Push Chain has successfully completed its security audit with @hackenclub.
By the numbers:
- Zero critical-severity findings were identified
- 300 hours of audit work
- 3 smart contracts and full chain audit completed
- $100,000 bug bounty launching soon
๐ญ ๐ ๐ถ๐ป๐๐๐ฒ ๐๐ถ๐๐ต ๐ฃ๐๐๐ต โก โ ๐ช๐ฒ๐ฒ๐ธ ๐ฐ๐ด
Heads-down build week. Here's where things stand ๐
๐ง ๐ฅ๐ฒ๐ฎ๐ฑ-๐๐๐ฎ๐๐ฒ ๐ฆ๐๐
We're wrapping up the SDK that lets apps read state directly.
โ ๐๐ฅ๐-๐ด๐ญ๐ด๐ฏ
The first implementation is done, with hooks.
- Every Job ID is now tied to a Mandate ID
- One AGW, one job, enforced right in the hook
Next up: letting existing mandates be modified.
๐ฌ ๐ฅ&๐: ๐๐ด๐ฒ๐ป๐ ๐๐ผ๐ฏ ๐๐ฟ๐ฐ๐ต๐ถ๐๐ฒ๐ฐ๐๐๐ฟ๐ฒ
Two design proposals are being explored side by side. We're also building more hooks for different job types.
โญ๏ธ ๐๐๐ช ๐ฆ๐๐
Kicks off this weekend or early next week.
๐ช๐ฒ๐ฒ๐ธ๐ฒ๐ป๐ฑ ๐ฉ๐ถ๐ฏ๐ฒ๐ ๐ฉ โ agents don't take weekends off, but the humans are trying.
๐ฃ๐๐๐ต ๐ฃ๐๐น๐๐ฒ ๐ซ โ ๐ฃ๐๐น๐๐ฒ ๐ฐ๐ณ
Read State is live in the Docs Playground โก
One batch. Three reads:
โ Ethereum price feed
โ Solana token balance
โ Public API
Hit run โถ๏ธย push.org/docs/chain/build/reโฆ
if you want to protect your onchain agents from getting hacked.
follow this secure runtime stack and study the 5 most destructive types of agent hacks shared below.
Our latest research paper explores the growing connection between AI and digital assets and explains why broad AI adoption may drive new demand, utility and applications across the digital asset economy. blackrock.com/us/individual/โฆ
Disturbing findings about AI agents you cannot ignore:
1. Out of 700, 87% of big scale orgs reported more than one security incidents with their deployed agents.
2. Google saw a 32% increase in malicious indirect prompt-injection detections btwn novโ25 - febโ26
3. 82% of Enterprises Have Unknown AI Agents in Their Environments
4. 3,250 attack scenarios across seven models with a 73.5% success rate
๐ญ ๐ ๐ถ๐ป๐๐๐ฒ ๐๐ถ๐๐ต ๐ฃ๐๐๐ต โก โ ๐ช๐ฒ๐ฒ๐ธ ๐ฐ๐ณ
๐ ๐ฅ๐ฒ๐ฎ๐ฑ ๐ฆ๐๐ฎ๐๐ฒ
Live on testnet. A contract on Push Chain can now read state from a contract on any supported chain.
๐งฉ ๐ช๐ฎ๐น๐น๐ฒ๐ & ๐ฆ๐ฒ๐๐๐น๐ฒ๐บ๐ฒ๐ป๐
- Wallet v1 architecture is finalized.
- SDK work has started on the feature set that talks to it.
๐ ๐๐๐ฑ๐ถ๐
Bug bounty is complete and closed.
๐งฑ ๐ก๐ฒ๐ ๐
Preliminary architecture for 8183 is finalized.
๐ช๐ฒ๐ฒ๐ธ๐ฒ๐ป๐ฑ ๐ฉ๐ถ๐ฏ๐ฒ๐ ๐ฉ: reading state, not the room.
TL;DR:
1. Give every agent its own identity, wallet, and audit trail.
2. Treat every website, API, and agent message as hostile input.
3. Lock memory writes with source, trust level, and expiry.
4. Always assume the agent will fail at some point so place effective measures to contain the blast radius.
Read rest of the tips here:
Disturbing findings about AI agents you cannot ignore:
1. Out of 700, 87% of big scale orgs reported more than one security incidents with their deployed agents.
2. Google saw a 32% increase in malicious indirect prompt-injection detections btwn novโ25 - febโ26
3. 82% of Enterprises Have Unknown AI Agents in Their Environments
4. 3,250 attack scenarios across seven models with a 73.5% success rate
๐ญ ๐ ๐ถ๐ป๐๐๐ฒ ๐๐ถ๐๐ต ๐ฃ๐๐๐ต โก โ ๐ช๐ฒ๐ฒ๐ธ ๐ฐ๐ฒ
๐ ๐๐๐ฑ๐ถ๐
- All reported issues are fixed. Final reports are in and we're verifying them now.
- Audited deployments go out next week.
๐งฉ ๐ช๐ฎ๐น๐น๐ฒ๐ & ๐ฆ๐ฒ๐๐๐น๐ฒ๐บ๐ฒ๐ป๐
- New wallet contracts and flow are live on testnet.
- Next: finalizing contract parameters, then evaluation and hook design. This is the logic that decides when a payment gets released.
- Marketplace research is done and in review.
๐ ๐ฅ๐ฒ๐ฎ๐ฑ ๐ฆ๐๐ฎ๐๐ฒ
SDK v1 changes are ready and going into review.
๐ช๐ฒ๐ฒ๐ธ๐ฒ๐ป๐ฑ ๐ฉ๐ถ๐ฏ๐ฒ๐ ๐ฉ โ rate limited until Monday.
Here's a slightly different outlook on answering "which chain will have the highest agentic activityโ
What if we stop measuring them using a single scalar metric (eg: txns performed, value locked ) and measure them based on multiple vectors that account for their execution intensities as well.
the current landscape looks somewhat like this: