How To Make 6 Figures+ With Smart Contract Audits

Owen Thurm
30 Mar 202325:09

Summary

TLDRThis video offers a comprehensive guide for aspiring smart contract auditors to transition from beginner to earning six figures. The speaker, founder of Guardian Audits, shares personal insights and strategies, emphasizing the importance of building a personal brand and leveraging contests to gain initial exposure. The script outlines steps to establish an inbound sales process, build a network, and create a risk-free offer to attract clients, ultimately leading to a successful and lucrative auditing career in the web3 space.

Takeaways

  • 🚀 **Starting Point**: The speaker emphasizes the importance of having a solid foundation in smart contract auditing, including knowledge of Solidity, experience with DApps, and familiarity with security practices.
  • 💡 **Personal Branding**: Building a personal brand is crucial for long-term success in smart contract auditing, as it makes one irreplaceable and compounds over time.
  • 🏆 **Contests as a Tool**: While not ideal for long-term income, contests can be a great way to kick-start one's brand and gain initial recognition in the field.
  • 🔄 **Avoid Commodification**: Being part of a contest can commoditize auditors, making them easily replaceable. It's better to build a unique brand that grows with each effort.
  • 📈 **Inbound Sales Strategy**: The speaker recommends an inbound sales process over an outbound one, given the time-specific nature of smart contract audits.
  • 🤝 **Building Connections**: Networking is key to establishing a strong presence in the web3 space, which can lead to inbound leads and clients.
  • 📊 **Value-First Approach**: Offering value upfront without expecting anything in return can initiate connections with protocols and build trust.
  • 📝 **Documentation and Transparency**: Keeping a public record of audits and findings on platforms like GitHub can enhance credibility and attract clients.
  • 💰 **Risk-Free Offers**: Making an offer that is contingent on finding vulnerabilities can reduce the perceived risk for clients and increase the likelihood of securing an audit.
  • 📈 **Portfolio Development**: A growing portfolio of quality audits and collaborations contributes to a strong personal brand and attracts better clients.
  • 🌐 **Community Engagement**: Actively participating in the community by sharing knowledge and insights can lead to more connections and opportunities.

Q & A

  • What is the main goal of the video?

    -The main goal of the video is to provide a comprehensive guide on how to earn six figures or more as a smart contract auditor, sharing the speaker's personal experience and strategies.

  • Why did the speaker found Guardian Audits?

    -The speaker founded Guardian Audits to transition from zero to getting paid audits, eventually quitting their job as a software engineer and building a team to deliver high-quality audit reports to major protocols.

  • What is the speaker's view on using contests as a long-term income source for auditors?

    -The speaker does not favor contests as a long-term income source because they commoditize auditors, making them easily replaceable. However, they acknowledge contests as a good way to kick-start a brand and improve auditing skills.

  • Why is it important to have the same handle on Discord and Twitter for an auditor?

    -Having the same handle on Discord and Twitter helps an auditor to be easily recognized across platforms, which can boost their personal brand and reputation in the web3 space.

  • What is the key difference between inbound and outbound sales processes in the context of smart contract auditing?

    -Inbound sales processes focus on clients coming to the auditor when they need the service, while outbound processes involve the auditor reaching out to clients regardless of whether they need an audit at that time. Inbound is more effective for time-specific products like audits.

  • How can auditors provide value to protocols without expecting anything in return?

    -Auditors can provide value by releasing articles that do high-level technical breakdowns of protocols, offering free code reviews, or participating in audits and contests, all with the aim of initiating connections and building trust.

  • What is the significance of building a personal brand and portfolio in the web3 space?

    -Building a personal brand and portfolio is crucial for gaining credibility, showcasing expertise, and attracting inbound leads and clients who need smart contract audits.

  • What is the 'pay per vulnerability' model and how does it benefit the auditor and the client?

    -The 'pay per vulnerability' model involves asking for a small down payment and charging more only if vulnerabilities are found. This removes risk for the client and makes it easier for them to accept the offer, while still allowing the auditor to be compensated for their work.

  • How does the speaker suggest building a network in the web3 space?

    -The speaker suggests building a network by participating in industry events, joining Discord servers, engaging on Twitter, collaborating on audits, and consistently providing value to the community through shared knowledge and insights.

  • What is the importance of protecting one's personal brand when choosing clients for smart contract auditing?

    -Protecting one's personal brand is important because the quality of clients and reports directly affects reputation. Choosing serious clients who value security and are willing to pay for quality work can lead to a virtuous cycle of better clients and higher earnings.

  • What additional resources does the speaker offer for those interested in smart contract auditing?

    -The speaker offers a link to lab.guardianaudits.com for building web3 connections and joining a group of auditors, and a program collaboration with security professionals for those who want to become certified pro smart contract auditors, with a discount provided through a link in the description.

Outlines

00:00

🚀 Starting Smart Contract Auditing Journey

The speaker introduces the video as a comprehensive guide to earning significant income through smart contract auditing. They emphasize the necessity of hard work and perseverance, contrary to the 'four-hour work week' myth. The speaker's credibility is established through their experience founding Guardian Audits, which led to quitting their software engineering job to build a team delivering high-quality audit reports. The video promises to share the exact steps to become a proficient smart contract auditor, avoiding common pitfalls.

05:03

🤔 The Strategy for Building a Sustainable Brand

This paragraph delves into the speaker's aversion to contests as a long-term income source for auditors due to their commoditizing nature. They argue for building a personal brand that compounds over time, making one irreplaceable. The speaker suggests leveraging contests to kick-start the brand by creating and sharing individual reports of findings and using social media to boost reputation. They also stress the importance of consistent branding across platforms like Twitter and Discord.

10:03

🛠️ Crafting an Inbound Sales Process for Audits

The speaker discusses the importance of recognizing smart contract audits as time-specific products, necessitating an inbound sales process. They advocate for providing value upfront without immediate expectation of return to initiate relationships with protocols. Suggestions include releasing articles or conducting free code reviews to demonstrate expertise and initiate connections, which can lead to a network that generates inbound leads over time.

15:05

🌐 Expanding Network and Building an Audience

The speaker emphasizes the importance of networking within the web3 space, not just with potential clients but with everyone. They suggest sharing knowledge through threads on Twitter, joining audits in contests, and attending industry events to build strong connections. The speaker also highlights the importance of building a GitHub portfolio to showcase work and gain credibility, which can lead to better clients and higher-quality audits.

20:09

📈 Scaling from Zero to a Successful Auditing Career

The speaker outlines a framework for going from zero to a successful smart contract auditor. They recommend setting up a Twitter profile with a clear call to action, creating threads to provide value and initiate connections with protocols, and offering a risk-free pay-per-vulnerability model to secure the first client. The speaker stresses the importance of building a strong portfolio and choosing the right clients to protect one's reputation and ensure a virtuous cycle of better clients and higher-quality work.

💼 Achieving Six-Figure Success and Beyond

In the final paragraph, the speaker discusses the importance of cultivating powerful relationships and continuing to invest effort to achieve six-figure success in smart contract auditing. They provide a link to a program for further skill development and encourage joining a community of auditors for collaboration and growth. The speaker concludes by reiterating the potential for significant earnings in the field and the importance of protecting one's personal brand.

Mindmap

Keywords

💡Solidity

Solidity is an object-oriented, high-level programming language for developing smart contracts on the Ethereum blockchain. In the video, it is the foundation for building decentralized applications (dApps) and is essential for smart contract auditing, which is a key theme of the video.

💡Smart Contract Auditing

Smart contract auditing refers to the process of examining and verifying the security and functionality of smart contracts to prevent vulnerabilities and ensure they perform as intended. The video focuses on how to build a career in this field, emphasizing the importance of auditing for the safety of blockchain-based projects.

💡Web3

Web3, or Web 3.0, is a term used to describe the next generation of the internet, which incorporates decentralized technologies like blockchain. The video discusses building a personal brand and career in the Web3 space, particularly focusing on smart contract auditing.

💡CTFs (Capture The Flag)

CTFs are cybersecurity competitions where participants solve a series of challenges to 'capture the flag'. In the script, completing CTFs is mentioned as a way to gain practical experience and skills in smart contract security, which is valuable for an auditor.

💡Personal Brand

A personal brand is the unique image or identity that an individual projects in their professional life. The video emphasizes building a personal brand in the Web3 space to establish credibility and attract clients for smart contract auditing services.

💡Inbound Sales Process

An inbound sales process is a marketing strategy that focuses on attracting customers through content marketing and other means, rather than actively seeking them out. The video suggests using inbound strategies to attract clients for smart contract audits when they are most likely to need the service.

💡Lead Generation

Lead generation is the initiation of consumer interest or inquiry into a product or service. The video discusses the importance of lead generation in building a client base for smart contract auditing, particularly through networking and content creation.

💡Commoditized Position

A commoditized position refers to a state where a product or service is treated as interchangeable with competitors. The video warns against being in a commoditized position in the auditing field, advocating for building a unique and irreplaceable personal brand instead.

💡Compounding Brand

A compounding brand is one that grows in value over time through consistent effort and quality work. The video stresses the importance of building a compounding brand in smart contract auditing to become irreplaceable and gain long-term success.

💡Risk-Free Offer

A risk-free offer is a proposal to potential clients that minimizes their perceived risk, often by offering a guarantee or a low initial payment. The video suggests using a risk-free offer, such as 'pay per vulnerability', to attract clients for smart contract audits and demonstrate confidence in one's abilities.

💡Sweat Equity

Sweat equity refers to the effort and hard work put into a project or business in lieu of financial investment. The video mentions putting in 'sweat equity' as a means to grow one's network and reputation in the Web3 space, which ultimately leads to success in smart contract auditing.

Highlights

The video aims to guide viewers on how to earn six figures or more by auditing smart contracts, emphasizing the need for massive action and perseverance.

The speaker shares their journey from founding Guardian Audits to becoming a successful smart contract auditor, offering to share their learnings to help viewers avoid common mistakes.

Contests are not recommended as a long-term income source for auditors due to their commoditized nature but are useful for initial brand exposure and skill improvement.

Building a personal brand that compounds over time is more valuable than contest-based income, making the auditor irreplaceable.

To leverage contests, create your own report after the contest ends to showcase your findings and expertise.

Sharing contest achievements on social media like Twitter can boost personal brand reputation in the web3 space.

Consistency in branding across platforms like Discord and Twitter helps in recognition and credibility.

Smart contract audits are time-specific products, requiring an inbound sales process focused on building a web of connections for lead generation.

Providing free value upfront to protocols, such as technical breakdowns or code reviews, initiates connections and trust.

Building a network involves engaging with the community, sharing knowledge, and collaborating with other auditors.

Participating in team audits or industry events can accelerate network growth and lead to private audit opportunities.

Creating a public portfolio on GitHub showcasing audit reports and findings adds credibility and attracts clients.

The speaker outlines a step-by-step framework for starting from zero, including setting up a professional Twitter profile and offering risk-free audit services.

Consistently creating and sharing technical threads on Twitter about various protocols can attract an audience and initiate protocol connections.

A pay-per-vulnerability model with a small down payment reduces client risk and can lead to higher payments for critical findings.

As the portfolio and connections grow, increasing the down payment and being selective about clients can protect and enhance the auditor's brand.

Cultivating strong relationships with collaborators and clients is key to long-term success in the smart contract auditing field.

The Solidity Lab offers a community for auditors to connect, collaborate, and participate in team audits, providing opportunities to sharpen skills and build a network.

A collaboration with security professionals offers a comprehensive program to certify and enhance smart contract auditing skills.

Transcripts

play00:00

okay so you've done the work you've

play00:02

learned solidity you've built some cool

play00:03

dapps read through dozens of audit

play00:05

reports scrolled through all of the web

play00:08

3 security related threads on Twitter

play00:10

and completed countless ctfs so now it's

play00:13

time to make some money but how in this

play00:15

video I'm going to answer this exact

play00:18

question to the absolute best of my

play00:20

ability this is the ultimate guide from

play00:23

going from zero to six figures in even

play00:26

multiple six figures through smart

play00:28

contract auditing and for the first time

play00:31

in a YouTube video This is actually not

play00:33

clickbait getting to that level is

play00:35

certainly not some four hour work week

play00:37

from the beach it will take in fact

play00:40

Massive Action and massive effort

play00:43

combined with extreme perseverance on

play00:46

your part but I'm here to tell you that

play00:48

it is indeed possible and lay out the

play00:51

exact steps that you need to take to

play00:53

actually get there but first why should

play00:55

you listen to me over a year ago I

play00:57

founded Guardian Audits and during my

play00:59

journey I learned how to go from

play01:01

absolutely zero to getting my first paid

play01:04

audit and then my second bigger audit

play01:07

and a third and a fourth and a fifth and

play01:10

so on until eventually I was able to

play01:12

quit my job as a software engineer and

play01:14

build out a team to deliver some of the

play01:16

highest quality auto reports to the

play01:19

biggest protocols in the space and so my

play01:22

goal is to distill down everything that

play01:24

I've learned from each step along the

play01:25

way and give it to you so you can avoid

play01:27

all of the mistakes that I made and

play01:30

ultimately become a much better smart

play01:32

contract auditor because of it alright

play01:34

we've got a lot to discuss so let's just

play01:37

hop right into it

play01:42

[Music]

play01:45

all right like I said in this video I'm

play01:48

not going to be holding anything back

play01:50

I'm going to give you literally

play01:52

everything I know about how you can earn

play01:54

six figures plus as a smart contract

play01:57

auditor the only thing I ask you to

play01:59

understand is that this is not going to

play02:01

be easy but with that being said I want

play02:03

you to know that it is entirely possible

play02:06

you are entirely capable of doing it and

play02:09

if you follow these principles and

play02:11

strategies that we're about to outline

play02:13

you will likely do it far quicker than I

play02:16

did all right we're going to cover four

play02:18

things in this video first of all why I

play02:21

don't like contests as a long-term

play02:23

income Source second of all how auditar

play02:26

a Time specific product and how that

play02:28

affects the way that we need to think

play02:30

about our lead generation and then third

play02:33

I'm going to go over a high level

play02:35

process to go from 0 to 1 and then

play02:39

beyond with your personal web3 brand and

play02:42

auditing portfolio and then finally I'm

play02:45

going to cover exactly what I would do

play02:47

if I had to start from zero all over

play02:49

again okay so first of all let's talk

play02:51

about why I don't like contests I don't

play02:54

like contests because they put you as an

play02:57

auditor in a commoditized position by

play03:01

that I essentially just mean that you

play03:02

are easily replaceable in the contest

play03:06

environment it might be true that you're

play03:08

able to make a good amount of money

play03:11

right off the bat by participating in

play03:13

some contests but unless you're building

play03:15

a brand based on it it's not very

play03:16

defensible over the long run more people

play03:19

can come in and instantly start

play03:21

competing with you on the same exact

play03:23

Audits and eventually shave down your

play03:26

Revenue instead what you want is a brand

play03:28

that compounds and compounds and

play03:31

continues to grow with every single bit

play03:33

of work that you do and ultimately makes

play03:35

you Irreplaceable as an auditor because

play03:38

of the personal brand that you've built

play03:40

up now even though I don't like the idea

play03:42

of using contests as a long-term income

play03:46

solution as an auditor I think they are

play03:48

a fantastic way to get your brand

play03:51

kick-started and get some initial

play03:53

findings and overall just improve at the

play03:56

skill of smart contract auditing and so

play03:58

here's how you can leverage contests

play04:01

early on to actually get this

play04:04

compounding started as quickly as

play04:06

possible for your web3 brand first of

play04:09

all as soon as the actual contest report

play04:12

has been compiled and delivered go ahead

play04:15

and create a full report of your own

play04:18

findings that you uncovered in the

play04:20

contest so that you can show off some of

play04:22

the cool things that you uncovered and

play04:25

show that you know what you're talking

play04:26

about when it comes to web3 security and

play04:29

then second of all when you do place in

play04:32

a contest make sure to share it all over

play04:34

the place share it on Twitter make sure

play04:36

you get the appropriate street cred for

play04:39

doing really well in a contest because

play04:41

this can immediately boost the

play04:43

reputation on your personal brand in the

play04:46

space and on that point it's also a good

play04:48

idea to have the same handle on your

play04:51

Discord that's going to be used in the

play04:52

competition as is used in your Twitter

play04:55

handle so that you can easily be

play04:59

recognized across these platforms okay

play05:02

great so before we officially dive in to

play05:06

talk about the sort of on the ground

play05:08

hand-to-hand combat of actually how

play05:11

you're going to be selling Audits and

play05:12

building your brand doing the legwork we

play05:15

need to discuss a key high level quality

play05:18

of the service that you're going to be

play05:20

selling so the most important thing we

play05:22

need to understand is that smart

play05:24

contract audits are a Time specific

play05:27

product teams only need audits at a very

play05:30

specific time right when their contracts

play05:33

have been finished and internally

play05:35

reviewed and they're getting ready for

play05:38

deployment and what we need to do is

play05:40

structure our approach to getting

play05:43

inbound leads and clients around this

play05:45

fundamental fact and so this means

play05:47

adopting an inbound sales process as

play05:51

opposed to an outbound sales process so

play05:53

what do I mean by that when we're

play05:55

talking about an inbound sales process

play05:57

we're talking about clients coming to us

play05:59

exactly when they need our product or

play06:03

service instead of us reaching out to

play06:05

the client regardless of whether they're

play06:08

looking for our product at that specific

play06:11

time or not now obviously as smart

play06:13

contracts are a Time specific product

play06:16

we'll want clients to be coming to us

play06:18

exactly when they need a smart contract

play06:21

audit this means that we already have to

play06:24

be known or connected to them through

play06:28

our web 3 brand now of course building

play06:31

up such a brand or really a web of

play06:34

connections throughout the industry that

play06:36

sends us inbound clients like this is no

play06:39

small task it's much much easier to

play06:42

Simply go and DM a bunch of protocols

play06:45

and ask them if they need an audit but

play06:48

because of the fundamental fact that

play06:51

smart contract audits are a Time

play06:53

specific product an inbound sales

play06:56

process is going to be a lot more

play06:58

effective than an outbound sales process

play07:01

and so the key focus of the process that

play07:04

we're about to discuss is really

play07:07

centered around getting that brand and

play07:09

getting that web of connections kicked

play07:12

off so we can continue to nurture it and

play07:14

grow it to the size where ultimately we

play07:18

have ample inbound leads coming in all

play07:20

right so without further Ado now that

play07:22

we've covered those two things let's go

play07:25

ahead and hop into the exact process for

play07:28

going from zero to one and then beyond

play07:31

with our web3 personal brand so first of

play07:34

all just like we discussed stop reaching

play07:38

out to protocols and just simply asking

play07:41

if they need an audit first of all this

play07:43

is approaching it from the wrong angle

play07:45

as we discussed because not only are

play07:48

audits a Time specific product we want

play07:52

to nurture a connection with the

play07:54

protocol over a long period of time

play07:56

rather than instantly upfront asking to

play07:59

give them an audit so instead what we

play08:01

want to do is we want to

play08:03

connect with the protocols and provide

play08:05

them with free value up front what we

play08:08

want to do is provide them value with

play08:10

the expectation of absolutely nothing in

play08:13

return just in order to start that

play08:15

relationship off and be able to initiate

play08:18

some connections in the space that will

play08:20

eventually grow to be immensely valuable

play08:22

and so just some ways that you can

play08:24

provide some easy value to protocols and

play08:27

initiate that connection is you could

play08:29

release articles that just do a high

play08:32

level technical breakdown of their

play08:34

protocol and sort of give them like a

play08:36

shout out do a thread on Twitter with it

play08:38

and then go ahead and DM them and say

play08:40

look here's the the high level technical

play08:43

breakdown I did for you is there

play08:45

anything you would like me to add or is

play08:47

there are there other contracts you

play08:48

would like me to do this for anything

play08:50

like that you're just leading with value

play08:52

they can feel the value they can feel

play08:54

that you're giving to them instead of

play08:56

immediately asking to take from them by

play08:59

you know asking if you can do a smart

play09:01

contract audit for them another thing

play09:03

you could do is just do a free review of

play09:07

their code and basically just DM them

play09:10

and give them the results of your review

play09:12

and of course if you find anything

play09:14

interesting they might be interested in

play09:17

reaching out to you for future audits

play09:20

that they're going to have done and so

play09:21

this way you're reaching out to

play09:23

protocols and you're sort of doing the

play09:25

legwork of starting to build your web of

play09:27

Connections in the space that will

play09:29

eventually grow and connections will

play09:32

they get more connections until you

play09:36

eventually reach a Tipping Point where

play09:39

you have such a strong Network within

play09:41

the space that you get inbound leads and

play09:43

inbound clients without even doing

play09:45

anything anymore and this really feeds

play09:47

into the next part of the process which

play09:50

is just building out your network and

play09:53

this is not even just networking with

play09:55

potential clients it's networking with

play09:57

everybody in the space you want to hop

play09:59

in the discords and meet fellow Auditors

play10:02

you want to be on Twitter

play10:05

and you know have discussions with

play10:07

fellow engineers and web3 inhabitants

play10:10

and this way like we said we're just

play10:12

exponentially increasing the rate that

play10:15

our sort of web grows in the space and

play10:19

then the next thing you want to do when

play10:20

you're building your network and sort of

play10:22

almost just building an audience is to

play10:25

be releasing all of the things that you

play10:27

learn as you go so if you learn

play10:29

something interesting about solidity or

play10:31

maybe an interesting novel exploit go

play10:34

ahead and write a thread on it and share

play10:36

it on Twitter first of all you're just

play10:37

doing a great service to the community

play10:39

by sharing your knowledge but you're

play10:42

also going to receive a lot more

play10:43

connections because of that because

play10:45

people can feel the value and they know

play10:47

that it's going to be worthwhile

play10:49

connecting with you next when you're

play10:51

building out your network go ahead and

play10:53

see if you can't join others as they do

play10:56

audits in contests or perhaps even team

play10:59

audits because these are the strong

play11:01

Connections in the space that are going

play11:03

to end up paying you dividend ends as

play11:06

the years go on if you get really good

play11:08

at working with a particular auditor

play11:10

then the two of you can team up and

play11:13

provide a much higher quality audit than

play11:15

if the two of you just worked separately

play11:18

right and similarly the people that you

play11:20

work with might end up inviting you to

play11:23

work on other private audits with them

play11:25

okay and then the last thing that you

play11:27

can really do to start building your

play11:29

network is of course going to be to go

play11:31

to Industry events right this is the

play11:33

easiest way to properly build as many

play11:36

strong connections as possible in even

play11:39

just a span of a weekend so if you have

play11:42

the ability and you're looking to really

play11:44

kick-start the growth of your network

play11:46

and the industry of course

play11:48

make time on your calendar to go to

play11:51

these industry events and then

play11:53

throughout this process as you're doing

play11:55

work in the space and you're reaching

play11:57

out to new protocols and you're growing

play11:59

your network make sure you're building

play12:01

your brand and your portfolio in unison

play12:04

so what you're going to want to do is as

play12:06

you're creating all of these new reports

play12:09

and as you're doing potentially contests

play12:11

and uncovering findings you want to

play12:13

accumulate all of this and put it on

play12:16

your GitHub and make it publicly

play12:18

available for everybody to see so that

play12:20

you can show off all the great work that

play12:21

you're doing and gain credibility and

play12:24

once you have a really high level of

play12:26

credibility it's going to be that much

play12:28

easier you're going to have that much

play12:29

more leverage when you go into a

play12:32

discussion with a client about doing a

play12:35

smart contract audit for them all right

play12:36

so that's a high level process for

play12:40

kickstarting the compounding of your

play12:43

brand but I want to discuss essentially

play12:46

what I would do if I was star starting

play12:49

from absolutely zero to sort of kick

play12:52

start my brand and then begin the

play12:54

compounding as fast as possible so we'll

play12:56

go through an exact framework of

play12:59

literally the steps that I would take

play13:01

each step and all of the actions that I

play13:04

would take to actually go from zero to

play13:07

one and then beyond so first things

play13:10

first literally the first thing I would

play13:12

do is set up my Twitter profile with

play13:15

these three things first of course I

play13:18

would have a name and a description that

play13:22

makes it really obvious that I am a web

play13:25

3 smart contract security perhaps even

play13:28

D5 or nft or whatever your specialty is

play13:32

auditor and then I would have a specific

play13:35

call to action in my bio to DM if you're

play13:39

looking for any sort of private audit or

play13:42

code review or anything like that it's

play13:43

important to have a specific call to

play13:46

action for people to DM you because this

play13:48

is how people are going to know that

play13:50

you're actually accepting work and

play13:52

looking for inbound leads and of course

play13:54

make sure that you're able to actually

play13:56

receive DMS on Twitter sometimes Twitter

play13:59

will will get you like that and

play14:01

you will have not been accepting any DMS

play14:04

so make sure DMS are turned on and then

play14:07

finally I would have a pinned tweet to

play14:10

my profile that shows I have credibility

play14:13

in the space this could be anything like

play14:16

a valuable thread that breaks down a

play14:18

very specific feature in solidity or a

play14:22

particular exploit or perhaps even a

play14:24

previous customer review of my audit if

play14:28

I have one or maybe if it's even a

play14:30

thread that just showcases all of the

play14:33

work that I've done all of the contests

play14:35

I've competed in all of the reports that

play14:37

I have in my portfolio Okay so after I

play14:39

get those first three things set up on

play14:42

my Twitter profile here's what I'm going

play14:44

to do I would do five threads a day

play14:47

breaking down the technical details of

play14:50

different protocols that I found on

play14:52

crypto Twitter I would just go and I

play14:54

would look up hashtag Phantom hashtag

play14:56

avax or different sort of like defy

play14:59

hashtags to find what are the newer

play15:02

protocols that are coming out who are

play15:05

they maybe they haven't launched yet and

play15:07

they're looking for an audit or they're

play15:09

going to be launching some upgrades or

play15:10

something like that where they they

play15:13

might need an audit and in the future

play15:15

and I want to essentially just start a

play15:18

connection with them and get things

play15:20

started off right so for each of these

play15:22

threads that I make on the technical

play15:24

details of their protocol I'm going to

play15:26

post it on Twitter and then go ahead and

play15:29

share it with the protocol and basically

play15:31

just let them know that you gave them a

play15:34

feature ask them you know is there

play15:36

anything that you'd like me to add do

play15:37

you have any other contracts that you

play15:39

would like me to add maybe I could do

play15:40

this for another system of yours and you

play15:43

know just like we said start out of the

play15:46

gate by providing value then if they

play15:48

respond positively and you know they're

play15:51

very thankful then you

play15:53

can go ahead and ask them you know well

play15:57

what are you working on right now what

play15:58

is what where your Project's at and this

play16:00

basically does two things for you first

play16:02

of all when you are actually releasing

play16:04

these five threads a day you're going to

play16:07

get a huge audience of people who are

play16:10

actually interested in the technical

play16:12

details of these protocols which is

play16:15

going to immediately kick-start your

play16:18

audience and ultimately grow to be an

play16:21

extremely valuable asset and then

play16:23

secondly obviously you're going to have

play16:26

these connections with these protocols

play16:28

kicked off and you're going to have lead

play16:30

with value and so automatically that

play16:33

imbues a certain level of trust and

play16:35

appreciation and indebtedness to you and

play16:40

so later when they are looking for an

play16:42

audit they'll go and you know either

play16:45

they'll remember you or you'll pop up on

play16:47

their timeline they'll go to your

play16:49

profile and they'll see that you are a

play16:51

smart contract auditor for or higher and

play16:54

a lot of times the projects that you end

play16:58

up featuring and dming will not be

play17:00

looking for an audit at that very moment

play17:03

and that's why the important part here

play17:04

is really just to initiate that

play17:07

connection and I want you to notice here

play17:09

how we're approaching it from The Stance

play17:11

of how we can help them out by giving

play17:15

them an audit especially in this

play17:17

beginning stage you have to sort of

play17:19

adopt the mindset that it isn't about

play17:21

making money but in fact it's about just

play17:24

purely helping people out helping teams

play17:26

out with the valuable skill that you've

play17:30

basically unlocked and trained up in

play17:33

yourself and paradoxically this will

play17:36

actually lead to an outsized return over

play17:39

the long run now this whole process of

play17:41

making threads and dming protocols is

play17:44

not going to have a huge impact on day

play17:47

one or even week one this is something

play17:50

that's going to take days and days and

play17:52

days of of consistent action on this

play17:56

single repeated task before you build up

play17:59

some semblance of an initial Network

play18:02

that you can leverage to get your first

play18:05

client and so after a few days of doing

play18:07

this you're not going to notice too much

play18:09

don't expect anything after the first

play18:12

few days but after one to two months

play18:14

you're going to be astonished at the

play18:17

opportunities that begin to open up to

play18:20

you now so you keep doing this and you

play18:22

keep sticking to it and doing your five

play18:24

threads a day five DMS a day until you

play18:27

get that one team that is actually

play18:30

looking for an audit and so when we do

play18:32

finally get that opportunity we want to

play18:34

capitalize on it and we need to have a

play18:38

great offer for them you need to make

play18:39

them an offer that they would feel

play18:42

almost stupid saying no to and so here's

play18:45

exactly what we're going to do

play18:47

to give them an absolutely risk-free

play18:49

offer that they cannot say no to this

play18:52

offer it is pay per vulnerability what

play18:55

you're going to do is ask for just a

play18:58

small down payment and only more if you

play19:01

actually uncover vulnerabilities in

play19:03

their smart contract system my first

play19:05

down payment was literally just fifty

play19:09

dollars for an nft contract just fifty

play19:12

dollars it's literally nothing for a

play19:14

smart contract audit but this is not to

play19:16

say that you should simply be cheap you

play19:19

could still quote five thousand dollars

play19:21

per critical bug and if the contract is

play19:23

going to hold millions of dollars of

play19:25

assets then that five thousand dollars

play19:28

for that particular critical bug is a

play19:31

no-brainer any protocol would be

play19:33

overjoyed to be able to spend only five

play19:36

thousand dollars to get that uncovered

play19:38

and fixed Point here is to remove the

play19:41

risk for the client if you charged ten

play19:44

thousand dollars up front they're going

play19:46

to have all sorts of outs running

play19:47

through their head about if you can

play19:50

actually give them an audit that's going

play19:52

to be worth that amount of money with

play19:55

the vulnerabilities that you're going to

play19:57

uncover however if you just ask for

play19:59

fifty dollars down and five thousand

play20:02

dollars per critical and x amount for a

play20:05

high and mediums Etc then it's going to

play20:08

be a no-brainer decision to them from

play20:10

their point of view the worst case

play20:12

scenario is that they give you just

play20:14

fifty dollars to do the audit and you

play20:16

uncover nothing and the best case

play20:19

scenario is they give you fifty dollars

play20:22

to do the audit and you inform them of

play20:24

multiple critical vulnerabilities that

play20:27

they had that would have absolutely

play20:29

wrecked them upon deployment but you

play20:32

saved them and they would be absolutely

play20:35

gracious to pay you thousands and

play20:38

thousands of dollars for that report and

play20:40

so the point is you'll deliver the same

play20:43

report either way but by back loading

play20:45

your price you create a risk-free offer

play20:48

that the client is much more likely to

play20:51

say yes to so you're going to start off

play20:53

by charging a much smaller down payment

play20:56

to get your portfolio and your web3

play20:59

brand kicked off and then once you have

play21:01

a more robust portfolio and you have a

play21:05

stronger web of connections throughout

play21:07

the industry bringing you in on leads

play21:09

then it's time to increase down payment

play21:13

that you're charging and actually start

play21:15

to be a little bit pickier about the

play21:18

protocols that you actually take on to

play21:20

audit over time the projects that you

play21:23

audit and the projects that you release

play21:25

reports for are going to become a part

play21:28

of your brand whether you like it or not

play21:30

so you need to choose the right clients

play21:32

that are going to protect your

play21:34

reputation ideally you want to only take

play21:37

on the clients that are really serious

play21:40

about security and are willing to pay

play21:43

you what you're worth give you the time

play21:45

that's necessary for the audit and take

play21:47

your report really seriously with all of

play21:49

the findings that you uncover and then

play21:51

of course the quality of the clients

play21:53

that you get will be directly correlated

play21:55

with the quality of reports that you

play21:58

give and so it's a virtuous cycle you

play22:00

get better clients who are willing to

play22:03

pay you more money and give you more

play22:05

time to do the audit which enables you

play22:08

to create better reports and collaborate

play22:11

with others who are even more skilled

play22:13

which in turn of course gives you more

play22:17

credibility in the space which gets you

play22:18

better clients who will pay you more and

play22:21

give you more time and of course you can

play22:23

see this all just spirals up right but

play22:26

it goes the other way as well if you

play22:29

don't protect your web 3 personal brand

play22:31

and you just take on any clients then

play22:34

the cycle spins the other way and so we

play22:37

need to be very protective of the

play22:39

clients that you actually choose to

play22:41

service and dedicate your precious time

play22:44

to and so from this point on it's all

play22:46

about creating those really powerful

play22:48

relationships with the people that you

play22:51

work with whether that be the people

play22:53

that you actually collaborate with and

play22:55

work with on audits or whether that's

play22:58

your actual clients and so now all you

play23:01

have to do is continue to cultivate

play23:03

these relationships and continue to put

play23:06

in The Sweat Equity and before long if

play23:09

you haven't reached already you will

play23:11

easily be in the six figures plus

play23:14

territory all right so that covers

play23:16

everything that you need to know about

play23:18

literally going from zero to one and

play23:21

then even Beyond as a smart contract

play23:23

auditor and going from you know complete

play23:26

side interest to a full-time gig if you

play23:29

want to find a place where you can start

play23:32

to really build your web 3 connections

play23:35

in the space and connect with other

play23:36

like-minded Auditors as well as sharpen

play23:39

your skills as an auditor go ahead and

play23:40

check out

play23:42

lab.guardianaudits.com and apply to join

play23:44

our growing group of like-minded

play23:47

Auditors in the solidity lab you can

play23:50

team up with others and participate in

play23:52

team Audits and get paid for the

play23:54

findings that you uncover this way you

play23:56

get the opportunity to work with others

play23:59

in a real audit setting to not only

play24:02

sharpen your skills but also potentially

play24:04

make those lasting connections that will

play24:07

pay dividends and dividends throughout

play24:09

the space and if you're still not

play24:11

absolutely confident in your web 3

play24:14

security skills and you want one place

play24:17

to basically go from where you are now

play24:19

to a certified Pro Smart contract

play24:22

auditor I actually collaborated on the

play24:26

perfect program that can take you in an

play24:29

organized step-by-step efficient process

play24:32

I collaborated with Security

play24:34

Professionals from across the field

play24:36

including Johnny time pass off crumb and

play24:40

Trust 90 to bring you dozens of hours of

play24:43

lecture content and exercises on

play24:46

literally every area of web 3 smart

play24:49

contract security that you could imagine

play24:51

if that sounds like something that could

play24:53

help you out on your journey wherever

play24:54

you are right now go ahead and take 50

play24:56

off when you use my link in the

play24:59

description below alright that's all for

play25:01

this time I'll see you in the next one

play25:05

foreign

play25:07

[Music]

Rate This

5.0 / 5 (0 votes)

関連タグ
Smart ContractsAuditing GuideWeb3 SecuritySolidityDAppsBlockchain AuditsPersonal BrandingInbound LeadsProfessional GrowthCryptocurrency
英語で要約が必要ですか?