1. X
  2. Spearbit
Log inSign up
Spearbit
2,135 posts
Image
user avatar
Spearbit
@spearbit
Industry Leading Web3 Security. Request a security review here ➡ cantina.xyz/solutions/spea…
cantina.xyz/solutions/spea…
Joined October 2021
33
Following
14.3K
Followers
RepliesRepliesArticlesArticlesMediaMedia
  • user avatar
    Spearbit
    @spearbit
    Jul 16
    Join the hunt.
    user avatar
    Cantina 🪐
    @cantinasecurity
    Jul 16
    Trading and lending in one protocol means one shared state managing both. The @ammalgam bug bounty is live. Researchers are already digging in. If you've ever wanted to see what happens when 2 financial primitives share liquidity, this is your playground: cantina.xyz/bounties/b5e37…
    Image
    1.6K
  • user avatar
    Spearbit
    @spearbit
    Jul 2
    A normal audit ends with a report. Our review of @arkisxyz ends with a signature that can block the deploy. We recompile the build, confirm the bytecode matches what ships, then sign that exact release by name in a public log. No signature, no release. The Spearbit half of our
    Image
    2.2K
  • user avatar
    Spearbit
    @spearbit
    Jul 2
    This is a real shift for onchain security. The audit report is no longer the deliverable. A named, independent signature on the exact code that ships becomes the gate, recorded in a public log, and without it the release cannot proceed. Proud to be the independent verification
    user avatar
    Arkis
    @arkisxyz
    Jul 2
    Arkis has partnered with @spearbit, the security research firm behind reviews for @Morpho, @coinbase and @liquid_col to create the first fully verifiable, tamper-proof digital provenance for institutional smart contracts. @spearbit's sign-off is required before any release
    3.1K
  • user avatar
    Spearbit
    @spearbit
    Jun 25
    We've been busy.
    user avatar
    Cantina 🪐
    @cantinasecurity
    Jun 25
    Vendors publish their wins. @chrispyprojects, who taught Apex (our AI appsec solution) how to hunt, published its full scorecard against human audits, some costing $500,000+: every critical and high matched, plus live bugs the audits missed. AI security claims should be backed
    2K
  • user avatar
    Spearbit
    @spearbit
    May 20
    Five household-name eng orgs hit in three weeks by the same group. A worm built for npm ended up walking ~3,800 internal repos out of GitHub.
    user avatar
    Cantina 🪐
    @cantinasecurity
    May 20
    We’ve detected that @github has been compromised by TeamPCP. A poisoned VS Code extension on an employee device. ~3,800 internal repos exfiltrated. Data already on a black forum for $50K. The technical vulnerability is two words: "runOn": "folderOpen" in a .vscode/tasks.json.
    Image
    4.5K
  • See @spearbit's full profile

    Sign up
    Log in

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Advertisement
Advertisement