There is a structural problem in how we fund security in crypto.
Today, most systems wait until something breaks. Then we scramble to patch it, pay out bounties, or argue about responsibility after losses have already occurred.
I think @satyanadella is speaking very clearly to the practical reality that the frontier models will not be able to own the full stack of the AI ecosystem for practical reasons. Differential context will always be a reality. This feels like validation of our direction.
Our bet is simple: that we can build our own ecosystem around what is really at its core a very basic data sharing interaction, backed by stake and forced into a pathway of conviction, to align long term outcomes in security.
NEW: malware developers added nuclear & biological weapons text to to their spyware.
Goal? To trigger LLM safety refusals... so that their spyware wouldn't be analyzed by an AI security scanner.
Cleanest practical example I can think of for why over-indexing on first order safety alignment is risky.
When closed (and open) models ship with aggressive refusals, they will be sprinkled with second-order blindspots that attackers will discover...and exploit.
We are only in the earliest days of attackers leveraging these features, and it wouldn't surprise me if users systems that need to handle complex cybersecurity issues demand that models be less safety-blunted.
In the weeds: @SocketSecurity's post also shows why intention matters in how you design a malware analysis pipeline to avoid prompt manipulation.
H/T to colleagues that shared this with me https://t.co/f3Aj9TYxU4
The scary part about Anthorpic's Fable nerf is not that it refuses to answer biology or cryptography. It's that it foreshadows what's coming. A world where a couple companies decide what you can and cannot do. They're building a new ruling class and you're not in it...
i don’t like the attempt from some insiders to paint the zcash bug disclosure as “heroic”
it’s not heroic. it’s a systemic problem
yes they paid a smart researcher to find bugs and he did. that’s great
but the issue isn’t that the bug existed
the issue is that zcash, unlike almost any other cryptocurrency, enables a unique class of bugs, where if they’re exploited no one would know
this unique class still exists. the fact that they fixed this specific bug is immaterial. mythos could find 8 others. and then mythos 2
bugs can exist in all cryptocurrencies. they can exist in btc or eth or sol. but if someone exploits them we will IMMEDIATELY KNOW and limit the damage
with zcash, when someone secretly finds a bug and exploits it, WE WILL NOT KNOW
imagine if the kelpdao hack was exploited but it somehow magically wasn’t visible onchain. the attacker stole 300m but no one would know. and aave and other apps would assume everything is fine not knowing that they secretly have a hole in the balance sheet. how much wider would the damage have spread by the time we found out?
this is the real issue. not a specific bug. the systemic vulnerability: if a hack happens, we won’t know until much later
and a lot of zcashers have been trying to downplay the severity of this fundamental issue for years (including yesterday when this was first disclosed but played down)
regardless of this specific bug, i don’t think zcash is a safe place to store meaningful wealth long-term, until the design fundamentally changes
i wish zcashers were more open about that. that would’ve been heroic
‼️🚨 A new npm supply-chain attack compromised 57 packages across over 286 malicious versions in under 2 hours. The attackers used self-replicating malware, a new version of the Miasma worm, which also used evasion techniques to stay under the radar.
The payload targets CI/CD and developer credentials, including GitHub Actions secrets, cloud credentials, Vault tokens, SSH keys, npm and GitHub tokens, and password-manager stores. This variant also injects AI coding assistant config files at `.claude`, `.cursor`, `.gemini`, and `.vscode` paths, a separate persistence and repo-poisoning angle.
Wrote some related thoughts (with admittedly drier prose) on the impact of temporal choices on community formation and incentives in the kinds of systems we're building at @glossifi
https://t.co/CWg1WN6lD9
AI black hats are the ultimate forcing function
most devs have been sleeping on security for years as their code was not worth the time or effort to attack
now you simply cannot ignore it
proactive AI security solutions will play a huge role going forward
It is no longer acceptable for organizations to use confirmed vulnerabilities as the sole basis for avoiding software supply chain vulnerabilities. We have to move towards proactive security, which will require swarms of AI agents building "vibe graphs" of software dependencies.
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
0/ Clear signing is now live.
An open standard to end blind signing, making human-readable transactions default.
This effort brings a major UX and Security upgrade to transaction signing on Ethereum.
Vitalik Buterin on Ethereum as the economic layer for AI
“The blockchain to me is the most natural way to allow applications and cooperation between many different people in the long term without needing to agree on who to trust. The other thing is also the economic layer. This is the layer where blockchains can support AIs.”
Vitalik believes Ethereum will play a large role in the future of decentralized AI:
“If you have more decentralized AI, that means you have different AIs (agents, programs) that are controlled by different people and need to interact with each other. And for that interaction to be possible, you need to have an economic layer. Either cooperation is based on economic incentives and economic rules. Or it’s based on central control. It’s usually one of the two, and if we can set up the economic system, that makes more decentralized interaction between AIs possible.”
Source: @okx (Apr 2026)
Read our full article on why AI agents will need Ethereum for low-risk DeFi below👇
intelligence DAOs are a new type of network that put intelligence at the center.
a central context window of knowledge that creates leverage for the business line of the dao. organized as a GitHub repository, obsidian vault, or Dropbox folder.
humans and agents at the edge that “garden” the context, building and maintaining aqueducts of intelligence capital, financial capital, and other types of capital
this is the AI era organizational paradigm applied to networks/DAOs
3/ If you believe Ethereum security matters, consider contributing to the public goods helping make the ecosystem safer.
And if Canon Guard resonates with you, we’d appreciate your support, too. Donate below 👇
https://t.co/L4R3kH4A3L
If you’re tired of watching exploits dominate the timeline, this is your moment to act.
The Ethereum Security QF Round is LIVE!
Support the people and projects securing Ethereum and its L2s.
500 ETH (~$1M+) in matching from @thedaofund.
Explore & donate:
https://t.co/IlryUemfIJ