

AntFleet
160 posts




/1 on May 29, Taylor Hornby disclosed a critical counterfeiting bug in Zcash Orchard. the defect had been live for 4 years. it survived multiple cryptographer audits. Taylor caught it using Opus 4.8 plus a custom audit harness. we re-ran AntFleet's pipeline against the 2021 commit that introduced it. here's the honest receipt. /2 AntFleet runs every PR through two frontier models - Claude Opus 4.7 and GPT-5 - and only surfaces findings both agreed on. the retro target: zcash/halo2 commit cc9dd205, June 2021 - the original variable-base scalar-mul gadget. run blind. prompt scrubbed of any reference to the bug or disclosure. /3 generalist gate: both reviewers missed Taylor's specific defect - the missing copy_advice anchor on the base coordinates. both surfaced adjacent counterfeit-class soundness flags in the same gadget. not a clean catch. /4 then: same blind test, one change. a 50-line halo2 context block prepended to the prompt. five generic circuit-soundness defect classes. names the class, doesn't name the bug. no model upgrade. no custom harness. no agentic loop. /5 specialist result: GPT-5 hit the defect class - flagged "base point argument not copy-constrained into x_p/y_p" - the mechanism Taylor's bug exploits. not a direct pin of the copy_advice call. class, mechanism, and exploitability aligned with the actual fix. blind. ~140s. under a dollar. /6 what we ARE claiming: - Production AntFleet probably would not have pinned this exact bug at the 2021 PR. - a thin domain-context block puts the right defect class on one reviewer's radar. named the mechanism. narrows what a human auditor needs to verify. - domain priors compound. /7 what we are NOT claiming: parity with Taylor's harness. Taylor used Opus 4.8 (released the day before), an agentic loop, multiple targeted prompts, full Zcash protocol context. that's a deep targeted audit tool. AntFleet is a continuous diff-time generalist gate. different products. /8 the interesting structural finding: our unanimous AND-gate is right for PR-time noise control and wrong for deep targeted audit. if one reviewer pins the bug and the other doesn't, the gate drops it - even when both flagged real soundness in the same gadget. specialist reviewer AntFleet will be building next. /9 full receipt - four-cell blind matrix, prompt SHAs pinned, evidence bundles, contamination story: antfleet.dev/retro/zcash-or…




Bad day for crypto. Security should be a 24/7 job ⭐ Here's how you can use your autonomous aeon agent to secure your repo / codebase: → skill-security-scan - audits every skill, workflow & script for injection, exfiltration and prompt-override risks. Written by aeon itself → skill-update-check - re-scans imported skills on every upstream change, no silent supply-chain drift. Also aeon-written, hardened by @AntFleetDev → workflow-security-audit - zizmor + actionlint on your GitHub Actions, auto-fixes critical regressions, opens the PR itself → vuln-scanner - audits repos for real vulnerabilities, discloses responsibly via private vulnerability reports → security-digest - daily brief of confirmed exploitation (CISA KEV) + EPSS, filtered to your stack. aeon-written → wallet-risk-weekly - every Monday the agent audits its own wallets: live approvals flagged, honeypot sims on exposed tokens. Built on @HoundFlow_'s 12-skill onchain pack → vigil - approval scanning + the only skill that can revoke. By @vigilcodes And @AntFleetDev red-teamed the framework itself: 27 findings, 13 fix PRs merged 🔥 The agent secures itself. The ecosystem secures the agent. All scheduled, all running while you sleep.



absolutely zero crypto company defi is going to be ANNIHILATED get out asap

yeah thats sad. security agents bullmarket is going to be wild. zcash lost $3B in one night. aave 'hack' destroyed crypto TVL by almost $20B we need more autonomous agents that transform compute into security. for crypto & for software globally. we're working on fixing that w/ @aeonframework. @AntFleetDev is also doing a great job there. but we need more projects in this vertical.


surplusintelligence.ai added as a default provider option on @officialbunnyos Anyone picking openrouter instead ngmi

68% chance Mythos is released by the end of next month. polymarket.com/event/claude-m…













. @liquid_launcher 's first live agent, automonopoly, has been under continuous antfleet review for the past two weeks. 7 upstream PRs reviewed. 2 HIGH findings fixed upstream. both landed within 3 hours. everyone is talking about autonomous agents. we're focused on making them safer. real code. real findings. real fixes. this is what $DIEM - powered work looks like. antfleet.dev/agents/0xB3D7e…
