our team is discussing @Mosaic_Build today, public goods smart contract infra for the agentic future. join in and check out what we've been building over the past two years
sad day today c4 really made so many careers, so many brands that are running the space today were built on what c4 created. i remember submitting my first few bugs on c4 only to get them invalidated, it took submitting to three different contests before i found my first medium that was duped to hell, but that was the inspiring moment that i realized wait, maybe i can DO this
c4 was that but for so many people that came before me and after me, forever grateful to them and what they created in our industry @sockdrawermoney is a OG for real and the whole @code4rena team deserves kudos
now on to the hard stuff, one of the main drivers of this is obviously the business model for contests is no longer profitable, this is dangerous though as it doesn't give junior auditors a place to sharpen their skills and learn, it also consolidates power around bug bounties to a few different programs that now run that space
this leaves us at the mercy of these programs and whether they decide to lean towards benefiting SRs (rarely) or their customers/projects. i know c4 wasn't the place the go fro bbp's but seeing it shutdown just brings more fear that with the advancements in AI we're only going to see more greyhats hacking projects and then asking for 10%
the other side to this is instead of saying AI spam killed contest platforms, we should be asking how can we create contest platforms for the agentic future, one that is open and accepting to AI generated submissions, one that is AI native itself (triaging, validation, judging) is mostly handled by AI and welcomes the future that we are stepping into
I think as time goes by its clear we're creating (unfortunately) an industry where blackhats thrive and whitehats get called "beggers" when they submit a valid issue. the LZ fiasco with dvns is the perfect example of this. this isn't to say that AI submissions aren't a problem, 1500 submissions on a two week contest is now the norm, and can cause massive problems for projects looking to deploy quickly. but the current leaders in our contest/BBP space seem to prefer to blame AI as the problem instead of use AI to innovate a creative solution.
curious to see how we as an industry evolve, there's still a lot of work to do and only collectively will we be able to secure web3.
uniswap cca deploy configs can easily lead to crits.
not from exotic bugs but from defaults, assumptions, and one bad parameter in prod.
https://t.co/3B73kOVQkE
one of the cooler things we built last year was YieldCore USD
that now powers multiple stablecoin protocols including a yield-bearing one at $15M TVL.
building, securing, improving.
What 33Labs ships. Connected.
Security: 31 engagements, manual reviews only. Caught 126 critical paths. Whitelisted Uniswap provider.
Dev: Built $15M stablecoins, $20M protocols. Your code gets an audit review on every PR: separate team, no self-grading.
AI Tooling: On-demand scans for hook vulns (15+ vectors). Open source. Cuts weeks to hours.
yea for sure that’s how it took, it’s still validation that we found the bug, though i am running it against other open source scanners as we need a way to verify that if we got a dup did we get it cause the model found it, or was or harness unique enough to find a bug a simple scan won’t find, that’s been really helpful in pushing things forward that actually work
@abarbatei@immunefi that’s fire though, we’ve been at it for about two months (similar set up) and have mostly found dupes. so nice work bro you’re cooking
we cut our OPEX by thousands this yea with AI agents we built in-house at 33Labs
we've been managing an overwhelming amount of our daily ops tasks with an in-house ops agent we call Kif
>it has its own email, calendar
>can manage our schedule,
>scope audits/dev work,
>create statements of work in minutes
>keep track of our financials, expenses, do a week analysis
>helps draft messages, emails and helps keep track of leads
>it even has access to our linear board and sends reminders to the team about their daily task
the biggest win its self learning, using an obsidian vault and karpathy's wiki format it gets better each week we use it
i feel like this is just the beginning as we make some serious moves to become an AI native crypto company there's so many more unlocks we are exploring, including a lead dev agent, security agents running 24/7 and marketing/sales help
this is the most exciting time i've had building in web3 and i can't see it slowing down. optimistic about the future