- an @aeonframework agent was given a non-custodial wallet with a few dollars of pocket money and one instruction: buy live ETH market data, fund its own deployer, and ship a Uniswap v4 hook to Base mainnet - which it did autonomously, with every step logged in a public GitHub Actions run.
- along the way it paid CoinMarketCap one cent in USDC over x402 and at one point *refused* a gas transfer the team actually wanted, because it read the wallet's transaction history and judged the repeated transfer plus a look-alike address to resemble a drain attack. It then compiled, simulated against a Base fork, and only deployed once the simulation passed - baking the purchased data (ETH's −0.18% 24h move, as an 1800 bp premium) into the hook's fee logic.
cool article @FD_XYZ ⭐
the vuln-scanner system on base:0xbf8e8f0e8866a7052f948c16508644347c57aba3 secured 2.4M stars amongst google, tencent & spaceX
it was so effective yet so simple, and a great proof of concept. now it's time to move to something bigger.
i've finally finished the new system, 10x more effective than the previous one.
starting to use it to secure the biggest orgs.
lets accelerate ⭐
Reddit loves @aeonframework
The vuln scanner skill of base:0xbf8e8f0e8866a7052f948c16508644347c57aba3 giving a vulnerability heads up to @Google , which was recognised is well appreciated by r/googlecloud fam.
r/googlecloud - The goto subreddit for Google Cloud Platform developers and enthusiasts , with over 35k+ users are learning more about aeon !
We’ve shipped a major set of updates across Family, covering new trading pairs, improved swaps, social profiles and followership, referrals, a redesigned House, continued progress on the House SDK, stronger platform safeguards, and a new way for communities to create a Family without launching a token immediately.
These changes are important because they move Family beyond simply creating and trading Familycoins and closer to the larger vision: giving communities the infrastructure to build their identity, grow their community, and eventually create a shared economy.
Read the full changelog and see what’s new across Family. https://t.co/X0mIQkFIX7
Shinhan Asset Management is Korea's leading asset manager.
They have AUM of over KRW 133.6 trillion and just signed an MOU with Plume for a KRW-denominated tokenized fund POC, to be held in a third jurisdiction.
Read more on how this helps Open Institutional Finance: https://t.co/jgH9v8g9M9
Plume joining The DTCC's Digital Assets Solutions Industry Working Group, alongside names like @BankofAmerica, @Citadel, and @jpmorgan, is a signal.
Open Institutional Finance is now non-negotiable for the world's largest financial institutions.
Network Reachability for Autonomous Agents
Banks are beginning to run AI agents against their own systems: software that holds delegated credentials and acts with some autonomy across internal services.
An agent can enumerate services, attempt connections, and move between hosts at a rate no analyst matches.
A security operations center evaluates this activity after the traffic reaches it. RAVID operates earlier, at the network layer that determines whether an agent can reach a service at all.
RAVID is identity-driven microsegmentation delivered as a software overlay. Microsegmentation means reachability between endpoints is controlled per connection rather than by broad network zones. An overlay is a software-defined layer that runs above the existing IP network. On that overlay, each user, agent, device, and service is addressed as a cryptographic identity - an endpoint authenticated by a credential rather than located by an IP address.
Agents are enrolled as identities, not as users issued API keys. The overlay operates default-deny: a service is not resolvable to a requester, and accepts no connection from it, until the requester authenticates and the specific connection is authorized. An agent that has not satisfied both conditions has no route to the service, and the service is not resolvable to it.
This model governs which services an agent can reach. It does not govern what an agent does once a connection is authorized, and it does not address application-layer logic or the misuse of a credential that policy currently permits. Behavioral control over an authorized agent is a separate concern, which Enigma addresses with the AI Killswitch; RAVID covers the network-reachability portion of that control.
Where the model contributes directly is containment. Because connection policy and network reachability are evaluated in one plane, revoking an identity ends its authorization and its connectivity at the same time. There is no interval in which permission has been withdrawn but a route still exists. For an agent showing unexpected behavior, revocation removes its reachability across the overlay in a single action rather than through firewall changes applied host by host.
$ENX
Development Update
A short status on current work.
EPN Beta:
EPN - session-scoped, non-routable private network connectivity - is close to launch towards community beta. We’re targeting June, gated by the current review pass.
Security review:
An independent group is running penetration testing against the current build and feeding findings back into development. Resolving findings is the condition for opening the beta.
User testing:
A small testing cohort is being added this week to cover usage under varied network conditions. We’re also opening this to the community: beta testers who can exercise the build and report back will help, and we’ll post details on how to participate alongside the beta.
Integrations:
Integration and evaluation discussions are underway with several partners, including a deployment to a self-healing datacenter operator. We’ll describe each in more detail once the technical scope is confirmed and disclosable.
Next step is an internal sync before the next round of testing and deployment.
48 countries now automatically report your crypto transactions to tax authorities.
Not in the future. Right now. CARF is live. DAC8 is live.
Every trade, every transfer, every wallet interaction.. collected, reported, and shared across governments automatically.
The era of flying under the radar is officially over.
This isn't a reason to panic. It's a reason to understand the difference between surveillance and compliance. Between handing over everything and proving what needs to be proven.
Zero-knowledge proofs let you do the latter. Prove your transactions are clean without exposing your entire financial history. Compliance without total transparency.
That's not a workaround. That's how privacy and regulation were always supposed to coexist.
𝗡𝗨𝗟𝗟𝗠𝗔𝗦𝗞
Privacy used to be a fringe obsession. Now it's infrastructure.
The shift happened because the problem became impossible to ignore. Your wallet is a public ledger. Every trade, every balance, every counterparty — permanently visible to anyone who looks.
The tools listed here are all building toward the same thing. The difference is where in the stack you solve it.
Most solve it at the chain or token level. You need a new coin, a new address, a new ecosystem.
Nullmask solves it at the wallet level. No new coins. No new seeds. No new anything. Just privacy, from the wallet you already have.
𝗡𝗨𝗟𝗟𝗠𝗔𝗦𝗞
Ray Dalio said it.
Grayscale filed for it.
Institutions are demanding it.
Privacy is no longer a fringe conversation in crypto.
It is the conversation.
The only question left is who builds the infrastructure that actually works.
Not for a new token, not for a new chain, but for the assets people already hold.
That's what we're building.
Nullmask
Most people think shielding a transaction is enough. It's not.
Even if your transaction is encrypted on-chain, the act of sending it reveals something: your IP address. The server that receives your transaction knows where it came from. That's a linkability problem.
Nullmask solves this with a decentralized relayer network.
When you send a shielded transaction, the Nullmask proxy doesn't broadcast it directly. It forwards it to a relayer, an independent node that submits the transaction to the contract on your behalf.
The relayer pays the gas.
You stay invisible.
The relayer sees the shielded transaction.
It doesn't know who sent it.
The contract sees the proof.
It doesn't know who created it.
End to end: no on-chain link between you and your transaction. No IP exposure. No metadata trail.
That's what complete privacy looks like.
NULLMASK
Privacy coins are having a moment.
Zcash at $600. Monero at all-time highs. Grayscale filing for a spot ZEC ETF. The market is screaming for privacy and capital is flowing toward it fast.
But here's the problem that nobody wants to talk about.
Every one of these assets asks you to leave behind the tokens you actually use. Your USDC. Your USDT. Your ETH. The stablecoins tied to your real financial life.
You can't send private USDC through Monero. You can't shield your USDT through Zcash.
Privacy coins solve privacy by creating a new silo.
Nullmask solves privacy by adding it to the silo you're already in.
The demand is real. The market is just still looking in the wrong place.
NULLMASK
Math. Not promises.
- The government keeps renewing mass surveillance laws.
- Hackers keep stealing centralized databases.
- Nation states keep studying your on-chain history.
The only answer is systems that don't require trust in the first place. Not trust in a company. Not trust in a government. Not trust in an operator.
Math. Not promises.
NULLMASK
Privacy is not the enemy of compliance. Surveillance is not the same as accountability.
These two things keep getting confused.. by regulators, by institutions, by journalists covering crypto.
Compliance requires that the right parties, under the right conditions, can verify that transactions were legitimate. It does not require that everyone can see everything all the time.
Surveillance is not accountability. It's a blunt instrument that catches criminals and innocent people in the same net, stores everything indefinitely, and creates databases that will inevitably be breached.
ZK proofs offer a third path. Selective disclosure. Prove what needs to be proven. Reveal nothing else.
Regulators get accountability. Users get privacy. Nobody has to compromise.
That's not a workaround. That's a more precise implementation of what compliance actually demands.
NULLMASK
Arbitrum froze $71M.
Not a smart contract.
Not a token issuer.
The network itself.
We’re not here to say if that decision was right or wrong.
But it highlights something fundamental:
If a system can make that decision,
then that power exists.
Security vs sovereignty.
Control vs ownership.
In moments like this, you see what a system really is.
Why QF exists:
To ensure the foundations of digital life cannot be paused, frozen, or overridden.
Ownership isn’t situational.
It either exists. Or it doesn’t.
QF
Start Where Freedom Is Engineered