MPC-lab

Market Prices

Coin Price 24h
BTC Bitcoin
$64,100.4 +0.95%
ETH Ethereum
$1,866.79 +0.62%
SOL Solana
$73.7 +0.70%
BNB BNB Chain
$598.9 +1.58%
XRP XRP Ledger
$1.07 -0.17%
DOGE Dogecoin
$0.0700 -0.10%
ADA Cardano
$0.1919 +0.10%
AVAX Avalanche
$6.66 +0.23%
DOT Polkadot
$0.8586 +3.78%
LINK Chainlink
$8.13 -0.29%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{年份}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$64,100.4
1
Ethereum
ETH
$1,866.79
1
Solana
SOL
$73.7
1
BNB Chain
BNB
$598.9
1
XRP Ledger
XRP
$1.07
1
Dogecoin
DOGE
$0.0700
1
Cardano
ADA
$0.1919
1
Avalanche
AVAX
$6.66
1
Polkadot
DOT
$0.8586
1
Chainlink
LINK
$8.13

🐋 Whale Tracker

🔴
0x88ac...9edb
3h ago
Out
2,741.61 BTC
🔴
0x1139...867e
12m ago
Out
4,242.21 BTC
🔵
0x14c0...ec7a
1d ago
Stake
323,754 USDC

💡 Smart Money

0xa6e9...45ab
Market Maker
+$2.5M
61%
0x3753...24d2
Market Maker
+$1.2M
75%
0x9c5c...22e9
Institutional Custody
+$0.5M
81%

🧮 Tools

All →
Research

23,000 Bugs, 126 CVEs, 6% Fixed: Anthropic Just Industrialized Vulnerability Discovery — Crypto Runs on the Damage

0xSam
July 28, 2026. Anthropic becomes CNA number 282. First AI company in history to hold the designation. Coverage called it a milestone. It is not. It is the day vulnerability discovery turned industrial — and the software supply chain beneath crypto was not designed for the output. Project Glasswing surfaced more than 23,000 vulnerabilities in H1 2026. FreeBSD NFS: a 17-year-old remote code execution. OpenBSD: a crash surviving 27 years. FFmpeg: a 16-year flaw. Not lab curiosities. The byproduct of a proprietary Claude model running five million automated test executions against foundational code. The model is unpublished. Anthropic says abuse safeguards are insufficient. Speed is the only currency that doesn't inflate. Anthropic just acquired the printing press. The market has no absorptive capacity for what it produces. Understand the mechanism before trading the narrative. A CVE Numbering Authority is an organization authorized to assign CVE IDs to vulnerabilities in its own products, services, or open-source projects. Historically the list reads like a docket of the obvious: Mozilla, FreeBSD, OpenSSL. The entity that owns the code names its bugs. Anthropic breaks that template. It owns none of the targets it analyzed. It is being granted authority to coordinate disclosure for software it merely audited. That is not ceremonial. That is institutional trust transferred to a model vendor. The underlying registry is drowning. NVD CVE submissions grew 263% between 2020 and 2025. 2026 projections exceed 60,000 entries. The pipeline became the choke point, which is why the CNA program expanded by roughly 150 organizations across 15 countries. Anthropic's designation fits that pattern, plus one destabilizing variable. Every other CNA assigns IDs to bugs that already exist. Anthropic is using AI to manufacture discovery at scale. The historical arc sharpens the difference. Vulnerability discovery used to run on survivor bias and luck. Project Zero, OSS-Fuzz, and the bug-bounty industrial complex professionalized the search — but each still depended on human guesses about where bugs hide. AI collapses that assumption. A model with semantic code comprehension does not search where humans suspect. It searches everywhere, including the 27-year-old code paths no living maintainer has touched. Obscurity no longer counts as security. Here is the cut most coverage missed. FreeBSD, OpenBSD, Linux, and FFmpeg are the substrate under validator nodes, exchange settlement layers, oracle networks, and media pipelines. A 17-year RCE in FreeBSD NFS is not a server-room footnote. It is settlement-layer risk. When an AI model surfaces that bug, the question flips: not "are we exposed?" but "who else has already found this, and how long have they known?" Now the numbers, read slowly. 23,000-plus findings. 126 CVEs published. A 6% fix rate. 94% of everything Glasswing surfaced sits outside the public-and-patched category. Duplicates. False positives. Coordinated disclosure limbo. Or no owner at all — vulnerable code maintained by volunteer projects that never asked for a thousand-bug inbox. That asymmetry is the real story. AI industrialized discovery. Absorption remains artisanal. Human triage, patch authoring, regression testing, release coordination — still handcrafted. The gap between what a model finds in a week and what an ecosystem patches in a quarter is an order-of-magnitude chasm. Timeline data compounds the pressure. In 2018, the median interval between disclosure and weaponized exploitation was 771 days. By 2026, single-digit hours. 28.3% of CVEs are now weaponized within 24 hours of publication. The first day after a CVE appears is not a response window. It is a combat window. A 6% fix rate inside a 24-hour weaponization environment is not a backlog. It is structural exposure. Run the production economics. Five million test executions per half-year is roughly 27,000 runs per day. A top-tier human team executes a few hundred targeted tests per week. The model is exhaustive where humans are strategic. This is a category change, not a productivity gain. Discovery was a boutique service. It is now a batch process. Batch processes reset pricing, expectations, and the balance of power between finder and fixer. Price the raw material. Commercial zero-days historically command six to seven figures depending on target and reliability. AI expands supply without marginal exhaustion — the 23,001st finding costs nearly nothing. That deflates the exploit-pricing curve, unless the finder controls disclosure. Control the CVE pipeline and you control when that supply hits the market, in what form, at what velocity. Anthropic just acquired the closest thing the security industry has to a central bank. The CNA owns the print schedule. My audit history says the bottleneck was never the finding. In 2021 I spent 72 hours straight clustering Sushiswap governance wallets on-chain and published the discovery that a single whale controlled 15% of voting supply before major outlets moved. One person. One wallet cluster. Project Glasswing is that process automated, pointed at every CVE, every patch diff, every line of open-source code written in three decades. It returns 23,000 bugs. I returned one wallet. The lesson: the finding was never the asset. The speed of interpretation was. The 126 CVEs Anthropic published carry more market information than the 22,000-plus held back, because public CVEs enter the risk-pricing mechanism. The 2022 Terra analysis reached the same conclusion in reverse. I reverse-engineered Anchor's yield model and showed the death spiral was mathematically inevitable — a liquidity mismatch, not a code bug. No audit caught it because no auditor modeled the balance sheet under sustained withdrawal stress. An AI reasoning across code and economic state might have. That is the dual-use edge no press release can launder: the capability that finds your bug also finds your exploit path. The smart-contract layer compounds it. Uniswap V4's hooks turned the DEX into programmable Lego, and the complexity scared off 90% of would-be developers — including much of the auditor talent pool. AI-assisted auditing flags reentrancy, oracle manipulation, and access-control failures in minutes. But protocols will drown at remediation because patch-writing capacity has not scaled. I watched that mismatch destroy weak balance sheets during the 2026 MiCA compliance wave: protocols that failed to restructure within six months faced insolvency. The regulation did not kill them. The speed gap between external requirements and internal response did. Read the CNA designation as a governance handoff. The program's original assumption: the party closest to the code names its flaws. Broken. Anthropic is closer to the vulnerability than any maintainer will ever be because it owns the detection machine. The maintainer's role — owning, understanding, fixing the code — is now separated from the finder's role. That fission changes accountability. When a 27-year-old OpenBSD crash surfaces, OpenBSD owns the remediation risk. Anthropic owns the disclosure timing. Neither fully controls the other's half. Structural misalignment produces blame cycles, disclosure disputes, and regulatory intervention within two years. Translate to validator economics. Node operators do not patch fast. The median operator prioritizes uptime over version churn. A 17-year-old FreeBSD NFS bug means most operators never considered that code path. The sequence is not "admin patches in 48 hours." It is "admin confirms exposure, then waits for distribution maintainers to backport a fix." That waiting period is the weaponization window. The 24-hour exploitation statistic is the margin between a model finding a bug and an attacker buying the same bug somewhere else. The downstream is neglected. The NVD backlog is measured in tens of thousands of unanalyzed entries. EPSS exists because raw CVSS scores fail to predict real exploitation. Multiply by AI-scale discovery and prioritization compounds. The market for vulnerability intelligence, automated patch generation, and AI-assisted triage is forming now. The projects that build scoring layers over the flood will capture more value than the finders. Scarcity lives in interpretation, not raw findings. The commercial read is colder than the celebration. CNA designation is not revenue. It is reputation infrastructure. Anthropic gains ID-assignment rights, proximity to MITRE and the standards bodies, and a signal to enterprise and government buyers that it can be trusted with critical code. No audit API shipped. No price tag on Glasswing. The model stays locked because the abuse surface is real. Monetization runs through enterprise trust, government contracts, and the Claude enterprise tier — not a standalone product. The underpriced asset is the data flywheel. 23,000 findings. Five million runs. A training loop ingesting CVE history, patch diffs, and exploit-validation results. Vulnerabilities-to-patches-to-exploits, compounding. Model weights can leak. A flywheel with this velocity cannot be cloned in a quarter. That is the moat. Competition has not matched it. No other major AI lab publicly holds a CNA designation. OpenAI and Google DeepMind run security research; neither published a 23,000-vulnerability half-year figure. Anthropic took the regulatory seal first while keeping the model private. Announce the output. Withhold the machine. That is how you build a moat in plain sight. Regulators are the hidden counterparty. The EU AI Act classifies high-risk systems; vulnerability-discovery models sit squarely in that class. A model that maps 23,000 vulnerabilities maps 23,000 exploit paths. Mandatory risk assessment, access logging, and license regimes are the logical extension of every framework in motion. Anthropic's CNA seat means it will help write those rules. A strategic asset with no income-statement line. My 2025 work on AI-agent economies made the endpoint clear. Autonomous agents already transact on-chain, manage liquidity, and execute strategies without human sign-off. If AI discovers a flaw in the infrastructure those agents run on, remediation escapes human scale. Patching becomes agent-to-agent, or exploitation becomes autonomous. The discovery line never sleeps. Maintainers wake to a thousand-bug inbox and a 24-hour clock. Security is about to face what trading faced when algorithms replaced manual desks: humans become exception handlers, not primary operators. Now the angle the celebratory cycle will not print. This is not a defense story. It is a liability story wearing a defense costume. One confirmed exploit in the wild. "Only one." Reassuring until checked against the timing data. 28.3% of CVEs are weaponized within 24 hours. Attackers do not need Anthropic's model. They need the published CVE, the patch diff, and an exploit generator. Every responsible disclosure inside a 6% fix-rate environment doubles as a public targeting list. The low exploitation count is a before image, not an acquittal. Then the shadow inventory. 23,000 findings. 126 disclosures. The remainder sits in a private database known to a few people. That is precisely the asset class that leaks, sells on black markets, or gets rediscovered by a less scrupulous lab. "We did not release the model" is not a safeguard. Research artifacts, intermediate results, and disclosed CVE patterns all leak methodology. And the structural critique crypto should recognize better than anyone: CNA expansion is framed as decentralizing burden, but the discovery layer is consolidating inside three or four AI labs that decide what the public learns to fear. In 2021 we fought a whale controlling 15% of Sushiswap voting supply. The same concentration now lives in the vulnerability inventory — who holds it, what they release, when. Governance is theater. The disclosure schedule is the power. The next 12 months separate the discovery layer from the remediation layer. Watch for a controlled enterprise audit API from Anthropic — that is the revenue signal. Watch for AI patch-generation startups; a 6% fix rate forces a market into existence. Watch audit firms adopt AI discovery while AI-native security agents price remediation instead of reports. Discovery is now a commodity. Remediation is the bottleneck. The winners close the gap between what the machine finds and what the ecosystem can fix. Speed is the only currency that doesn't inflate. Anthropic just cornered the supply. The question is who builds absorptive capacity before the flood decides for them.