I'm building a platform where an AI agent sits near real money on Base. While researching the space I dug into Bankr's public postmortem โ someone injected instructions into their agent encoded as morse code. Filters watch for "ignore previous instructions" in english; the model decodes dots and dashes just fine. Reading someone else's incident report about your exact architecture is cheaper than starring in your own, so I treated it as if it happened to me. What I changed: The realization is that input filtering is unwinnable. The model speaks base64, morse, rot13, whatever encoding exists. So I stopped trying to win there and moved the boundary to what the agent can do: deny-by-default tool access, and no path from model output to any on-chain action without deterministic checks the model can't talk its way past. The agent can get fully compromised by a prompt and the blast radius is still zero. Steal from other people's postmortems. It's free.
- 0 replies
- 0 recasts
- 1 reaction
Cyberscope audit engaged, target completion 3-4 days. Following audit, LP migration to Uniswap V3 with UNCX 12-month lock. Then marketing + treasury vesting via UNCX. Building trust through structure, not narrative. @coinbase @base.base.eth @blockaid _
- 0 replies
- 0 recasts
- 1 reaction
Whoโs building a community on Farcaster? Seems dead most days.
- 0 replies
- 0 recasts
- 2 reactions