Contenu source (brut)
<div id="bsf_rt_marker"></div>
<p class="wp-block-paragraph">Speaking on a <strong>Beyond Finance</strong> community call, <a href="https://taodaily.io/mentat-lend-adds-bitsecs-sentios-to-its-growing-security-stack/">Bitsec (SN60)</a> laid out a result that redefines what security testing on Bittensor should catch.</p>
<p class="wp-block-paragraph">A frontier model ran a client codebase and returned a clean, accurate report of roughly 60 vulnerabilities, none of them critical.</p>
<figure class="wp-block-image size-large is-resized"><img fetchpriority="high" decoding="async" width="1024" height="468" src="https://taodaily.io/wp-content/uploads/2026/08/image-169-1024x468.png" alt="" class="wp-image-24195" style="aspect-ratio:2.1894736842105265;width:624px;height:auto" srcset="https://taodaily.io/wp-content/uploads/2026/08/image-169-1024x468.png 1024w, https://taodaily.io/wp-content/uploads/2026/08/image-169-300x137.png 300w, https://taodaily.io/wp-content/uploads/2026/08/image-169-766x350.png 766w, https://taodaily.io/wp-content/uploads/2026/08/image-169.png 1882w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><a href="https://bitsec.ai/leaderboard">Live Bitsec Dashboard</a></figcaption></figure>
<p class="wp-block-paragraph">Bitsec ran its own agents across the same code and surfaced more than 160, including five criticals the frontier model never flagged.</p>
<p class="wp-block-paragraph">The model found real bugs and described them correctly before it stopped looking, which is exactly the gap continuous testing exists to close.</p>
<h2 class="wp-block-heading">Why a Yearly Audit Is the Wrong Way to Look at Codes</h2>
<p class="wp-block-paragraph">Bitsec argues that <strong>traditional audits are structurally mismatched to how code behaves</strong> over time.</p>
<p class="wp-block-paragraph">A team freezes its codebase, fixes what the report names, and keeps shipping against a snapshot that already went stale since last audit.</p>
<figure class="wp-block-image size-large is-resized"><img decoding="async" width="1024" height="576" src="https://taodaily.io/wp-content/uploads/2026/08/image-170-1024x576.png" alt="" class="wp-image-24196" style="aspect-ratio:1.7777777777777777;width:624px;height:auto" srcset="https://taodaily.io/wp-content/uploads/2026/08/image-170-1024x576.png 1024w, https://taodaily.io/wp-content/uploads/2026/08/image-170-300x169.png 300w, https://taodaily.io/wp-content/uploads/2026/08/image-170-678x381.png 678w, https://taodaily.io/wp-content/uploads/2026/08/image-170-768x432.png 768w, https://taodaily.io/wp-content/uploads/2026/08/image-170.png 1672w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">How Bitsec Moves Differently From Traditional Audits</figcaption></figure>
<p class="wp-block-paragraph">1. Human audits start at $25,000 to $50,000 and climb into the millions on larger codebases</p>
<p class="wp-block-paragraph">2. The review happens once a year at best, and often never happens after that</p>
<p class="wp-block-paragraph">3. The report describes a version of the code that has evolved over time</p>
<p class="wp-block-paragraph">A practical example was when a protocol on the Move blockchain lost $250 million despite the layers of traditional audit it passed. Bitsec later went at that same Move protocol and found the exploit in 10 to 15 minutes on a language it had never trained against.</p>
<h2 class="wp-block-heading">How the Competition Stays Sealed Off</h2>
<p class="wp-block-paragraph">No serious protocol hands a crowd of strangers its private code, which is the obvious objection to decentralized security.</p>
<p class="wp-block-paragraph">Bitsec answers it by never letting the two sides meet, <strong>running the competition on codebases it controls with known exploits planted inside</strong>.</p>
<figure class="wp-block-image size-large is-resized"><img decoding="async" width="1024" height="466" src="https://taodaily.io/wp-content/uploads/2026/08/image-168-1024x466.png" alt="" class="wp-image-24194" style="aspect-ratio:2.1971830985915495;width:624px;height:auto" srcset="https://taodaily.io/wp-content/uploads/2026/08/image-168-1024x466.png 1024w, https://taodaily.io/wp-content/uploads/2026/08/image-168-300x136.png 300w, https://taodaily.io/wp-content/uploads/2026/08/image-168-767x349.png 767w, https://taodaily.io/wp-content/uploads/2026/08/image-168.png 1886w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption"><a href="https://bitsec.ai/agents-status">Bitsec Agents’ Status</a></figcaption></figure>
<p class="wp-block-paragraph">1. <strong>Miners build agents to find planted vulnerabilities</strong> on Bitsec’s own code, never the client’s</p>
<p class="wp-block-paragraph">2. <strong>Agents must find every</strong> critical and high-severity <strong>issue</strong>, and missing one fails the whole run</p>
<p class="wp-block-paragraph">3. Only <strong>winning agents reach client work</strong>, alongside in-house agents hunting novel exploits</p>
<p class="wp-block-paragraph">4. <strong>Findings arrive chained into criticals</strong>, each with a test that proves the vulnerability exists</p>
<p class="wp-block-paragraph">Once fixes go in, everything gets rescanned from scratch, because a fix routinely opens fresh surface area of its own.</p>
<h2 class="wp-block-heading">The Economics That Flip Security Into a Running Cost</h2>
<p class="wp-block-paragraph"><strong>A quality human audit starts around $2,000</strong> per 100 non-test, non-comment lines of code, and climbs from there. <strong>Bitsec charges roughly $250</strong> for that same unit and turns it around in hours or days rather than months.</p>
<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="576" src="https://taodaily.io/wp-content/uploads/2026/08/image-171-1024x576.png" alt="" class="wp-image-24197" style="aspect-ratio:1.7777777777777777;width:624px;height:auto" srcset="https://taodaily.io/wp-content/uploads/2026/08/image-171-1024x576.png 1024w, https://taodaily.io/wp-content/uploads/2026/08/image-171-300x169.png 300w, https://taodaily.io/wp-content/uploads/2026/08/image-171-768x432.png 768w, https://taodaily.io/wp-content/uploads/2026/08/image-171-678x381.png 678w, https://taodaily.io/wp-content/uploads/2026/08/image-171.png 1672w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Human Audit v. Bitsec</figcaption></figure>
<p class="wp-block-paragraph">1. Audits sell in sets of four, since one snapshot is the thing the subnet argues against</p>
<p class="wp-block-paragraph">2. Four audits at $250 per 100 lines cost half of one audit at the bottom of the human range</p>
<p class="wp-block-paragraph">3. The introductory price should roughly double soon, still a quarter of the incumbent at $500</p>
<p class="wp-block-paragraph">4. The real cost line is inference, which keeps falling as cheaper models reach frontier parity</p>
<p class="wp-block-paragraph">At an eighth of the incumbent price, an audit becomes a recurring cost like hosting rather than a capital event braced for once a year.</p>
<h2 class="wp-block-heading">The Buyers Showing Up Weren’t the Ones Expected</h2>
<p class="wp-block-paragraph"><strong>Bitsec launched wanting to audit subnets</strong>, and subnets have mostly not bought, since a team treating its own mechanism as broken feels no urgency about a security budget.</p>
<p class="wp-block-paragraph">What converts instead is the audience already spending $25,000 to $100,000 on audits and needing no convincing the category matters.</p>
<p class="wp-block-paragraph"><strong>Web2 companies now approach the team</strong> unprompted, and the direction of travel points out of crypto toward npm supply chain attacks and AI-written code ar