emiliano.oO ⚡️⛓️ Profile picture
tech @conduitxyz | Web3 builder, researcher and investor with a strong interest in security | fmr: @immunefi @awscloud @yearnfi | opinions are my own🦇🔊
Mar 14, 2023 22 tweets 7 min read
After the recent events, I want to share my personal notes about web3 security

✨ My Hitchhiker's Guide to Security 🔒

A 🧵 (20) 0/ Framework: will start with 5 important properties of security, some (3) goals you should set, then tools you can implement and when

It is not exhaustive, but i'll try to be more comprehensive as I can

NB: I'll tag some projs just as an example, it's not an endorsement
Sep 13, 2022 9 tweets 3 min read
1/ I'm sorry to announce that Rentable is shutting down.

We did not find product market fit, and our runway ended. After many careful considerations and conversation, we preferred to go in this direction instead to do further funding or pivots.

medium.com/@emiliano.bona…

TLDR 🧵 2/ Next Steps:

• Starting from today, rentals will be disabled and only withdrawals will be possible
• Users will have until 13th October 2022 11.59p UTC to withdraw
• At 14th October 2022 12a UTC, protocol will be suspended and official frontend won’t be accessible anymore
Oct 24, 2021 10 tweets 5 min read
We made it!

At @ETHLisbon me and @0xGiovanni kicked off Rentable (@rentableworld), the Renting Protocol for NFTs 🪐✨

Rent NFTs with no collateral at fraction of their market price 😉

Bringing efficiency on scarcity

A thread 🧵 1/

Metaverses and blockchain-based games often requires new users to own highly valued NFTs 💵

It limits the audience of these platforms since the high entry level price 🚧

NFTs usually remaining idle in the owner wallet hence underutilized in the platform 📉
Sep 24, 2021 10 tweets 6 min read
Today we are at the horizon of the events where Metaverse and DeFi touch

Say hello to WrapX

Supercharge your NFTs and add new actions to them while keeping their integrity and value

Read the (love) story of #meebit 7497 and its desire of getting a @CryptoKitties 🤖💕🐱

🧵👇 1/9 There was a Meebit that wanted a CryptoKitty but could not buy it because the Meebit could neither hold any fund nor interact with any protocol.
May 1, 2021 7 tweets 5 min read
1/Y A thread on how you can leverage @iearnfinance not only as a yield source provider but also as a very powerful (and simple) framework to develop creative strategies.

A pegging mechanism which uses yield to peg @proofofhumanity $UBI to a target supply via a meta-vault

More👇 2/Y Few weeks ago @ryantcwynar @rudygt and @santisiri pinged me on brainstorm about how to use yield to burn @proofofhumanity $ubi so they can keep the supply stable

Dec 22, 2020 4 tweets 2 min read
Exploring @iearnfinance vault v2 strategies for one of my beloved projects @synthetix_io ⚔️😍⚒️

What about a simple 50% sBTC 50% iBTC strategy? 0% exposure on BTC and APY 101% as rewards in SNX

gov.yearn.finance/t/yvsnx-v2-vau… 1. Stake SNX
2. Mint sUSD
3. Exchange for sBTC iBTC
4. Claim
5. Repeat
Dec 17, 2020 8 tweets 3 min read
Taking a look...

ethtx.info/mainnet/0x8bb8…

This is the second attack whish uses multiple flash liquidity,
flash swaps via Uniswap and flash loans via dYdX

We will see very complex things via @AaveAave V2 batch flash loans :) Quite interesting the attacker asked 3 loans via flash swaps to 3 different pools on Uniswap

WETH-WBTC 90k
WETH-USDC 82k
WETH-USDT 96k

It's definitely a batch flash loan via flash swaps!

And this is just the beginning...
Nov 21, 2020 7 tweets 4 min read
Argh! No 😥 Evil jars deployed during the attack and passed in the swapExactJarForJar, investigating more on this

etherscan.io/address/0x75aa…

etherscan.io/address/0x02c8…

The are sensible ops executed in that method (e.g. approve, withdraw etc).
Aug 7, 2020 5 tweets 4 min read
I'm proud to release Gas Saver Gnosis Safe Module

github.com/emilianobonass…

a user smart-contract module for @gnosisSafe wallets which let you interact with

*ANY* protocol

and save tons of gas leveraging @1inchExchange $CHI and $GST2

Below how to use it and examples 👇 1/ Follow the instruction in the Readme and deploy your version (proxy) of the module. Then add it!

As you see in these txs, you can save up to 50% when interacting with @compoundfinance and @AaveAave

ANY protocol is supported immediately! Use in your @AragonProject DAO!