Securing and Building EMERGING Web3 Ecosystems 🛡️Sub-brand: @MoveBit_ | @ScaleBit_ | @TonBit_ 💡Bitslab AI Scanner:@BitslabAIOfc
1. Background & Event Overview In the evolving landscape of Decentralized Finance (DeFi) and Non-Fungible Tokens (NFTs), hybrid token standards combining ERC-20 and ERC-721 functionality (such as
Between August 20 and August 25, 2026, attackers exploited a balance-handling flaw in Cosmos EVM across multiple Cosmos-based networks. Cosmos Labs later confirmed that six networks were exploited.
Security incidents in DeFi are increasingly revealing a fundamental shift: the most dangerous vulnerabilities are not always hidden inside smart contract code. They often exist in the assumptions
In smart contract security, most discussions start with a familiar question: does the code contain vulnerabilities? Security teams spend significant effort analyzing reentrancy attacks, access control
For most users, joining a Zoom meeting would not normally be considered an attack surface. There is no need to open a suspicious attachment, click a link, or download a file. But a recently disclosed
Briefing As AI Agent frameworks scale into production, identity authentication and prompt injection are being chained together in increasingly subtle ways. During a code review of the open-source
BitsLab Research · Balancer V2 Series (1/3) In 2020, while every other AMM was iterating on the "one contract per pool" model that Uniswap V2 popularized, Balancer made a counterintuitive call: put
TL;DR — BitsLab has disclosed the first security vulnerability identified in nanobot, an AI Agent framework. The flaw is a Channel-layer authorization bypass that requires only a single | character to
By BitsLab Security Research | 2026-04-20 —————————————————————— I. Incident Overview On 2026-04-18, a major security incident occurred on the rsETH cross-chain path operated by Kelp DAO / KernelDAO.
2026-04-13 | Security Incident Report by BitsLab On April 13, 2026, the Hyperbridge bridged DOT asset on Ethereum suffered a confirmed security exploit. The attacker forged a cross-chain message that
Prediction markets are emerging as one of the most disruptive sectors in on-chain finance. As the largest decentralised prediction platform today, Polymarket's underlying arbitrage dynamics have
1. Introduction When an AI Agent possesses system-level capabilities such as shell execution, file read/write, network requests, and scheduled tasks, it is no longer just a "chatbot"—it is an operator