i have quit my job and am officially full-time zauth. this will be our most productive week in the past six months.
as AI keeps advancing, we'll see a scary rise in smart contract exploits. nearly a billion dollars was lost to these exploits last year alone.
it used to cost tens of thousands of dollars to build a custom contract. now it's a $100 claude subscription, but auditing hasn't moved. it's still priced and paced for the old world: too expensive, slow, and inaccessible to keep up.
that gap is where the money gets stolen, and it's the gap we're closing.
affordable, high-quality, autonomous smart contract auditing that moves at the speed AI ships code.
smart contract owners will be able to audit their own contracts, and we'll also offer white-hat services.
soon.
Our pentests beat the leading agentic cybersecurity company. Faster, cheaper, and simpler to use.
zauth is expanding into smart contracts, mobile apps, CI/CD, enterprise environments, and more.
The best security in the world, now for everyone.
Hi everyone. I'm Will, most of you know me as zpointz. Over the past five months I've poured my heart into zauth. Everything between the videos you've seen and the finished product, that was all me. I'm grateful beyond words for the support and opportunity we've received so far.
I am at a true inflection point in my life. I am 23 years old, just graduated college, five months into a six-figure engineering job... and I'm walking away from it. I am ready to make the jump and focus on something I am truly passionate about. Something I believe is going to change how the internet is built.
zauth is a completely different company than it was when it first started. I created the initial product within 10 minutes of seeing a post from Coinbase about the x402 bazaar that tackled the problem of AI agents paying for x402 services that don't work.
When I launched zauth in December, I began by testing every single x402 endpoint in the bazaar, spending thousands out of pocket on AI credits and x402 providers with no guarantee of any reward. That bet paid off in ways I never anticipated. A hackathon win, a community, and the foundation for the thousands of hours of work I’ve put in. None of it would have been possible without @pumpfun.
Following our x402 discovery, I realized it was a symptom of a much larger problem: AI agents care about one thing, accomplishing a task. They don't care how they get there, and they ship code, move money, and make decisions with almost zero accountability for what they do wrong.
After I finished our x402 database that now has 900,000 transactions processed and 2,700+ endpoints tested and graded, I moved onto our second product and created RepoScan, which is now used by 5 (soon to be 6) of the largest trading terminals and bots within the crypto community and boasts 650,000 unique interactions and 27,000 repositories scanned. Seeing something you built that people can rely on, trust, and use on a daily basis… there's no better feeling. That feeling led to more inspiration, and the genesis of Vector, our agentic penetration testing suite.
Black box, grey box, white box -- these represent different types of pentests, with black box being no code access, grey box being some, and white box being the full repo. We began with black box, which requires absolutely zero code access. Just point at a domain and shoot. Our black box model is finding higher levels of vulnerabilities at a fraction of the cost and time than our counterparts from a billion dollar security company, which uses white box testing with full repository access. 83% critical vulnerability detection rate compared to their 42% -- all with no code access. We've written a complete academic paper on this that we'll be making public soon.
And now we're on the verge of releasing a monster with white box testing, using methodologies that aren't being used by leading security firms today, in hopes of making apps bulletproof to the core. Think about it this way: I built the first version of zauth in 10 minutes. People are shipping entire apps that fast now. If security can't move at the same speed, AI will find your exploits before you do. And it won't be on your side.
What started as just me and 10 minutes is now three co-founders, 900,000 transactions processed, 27,000 repo scans, and a security product outperforming a billion dollar competitor. We're just getting started.
I hope you'll follow along and join me. @zauthinc
Big RepoScan update today.
Scans are 3x faster. Our new AI-powered file selection focuses on the code that matters, improving accuracy and time.
Failed and stuck scans are gone. We resolved the browser crashes, added real-time error handling, and scans now recover automatically.
Our UI got a glow-up too. Cleaner error messages, consistent styling, and flexible URL input (just paste owner/repo and go).
https://t.co/91SyEP2MuF
Scan your github repository today!
Building for Colosseum? We want to support you.
Proud to be the only application security provider on @colosseum's official resources.
Businesses charge thousands for a pentest we've made available for under $20.
Security should never be optional.
https://t.co/2hN9Oz5LTv