A signature can be 100% valid and still let an attacker steal funds.
Here's a bug pattern we keep finding in cross-chain code — and how we prove it's real before it ever hits a report.
Static analysis usually stops there. But not Azimuth.
Azimuth’s Validation Engine builds the exploit path and run it against forked state:
→ capture a legitimately signed message
→ replay it against a different instance that trusts the same signers
→ confirm it's accepted and something of value actually moves.
8/ That’s really what we want Context Bot to do:
Find interesting things being built, understand them quickly, and surface projects worth paying attention to.
If you like discovering new protocols early, follow @ContextBot — we’ll keep sharing what it finds.
And if you’re on one of the teams we surface and want to see what Azimuth makes of your code, reach out. We’d be happy to run a scan.
1/ We built @AzimuthContext to help us keep up with what’s being built across crypto.
It researches protocols, pulls together their architecture, repos, integrations and security context, and surfaces projects worth a closer look.
It’s also become a pretty useful source of early protocol alpha.
Here are 6 it picked up recently that caught our attention 🧵
7/ And finally @lptokenfun.
This is another reason we built Context Bot in the first place.
Interesting new protocols can appear long before they make it onto the usual dashboards or research feeds.
Automating that discovery gives us a much wider view of what builders are experimenting with across the ecosystem.
https://t.co/wZjnbbmGmV
Public challenge: prove us wrong.
We know Azimuth is the best AI-powered digital assets security system out there.
But be our guest and try prove us wrong.
• Run it on your own repo.
• Run it on something already audited.
• Run it on code with known historical exploits.
• Run it on the nastiest codebase you can find.
Don’t trust our benchmarks.
Don’t trust our case studies.
Don’t trust our posts.
Test it yourself.
If Azimuth misses something it should have caught, tell us.
If another tool does better, show us.
We’re confident enough in the product to make the challenge public.
Try to stump Azimuth.
Everyone gets free quota to start. If you need more to really put it through its paces, reach out!
https://t.co/ipYvpPSVii
Our new quota ystem isn’t just about how much you can use Azimuth, it’s about where you can use it.
Every user can now generate an Azimuth API key and use their recurring quota through our MCP in Claude Code, Cursor, or any MCP-compatible workflow.
Azimuth is moving beyond the app.
Set up your API in 30 seconds on the TestMachine app.
https://t.co/ipYvpPSVii
We shipped a lot last week.
Four updates across TestMachine, all focused on making security easier to use, easier to navigate, and more rewarding.
1/ Points + the Azimuth Leaderboard are live
Season 1 is underway.
Earn points for validated findings and for using Azimuth, with rewards for the top users on the leaderboard.
The idea is simple: reward signal, not noise.
2/ Token Explorer got a major upgrade
See what’s hot, then see what’s risky.
Token Explorer now surfaces trending tokens across Ethereum, Base, and Robinhood alongside TestMachine’s security findings.
11.8M+ tokens analyzed. 2.7M+ behaviors surfaced.
3/ Azimuth got an AI Assistant
You can now operate Azimuth through conversation.
Tell it to scan a repo and it can scope the codebase, calculate the cost, and prepare the scan.
Once it’s done, ask what matters most, why a finding is severe, what to investigate first, or what previous audits found.
Your security workflow, increasingly accessible through one conversation.
4/ We added Azimuth Signal
Azimuth now ranks findings based on how confident it is that they’re real, using signals like reachability, groundedness, preconditions, and impact.
Less time sorting noise. More time on what matters.
A pretty productive week.
More coming.
See everything live in the TestMachine app → https://t.co/ipYvpPSVii