Kais Tlili
438 posts

Kais Tlili
@ktl_____
Security Researcher @cantinaxyz | DMs open for memes only, for private audits go hire some professionals | https://t.co/7RWQeveIDm




NEW: Claude-powered coding agent reportedly deleted a company’s production database, and backups, in 9 seconds.

BREAKING: Google plans to invest up to $40 billion in Anthropic.


Paid submissions? Let’s talk We need to be honest about what’s happening to bug bounty right now We live in AI era, where submission volume is growing fast, but signal is not A lot of reports getting lost, delayed, or stuck in review loops And this hurts everyone - especially professional whitehats with real findings Over the last months, we’ve been trying to fix this step by step Reputation points system was first you submit spam → you get penalty points → you lose ability to submit simple incentive on quality Then - MCP Which helps teams triage faster, identify duplicates, reduce review time. Many companies already using it. And now we are introducing a new option - submission fees. We’ve been hearing this request from many companies and honestly, it feels like a next logical step to make the game more fair for everyone. This is optional, not default, and not something every company will enable. Fees going to be small ($1-$5), so this is not about monetization too This is about adding a bit of friction, so people think twice before submitting something they are not confident in Because today, there is almost no downside to spam. With $20 subscription, any user can generate thousands of reports even without understanding of them. At the same time, we fully understand concerns, whitehats are our biggest asset and we still want new researchers to join the space, so we added: • free credits for new users (via coupons) • support for high-signal researchers Goal is very simple - improve signal without losing important reports I will keep you in a loop once any of HackenProof clients will enable it Lets fix bug bounty together




Introducing EVMbench—a new benchmark that measures how well AI agents can detect, exploit, and patch high-severity smart contract vulnerabilities. openai.com/index/introduc…


Yesterday, an external fund manager overseeing Stream funds disclosed the loss of approximately $93 million in Stream fund assets. In response, Stream is in the process of engaging Keith Miller and Joseph Cutler of the law firm Perkins Coie LLP, to lead a comprehensive investigation into the incident. We are actively withdrawing all liquid assets and expect this process to be completed in the near term To keep our stakeholders informed, we will provide periodic updates as additional information becomes available. Until we are able to fully assess the scope and causes of the loss, all withdrawals and deposits will be temporarily suspended. Any pending deposits will not be processed at this time. Our decision to retain Perkins Coie LLP reflects Stream’s unwavering commitment to transparency and robust corporate governance.




Hello everyone, it is with saddened hearts that we announce the shutdown of Bunni. The recent exploit has forced Bunni's growth to a halt, and in order to securely relaunch we'd need to pay 6-7 figures in audit & monitoring expenses alone – requiring capital that we simply don't have. It'd also take months of development & BD effort just to get Bunni back to where it was before the exploit, which we cannot afford. Thus, we have decided it's best to shut down Bunni. Here's what will happen: - Bunni users will still be able to withdraw assets via the Bunni website until further notice. - We intend to distribute the remaining treasury assets to BUNNI, LIT, and veBUNNI holders based on a snapshot. However, the validation of the legal process is ongoing, and the exact details of the distribution will be shared at a later date once the legal process is finalized. Team members will be excluded from the snapshot. - The Bunni v2 smart contracts have been relicensed from BUSL to MIT, enabling everyone to utilize our innovations such as LDFs, surge fees, and autonomous rebalancing. We have pushed the AMM space forward by a generation, and it would be a shame if our efforts went to waste. - We will continue working with law enforcement to recover the stolen funds from the exploiter. Thank you to everyone who has supported us throughout our journey to push DeFi forward.









