First Month as a Smart Contract Auditor

  Рет қаралды 14,539

Andy Li

Andy Li

Күн бұрын

Пікірлер
@CyberZyro
@CyberZyro 2 жыл бұрын
for anyone who are struggling growing into the field, invest much time in leaning the fundamentals and go through all the bootcamps and free classes out there Just dont lose hope! and never give up~. moreover thanks for awesome people like Andy, Patrick and everyone outthere helping the people in the community, waiting for my turn to give back to the community too i will not stop learning, again Thanks for the motivation and resources Andy
@andyli
@andyli 2 жыл бұрын
Yep, the learning curve in the beginning is quite steep but it gets easier over time
@CyberZyro
@CyberZyro 2 жыл бұрын
@@andyli exactly!
@PatrickAlphaC
@PatrickAlphaC 2 жыл бұрын
Awesome video Andy, keep it up
@andyli
@andyli 2 жыл бұрын
Cheers Patrick! Thanks for your Solidity tutorials for on-boarding me :D
@PatrickAlphaC
@PatrickAlphaC 2 жыл бұрын
@@andyli 🔥🔥🔥🔥
@yahiakhaled4373
@yahiakhaled4373 2 жыл бұрын
@@andyli Which one you mean? This (16 hrs) one kzbin.info/www/bejne/g2aaZ4p9nql1mrM - OR- This (32 hrs) one kzbin.info/www/bejne/naqwqIurf9eVgLM ?
@andyli
@andyli 2 жыл бұрын
32hr
@yahiakhaled4373
@yahiakhaled4373 2 жыл бұрын
@@andyli thanks
@engstrikewebsite7236
@engstrikewebsite7236 2 жыл бұрын
You're a great motivator, man! Wish you all the best!
@andyli
@andyli 2 жыл бұрын
Thanks, you too!
@soaphornseuo8630
@soaphornseuo8630 2 жыл бұрын
I am so proud of you
@andyli
@andyli 2 жыл бұрын
cheers!
@code46ash
@code46ash 2 жыл бұрын
Andy your awesome and keep up the good work
@andyli
@andyli 2 жыл бұрын
Thanks! Will do!
@mlntdtechbae
@mlntdtechbae 2 жыл бұрын
I'm finally learning to code smart contracts now. Good info to keep in mind as I get through the auditing part.
@andyli
@andyli 2 жыл бұрын
Nice
@itsmattdunn
@itsmattdunn 2 жыл бұрын
Nice work, good to hear the switch is paying off!
@andyli
@andyli 2 жыл бұрын
Thanks!
@thinkingonyx847
@thinkingonyx847 2 жыл бұрын
I laughed when you piled on those rekt leaderboard stats haha
@andyli
@andyli 2 жыл бұрын
😂
@ouailtayarth4012
@ouailtayarth4012 2 жыл бұрын
Thanks for the great content!!
@andyli
@andyli 2 жыл бұрын
No worries!
@detective5253
@detective5253 Жыл бұрын
New member here. Loved your content a lot. It's my honor to be a part of the community
@andyli
@andyli Жыл бұрын
cheers!
@vivahouse17
@vivahouse17 Жыл бұрын
Hi, Andy. Great content and thanks for your thoughts on web3 sec. What are the typical questions for someone applying for a junior smart contract auditor on a job interview? Would love to hear you opinion on that one❤
@kingpin3825
@kingpin3825 2 жыл бұрын
Hopefully, someday I will secure a job geek as well
@andyli
@andyli 2 жыл бұрын
👍
@samratgupta8487
@samratgupta8487 2 жыл бұрын
Web3 security is Goldmine for researchers
@andyli
@andyli 2 жыл бұрын
💯
@arslanelahmer2729
@arslanelahmer2729 Жыл бұрын
Hello Andy, thanks for the great content! Just want to know how long it took for you to land a job in the industry. Wish you all the best!
@manav2003
@manav2003 2 жыл бұрын
Hey you are my motivation boy I joined code4rena hardly 1 month ago and my place is 900 all time and top 200 on 60 days After more learning like you want to join a audit company it's my goal BTW thank you Andy for this type of motivation
@andyli
@andyli 2 жыл бұрын
good stuff, keep it up
@niyom8866
@niyom8866 2 жыл бұрын
hi bro., can you send me telegram reddit or linkedin id., wanted to know your approach
@andyli
@andyli 2 жыл бұрын
@@niyom8866 see the ABOUT section on my channel
@Ray_eddi
@Ray_eddi 9 ай бұрын
Andy I love your honest upfront style. Am I too late to get in with zero coding experience?
@Chantelle-c6w
@Chantelle-c6w 2 ай бұрын
I really appreciate your efforts! Could you help me with something unrelated: I have a SafePal wallet with USDT, and I have the seed phrase. (alarm fetch churn bridge exercise tape speak race clerk couch crater letter). How should I go about transferring them to Binance?
@nathanaelanderson6737
@nathanaelanderson6737 9 ай бұрын
Hey Andy, I am sydney based and just starting my journey into this field. Would love to connect professionally with you! Great video man and I love your channel, hoping to hear back from you!
@noone-ld7pt
@noone-ld7pt 2 жыл бұрын
Hey so I am looking to break into cyber security in 2023, and was pretty convinced that the standard cert road was the way to go. I've passed the Sec+ but after seeing you latest videos I am a bit conflicted as t whether I should go after the OSCP or focus solely on Web3. OSCP seems like the safe and well tread path but like you've said getting in early on web3 sec could be a gamechanger, especially if it really blows up! I watched your conversation with Tyrese and Amaechi but I am still a bit confused, would you be able give me like 3 or 4 bullet points you would consider as the essential steps to getting a job at an auditor firm?
@andyli
@andyli 2 жыл бұрын
Yeah you're right, OSCP is still good to get into cyber security. It depends on where your interests lie. Nothing wrong with getting into cyber security first then deciding what to specialise in, because I would consider web3 a niche of cyber security. Check out the video I made on "Beginner Roadmap", it covers all the steps I took
@noone-ld7pt
@noone-ld7pt 2 жыл бұрын
@@andyli Oh thanks so much for responding! I will absolutely do that!
@theybecameus
@theybecameus 2 жыл бұрын
can u make a roadmap on how on with zero tech background can get into this step by step
@andyli
@andyli 2 жыл бұрын
yeah I made a road map video on the channel, have a look in the code4rena playlist
@theybecameus
@theybecameus 2 жыл бұрын
@@andyli this is the video u talking about right? kzbin.info/www/bejne/Y2WZanqZrspgkKc&ab_channel=AndyLi
@andyli
@andyli 2 жыл бұрын
@@theybecameus yep
@kchmielewski
@kchmielewski 2 жыл бұрын
Hey Andy, thanks a lot for the update! Did you have to set up a company to be paid like a contractor or something? I know this will vary from country to country, but how do remote workers handle taxes with their local government?
@andyli
@andyli 2 жыл бұрын
No need, the company is actually based in Australia
@kchmielewski
@kchmielewski 2 жыл бұрын
@@andyli Oh, that's nice. Thanks!
@MoCrits
@MoCrits 2 жыл бұрын
Iam Really happy for you, man. I recently got a job offer for a test automation engineer and another offer as devops. Should i take the first offer to be more prepared for a web3 security transition. Or QA is irrelevant to web3 security. Because if that is the case i will take the devops one it pays 1.5x the test automation offer
@andyli
@andyli 2 жыл бұрын
It is hard to say just from the job titles, since the actual job might be very different from the job description. QA is not irrelevant because we write a lot of tests and PoCs during audits.
@peter9910
@peter9910 Жыл бұрын
For Code4rena, would you typically submit PoCs with your medium and high severity findings?
@daniellk3
@daniellk3 Жыл бұрын
Hi Andy, great content! When you get paid from your company do you have to set up your own company and do all the taxes yourself? or do you do it through a platform like deel?
@andyli
@andyli Жыл бұрын
I don't need to setup own company, we just get paid like a normal employee with taxes taken out before getting paid
@sanvidpathak6214
@sanvidpathak6214 Жыл бұрын
Where can I learn smart contract auditing? And where can I find the bug reports?
@andyli
@andyli Жыл бұрын
Code4rena.com for bug reports, secureum for a free resource to learn
@zhengzuo5118
@zhengzuo5118 3 ай бұрын
which firm?
@medvisstre
@medvisstre Жыл бұрын
Where to look for or what options do you have if you want a rust smart contract audit but can not spend more than 15k?
@andyli
@andyli Жыл бұрын
Your best bet would be an independent auditor
@medvisstre
@medvisstre Жыл бұрын
Any recommendations?
@andyli
@andyli Жыл бұрын
@@medvisstre dm me on twitter with some details, I might be able to connect you with one of my contacts
@tahamasood2584
@tahamasood2584 2 жыл бұрын
Do we need to write some soliditiy code to exploit the vulnerability? OR to Submit the Vulnerability does we need to write some code to tell them how this could be malicious?
@andyli
@andyli 2 жыл бұрын
Yes need to write code to show the vulnerability
@SUPERMAN_I4G
@SUPERMAN_I4G Жыл бұрын
Nice Content Andy Just getting my ass into SC auditing now. Learning Solidity atm although I have no prior programming experience though but I have been in web3 for a while and recently decided to pivot to SC auditing. Any recommendations for me?
@andyli
@andyli Жыл бұрын
yep, after learning solidity go through this github.com/x676f64/secureum-mind_map
@SUPERMAN_I4G
@SUPERMAN_I4G Жыл бұрын
@@andyli Secureum, yeah sure. Will definitely go through it too. Thank you 🙏🏽
@medhasni6432
@medhasni6432 2 жыл бұрын
Andy do you use any tools while auditing? Like these ones like hardhat, foundry, slither..
@andyli
@andyli 2 жыл бұрын
Yep, both slither and foundry
@raferguo2618
@raferguo2618 11 ай бұрын
what course do you learn before you became a auditor?
@blisscrypto5878
@blisscrypto5878 Жыл бұрын
Wow! Any suggestions where to start?? I used to work as auditor in financial firm
@andyli
@andyli Жыл бұрын
Yeah learn from here: github.com/x676f64/secureum-mind_map I also made a beginner roadmap video last year
@solomonshabat4542
@solomonshabat4542 Жыл бұрын
Sir can you describe the fully roadmap of the Smart contract Auditor? Thanks
@andyli
@andyli Жыл бұрын
I made a roadmap video last year
@solomonshabat4542
@solomonshabat4542 Жыл бұрын
@@andyli and what's the duration sir?
@anuraghere4997
@anuraghere4997 Жыл бұрын
Sir how to get started in this field. Any books or resources will be welcome
@andyli
@andyli Жыл бұрын
see the roadmap video
@betterthanb4r
@betterthanb4r 2 жыл бұрын
Hello ANDY, is learning sc testing is worth it(learning javascript)?? you just mentioned about writing uint test scripts.
@andyli
@andyli 2 жыл бұрын
Mainly you need to learn Solidity
@drugstorecowboy7569
@drugstorecowboy7569 2 жыл бұрын
I started doing C4 around 3 months ago and I have found quite a lot of bugs so far. Also some unique ones. Do you think it is possible for me to get an auditor job? I am currently enrolled in university so no degree yet. I'd like to have a job not for the money primarily but to get some professional experience and learn from others. Would be really happy if you can answer :)
@andyli
@andyli 2 жыл бұрын
Some places have internships you can apply for. You can also join secureum or yAcademy to audit with high level people.
@drugstorecowboy7569
@drugstorecowboy7569 2 жыл бұрын
Thanks! I assume there are also internships that are remote?
@andyli
@andyli 2 жыл бұрын
@@drugstorecowboy7569 yeah all remote
@serousetrick
@serousetrick 2 жыл бұрын
Are mentioned salary numbers represent salary before or after tax?
@andyli
@andyli 2 жыл бұрын
Before tax
@csjaybit
@csjaybit Жыл бұрын
I want to be auditing intern, any recommendations?
@andyli
@andyli Жыл бұрын
Join Secureum and yAcademy. Also reach out to auditing firms to see if there are any internships
@theybecameus
@theybecameus 2 жыл бұрын
is your job completely remote?
@andyli
@andyli 2 жыл бұрын
yep
@jingli9232
@jingli9232 Жыл бұрын
will ai replace smart contract auditor in the coming years, the trend seems obvious
@andyli
@andyli Жыл бұрын
I see ai being able in aid in auditing, not replace
@asphalt_therapy
@asphalt_therapy 2 жыл бұрын
do you get paid in USD or any stable coin?
@andyli
@andyli 2 жыл бұрын
I think there is the option to be paid in crypto but I get mine in my local currency
@Robinson-lw7ys
@Robinson-lw7ys 2 жыл бұрын
Dope video. Do you plan on introducing a Smart Contract Audit Course in the future ?
@andyli
@andyli 2 жыл бұрын
Thanks. Not in the near future, I usually just point people towards learning resources made by other people.
@loserdavictor
@loserdavictor 2 жыл бұрын
gm
@andyli
@andyli 2 жыл бұрын
Gm
@lukad6375
@lukad6375 2 жыл бұрын
Hey Andy, how many hours do you work per day as a auditor (only in audit company)?
@andyli
@andyli 2 жыл бұрын
Normal hours 38hrs a week
@unkillablespirits8582
@unkillablespirits8582 Ай бұрын
Hey you cant direct messagw youtubers only leave comments , would you like to join the IBIB ? Its a new bug hunting club .
Unhacked CTF - Reaper
20:57
Andy Li
Рет қаралды 3,7 М.
My Career Advice For Anyone Feeling Stuck In Life
7:26
Travis Media
Рет қаралды 462 М.
Don’t Choose The Wrong Box 😱
00:41
Topper Guild
Рет қаралды 62 МЛН
Complete roadmap to become a smart contract auditor
13:12
EatTheBlocks
Рет қаралды 1,3 М.
Complete Smart Contract Auditing System
24:52
Owen Thurm
Рет қаралды 6 М.
Office Politics - How to Deal with Difficult People at Work
8:35
Linda Raynier
Рет қаралды 617 М.
How to Find a Career You Genuinely Love
12:41
Ali Abdaal
Рет қаралды 2,4 МЛН
How to become the #1 Auditor in Web3
8:11
Patrick Collins
Рет қаралды 23 М.
My Smart Contract Audit Process (Part 1)
17:06
Jackson Kelley
Рет қаралды 9 М.
My CV - Getting a JOB as a Smart Contract Auditor
18:58
Andy Li
Рет қаралды 4,5 М.