1/ 🚀 In today’s DeFi market, users are getting rugged more than ever through bad quotes.
Security is essential at every layer.
That’s why we just shipped Swap Shield on https://t.co/ppb6sWC9Kf — oracle-protected swaps.🛡️
Fireside Chat with @VitalikButerin - on oracles:
1. Oracles are the skeleton in the closet of the entire industry.
2. No point hardening ZK proofs and pushing Stage 2 while oracles often run on a single server
3. "Security is only as strong as the weakest link"
While our BackGeoOracle has its own limits - the asset must exist onchain - it is an onchain non-centralized non-censorable manipulation-resistant oracle.
Fireside Chat with @VitalikButerin , @ethereumJoseph & Lighter founder @vnovakovski !
We will discuss high performance applications, ZK rollups on Ethereum, roadmap for scaling, future of DeFi, and beyond.
Monday, May 18th at 3PM UTC. Link in the replies.
Don't miss it!
New Market Trading reached for it as the entry point for privileged Safe actions, placed no additional access control behind it, and shipped it to production.
Fact about onchain asset management vaults: nothing prevents a strategy curator to use a vault's gains to cover another vault's losses. And yes, it's called fraud.
You can spin up a price feed for any token in seconds - you could even ask your agent to do it for you!
read more at https://t.co/IrS86sq6ae
built on @Uniswap V4
A new price feed for ethereum:0x232ce3bd40fcd6f80f3d55a522d03f25df784ee2 is live on the BackGeoOracle.
This means:
1. @Lighter_xyz protocol token is tradable for Rigoblock smart pools
2. any application that needs a price feed can tap into it for free
3. no downtime, ever! Even at current ultra-low liquidity it has updated almost every hour, its heartbeat is determined by market movements
Do you want your own price feed? 👇👇👇
Announcing Lighter RFQ in beta! Available on the web app on eligible RWA markets.
Enter and exit larger positions in one click with lower slippage and better pricing.
“Most of the largest recent hacks haven't come from missed smart contract bugs but from off-chain attacks and code shipped between audits.”
For vaults, this has meant moving code from the smart contracts to offchain components. A hazardous game — as endless exploits have proven.
Crypto companies lost over $3.4 billion to hacks in 2025 🚨
The largest losses didn't come from smart contract bugs. They came from compromised credentials, operational failures, and code shipped between audits.
While audits are essential, it's clear they're not enough.
You do not leave a hanging allowance
You Do Not Leave a Hanging Allowance
YOU DO NOT LEAVE A HA - wait… that’s a professional market maker?
1. As a trader, trade. Leave smart contract design to the professionals.
2. As a price taker, leverage tools that protect yourself.
1/ Security incident on Ethereum
Tx:
0xc5c61b3ac39d854773b9dc34bd0cdbc8b5bbf75f18551802a0b5881fcb990513
This was not an AMM or lending exploit.
It appears to be an RFQ / OTC order execution abuse caused by a missing access control check on signer registration.
A good agent design should ship with strong execution guards. The Rigoblock agent is bound to:
- Mandatory NAV Shield
- Mandatory Swap Shield - Restricted functionalities
Agents are great - harnesses give you piece of mind.
https://t.co/8ryNn0lwCF
#AgenticAI#DeFi
Someone gifted Grok a free NFT and used it to steal $174,000.
> Grok, the AI built by xAI, has a publicly labeled onchain wallet on Base. Anyone can see it on Basescan.
> An attacker linked to the address ilhamrafli.base.eth spotted something. Grok's wallet had limited transfer capability on its own.
> So the attacker gifted Grok's wallet a Bankr Club Membership NFT.
> That gift was not generosity. It was a key.
> The NFT unlocked Bankr's full toolset inside Grok's agent including the ability to sign and execute transfers autonomously.
> Then the attacker sent Grok a crafted prompt. The exact message was deleted before anyone could screenshot it.
> Known techniques used in attacks like this include hiding instructions in Morse code, base64 encoding, or framing commands as games or tests to bypass filters.
> Grok's intent parsing layer read the prompt as a legitimate user command and decided to execute it.
> Bankr signed and broadcast the transfer. 3,000,000,000 DRB tokens worth approximately $174,000 moved from Grok's wallet to the attacker's address.
> The tokens were instantly bridged to a second wallet linked to ilhamrafli.base.eth and dumped.
> The attacker's X account was also deleted within minutes of the transfer.
> The exploit only required a free NFT and a carefully worded message.
The most sophisticated AI in the world was robbed with a gift and a sentence.
Accessible either directly or via API (without account).
Also, when you make queries to our agent you get charged for only the actual inference cost - coupled with a superefficient architecture, you can sharply reduce the inference cost of your main agent.
If you need strong harnesses for your DeFi trading agent https://t.co/mK8yT4DgQW is definitely what you’re looking for:
- max portfolio loss protection
- swaps pre-verified against an oracle
- extra protections if your agent goes rogue or is compromised
After 6 weeks with 44 early builders, Zealynx Academy is public today 🥳🥳🥳🥳🥳🥳
A platform to help Web3 founders build secure protocols and grow them into real businesses.
Four things inside:
- Guides to fork DeFi protocols with awareness
- Security training to build safer Smart Contracts
- MBA-level knowledge to grow your protocol into a business
- Interactive guides to build your own AI Agents to help you grow your company
https://t.co/OfrgnFHscJ
Maybe — just maybe — users should not hold the tokens on the same wallet that signs the transactions. Maybe the wallet holding the tokens should have onchain rules to protect those tokens. And maybe a separate wallet should be delegated for interacting with DeFi applications safely.
If only one such product existed!
6/ Live now on RigoBlock Vaults inside the Agentic Chat. Ready to trade? → Try Swap Shield right now: https://t.co/mK8yT4DgQW
Builders & integrators: Want oracle-protected quotes in your own app? Get in touch.
#RigoBlock#SwapShield#DeFiSecurity#UniswapV4#AgenticAI
1/ 🚀 In today’s DeFi market, users are getting rugged more than ever through bad quotes.
Security is essential at every layer.
That’s why we just shipped Swap Shield on https://t.co/ppb6sWC9Kf — oracle-protected swaps.🛡️
5/ Equally powerful for humans and agents.
When you give autonomous agents execution power, you want protection against bad quotes or hallucinations.
Swap Shield delivers exactly that.