Standard monitoring isn't enough anymore. So we built on top of it.
Today we're launching Glider Monitor, built for everyone in Web3 deploying Contracts or Capital.
At its core is Glider - which recognizes any on-chain pattern and tracks it across your contracts continuously, protecting you on multiple fronts.
• Exposure replay: when an exploit hits another protocol, or a novel attack vector surfaces in public research, we replay it against your contracts and tell you if you share the vulnerability - before it reaches you.
• Dependency risk & invariants: your contracts trust oracles, vaults, and third-party code. Glider Monitor maps your full dependency graph automatically and monitors invariants for known risk classes - stale oracles, vault health, stablecoin depegs - plus custom invariants built for your specific risk profile.
• Real-time attack monitoring: continuous observation of your contracts, alerting you the moment you're targeted.
Threats in web3 are continuous.
Now your security matches the pace.
Start with our free tier, <10 contracts, 60 seconds onboarding.
1/
we found a bug in the Aptos Move VM that put up to $70B at systemic risk. type confusion at the execution layer. a ~90% success rate across hundreds of simulated runs on a 30+ validator cluster. cost to build the attack infrastructure: $3,000.
Conducted by @kemmio , to our knowledge this is the first public research that showcases how to land a sophisticated multi-block attack in real-world environments. It includes mempool feng shui, block production specifics and about a dozen of other primitives and tricks chained to get to near-perfect exploitation results.
Nonetheless, Aptos called it "extremely low exploitability."
[https://t.co/vjeLaENYn0]
@andykoo recently broke down six security issues that recur across Hexens wallet audits. Not bugs. Architectural defaults that survive design review because nobody pushes back.
Today we're expanding Hexens Builder Support into a full ecosystem program.
Partners across the essential early-stage stack all chipping in to help teams ship safely.
Meet our initial launch partners:
@Spredoio, @Blocksource_co , @ChainstackHQ, @Quicknode, @infura_io, @layer3, @Wonderland, @ISinfra, @Labrys_io, @LunarStrategy, @xyz_remedy
Always room for more partners supporting early-stage builders.
Partners apply here: https://t.co/kaC5A72Ix5
Builders apply here: https://t.co/hy5Rb1uM0P
Earlier, Apple announced another significant patch release for macOS (Tahoe 26.4), patching almost 80 CVEs spanning across user-space to kernel modules.
Together with dozens of other bright minds, we again had our own contribution, with the credit going to our researcher Gor Aleksanyan (@GorAleksanyann) who co-discovered CVE-2026-28868 and CVE-2026-20695 - kernel address/info leak bugs.
Update your devices.
Full advisory:
https://t.co/rRouknmBt9
Apple just released iOS 26.5 and iPadOS 26.5, patching a significant number of security vulnerabilities across core system components - from memory corruption in media handling to sandbox escapes and privacy bypasses.
Among the credited researchers: our own Andy Koo (@andykoo), who discovered CVE-2026-28974 - a double free vulnerability in Spotlight, found using an AI-augmented fuzzing setup.
Update your devices.
Full advisory: https://t.co/sDdxaB6pQY
The ETHSecurity badges distribution from @thedaofund is finished now.
We are proud to share that members of Hexens team are part of this important initiative:
@andykoo — Lead Security Researcher
@p0wn4j — Lead Cryptography Security Researcher
@kemmio — CTO & Co-Founder
TheDAO's mission is to make Ethereum safer, and ETHSecurity is how they vet the researchers capable of contributing to that work.
Over 75% of recent major exploits had nothing to do with smart contract bugs.
Phished developers. Compromised signer machines. Malicious dependencies. Breached infrastructure.
Code audits weren't built to catch any of that. APT simulation is.
A full adversarial engagement against your team, keys, infrastructure, and operational security.
Modeled on the tactics behind the headlines, not a generic pentest checklist.
If your protocol holds real value and you've only done code audits, that's your blind spot.
Simulate the attack before it’s too late → https://t.co/LLRDk2QjBQ
Builders: you now have access to Hexens audits through the @areta_io $1M Ethereum Audit Subsidy Program.
Backed by @ethereumfndn, @chainlinklabs & @NethermindSec.
We're excited to be a part of this initiative.
Apply here: https://t.co/x8tQ1SBhqM
The next 60 ETHSecurity Badge holders have been selected using a new rubric updated by the applicants themselves!
Thank you to the people who chatted with the bot, your refinement of the rubric is the first DAO experiment we have tested.
And thank you to @bonfiresai for making amazing DAO tooling!
Cross-chain bridges remain critical infrastructure, proof verification is the core of their security model.
New disclosure on our research page: a vulnerability in the Polygon Plasma bridge that allowed transaction proofs to be forged.
At the time of discovery, $800M in POL was at risk, exploitable in a single transaction with no prerequisites.
The research covers how the proof verification breaks, how the exploit was built, and what it means for bridge security.
Full technical deep-dive: https://t.co/Zigi7VwNes
Audits Completed: @roycoprotocol
Two consecutive security reviews of Royco - a perpetual risk-tranching protocol dividing yield opportunities into senior and junior tranches.
Our assessments covered the core protocol contracts, tranche and kernel mechanics, liquidation bonus mechanisms, and RWA integration alignment.
We're glad to support @roycoprotocol 's ecosystem and look forward to working together again in the future.
Full reports below:
Audit Completed: @Zharta
Security review of Zharta's structured credit order book protocol for ERC20 tokens.
Our assessment focused on updated lending contract logic, asset handling, and overall fund safety.
We're glad to support Zharta's ecosystem and look forward to working together again in the future.
Full report below: