We're applying to become a GIVbacks eligible project on @Giveth
Audit waiting times and costs keep low-TVL protocols unaudited. Most exploits happen there. We're filling that gap.
https://t.co/EuyRtPYIHU #giveth
More support for Ethereum Security QF Round projects!
Thanks to @blockscout, every project in the round is eligible for a free one-month upgrade to one of Blockscout's developer plans.
🔹 Top 10 projects: Business API Plan (3B Credits/month @ 50 RPS)
🔹 Projects 11-134: Pro Plan (500M Credits/month @ 30 RPS)
Eligible projects will receive an email from Giveth with instructions on how to claim their upgrade.
Huge thanks to Blockscout for supporting the teams helping keep Ethereum secure. 🛡️
JUST IN: Zcash crashes 48% after Claude AI finds critical vulnerability allowing unlimited minting of $ZEC.
It went unnoticed for 4 years until it was patched on June 1st.
🤯An AI security tool has 1st-place performance on security contests from just 1yr ago. Solidity-auditor v3 is out, FREE & Open Source.
Thousands of Solidity developers are using the tool already. Upgrade your security baseline, use the tool🫡
https://t.co/SfxjuQ17gA
🤯An AI security tool has 1st-place performance on security contests from just 1yr ago. Solidity-auditor v3 is out, FREE & Open Source.
Thousands of Solidity developers are using the tool already. Upgrade your security baseline, use the tool🫡
https://t.co/SfxjuQ17gA
🚨Zcash reports a Critical security vulnerability capable of minting unlimited counterfeit ZEC tokens
The writeup proves that not all AI harnesses/prompts are made equal. "Using Claude" is not enough. Learn to evaluate which "AI" is good and which isn't. Hint: expertise & data
I also have another theory about duplicates: some projects and platforms abusing nonsense slop submissions.
You disclose an e2e-proven exploit, but it gets marked as a duplicate because of the "root cause".
The slop report contains the vulnerable lines but no actual proof or has invalid claims.
With enough slop, you cover all the lines where a reasonable bug could exist. Then the project reopens the invalid slop submission, pays it as Low, and avoids paying the actual Critical.
That’s my worst nightmare. That shouldn’t happen ever.
@WhiteHatMage I truly think i've been done like this as well, but very hard to know for sure. My hackenproof rep is almost solely coming from valid dups
How to actually earn $ as a web3 security researcher in 2026
We're getting @RealJohnnyTime, @sammyaudits, and @GuildAcademy_ together with the Remedy team to talk through it honestly:
→ Bug bounties vs contests vs going in-house - what's worth your time
→ How to pick targets that'll actually pay you
→ Competing when everyone has the same AI agents
→ Where independent researchers go from here
We see this differently, so come ready to push back.
June 4, 14:00 UTC
Live discussion on @xyz_remedy