Top 3 Open Source scanners:
1. https://t.co/PMB8RpTxD7 - so cheap it's basically free
solidity-auditor + x-ray pre-audit scan + fuzz suite gen, feedback in ~10 min while you build
2. https://t.co/IxpCluWVve - 30-100$ per full run
autonomous agent, 8 phases, ships PoCs with the findings, covers EVM, Solana, Move
3. https://t.co/VoueEdlrO8 - cheap
40+ security skills from Trail of Bits for contract audits, differential review, static analysis
@brandon_shi Which models do you use? How do GPT models manage to bypass cybersecurity-related censorship or controls? Every time I try to use them, I get blocked.
5 more prediction market bug
All from real audits I ran
---
1. Minting one side breaks the backing
In the Gnosis conditional tokens framework, adding collateral mints both YES and NO, so outcome supply always stays backed by collateral. This AMM mints only the side you buy.
Fund the market with 1000, then buy 500 YES, and it mints 500 YES and 0 NO. The market now sees 2500 in outcome supply against 1500 of collateral. The cost function prices off that inflated supply, so every trade after it is mispriced.
---
2. Buy and sell in one trade
The same trade path takes a signed amount per outcome, positive to buy, negative to sell, then casts each one to unsigned in the buy branch. A sell is negative, and casting a negative number to unsigned turns it into a huge one.
Sell 50e6 of one outcome while buying another and the contract tries to mint 2^256 - 50e6 of it. Usually that reverts on the overflow. Under the right pool state it does not, and one outcome token gets inflated instead.
---
3. YES and NO counted as a dollar each
When paying out yield, the vault adds up the YES side and the NO side and treats each of them as USDC.
A YES and a NO are worth 1 USDC together, not 1 USDC each. Summing them separately double counts the payout, so the vault sends out more than the position is worth and the shortfall comes out of everyone else.
---
4. Fake TWAP finalizes a market early
Markets resolve off a signed TWAP from the backend, but the signature check only runs if the market is flagged as needing one. On a market that is not, the condition short-circuits and the verification is never reached.
Anyone can then submit unsigned TWAP data with a positive end time. The market treats itself as finalized and all the yield skews to one side before it should have resolved at all.
---
5. Block the TWAP that resolves the market
The resolving update has to line up exactly with the last update timestamp. That start timestamp is fixed inside the backend's signed data, but the last update moves on any vault activity.
Front-run the resolving update with any small action, the last update jumps past the signed value, and the real TWAP can never be applied. The market cannot finalize and yield distribution stalls.
@Tele_Swap It appears TeleSwap had a $735K+ exploit on July 15, 2026 and still has not disclosed the incident publicly after five days.
Shortly after the suspicious outflows its Bitcoin hot wallet stopped processing transactions. Two hours ago the attacker deposited the funds to Tornado.
Source: DefimonAlerts. Fractal Protocol's Arbitrum USDF vault had a smart contract exploit. About $13.7K was taken and the vault's liquid USDC buffer collapsed from 14,778.313371 USDC to nearly zero. TVL before was 97.27K, so this was a material loss path.