Industry leading OpSec audits, security tools, and code reviews performed by true security wizards

Great things are coming 😈
You want me to use AI to alert you when a process on any of your dev devices suspiciously tries to open a MetaMask wallet? 🦊 No right? Because that would mean my AI agents, systems, and employees can see all that your employee is doing But how powerful would that be? SOLVED: Using zero-knowledge proofs, endpoint agent (prover) can only prove to the control server (verifier) that a statement is true (e.g. a process tried to access web extension id `nkbihfb.*` (metamask)). Moreover, having the entire code open-source, self-deployable on your own AWS/GCP/Hetzner gives only you the control over what happens (e.g. investigate, block, run IR playbooks). Orgs don't want to build this, because this kills EDR companies' profits - we want to give it away for free. Thanks to @thedaofund, we can make our PoC generally accessible. If you want this for yourself, free forever, we only need web3 to step in, even with the smallest of donations, to turn this into reality. Here is the initiative paper: initiatives.thedao.fund/init…
5
620
Opus 5.5 is apparently great at website facelifts! auditware.io
5
839
We’ve officially extended the Cloud Security Grant registration window! A small team can build something the rest of us depend on well before it has the budget for all the security work that comes with it. We think helping those teams is a good use of our time, so we’re covering cloud security reviews for selected teams and working with them on the fixes. Apply below, or send this to a team you’d like to see take part: auditware.io/cloud-security-…
2
8
610
Jev is the clearest sign yet that target selection is getting cheap. An attacker used to pick one protocol and stare at it for a week, while now a model triages thousands of contracts overnight and hands back the ten that look soft. Which means every human hour goes straight into exploitation, and that was always the expensive part. Our take is that protocol teams should be running the exact same loop on their own code before someone else does. The tooling is public and the cost is near zero, so the real question is who points it at your repo first. We built Sentry partly for this reason and it is free and open right now at sentry.auditware.io, so if you have not run your codebase and infra through it yet that is a decent first step. Where is Jev already pulling real weight in your security process? 🤔
Jev is now available to everyone. No waitlist. Start using it here: console.typesafe.ai
10
794
Auditware retweeted
For researchers that want to know how this is done without going on AI-heavy details: ( affordable DIY at the bottom ) They took a model, and compressed it to be able to run on a single 4-GPU (still expensive for non-enterprise, so not for solo use - think $80/hour or $180,000 purchase). Their process / methodology: - Pick a model with the expert architecture - Choose a calibration dataset that matches the intended use ( So audited codebases v.s. reports etc) - Run the calibration data through the unmodified model and record two numbers per expert per token - Compute a single score per expert - Delete the lowest-scoring experts in each layer The expert's weights are dropped from the model file, and the router's output columns for those experts are removed so it can only choose among survivors. The router then renormalizes its weights over the remaining experts as it normally would. This is EXPENSIVE. BUT it's no different than the token game you play v.s. large scale security companies either way so no reason to give up. You can do the exact same process for a smaller model and have something you can run on your mac or a hetzner node. 🙂‍↔️🙂‍↔️ Affordable DIY plan: 1. Start from the unpruned GLM-4.7-Flash 2. Collect a few hundred to a thousand traces from your own audits 3. Run the Cerebras REAP repo over them on a rented A100 for an hour or two. Under $10 of compute. 4. Prune 25%~50%, quantize to GGUF, load in LM Studio or whatever. 5. Run locally on your mac
Introducing Altar-1, our first open-weight security model. Frontier-grade defensive AI, built to deploy. Own your own security.
3
5
109
10,822
Starting to see PRs from paid contributor work made possible by @Giveth and @thedaofund earlier this year. github.com/W3OSC/web3-opsec-… We brought in external experts to widen the W3OS guides to cover enterprise AI risks from misconfiguring Bedrock, LangChain, Langfuse and more. All guides are distributed FREE to teams through the most intuitive UI you could ask for, with AI integration for automatically testing your own infra and much more at sentry.auditware.io 👀 45 different people contributed $9,929, and it’s our job to put it to good use!
8
423
S&P Global has agreed to acquire OpenZeppelin, with plans to expand onchain security assessments through its Ratings business! This means a lot for the space and is a huge inspiration to us all. In our view, a Web3 protocol’s risk rating may come down more to the organization behind the contract than the onchain code, since compromised signers, deployment pipelines and admin accounts can put funds at risk. With the code layer getting this kind of attention, we want to see the same for the OpSec of the organization behind it, If you audit or invest in protocols, take a look at its RFP for shared OpSec ratings: initiatives.thedao.fund/init…
Today we are announcing that S&P Global has entered an agreement to acquire OpenZeppelin. Onchain finance is growing from an emerging market into core financial infrastructure, and the standards and rails our team and community built are becoming the rails of global finance. OpenZeppelin smart contracts facilitated over $37 trillion in value transferred, with the vast majority of the largest DeFi protocols, blockchain networks, stablecoins and tokenized funds relying on them. With S&P Global, we expect to accelerate the impact of onchain finance, backed by more than a century of trust in global markets, benchmarks, and risk frameworks. To our clients and to all the users of OpenZeppelin open source tools: • OpenZeppelin Contracts and all our open source applications and tools remain open source, free, and publicly maintained on GitHub. Building open source standards stays a core priority. • Audits, engineering work, and ecosystem programs continue with the same team, brand, quality, and customer experience, with what will be the added benefit of S&P Global's research capacity, market data, and institutional reach. For the last decade, OpenZeppelin has set the security standard for onchain finance. Today begins a new chapter for that mission, together with one of the most trusted names in global markets. Read the full announcement: openzeppelin.com/news/spglob…
1
5
740
Auditware retweeted
🚨🚨 Privacy-preserving EDR funding is LIVE Repost this if you want to see us build: - Free, self-hosted (BYOC) EDR solution - Completely open source - Detections specific for web3 (not even the biggies get this part right for $100 per endpoint per month) - Privacy-first, meaning your admin can see alert details but not your browsing history The last part is huge. Although lots of organizations normalize spying on employees - small teams, and teams working with vendors, should also sleep well having their data protected without compromising employee privacy. We already pioneered so much around this problem space for web3 and just eager to see the community support us to build this. Thank you @thedaofund for this major opportunity 🤍 Help us spread the word! 🔁 🟰 🪄 initiatives.thedao.fund/init…
2
4
13
1,445
We had a hand in a couple of these! Glad it's finally out, go take a look and shoutout to @thedaofund as always 💜
Onchain security is everyone’s problem and nobody’s job. ETHSecurity Initiatives is how we are changing that. Propose the work. Fund the work. Build the work. initiatives.thedao.fund/
5
492
Web3 rejected EDR and the reasoning held up: people holding signing keys were not going to install a vendor's kernel agent that streams their laptop to a cloud they do not control. So the machine that approves the transactions is the one with nothing watching it. That trade made sense while the alternative was handing a third party root on the box, and it stops making sense the moment an agent exists you can read, host yourself and point at your own storage, one that reports the match and keeps the telemetry. Teams are picking a blind spot over a backdoor because those are the two options on the table! We think that choice looks very old, very soon 🤔
8
562
There's now a certification for the parts of a protocol's security that aren't code related, and it's about time! SEAL's program covers six areas, incident response, multisig operations, treasury, identity and account access, DNS and registrar, and the passes land on chain as attestations, so a protocol can check a firm's standing without asking the firm. That's the first time the operational side gets the same kind of public stamp a code audit has had for years. We do OpSec audits and compromise monitoring for a living, so we put ourselves up for accreditation, one of 15 firms going through it now. If you're a protocol wondering what's beyond the code audit, this is one of the best resources for you to follow 🫡 securityalliance.org/our-wor…
15 firms are undergoing accreditation with SEAL Certifications and taking on audit engagements right now — smart contracts, incident response, treasury security, multisig ops, and more! If your protocol hasn't scoped an audit yet, reach out directly to a Certification Partner today: securityalliance.org/our-wor… @AdevarLabs @audit_wizard @BlockSecTeam @chain_security @Composable_Sec @ConsensysAudits @DefiSafety @hackenclub @HackenProof @SecurityOak @opsek_io @sigp_io @Wonderland @zellic_io @zeroshadow_io
1
8
902
Intruder read 3,000 orgs and 83% of the AWS accounts had a policy that lets someone climb to admin, and that number is roughly why the cloud grant exists. The pattern behind it is boring on purpose, permissions that each made sense the day they were granted, by people who weren't looking at the whole account at once, and it takes an outside read end to end to see where they add up. That's the read we do under the grant! If you run production on AWS with user funds in it and the whole account has only ever been read by the people who built it, you should apply ASAP or if that 83% made you think of a team, send them this 🫡 auditware.io/cloud-security-…
⚠️ 76% of AWS accounts analyzed had exposed services. Google Cloud: 8%. Intruder analyzed 3,000 organizations. In its AWS sample, 83% of accounts had IAM policies allowing privilege escalation. See the most common configuration gaps by provider: thehackernews.com/2026/09/yo…
7
976
Six months back our CTO @forefy gave a talk on radar at @EthereumDenver and the problem it opened on has only gotten worse 🚨 Your dev vibe audits with AI. The firm you hire might be running AI on the same code. And AI review hands back a different answer every run, so you can't trust it or build on it. Radar is the deterministic layer. AI writes a template once, you review it, and it catches that bug class the same way every time, contract after contract. That was our bet and since then: • An agent exploited 72% of smart contract vulns in EVMbench (OpenAI/Paradigm) • Researchers logged $4.6M in exploits written by AI on live contracts • Solana hit record volume Radar's open source and runs on templates. The talk aimed for thousands of community rules, we were at 30 then and 130 now! Write a rule for a Solana pattern you know and it flags any contract that shares it. That's how you hunt a bug class at scale 🔍 Full Talk: piped.video/watch?v=utpOmr9M… github.com/Auditware/radar
3
2
6
1,083
We ran Delve through a security check and it pulled an F on headers (yes, that Delve) 🫣 Missing security headers barely matter on a blog. On a dapp they decide whether an injected script can quietly rewrite the transaction in your wallet while the page still shows the domain you trust. A strict Content Security Policy is the control that makes that hard, and it's the first thing teams skip because nothing visibly breaks without it. Sentry grades any domain's headers and DNS from the login page in seconds, no account needed. Check yours: sentry.auditware.io
3
777
W3OS has added a whole domain for AI agent OpSec, and two of its requirements will annoy people. Allow listing domains does not satisfy session isolation. The untrusted content lives on the domains you already allowed, your agent reads GitHub issues and web pages and both are attacker controllable. And repository write access counts as production access anywhere pipelines run with prod credentials. An agent that can push a workflow file can reach prod. The standard is open 👇 github.com/W3OSC/web3-opsec-… If you're interested in where OpSec stands right now and where it's heading our CEO @joe_vanloon sat down with other OpSec leaders on @thedaofund's Space last week!
Less than 4 hours until go time. Today we’re talking OpSec with people who work directly on Ethereum security. Joining us: @isaacpatka from @_SEAL_Org Roman from @Quantstamp @dobsec @hudsonjameson and @arda_certik from @CertiK @joe_vanloon from @audit_wizard @officer_secret and more.. We’ll talk about where teams are still exposed, why good recommendations don’t always get followed, and how Ethereum can get more serious about operational security. Join us ↓ nitter.net/i/spaces/1qxvveebjzlxB…
1
6
1,193
Excluding vercel-hosted, upgrade your Next.js to 16.3.3, and ASAP.
🚨🚨Next.js 16.3.0 vulnerable to a yet unpatched remote code exec but here's the more interesting part 👇 Agentic attacks are all about token allocations. even if the vuln technical details remain unreleased, just knowing the vulnerable version already set attackers to focus all their tokens in motion, evidently they will reverse engineer to refind it soon enough (maybe even before the disclosure is fully triaged) This is insane. Stay ahead of agents.
5
1,193
This is what happens when you point an AI agent at a K8 Labs challenge (we built the labs to let it in on purpose) 🤖 In short: ✅ the agent gets real access on a temporary, scoped key ✅ it maps the box, reads the primitives, walks itself toward the answer ✅ the API hands out hints, not answers 🔒 that key CANNOT submit the flag 🔒 the model can reach the answer, it physically cannot finish for you You can learn with AI here. You just can't use it to take the shortcuts that hurt your progress. k8.auditware.io
1
8
3,049
THIS is the how. A read-only account you grant us, the whole cloud poured into a graph we can query. Hundreds of queries tuned over the years, straight to where the concerns hide, coverage first. A few teams get us in there, granted on merit. Apply 👉 auditware.io/cloud-security-…
I've been asked how are we possibly able to provide this type of service effectively under one week and here's my answer: 1. From my experience the most efficient way to assess your cloud security is via misconfiguration review. 1b. this means using a read-only global reader account (granted by the client) that be used to query the whole cloud-provider-provided API to turn the entire cloud posture to a structured graph database. 2. Mapping an entire cloud is hard to get right, especially on the asset aggregation and threat model part, but after you've done hundreds of cloud audits it gets better and better. 3. today we're able to pour an entire cloud posture to a local graph database and have hundreds of premade queries which we optimized over the years, that will lead me (quicker than most) to where the security concerns hide, and I'm able to do it with a coverage-first approach. Not to talk about how AI performs well under these setup efforts ! I KNOW PEOPLE. this is too good to be true, dare you to apply and see the results speak for themselves.
6
807
Shoutout to security researcher Rotem Kama 🔎 linkedin.com/in/rotem-kama-0… Rotem caught a K8 Labs lab handing out a world-readable cluster-admin key - an unintended shortcut past the exercise! Didn't cross the bounty line (the Firecracker wall held, no host escape), but sharp eyes and a clean writeup ! Jump on this ship before it leaves the dock! the bug is still up for grabs !!
Auditware's Bug Bounty Program is LIVE. We break other people's systems for a living, so for our first bug bounty program we're not hiding behind privilege. Every hunter gets root in the labs over at k8.auditware.io by design, but we want to see if you can break out entirely to our outer infra. The ~$1,000 pot (in ETH) sits behind the one wall we're most sure holds: escape your lab session's microVM. The program is officially published in this post - which means that if you're seeing this, you're not contesting against the full bug bounty world, but only against our followers and X reach. This doesn't mean it will be easy though, as four layers of defense-in-depth are between you and the money: 1. Own the k3s API inside the runner (part of the labs) 2. Break from Container → guest kernel 3. Break from Guest kernel → ? 4. Reach the outer AX41 host Rules are simple - read the full brief below. Safe harbor if you play in good faith. Submit via DM to our founders @joe_vanloon and @forefy (telegram forefy_t) --- Ensure to register as an active bug bounty hunter by replying something to this post -- Who's taking this box apart ⁉️ k8.auditware.io
4
312