Trading and lending in one protocol means one shared state managing both. The @ammalgam bug bounty is live. Researchers are already digging in.
If you've ever wanted to see what happens when 2 financial primitives share liquidity, this is your playground: cantina.xyz/bounties/b5e37…
Industry Leading Web3 Security. Request a security review here ➡ cantina.xyz/solutions/spea…
Joined October 2021
- This is a real shift for onchain security. The audit report is no longer the deliverable. A named, independent signature on the exact code that ships becomes the gate, recorded in a public log, and without it the release cannot proceed. Proud to be the independent verification
- Vendors publish their wins. @chrispyprojects, who taught Apex (our AI appsec solution) how to hunt, published its full scorecard against human audits, some costing $500,000+: every critical and high matched, plus live bugs the audits missed. AI security claims should be backed
- Five household-name eng orgs hit in three weeks by the same group. A worm built for npm ended up walking ~3,800 internal repos out of GitHub.We’ve detected that @github has been compromised by TeamPCP. A poisoned VS Code extension on an employee device. ~3,800 internal repos exfiltrated. Data already on a black forum for $50K. The technical vulnerability is two words: "runOn": "folderOpen" in a .vscode/tasks.json.



