Rust/Solana-native Web3 security. On-demand AI audits (Sentinel), 24/7 runtime monitoring (Tripwire). We watch your contracts after they ship

sigintzero retweeted
Someone bought $20k of NTRN and staked it 11 minutes before a Neutron vote closed. It passed. The proposal made them admin of 10 Astroport and Drop contracts. 24 minutes later all 10 ran their code and were empty. About $9.4M. It sat in plain view for three days.
1
1
1
39
sigintzero retweeted
This bridge contract had a cap written into it. One million tokens per conversion. It enforced that on deposits. On payouts it enforced nothing. Someone got the signing key and asked for 8.7 million in one call. Float gone. The older version checked both ways.
1
1
1
40
sigintzero retweeted
Liquid lost 4,000 BTC on Sunday. About 95% of what backs L-BTC. The coins were minted from nothing and pegged out like any order. Every key stayed put. The hole was a cache key. Four fields hashed back to back, no length prefixes. Merged 5 days earlier. Never released.
1
1
1
67
sigintzero retweeted
Dive into our members @sigintzero_ 🇦🇺 Aussie security builders quietly cooking. Their Sentinel AI auditor caught 2 critical/high bugs missed by 32 other audit tools. Tripwire then took first in our @colosseum Frontier AU side track. Audit before launch. Defend after. Serious infra. Check them out below 👇
2
2
12
546
sigintzero retweeted
Everyone ran this as a $9.3M hack. Flow later corrected it to $410k. More Markets on Flow lost its whole WFLOW reserve Monday. Staking 1 FLOW minted 1 ankrFLOW. Redeeming 1 ankrFLOW paid 1.2 FLOW. Loop that 54 times, print 52M tokens, post them as collateral.
1
1
1
91
sigintzero retweeted
A token doing about $11k of daily volume was backing $119M of loans on Cronos. Someone spent ~$600k pushing TONIC up 100x in 20 minutes, posted it as collateral, and borrowed Tectonic empty. Validators halted the entire chain to trap the money. About $6M got out.
1
1
1
115
sigintzero retweeted
Someone lost 810 ETH on Tornado Cash last week. About $2M. The contracts were fine. They opened an old bookmark. That web address lapsed while the project was sanctioned and somebody else picked it up. The clone sitting there kept their withdrawal secret.
1
1
3
226
sigintzero retweeted
Maya Protocol lost $1.7M this week to six separate bugs. Each one was small enough to pass an audit alone. One transaction chained them. It minted 49M tokens into a pool nothing backed, then the attacker bought 99.93% of it and left with 20 BTC.
1
1
158
Average time from exploit start to drained treasury: under 20 minutes. Your audit ended the day it shipped. 🔴 Tripwire watches your live contracts right now, and fires a pre-approved runbook in seconds.
1
2
7
742
sigintzero retweeted
A fake Solidity extension showed up on the TRAE editor. Install it and your machine gets backdoored the second the IDE opens. The clever bit: it reads its C2 server off an Ethereum contract. Kill the server, they just write a new one on-chain.
1
1
2
523
sigintzero retweeted
allbridge got flash-loaned for $1.65M on solana this weekend. rough part: they got hit the exact same way in 2023 and promised a fix back then. one stablecoin per pool, nothing to swap against. worked on bnb chain. solana was still running usdc and usdt in one pool.
1
1
1
545
sigintzero retweeted
Australia has a $4 trillion super pool walled off from venture by its own performance test. It has grant programs that are closed more often than they're open. And it has founders who leave because the map is unreadable, not because the territory is bad. We drew the map.
1
1
5
184
sigintzero retweeted
Say g'day to @ErrToCompile. CEO of @SigIntZero_, leading strategy, growth and technical direction in cybersecurity 💪 Also co-founder, director and solutions architect at TrueOrigin Venture Studio, building next-gen financial and decentralised tech. 🇦🇺
6
3
31
872
~$36M drained from Humanity Protocol on June 8. No contract bug. One employee's laptop held the keys: 3 of 6 on the Ethereum multisig, 3 of 5 on the BNB Chain multisig. One machine cleared both. A proof-of-humanity project, undone by one
2
2
7
433
sigintzero retweeted
🥇 Tripwire: Built by @sigintzero_ is a 24/7 threat detection and response system that identifies exploit signals before execution, monitoring contract behaviour, fund flows, and attack patterns to protect deployed protocols in production. Built by @alteredlad Link: sigintzero.com
2
1
20
1,379
sigintzero retweeted
these things can literally happen to literally anyone, anywhere, check your deps & stay safe peeps 🧑‍💻
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
1
3
220