Answering the question everyone wants to know: we pit Apex against @claudeai and @OpenAI's Codex on the same codebase. Who comes out on top?
Of all the issues they detected, 78.6% of Apex’s findings were confirmed in the final review. For Claude, this number was 28.6%, and for
Trading and lending in one protocol means one shared state managing both. The @ammalgam bug bounty is live. Researchers are already digging in.
If you've ever wanted to see what happens when 2 financial primitives share liquidity, this is your playground: cantina.xyz/bounties/b5e37…
A normal audit ends with a report. Our review of @arkisxyz ends with a signature that can block the deploy.
We recompile the build, confirm the bytecode matches what ships, then sign that exact release by name in a public log. No signature, no release.
The Spearbit half of our
This is a real shift for onchain security. The audit report is no longer the deliverable. A named, independent signature on the exact code that ships becomes the gate, recorded in a public log, and without it the release cannot proceed.
Proud to be the independent verification
Arkis has partnered with @spearbit, the security research firm behind reviews for @Morpho, @coinbase and @liquid_col to create the first fully verifiable, tamper-proof digital provenance for institutional smart contracts.
@spearbit's sign-off is required before any release
Vendors publish their wins. @chrispyprojects, who taught Apex (our AI appsec solution) how to hunt, published its full scorecard against human audits, some costing $500,000+: every critical and high matched, plus live bugs the audits missed.
AI security claims should be backed