Hot take: AI agents are going to cause a payments fraud wave bigger than early e-commerce and nobody is ready.
Agents are passing around CVCs in plaintext. The security infra we built for humans (CAPTCHAs, MFA) is useless when the buyer is an LLM.
We just shipped something about it → https://t.co/U0PelZu7nb
Announcing https://t.co/5iGRosL4dq. The open payment standard for OpenClaw agents.
There's no secure way for OpenClaw agents to pay for things. Until now.
Powered by @crossmint, @Visa Intelligent Commerce, @solana, @circle, and @stytchauth.
🧵👇
Just published: How I tricked an AI agent into leaking data and why fintech security needs a rethink. Deep dive on risks, fixes, and worries. What's your AI security nightmare?
Read here: https://t.co/M6MIp7gcvs
ClawdBot went viral.
Mac mini sales spiked.
Thousands of AI agents are now online with zero authentication.
They're already being exploited.
Here's how to fix yours before it's too late. 🧵
→Rotate every secret you used. Assume compromise
→Add rate limiting. Stops brute force and DoS.
→Logging + alerts. Know when something's wrong, not after.
Let’s look at Solana MEV for September
-> We’ll also look at Jito bundle compositions
-> A DATASET of 1M atomic arbs is available
Did you know that the top atomic arb searcher on Solana doesn’t use a custom program? They route through Jupiter’s program. More on this in a bit.
Let's start with atomic arbitrage
Tips for atomic arbs hover at around 50% of revenue. This is significantly less competitive compared to Ethereum where you see 90-99%+ paid to the proposer.
Notice also that about half (by revenue) of atomic arbs are sent directly to validators and don’t go through Jito. These are virtually all “blind” or speculative arbs where searchers hope to land a profitable transaction that pays for all the failed ones. Most of these transactions fail but when they hit, they can avoid paying tips or significant priority fees.
Here’s the top arb for September (by CET timezone). The searcher kept 80%. You don’t really see that on Ethereum.
Here’s the 2nd most profitable atomic arb in September and it was sent directly to the validator. It was not part of a Jito bundle. If you check this searcher’s history, you’ll see many failed transactions. To determine profitability you would have to account for the sum of fees for those failed transactions.
Some searchers, like the one above, don’t use a custom program. Instead they route their arbs through Jupiter. We were a bit surprised but also impressed.
See below for average tips per (signer, program) and notice how the profitable searchers use both Jito and direct-to-validator. Many searchers also hardcode their tips. If arb on Solana becomes more competitive, we expect to see more custom programs (to allow for runtime input amount adjustments) as well as dynamic tips
🚨 NEW: @RangeSecurity, the blockchain security and intelligence platform, has integrated @solana, delivering real-time security and advanced forensics across the network.
Today is the start of something huge.
We have partnered with @SolanaFndn to bring Range to @solana.
The best teams are already in our beta. Join us now!
Our head of product @LimarisT gave a talk this weekend at @ThePortMiami about security and risk monitoring for Solana protocols.
Big things are coming. Soon.
The interoperability standard for blockchains deserved an even better explorer.
Today, we're launching IBC Explorer 2.0, the ultimate platform for tracking cross-chain transactions, flows, rate limits, and asset volumes in real-time.