Agentic security for decentralized infrastructure: detecting what traditional scanners miss.

Planet Earth
NullRabbitLabs retweeted
We're publishing our most detailed threat intelligence report to date. It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them. We disrupted every operation in the report, and used the lessons from them to strengthen our safeguards. Where appropriate, we also shared what we found with authorities and other AI companies. These cases are not typical: we’re highlighting some of the most sophisticated misuse we’ve seen. But they’re especially important to discuss, because they show us where AI misuse is headed, where our safeguards work, and where they need to improve. We’re publishing this report so others can spot the same activity on their own platforms, and so we can give the public a clearer view of how emerging threats develop. Read the report: anthropic.com/threat-intelli…
3,234
11,714
50,540
43,661,890
NullRabbitLabs retweeted
1/ 12 August 2026. Malformed route leaves @Teraswitch Miami, hits Amsterdam reflector, poisons EU/APAC paths. 27 validators drop consensus in one minute. 50.9M #SOL stops voting. ~$3.9B. #Solana kept producing. No slash. Operators just bled rewards and vote credits. We measured it.
1
2
1
106
Interested to see what’s about to pan out with solana
Eleven Solana validators have dropped offline in the last fifteen minutes. A correlated failure is now unfolding. #slashr #Solana
26
NullRabbitLabs retweeted
1/ Your validator got hit with a network DoS and your host security tooling didn't fire. Not a tuning problem. A technique-by-technique analysis of why syscall-layer tooling structurally cannot see this class of attack.
1
1
2
29
NullRabbitLabs retweeted
1/ CometBFT completes the full SecretConnection handshake, X25519 key exchange + Ed25519 verify, for any inbound peer before it checks the peer's node-ID against the allowlist. No valid key needed to make the node pay.
1
1
2
27
1/ NRDAX is now fully machine-native. The canonical registry for decentralized infrastructure attacks reads as cleanly for agents as it does for humans. 621 techniques across 64 chains, every mechanism, instance, family, and coverage mapping, available as structured data at stable URLs. Built for the agentic systems that are increasingly doing the reading.
1
1
17
2/ New today: → knowledge-pack.jsonld: the entire registry (Dataset + families + every technique) in one self-contained JSON-LD @graph. One fetch. No crawling. The complete source of truth. → feed.xml: Atom feed with newest techniques first. Subscribe and stay current.
1
16
3/ Already live: STIX 2.1 bundle, llms.txt for answer engines, per-technique JSON endpoints, coverage matrix, and permanent NRDAX-Tnnnn IDs (with DOIs, BibTeX, CSL-JSON citations). This is the package agents should default to. Full machine directory: nrdax.com/machines
10
NullRabbitLabs retweeted
NRDAX now maps 368 techniques across 21 chains for decentralized infrastructure. 140 reproduced. 228 known from public CVEs/advisories but not yet reproduced. Look up any CVE → land on its technique. nrdax.com
1
1
38
NullRabbitLabs retweeted
NRDAX is live. The canonical technique registry for decentralized infrastructure attacks. nrdax.com
1
1
1
15
NullRabbitLabs retweeted
🚨 JUST IN: @TransitFinance appears to have been hacked for ~$1.88M. Stolen funds are sitting in DAI on Ethereum, with reports saying they originated from Tron. Root cause is still unclear. Transit sent an on-chain message offering a bounty if funds are returned within 48h.
7
8
77
6,073
NullRabbitLabs retweeted
I run a lot of attacks on my home located validators..... This is one of the funniest messages I've seen from Claude. Yes please, you ease off, because that's exactly what an attacker would do.
1
2
35
Validator infrastructure attacks have no MITRE. No taxonomy. No shared training data. Until today. We've just published the first piece on Hugging Face today: 31 bundles, 7 vulnerability families, #Sui and #Solana. Open format, CC-BY-4.0. huggingface.co/datasets/Null…
1
53
Not everyone does responsible disclosures because they want to profit from the bug bounty. Some of us do them because we actually care about the decentralised world. So many disclosures are dismissed these days for this reason. We need a new way to do this.
2
90
Existing crypto security work is overwhelmingly focused inside the perimeter. Smart contracts, on-chain logic, protocol-layer audits. The validator daemon's network surface and RPC architecture are systematically under-examined. NR-2026-001 is what that gap looks like in practice: github.com/NullRabbitLabs/nu…
1
4
52
This was found on #Solana #Agave btw, more inbound for other networks, including #Sui It's frustratingly slow getting people to ack these as issues.
31
Submitted three Agave RPC findings to Anza last week. Closed as out of scope under "RPC DoS" carve-outs. Two of them aren't rate-limit DoS. They're architectural. Operator advisory + reproducers: github.com/NullRabbitLabs/nu… #Solana #Agave
1
78
Introducing Substrate: An Open Format for Validator Threat Intelligence.
1/ Threat intelligence sharing for blockchain validator infrastructure is broken in a specific, boring way:there's no standard format for capturing what an attack against a validator actually looks like. So we built one. 🧵 Look mum, I did something!
1
21
NullRabbitLabs retweeted
Your validator raised their commission from 5% to 10% last week. Did they tell you? I'll bet you a pint of milk they didn't. We now track every commission increase across Solana, in real time. 🧵
1
1
1
22