SShortSingh.
Back to feed

Bitget DeFi Protocol Rated Medium-High Risk With $5.9B TVL Under Scrutiny

0
·1 views

A DeFi security assessment dated September 28, 2026, evaluated Bitget, a multi-chain liquidity and derivatives platform currently holding $5.92 billion in total value locked across Ethereum and Layer 2 networks. The protocol received an overall risk rating of 6.8 out of 10, driven by rapid TVL growth of 3.2 times since early 2023 and heavy concentration on L2 chains, which now account for 68% of assets. Auditors identified cross-chain bridge exposure as the most critical vulnerability, with roughly $1.07 billion at risk from potential exploits on Arbitrum and Optimism bridges. Oracle dependency on Chainlink and Pyth also raised concerns, as both feeds share underlying data providers, creating a single point of failure that could affect up to $450 million in leveraged positions. Additional risks include flash-loan-based liquidity drains and governance token mechanics that could be exploited to manipulate on-chain voting outcomes.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Developer builds Rust-native AI agent runtime with unified streaming model

A developer has completed pi-rust, a Rust-based coding agent runtime designed to simplify AI agent construction. The project centers on an agent loop that reads messages, calls a language model, checks for tool calls, executes them, and repeats until completion. A key challenge addressed is normalizing streaming responses from multiple AI providers — including Anthropic and OpenAI — into a single consistent event model. The runtime processes streamed events such as text deltas, tool call deltas, and completion signals in a unified way regardless of the underlying provider. The developer has open-sourced the approach and is inviting feedback from others working on similar multi-provider agent systems.

0
ProgrammingDEV Community ·

Reusing Browser Sessions Instead of Fresh Logins Cuts Automation Flag Rate Dramatically

A developer running browser automation across dozens of accounts found that logging in fresh on every run was the primary trigger for anti-bot detection systems. Switching to persisted browser sessions — saved after a single manual login and reloaded on subsequent runs — reduced failure rates from roughly one in four runs to one in thirty. Anti-bot systems treat repeated fresh logins as suspicious signals, while a reused session mimics the behavior of a returning human user. The developer also found that sharing a session file between accounts caused both to be flagged quickly, emphasizing the need for strict per-account session isolation. Staleness is handled reactively by detecting login redirects or 401 responses, rather than logging in preemptively on a timer.

0
ProgrammingDEV Community ·

13 AI Models Asked to Describe Their Appearance: All Rejected Human Form

A developer posed an identical question to 13 AI models from 10 companies, asking each to describe its own appearance in any form, generating 116 total responses. Not a single model chose a human body, with roughly a third explicitly rejecting human features like faces or limbs. Nine of the first ten models described a glowing network or lattice floating in darkness, typically in blue and gold, while the three newest models — Gemini 3.8 Flash, Grok, and ChatGPT — favoured a translucent glass polyhedron instead. Only Claude Haiku and Claude Sonnet regularly expressed uncertainty about their own nature, while most other models described themselves with full confidence. Separately, several models showed identity confusion when asked their own names without a system prompt, with Kimi K3 identifying itself as 'Claude' in seven of ten answers.

0
ProgrammingDEV Community ·

MCP Servers Explained: Why stdio and Streamable HTTP Beat Deprecated SSE

The Model Context Protocol (MCP) is an open standard that lets AI model hosts like Claude Desktop and Cursor connect to external tools and data through small, controlled server processes. An MCP server wraps APIs, files, or internal services behind a stable interface, acting as a policy layer for auth, rate limits, and access control rather than giving models direct database or shell access. Developers can build a minimal MCP server in Python using the FastMCP library, which uses decorators to define typed tools and resources without writing raw JSON-RPC handlers. MCP supports three transports, but the HTTP+SSE approach has been deprecated as of early 2025, leaving stdio for local use and Streamable HTTP for remote deployments as the two relevant options. Key pitfalls include omitting type annotations and docstrings on tool functions, both of which degrade how well the model understands and invokes available tools.