Log inSign up
Neodyme
388 posts
Image
user avatar
Neodyme
@Neodyme
We secure software with deep-dive audits, cutting-edge research, and in-depth trainings. Secure your solana program with Riverguard @ riverguard.io 🏞️💂
Germany
neodyme.io
Joined August 2021
46
Following
5,639
Followers
  • Pinned
    user avatar
    Neodyme
    @Neodyme
    Nov 1, 2023
    Introducing Riverguard 🏞️💂 A new security tool for Solana program deployers... 🧵 riverguard.io
    Image
    30K
  • user avatar
    Neodyme
    @Neodyme
    Dec 3, 2021
    We recently discovered a critical bug in the token-lending contract of the solana-program-library (SPL). This blog post details our journey from discovery, through exploitation and coordinated disclosure, and finally the fix.
  • user avatar
    Neodyme
    @Neodyme
    May 13, 2023
    When CS:GO clients connected to our server, they got more than a game. We found 3 RCE vulnerabilities to give clients an unexpected 'welcome'. Ready for a deep-dive? 🎮🔧🎆 neodyme.io/blog/csgo_from… #InfoSec #CSGO #Exploit
    CS:GO: From Zero to 0-day
    CS:GO: From Zero to 0-day
    From neodyme.io
    63K
  • user avatar
    Neodyme
    @Neodyme
    Nov 12, 2022
    Who **actually** controls the largest projects on #solana? What's the deal with Upgrade Authorities? Are your funds more safu in DeFi contracts than they were on #FTX? Let's find out 🧵👇
  • user avatar
    Neodyme
    @Neodyme
    Aug 21, 2021
    Heads up #solana #developers! Our team has been helping @solana with peer-reviews and we'd like to share what we've learned over the course of our audits:
    Solana Smart Contracts: Common Pitfalls and How to Avoid Them
    Solana Smart Contracts: Common Pitfalls and How to Avoid Them
    From neodyme.io
  • user avatar
    Neodyme
    @Neodyme
    Dec 3, 2021
    Replying to @Neodyme
    As such, we’ve written up a dive into how this vulnerability could have been exploited, and how we found it:
    How to Become a Millionaire, 0.000001 BTC at a Time
    How to Become a Millionaire, 0.000001 BTC at a Time
    From neodyme.io
  • user avatar
    Neodyme
    @Neodyme
    Dec 14, 2023
    Technical Analysis of the Ledger Supply-Chain Attack 🧵 We did a brief analysis of today’s attack against the @Ledger browser integration. This is what we found. Ledger’s browser integration, Ledger Connect, was attacked via a suspected supply chain attack. The attacker
    Image
    Image
    Image
    Image
    user avatar
    Ledger
    @Ledger
    Dec 14, 2023
    Replying to @Ledger
    Update: The malicious version of the file was replaced with the genuine version at around 2:35pm CET. The new genuine version should be propagated soon. We will provide a comprehensive report as soon as it’s ready. In the meantime, we’d like to remind the community to
    32K
  • user avatar
    Neodyme
    @Neodyme
    Oct 31, 2021
    Are you a #Solana #dev and attending #BreakpointLisbon? Come join our security masterclass where we'll teach you how to think like an attacker! conference.solana.com/agenda/session…
  • user avatar
    Neodyme
    @Neodyme
    Apr 4, 2022
    We believe every software project should clearly communicate its bug bounty policies and how to get in touch regarding security issues. In order to facilitate this, we brought security.txt to Solana:
    Image
    GitHub - neodyme-labs/solana-security-txt: security.txt for Solana Contracts
    From github.com
  • user avatar
    Neodyme
    @Neodyme
    Dec 3, 2021
    Replying to @Neodyme
    The bug was fixed, and dapps updated promptly to close the vulnerability. We believe the most secure code is open-source, and as auditors we believe one of the best ways to write better code is to understand vulnerabilities.
  • user avatar
    Neodyme
    @Neodyme
    Dec 3, 2021
    Replying to @Neodyme
    The total TVL at risk was about 2.600.000.000 USD. Some of that value is lent out, and some other low-value coins are not economically viable to steal, but the potential profit was easily in the hundreds of millions.
  • user avatar
    Neodyme
    @Neodyme
    Mar 10, 2023
    Total Loss of Funds The story of Solana's highest-severity bug -- and how we found it back in late 2020. Among other things, it allowed us to: - Mint or steal any amount of any token - Modify any NFT - Delete liabilities in any lending protocol
    Nonce Upon a Time, or a Total Loss of Funds - Exploring Solana Core Part 3
    Nonce Upon a Time, or a Total Loss of Funds - Exploring Solana Core Part 3
    From neodyme.io
    81K
  • user avatar
    Neodyme
    @Neodyme
    Jun 10, 2023
    > tfw you audit Solana so well, the SEC considers it "security"
    Image
    user avatar
    Solana Foundation
    Solana
    @SolanaFndn
    Jun 10, 2023
    The Solana Foundation disagrees with the characterization of SOL as a security. We welcome the continued engagement of policymakers as constructive partners on regulation to achieve legal clarity on these issues for the thousands of entrepreneurs across the U.S. building in the
    14K
  • user avatar
    Neodyme
    @Neodyme
    Aug 11, 2023
    Cypher protocol was exploited for over $1 million. But how? Here’s the main idea for what the attacker did, and why it worked 👇🏻
    Image
    18K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up