How to become the #1 Auditor in Web3

Поділитися
Вставка
  • Опубліковано 3 чер 2024
  • We catch up with Or aka "Trust" and learn his process for finding bugs with Immunefi, Code4rena, and his approach to security in Web3.
    🔐 Trust Twitter: / trust__90
    🔑 Trust Website: www.trustindistrust.com/
    ✍️ Blog: / how-to-become-the-numb...
    📽️ Full Interview: • Code4rena Trust Full I...
    ⏰ Timestamps
    0:00 | Introduction
    0:43 | 1. Understand the EVM
    1:42 | 2. Understand the protocol
    4:53 | 3. Compare your understanding of the code
    5:39 | What tools do you use?
    7:07 | Where can you follow Or?
    7:28 | Summary
    Check out these articles to learn about some of these tools and start your journey as a smart contract engineer!
    👇👇👇👇👇👇👇👇👇👇👇👇👇👇👇👇👇👇👇
    📕How to Become a Blockchain Engineer: betterprogramming.pub/how-to-...
    ✍️Top 10 Resources, Tutorials, and Follows: dev.to/patrickalphac/top-10-s...
    👆👆👆👆👆👆👆👆👆👆👆👆👆👆👆👆👆👆👆
    ✅✅ Donate ✅✅
    I use donated funds to spend money on making fun & informational videos.
    ETH/Polygon/Avalanche/EVM Chains Wallet address:
    0x9680201d9c93d65a3603d2088d125e955c73BD65
    Or, optionally:
    - patrickalphac.eth (ETH Only)
    😸😸Follow Patrick!😸😸
    Twitter: / patrickalphac
    Medium: / patrickalphac
    TikTok: / patrickalphac
    Twitch Stream Uploads & Shorts: / @patrickalphac-alt
    All thoughts and opinions are my own.
  • Наука та технологія

КОМЕНТАРІ • 65

  • @mknight3488
    @mknight3488 Рік тому +15

    This is Patrick Collins. Aka the reason why we keep youtube notification off our permaban for sending notifications. A legendary person that is the first one to actually pass the 10 hour marked video by Michael Knight. Patrick offered thousands of developers and interested persons in tech such valuable insight that I as representative of the human race am truly grateful for his work and how much he means for the future. Patrick is a living legend and shines a light on fellow living legends.

  • @kenmeyer100
    @kenmeyer100 Рік тому +8

    Thanks, Patrick. Now I am already on my way to becoming a bugfinder degen 🤣

  • @SadFace229
    @SadFace229 Рік тому +12

    Man, becoming an auditor sounds absolutely daunting. But it feels like you should aim to be able to audit others' code if you're a Web3 developer anyway as everyone benefits; you for gaining more experience in securing your own project and helping to protect others' projects. Thank you for the video, I'll be sure to have try my hand in Code4rena in the future.

  • @fulumbeats1310
    @fulumbeats1310 Рік тому

    So interesting contents, thanks Trust and Patrick👌

  • @rickkdev
    @rickkdev Рік тому +2

    Finally new videos I was waiting for ages

  • @Taurus_Art
    @Taurus_Art Рік тому +4

    Thanks for the efforts on this, really opens up a new arena on opportunities in Web3 along with practicality.

  • @signalrod2213
    @signalrod2213 Рік тому +4

    very good topic to pick, thanks

  • @theweb3experience
    @theweb3experience Рік тому +1

    Great interview

  • @BenMinal
    @BenMinal Рік тому +2

    Patrick, you are the MAN. Trust is next level. Thanks for the constant flow of game-changing info.

    • @PatrickAlphaC
      @PatrickAlphaC  Рік тому

      Absolutely ser 🫡🫡🫡 I’m very happy trust is in the web3 community!

  • @Ali_Murtaza_Memon
    @Ali_Murtaza_Memon Рік тому +6

    Why my six sences are saying that you are recording a course on Auditing? 😀 BTW Thanks to you both for the information.

  • @chandrabalanc4258
    @chandrabalanc4258 Рік тому +5

    Good morning sir I am from India

  • @jingli9232
    @jingli9232 Рік тому +1

    super cool

  • @dxzmakavelli1083
    @dxzmakavelli1083 Рік тому +1

    thanks . from algeria

    • @kamalchan9756
      @kamalchan9756 24 дні тому

      سلام خو معليش تعطيلنا الفيس ولا الديسكورد نتواصلو

  • @kaustubhthakur5178
    @kaustubhthakur5178 Рік тому +1

    GM @patrick I need yo help, can you suggest me some platform for where I can do auditinh

  • @mihirpratapsingh3178
    @mihirpratapsingh3178 4 місяці тому

    does his work only contain finding the vulnerability or solving those bugs also?

  • @sujayvadavadagi
    @sujayvadavadagi Рік тому +1

    Hi Patrick ,
    I have been learning Blockchain from your free code camp 32 hour video , it’s really great resource,
    And Thank you for putting out a great content , really appreciate.
    But bit doubtful if there is job opportunity in blockchain space with solidity .
    Because lately getting to see a lot of negativity and some of the guys being jobless as a blockchain developer.
    So PLEASE let me know your insights about job opportunities and also future of being a blockchain developer.🙂

    • @PatrickAlphaC
      @PatrickAlphaC  Рік тому +3

      We are currently in a bear market, but I also ask this question:
      "Given two systems, one where you can verify everything yourself, and one where you can only trust someone behind closed doors is being honest, everything else the same, which would you pick?"
      That makes smart contracts (and therefore solidity) inevitable.

    • @sujayvadavadagi
      @sujayvadavadagi Рік тому

      @@PatrickAlphaC Thank you for replying Patrick,
      As you said Smart Contracts are Inevitable,
      And also you mean to say that If we are in Bull market then there would be better job opportunities . Ohkay will stay around the block until it's back flying high .
      But this question came to my mind because of some guys posts in LinkedIn who were in bad shape and jobless due FTX scam .
      Anyway Thank you for insightful Videos . 😊

  • @jrsantos1737
    @jrsantos1737 Рік тому +2

    Trust came from NSO group - cyber intelligence firm, no doubt this is easy for him.

    • @PatrickAlphaC
      @PatrickAlphaC  Рік тому

      They really breed them different over there.

  • @andyli
    @andyli Рік тому +1

    nice

  • @tamzhamz4615
    @tamzhamz4615 6 місяців тому

    Should you learn JS before solidity?

    • @PatrickAlphaC
      @PatrickAlphaC  6 місяців тому

      If you'd like! But you 100% can just jump into solidity

  • @luckieoleary6459
    @luckieoleary6459 Рік тому +3

    Quick question, can ChatGPT become #1 Autitor tool in the future?

    • @handgunpro3195
      @handgunpro3195 Рік тому

      I think you are referring to AI or machine learning in general, chatGPT is just a chat bot. But yes, there already exist many projects for finding bugs in code in an automated way using machine learning to find the best pathways of execution to follow, rather than brute force. There are some products out there that can automatically generate working exploit code, and of course, automatically generate the fix and tell the developers how to fix the issue.

    • @PatrickAlphaC
      @PatrickAlphaC  Рік тому +1

      Great question! So chatGPT big submissions have proved to be… bad.
      Maybe in the coming years, but right now it’s not good.

  • @beccalangdon5463
    @beccalangdon5463 Рік тому

    I wanna be #1

  • @VighneshRege
    @VighneshRege Рік тому

    I don’t understand the existing financial infrastructure well enough. Where can I read up on it? Like collateral, staking and other existing financial concepts

    • @PatrickAlphaC
      @PatrickAlphaC  Рік тому +3

      There are a number of great places to learn about DeFi, here is one: thedefiant.io/tag/defi-101

    • @emmanueloduor8365
      @emmanueloduor8365 3 місяці тому

      Thanks so much for sharing the link@@PatrickAlphaC

  • @cagataysilverwind33
    @cagataysilverwind33 Рік тому

    Selam from Türkiye Patrick. Don't forget the channel XD

  • @mhzboxing1759
    @mhzboxing1759 Рік тому +2

    I believe the most important thing that was said...READ DOCUMENTATION..

  • @benjaminrockiee3888
    @benjaminrockiee3888 Рік тому

    Please how can we make a token that can automatically keep minting a new token every second till 20 billion tokens are minted? I would really appreciate any open source for this.. And investors can purchase these tokens but will be unable to sell it till after 2 years?..

    • @PatrickAlphaC
      @PatrickAlphaC  Рік тому +1

      Really specific request, but basically you'd just have a "view" function of total supply which increments every block and then you'd disallow transfers.

    • @benjaminrockiee3888
      @benjaminrockiee3888 Рік тому

      @@PatrickAlphaC Okay thanks broski.. I wish I could see some codes in action that explains this, I'm kinda still a beginner!

    • @benjaminrockiee3888
      @benjaminrockiee3888 Рік тому

      @Patrick Collins Also do I need to use a vesting contract for the Time lock where these users can't withdraw or have access untill after two years? And then a different contract for this token minting?

    • @benjaminrockiee3888
      @benjaminrockiee3888 Рік тому

      @@PatrickAlphaC
      Actually this is what it's about
      A time Lock token to release a token every day (no longer seconds) till it gets to 20 billion..
      there will be pre issued tokens too for investors & developers but locked for 2 years (they wont be able to sale it for two years but it can be optional incase they need Money)

  • @peter9910
    @peter9910 4 місяці тому

    For those unaware, unless you're literally the #1 auditor, the likelihood that you'll end up penniless and on the streets is very high

    • @PatrickAlphaC
      @PatrickAlphaC  4 місяці тому

      Not true. The reality is the top 1% make a ton of money, the top 10% make good money, and everyone else makes a lot less.
      If you're only in here for making money, that's the situation. If you're here to make web3 more secure, these skills are helpful a million other places. Being a security focused smart contract developer actually makes you way more enticing to hire as an engineer.

    • @peter9910
      @peter9910 4 місяці тому

      @@PatrickAlphaC Yes but firms only want to hire either senior smart contract developers with years of tangible experience, or those who were lucky enough to be successful on ImmuneFi/C4 2 years ago.
      There's like 8 reputable smart contract security firms in the world, and none of them care anymore if you know the EVM inside out and have a respectable C4/ImmuneFi ranking

  • @theviperxxsy1041
    @theviperxxsy1041 Рік тому +2

    smart contract Auditor is veryyyyyyyyyyyyyyyyyyyyyy difficult job and hard job in the world

    • @HT_Ray
      @HT_Ray 5 місяців тому

      Hard for you!

  • @chris9352
    @chris9352 Рік тому

    Do you really think that he will tell you steps to take in order to become as good as him?
    Lol, people are really naive!

    • @signalrod2213
      @signalrod2213 Рік тому

      bro ...

    • @PatrickAlphaC
      @PatrickAlphaC  Рік тому +10

      I can see where you skeptisim is coming from, but I made a 32-hour-long tutorial to get people up to speed with me and this channel is dedicated to getting you better at being a web3 dev.
      Yes, I make sure when I work with someone they are being authentic. I also do security audits and his advice was 100% on the money.
      And in the grand scheme of things, it actually is in his best interest to teach people to get good enough to get into web3. The more people in web3, the more potential clients he has.

    • @DonDodge
      @DonDodge Рік тому +3

      Chris, Did you listen to the video? He absolutely revealed how he does audits, and the tools he uses.

    • @davidkulman2291
      @davidkulman2291 Рік тому +4

      The best auditor ever can tell you his exact step by step process. It doesn't mean you will be as good as him, not even close. To be a good auditor you need to put in the work.

    • @HT_Ray
      @HT_Ray 5 місяців тому

      Be careful - you attract what you are!

  • @brunorocha9898
    @brunorocha9898 Рік тому

  • @ankiy
    @ankiy Рік тому

    Patrick why that white hair while podcasting 🥹🥹😭😭😭😭🤣🤣