You would hope that after we wrote up our findings for multiple live criticals on the Zodiac modules at @therealgregoAI months ago, that PERHAPS if one's company used these modules in a live, deployed, project the CISO would want to have another audit done (last one was 6 years ago with many changes since then)
Instead what happened is Gnosis has split into multiple different entities and neither one of them wants to own something that is widely used and directly affects their core product and brand
If a hacker reported this bug he would have received no bounty
Unfortunately, again, it looks like DeFi will only improve through pain
Big changes are on the horizon for DeFi and further crypto adoption in Japan next year
Lets keep security at the forefront while opening up more pathways to onboard to DeFi
Grateful for the opportunity and looking forward to a great discussion in Tokyo
I just found a bug and got paid on @immunefi#immunefitribe https://t.co/GnxG0hlmzc
One of the findings from v1.0 of @therealgregoAI which we originally submitted NINE MONTHS ago has finally reached a resolution
I wish this painful lengthy experience on no one and likely have set the immunefi world record
Let's strive to do better as an industry recognizing the efforts of whitehats and value their time appropriately
Believe it or not, there is code on the blockchain, that no matter how many times you run AI against it, it remains bug free
And then there are protocols with poor security (incl key management) that are getting rekt
Ultimately, we strengthen the ecosystem by embracing well established and well known INCREDIBLY BASIC security precautions + levelling up on AI defensive measures
There is a real need right now for AI defensive security which is what we are building at @therealgregoAI. It is a problem with a solution. Our team and many other big brains in this space are hard at work fighting back to ensure this space survives and thrives.
If you feel that the risk is not priced appropriately then that is an individual investment decision, but the market as a whole does not agree given current rates
IMO the benefits of DeFi outweigh its growing pains, and no, it's not time to throw in the towel because your favorite protocol trades meme coins with the admin key, but it is time for investors to demand security be taken more seriously and vote with their capital appropriately
Growth and maturation happens only through adversity
DeFi forever
We found multiple critical bugs in a well known Gnosis Safe Module recently (https://t.co/hjOmFAQvKl) and warned about the root level access that modules have when enabled
If you have a module that you have enabled on your Safe please drop it here and @therealgregoAI can take a look
The core argument: protocols often spend 6-figures on periodic human audits and still have no guarantee of security.
Code now ships faster than auditors can keep up with.
This exposes protocols to new risks between cycles.
Attackers are increasingly AI-assisted and are constantly looking for new vulnerabilities.
Security has to be continuous, and it has to be AI-powered too.
But not all AI security is the same. Most AI scanners stay at the surface and give you a ton of false positives.
Grego AI is built to go deeper than human review, because it’s tracing multiple logic across layers of interacting systems, and gives you minimal false positives.
We’ve found confirmed vulnerabilities in protocols like Lido, Chainlink, Reserve, Aave, Uniswap, Euler, Polygon, and others. All previously audited by leading security firms. All found 100% through AI.
Watch the full talk with our CEO @0xriptide here 👇
One more reminder that the best part of any event is always the people.
We had an amazing time at @ETHCluj with @banescusebi, @therealgregoAI, @kaereste@SteffenKux, and many others, and truly enjoyed the conversations throughout the event.
We had the opportunity to discuss the importance of public goods and open-source tools in the Ethereum ecosystem - from shared infrastructure and collaboration models to balancing open-source values with sustainable business growth.
Grateful for the warm atmosphere, the meaningful connections, and the great energy.
Honestly, I feel that the panels I am moderating are some of the best I've seen.
Just hosted one at @ETHCluj, on security issues we have on Ethereum, the AI threat and where are we heading (as in April we just lost over $600 M) and we had a fuuull house.
Here's a TL;DR:
* We have the same issues since 2018 because we are greedy (as humans)
* We need regulations, but not too much, as this might lead to too much centralization and control
* AI threads are winning at the moment over @ethereum
* We, as founders and builders are not sharp enough and attentive enough to look at security breaches (that can happen even by clicking something that someone we trust have sent) - look at what happened with Drift just last month
We also looked at some funny stories, bounty hunters and the impact of AI in security perception and the conversation could have gone on and on.
Wanna thank: @AdevarLabs, @DmytroMatviiv, @0xriptide , @kaereste and @SteffenKux and if you're interested, you will be able to watch the talk on Eth Cluj's youtube channel.
A $250,000 critical bounty is more than just a payout. It reflects a finding that helped protect $27.7M in user funds and shows how AI-assisted security is entering a new era.
This one breaks expectations in the best way. Congrats 🫡 @therealgregoAI
AI auditors are not created equal. @therealgregoAI has found millions of dollars worth of vulnerabilties and scan codebases, bug bounty or not, to keep us all safer.
Learn more: https://t.co/UiM4BqbDky
Support: https://t.co/vtNDB1wfCI
The Grego AI team is at @EthPrague !
Stop by our booth to learn how Grego AI found $450,000+ worth of public bug bounties in the last 6 months
What did your human auditors miss ... ?
$IMU pledgers remain bullish on AI sec agents.
@therealgregoAI just received another 20,000 $IMU pledge!
Pledge more to see what it can pull of this year:
https://t.co/QOzPqwLXFa
Excited to welcome @0xriptide as a speaker at ETHCluj.
Riptide is the CEO & Co-founder of @therealgregoAI , a deep scanning AI vulnerability detection system, and a top-ranked bounty hunter who has disclosed numerous critical bugs across major DeFi protocols.
We look forward to the insights he’ll share with the community.
Help us secure the blockchain!
Grego AI is part of this QF round for Ethereum Security along with many, many, other great projects that could all use your support!
https://t.co/7JqgfsxCxP
"AI Killed the Audit Cycle", and we’re going to talk about that on stage.
Justus (@0xriptide) is the co-founder of @therealgregoAI, "the security layer that never sleeps," and one of the partners of this year’s edition.
Soon at ETHPrague ☀️