Security for those who cannot afford a mistake.

Pinned Tweet
1/ we found a bug in the Aptos Move VM that put up to $70B at systemic risk. type confusion at the execution layer. a ~90% success rate across hundreds of simulated runs on a 30+ validator cluster. cost to build the attack infrastructure: $3,000. Conducted by @kemmio , to our knowledge this is the first public research that showcases how to land a sophisticated multi-block attack in real-world environments. It includes mempool feng shui, block production specifics and about a dozen of other primitives and tricks chained to get to near-perfect exploitation results. Nonetheless, Aptos called it "extremely low exploitability." [hexens.io/research/aptos-hij…]
11
47
327
85,140
Most fraud in crypto starts with an address someone should have screened 🔎 Our Security API is that screen. One call tells you if an address has been flagged for scams, hacks, or illicit activity. We run it with @hexens 🤝 On #Ethereum, #Bitcoin, Liteoin, #Solana, and #Tron.
1
4
15
1,204
Audit Completed: @Re7Labs We audited the application that is powering the new hub for accessing Re7's vaults & tokenised strategies - see comments for the link! We covered access control, phishing and origin-confusion paths, transaction integrity end-to-end, the browser-facing HTTP surface, and backend read endpoints. Wishing the team the best as they keep launching new products. Full report below:
1
8
18
851
Avalanche builders: you now have access to Hexens audits through the @AvaxDevelopers Audit Marketplace. Request a quote below:
The Avalanche Audit Marketplace is live on the Builder Hub 🔺 One request reaches all Ava Labs vetted firms. Quotes stay private, you pick one, and the program can cover up to 75% of the cost. $0 fees for builders and auditors. Request quotes 👇
2
3
9
662
hexens retweeted
4/ Risk monitoring runs around the clock. Zyfai tracks: → TVL drawdowns → APY fluctuations → Liquidity traps → Vault share concentration → Depegs → FUD on X → Underlying collateral health and changes Last week, we strengthened our risk engine with @hexens' Glider Monitor, adding real-time attack detection, vulnerability checks and custom monitoring rules across all 80+ supported pools, alongside a dependency graph that maps their underlying contracts to identify which pools could be affected by a problem in a dependency.
Zyfai is integrating Glider Monitor by Hexens to strengthen our existing risk monitoring. It adds deeper visibility into the contracts and dependencies behind our 80+ pools with real-time attack detection, vulnerability checks and custom monitoring rules.
Article

Zyfai Strengthens Its DeFi Risk Engine with Hexens

Zyfai is integrating Glider Monitor by @hexens as its institutional-grade alerting system. Yield only holds if the exit is as disciplined as the entry. Rates, liquidity, and collateral health were

1
2
1
308
One Morpho vault depends on atleast 157 contracts. At least 27 of them can have their code replaced. Not by the vault you chose. By whoever holds the key to their upgrading mechanism. For 14 of them there is no waiting period. A multisig signs, or in 3 cases a single key, and the new code is live in the same block. No queue, no notice, nothing for a depositor to react to. Your money sits on code that can become different code before you'd ever see it coming. Glider Monitor watches for that swap.
3
9
15
1,116
80+ pools. Every dependency. Monitored in real time. Welcome to Glider Monitor, @Zyfai_
Zyfai is integrating Glider Monitor by Hexens to strengthen our existing risk monitoring. It adds deeper visibility into the contracts and dependencies behind our 80+ pools with real-time attack detection, vulnerability checks and custom monitoring rules.
Article

Zyfai Strengthens Its DeFi Risk Engine with Hexens

Zyfai is integrating Glider Monitor by @hexens as its institutional-grade alerting system. Yield only holds if the exit is as disciplined as the entry. Rates, liquidity, and collateral health were

2
6
18
1,237
You integrate Aave by writing one address into your code. That one address pulls in at least 310 risks that you didnt monitor or even know of (428 nodes). But how do you monitor all of this? When anything happens there nobody calls you. There is no changelog for your risk surface or any notification for incidents. You find out the way everyone finds out: from your own balances, or from someone on Twitter. DeFi is built this way, its complex and interconnected. Stay on top of you risks and respond timely with Glider Monitor.
1
6
16
1,588
We're bringing the Loss Prevention Lounge to TOKEN2049. Both days. Paste a public address, wallet or contract, and watch us map what it actually rests on, hop by hop. Anything worth an alert, we put under live monitoring before you leave. Oct 7 & 8 · 10:00-18:00 SGT · Level 1, Booth PB1-15 You can find the link below:
3
8
16
893
hexens retweeted
🗳️ New Proposal for Safenet Aegis is now live on the Safe{DAO} forum. Here is a breakdown ↓ It asks to fund the first production-ready protocol version built to secure @safe Multisig and the wider ecosystem in Q4. Threats to self-custody are only increasing, and most defences today are still just warnings, not enforcement. Safenet Aegis is changing that paradigm. 🔰 Safenet is a decentralized network of independent Sentinels and Validators 📜 Sentinels check every transaction against a public, DAO-owned charter using their own proprietary threat detection systems 🧾 Sentinels pass verdicts. Verdicts are attested by validators onchain making security enforceable 🛡️ Enforcement happens at the account level via Safenet Guards Proposed Independent Sentinels checking transactions: @OpenCover, @IntentGuard , @hackenclub, @hexens, @BlockSecTeam and @candidelabs Proposed Validators: @gnosisdao, Core Contributors, @greenfield_cap, @SafeLabs_, @RockawayX and @bcap Safe{DAO} through this proposal, owns every fee parameter on the Safenet protocol. Safenet Aegis will ship inside @SafeLabs_ multisigs in Q4 2026. Read More ↓
Draft Proposal for Safenet is live on the Safe{DAO} forum for discussion: It asks to fund Safenet Aegis: The first production-ready protocol release to secure the @safe ecosystem and the first, with onchain fees paid to participants in the network. Read More: forum.safefoundation.org/t/d…
8
8
31
8,325
A team we onboarded to Glider Monitor runs 85 contracts across six chains — Ethereum, Arbitrum, Base and three more. Their dependency graph came back with 2,895 addresses. That is 34 inherited contracts for every one they deployed. Oracles, routers, proxies, token implementations, and whatever those call in turn. None of it was in anyone's audit scope. None of it sits in their repo. All of it can change without a single person on their team being told. Worth noting where those 2,895 concentrate: across six deployment chains, the dependency graph clusters onto two. Most teams assume their inherited risk spreads the way their contracts do. It rarely does. An audit tells you your code was correct on the day someone read it. It says nothing about the 2,895 addresses underneath, and nothing about tomorrow. Map what you depend on. Then watch it.
4
5
28
1,901
hexens retweeted
Glider Monitor is now the fastest-growing production security tool in web3, and probably tops in general web3 sec products too. This didn’t come without panic in some indirect competition backoffices. Everything has a price to be paid for.
1
9
33
1,552
hexens retweeted
Pegged swap pricing, decay, fees and external calls each affect how a swap fills. @Hexens audited these production paths in SwapVM. One of 8 independent Aqua and SwapVM audits, all public 👇
Audit Completed: @1inch Aqua and Swap VM, a bytecode engine where makers compose swap strategies from individual instructions. Across two reviews we looked at PeggedSwap pricing, decay offsets, protocol fee ordering and the external call surface, plus the SplineSwap update. Wishing the team the best as they keep building. Full reports below:
5
4
29
19,736
Audit Completed: @1inch Aqua and Swap VM, a bytecode engine where makers compose swap strategies from individual instructions. Across two reviews we looked at PeggedSwap pricing, decay offsets, protocol fee ordering and the external call surface, plus the SplineSwap update. Wishing the team the best as they keep building. Full reports below:
3
7
24
17,755