🤯An AI security tool has 1st-place performance on security contests from just 1yr ago. Solidity-auditor v3 is out, FREE & Open Source.
Thousands of Solidity developers are using the tool already. Upgrade your security baseline, use the tool🫡
https://t.co/SfxjuQ17gA
🤯An AI security tool has 1st-place performance on security contests from just 1yr ago. Solidity-auditor v3 is out, FREE & Open Source.
Thousands of Solidity developers are using the tool already. Upgrade your security baseline, use the tool🫡
https://t.co/SfxjuQ17gA
rant time: people are so fucking obsessed with building more tools, more products, more services, more "security" layers. are you guys all fucking insane?? every single thing you add is more complexity. and complexity is exactly what makes systems _dangerous_. you don't get safer by stacking abstractions on top of abstractions. you just increase the attack surface and pray the whole dependency chain doesn't collapse (hint: it will collapse!!). now you depend on 10, 50, 100 moving parts. all needing updates, all with their own bugs, all potential supply chain failures and we call that "security" like fucking retards.
dude, it's the fucking opposite. we're not building safer systems. we're building systems so complex nobody actually understands them anymore. and almost nobody is asking the obvious question: **what can we remove?** everyone wants to add. nobody wants to reduce. that's how you end up in a nightmare system (hint: we're already in that nightmare). not because of one big failure. but because of thousands of tiny dependencies you never should have had in the first place.
software engineering in 2026:
- your package manager is compromised
- your cloud provider blocks your account
- github itself is hacked
software is solved
Kelp rsETH exploit is terrible due to extensive DeFi integrations.
Not sure how big the exposure is yet but:
- Aave V3: Markets already frozen
- SparkLend: Also froze the rsETH market
- Lido Earn via Mellow strategy meta-vault. I think it was a leveraged market
- Fluid: Frozen market
- Compound
- Euler
- Upshift: Paused High Growth ETH and Kelp Gain vaults
- Pendle PT YT tokens
- Some Beefy strategies. Yearn?
I suppose LayerZero is probably affected too, as rsETH were bridged from L2s, so I wonder if those rsETH on L2s aren't worthless right now.
The situation is still developing, so I don't want to FUD any protocol, but it seems there are not many places to hide in DeFi.
SEAL is coordinating an active investigation into the ongoing incident involving Kelp DAO along with all relevant stakeholders. If you have information to share or are able to assist in freezing/recovering funds, please reach out at https://t.co/QpXmM0iDM8
Link to site: https://t.co/Rq7IyUSvDm
Some highlights:
- Stack-too-deep is the number 1 pain point
- The majority use AI and 45% don't trust the output
- Foundry sees continued market gain as dev framework
- 70% have not heard of Core Solidity
🆕 Contract Tab Revamp
Navigating contract source code used to mean a lot of scrolling. Now you've got a full IDE-style code browser, plus refreshed read/write tabs
Here's what's new ⤵️
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now.
Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that:
• Deobfuscates embedded payloads and operational strings at runtime
• Dynamically loads fs, os, and execSync to evade static analysis
• Executes decoded shell commands
• Stages and copies payload files into OS temp and Windows ProgramData directories
• Deletes and renames artifacts post-execution to destroy forensic evidence
If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
The @battlechain testnet is now LIVE.
Come enter the ultimate red-team platform.
Give us feedback so we can launch mainnet very soon, and fix web3 security.
Web3 companies are posting jobs on https://t.co/zvJkff2QtY
Here is how to find them
1. Google "site:https://t.co/zvJkff2QtY defi"
2. Filter by date (last month)
Replace "defi" with other keywords
Positions I found
https://t.co/XeTACEsj49
Good luck
Source Code Intelligence is now live in EVM Chronicle.
Variables are now inline-clickable in source view, so you can inspect live storage instantly.
Functions are now simulatable directly from code, with inputs and execution traces in one flow.
From source → state → execution, without leaving the page.
Being the 1st public auditing skills author I can share this:
• AI can't write skills as well as actual auditors
• Over-verbose skills (e.g more than 5000 tokens a page) are creating context rot
• Installing other people's skills is much scarier than npm install
I solved this by utilizing my profile site to host the Auditor Skills Registry
• Skills I personally use (including skills from @pashov , @trailofbits , @QuillAudits_AI , @auditmos myself etc.)
• Security reviewed, guardrails, AI reliance rating
• Easy and secure 1-click installation to claude code / copilot cli / gemini cli / codex
IMPORTANT: Like or repost if you plan on using it, to let me know if I should keep it live:
https://t.co/ZzcrI0GfEN