AI is changing how security research works.
building better tools, and uncovering bugs that traditional testing might miss.
For Web3 security, that shift matters.
#DeepSafe@DeepSafe_AI
AI isn't just making security audits faster. It's making experimentation cheaper and helping uncover bugs we might otherwise miss.
More exploration. Better tools. Stronger Web3 security.
#DeepSafe@DeepSafe_AI
In Web3 security, better audits don't always start with better auditors or better AI models.
Sometimes, they start with better tools built before the audit even begins.
That's an underrated shift.
Trail of Bits published notes on 18 September on reviewing the Miden zkVM. The part worth reading is what happened before the review started.
Security firms โ the same firm included โ have published a number of posts describing how they pointed an agent harness at a codebase. This post is about a stage earlier than that: "before code review even starts, agents now allow us to build custom tooling and formal models that improve the quality and depth of our reviews."
Miden has its own assembly language, MASM, and very little tooling around it. The firm had six months of lead time, because the implementation was not yet feature complete. It spent them having its agents build an LSP server, a decompiler, a static analysis engine, and a Lean model of the VM executor. None of that was the review.
Applied during the review that followed, those tools produced concrete results. The static analysis identified over 400 unique locations where type validation could be improved, all of them reachable from the library's public API, as well as one high-severity finding: a remainder supplied by the prover was never validated before being passed to a 32-bit subtraction โ "a malicious prover could exploit this to forge Falcon signatures and drain any Miden account controlled by a Falcon key pair." The Lean modeling effort produced 95 machine-checked correctness proofs covering all the binary arithmetic in the core library, and surfaced two more bugs the existing unit tests had not caught.
The detail worth sitting with is smaller than any of those. The decompiler was the single largest piece of the work, over 100 agent-generated commits across months. The firm's own account of where the benefit landed: "The main benefit of this work turned out to be the decompiler's internal analysis frameworks and intermediate representation, which we could reuse for static analysis, rather than the full decompilation pipeline."
The post is direct about why work like this did not happen before. It is "highly exploratory in nature, and the end results and potential payoff may be difficult to predict," which makes it "hard to sell clients on them in advance."
What has changed, on the post's own account, is the cost of a miss: "Today, a failed side project only costs tokens." The payoff is no easier to predict than it was. What a wrong guess costs is smaller.
One thing about this particular case is worth noting on its own. The main benefit ended up somewhere the single largest piece of the work had not been aimed at. That is a payoff shape easier to recognize once the work is finished than to argue for before it starts.
https://t.co/972ijKSY19
#DeepSafe #Web3Security
Trail of Bits published notes on 18 September on reviewing the Miden zkVM. The part worth reading is what happened before the review started.
Security firms โ the same firm included โ have published a number of posts describing how they pointed an agent harness at a codebase. This post is about a stage earlier than that: "before code review even starts, agents now allow us to build custom tooling and formal models that improve the quality and depth of our reviews."
Miden has its own assembly language, MASM, and very little tooling around it. The firm had six months of lead time, because the implementation was not yet feature complete. It spent them having its agents build an LSP server, a decompiler, a static analysis engine, and a Lean model of the VM executor. None of that was the review.
Applied during the review that followed, those tools produced concrete results. The static analysis identified over 400 unique locations where type validation could be improved, all of them reachable from the library's public API, as well as one high-severity finding: a remainder supplied by the prover was never validated before being passed to a 32-bit subtraction โ "a malicious prover could exploit this to forge Falcon signatures and drain any Miden account controlled by a Falcon key pair." The Lean modeling effort produced 95 machine-checked correctness proofs covering all the binary arithmetic in the core library, and surfaced two more bugs the existing unit tests had not caught.
The detail worth sitting with is smaller than any of those. The decompiler was the single largest piece of the work, over 100 agent-generated commits across months. The firm's own account of where the benefit landed: "The main benefit of this work turned out to be the decompiler's internal analysis frameworks and intermediate representation, which we could reuse for static analysis, rather than the full decompilation pipeline."
The post is direct about why work like this did not happen before. It is "highly exploratory in nature, and the end results and potential payoff may be difficult to predict," which makes it "hard to sell clients on them in advance."
What has changed, on the post's own account, is the cost of a miss: "Today, a failed side project only costs tokens." The payoff is no easier to predict than it was. What a wrong guess costs is smaller.
One thing about this particular case is worth noting on its own. The main benefit ended up somewhere the single largest piece of the work had not been aimed at. That is a payoff shape easier to recognize once the work is finished than to argue for before it starts.
https://t.co/972ijKSY19
#DeepSafe #Web3Security
@DeepSafe_AI The combination of custom static analysis and machine-checked proofs is what stands out to me. AI-generated tooling becomes much more interesting when it helps uncover bugs that existing tests miss.
Airdrop common dari kita untuk kita!
Anda mendapatkan 7 poin untuk memberikan poin dan sebaliknya.
Kunjungi https://t.co/zPnjrrY6s3
Masuk dengan X
Hubungkan GitHub Anda
untuk mendapatkan skor lebih tinggi vouch Beri tag
Hey @commonsmade, vouch @jonesstm1
The Saudis have struck something. ๐ข๏ธ
Early wallets will receive special access.
Something is coming to Robinhood. ๐ข
https://t.co/0Au1GMR6am
Like. Repost. Drop your wallet. ๐
https://t.co/zLLs46Vmni
saya sedang mengerjakan meta tipfi di @motiontip
saya butuh dukungan dan arahan agar bisa saling tip di kolom komentar.
keep build @tipmotion thanks you so much solana:FCaPNUJbWfECeeCeA3tvqkGUQ1BFPuon71KphJM5pump
you are the best socialFi