Trail of Bits published notes on 18 September on reviewing the Miden zkVM. The part worth reading is what happened before the review started.
Security firms — the same firm included — have published a number of posts describing how they pointed an agent harness at a codebase. This post is about a stage earlier than that: "before code review even starts, agents now allow us to build custom tooling and formal models that improve the quality and depth of our reviews."
Miden has its own assembly language, MASM, and very little tooling around it. The firm had six months of lead time, because the implementation was not yet feature complete. It spent them having its agents build an LSP server, a decompiler, a static analysis engine, and a Lean model of the VM executor. None of that was the review.
Applied during the review that followed, those tools produced concrete results. The static analysis identified over 400 unique locations where type validation could be improved, all of them reachable from the library's public API, as well as one high-severity finding: a remainder supplied by the prover was never validated before being passed to a 32-bit subtraction — "a malicious prover could exploit this to forge Falcon signatures and drain any Miden account controlled by a Falcon key pair." The Lean modeling effort produced 95 machine-checked correctness proofs covering all the binary arithmetic in the core library, and surfaced two more bugs the existing unit tests had not caught.
The detail worth sitting with is smaller than any of those. The decompiler was the single largest piece of the work, over 100 agent-generated commits across months. The firm's own account of where the benefit landed: "The main benefit of this work turned out to be the decompiler's internal analysis frameworks and intermediate representation, which we could reuse for static analysis, rather than the full decompilation pipeline."
The post is direct about why work like this did not happen before. It is "highly exploratory in nature, and the end results and potential payoff may be difficult to predict," which makes it "hard to sell clients on them in advance."
What has changed, on the post's own account, is the cost of a miss: "Today, a failed side project only costs tokens." The payoff is no easier to predict than it was. What a wrong guess costs is smaller.
One thing about this particular case is worth noting on its own. The main benefit ended up somewhere the single largest piece of the work had not been aimed at. That is a payoff shape easier to recognize once the work is finished than to argue for before it starts.
https://t.co/972ijKSY19
#DeepSafe #Web3Security
Weekend puzzle.
A node operator publishes its source code. The code has been audited, and the audit report is public too.
Does any of that tell you which build is actually running on the node?
A. Yes. The code is public.
B. Yes. The code is audited.
C. No—not on its own.
YneraX One Early User Giveaway
The YneraX One Early User Campaign is live, featuring a total reward pool of $150,000 USDT and 4,000,000 $YNX tokens.
Reward allocation
$50,000 USDT for the top 2,000 leaderboard participants.
$100,000 USDT distributed to 20,000 randomly selected winners.
4,000,000 $YNX allocated across leaderboard rewards, community rewards, and special bonuses.
How to participate
Sign in with X, complete tasks, and invite friends to earn more entries. Your entries determine your leaderboard rank.
Participate: https://t.co/6BuLomn8oZ
Full details and rules: https://t.co/bGWmzFww3M
Campaign closes: October 15, 2026, at 14:44 UTC.
On 24 August, a proposal on Neutron titled "TestProp: Preparation for AIATO: AI Agent Takeover" asked governance to make one address the admin of ten contracts, among them six Astroport pools and two Drop contracts. When voting closed on 31 August, it was rejected. Roughly 10.4 million NTRN voted no; about 0.32 million voted yes.
On 19 September, proposal 9, "AIATO: AI Agent Takeover. Phase 1: Agent Admin Registration", asked for the same ten admin changes to the same address, plus an eleventh. It was filed as an expedited proposal and passed when voting closed on 22 September at 02:24 UTC, with about 37.3 million NTRN voting yes.
Cosmos Hub validators halted the Hub to limit losses of ATOM moved there from Neutron, and say the funds secured at restart are held in a community validator multisig.
None of this was hidden. From 24 August, the title, the ten contracts and the address that would become admin were public on-chain. From 31 August, so was the rejection.
The August vote said no to that proposal. It did not stop the same request from being filed again nineteen days later and passing. It ended a vote. It did not end the attempt.
Proposal 5: https://t.co/c1atRWPk16
Proposal 9: https://t.co/7LorAITXVB
Cosmos Hub halt: https://t.co/11iqGhmtsp
Cosmos Hub restart: https://t.co/kNhbpbafrG
#DeepSafe #Web3Security
A draft posted to bitcoin-dev this month reworks one small piece of taproot backup. It sits in an individual fork, hasn't been assigned a BIP number, and is still in its earliest form.
The draft addresses backup for unspendable internal keys. One existing approach it cites as motivation is to choose a random r and retain it, so the internal key can be recomputed later.
The draft's mechanism derives a chain code from a tagged hash of a normalized wallet policy. That chain code, the fixed NUMS point H, and a selected derivation path together determine the internal key — in a step the draft describes as being done "without additional secret material."
Its Security considerations section states two things: "The policy and selected derivation are enough to reproduce the internal key," and, in the same section, "Seed backups alone do not reconstruct the policy."
Read narrowly, what the draft changes is which inputs are needed to reconstruct that internal key.
Draft: https://t.co/IiCRQuQPcv
Weekend puzzle.
A contract checks a condition, then acts on it. Both in the same transaction, atomically.
How old can the thing it checked be?
A. Zero. It's atomic.
B. One block at most.
C. Depends on where the fact came from.
🦎 XIIID Is Now on CoinGecko! 🎉
We’re celebrating our CoinGecko listing with a special XIIID Hunt Airdrop! 🚀
🔎 Find XIIID. Complete the mission. Earn XIIID!
🎁 Rewards
• FCFS 1,000 eligible participants × 300 XIIID
• 50 Lucky Winners × 1,000 XIIID
• Bonus Mission: Complete the Q4 Roadmap post engagement (Like + Comment) → Extra 100 XIIID
📋 How to Join
✅ Search XIIID on CoinGecko
https://t.co/b2ZpbYq4tD
✅ Follow @xiiid_official on X
✅ Like, Repost & Comment on this post
✅ Complete the “XIIID CoinGecko Listing Celebration” Class on XCLASS
✅ Bonus: Like & Comment on XIIID Q4 Roadmap post
👉 https://t.co/OcuOJZl0Fb
✅ Submit the participation form
👉 https://t.co/aEZqX18BQX
⚡ FCFS is determined by the completion time of the “XIIID CoinGecko Listing Celebration” Class.
⚠️ Bots, duplicate accounts, and suspicious activity are excluded.
📅 Event Period
September 2 – September 10, 2026 (UTC)
📢 Results Announcement
September 11, 2026 (UTC)
🦎 Find XIIID. Learn. Earn. Celebrate! 🚀
#XIIID #CoinGecko #XCLASS #Airdrop #Web3 #Solana