Industry Leading Web3 Security. Request a security review here ➡ cantina.xyz/solutions/spearb…

Spearbit retweeted
open weights. open weights. open weights. Apex Flash is coming, trained for security research.
7
6
82
3,411
one million reasons to join! Start the hunt:
Your next $1,000,000 rabbit hole: Robinhood Chain by @RobinhoodCrypto. Stock Tokens available to eligible users in 120+ countries. Trading around the clock, and a lot of code behind every trade. Now that code is part of a new bounty on Cantina. Bring your curiosity and a mindset of “that should never happen.” scope & targets: cantina.review/robinhood-def…
1
2
1,168
Spearbit retweeted
we will be giving away a limited amount of Apex credits for people to run a free vulnerability scan on a code base! this offer will only be available for 24 hours. register in the link below. cantina.review/free-scan
7
12
63
8,136
Spearbit retweeted
In 2011, researchers spent six CPU years stress testing CompCert and found zero bugs in its formally verified core. CompCert later added new x86-64 code. 15 years after, Apex found a vulnerability in the new code which followed another discovery of 3 CompCert bugs a few weeks earlier. CompCert’s mathematical model used the right values but the compiled code picked up leftover data in the processor’s register, causing a program crash or jump to the wrong location. if we want inherited software to stay safe we must keep challenging even after formal verification and years of fuzzing. we built Apex to help teams continuously test the software they rely on as new code is developed. full writeup: cantina.review/switch-miscom…
2
4
23
1,706
Spearbit retweeted
we've been asked several dozen times how we ended up at #1 on the @Hacker0x01 US leaderboard, and the answer is...Apex Black. we created an autonomous penetration testing system called APEX BLACK. it runs as a swarm of agents that can interact with applications like real users do. with hundreds of automated security capabilities, they can find any unexpected behavior and produce valid exploits. each time we point Apex at a target it finds a bug. we have not optimized to be #1, this is just a byproduct of our work. we will be talking more about our offensive security work so stay tuned!
2
6
53
4,261
gg
gg. we'll take the number 1 spot on @Hacker0x01's US leaderboard with our autonomous pentester. more than number 2, 3 and 4 combined.
7
1,541
Researchers, you're gonna want to join this one:
Researchers, fresh bug bounty just landed @tenbinlabs is building a tokenization protocol that brings assets and their underlying liquidity on-chain, starting with yield-bearing BRL and MXN, alongside commodities like gold. the core code is live for hunting on Cantina. Who’s taking the first pass? Find a crit and receive up to $40,000 USDC: cantina.review/tenbin
1
9
1,704
Spearbit retweeted
security will win, no matter what.
Cyber is having a moment Across 21 major software companies, including Apple, AWS, Microsoft, and Google: - Reported critical vulnerabilities never cleared 100 per month in four years - Since spring they've jumped to over 600 per month Charts of the Week: a16z.news/p/chart-of-the-wee…
4
4
25
2,890
Spearbit retweeted
we trust machines with our jobs, our finances, our health records, the things we most can’t do without. we rely on them to store and retrieve all that data and ensure everything is always in the correct location. we put Apex into Seagate’s openSeaChest storage toolkit. It found 3 ways the software could lose track of where its own memory ended. The only CVEs from Seagate this year: cantina.review/openseachest-…
5
27
3,071
Did anyone say FREE scan? 👀
We pointed Apex at Pathling, an open source FHIR server used in hospitals. It discovered 5 high-severity findings and 6 public CVEs, one allowed a token limited to a single patient to access records that it should never have been able to reach. None of them would fail a conformance test. Building FHIR APIs for 2027? We'll check yours free: cantina.review/free-fhir-62a…
1
6
1,507
Spearbit retweeted
Clarion now reads Claude Code telemetry and turns every MCP server your agents touch into an audited and tracked asset. For everything else new in the platform: cantina.review/claude-code-9…
1
4
16
2,117
Harness models are getting there, but are they matching @cantinasecurity's Apex? 👀
Answering the question everyone wants to know: we pit Apex against @claudeai and @OpenAI's Codex on the same codebase. Who comes out on top? Of all the issues they detected, 78.6% of Apex’s findings were confirmed in the final review. For Claude, this number was 28.6%, and for Codex, just 16.7%. The full method & results: cantina.review/claude-code-a…
1
6
1,734
Spearbit retweeted
Apex's intelligence compounds over time. We wanted to check the performance of Apex vs. other tools like Claude and Codex Security. We ran all three on the same codebase and applied a single quality bar to the findings that they generated . Results coming later today.
The most common use case for Apex is a weekly scan of your codebase as you're building it. We spend a lot of our time optimizing our bug-hunting recipe to chase the pareto-optimal frontier, and since the beginning of the year, we have managed to get over 10 times more security intelligence per dollar. An average weekly scan these days allocates around 10 billion tokens! It's not just the size and scale, but the learning along the way. Every week, it learns something new about the code and what you like so it can tune its hunt specifically for you.
2
5
26
2,852
Spearbit retweeted
Aviation got safe by assuming aircrafts could fail. Plane systems might break, so critical systems are duplicated and no single failure is allowed to matter. Balancer V3 security works the same way, in four different layers. 🧵
5
7
36
7,240
Spearbit retweeted
The next era of security will be a daily adversarial feedback loop. In over 4,000 findings made by Apex, over a third were high or critical. Staying ahead of adversaries on a daily basis is the new mission. Read our latest report: cantina.review/apex-field-1b…
5
31
2,242
Spearbit retweeted
How can you find a bug in a compiler that has been mathematically proven to be correct? Instead of focusing on the proof, you look for issues in everything else connected to it. This is what our agentic OffSec engineer, Apex, did with CompCert, and it found 3 issues: cantina.review/bugs-ca2386
1
9
44
11,204
Spearbit retweeted
In our Node.js/SQLite test, one legitimate account transfer was executed three times. Apex discovered two Node.js bugs. One let a stale SQLite iterator replay a later write. victim: 1,000 to 700 recipient: 0 to 300 Node.js has fixed both. Write-up: cantina.review/two-node-9840…
5
7
12
1,964
Spearbit retweeted
At @BlackHatEvents, Mike Bartlett ( @mydigitalself ), who leads product at Cantina, built a security agent live from scratch. 🪐 Thanks to everyone who joined the session and stopped by our booth. We’ll be back next year. If you missed the session, we’re running it back as a webinar. Stay tuned.
5
15
1,941
Spearbit retweeted
Cantina research: we discovered a stack buffer overflow in Prism, the parser Ruby has used by default since version 3.4. A single 4-byte character in the right spot can trigger it. Details below.
5
3
16
2,100