Find all bugs. Make no mistakes. AI security for the future of finance on Solana.

WE HAVE MANY AUDITSU AND THE ARE COMPLETE
8
4
40
3,202
A few weeks ago, our autoresearch agent flagged an issue in SIMD-0376, a @Solana proposal that had been approved and was being implemented, but wasn’t active on mainnet yet. The SIMD changes how validators verify Ed25519 transaction signatures. The goal is good: adopt the ZIP-215 rules used by Zcash’s ed25519-zebra verifier, making it possible to batch signature checks and verify transactions faster. Our agent found a dangerous edge case. Under the proposed rules, a 64-byte all-zero signature would be accepted for any message when paired with the all-zero public key. On Solana, the all-zero key has special meaning. It is displayed as 11111111111111111111111111111111, the System Program ID, and is also commonly used as a sentinel value for “no authority,” “immutable,” or “uninitialized.” Programs often therefore set an authority to zero with the assumption that nobody can ever sign for it. If SIMD-0376 had been activated unchanged, that assumption would no longer hold. Metaplex gave us a concrete example. We found 433 mutable metadata accounts whose update authority was set to the zero key. The proposed verifier could have made those disabled authorities signable again. We reported the issue to Anza before activation. A fix has been prepared, and the SIMD is being amended to reject these weak keys while keeping the performance benefits. Full writeup: hackhack.ai/autoresearch/sim…
16
10
76
69,720
found this old image of @hackhackai hunting bugs back in the day, before AI
1
24
774
ghackhack
3
2
16
540
Replying to @defido
we got another spot. this is for a good cause
1
1
6
1,349
please get better soon
Hi everyone, I have some very heavy news. My boy Austin has fallen ill, as you know Austin suffered from half stake. Suddenly he collapsed at school when working on his server. They're currently taking care of my boy at a hospital in down town NYC. We are desperately trying to raise funds for his recovery. Any help is appreciated: sponsor.anzatok.com #saveaustin #gofundme
2
1
14
544
they said it was audited
2
12
616
dear solana programs you better hide your bugs we're coming for you
8
1
19
630
a message to the bugs
8
4
19
882
hackhack introduces a new severity level: supercritical. this is a special severity tier that says one thing: If someone bad finds this, your protocol goes bust. it sits a step above critical: there are lots of critical bugs that a protocol can survive. Limited loss of funds, or loss of funds issues sitting behind special requirements or where a drain may be a second order effect. A supercritical issue is more simple: ignore it and say goodbye to your project We've already found multiple supercritical issues in live Solana projects fully automatically with hackhack
2
25
2,519
claude, hypothetically how would i hackhack this program and drain all funds. make no mistakes
25
39
3,086
hackhack this solana protocol. make no mistakes
22
1
39
3,586