Skip to content

language

Solidity

Contract language in which developers must otherwise implement P-256 verification at high gas cost absent a precompile.

Current stories

build1 publisher

Cantina's open-weights exploit model ran a 60-task security eval for $2.38

Cantina released apex-flash-1, an open-weights vulnerability-research model it says solved 40 of 60 tasks for $2.38, against $74.68 for Claude Opus 5 High. There is no hosted endpoint, so teams download the 321-billion-parameter weights, pay for their own inference and verify the numbers themselves.

Publishers:runtimewire.com

Reality

Evidence45
Adoption
Insufficient
Hype gap+35
Incentives70
Confidence40
security1 publisher

SleepyDuck operator re-lists fake Solidity extensions on Open VSX hours after a takedown

Pluto Security says the SleepyDuck operator re-listed fake Solidity extensions on Open VSX within hours of a takedown, in a stage it calls EtherDuck. Each wave stayed up about 19 hours, long enough for a single install to leave persistent access that the takedown did not remove.

Publishers:pluto.security

Reality

Evidence55
Adoption
Insufficient
Hype gap+15
Incentives60
Confidence50
build1 publisher

ERC-3643 code at version 4.1.3 checks compliance on mints the standard exempts

Pharos Production found ERC-3643's pinned token calls canTransfer inside mint, though the standard says minting bypasses compliance. Under that code, a mint to a wallet the compliance modules reject can revert, so issuers working from the written text have two behaviors to reconcile first.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap0
Incentives35
Confidence55