tweetindex
ES

Zellic

@zellic_io · joined 16 Nov 2021

Security reviews and research that keep winners winning. We apply unmatched hacking talent to secure critical software for the most innovative teams.

18 144Followers
18Following
1 735Posts total
1.9MViews on collected posts

Últimas publicaciones

https://t.co/6BHa6v4GyW 200 views · 0 likes · 0 reposts · 0 replies Open on X →
One permissionless call and your deposit is… miner fees? Legacy P2PKH signatures, trusting user calldata, and a signer with no context of what it’s signing. Here’s how 64 missing bits allowed @RelayProtocol’s permissionless `sweep()` to drain Bitcoin funds to fees. 🧵 https://t.
3.9K views · 34 likes · 6 reposts · 1 replies Open on X →
We're very excited to be sponsoring Paged Out! once again! Check out Issue #9👇 https://t.co/DxicgzO096
6.5K views · 26 likes · 3 reposts · 1 replies Open on X →
Paged Out! #9 is live! Read, share, enjoy! https://t.co/kVmdLe0l7s We are running final QA on all PO! issues that should be available on Lulu (https://t.co/RoJJnVAYnY) in a few days! In case you want to support us, we have a Patreon now - https://t.co/CkLKpl1WWU https://t.co/
14.3K views · 74 likes · 28 reposts · 2 replies Open on X →
https://t.co/ycFLmlQKwZ 737 views · 1 likes · 0 reposts · 1 replies Open on X →
@zellic_io good job guys 😅 860 views · 19 likes · 0 reposts · 1 replies Open on X →
Note that all of our proofs are valid proofs for the statements they claim to prove. The issue lies in those statements not meaning what they were intended to mean. While our circuits were still sound and complete, the flaw in the spec for mainCost allowed us to break the larger 30.9K views · 70 likes · 7 reposts · 0 replies Open on X →
The cost claim only covers the first branch and is thus trivial to prove. https://t.co/P91iba8HHb
2.1K views · 10 likes · 0 reposts · 1 replies Open on X →
Our solution thus branches on whether the input is equal to this default constant. If it is, we just return the correct result as a constant, requiring zero allocations or constraints. If it is not, we fall back to the baseline circuit. https://t.co/SE4uLhsTi9
1.6K views · 11 likes · 0 reposts · 1 replies Open on X →
Both branches are sound and complete for their respective inputs, so we can also prove soundness and completeness for our `main`: https://t.co/4nG0k5H9Rj
1.6K views · 10 likes · 0 reposts · 1 replies Open on X →
So what is the default input? Ultimately, the input boils down to consisting of `Expression`s. These can be a constant, a symbolic variable, or a polynomial in other expressions. https://t.co/5RlKkYO4Q2
1.8K views · 11 likes · 0 reposts · 1 replies Open on X →
The default expression turns out to be the constant zero. The cost counting function thus gets passed `main` applied to an input consisting only of constants with value zero. https://t.co/NzTVc3WfAg
1.6K views · 10 likes · 0 reposts · 1 replies Open on X →
Solutions claim a number of allocations and constraints, and must provide a proof of `mainCost`, which is intended to be the statement that `the` circuit allocates that many witnesses and has that many constraints. But note that the argument to `Challenge.CostR1CS.circuitCount`
2K views · 14 likes · 0 reposts · 1 replies Open on X →
In this screenshot you can see the types of everything we need to provide. The circuit is provided with `main`. This takes the circuit input as an argument, and returns a circuit (constraint system). Note that `main` having this type means that the constraints are allowed to ht
2.3K views · 14 likes · 0 reposts · 1 replies Open on X →
How does it work? You upload a circuit, along with a Lean 4 proof of correctness, and submissions are ranked based on circuit cost, which is the sum of the number of witness allocations and the number of constraints. As all submissions are formally verified, developers could ht
2.9K views · 18 likes · 0 reposts · 1 replies Open on X →
You "win" https://t.co/y2fdv7oJiN – ZKSecurity’s FV contest – by writing the most optimized formally verified circuit for cryptographic primitives. But how does the best SHA256 circuit have a cost of 0? Here's how we exploited the FV spec for the top score on all circuits.👇 htt
49K views · 147 likes · 10 reposts · 6 replies Open on X →
https://t.co/QFtryPT6KT 1.1K views · 1 likes · 0 reposts · 1 replies Open on X →
We formally verified a Plonky2 gate. ZK proofs show circuit satisfaction, but do they prove the statement you rely on? One flaw and attackers can convince a verifier that false statements are true. We closed that gap with formal verification. Here's how we proved it in Lean.
7.7K views · 97 likes · 10 reposts · 5 replies Open on X →
https://t.co/KeUKWnOjno 1.3K views · 0 likes · 0 reposts · 1 replies Open on X →
How to find a $65,000 zero-day in Chrome V8: Meet @eternalsakura13, researcher at Zellic. - Top 3 Chrome VRP 2022–2024 - Top 2 Facebook whitehat in 2023 - Top 10 MSRC MVR in 2025 Here’s a walk through the mind of one of the world’s best Chrome researchers. Can you follow along?
55.2K views · 510 likes · 57 reposts · 4 replies Open on X →
https://t.co/lXqgoYBrjN 1.4K views · 0 likes · 0 reposts · 1 replies Open on X →
Solana’s VM has bugs. Or to be more precise, it had these two bugs: - One bug leaked memory. - Another corrupted “untouchable” memory. Both were found in Solana’s high-performance sBPF engine. These bugs have since been fixed. But the following bugs reveal what happens when
10.6K views · 101 likes · 7 reposts · 5 replies Open on X →
https://t.co/8d6elFmBEG 1.5K views · 0 likes · 0 reposts · 1 replies Open on X →
You’re probably using WebViews wrong. There are a million ways to use a WebView wrong. Properly securing a WebView is hard. In this thread, we’ll cover common vulnerabilities in wallet WebView implementations and the ways to properly secure WebViews. https://t.co/DG6a4fK7VG
25.7K views · 241 likes · 37 reposts · 1 replies Open on X →
https://t.co/E3WaSUXOro 2.3K views · 1 likes · 0 reposts · 2 replies Open on X →
ZK protocols use special hash functions that are algebraically simple. But if our proof system supported lookup tables, could we do better? Introducing Polocolo: a new ZK-friendly hash function for PlonKup, co-authored by Zellic Cryptographer @baaaaaarkingdog. https://t.co/hviZ
8K views · 73 likes · 9 reposts · 5 replies Open on X →
https://t.co/tArCx3f9G8 2K views · 2 likes · 0 reposts · 1 replies Open on X →
BLS signatures are everywhere, from Ethereum’s consensus to EigenLayer. But it’s easy to use them wrong. What are BLS signatures? Let’s talk about the right way and the wrong way to use them: https://t.co/5oQ44rhSyP
54.4K views · 330 likes · 49 reposts · 5 replies Open on X →
https://t.co/3EZnq2dseD 1.8K views · 2 likes · 0 reposts · 1 replies Open on X →
Last month, @chrisling_dev introduced WHLUSDC, a Hyperliquid-native stablecoin. On a Spaces after the announcement, Chris mentioned a bug purposely introduced in WHLUSDC as a challenge. Our team quickly got to work. This is how we found the bug along with the POC to prove it.
18.3K views · 84 likes · 10 reposts · 2 replies Open on X →

Frente a cuentas del mismo tamaño

18 publicaciones de los últimos 90 días, junto al rango de 10K–100K seguidores. llega a mucha gente, pero pocos de esos espectadores reaccionan.

Visualizaciones medianas2 012esta cuenta949mediana de 10K–100K
Alcance, %11.09%esta cuenta3.31%mediana de 10K–100K
Interacción, %0.66%esta cuenta1.88%mediana de 10K–100K
MétricaEsta cuentaMediana de 10K–100KProporción
Visualizaciones medianas por publicación2 0129492.12×
Alcance (visualizaciones ÷ seguidores)11.09%3.31%3.35×
Tasa de interacción0.66%1.88%0.35×

Otras cuentas de este rango →   Comparar con otra cuenta →   Cómo se construyen estas referencias →

Growth & engagement

How the posts we collected actually performed: views and reaction rate post by post, what the audience did with them, and where the follower count goes.

Views per post

2.3K3 Jul
2K
1.6K
1.8K
1.6K
1.6K
2.1K
30.9K
860
7376 Jul
14.3K27 Jul
6.5K
3.9K27 Aug
20028 Aug

Last 14 collected posts, oldest on the left. The scale is logarithmic: one post can outrun the rest a hundred times over.

Engagement rate per post

0.65%3 Jul
0.76%
0.67%
0.68%
0.68%
0.75%
0.53%
0.26%
2.33%
0.27%6 Jul
0.79%27 Jul
0.46%
1.07%27 Aug
0.00%28 Aug

Reactions — likes, reposts, replies and quotes — divided by views. Median for 10K–100K accounts is 1.88%.

What the audience does

Likes79.4%1 911 in total
Reposts9.7%233 in total
Replies2.3%55 in total
Quotes1.7%42 in total
Bookmarks6.9%166 in total

Share of every reaction we collected for this account. Replies mean argument, reposts mean endorsement, bookmarks mean the post was worth keeping.

The follower curve appears once this account has two daily snapshots — we take one a day, and this one is on its first.

Cuentas similares