AI-driven deep security intelligence for complex systems.

Alpha confirmed
if you will be at @token2049 in SG this year our team @therealgregoAI will be hosting an event here: luma.com/dupkf78j
1
14
703
GregoAI retweeted
New @cyphertalkmedia episode: our co-founder @beyer_st sits down with @0xriptide of @therealgregoAI. Chaining vulnerabilities with AI, the $27.7M exploit it caught, and what's left for the human auditor.
🎙️ New episode: @0xriptide, bug bounty hunter turned co-founder and CEO of Grego AI. He built AI that chains vulnerabilities humans would almost never reach, found a high-severity bug in Lido, and prevented a $27.7M exploit. 🎧 podbean.com/ep/pb-e9u3w-1b5f…
1
11
1,903
If you think AI security tools are just cheap scanners that dump 20 pages of false positives, this conversation is worth listening to. This week’s Security Voices features @flack00n, Head of Bugs at @therealgregoAI . From @bountyhunt3rz with @0xriptide. What I found interesting wasn’t just the $500K+ in bounties or the $27.7M they helped save. It was how they think about depth, verification, and why they still don’t trust AI 100%. Some thoughts from the conversation 👇
5
5
43
1,883
Finding bugs that humans miss ... while staying extremely humble
An AI security agent now ranks #17 on the Immunefi leaderboard. In 2026 alone, it has found 3 valid Critical vulnerabilities and 5 Highs, earning more than $197,000 in bounties. The AI security agent race is clearly not slowing down. If you’re building an AI security agent and have been hunting on Immunefi, DM us. We’d love to see what you’re working on, support your training with our Studio Review product, and help amplify your work. Congrats, @therealgregoAI! 🤖
2
12
780
GregoAI retweeted
An AI security agent now ranks #17 on the Immunefi leaderboard. In 2026 alone, it has found 3 valid Critical vulnerabilities and 5 Highs, earning more than $197,000 in bounties. The AI security agent race is clearly not slowing down. If you’re building an AI security agent and have been hunting on Immunefi, DM us. We’d love to see what you’re working on, support your training with our Studio Review product, and help amplify your work. Congrats, @therealgregoAI! 🤖
7
8
147
6,547
GregoAI retweeted
Treat your whitehats better than your blackhats
13
36
218
8,743
GregoAI retweeted
Shocked seeing incentives misaligned yet again $320M or potential $10k w negotiation + KYC
No, Liquid Network / Blockstream did not run a public security bug bounty program. Elements (the software powering Liquid) and related projects only had a standard responsible disclosure policy: report privately via PGP-encrypted email to securityblockstream.com. No rewards or formal bounty platform (Immunefi, HackerOne, etc.) were offered for vulnerabilities. They occasionally posted development bounties for features (e.g. wallet kits), but nothing covering protocol or consensus bugs.
10
5
137
9,821
GregoAI retweeted
An AI just found a critical bug worth $70,000. That brings its 2026 earnings past $187k. Pledge $IMU behind @therealgregoAI and you both earn when it finds the next one: immunefi.com/pledge/gregoai/
12
10
229
16,053
The real bottleneck in AI security isn't prompting. It's reasoning. @0xriptide, CEO of @therealgregoAI and a top-40 globally ranked bug bounty hunter, joins the Common S3nse stage. After years of finding high-severity vulnerabilities in smart contracts and DeFi, Justus is now building AI-powered defenses that can reason, verify, and find real bugs without drowning teams in false positives. Privacy • Security • DeFi 📍 Amsterdam 📅 September 4-5 (during Cypherpunk Week) 🦦 Privacy is Common S3nse 👉 commons3nse.cryptocanal.org/ 🐈‍⬛ Cypherpunk Week 👉 cypherpunkweek.com/
2
7
511
GregoAI retweeted
see you at @CryptoCanal anon
1
3
29
2,018
BOUNTYHUNT3RZ Episode 36: w/ @flack00n & @0xriptide discuss the inner workings of @therealgregoAI's lab including the origin story, why riptide co-founded the company, the AI security narrative, the future of bug hunting with AI, how their depth-first tool stacks up against the rest of the AI-sec space, flacko's humble beginnings and his journey with Grego AI, random discussion about motorcycles, and much, much more … podcast, discord, substack: linktr.ee/bountyhunt3rz
1
2
15
3,341
Glad to receive some humble donations from The DAO Fund's First Security Round on @Giveth We have put this funds to good use in creating the next iteration of Grego AI by funding continued R&D and covering a portion of our inference costs Thank you also to the organizations who contributed to the funding including @wintermute_t and @thedaofund
6
926
GregoAI retweeted
We will see many more of these on new chains and low activity chains Ethereum and its L2s have been tested out in the open, thus AI blackhats have moved on to any low hanging fruit that has never really had eyeballs but secures value Yesterday was the time to think about and implement a strong AI native defense security strategy, unfortunately most will wait until it’s too late
Wanchain @wanchain_org Cardano bridge was reportedly being attacked, with ~515M $NIGHT drained from the bridge Treasury. Our initial investigation suggests that the root cause seems to be a non-injective signed-message encoding in the TreasuryCheck validator. The signed message is built by raw-concatenating 14 variable-length redeemer fields (via `AppendByteString` fold) without delimiters or length prefixes. Different field-value tuples can produce the same byte string — and therefore the same hash and a valid signature reuse. We verified this by decompiling the on-chain Plutus V2 bytecode (pic 1) and decoding the attack redeemer from the exploit TX (pic 2). The same on-chain bytecode also contains a `SerialiseData` builtin — but it is only used on the output-datum matching path, not in the signature-hash construction. Using `Sha3_256(SerialiseData(...))` instead would have provided unambiguous CBOR-encoded field boundaries, preventing this class of field-splitting signature reuse. Attack TX: cardanoscan.io/transaction/0…
13
3
84
7,477
GregoAI retweeted
Must watch for anyone in the bug bounties space
7
11
157
7,841
GregoAI retweeted
fantastic buzz here in tokyo for @WebX_Asia and @JBCWeek a lot of talk about institutional adoption and more hybrid TradFi/RWA/blockchain based businesses coming online vs. pure DeFi the technologies developed out in the open over the last 10 years appear to be finally beginning to merge with the legacy systems of global finance i had some heavy mic time during the panel with @intmaxIO, @virtuals_io and @a16zcrypto on the panel which says something about what investors and protocol teams are constantly thinking about above all else: security, security, security proactively defending against AI blackhat threats with AI whitehat solutions will be a huge piece of this security puzzle as companies try and stay one step ahead of the bad guys in this new era
10
3
66
3,380
GregoAI retweeted
in SF all week if you would like to meet DM
4
1
18
1,517
GregoAI retweeted
if you are still wondering if you need to run your own "benchmarks" for Grego AI before integrating into your protocol ... we've been posting receipts since day 1
Grego AI is now 15th on the @immunefi leaderboard for 2026 👀
4
2
72
5,415
Grego AI is now 15th on the @immunefi leaderboard for 2026 👀
1
42
7,920