DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
We Scanned 50 MCP Servers for Security Flaws - Here's What We Found

We Scanned 50 MCP Servers for Security Flaws - Here's What We Found

Comments
2 min read
LangChain Just Got Three CVEs. The Bugs Are From 2006.

LangChain Just Got Three CVEs. The Bugs Are From 2006.

1
Comments
6 min read
The Venus Protocol Donation Attack: How a Dismissed Audit Finding Became a $2.15M Bad Debt — Twice

The Venus Protocol Donation Attack: How a Dismissed Audit Finding Became a $2.15M Bad Debt — Twice

1
Comments
5 min read
The LiteLLM Fork Bomb Was an Accident. That's the Scary Part.

The LiteLLM Fork Bomb Was an Accident. That's the Scary Part.

Comments
5 min read
The DBXen ERC2771 Exploit: How _msgSender() and msg.sender Confusion Turned 1,085 Staking Cycles Into Instant Cash

The DBXen ERC2771 Exploit: How _msgSender() and msg.sender Confusion Turned 1,085 Staking Cycles Into Instant Cash

1
Comments
5 min read
Sovereign AI Agents Need Cryptographic Identity: Here's Why

Sovereign AI Agents Need Cryptographic Identity: Here's Why

Comments
5 min read
Flash Loan Circuit Breakers: 5 On-Chain Defense Patterns That Would Have Stopped 80% of Q1 2026's $137M in DeFi Exploits

Flash Loan Circuit Breakers: 5 On-Chain Defense Patterns That Would Have Stopped 80% of Q1 2026's $137M in DeFi Exploits

Comments
7 min read
Auditing Solana Token-2022 Transfer Hooks: The New CPI Attack Surface Your Fuzzer Isn't Catching

Auditing Solana Token-2022 Transfer Hooks: The New CPI Attack Surface Your Fuzzer Isn't Catching

Comments
9 min read
Your AI Agent Can Delete Production — Can You Prove It?

Your AI Agent Can Delete Production — Can You Prove It?

Comments
2 min read
Output Provenance: Proving What Your AI Agent Actually Said

Output Provenance: Proving What Your AI Agent Actually Said

Comments
2 min read
EVMbench Deep Dive: Can AI Agents Actually Find Smart Contract Bugs Better Than Human Auditors? We Tested the Claims

EVMbench Deep Dive: Can AI Agents Actually Find Smart Contract Bugs Better Than Human Auditors? We Tested the Claims

1
Comments
7 min read
220,000+ OpenClaw Instances Are Exposed. Here's How to Check Yours.

220,000+ OpenClaw Instances Are Exposed. Here's How to Check Yours.

1
Comments
3 min read
SafeBrowse: A Trust Layer for AI Browser Agents (Prevent Prompt Injection & Data Exfiltration)

SafeBrowse: A Trust Layer for AI Browser Agents (Prevent Prompt Injection & Data Exfiltration)

Comments 1
3 min read
The XRPL Batch Amendment Near-Miss: How a Loop Exit Bug Almost Let Attackers Drain Any Wallet Without a Private Key

The XRPL Batch Amendment Near-Miss: How a Loop Exit Bug Almost Let Attackers Drain Any Wallet Without a Private Key

Comments
7 min read
Building a Zero-to-Production Solana Security Pipeline in 2026: Trident Fuzzing + Sec3 X-ray + AI Audit Agents in One GitHub Action

Building a Zero-to-Production Solana Security Pipeline in 2026: Trident Fuzzing + Sec3 X-ray + AI Audit Agents in One GitHub Action

Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.