

The Cryptomaniac
933 posts




Proud to announce that when you build with @TryNoahAI, you can run our agentic security scan before your site's live. AI carries ~2.7x the vulnerabilities of human code, big props to the team for taking security seriously. If your app has or will have users, it needs a pentest.




We spent $1,500, built 10 production apps on Lovable, and ran two agentic penetration tests against each of them. Vector (ours) and Aikido Security (Lovable's native partner). Vector found 94% of critical vulnerabilities. Aikido found 47%. Vector cost $14.31/scan average. Aikido cost $100/scan flat. Vector averaged 34.7 minutes per scan. Aikido averaged 73.0 minutes. 100,000 AI-generated apps ship every day. Each one is riddled with vulnerabilities. Full paper below.


Hey, solana defi projects, maybe formally verify your code pls before the mythopocolypse is upon us

Quick update for everyone. Getting ready for our staking update on Tuesday - going to be a massive event for many reasons. This weekend I've put in egregious amounts of time into our UX - custom loading components, live SSEs for staking page, new slick dotmatrix number components that use a 7x9 grid (going for that cool old school dot matrix style) and most importantly - our smart contract. The smart contract is a really big deal. We are anticipating over half a million in TVL within a month, so no pressure, right? As I previously said, it will be immutable. Non upgradeable, meaning absolutely no upgrade authority. We are going for absolute maximum security with it - so there have been literally hundreds of edge cases that we have had to think through to bring it to life. Your staked tokens can only be moved by your wallet signature. Admin cannot access the stake vault - no backdoors, no admin withdrawals, no exceptions. You stake, you unstake. That's it. 1,573 lines of rust, 118 overflow-checked math operations, 10 test suites with 119 cases, tiered DPT ring buffer for our epoch-capped earnings every 2 months, and so so so much more. Once deployed, you'll be able to view the full program on Solscan - every instruction, every constraint, fully transparent and immutable.






@slingoorio do it to solana:DNhQZ1CE9qZ2FNrVhsCXwQJ2vZG8ufZkcYakTS5Jpump and i'll buy more $lmao
