Last day of the month.
Not everything went exactly as planned.
But there’s still progress to take with me into the next one.
One more day. One more push.
🎯 Day 237
🕰️ 3h
Completed the upgradeable smart contract section today.
Now I’m going to spend some time practicing and reinforcing what I’ve learned before moving on.
Understanding first. Moving forward second.
@PatrickAlphaC
🎯 Day 235
🕰️ 3h
Back after a long break.
Started learning about upgradeable smart contracts today.
New topic, fresh start. Time to get back into the rhythm.
@PatrickAlphaC
🎯 Day 235
🕰️ 3h
Back after a long break.
Started learning about upgradeable smart contracts today.
New topic, fresh start. Time to get back into the rhythm.
@PatrickAlphaC
💰🚨 $1.4M from Web3 bug bounties in 2026!
Meet @0xvivekd and learn about his journey, mindset, AI workflow, and the lessons he's learned along the way.
Part 1: The Journey
- Vivek didn't come from a software engineering background.
- He was a Chartered Accountant (licensed financial and tax professional) running his own firm.
- In 2021, a friend who traded crypto came to him for help filing taxes. That's how he got introduced to crypto and started investing, mainly participating in IDOs (Initial DEX Offerings).
- When the bear market arrived, he didn't leave the industry. He pivoted into data analysis.
- Then in 2023, as the market became active again, he started airdrop farming.
- In June 2024, he entered Web3 security through public audit contests.
- The next 15 months were difficult.
- He kept participating in contests but struggled to achieve consistent results.
- Around August/September 2025, he made a decision that completely changed his career.
- He switched from public audit contests to bug bounties.
Today, he has earned over $1.3M in bug bounties in 2026 alone, including another $250,000 critical bounty announced yesterday.
Part 2: The Mindset
- "Bug bounties are not difficult in the technical sense. They are difficult from a psychological point of view."
- He explained what led him to leave audit contests:
- During a White Hat Mastermind, everyone was asked what they were working on.
- Around half of the researchers were working on the contest with the smallest scope and the lowest payout.
- Vivek realized he was always choosing the easiest targets because they offered the fastest and most predictable payouts.
- Bug bounties were different. There was no guarantee of finding anything. No guaranteed payout. Sometimes weeks of work could lead to nothing.
- That was exactly why he switched.
- As he put it:
"Bug bounty hunters are paid handsomely for dealing with uncertainty."
Part 3: AI
- AI has completely changed Vivek's workflow.
- Today, he gives AI a target while he spends that same time building a high-level understanding of the protocol.
- Once AI surfaces potential issues, he validates them, removes false positives, and determines whether they're actually valid vulnerabilities.
- His estimate surprised me.
Today, around 70-80% of the issues are initially surfaced by AI.
- But he doesn't believe AI will replace security researchers. His reasoning is simple.
- AI is excellent at spotting unusual behavior. It still struggles to understand intended behavior. That's why human validation remains essential.
- He also believes the learning process has changed.
- Reading audit reports and recent hacks is still fundamental, but today researchers should also follow AI developments and continuously experiment with AI tools.
Part 4: Advice
- According to Vivek, DISCIPLINE is what separates the best researchers from everyone else.
- His advice was straightforward:
Don't expect meaningful results during your first 12 months. Focus on the inputs, not the outputs. Don't compare yourself to researchers who have been building their skills for years. Stay disciplined. Don't chase shiny objects. Keep adapting as the industry evolves.
- One detail I really liked was how he dealt with difficult periods.
- Whenever he went through a dry spell, he listened to podcasts from other top white hats.
- Not because they never struggled. But because they did.
- It reminded him that even the best researchers experience periods without finding bugs.
Congratulations on the incredible journey! @0xvivekd. 👏
Got a lot of DMs after the Immunefi post asking for advice on web3, security, careers, etc.
Thank you all, but unfortunately I don’t have time to reply to everyone individually.
Still, there’s one story I really want everyone to hear:
A young man once came to Socrates and said he wanted knowledge. Socrates took him to the sea, pushed his head underwater and held him there. When he finally let him up, the young man was gasping desperately for air.
Socrates said:
“When you want knowledge as badly as you wanted air just now, then you will get it.”
The same applies to web3, smart contract auditing, security, or anything else.
There are no shortcuts. If you truly internalize this story and want knowledge that much, I believe you will succeed.
every Claude and ChatGPT user now has the power to trade anything on @solana by having a conversation
welcome to PayBox, the payment vault and non-custodial wallet that lets AI Agents securely transact across the open internet
prompt, approve, pay: paybox.sh
today we are going to feed CT
ahead of the festivities and official claim instructions, a few notes:
1️⃣ over 270,000 people have used PayBox since launch
2️⃣ things might get a little crazy, but our team is all hands on deck
3️⃣ official claim mechanics will change slightly
4️⃣ we take data privacy very seriously
5️⃣ get ready by connecting PayBox to Claude or ChatGPT at paybox.sh
6️⃣ all info will come from this account
love you all
every Claude and ChatGPT user now has the power to trade anything on @solana by having a conversation
welcome to PayBox, the payment vault and non-custodial wallet that lets AI Agents securely transact across the open internet
prompt, approve, pay: paybox.sh
Day 234
Still focused on theory.
Reminder: Before implementing CCIP, understand the flow first.
User → Token Pool → CCIP Router → Destination Token Pool → Mint
Code is easier to write when the architecture makes sense.
Day 233
Took a step back from coding today to focus on understanding how Chainlink CCIP works under the hood.
Strong foundations make implementation much easier.
#BuildInPublic#CCIP#Solidity
Day 232
Started integrating my Burn & Mint token with Chainlink CCIP.
Added a dedicated pool role for minting and burning. Next up is extending TokenPool for the cross-chain flow.
#BuildInPublic#Solidity#Web3Security#CCIP
🚨ALERT: Web3 security firm Blockaid has detected an ongoing exploit targeting Garden Finance’s HTLC contracts.
Around $450,000 in USDT has been drained across Ethereum, Base, Arbitrum and BNB Chain so far.
262 Followers 301 FollowingFrontend dev going all-in on Web3 🔗 | BlockChain | Learning Solidity in public | Turning UIs into dApps | Document everything😁
414K Followers 26K FollowingHelping the world move value since 2019. Try PayBox today. Title Partner of MoonPay X Games League. Posts here not intended for UK users - follow @moonpay_UK!
41K Followers 546 FollowingAfter 5 years of securing DeFi, Code4rena has closed its doors.
Follow our ongoing security work at @zellic_io, @v12sec, & @zenith256.
2K Followers 666 Followingbreaking your smart contracts before the bad guys do |
Senior Security Researcher @sherlockdefi |
Associate All Star @Immunefi
1K Followers 1K FollowingSecurity Researcher Friend, Advocate & Community Activator
Host of The Island 🌺 🏝️
🕹️ also working on web3 auditing indie game!
prev @immunefi
25K Followers 5 FollowingTeaching the next generation of web3 developers.
150+ hours of Smart Contract Development and Security Courses, completely for Free.
Powered by @cyfrin