Let's make web3 more secure! AiSec x Web3

DeFiHackLabs retweeted
🔥We’re heading to Seoul today for tomorrow’s ScanCTF finals, a CTF focused on tracing and investigating on-chain fund flows, with challenges created by Chainalysis.
1
2
12
701
DeFiHackLabs retweeted
ETHTaipei 🔥
1
3
29
1,331
DeFiHackLabs retweeted
We’re excited to partner with @DeFiHackLabs for ETHTaipei 2026. DeFiHackLabs is a Web3 security community that turns real incidents into open learning resources. Its initiatives reproduce DeFi exploits with Foundry, document root causes, teach common smart contract vulnerabilities, and make past incidents searchable through the Incident Explorer. Through its Web3 Security Academy and BootCamp, the community also brings those lessons into hands-on security practice, helping builders learn from past attacks and build more securely. Sep 13–14 · Taipei Explore ETHTaipei 2026: ethtaipei.org Join us in Taipei: luma.com/8z5ys4rl
4
10
682
🔥 Congratulations to the DeFiHackLabs members who participated in the Trustworthy AI Hackathon, organized by TABEI, and won 🥈 2nd Place! #Trustworthy #AI #Hackathon
1
2
11
1,054
DeFiHackLabs retweeted
A few weeks later and I’m still buzzing from Black Hat USA 2026. Learned so much, met tons of new friends, and the memories are still fresh. Special thanks to @1nf0s3cpt for joining me. Everything was just perfect.
1
6
164
DeFiHackLabs retweeted
A Security Researcher Reworked OpenAI’s CDC Prompt — and Found a $500K RCE for About $25 in Model Usage I adapted the approach into a generic vulnerability research prompt. The image contains the full version; here’s the short version. Good luck hunting. If you’ve built your own prompts or harnesses, share them too. A generic CDC-style vulnerability research harness (short version): - Run multiple agents in parallel across distinct exploit families. - Avoid premature convergence. Do not let every agent pursue the same promising path. - Mark failed or exhausted paths as blocked. - Regularly launch new hypotheses and explore neglected attack paths. Independently adversarially validate every concrete finding. - Have the root agent continuously synthesize results, challenge assumptions, reprioritize work, and redirect agents. - Do not use git history, changelogs, CVE databases, or patched-version diffs as shortcuts. - Require the full exploit chain to work in a realistic, commonly deployed configuration and meet the defined starting-privilege → impact goal. - When behavior depends on implementation details, inspect the runtime, framework, database, libraries, and dependency source directly. - Do not stop at the first primitive. Chain validated primitives until the concrete success condition is reached.
21
81
851
46,980
DeFiHackLabs retweeted
🚨 History tells us what comes next: another wave of fake scams. Expect fake SafePal support accounts, fake compensation claims, fake security updates, and fake verification links. Scammers love exploiting the confusion right after a real security incident. Stay alert. 👀
Beware of phishing attempts! 👇 Disclosure: SafePal is a YZiLabs portfolio company (minority investor).
2
8
1,016
DeFiHackLabs retweeted
@AliceHsu_kou joins ETHTaipei 2026 with new research on evaluating LLM tools for smart contract security at @onesavielab. After presenting at ETHTaipei 2025 on AI-powered smart contract security, Alice is back this year with results from Bastet, an open-source DeFi vulnerability research project, and its Kaggle competition for LLM-based vulnerability identification. In “Evaluating LLM Tools for Smart Contract Vulnerability Identification in Web3,” she’ll break down the dataset pipeline, scoring mechanism, top solutions, and what the results reveal about how LLM security tools actually perform. Explore more and attend: ethtaipei.org/
2
6
431
DeFiHackLabs at Black Hat & DEF CON. 👉 🥇 1st Place at the DEF CON Cryptocurrency Village Web3 CTF 👉 Presented at Black Hat Arsenal
DEF CON 34 & Black Hat USA 2026 — what a week in Vegas! 🔥 🥇 1st Place - DEF CON Cryptocurrency Village Web3 CTF 🎤 Speaker - Black Hat USA Arsenal Had an amazing time hacking, learning, and sharing. Great to meet so many new friends along the way! See you next time! 🫡 #DEFCON34 #BlackHatUSA #Web3 #CTF #CyberSecurity
6
926
DeFiHackLabs retweeted
🚨>900 incidents and >$8B in DeFi exploits, most with analyses & reproducible Proof of Concepts Foundry tests Awesome resource, a ton of alpha for web3 security researchers & developers - THANK YOU @1nf0s3cpt 🫡 defihacklabs.io/explorer/ind…
3
22
188
53,261
DeFiHackLabs retweeted
🔥From Black Hat Asia 2017 as a Speaker to Black Hat USA 2026 at Arsenal. Nine years later, still building, still breaking, still learning. #BlackHatUSA #Arsenal #AISecurity #Web3Security
2
3
19
1,001
DeFiHackLabs retweeted
🔥I’ll be presenting at Black Hat USA 2026, then joining DEF CON 34 at the AI Village and Cryptocurrency Village. Want an exclusive DeFiHackLabs T-shirt? DM me. limited quantities available. See you in Las Vegas—let’s connect in person!
2
4
18
1,194
DeFiHackLabs retweeted
🚀 Introducing 10x Daily. Every day we scan dozens of tech videos and security feeds, then distill them into the 10 stories that actually matter. 🤖 AI 🛠️ Dev Tools ⛓️ Web3 🔐 Cybersecurity 🎥 New episodes daily Mandarin English On your commute. Over coffee. Or between meetings. Just 5 minutes to stay ahead. Subscribe and ring the bell. 🔔 #AI #CyberSecurity #Web3 #TechNews
2
3
10
1,093
DeFiHackLabs retweeted
🔥Reviewed 120K red-team messages and kept seeing the same 10 LLM security questions: 🧵👇 I’ll also be releasing the LLM Red Team Field Guide soon—a practical guide to red teaming LLMs, agents, and RAG systems.
Made with AI
2
1
24
1,623
DeFiHackLabs retweeted
🚨 The Verus–Ethereum Bridge has been exploited again. Same contract. Same vulnerability. Same attack method. • May 17: ~$11.6M stolen • July 23: ~$7.5M stolen The same root cause remained exploitable for 66 days, bringing the combined loss to approximately $19.1M. How did the attack work? The attacker submitted a maliciously crafted Verus-side import containing an unbacked payout request. The bridge successfully verified the notary-signed state root, Merkle proof, and transaction hashes—but failed to confirm that the amount requested on Ethereum matched the amount actually exported or locked on Verus. In other words, the cryptography worked, but it authenticated the wrong thing: It proved that the import had been notarized—not that the payout was fully backed. Once the crafted import passed verification, the bridge treated it as legitimate and released assets from its own reserves, including ETH, tBTC, MKR, USDC, USDT, EURC, and scrvUSD. The DAI path went even further: the bridge accessed its MakerDAO collateral position and minted approximately 220,357 DAI to satisfy the fraudulent payout. The attack flow was: Malicious Verus import → Valid notary and proof verification → Missing source-amount validation → Unbacked Ethereum payout → Bridge reserves drained Victim contract: 0x71518580f36feceffe0721f06ba4703218cd7f63 Attacker: 0xbda71b58cec0b1c20a8f87ccd52fa0679747855c Payout recipient: 0xcfd0a20703cd11e0b9f665e1c3f1ef989c142d54 TX: 0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099
8
16
82
6,135
DeFiHackLabs retweeted
🚨 Technical Forensic Analysis — $24.15M USDC Bridge Theft on Arbitrum This incident was not caused by a smart contract logic bug. On-chain and cryptographic evidence points to a compromise of the hot-validator signing path. Asset: Native USDC Token: 0xaf88d065e77c8cc2239327c5edb3a432268e5831 Amount: 24,150,000 USDC Date: July 22, 2026 1️⃣ Withdrawal proposal At 21:26:55 UTC, the attacker submitted a malicious withdrawal through: batchedCreateWithdrawals Selector: 0x6cc76ee8 Transaction: 0x217c45c1272550e0439e53243f2987b7fb3f58b1d33c222597bbb71851b93f74 The transaction contained five validator signatures and the complete seven-validator set, whose voting power totaled 10,000. Withdrawal parameters included: user/destination: 0x2f2974fabc54dba33442261211c06bd20e0feefc usd: 24,150,000 nonce: 0xa5fb88f9 The attacker wallet is an EIP-7702 delegated EOA—not a plain EOA. Delegate/sweeper: 0x63c0c19a282a1b52b07dd5a65b58948a07dae32b The proposal was relayed by a one-off address outside the normal relayer rotation: 0x32e3200d6e944cd9bd1c8c9865293b07206e7a01 2️⃣ Validator signatures The five recovered signers were registered hot validators: • 0x00bb84af06dac03bfe744da13df9d2d6fd8e77e5 — 1,428 • 0x27259f90d6ae500262ace6e8428434e0c1f308f5 — 1,429 • 0x2e26de22a92e41704b3ea00cc65a6cda47b12c9e — 1,428 • 0x52d4d9ad78a53a69bd089ee8f282ce0cd0506da7 — 1,428 • 0xbb472bc3962ad02ac660429fdbb319b5bc66da7b — 1,429 Total signing power: 7,142 / 10,000 Required quorum: 2/3 = 6,667 Therefore, the malicious withdrawal carried enough valid signing power to pass the contract’s verification. 3️⃣ EIP-712 cryptographic verification I reconstructed the signing message using the verified contract’s own scheme: message = keccak256( abi.encode( AGENT_TYPEHASH, keccak256("a"), keccak256( abi.encode( bridge, keccak256( abi.encode( "createWithdrawal", user, destination, usd, nonce ) ) ) ) ) ) The final EIP-712 digest was calculated as: digest = keccak256( 0x1901 || domainSeparator || message ) Domain: name: "Exchange" version: "1" chainId: 42161 verifyingContract: 0x0100000000000000000000000000000000000001 Recomputed message: 0x558a989f405d706935fa15efee8eac6e32fbba7ea3f70dfd930c66436e7ed8c2 This exactly matches the message ID used in the on-chain finalize transaction. Signing digest: 0x417d4213ff618235c568f6932e8d389ca663d004c947ebe64de8f144ff957faa Recovering the five ECDSA signatures from this digest produced the five registered hot-validator addresses above, cryptographically confirming their combined 7,142 voting power. 4️⃣ Withdrawal finalization At 21:30:25 UTC, the withdrawal was finalized through: batchedFinalizeWithdrawals(bytes32[]) Selector: 0xc5bdf3ca Transaction: 0x50d0b3ec6c3f5fce0f10abf81540bbb508f421494aa2b3480c4a264b0436547b The finalize call contained only the 32-byte message ID—no validator signatures. The signatures were included in the earlier proposal transaction. The gap between proposal and finalization was 210 seconds, approximately matching the contract’s 200-second dispute window. The contract correctly validated the signatures, observed the dispute period, and released the funds exactly as designed. The validator signing path—not the contract logic—was the failure point.
2
13
1,476
DeFiHackLabs retweeted
DeFiHackLabs funding update 🛡️ We raised $2,918.27 in donations + 11.0526 ETH in matching through Ethereum Security QF. Funds support open tools/data, AI security research & rewards for builders, submissions and hackathons. Thanks @TheDAOfund, @Giveth, @wintermute_t & every donor! We’re putting the support to work. Our open resources now include: • 734 root-cause cases (from 611) • 822 incidents (from 622) • 827 reproducible PoCs (from 715) • A daily Web2 & Web3 security digest nitter.net/1nf0s3cpt/status/20714… The funds will help us keep these public goods accurate, accessible, and useful: maintaining datasets, improving the Incident Explorer, adding reproducible exploit PoCs, and covering the infrastructure needed to keep them open to the community. We’ll also support builders and white hats applying AI to Web3 security—including AI credits for projects that create practical security public goods. nitter.net/1nf0s3cpt/status/20603… One result we’re proud to share: Black Hat USA 2026—and it was accepted into Arsenal. We’ll present it in Las Vegas this August. blackhat.com/us-26/arsenal/s… We’ll dedicate funding to community incentives, including rewards for open-source development, technical research and write-ups, security hackathon participation, and submissions to international conferences. We’ll keep publishing progress and outcomes. Thank you for helping us make Ethereum safer. 🛡️
Got an idea for Web3 security but need AI credits? 🔥DeFiHackLabs AI Credits Initiative is now open. We’re supporting builders and white hats using AI to create security public goods. Apply 👇
6
6
36
3,109
DeFiHackLabs retweeted
🏆 We did it — 1st place in the OneSavie Bastet Kaggle Competition. The challenge focused on using LLMs to detect and classify smart contract vulnerabilities. Over the three-month competition, I ran tens of thousands of scans, encountered countless pitfalls and failed approaches, and continuously refined the prompts, workflow, and auditing harness. This result validates the AI-powered security workflow we’ve been building and demonstrates the potential of LLMs to improve vulnerability detection while significantly reducing missed findings. Huge thanks to the OneSavie Bastet team at @onesavielab for organizing the competition, and to everyone who participated! As a competition participant, I’ll also be sharing more about my LLM smart contract auditing harness at Black Hat USA Arsenal this August. #Kaggle #Web3Security #SmartContractSecurity #LLM #AI #BlackHat
6
4
45
1,628