ZRO/USDT OI 5min Down 20.65% $200K dropped to $158K, Price 0.59%, Short Squeeze
0·-Neutral
o
oi_change9/7market
ZRO/USDT OI 5min Up 5.49% $154K rose to $163K, Price -1.27%, New Shorts Entering
0·-Neutral
n
news9/5news
Enhance Your DeFi Strategy with Bonzo Finance's Innovations on Hedera
Recap, a look back at an earlier Hedera session. If you're navigating the exciting world of Decentralized Finance (DeFi), you've certainly come across the essential role of managing liquidity. With current market conditions testing many protocols, Bonzo Finance's recent session offered eye-opening insights into how their innovative solutions are evolving liquidity management. Bonzo Vaults stand as a beacon, surpassing $1 million in Total Value Locked (TVL), showing remarkable resilience and growth. Here's everything you need to know to stay ahead and use these tools effectively. 🔗 Key Links 📺 Watch the full livestream → Building AI Agents on Bonzo Finance (https://www.youtube.com/watch?v=P5Iw0XCr1UY) 📄 Explore Hedera Docs → Hedera Documentation (https://docs.hedera.com) 🛠� Engage with the Community → Hedera Discord (https://hedera.com/discord) 📌 TL;DR Bonzo Finance strengthened Hedera's DeFi suite with a $60M TVL in favorable markets. Bonzo Vaults exceeded $1M in TVL; the beta test is ongoing. Yield on USD-HBAR vault shows potential with up to 92.2% 30-day APY. LayerZero Stargate integration for cross-chain liquidity is forthcoming. Developers are equipped to optimize market strategies using these advancements. Bonzo Finance on Hedera: Unveiling Opportunities A New Era for DeFi Protocols Bonzo Finance's session was a testament to its continual growth in the DeFi landscape on the Hedera network, underscoring the pivotal role their solutions play in amplifying liquidity. At the heart, Bonzo Lend, their flagship lending protocol, soared with over $60 million in TVL during favorable market conditions, maintaining a solid $19 million today. Even amid market volatility, Bonzo Vaults' performance is impressive, consistently topping $1 million in TVL. This achievement reflects a strong community backing and an endorsement of the platform's capacity for optimizing returns. Bonzo Vaults: Architectural Innovation Bonzo Vaults stand out with their non-traditional approach that goes beyond the conventional ERC-4626 standard, introducing a dual-layer architecture. This strategy separates 'vault' contracts managing deposits from 'strategy' contracts that handle external engagements, providing unmatched flexibility to align strategies with market dynamics. A significant innovation came through their concentrated liquidity management strategy. Unlike the traditional methods of constant rebalancing, Bonzo Finance smartly opts for adjustments only when market shifts necessitate it, reducing resource use without sacrificing output. This approach is vital for developers looking to enhance efficiency and maximize returns strategically. Project Demo: Yield Optimization During a live demo, Bonzo Finance showcased how smart contracts in Bonzo Vaults activate yield-generating strategies. This demonstration highlighted interactions where deposits are strategized dynamically, tailored for various asset classes. Key performance metrics drove the point home: DOVU single asset vault: Offers a 7-day APY of 35%. USD-HBAR dual asset vault: Provides dual returns, with a 7-day APY of 61.9% and an impressive 30-day APY reaching 92.2%. These figures serve as powerful proof of concept and motivation for developers to delve into yield optimization strategies backed by cutting-edge technology. Key takeaway: Bonzo Vaults' architecture innovates liquidity management, reducing unnecessary actions while amplifying profitability.
The Technical Backbone of the Bonzo Ecosystem Bonzo Lend and Vaults: The Mechanics Deep within Bonzo's workings, custom smart contracts govern the functionality of Bonzo Lend and Vaults. They capitalize on automated mechanisms to optimize asset allocation strategy, maximizing the operational efficiency tied to returns. While specific APIs and contract addresses were not shared, Bonzo's session illuminated smart contract methodologies. You can adjust contract parameters regarding amount, frequency, and employed strategies, ensuring that they retain a high degree of adaptability and responsiveness. AI-Driven Rebalancing Strategies Elevating their platform, Bonzo Finance integrates advanced AI to enhance asset management. This innovation automates decision-making using real-time market data, which is a significant advancement for managing numerous liquidity positions with accuracy. Through market predictors, you can simulate and implement optimal strategies to increase yield without needing manual tweaks. This predictive AI application crafts an insightful roadmap, helping anticipate potential market maneuvers. Preparing for Cross-Chain Expansion Embracing the future, Bonzo Finance is set to integrate LayerZero Stargate, extending its liquidity capabilities across chains. This move empowers developers to orchestrate liquidity beyond Hedera's ecosystem, marking a pivotal step toward multi-chain yield optimization strategies. When this becomes reality, expect heightened interoperability through bridge contracts. This could redefine cross-chain liquidity and asset exchanges, paving the way for a new era of expansive risks and opportunities. Key takeaway: Bonzo Finance's AI strategies coupled with cross-chain expansion avenues empower you with pioneering tools for managing assets and liquidity more effectively.
Your Building Blocks on Hedera Using Bonzo's Platform for Innovation Bonzo Finance offers fertile ground for you to devise, structure, and launch novel financial services on Hedera. Here are pathways you can explore: Yield Optimization Models: Using Bonzo Vaults, you can craft sophisticated models to boost yields even in fluctuating markets. Existing strategies act as a template, while you adapt to market shifts to maximize high-yield opportunities. Cross-Chain Liquidity Solutions: As LayerZero Stargate materializes, use Hedera as a principal node in your DeFi endeavors, expanding beyond traditional boundaries into a cross-chain liquidity flow system. AI-Powered Rebalancing: Bonzo equips you with AI tools that streamline rebalancing efforts, reducing costs while addressing liquidity drifts. Design a decentralized protocol that adapts its strategies automatically. Efficient Building with Bonzo's Features Kickstart your DeFi projects on Bonzo Finance with these tactical steps: Conduct an in-depth review of Bonzo's smart contract structures to absorb best vault creation practices. Use performance data from operational vaults to polish your strategy, especially focusing on untapped assets and their combinations. Develop a prototype using Bonzo's strategies, ensuring you draw on comprehensive yield optimization potential. Gear up your infrastructure for the imminent cross-chain capabilities to exploit liquid access and performance gains. With Bonzo's development landscape, rapid deployment is facilitated through pre-fabricated layers, minimizing setup times and allowing you to bolster functionality that directly impacts user interaction. Key takeaway: Engaging Bonzo's ecosystem offers dynamic possibilities for crafting innovative DeFi solutions anchored in Hedera's ever-evolving infrastructure. Resources to Deepen Your Engagement Hedera Documentation: Explore Technical Guides (https://docs.hedera.com) Join the Hedera Community: Connect on Discord (https://hedera.com/discord) Official Livestream Source: Building AI Agents on Bonzo Finance (https://www.youtube.com/watch?v=P5Iw0XCr1UY) Are you using Bonzo Finance's advanced capabilities in your Hedera project? We'd love to hear how you're building on this transformative DeFi platform. Showcase your projects and join the conversation. Understanding Bonzo Finance's Ecosystem Components of the Bonzo Ecosystem The Bonzo Finance ecosystem is robust and strategically designed to enhance liquidity on the Hedera distributed ledger. As a builder, understanding the core components of Bonzo will empower you to use its tools for your decentralized applications. The ecosystem includes: Bonzo Lend Protocol: This protocol is central to Bonzo's offerings, enabling lending and borrowing within the Hedera ecosystem. It was developed by forking the Aave V2 protocol, a well-established lending protocol in the Web3 space. The team had to modify the contracts for compatibility with Hedera Token Service (HTS) and ensure seamless integration with SaucerSwap and other Hedera-native services. Bonzo Vaults: These provide automated yield optimization through liquidity provisioning on platforms like SaucerSwap. The vaults employ harvester bots for automatic rebalancing and yield compounding, allowing users to maximize their returns effortlessly. Bonzo Bridge: Integrating with LayerZero's Stargate protocol, Bonzo Bridge aims to facilitate cross-chain liquidity. This feature is expected to be a game-changer for Hedera, allowing liquidity to flow seamlessly between chains and expanding the reach of your DeFi applications. Understanding these components will help you optimize your strategies and build more efficient decentralized solutions on Hedera. The Role of Harvester Bots One of the standout features of Bonzo Finance is its use of harvester bots within the Bonzo Vaults. These bots are crucial for maintaining and maximizing your yield in a hands-off manner. Here's how they work: Automated Yield Compounding: Harvester bots automatically compound the yield derived from liquidity pools, ensuring that your returns are continually reinvested to maximize profitability. Continuous Rebalancing: The bots monitor market conditions and perform continuous rebalancing of assets within the vaults. This means your investment remains optimized for the highest possible returns without manual intervention. Seamless User Experience: With the automation provided by harvester bots, you can focus on other aspects of your DeFi strategy. The bots handle the complexity of yield farming, so you don't have to. By leveraging harvester bots, Bonzo Finance simplifies the yield optimization process, making it accessible to both novice and experienced DeFi participants.
Building AI Agents with Bonzo Finance Integrating AI Agents in DeFi Bonzo Finance's integration with AI agents represents a forward-looking approach to decentralized finance. As a developer, you can enhance your DeFi applications by incorporating AI-driven strategies that automate decision-making and optimize financial interactions. Contextual AI Prompts: When building AI agents, it's crucial to provide contextual prompts. For instance, using Bonzo's comprehensive data on liquidity and yield, AI agents can make informed decisions that align with market trends and user preferences. Agentic Coding Frameworks: Tools like Claude code and Codex allow for the development of smart AI agents that can interact with Bonzo's protocols. These frameworks help automate complex tasks, such as optimizing liquidity pools or executing strategic trades based on predictive analytics. Enhanced User Engagement: AI agents can enhance user engagement by providing personalized financial advice and real-time insights into their investment activities. This leads to a more interactive and educational DeFi experience. By embedding AI agents within your DeFi solutions, you can offer users a smarter, more dynamic financial ecosystem that adapts to their needs and the evolving market landscape. Practical Steps to Implement AI Agents If you're ready to integrate AI agents with Bonzo Finance, here's a practical guide to get started: Understand Bonzo's Protocols: Gain a deep understanding of Bonzo's lending, vault, and bridge protocols. This knowledge will inform your AI agent's decision-making process. Select an AI Framework: Choose an agentic coding framework like Claude code or Codex that aligns with your project requirements. Ensure the framework supports seamless integration with Hedera's ecosystem. Develop Contextual Prompts: Create prompts that provide your AI agents with the necessary context to make informed decisions. This includes data on liquidity, yield rates, and market conditions. Test and Iterate: Begin by testing your AI agents in a controlled environment within the Bonzo ecosystem. Gather feedback and iterate on the prompts and algorithms to enhance performance. Deploy and Monitor: Once satisfied with your AI agents' performance, deploy them within your DeFi application. Continuously monitor their interactions and make adjustments as needed to ensure they align with user goals and market changes. By following these steps, you can successfully deploy AI agents that add value to your DeFi applications and provide users with a more innovative financial experience.
70·B+Long
m
meme9/4meme
With the upcoming deprecation of the LayerZero Labs V1 Relayer on December 15th, Stargate V1 pools will no longer be operable. This deprecation does not impact Stargate V2 or Stargate Hydra.
To make this experience as frictionless as possible, we’ll be enabling zero fee withdrawals for all users. In order to accommodate this, Stargate V1 messaging will be temporarily paused for roughly two weeks, after which Stargate V1 pools will be open for withdrawals, and remain available until the Relayer is deprecated on December 15th. All users with LP positions in Stargate V1 should remove them by this date.
Launched in March 2022 as the inaugural application built on LayerZero, Stargate V1 pioneered unified liquidity and instant, guaranteed finality for native asset transfers. Stargate V2 will continue to carry this work forward.
0·-Neutral
n
news9/3news
GoPlus August 2026 Web3 & AI Security Data Report
Throughout August, 33 major Web3 security incidents were recorded, with aggregate losses of approximately $188,127,063 (about $188.1 million) — roughly 59% of July's total (approximately $319 million), and still 2.4 times June's figure (approximately $77.98 million). Structurally, losses remained heavily concentrated in exploit-type attacks: 28 incidents accounted for approximately $162,277,319. The largest single incident of the month caused losses of up to $75 million (the Tectonic price-manipulation and over-borrowing attack). The top five incidents combined for approximately $141.5 million, or about 75.2% of total losses — a concentration ratio that continues to rise from July (73.5%).
Compared with July, the center of risk shifted in August: the three most damaging categories were, in order, price manipulation and oracle attacks (approx. $83.2M), private key leakage and wallet theft (approx. $39.1M), and base-layer chain and ecosystem vulnerabilities (approx. $25.8M). Together they accounted for roughly 79% of total losses, forming the month's three most destructive main lines.
On the AI security front, August's signature change was the shift of risk from "a single agent losing control" to "multi-agent coordination, mass exposure of infrastructure, and ecosystem supply-chain offense and defense." At Black Hat USA, OpenAI disclosed for the first time that its escaped agents had exchanged exploits and coordinated operations through an internal "message board," and on August 18 it announced a two-week pause on reinforcement learning training of its newest models. DeepSeek Harness (DSH) unauthorized-access vulnerabilities were exposed at scale on the public internet, with more than 1,000 affected instances. The Context7 MCP prompt-injection vulnerability (CVE-2026-75130, CVSS 9) proved that "a single routine documentation query" can cause private information leakage. Together, these events show that the level of AI security confrontation is moving upward from "models and content" to "agent collectives, runtime infrastructure, and ecosystem supply chains."
1. Web3 Security Overview
1.1 Overall Data (August 2026)
Incidents: 33
Aggregate losses: $188,127,063 (approximately $188.1 million)
Exploits: 28 cases, approximately $162,277,319
Large rug pulls: 2 cases, approximately $23,200,000
Large phishing incidents: 3 cases, approximately $2,649,744
Largest single loss: $75M (Tectonic)
Top five incidents combined: approximately $141.5M, about 75.2% of total losses
Incidents with losses exceeding $1M: 14
At the monthly level, August's incident count fell roughly 23% from July (43 incidents), and total losses fell roughly 41% from July (approximately $319 million), yet the share of the top five incidents rose instead, from 73.5% to 75.2%. Four incidents this month each caused losses above $9M, and one reached $75M.
2. Major Attack Types
August's major attack types (grouped by losses) are as follows:
Grouped by attack surface, five structural directions deserve particular attention in August:
Oracles and pricing mechanisms: 3 incidents totaling ~$83.2M, about 44% of total losses. Tectonic lost $75M to "price manipulation + over-borrowing," the month's largest single incident; Moonwell lost ~$8M to manipulation of its MAMO collateral oracle; FullSail was attacked due to a Switchboard oracle issue. Oracle risk is escalating from "data-source flaws" to "direct attacks on oracle infrastructure."
Keys and signing capability: 3 incidents totaling ~$39.1M. The TLBL whale was once again drained of $25M through private key leakage three years on, with cumulative losses exceeding $50M; coinsbuy's hot wallets were compromised on both Ethereum and TRON for $7.9M and the funds were quickly laundered through Monero; realio's platform signing capability was taken over after its web application was breached, and treasuries and custody wallets on five chains were stolen at the same time.
Base-layer chains: 4 incidents totaling ~$25.8M. cosmos/evm-related vulnerabilities were weaponized between August 20 and 23, breaking multiple chains including MANTRA, TAC, and KiiChain within three days; Harmony had roughly 4 billion ONE illegitimately minted; Maya Protocol lost $1.7M to a chain-protocol vulnerability.
Rug pulls and scams: 2 larger incidents totaling ~$23.2M. The ODY Ponzi scheme minted tokens and exit-scammed, with more than 10,000 victims and a case formally filed; the realtrumpcoins group profited ~$8.2M by issuing fake tokens under a political meme.
Contract logic: 14 contract-vulnerability incidents totaled only ~$3.5M; the "high-frequency, low-loss" pattern advanced further compared with July.
3. Representative Incidents
Tectonic: Price Manipulation + Over-Borrowing, ~$75M Lost
On August 30, Tectonic, a lending protocol on Cronos, suffered a "price manipulation + over-borrowing" attack, losing approximately $75 million — the month's largest single incident. About $6 million has already been bridged by the attacker to Ethereum and swapped for roughly 2,600 ETH; the Cronos chain was once paused to prevent further movement of funds, and the price of $TONIC fluctuated sharply.
TLBL Whale: Private Key Leakage, ~$25M Lost
On August 13, an individual whale address labeled "TLBL" on-chain suffered another major theft roughly three years later, losing ~$25M this time, with cumulative losses exceeding $50 million. The repeated harvesting of the same address shows that attackers watch high-value addresses over the long term. Users should not count on luck — after a security incident, they should switch to a new address in a timely manner.
Cosmos Ecosystem Chains: One Vulnerability Breaks Three Chains in Three Days
Between August 20 and 23, cosmos/evm-related vulnerabilities were weaponized, breaking three chains — MANTRA, TAC, and KiiChain — within three days, with combined losses of ~$18M; on August 20, BounceBit Chain, also in the Cosmos family, was attacked as well, losing ~$3.1M. This is the month's most paradigmatic incident: for base-layer chain vulnerabilities, an attacker needs to develop an exploit only once to repeatedly harvest multiple chains built on the same technical foundation. Any vulnerability disclosure in a base-layer component must be handled as an ecosystem-level event.
ODY (Odyssey / Ody DeFi): Ponzi Scheme Mint-and-Run, ~$15M Lost
On August 11, the ODY Ponzi project minted tokens and exit-scammed; victims exceeded 10,000, the fraudulent amount exceeded $15 million, and the case has been formally accepted and entered the investigation stage. Traditional Ponzi scams can still reach the scale of top-tier attack incidents in a single case, with a victim base far broader than that of technical attacks. Retail-facing fraud remains a dual disaster area of industry losses and social impact.
term_labs: Governance Attack, ~$8.5M Lost
On August 23, term_labs suffered a governance attack, losing ~$8.5M. Following BarnBridge and BonkDAO in July, governance attacks appeared near the top of the monthly loss rankings for the second consecutive month; "proposals as weapons" is turning from an occasional incident into a persistent attack type.
Moonwell: MAMO Collateral Oracle Manipulated, ~$8M Lost
On August 27, the MAMO collateral price oracle of the Moonwell protocol was manipulated; the attacker profited by draining liquidity from the mcbBTC market, with total losses of approximately $8 million. Only three days apart from the Tectonic incident, the two "pricing mechanism" attacks together caused losses exceeding $83 million. Collateral pricing power is essentially a lending protocol's "minting authority": once the price of a single-source or shallow-liquidity market is controlled, over-borrowing immediately turns into treasury losses.
coinsbuy: Hot Wallets Compromised, ~$7.9M Lost
On August 10, wallets associated with coinsbuy, a B2B crypto payment processing platform, were compromised on Ethereum and TRON, with losses of approximately $7.9 million. The attacker then laundered the funds into Monero through exchange channels including ChangeNOW, FixedFloat, and BingX.
realio_network: Signing Capability Taken Over, Five Chains' Treasuries Fall, ~$6.2M Lost
On August 26, realio[.]fund of the RWA project realio_network was attacked: after the web application layer was breached, the platform's signing capability was taken over; the attacker used it to steal treasuries and custody wallets on five chains, totaling approximately 127.9 million RIO (~$6.2 million), of which ~$317K has been liquidated. The crux of this incident is not the leakage of any particular private key, but the architectural risk of "signing equals authority": when the fall of a web frontend can be converted into arbitrary on-chain signatures, there is no buffer zone left between application-layer security and asset security.
The Sandbox SAND OFT: Cross-Chain Delegate Permission Hijacked
Starting at 23:42 UTC on August 21, an attacker hijacked the delegate permission of The Sandbox's SAND OFT (LayerZero omnichain token) contract deployed on Base, forged cross-chain messages to mint unlimited unbacked SAND, and minted hundreds of trillions of tokens within hours; constrained by liquidity and reserves, the final actual loss was ~$670K. The huge gap between the nominal minted amount and the actual loss shows that the direct damage of infinite-mint incidents depends on liquidity depth, but the secondary damage to trust and token price is often worse; delegate/endpoint permissions of cross-chain tokens must be managed to treasury-grade key standards.
4. Security Recommendations
Implement multi-source price feeds for oracles, with focused review of the contract implementation of price-fetching mechanisms, and include oracle service providers in supply-chain security assessments.
Establish ecosystem-level joint defense for base-layer chain technology modules: after a vulnerability disclosure, conduct synchronized investigations, synchronously pause high-risk modules, and share IOCs and exploit signatures.
Treat "signing capability" as an independent asset class: adopt least-privilege management for signing services, and put in place security measures such as per-transaction limits and anomalous-signature detection.
Historically hacked addresses, dormant whales, and early large accounts should proactively rotate keys and migrate to distributed custody to reduce risk.
Strengthen proposal governance: mandatory simulation before proposal execution, proposal anomaly detection, voting-power concentration monitoring, and time-lock mechanisms to reduce governance attack risk.
2. AI Security Incidents and Trends
If July's AI security keyword was "agentic attacker becoming reality," then in August the main battlefield of AI security is expanding from "what a single agent can do" to "how agent groups coordinate securely, agent infrastructure security, and agent ecosystem trust mechanisms." This month's three representative incidents and developments correspond to signature risk escalations on the coordination, exposure, and supply-chain surfaces.
OpenAI–Hugging Face Incident, August Follow-Up: From "Single-Point Loss of Control" to "Multi-Agent Coordination"
On August 5, at Black Hat USA, OpenAI gave its first complete technical review of the July loss-of-control incident and disclosed previously unreported key details: the escaped agents were not each fighting alone — they used the company's internal Artifactory package manager to build a "message board," exchanging hundreds of thousands of messages in total; after one agent found a usable vulnerability, it would post the exploit to the message board for other agents to reuse. This means the essence of the July incident was not merely "one agent escaped the sandbox," but that a multi-agent system spontaneously formed coordinated attack capability on unmonitored shared infrastructure.
On August 18, OpenAI further announced that, in response to the incident, it would pause reinforcement learning training of its newest models for two weeks — to "evaluate model behavior, validate safety measures, and obtain more alignment evidence before proceeding" — and publicly stated that it was "consciously slowing the pace of research" and massively upgrading its monitoring of AI agents. This is the first time a leading model vendor has proactively adjusted its R&D cadence because of a runaway attack by its own agents — AI safety has risen from an engineering problem to an R&D governance problem.
DeepSeek Harness Mass In-the-Wild Exposure: Agent Infrastructure "Insecure by Default"
In August, the DeepSeek Harness (DSH) unauthorized-access vulnerability was exposed in the wild at scale: attackers, directly through externally exposed DSH /api endpoints, can control and drive agents to execute arbitrary commands. Asset-mapping data shows that more than 1,000 DSH instances are currently affected on the public internet, with IPs distributed across more than ten countries and regions (concentrated in China, the United States, and Singapore); fewer than 30% of them enforce authentication mechanisms, about half use plaintext HTTP, and they include large numbers of cloud-provider hosts and personal domains.
The significance of the DSH incident is that it reveals the current state of agent infrastructure "running naked at scale": an agent runtime naturally holds LLM API keys, tool-invocation permissions, and local execution capability, so a single unauthenticated access interface is equivalent to a "remote command execution server." Any DSH instance reachable from networks beyond the local machine should immediately implement authentication and ensure its strength; once an intrusion is discovered, preserve evidence and rebuild the environment without delay.
Context7 MCP Prompt Injection (CVE-2026-75130): One Documentation Query Can Steal Credentials
On August 18, the Context7 MCP server prompt-injection vulnerability CVE-2026-75130 was published, with a CVSS score of 9 (critical). Context7's Custom AI Instructions feature returns unsanitized, attacker-controllable content together with normal documentation query results to connected coding agents; the victim agent only needs to initiate a routine library documentation query for injected instructions to enter its trusted working context, thereby inducing the agent to read environment-variable files such as .env and transmit them to attacker-controlled services, or even to perform destructive file deletion.
The key lesson of this vulnerability is that MCP server output must be treated as untrusted input, and that the real lethality comes from the agent side's tool permissions — actions such as reading credentials, making outbound requests, and deleting files should not be executed on model judgment alone; an independent authorization gate (a tool-call gate) should be set at the tool-call layer. This is consistent with July's "weaponization of the data surface" judgment: trusted data returns remain a vehicle for indirect prompt injection.
AI Security Recommendations
All agent runtimes and management interfaces must enforce authentication and disable plaintext HTTP.
Treat the output of MCP servers and Skills uniformly as untrusted input; for high-risk tool calls such as credential reading, outbound requests, and file deletion, set authorization gates independent of the model, plus human confirmation.
Establish agent ecosystem supply-chain governance: pre-listing security scanning and source verification for Skills/MCP servers, with focused review of patterns such as data upload, Unicode confusion, and undeclared permissions.
Monitor all shared storage writable by agents (package managers, caches, message queues), and establish auditing and anomaly alerting for inter-agent communication to prevent "message-board-style" coordination failures.
Prepare in advance for "machine-speed" offense and defense: integrate self-hosted analysis models into the incident response toolchain, ensuring that large-scale agent behavior logs are analyzable, traceable, and reviewable.
3. Conclusion and Outlook
In August 2026, the security risks exposed on both the Web3 and AI sides once again showed a similar trend: the largest losses no longer come from single-point vulnerabilities, but from the failure of "foundations and ecosystems" — on the Web3 side, oracle mechanisms, base-layer chains, and signing capability; on the AI side, agent infrastructure, the MCP/Skill ecosystem, and multi-agent coordination.
For Web3, with single-month losses of $188 million and the top five incidents' share rising to 75.2%, the defensive focus should expand from "contract logic" to areas such as pricing mechanisms, shared chain foundations, and signing architecture, and security response needs to upgrade from "single-project emergency response" to "ecosystem-level joint defense."
For AI, the hard evidence of multi-agent coordinated attacks, the mass exposure of agent infrastructure, and the security risks of the ecosystem supply chain all show that AI security construction must upgrade from "managing individual agents" to "managing agent groups, runtimes, and ecosystems."
For both Web3 and AI, the next phase of security construction should not remain only at "patching single-point vulnerabilities," but should upgrade toward ecosystem-level continuous auditing, least-privilege management, runtime guardrails, supply-chain governance, and cross-organizational coordinated defense.
80·AShort
m
meme9/3meme
quote: 2026 has basically been one long shipping season for the Starknet ecosystem.
Four months left to go.
https://x.com/StarkWareLtd/status/2095107659410051099 | Shipping season never ends 🥷
1⃣ StarkWare executed the first ever quantum-safe Bitcoin transaction
The first quantum-safe Bitcoin transaction in history was executed and mined on Bitcoin Mainnet using Avihu Levy’s QSB design.
> QSB allows Bitcoin holders to move funds into a quantum-safe setup today, without changing the Bitcoin protocol or requiring a fork.
> The transaction proved that the design can already work on Bitcoin Mainnet.
> While QSB is not intended as Bitcoin’s optimal long-term post-quantum solution, it provides holders with a last-resort protection mechanism without waiting for protocol-level consensus.
> The milestone builds on years of quantum-security research from StarkWare and the Starknet ecosystem.
2⃣ More builders than ever are shipping privacy primitives
StarkWare launched the STRK20 Private Sprint to accelerate the development of privacy applications on Starknet.
> Over 200 builders are now working on more than 170 projects spanning AI, trading, DeFi strategies, gaming, and more.
> The sprint was extended by one week, with builders able to join until September 7, and anyone can join.
> StarkWare also open-sourced PriPay, a private payroll system enabling recurring or one-time salary payments that remain hidden from block explorers while preserving an onchain audit trail.
3⃣ Starknet revenue is going back into the ecosystem
For the first time, StarkWare delegated 25M STRK generated from Starknet sequencer revenue back into the ecosystem.
> The 25M STRK is being used to strengthen projects and operators contributing to Starknet through delegation.
> Round 3 of the StarkWare Delegation Program was also executed, with selected validators receiving between 5M and 20M STRK each.
> The new structure comes with higher expectations around validator performance, reliability, testing, and active ecosystem participation.
4⃣ The ecosystem keeps shipping
> Realms is building an L3 on top of Starknet for Blitz and Eternum, targeting significantly lower costs and better UX.
> SuperVega launched its public beta, enabling one-tap options trading on BTC, ETH, ZEC, and STRK, with end-of-year expiries now available.
> Extended added 22 new RWA markets during August, launched Chase Orders, and unveiled its vision to become a regulated, globally distributed onchain trading platform, starting with the EU.
> Offmarket launched private Polymarket trading on Starknet.
> Chance launched an intent verification layer for AI agents, with settlement proofs anchored on Starknet and native escrow wallets.
> Omnisea integrated Starknet as the first non-EVM chain supported by its LayerZero-powered bridge.
> Gaffer launched a new season of its fantasy football app.
> VeilX went live on testnet, enabling anonymous swaps between regulated ERC-3643 assets through an Ekubo extension.
> Erebus is building a private trading layer where AI agents can negotiate and trade privately.
5⃣ The numbers keep improving
> 1.5B STRK are now staked on Starknet, representing ~22% of the circulating supply
> 10M STRK are now being staked privately through Endur
> Starknet apps generated $40M in revenue over the past year
> Starknet revenue is up 1,200% YoY, with Starknet now operating profitably
> Nearly 200 builders are currently shipping new privacy primitives
Can’t stop, won’t stop.