Smart Contracts, Off-chain Components and AI Integrations Security Reviews Worked with: @LidoFinance @UniswapFND @redstone_defi @YieldNestFi @0xOthentic

Let us help ๐Ÿ”Ž๐Ÿ›
We are proud to announce the release of the updated ๐—ฆ๐—บ๐—ฎ๐—ฟ๐˜ ๐—–๐—ผ๐—ป๐˜๐—ฟ๐—ฎ๐—ฐ๐˜ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฉ๐—ฒ๐—ฟ๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ฆ๐˜๐—ฎ๐—ป๐—ฑ๐—ฎ๐—ฟ๐—ฑ (๐—ฆ๐—–๐—ฆ๐—ฉ๐—ฆ)! โœ… The best and most comprehensive checklist available for Solidity based smart contract projects.
5
42
116
32,688
There may be some AI security involved.
Quietly added a pretty cool client to our website ๐Ÿ‘€ More on this one soon.
109
Only 15 security firms worldwide are currently undergoing accreditation with SEAL Certifications. @Composable_Sec is one of them. If your protocol is considering certification, talk to us! We can explain the requirements and help you get started.
15 firms are undergoing accreditation with SEAL Certifications and taking on audit engagements right now โ€” smart contracts, incident response, treasury security, multisig ops, and more! If your protocol hasn't scoped an audit yet, reach out directly to a Certification Partner today: securityalliance.org/our-worโ€ฆ @AdevarLabs @audit_wizard @BlockSecTeam @chain_security @Composable_Sec @ConsensysAudits @DefiSafety @hackenclub @HackenProof @SecurityOak @opsek_io @sigp_io @Wonderland @zellic_io @zeroshadow_io
1
135
Quite a piece of history
Wow - 7 years ago together with @drdr_zz we published the first version of SCSVS, the Smart Contract Security Verification Standard. It wasn't even on GitHub. At the time, it was the first security standard created specifically for smart contracts. A lot has changed since then. SCSVS evolved, Web3 security evolved, and many early auditor checklists, methodologies and security tools drew inspiration from the knowledge collected in SCSVS - including projects such as Solodit. With limited resources, we eventually chose to focus our time on building other things rather than pushing SCSVS as aggressively as we once did. But in many ways, what exists today is even better. We now have initiatives like @_SEAL_Org Security Frameworks - a much more advanced, community-driven effort built collaboratively by many excellent security researchers across the ecosystem. And I think thatโ€™s exactly how security standards should evolve: not owned by one company or a handful of people, but continuously improved by the collective experience of the community. I still remember the first feedback, discussions and support we received from many Security OGs when SCSVS was just getting started. A beautiful little piece of Web3 security history for me. Thank you to everyone who contributed, challenged us, shared it or supported the idea along the way. โค๏ธ github.com/ComposableSecuritโ€ฆ
80
Quietly added a pretty cool client to our website ๐Ÿ‘€ More on this one soon.
9
3
20
441
Weโ€™ve all heard that AI agents can escape sandboxes or find unexpected ways around isolation. That doesnโ€™t mean sandboxing is useless. The goal isnโ€™t perfect containment. Itโ€™s reducing access and limiting the blast radius when something goes wrong. If your coding agent has a shell, you should think carefully about what it can reach. We covered practical options here ๐Ÿ‘‡
1
1
4
232
Composable Security โ›“๏ธโ€๐Ÿ’ฅ retweeted
New framework on developer-targeted intrusions. Based on SEAL's incident responses, it covers the most common attack vectors we observe against devs. Learn to threat model your execution environment and stay secure against persistent malware campaigns. frameworks.securityalliance.โ€ฆ
3
17
63
7,443
Another 5.0 โญ๏ธ review We helped the team identify and remove 21 issues from the codebase, but just as importantly, they appreciated how we worked together: clear communication, quick responses, and staying on schedule. Thatโ€™s exactly the kind of relationship we want to build with the teams we work with. Thanks for the trust and the great feedback!
1
1
146
Composable Security โ›“๏ธโ€๐Ÿ’ฅ retweeted
AI FOMO has a security side effect: permissions become an afterthought. During security reviews of AI-integrated projects, Iโ€™ve noticed a recurring pattern: the pressure to adopt AI quickly, often driven by FOMO as you said, leads teams to underestimate the importance of well-designed authorization and permission models. As teams push for more usability and autonomy, security controls are often loosened to avoid slowing development down. In practice, this creates systems that are easier to build quickly, but much harder to govern, scale, and secure over time. From my experience, successful AI adoption requires the opposite approach: strong foundations, explicit trust boundaries, precise permissions, and clear instructions defining what AI systems are allowed to do - and under which conditions. Speed matters, but sustainable modernization comes from designing autonomy with security in mind from the beginning, rather than trying to add control once the system is already in production.
1
1
3
330
Back with @LidoFinance - this time at the authorization layer. Weโ€™re auditing LIP-37: Execution Delegation Framework (EDF), security-critical infrastructure for delegated permissions across Lido Oracle and DSM roles. Who gets to act matters. So does the code. ๐Ÿ”
1
2
107
Composable Security has joined @Anthropic's Cyber โ€‹โ€‹Verification Program We automate everything a security expert shouldn't focus on and provide the best possible tools to make our work effective. It gives us, and our agents, access to Claude's extended cyber capabilities for defensive work and research.
1
2
143
We are pleased to announce that we will be auditing DCLEX, the non-custodial exchange for tokenized stocks built by @PrimeDelta_. DCLEX lets traders swap tokenized stocks and cryptocurrencies at real-time market prices. It runs on a peer-to-pool model: liquidity pools pair each stock with USDC, and anyone can contribute liquidity to earn a share of the swap fees. The team entrusted us with an important first audit of the core functionality, and as always, we intend to do everything in our power to secure our client. Throughout the engagement, we will work closely with them to make sure the audit not only detects vulnerabilities but also enhances overall security. More details soon; follow us to not miss them!
1
2
138
Itโ€™s a pleasure to work with such an experienced team. Weโ€™re grateful for the trust @LidoFinance placed in us. Our expertise in off-chain component audits helped strengthen protocol security. A true collaboration, driven by brainstorms and a shared focus on the best results.
Lido Core Upgrade: Audited โœ… Contributors maintain the highest security practices with every upgrade undergoing two independent security reviews. The Lido Core upgrade is no exception with audits covering smart contracts, governance components, and off-chain infra. โ†“
3
134
Composable Security โ›“๏ธโ€๐Ÿ’ฅ retweeted
1/ Your AI coding agent can read your repos, credentials, and SSH keys. The question is not "is my tool safe" but "how much can it reach." We mapped 7 AI dev setups to where each one actually belongs. ๐Ÿงต
3
2
5
124
1/ Your AI coding agent can read your repos, credentials, and SSH keys. The question is not "is my tool safe" but "how much can it reach." We mapped 7 AI dev setups to where each one actually belongs. ๐Ÿงต
3
2
5
124
4/ VM โ†’ high. For untrusted code, external PRs, sensitive work. Remote env โ†’ high. Central governance, but the risk moves to the provider you now trust. Ephemeral per task โ†’ highest. Fresh env, destroyed after. For autonomous agents and unknown code.
1
24
5/ Two things that don't change with any setup: - Isolation โ‰  trust. Architecture protects more than configuration. - Output still needs review. Merged code and CI/CD changes carry risk out of the sandbox. When unsure: move one level up. Full guide ๐Ÿ‘‡composable-security.com/blogโ€ฆ
18
The biggest risk with AI agents is giving the wrong agent the wrong level of access. Each AI development setup gives an agent a different level of access to your machine, source code, credentials, system commands, and network resources. The goal is not to maximize security at the expense of productivity. It is to match the level of protection to the risk of the task. You do not need maximum security for every task. But you should never use a weak setup for a high-risk one. ๐Ÿ“ฐ New article about this soon!
Made with AI
2
90