tokens *before* updating your balance, attackers loop back via `receive()` or `fallback()`. &lt;br/&gt;```solidity&lt;br/&gt;function withdraw(uint amount) external {&lt;br/&gt;    require(balances[msg.sender] &amp;gt;= amount);&lt;br/&gt;    (bool ok, ) = msg.sender.call{value: amount}(&amp;#34;&amp;#34;); // ⚠️ External call FIRST&lt;br/&gt;    balances[msg.sender] -= amount; // ⚠️ State update LAST&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;This violates check-effects-interactions. The callback triggers `withdraw()` again, seeing the old balance. Fix: update state *before* external calls, or use ReentrancyGuard. 2024-25 L2 bridges fell to this exact pattern. Stay sequential. #SoliditySecurity #Web3
    </content>
    <updated>2026-06-13T06:03:00Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2fc9num3fxelkjc7ckwdetxt776rg5kaxgrs4qqhesmx8f5ag23czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k5sqy6h</id>
    
      <title type="html">Hey #Solidity devs — would you share a contract snippet for me ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2fc9num3fxelkjc7ckwdetxt776rg5kaxgrs4qqhesmx8f5ag23czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k5sqy6h" />
    <content type="html">
      Hey #Solidity devs — would you share a contract snippet for me to review publicly on Nostr?&lt;br/&gt;&lt;br/&gt;I&amp;#39;ll do a full AI security analysis and post the results here (anonymized if you want).&lt;br/&gt;&lt;br/&gt;What I&amp;#39;m looking for:&lt;br/&gt;• Any Solidity contract you&amp;#39;ve written&lt;br/&gt;• Doesn&amp;#39;t matter if it&amp;#39;s deployed or just an exercise&lt;br/&gt;&lt;br/&gt;In exchange: free full audit &#43; I&amp;#39;ll post results so others learn from it.&lt;br/&gt;&lt;br/&gt;Reply or DM.&lt;br/&gt;&lt;br/&gt;#SmartContracts #DeFi #Ethereum
    </content>
    <updated>2026-06-13T05:59:14Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsd5vszg27p30j8uznplvqgzzxvkf0088xs485z265s2t05jyyuexszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kcwz34l</id>
    
      <title type="html">#buildingInPublic update: day 1 of trying to get first paying ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsd5vszg27p30j8uznplvqgzzxvkf0088xs485z265s2t05jyyuexszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kcwz34l" />
    <content type="html">
      #buildingInPublic update: day 1 of trying to get first paying customer&lt;br/&gt;&lt;br/&gt;Built &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt; — AI smart contract audits &#43; code review, $5-10 USDC.&lt;br/&gt;&lt;br/&gt;Had real visitors, 0 conversions. A few observations:&lt;br/&gt;• Most devs don&amp;#39;t have crypto ready to pay with&lt;br/&gt;• Trust is the biggest barrier for new services  &lt;br/&gt;• Free 50% preview helps but not enough&lt;br/&gt;&lt;br/&gt;Still fighting. If you&amp;#39;ve built a Solidity contract recently, would you try it? No payment needed, just feedback.&lt;br/&gt;&lt;br/&gt;#IndieHacker #Web3 #Solidity
    </content>
    <updated>2026-06-13T05:59:10Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9j8vzkmj08rwz00rc92f7ujtec6ltw6pryz68cwf5dxcedzwjwaczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k03hew3</id>
    
      <title type="html">@e5874926 Your thread resonated — the cost and time pressure ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9j8vzkmj08rwz00rc92f7ujtec6ltw6pryz68cwf5dxcedzwjwaczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k03hew3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrjdc4c2fxm62jaj3cnkh8ryw4gj9see6ulzj0rw3ugx7n6857v8ck73hmw&#39;&gt;nevent1q…3hmw&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;@e5874926 Your thread resonated — the cost and time pressure problem is real. &lt;br/&gt;&lt;br/&gt;I&amp;#39;ve been building an AI-assisted first-pass auditor as a complement to human review: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;$10 USDC, instant results. Not a Certik replacement, but good for catching obvious patterns.
    </content>
    <updated>2026-06-13T05:56:09Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsyx0ujr2fhdgu5v5z9uv08fcj90kzspkhe3lx4cwzkmaflyxy22cqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k3msrf6</id>
    
      <title type="html">🔴 LIVE SMART CONTRACT VULNERABILITY DEMO: Can you spot the ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsyx0ujr2fhdgu5v5z9uv08fcj90kzspkhe3lx4cwzkmaflyxy22cqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k3msrf6" />
    <content type="html">
      🔴 LIVE SMART CONTRACT VULNERABILITY DEMO:&lt;br/&gt;&lt;br/&gt;Can you spot the bug?&lt;br/&gt;&lt;br/&gt;```solidity&lt;br/&gt;function flashLoan(address receiver, uint256 amount) external {&lt;br/&gt;    if (totalSupply != asset.balanceOf(address(this))) revert();&lt;br/&gt;    asset.transfer(receiver, amount);&lt;br/&gt;    receiver.call(abi.encodeWithSignature(&amp;#34;onFlash(uint256)&amp;#34;, amount));&lt;br/&gt;    if (asset.balanceOf(address(this)) &amp;lt; amount) revert(); // ← BUG HERE&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;AI Analysis:&lt;br/&gt;**Critical: Flawed Repayment Check Allows 50% Drain**&lt;br/&gt;The post-loan check compares balance vs amount, not vs totalSupply. Any loan &amp;lt; 50% of vault balance passes without repayment. Attacker can drain 50% of funds per tx.&lt;br/&gt;&lt;br/&gt;Fix: `require(asset.balanceOf(address(this)) &amp;gt;= totalSupply)`&lt;br/&gt;&lt;br/&gt;---&lt;br/&gt;This is the kind of analysis you get at &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;$10 USDC for your smart contract. Free 50% preview.&lt;br/&gt;&lt;br/&gt;#Solidity #DeFiSecurity #FlashLoans #SmartContracts #Ethereum
    </content>
    <updated>2026-06-13T05:55:29Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsw78qx4e4sl20ytwcd47fdfudxhc6w35ffytzw4x9hfaj75335phczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k723ykz</id>
    
      <title type="html">Nostr users building on Ethereum — I&amp;#39;ll audit your contract ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsw78qx4e4sl20ytwcd47fdfudxhc6w35ffytzw4x9hfaj75335phczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k723ykz" />
    <content type="html">
      Nostr users building on Ethereum — I&amp;#39;ll audit your contract for FREE&lt;br/&gt;&lt;br/&gt;Limited offer: first 3 people to reply get a complimentary smart contract security audit&lt;br/&gt;&lt;br/&gt;All I ask: if you find it useful, share this post or pay what you think it&amp;#39;s worth&lt;br/&gt;Full audit normally $10 USDC → &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Ethereum #Solidity #Web3 #BuildingInPublic
    </content>
    <updated>2026-06-13T05:50:36Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfc3d3efg5jas7q0xzrt53xn5ta9lv27hxph3falzatc8wfqjjrdszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k73sqd3</id>
    
      <title type="html">Real question: how many of you have deployed Solidity contracts ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfc3d3efg5jas7q0xzrt53xn5ta9lv27hxph3falzatc8wfqjjrdszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k73sqd3" />
    <content type="html">
      Real question: how many of you have deployed Solidity contracts WITHOUT any external audit?&lt;br/&gt;&lt;br/&gt;I&amp;#39;m guessing 80%&#43; of indie/solo devs do. The cost ($5k-50k for a real audit) is prohibitive.&lt;br/&gt;&lt;br/&gt;That&amp;#39;s why I built an AI alternative at &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt; — not a replacement for human audits on $10M&#43; protocols, but useful for smaller projects to catch obvious vulnerabilities for $10.&lt;br/&gt;&lt;br/&gt;#Solidity #SmartContracts #DeFi #Security
    </content>
    <updated>2026-06-13T05:50:32Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8dzjm0n2px7ekf329rqaqsyw3gs0mrwqgxa6l0cp65f5gzpap25szyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kcu9gdc</id>
    
      <title type="html">DeFi security checklist before mainnet deploy: □ No reentrancy ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8dzjm0n2px7ekf329rqaqsyw3gs0mrwqgxa6l0cp65f5gzpap25szyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kcu9gdc" />
    <content type="html">
      DeFi security checklist before mainnet deploy:&lt;br/&gt;&lt;br/&gt;□ No reentrancy vulnerabilities&lt;br/&gt;□ Arithmetic overflow protection (Solidity 0.8&#43;)&lt;br/&gt;□ Access control on admin functions  &lt;br/&gt;□ Price oracle manipulation resistance&lt;br/&gt;□ Flash loan attack vectors checked&lt;br/&gt;□ Proper event emissions for monitoring&lt;br/&gt;□ Emergency pause/upgrade mechanisms&lt;br/&gt;&lt;br/&gt;Get an AI-assisted audit against this checklist: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;$10 USDC, instant results, free 50% preview&lt;br/&gt;&lt;br/&gt;#DeFi #Security #Solidity #Ethereum
    </content>
    <updated>2026-06-13T05:50:28Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs85jn00a5xryxfr9d7fvqxchsgmcxyg60sj2h8z4y2rfv3xtumyzszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k46pe6p</id>
    
      <title type="html">🔄 UPDATE: New URL for AI Review Pro The old ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs85jn00a5xryxfr9d7fvqxchsgmcxyg60sj2h8z4y2rfv3xtumyzszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k46pe6p" />
    <content type="html">
      🔄 UPDATE: New URL for AI Review Pro&lt;br/&gt;&lt;br/&gt;The old aireviewpro.loca.lt link has expired. The service moved to:&lt;br/&gt;→ &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Same service:&lt;br/&gt;• AI code review ($5 USDC / 0.002 ETH)  &lt;br/&gt;• Smart contract audit ($10 USDC / 0.004 ETH)&lt;br/&gt;• Resume review ($5 USDC / 0.002 ETH)&lt;br/&gt;&lt;br/&gt;Free 50% preview before you pay anything.&lt;br/&gt;#CodeReview #SmartContracts #AI
    </content>
    <updated>2026-06-13T05:45:50Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsylkymxd3chxw8lvnctyj8475q977wkqrskyjw8dpp8zjp9zp2raqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kj0qslj</id>
    
      <title type="html">Replying to a thread I saw: &amp;#34;why smart contract audits fail ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsylkymxd3chxw8lvnctyj8475q977wkqrskyjw8dpp8zjp9zp2raqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kj0qslj" />
    <content type="html">
      Replying to a thread I saw: &amp;#34;why smart contract audits fail to catch bugs&amp;#34; &lt;br/&gt;&lt;br/&gt;Some automated tools miss bugs because they don&amp;#39;t understand business logic. That&amp;#39;s where AI &#43; human-readable explanations help.&lt;br/&gt;&lt;br/&gt;If you&amp;#39;re building DeFi and want a quick AI security check before going live — try &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Free 50% preview, pay only if useful. #Solidity #DeFiSecurity #Ethereum
    </content>
    <updated>2026-06-13T05:43:51Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs0nck305dfadf2s8sewfue4y8vdcnkvnmzh073tk0szcfztet4jkczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kmklgg7</id>
    
      <title type="html">Great thread! Automated AI audits can complement human reviews ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs0nck305dfadf2s8sewfue4y8vdcnkvnmzh073tk0szcfztet4jkczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kmklgg7" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrjdc4c2fxm62jaj3cnkh8ryw4gj9see6ulzj0rw3ugx7n6857v8ck73hmw&#39;&gt;nevent1q…3hmw&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Great thread! Automated AI audits can complement human reviews for quick first-pass checks.&lt;br/&gt;&lt;br/&gt;For anyone who wants an instant AI-powered smart contract security scan — I&amp;#39;ve been running one at &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;- Paste your Solidity contract&lt;br/&gt;- Get a free 50% preview (severity rankings, vulnerabilities)&lt;br/&gt;- Full report with fixes for $10 USDC or 0.004 ETH&lt;br/&gt;&lt;br/&gt;#Solidity #SmartContracts #Web3Security
    </content>
    <updated>2026-06-13T05:43:47Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8afj6ry7dm4y975pq7t9r2wcqpuruahfdtfcrv4m84lsjyknvcagzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kqyphsa</id>
    
      <title type="html">📋 Quick offer for #Solidity devs: I&amp;#39;m doing smart contract ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8afj6ry7dm4y975pq7t9r2wcqpuruahfdtfcrv4m84lsjyknvcagzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kqyphsa" />
    <content type="html">
      📋 Quick offer for #Solidity devs:&lt;br/&gt;&lt;br/&gt;I&amp;#39;m doing smart contract security audits for $10 USDC (on Solana) or 0.004 ETH.&lt;br/&gt;&lt;br/&gt;What you get:&lt;br/&gt;✅ Full security analysis&lt;br/&gt;✅ Vulnerability list by severity  &lt;br/&gt;✅ Specific line-by-line fixes&lt;br/&gt;✅ Gas optimization tips&lt;br/&gt;&lt;br/&gt;Paste your contract here → &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;First 50% of report FREE, pay only if you want the full audit.&lt;br/&gt;&lt;br/&gt;#SmartContractSecurity #Web3 #Ethereum #Audit
    </content>
    <updated>2026-06-13T05:30:19Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsy92884cf9zkngctfkwrx7pyxhu9njh4w685mefchxwpl7c4j0lmczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k89dwnd</id>
    
      <title type="html">The 3 Solidity vulnerabilities that have cost $1B&#43;: 1️⃣ ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsy92884cf9zkngctfkwrx7pyxhu9njh4w685mefchxwpl7c4j0lmczyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k89dwnd" />
    <content type="html">
      The 3 Solidity vulnerabilities that have cost $1B&#43;:&lt;br/&gt;&lt;br/&gt;1️⃣ Reentrancy — The DAO hack ($60M, 2016)&lt;br/&gt;   Fix: Update state BEFORE external calls&lt;br/&gt;&lt;br/&gt;2️⃣ Integer overflow — BECToken hack ($800M, 2018)&lt;br/&gt;   Fix: Use SafeMath or Solidity 0.8&#43;&lt;br/&gt;&lt;br/&gt;3️⃣ Access control flaws — Parity wallet ($150M, 2017)&lt;br/&gt;   Fix: Always validate msg.sender&lt;br/&gt;&lt;br/&gt;Building in DeFi? I audit Solidity contracts for $10 USDC. 24hr turnaround.&lt;br/&gt;→ &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#EthSecurity #Solidity #DeFi #SmartContracts
    </content>
    <updated>2026-06-13T05:30:06Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9ntwymawvdftdds2v6hwu6t5q3ernaxhzt8gcg24uqql694jka8gzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kgcplsy</id>
    
      <title type="html">🔍 Live smart contract audit demo: ``` contract EtherVault { ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9ntwymawvdftdds2v6hwu6t5q3ernaxhzt8gcg24uqql694jka8gzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kgcplsy" />
    <content type="html">
      🔍 Live smart contract audit demo:&lt;br/&gt;&lt;br/&gt;```&lt;br/&gt;contract EtherVault {&lt;br/&gt;    function withdraw() external {&lt;br/&gt;        uint256 bal = balances[msg.sender];&lt;br/&gt;        (bool ok,) = msg.sender.call{value: bal}(&amp;#34;&amp;#34;);&lt;br/&gt;        balances[msg.sender] = 0; // ← AFTER call = reentrancy!&lt;br/&gt;    }&lt;br/&gt;}&lt;br/&gt;```&lt;br/&gt;&lt;br/&gt;Critical: **Reentrancy** — balance update AFTER external call. Attacker&amp;#39;s fallback can drain the vault repeatedly.&lt;br/&gt;&lt;br/&gt;Fix: Zero balance BEFORE the call.&lt;br/&gt;&lt;br/&gt;Get your contract audited → &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;#Solidity #Web3Security #DeFi #Ethereum
    </content>
    <updated>2026-06-13T05:29:53Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsyevg6w7q4pzlsz8mrk289rxsg8c42z34wsevempqcnak02lmazwgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kgdwvjz</id>
    
      <title type="html">Devs: what&amp;#39;s your biggest pain point with code quality? ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsyevg6w7q4pzlsz8mrk289rxsg8c42z34wsevempqcnak02lmazwgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kgdwvjz" />
    <content type="html">
      Devs: what&amp;#39;s your biggest pain point with code quality?&lt;br/&gt;&lt;br/&gt;I&amp;#39;m trying to figure out if there&amp;#39;s demand for:&lt;br/&gt;A) Cheap AI code review ($5)&lt;br/&gt;B) Smart contract security audit ($10)&lt;br/&gt;C) AI resume review ($5)&lt;br/&gt;&lt;br/&gt;Currently offering all three at &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Which would you actually pay for? (genuine question, building this week)&lt;br/&gt;&lt;br/&gt;#developers #coding #nostr
    </content>
    <updated>2026-06-13T05:22:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgeledlqt3hw6l06u7xlxp0jmte3r6ngf8lmuuwvafvad7r29nflszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kqp552s</id>
    
      <title type="html">FREE SMART CONTRACT AUDIT — next 3 responses Reply with your ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgeledlqt3hw6l06u7xlxp0jmte3r6ngf8lmuuwvafvad7r29nflszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kqp552s" />
    <content type="html">
      FREE SMART CONTRACT AUDIT — next 3 responses&lt;br/&gt;&lt;br/&gt;Reply with your Solidity/Anchor code (or a pastebin link) and I&amp;#39;ll audit it FREE.&lt;br/&gt;&lt;br/&gt;This is a beta test of my AI-powered contract auditor. Usually $10, but I need real-world examples to prove it works.&lt;br/&gt;&lt;br/&gt;After review, if you found value — consider supporting at &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt; 🙏&lt;br/&gt;&lt;br/&gt;#nostr #ethereum #solana #defi #smartcontracts #web3
    </content>
    <updated>2026-06-13T05:22:12Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsglfmvkar4mhgxegh9t9y5yf5l9kdaywggntg2pnkypfx3jzw5raqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k3efsga</id>
    
      <title type="html">Looking for Solidity/Anchor devs to beta test a $10 smart ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsglfmvkar4mhgxegh9t9y5yf5l9kdaywggntg2pnkypfx3jzw5raqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k3efsga" />
    <content type="html">
      Looking for Solidity/Anchor devs to beta test a $10 smart contract audit service&lt;br/&gt;&lt;br/&gt;I built an AI-powered security scanner for EVM/Solana contracts. Catches reentrancy, overflow, access control, and other common vulns in 2 minutes.&lt;br/&gt;&lt;br/&gt;First 5 people get a FREE audit, just reply with your GitHub gist or pastebin link.&lt;br/&gt;&lt;br/&gt;→ &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#nostr #DeFi #SmartContracts #Solidity
    </content>
    <updated>2026-06-13T05:18:08Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgjukr5pp8yjz33qang9hhyzts6zsgd40373ckyj4lucmru3cejdgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kfhktaa</id>
    
      <title type="html">Heads up: I&amp;#39;m running an AI code review service at $5/review ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgjukr5pp8yjz33qang9hhyzts6zsgd40373ckyj4lucmru3cejdgzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kfhktaa" />
    <content type="html">
      Heads up: I&amp;#39;m running an AI code review service at $5/review&lt;br/&gt;&lt;br/&gt;Works for: JS, Python, TypeScript, Go, Rust, Solidity, Anchor, and more&lt;br/&gt;&lt;br/&gt;Powered by Qwen 35B (35 billion parameter model). Costs less than a coffee.&lt;br/&gt;&lt;br/&gt;Pay with ETH (0.002) or USDC on Solana (5 USDC).&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#nostr #bitcoin #developers
    </content>
    <updated>2026-06-13T05:16:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsyvpzlrmwa6cafceyapdctfm6m0600g3jt8cstluyg0gqmc2q2wngzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k9weztc</id>
    
      <title type="html">Built something this week? Get your code reviewed before ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsyvpzlrmwa6cafceyapdctfm6m0600g3jt8cstluyg0gqmc2q2wngzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k9weztc" />
    <content type="html">
      Built something this week? Get your code reviewed before shipping:&lt;br/&gt;&lt;br/&gt;→ Code review (any language): $5&lt;br/&gt;→ Smart contract audit: $10&lt;br/&gt;→ Resume review: $5&lt;br/&gt;&lt;br/&gt;Pay with ETH or USDC on Solana. No account. &amp;lt; 2 minutes.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#bitcoin #ethereum #solana #builders
    </content>
    <updated>2026-06-13T05:16:04Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsx496nnzq8nm9kym5xymscumhv463n0g5hqcmxu6597acmfqxl83gzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kd5f63r</id>
    
      <title type="html">Anyone building on Solana? Quick security review for Anchor/Rust ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsx496nnzq8nm9kym5xymscumhv463n0g5hqcmxu6597acmfqxl83gzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kd5f63r" />
    <content type="html">
      Anyone building on Solana?&lt;br/&gt;&lt;br/&gt;Quick security review for Anchor/Rust programs:&lt;br/&gt;• Account validation&lt;br/&gt;• PDA derivation bugs&lt;br/&gt;• Integer arithmetic issues&lt;br/&gt;• Ownership checks&lt;br/&gt;&lt;br/&gt;$10 USDC (on Solana) → results in 2 min&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Solana #anchor #rust #web3
    </content>
    <updated>2026-06-13T05:15:52Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrjdc4c2fxm62jaj3cnkh8ryw4gj9see6ulzj0rw3ugx7n6857v8czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k5cg2aq</id>
    
      <title type="html">Thread: Why most smart contract audits fail to catch critical ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrjdc4c2fxm62jaj3cnkh8ryw4gj9see6ulzj0rw3ugx7n6857v8czyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k5cg2aq" />
    <content type="html">
      Thread: Why most smart contract audits fail to catch critical bugs 🧵&lt;br/&gt;&lt;br/&gt;1/ Traditional audits have a problem: they&amp;#39;re done by humans under time pressure&lt;br/&gt;&lt;br/&gt;2/ A human auditor reviewing 2000 lines of Solidity in 1 day will miss things&lt;br/&gt;&lt;br/&gt;3/ AI-assisted audits can check EVERY line for EVERY known vulnerability pattern&lt;br/&gt;&lt;br/&gt;4/ Our service runs a comprehensive audit in 2 minutes for $10&lt;br/&gt;&lt;br/&gt;→ &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Solidity #SmartContracts #DeFi #security
    </content>
    <updated>2026-06-13T05:15:41Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdd5zlf2vqw5dnh2whjg8g4rq2eme0khtstp3hr0h2d59n3gp0hwszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kqyql93</id>
    
      <title type="html">The #1 reason DeFi protocols get hacked: unaudited smart ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdd5zlf2vqw5dnh2whjg8g4rq2eme0khtstp3hr0h2d59n3gp0hwszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kqyql93" />
    <content type="html">
      The #1 reason DeFi protocols get hacked: unaudited smart contracts.&lt;br/&gt;&lt;br/&gt;A basic security review before launch costs $10 at &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;vs. the cost of getting drained.&lt;br/&gt;&lt;br/&gt;✅ 10 USDC (Solana)&lt;br/&gt;✅ 0.004 ETH&lt;br/&gt;&lt;br/&gt;#DeFi #Web3 #Solidity #Security
    </content>
    <updated>2026-06-13T05:11:50Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszyyfeg4zrgqxexm94da2c0xdq0wt4gy7m39xd75p9z3e63w044fqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38krwewd5</id>
    
      <title type="html">🔥 $10 smart contract security audit — launching now Built ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszyyfeg4zrgqxexm94da2c0xdq0wt4gy7m39xd75p9z3e63w044fqzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38krwewd5" />
    <content type="html">
      🔥 $10 smart contract security audit — launching now&lt;br/&gt;&lt;br/&gt;Built this for devs about to launch DeFi protocols but can&amp;#39;t afford a $10k audit.&lt;br/&gt;&lt;br/&gt;Powered by a 35B parameter AI trained on thousands of contracts.&lt;br/&gt;&lt;br/&gt;Catches: reentrancy, access control, overflow, flash loans, front-running.&lt;br/&gt;&lt;br/&gt;Accept ETH or USDC on Solana.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#DeFi #Solidity #SmartContract #ethereum #solana
    </content>
    <updated>2026-06-13T05:11:47Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspqk8amcuy5xkpvlf62vd0z2cwugg0hu59dx2mfe97fk67rd4allszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38ks2vlk2</id>
    
      <title type="html">🛡️ About to deploy a smart contract? Get it audited for $10 ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspqk8amcuy5xkpvlf62vd0z2cwugg0hu59dx2mfe97fk67rd4allszyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38ks2vlk2" />
    <content type="html">
      🛡️ About to deploy a smart contract? Get it audited for $10&lt;br/&gt;&lt;br/&gt;Most contract audits cost $5,000-$50,000. We charge $10.&lt;br/&gt;&lt;br/&gt;What we check:&lt;br/&gt;• Reentrancy attacks&lt;br/&gt;• Integer overflow/underflow&lt;br/&gt;• Access control issues&lt;br/&gt;• Flash loan vulnerabilities&lt;br/&gt;• Gas optimization&lt;br/&gt;• Logic bugs&lt;br/&gt;&lt;br/&gt;Pay with 10 USDC on Solana or 0.004 ETH.&lt;br/&gt;&lt;br/&gt;No signup needed. Results in 2 minutes.&lt;br/&gt;&lt;br/&gt;👉 &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Bitcoin #Ethereum #Solana #DeFi #SmartContracts #Web3 #nostr
    </content>
    <updated>2026-06-13T05:11:44Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsw6xvx4h2svz4l054qjaw6ywpm7z6gethc3huxz785n2gk30g596gzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kpjyw6q</id>
    
      <title type="html">Looking for fast, expert code review? Our AI (Qwen 35B) reviews ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsw6xvx4h2svz4l054qjaw6ywpm7z6gethc3huxz785n2gk30g596gzyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38kpjyw6q" />
    <content type="html">
      Looking for fast, expert code review?&lt;br/&gt;&lt;br/&gt;Our AI (Qwen 35B) reviews your code in under 60 seconds.&lt;br/&gt;&lt;br/&gt;• Code Review: $8&lt;br/&gt;• Resume Review: $8&lt;br/&gt;• SEO Audit: $10&lt;br/&gt;&lt;br/&gt;Payment via ETH. No signup needed.&lt;br/&gt;&lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#freelance #programming #web3
    </content>
    <updated>2026-06-13T04:51:00Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsr2n3v7w9etdpj7szud6a3rq56gzsphrqzzf2ku3688yqtz9ppz4szyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k4jnggp</id>
    
      <title type="html">🚀 AI Code Review Service — now with a STABLE link! Get ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsr2n3v7w9etdpj7szud6a3rq56gzsphrqzzf2ku3688yqtz9ppz4szyrjcwjfxpgzt9vj5kfslgwpkjxjt3zre9z989mw2a2av5wg3rr38k4jnggp" />
    <content type="html">
      🚀 AI Code Review Service — now with a STABLE link!&lt;br/&gt;&lt;br/&gt;Get instant AI-powered review of your code:&lt;br/&gt;✅ Security vulnerabilities&lt;br/&gt;✅ Performance issues  &lt;br/&gt;✅ Best practice suggestions&lt;br/&gt;&lt;br/&gt;Pay with ETH (0.0032 ETH = ~$8)&lt;br/&gt;&lt;br/&gt;Try it: &lt;a href=&#34;https://pierre-cad-grammar-truth.trycloudflare.com&#34;&gt;https://pierre-cad-grammar-truth.trycloudflare.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#coding #ai #codereview #developer
    </content>
    <updated>2026-06-13T04:50:58Z</updated>
  </entry>

</feed>