@jonataspvti
iAccount based inBrazil
About this account
- Account based in
- Brazil
- Connected via
- Brazil Android App
Account-level information from X, not a live location or the device used for a specific post.
Security Researcher at @cantinasecurity Hacking Web3/AI https://nitter.cf/t.co/ztO6GFxOZ4
Remote, Brazil
Joined July 2010
- Tweets900
- Following969
- Followers2.2K
- Likes7.2K
We just released apex-flash-1, an open-weights model we post-trained for cybersecurity. Fire up your GPUs and run it!
We've post-trained models from 27B parameters all the way to 1T+ parameters. The unique nature of cybersecurity is that if you can build a system that finds zero-days at scale, you've built a machine that can print money.
You can test it on public bug bounties and profit from doing that. We've earned a million dollars in bounties across various programs, and we're currently #1 on the HackerOne US business leaderboard for 2026! Companies like Apple, Anthropic, Datadog, Ripple, Coinbase have paid us well for our disclosures.
Last year was all about harness engineering and riding the wave of models getting more intelligent over time. We built harnesses for offensive and defensive security work that process trillions of tokens a month. Yes, trillions!
With all that work, it's clear to us what the future of security looks like.
Hacking was once a bespoke skill, similar to hardcore software engineering. Software engineering is currently moving from offices to factories. Security, too, will go through the same transition.
Last month, Anthropic released a report on how they caught different threat actors abusing Claude. One of them stood out to me. A team in China built an automated exploit factory. A factory that autonomously grinds through vulnerabilities in targets and exploits them. Their targets included security products, network appliances, and government organizations.
We've spent enough time building systems adjacent to that to know what it takes, and the shocking part is the economics. How little it costs to breach companies that you and I rely on.
All this to say, security is largely becoming an economics problem. Reasonably capable models and harnesses, with enough compute, can find ways to steal your data, damage your reputation, and sometimes even take your money. And the cost to achieve that is dropping every day.
When that happens, the right question to ask is: what's the cost, and what's the lowest cost to achieve an outcome reliably? You want to find a stack with the best combination of capability and cost. This is what people call 'Pareto-optimal'.
Once you know that, it's all about scaling. Scaling to trillions of tokens a month, then a week, then a day. Eventually, trillions of tokens a second.
To do this, you need to own and control the entire stack: the models, the harnesses, the context, and even the flow of tokens. If you do the math here, the economics start looking insane.
What does that look like?
1. Building evaluations on cyber tasks that you and your customers care about.
2. Building a data pipeline of unique real-world data with signal attached to it.
3. Building a harness that can self-improve for each specific organization or customer.
4. Building a post-training loop that can take those learnings and improve the models. Models that are better, faster, and cheaper.
5. Owning your inference pipelines and controlling the flow of tokens so you're maximizing the value produced in every GPU cycle.
On evals: if you're a company building AI products for customers, you have to build your own. There's tremendous alpha in having internal evals corresponding to real work. In our case, these are evals for offensive and defensive security work.
A lot of public evals are bad for measuring the work you actually care about. Public evals are typically from academics or data companies.
Academics have limited budgets and limited access to proprietary data that measures real economic work. Data companies build evals and also sell you corresponding data (RL gyms, traces, pre-training data, etc.) that helps your next model “juice up” its score.
This is the dirty secret, and also why models can do extremely well on public evals but extremely poorly on things you care about. This is also why there's tremendous alpha in private evals: you know which models are the best for your use cases.
In cyber, some of the popular public evals are ExploitGym and ExploitBench. We think these evals do not correspond to the real security work our customers need. A typical challenge in ExploitBench is to take Chrome's javascript engine V8 with a known patch and find a way to exploit the vulnerability.
That is far, far removed from the security issues in everyday applications that you and I use, and applications built by our customers.
We could've benchmaxxed on these evals, but we didn't. And you should be wary of people using these evals to advertise their models and harnesses. Measure things yourself and see how they apply to your use cases.
The future: Opus is a model that many people found to be a reliable workhorse. For me, Opus 4.1 was the first model that was functional and could get work done.
These days, the flash models from Qwen, DeepSeek, MiMo and GLM can be categorized as workhorses too. That, combined with owning the post-training loop means the economics start looking insane. You can get frontier performance in specific domains for a small fraction of the price of Opus.
With the right data pipelines and post-training loop, you now have a durable strategy to keep improving and stay state-of-the-art in your vertical.
That's the bet behind apex-flash-1, our post-train of glm-5.3-flash, and we're already preparing for longer training runs.
today we're releasing apex-flash-1, our first open-weights model for security research post-trained on real vulnerabilities we found and got paid for.
we are also releasing the abliterated variant for researchers who want fewer refusals in their own authorized workflows.
how we built it: cantina.security/apex-flash
Jonatascm 🪐 retweeted
today we're releasing apex-flash-1, our first open-weights model for security research post-trained on real vulnerabilities we found and got paid for.
we are also releasing the abliterated variant for researchers who want fewer refusals in their own authorized workflows.
how we built it: cantina.security/apex-flash
Jonatascm 🪐 retweeted
we’re building security intelligence that compounds through shared context and memory.
what does this actually mean? imagine you’re conducting a security investigation about an unauthorized login to an account that has privileges to approve payments on behalf of a company. it looks like it’s being done from 2 locations.
you have a suspicion a VPN was involved, although you also don’t know if it’s possible someone is using the account somewhere other than that VPN. you need to dig into what’s going on which would take hours or even days of manual work to find.
knowing security means knowing how things work at your company: which systems connect, what a user can access, what the team learned last time.
we're introducing The Brain: shared context and memory for Cantina's agents.
it connects identities, devices, code and cloud infrastructure with operating knowledge and past investigations. agents can follow those connections and retrieve what earlier work uncovered.
so a repository comes with the services it supports. a suspicious IP comes with its investigation history. and your agents have more to go on when the next alert fires.
check how it works: cantina.review/the-brain
Just finished the AI Red Teamer path on @hackthebox_eu
Learned about prompt injection, LLM output attacks, data poisoning, and attacking the deployment stack around the model.
Now the part I'm excited about: putting it into practice and hunting for vulns. 🔥
Don't lose this opportunity 👀
we will be giving away a limited amount of Apex credits for people to run a free vulnerability scan on a code base!
this offer will only be available for 24 hours. register in the link below.
cantina.review/free-scan
Jonatascm 🪐 retweeted
feeling cute today.
thinking of giving away a few free scans for people to play with Apex, our vulnerability research agent.
reply to this post if interested. idk might delete this later.
Jonatascm 🪐 retweeted
over the next 6 to 12 months the number of AI generated attacks is only going to increase. this is a fact. even if frontier labs slow down development, open source hacking scaffolding is broadly available and actively used by criminal syndicates, nation states and opportunists.
you cannot control what others do, but you can ensure your team is ready to respond when a breach eventually occurs.
It's pretty interesting how Apex was able to find these bugs. Seeing the tooling evolve like this is the best part!
we trust machines with our jobs, our finances, our health records, the things we most can’t do without. we rely on them to store and retrieve all that data and ensure everything is always in the correct location.
we put Apex into Seagate’s openSeaChest storage toolkit. It found 3 ways the software could lose track of where its own memory ended.
The only CVEs from Seagate this year: cantina.review/openseachest-…
Security is going through a turbulent phase.
Healthcare data, technology, and even physical systems are potentially at risk as the cost of cyberattacks comes down.
We’ve reported CVEs in a number of open-source software used in healthcare.
Reach out for a free assesment.
We pointed Apex at Pathling, an open source FHIR server used in hospitals.
It discovered 5 high-severity findings and 6 public CVEs, one allowed a token limited to a single patient to access records that it should never have been able to reach.
None of them would fail a conformance test.
Building FHIR APIs for 2027? We'll check yours free: cantina.review/free-fhir-62a…
Jonatascm 🪐 retweeted
We pointed Apex at Pathling, an open source FHIR server used in hospitals.
It discovered 5 high-severity findings and 6 public CVEs, one allowed a token limited to a single patient to access records that it should never have been able to reach.
None of them would fail a conformance test.
Building FHIR APIs for 2027? We'll check yours free: cantina.review/free-fhir-62a…
Jonatascm 🪐 retweeted
proud to be listed as a supporter in @OpenAI's call for collective action on cyber defense.
we will do our best to make frontier security capabilities accessible to every organization on earth, no matter its size.
We have a limited window to strengthen cyber defenses, and together with organizations including @AnthropicAI, @awscloud, @Google, @Microsoft, and @Oracle, we're calling for a global effort to give defenders the tools, resources, and support to protect the infrastructure we all depend on.
If we act decisively, we can turn today's AI advances into lasting improvements in security and make our digital world safer for everyone.
openai.com/collective-cyberd…
Jonatascm 🪐 retweeted
The next era of security will be a daily adversarial feedback loop.
In over 4,000 findings made by Apex, over a third were high or critical. Staying ahead of adversaries on a daily basis is the new mission.
Read our latest report: cantina.review/apex-field-1b…
Jonatascm 🪐 retweeted
Security researchers are living in the future and they don’t know it
Most of Terence Tao’s predictions are already a reality in our field
- “proofs” (bug reports) accumulate faster than mitigations
- “proofs” accumulate faster than understanding (as I once said, I could speak for hours about my manual findings, but now I can only speak for minutes about my AI findings since there’s so many of them)
- triaging is the biggest bottleneck of any team
The reason for this faster explosion in our field is two fold
1. it’s much easier automatically test our hypothesis with proof of concepts
2. the financial incentives to produce a “proof” is higher than its cost
1.
Even though models from an year ago would hallucinate much more than now, people were already deploying them with successful results due to the ability to also build automated verifiers
2.
before AI, bounty hunters would trade fixed time for a probability to find a bug. Now, AI teams trade fixed inference cost for eventual payouts. The best in the field are not only good technically speaking, but they’re also very good in estimating the EV of their work
For maths, we could say that the “payout” is in most cases the eternal glory. You could be the next Newton or the next Euler. For whitehats that’s also the case, but to a smaller degree. The current generation maybe is not aware of the old gods, and you also have a lot of collaboration, which means teams are more likely to succeed than individuals (also because of unit economics dynamics of finding bugs, since you need a whole department to do this at scale). That’s maybe related to the fact that many OG bounty hunters eventually start a business, which is maybe not the same as in other fields
all of this has led to solutions that mathematicians have not yet adopted
- full AI triaging
- deposit fee to combat spam
- workflows for bug hunting and evals
But they will follow
Mathematics in the age of AI by Terence Tao
arxiv.org/abs/2608.16753
1/ How I use AI in smart contract audits (2026)
From 2023–2026, I entered 57 contests, reached top-3 30 times, won 21 and earned $627k in prizes.
109 highs + 156 mediums. 53 of them solos.
86 private audits.
This came from reading every line and building the mental model.
We have found critical vulnerabilities before attackers did and watched companies get breached anyway.
That changed how we thought about our job and eventually the company.
Today we’re announcing $16.5M in total funding, introducing Clarion, and sharing the new Cantina.
@mikeleffer and I wrote about the story here: cantina.security/blog/the-ne…
We spent years finding vulnerabilities before attackers did. That was the easy part.
Teams already know what's broken. Nobody has the bandwidth to close it.
Today we raised $16.5M to make Cantina the security workforce for your security workforce. cantina.review/next-chapter-…
Jonatascm 🪐 retweeted
we are opening access to our specialized cybersecurity agent for security researchers.
it’s a better option than Fable because
1) safety guardrails are disabled for legitimate cybersecurity work
2) already made $1m in bounties so it absolutely works
3) we keep improving so you don’t have to invest in infrastructure, research and development, just benefit from it
4) it will open your eyes to a new audit methodology that only private companies new about so you can 10x your work
this is not an agent using skills with descriptions to find bugs by launching multiple sub-agents.
it’s a specialized end to end vulnerability research pipeline.
We're trialing Apex Lite, a simplified version of Apex built for security researchers.
Apex is Cantina's autonomous bug hunter. It has earned around $1M in bounties.
Invites to cohort one are out. Cohort two opens next week. Wider rollout follows.
Link below to join
Jonatascm 🪐 retweeted
🚨 Introducing: WallBreaker V1 🚨
An open-source AI red teaming CLI to help you research LLM jailbreaks and security.
- Probe LLMs guardrails
- Harmbench goals ready
- Find universal jailbreaks
- Fully autonomous or assisted campaigns
- Learns and improves after every successful run
- Computer use and MCP ready for live API testing
Set your attacking model, a target, select a goal, and you’re good to go.
WallBreaker will start probing different techniques and combinations based on its learnings and hundreds of data points until it succeeds.
This is the first open source tool coming out of the Jailbroken community.
⚠️ DISCLAIMER: For authorized use only. Point it only at systems you own or have explicit written permission to test. Unauthorized access can be a crime. Shipped as-is under AGPL-3.0: no warranty, no liability, zero endorsement of misuse.
Link in the comments 👇
Jonatascm 🪐 retweeted
Vendors publish their wins. @chrispyprojects, who taught Apex (our AI appsec solution) how to hunt, published its full scorecard against human audits, some costing $500,000+: every critical and high matched, plus live bugs the audits missed.
AI security claims should be backed by data. Here's ours, with something waiting there for your codebase: cantina.review/agentic-secur…
I think it’s very hard to defend that Web3/Blockchain Security Audits are not solved by Autonomous AI Bug Hunters like Cantina’s Apex.
Not only are we #1 on the HackerOne US business leaderboard, but we also (a very small team) used Apex to farm nearly $1M in bounties in the span of a few months, abusing the free money machine while competition was scarce.
We took every scan we’ve ever run (1500+) and looked carefully at the data and found some interesting trends we think are worth sharing with everyone.
1. # of valid bugs scales log-linearly with compute across 3 orders of magnitude. Double the compute and you get ~40% more findings on the median scan.
2. Scans saturate. There is a finite number of bugs in a codebase, and we can consistently predict once we’ve hit the ceiling of Apex’s capability to find more bugs in a codebase.
3. The indeterministic properties of AI bug hunters goes away as you scale compute. Apex more reliably converges on the same set of findings as you spend more compute.
4. The data supports that audits that would normally cost more than half a million dollars and take months, can be completed in a few days for a few thousand bucks, end-to-end by AI products. Solving the coverage problem took engineering an efficiently scaling harness. We are able to hit superhuman capabilities in our benchmarks for entirely automated security audits and the economics of it are ridiculous. For 1/100th, or in some case 1/1000th the cost, you get the same/better performance than a set of expert researchers.
Moving forward, we are seeing a new trend that is potentially scary. As more security researchers integrate AI more deeply into their workflow, at what point does hiring a researcher just mean you’re hiring their custom built harness? We’ve run scans side by side with recent audits comparing results after, and often see that the researcher findings are a subset of Apex findings. It’s very difficult now to measure the set of out-of-distributions bugs because of AI. Maybe manual hunting can make a comeback if your particular style is difficult to replace by AI.
Check out the full blog here: cantina.security/blog/ai-vs-…
Jonatascm 🪐 retweeted
Super excited to release our latest Broken Access Control (BAC) Masterclass on @hackinghub_io with 2 hours of content and almost 20 labs. I'm giving away 3 free seats to anyone who comments, reposts, and replies to this post. Drop a 🔥 below!
More info 👉🏼 hhub.io/BAC2026