Find all bugs. Make no mistakes. AI security for the future of finance on Solana.

hackhack retweeted
AI audits will be more common as the machine doesn't have the limited time and focus humans have. Its like an intern that can spot, chain and reproduce known patterns ran in a infinite simulation @hackhackai is doing awesome stuff. make no mistakes
1
1
5
366
WE HAVE MANY AUDITSU AND THE ARE COMPLETE
Made with AI
8
4
40
3,198
hackhack retweeted
AI audits is an incredible tool all protocols should embrace. Thank you for the amazing work @hackhackai!
1
7
259
Kormos has been an early customer for @hackhackai and we're really proud that we could deliver such value to them. We've found that our AI tool can be really strong for large codebases like this where 30k lines of code simply overwhelm a human auditor and would require weeks of deep work to start surfacing issues. While we don't claim that our AI tool is better than a human auditor with weeks or months of time to real all this code and find all the bugs, the big advantage is that we can start delivering real bugs within hours. This means that the team can go to start fixing issues within days instead of weeks or months, and while a human auditor is still reading v1 of the code, we can do another AI run on v2, v3 and v4, making the codebase better step by step!
1
2
17
657
A few weeks ago, our autoresearch agent flagged an issue in SIMD-0376, a @Solana proposal that had been approved and was being implemented, but wasn’t active on mainnet yet. The SIMD changes how validators verify Ed25519 transaction signatures. The goal is good: adopt the ZIP-215 rules used by Zcash’s ed25519-zebra verifier, making it possible to batch signature checks and verify transactions faster. Our agent found a dangerous edge case. Under the proposed rules, a 64-byte all-zero signature would be accepted for any message when paired with the all-zero public key. On Solana, the all-zero key has special meaning. It is displayed as 11111111111111111111111111111111, the System Program ID, and is also commonly used as a sentinel value for “no authority,” “immutable,” or “uninitialized.” Programs often therefore set an authority to zero with the assumption that nobody can ever sign for it. If SIMD-0376 had been activated unchanged, that assumption would no longer hold. Metaplex gave us a concrete example. We found 433 mutable metadata accounts whose update authority was set to the zero key. The proposed verifier could have made those disabled authorities signable again. We reported the issue to Anza before activation. A fix has been prepared, and the SIMD is being amended to reject these weak keys while keeping the performance benefits. Full writeup: hackhack.ai/autoresearch/sim…
16
10
76
69,707
found this old image of @hackhackai hunting bugs back in the day, before AI
1
24
774
ghackhack
3
2
16
540
hackhack retweeted
hackhack.ai @hackhackai has outbid @Tokenshit_ replacing them on the blanket to save my boy. Hackhack autonomously reviews Solana programs, reproduces exploitable vulnerabilities, and returns verified findings in hours. Built for Anchor, native Rust, and Pinocchio.
Replying to @defido
we got another spot. this is for a good cause
1
1
13
1,846
please get better soon
Hi everyone, I have some very heavy news. My boy Austin has fallen ill, as you know Austin suffered from half stake. Suddenly he collapsed at school when working on his server. They're currently taking care of my boy at a hospital in down town NYC. We are desperately trying to raise funds for his recovery. Any help is appreciated: sponsor.anzatok.com #saveaustin #gofundme
2
1
14
544
they said it was audited
Made with AI
2
12
616
dear solana programs you better hide your bugs we're coming for you
Made with AI
8
1
19
630
a message to the bugs
Made with AI
8
4
19
882
hackhack introduces a new severity level: supercritical. this is a special severity tier that says one thing: If someone bad finds this, your protocol goes bust. it sits a step above critical: there are lots of critical bugs that a protocol can survive. Limited loss of funds, or loss of funds issues sitting behind special requirements or where a drain may be a second order effect. A supercritical issue is more simple: ignore it and say goodbye to your project We've already found multiple supercritical issues in live Solana projects fully automatically with hackhack
2
25
2,519
hackhack retweeted
Latest version of @hackhackai is scary good
3
1
14
1,585
It's fixed and works on phones now! check it out: hackhack.ai
I found 1 bug in bug hunt. And its that on mobile i cant aim properly without shooting. Pls fix!! hackhack.ai/bug-hunt/?score=…
9
699
hackhack retweeted
Implemented a new element for our website! try it out on hackhack.ai I heard the best engineers can get >100 score, not sure if this is true
I found 8 bugs in @hackhackai's bug hunt. Find all bugs. Make no mistakes. Can you beat my score? hackhack.ai/bug-hunt/?score=…
3
2
18
1,357
hackhack retweeted
Ireland is one of the dopest countries I’ve been to. With trillions of dollars of ETFs and other funds domiciled there and an ambitious government, I suspect it will play a large role in the future of crypto. Superteam Ireland is one of our largest communities, and @A_gutierro put together something really special at Slane Castle this year and I hope they run it back again soon. Was a pleasure to meet some of the teams on Solana: @Styx_PQ @realPumpApi @MentionedMarket @infesteddotfun @craftsdev @finagotchi @slasheddotwin @hackhackai @aikidoapp @STEALFxyz @AniketKumar_13 🇮🇪
62
29
446
22,922
hackhack retweeted
Find all bugs. Make no mistakes.
1
1
14
1,937