@hexensi
iAccount based inArmenia
About this account
- Account based in
- Armenia
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
Security for those who cannot afford a mistake.
Joined September 2021
- Tweets2K
- Following3
- Followers9.2K
- Likes1.6K
1/
we found a bug in the Aptos Move VM that put up to $70B at systemic risk. type confusion at the execution layer. a ~90% success rate across hundreds of simulated runs on a 30+ validator cluster. cost to build the attack infrastructure: $3,000.
Conducted by @kemmio , to our knowledge this is the first public research that showcases how to land a sophisticated multi-block attack in real-world environments. It includes mempool feng shui, block production specifics and about a dozen of other primitives and tricks chained to get to near-perfect exploitation results.
Nonetheless, Aptos called it "extremely low exploitability."
[hexens.io/research/aptos-hij…]
80+ pools. Every dependency. Monitored in real time.
Welcome to Glider Monitor, @Zyfai_
You integrate Aave by writing one address into your code.
That one address pulls in at least 310 risks that you didnt monitor or even know of (428 nodes). But how do you monitor all of this?
When anything happens there nobody calls you. There is no changelog for your risk surface or any notification for incidents. You find out the way everyone finds out: from your own balances, or from someone on Twitter.
DeFi is built this way, its complex and interconnected.
Stay on top of you risks and respond timely with Glider Monitor.
Monitor what you depend on in under a minute:hexens.io/solutions/glider-m…
We're bringing the Loss Prevention Lounge to TOKEN2049. Both days.
Paste a public address, wallet or contract, and watch us map what it actually rests on, hop by hop. Anything worth an alert, we put under live monitoring before you leave.
Oct 7 & 8 · 10:00-18:00 SGT · Level 1, Booth PB1-15
You can find the link below:
🗳️ New Proposal for Safenet Aegis is now live on the Safe{DAO} forum. Here is a breakdown ↓
It asks to fund the first production-ready protocol version built to secure @safe Multisig and the wider ecosystem in Q4.
Threats to self-custody are only increasing, and most defences today are still just warnings, not enforcement. Safenet Aegis is changing that paradigm.
🔰 Safenet is a decentralized network of independent Sentinels and Validators
📜 Sentinels check every transaction against a public, DAO-owned charter using their own proprietary threat detection systems
🧾 Sentinels pass verdicts. Verdicts are attested by validators onchain making security enforceable
🛡️ Enforcement happens at the account level via Safenet Guards
Proposed Independent Sentinels checking transactions: @OpenCover, @IntentGuard , @hackenclub, @hexens, @BlockSecTeam and @candidelabs
Proposed Validators: @gnosisdao, Core Contributors, @greenfield_cap, @SafeLabs_, @RockawayX and @bcap
Safe{DAO} through this proposal, owns every fee parameter on the Safenet protocol. Safenet Aegis will ship inside @SafeLabs_ multisigs in Q4 2026.
Read More ↓
Draft Proposal for Safenet is live on the Safe{DAO} forum for discussion:
It asks to fund Safenet Aegis: The first production-ready protocol release to secure the @safe ecosystem and the first, with onchain fees paid to participants in the network.
Read More: forum.safefoundation.org/t/d…
A team we onboarded to Glider Monitor runs 85 contracts across six chains — Ethereum, Arbitrum, Base and three more.
Their dependency graph came back with 2,895 addresses.
That is 34 inherited contracts for every one they deployed. Oracles, routers, proxies, token implementations, and whatever those call in turn. None of it was in anyone's audit scope. None of it sits in their repo. All of it can change without a single person on their team being told.
Worth noting where those 2,895 concentrate: across six deployment chains, the dependency graph clusters onto two. Most teams assume their inherited risk spreads the way their contracts do. It rarely does.
An audit tells you your code was correct on the day someone read it. It says nothing about the 2,895 addresses underneath, and nothing about tomorrow.
Map what you depend on. Then watch it.
Pegged swap pricing, decay, fees and external calls each affect how a swap fills. @Hexens audited these production paths in SwapVM.
One of 8 independent Aqua and SwapVM audits, all public 👇
Audit Completed: @1inch
Aqua and Swap VM, a bytecode engine where makers compose swap strategies from individual instructions.
Across two reviews we looked at PeggedSwap pricing, decay offsets, protocol fee ordering and the external call surface, plus the SplineSwap update.
Wishing the team the best as they keep building.
Full reports below:
Audit Completed: @1inch
Aqua and Swap VM, a bytecode engine where makers compose swap strategies from individual instructions.
Across two reviews we looked at PeggedSwap pricing, decay offsets, protocol fee ordering and the external call surface, plus the SplineSwap update.
Wishing the team the best as they keep building.
Full reports below:
Audit Completed: @rowa_finance
ROWA is the Institutional on-chain portfolio management system that allows users to build, automate, and monitor sophisticated hedge fund strategies across their portfolios.
Across three phases, we focused on transparency: the accounting that keeps positions and valuations verifiable on-chain. And automation: the logic that executes strategies unattended, and whether it stays within its limits.
We also covered investment limits and upgradeability.
Wishing the team the best as they keep building.
Full report below:
Audit Completed: @ValigatorTech
Holdfast is a non-custodial Solana stake manager, a Chrome extension built for hardware wallet users.
We covered hardware signing and the transaction preflight checks, access control across the extension and its RPC proxy, and the build and release pipeline.
Wishing the team the best as they keep building.
Full report below:
hexens retweeted
Institutional capital requires security controls that operate continuously rather than a one time snapshot.
At Vault Street, continuous monitoring is part of the infrastructure protecting capital from day one.
Glider Monitor continuously checks our contracts and their dependencies, monitors critical invariants and real-time activity, and can replay newly discovered exploits against our contracts to identify exposure to emerging attack vectors.
This sits alongside audits, access controls, onchain limits and automated circuit breakers as part of our defense in depth approach.
The risk landscape is dynamic and our security infrastructure is built to be the same.
Allocated capital needs continuous coverage, not a one-time assessment. That’s why @Vault_St launched with Glider Monitor in place from day one
primeUSD is an investment-grade fixed-income vault: tokenized US Treasuries, AAA rated structured credit.
Glider Monitor checks their contracts against new vulnerabilities as they surface on mainnet, watches what they depend on, and verifies the invariants that keep Vault Street healthy.
Audit Completed: @Anchorvaultcoin
AnchorVaultCoin is a non-custodial multi-asset vault protocol with tier-based deposit terms.
We covered the vault lifecycle, the secure transfer flow, signature and auth key validation, and the tier-based fee logic.
Wishing the team the best as they keep building.
Full report below:
Quantum Key Distribution (QKD) is often presented as security based on the laws of physics.
But building a secure QKD system is a different story.
From BB84 and photon-number splitting to detector blinding and newer approaches like MDI-QKD and Twin-Field QKD, the interesting part is where theory meets real hardware.
A closer look at how QKD works and where things get complicated.
Full article below:
Full Article:
hexens.io/blog/quantum-key-d…