๐ฅ Tripwire: Built by @sigintzero_ is a 24/7 threat detection and response system that identifies exploit signals before execution, monitoring contract behaviour, fund flows, and attack patterns to protect deployed protocols in production.
Built by @alteredlad
Link: https://t.co/2lSC6IeKb3
Super stoked to share that we at @sigintzero_ have been awarded a $10k USDG grant from @SuperteamAU as we build toward Tripwire, our 24/7 on-chain monitoring and threat response system for Solana, focused on post-deployment security and real-time protection.
Awesome to see support going toward Australian builders pushing the ecosystem forward.
Weโre now heads down for the final stretch of the @colosseum Frontier Hackathon, focused on delivering it in full and getting it into the hands of teams.
you can vibe code crypto stuff:
1. ideate with claude on web
2. spec it up with claude code
3. claude code it from spec
4. thoroughly test the lot
5. audit by @sigintzero_
gtm. get a response. pivot
you can do anything
AUS BUILDOOORS APR 2026
Our monthly Sydney meetup is back! Here's who's speaking:
- @ksaitor (founder of @CryptoJobsList)
- @SanLeo461 on wallet privacy
- @alteredlad on AI audits with @sigintzero_
Date: Wed 29th April
Time: 5:30PM - 8PM
Location: Redfern
RSVP Below ๐
We wrote a full breakdown: how durable nonces work, why a 2-of-5 multisig with zero timelock made this possible, and what protocols need to change.
Audits tell you the code is safe. Tripwire tells you it still is, right now, in production.
https://t.co/N6k2NMGDEy
Drift Protocol lost $270M+ on April 1. No smart contract bug. No stolen keys.
The attacker abused Solana's durable nonces to trick 2 of 5 Security Council multisig signers into approving what looked like routine transactions. Those approvals sat dormant for 9 days.
On April 1, one minute after a legitimate insurance fund withdrawal, the attacker submitted the pre-signed transactions. Two txns. Four Solana slots apart. Full admin control transferred. Vaults drained.
Elliptic suspects DPRK. Bybit lost $1.5B the same way 14 months ago.
The code was fine. The people were the attack surface.
Earlier today, a malicious actor gained unauthorized access to Drift Protocol through a novel attack involving durable nonces, resulting in a rapid takeover of Driftโs Security Council administrative powers.
This was a highly sophisticated operation that appears to have involved multi-week preparation and staged execution, including the use of durable nonce accounts to pre-sign transactions that delayed execution.
We analyzed the 100 largest protocol hacks - $10.77 billion in total losses.
Only 20% were audited.
Audited protocols = just 10.8% of losses.
Audits work. But when audited protocols DO get exploited, the cause is always the same.
A thread on what the data actually shows:
We published a full comparison of 6 firms - SigIntZero, Trail of Bits, OpenZeppelin, CertiK, Consensys Diligence, Halborn.
Evaluated on business process comprehension, not just tooling.
Also covers:
- Competitive audits (Immunefi, Code4rena, Sherlock)
- Actual audit pricing ($5Kโ$200K+)
- MiCA regulatory impact