oksolc 🚀
a new Solidity compiler written in Zig
builds 10 min → 2 min
incremental 700s → 99s
and most importantly: same bytecode
👉 github.com/okcontract/oksolc
We got tired of waiting 10 minutes for Solidity builds, so we built oksolc in Zig.
Same bytecode. 5×+ faster on many contracts.
Our builds:
10 min → 2 min
Incremental large changes: 700s → 99s
If the bytecode ever differs, please tell us.
Huge thanks to the Solidity team.
github.com/okcontract/oksolc
AI agents may automate the work, but they do not solve the security problem.
@hbbiok explains why privileged actions still need to be protected, and how blockchain-based timelocks can add a layer of security before dangerous operations like sending money or approving access can be executed.
@okcontract
Henri Binsztok (@hbbiok), Co-Founder of OKcontract (@okcontract), will be joining us LIVE for our first-ever stream of The Offline Network — Southeast Asia.
Catch him LIVE today at 6 PM SGT.
Join us today at the Singapore GUG meetup, hosted by SQ Collective!
Our founder @hbbiok will share how frontier AI models are changing cybersecurity — from discovering serious software vulnerabilities to what defenders can do about it.
We’ll discuss:
- what is already happening,
- where these capabilities are heading,
- and what defenders can do to secure systems and operate around the clock in this new environment.
🎲 Randomness is the root of every crypto wallet.
If the seed is weak, everything built on it is weak.
🔑 Key generation deserves the same scrutiny as transaction signing.
So which pseudorandom number generator can you actually trust?
🛡️ Trust a process you can verify:
→ Know the exact code generating the secret
→ Combine independent entropy sources
→ Generate keys offline
→ Verify the public address independently
→ Erase the temporary environment when finished
🚀 Meet Entropy Mixer:
Our experimental, open-source, client-side tool for combining operating-system randomness with human interaction data, publishing a fixed IPFS build, and creating a public checkpoint for wallet verification.
Audits secure the contract.
Chainwall secures the interaction.
Contracts may be audited and formally verified, yet UI spoofing, weak approval flows, and blind signing remain risks.
Chainwall secures the interaction itself by proving what was signed and by whom.
We are excited to support the @hexens Builder Support Program. For accepted teams:
▸ 3 months of Chainwall, free
▸ Fully sovereign, onchain security
▸ New customers only
🥷 The attack surface has moved to vault infrastructure
The $6M Summer.fi hack exposed vault NAV accounting and strategy adapter risk
💡 One possible solution:
local vaults should not treat passive adapter balances as always-valid NAV components.
Replace passive adapters with policy-gated execution.
Read our analysis: medium.com/@okcontract/summe…
THE BLOCK: Summerfi says the $6M exploit came from manipulating the NAV/share price of two USDC vaults — not from hacked keys. The attacker prepped for at least 3 months.
The Lazy Summer DAO will now discuss next steps, including user compensation.
A manipulable ERC-4626 exchange rate was accepted as collateral pricing, giving an attacker the ability to inflate collateral value and drain the lending market.
Read the full analysis and how it could have been prevented:
medium.com/@okcontract/can-e…
🚨 @edeldotfinance - Loss ~$403K (2026-07-01)
Network: Ethereum
Type: Oracle Manipulation (ERC-4626 exchange-rate)
Edel Finance is an Aave-fork lending market that accepts wrapped xStock tokens (e.g. wGOOGLx) as collateral. Its price oracle for wGOOGLx derives the collateral value from the wrapper's ERC-4626 share-to-asset rate (convertToAssets = underlying balance / totalSupply), which is manipulable. The attacker flash-loaned 180K USDC and ran a 41x supply/borrow loop that skewed the vault's share ratio, inflating the reported wGOOGLx price (now ~$28k vs ~$180 real). With hugely over-valued collateral, they borrowed out the pool's assets — 204K USDC plus tokenized stocks wSPYx/wQQQx/wMSTRx/wNVDAx/wTSLAx — netting ~$403K and draining most of the ~$602K pool TVL.
TX: etherscan.io/tx/0xe2320086b2…
Attacker: etherscan.io/address/0x58428…
Victim: etherscan.io/address/0x3eeeb…t.me/defimon_subscription_bo…
Attackers have moved past smart contracts.
The soft targets now are frontends, cloud, and developer machines, the layer between what a user intends and what gets signed, and attacks will become more sophisticated with the rise of AI.
@OKcontract co-founder and CEO @hbbiok was on @NFTmorning on Friday, digging in French into the most common attack vectors in our industry in 2026.
The podcast breaks down where wallet risk really lives, and how #Chainwall protects self-custody with no central point of failure.
People worry about signing transactions.
Over the past week and a half, our team was on the road:
🔹first at @proofoftalk in Paris, meeting with institutions shaping the next phase of digital asset adoption
🔹then at the @waibsummit in Monaco our co-founder @hbbiok joined a panel on risk management.
The discussion kept returning to a central theme:
Securing keys is necessary, but far from sufficient. The next frontier is securing what a signed transaction actually does.
That is the problem Chainwall is building for.
Attending @waibsummit 🇲🇨 today?
When digital assets enter institutional strategies, risk management becomes central to how capital moves confidently into the space.
🎤 Our cofounder @hbbiok will moderate a panel on Risk Management for Digital Assets, bringing together leaders across security, custody, legal structuring, operations, and market exposure.
📅 June 9, 2026
🕰️ 12:00 PM – 12:40 PM
Panelists:
Mitchell Amador, @immunefi
Dominic Longman, @ZodiaCustody
Pascal Tallarida, @Jarvis_Network
Rob D., AlphapartyCapital
Alina Maria Serban, Serban & Serban Law Firm