Too Late to Learn Web3 Security

Поділитися
Вставка
  • Опубліковано 3 жов 2024
  • Is it still worth it to learn web3 security now? Are the bounty rewards still good? My thoughts around whether it is still worth participating in audit contests on code4rena, and my future plans.

КОМЕНТАРІ • 60

  • @rokinot5523
    @rokinot5523 2 роки тому +5

    I think the reason why that high vuln payout was so low was because it was a low hanging fruit finding, almost 30 ppl found it and it was a very simple mistake to spot, which is why the rewards were so diluted. Some recent high vuln findings, if unique, were paying >5k for some contests, so there's still a chance to make some good amount

    • @andyli
      @andyli  2 роки тому +1

      True, we need to find uniques to get paid well now. Not easy though, I have not gotten a unique finding yet!

  • @lacag-lacag
    @lacag-lacag 2 роки тому +4

    Thanks keep the update man.

  • @cowsecurity
    @cowsecurity 2 роки тому +2

    Great work buddy, also thanks for accepting my request on linkedin!

    • @andyli
      @andyli  2 роки тому

      Thanks, good to connect!

  • @jaym4697
    @jaym4697 2 роки тому +7

    Great content. Keep it up!

  • @soaphornseuo8630
    @soaphornseuo8630 2 роки тому +5

    Thank brother 😀

    • @andyli
      @andyli  2 роки тому

      No problem!

  • @qu4ku
    @qu4ku 3 місяці тому

    the rewards are huge precisely because there is no competition (talent is scarce), when the talent is not scarce there is commoditization = even highs are worth $50/$500 (it's not different than thousands of indians available to make you an website).

  • @linuxinside6188
    @linuxinside6188 2 роки тому +1

    Great content andy 👌, thank you.

  • @arslanelahmer2729
    @arslanelahmer2729 11 місяців тому +3

    what's the situation one year on?

  • @mujtabaaltayib7417
    @mujtabaaltayib7417 2 роки тому +1

    I'm still confused on it but thanks for the guidance for the beginners like me

    • @andyli
      @andyli  2 роки тому +1

      No problem, feel free to ask any questions

  • @luce36
    @luce36 Рік тому

    This channel is amazing!

  • @tangjunnz
    @tangjunnz 2 роки тому +2

    Thanks

  • @jxkz7
    @jxkz7 5 днів тому

    Am i too late to start 😊?

  • @aftabkhan2677
    @aftabkhan2677 Рік тому +3

    Hi Andy, I am 19 just starting into web3. I am no previous experience in coding I am noob in coding, should I learn java script first or solidity ? In the article you mentioned in the road map of web3 security. its tolded to learn java first.

    • @andyli
      @andyli  Рік тому +4

      I would say Solidity first, go through the 32 hour solidity tutorial on youtube

    • @aftabkhan2677
      @aftabkhan2677 Рік тому

      Thank you will do that.

  • @devabdee
    @devabdee 2 роки тому +1

    TY. Sir

  • @serousetrick
    @serousetrick Рік тому +1

    Any advice on what can be profitable but still less competitive area of web3, like what smart contract auditing was a year or two ago?

    • @andyli
      @andyli  Рік тому +9

      No easy profits now since we are in a crypto bear market. Learning to become a dev/auditor in web3 is still going to pay off long term.

  • @tomj1883
    @tomj1883 2 роки тому +1

    yea I feel this too but I will definitely continue participating in code4rena because Im there to learn, not the money :) Thanks for the great content!

    • @andyli
      @andyli  2 роки тому +3

      yep 100%, money is just a bonus

  • @HelloWorld-sy4yc
    @HelloWorld-sy4yc 2 роки тому +1

    Ohh, u get it. It's cuz of your videos, dude...

    • @andyli
      @andyli  2 роки тому

      It can't *all* be because of my videos lol

  • @zerocool2765
    @zerocool2765 2 роки тому +1

    Should I start my journey in web 3 bug bounty or traditional bug bounty?

    • @andyli
      @andyli  2 роки тому

      web3 has bigger long term upside I think

  • @digitalchinmay263
    @digitalchinmay263 2 роки тому +1

    Hey do you know any other platforms other than code4rena, like one that accepts gas opt etc. ? I'm asking about permissionless open platforms.

    • @andyli
      @andyli  2 роки тому

      I don't know of any others that accepts QA and gas ops.

    • @digitalchinmay263
      @digitalchinmay263 2 роки тому

      @@andyli And other audit platforms ? Like code4rena and immunefi ?

  • @devone7702
    @devone7702 11 місяців тому

    I'm a proframmer, who is starting his journey in traditional bug bounty. Do you think it's better to learn web3 bug bounty instead ?

    • @andyli
      @andyli  11 місяців тому

      try some CTFs and see if you enjoy web3

  • @farena.human_
    @farena.human_ Рік тому

    Is it right time to learn web3 security? I mean now days

  • @emmanuelochubili
    @emmanuelochubili 2 роки тому

    @Andy please what are the requirements .. if i am a begginer in bug bounty

    • @andyli
      @andyli  2 роки тому +1

      Start with doing Ethernaut CTF, I made a video on beginner road map

    • @emmanuelochubili
      @emmanuelochubili 2 роки тому

      @@andyli thanks man.. will look for the link

  • @eugenionull9758
    @eugenionull9758 2 роки тому

    same feeling here... it's over

  • @ashhadali7592
    @ashhadali7592 2 роки тому

    So i start it or not whats ur advise? i already do web 2 bug bounties intrested to learn web 3 your advise save mu time

    • @andyli
      @andyli  2 роки тому +2

      Depends on if you are doing this full time and how much you are currently earning in web2 bounties.
      It is still possible to make $500-$1000 per month doing this part time, and of course the long term upside is huge

    • @ashhadali7592
      @ashhadali7592 2 роки тому +4

      @@andyli no part time
      In web 2 mar earning is 1000-2000$
      2) part time 1000$ is good so u mean i start it
      Thank you Very much
      u help me alot

  • @goodboy9758
    @goodboy9758 2 роки тому +1

    psyops

  • @bluelantern5241
    @bluelantern5241 2 місяці тому

    Bro youve got to stop making that "suck" noise. Have you ever gone back and listened. Holy cow

  • @fuffsec
    @fuffsec 2 роки тому

    Great content. Thank you so much

  • @haanrey
    @haanrey 2 роки тому +4

    Don't take advice from everyone. I had found a $$$$$ bug in one of the oldest programs in bugcrowd . The bug was 5 years old .

    • @andyli
      @andyli  2 роки тому +1

      damn, congrats

    • @haanrey
      @haanrey 9 місяців тому

      @@andyli coming here after a year , I am sorry for being rude while commenting . I wish you more success .

    • @priyanshujaswal2210
      @priyanshujaswal2210 3 місяці тому

      ​@@haanreyAt least you learnt brother. And doing this after a few months shows that you are a good person 😊