With the amount of new subnets being added it can be hard to get up to date information across all subnets, so data may be slightly out of date from time to time
Bitsec is a robust ecosystem designed to enhance AI-powered code vulnerability detection. In its early stages, the primary focus of Bitsec will be to assist other Bittensor subnet owners in identifying and rectifying flaws within their incentive mechanisms and smart contract code. By leveraging advanced AI models, it aims to pinpoint vulnerabilities that might otherwise go unnoticed, helping to ensure the security and integrity of decentralised applications and systems.
As Bitsec evolves, it plans to broaden its scope, extending its coverage to various other types of codebases beyond just smart contracts and incentive systems. This expansion will allow Bitsec to serve a wider range of industries and projects, providing comprehensive vulnerability detection and contributing to the creation of more secure and reliable software systems. Through its growing ecosystem, Bitsec will continuously refine its AI-driven tools to stay ahead of emerging threats and provide developers with the resources they need to protect their code and systems.
Bitsec is a robust ecosystem designed to enhance AI-powered code vulnerability detection. In its early stages, the primary focus of Bitsec will be to assist other Bittensor subnet owners in identifying and rectifying flaws within their incentive mechanisms and smart contract code. By leveraging advanced AI models, it aims to pinpoint vulnerabilities that might otherwise go unnoticed, helping to ensure the security and integrity of decentralised applications and systems.
As Bitsec evolves, it plans to broaden its scope, extending its coverage to various other types of codebases beyond just smart contracts and incentive systems. This expansion will allow Bitsec to serve a wider range of industries and projects, providing comprehensive vulnerability detection and contributing to the creation of more secure and reliable software systems. Through its growing ecosystem, Bitsec will continuously refine its AI-driven tools to stay ahead of emerging threats and provide developers with the resources they need to protect their code and systems.
Why Choose Bitsec?
Identify Expensive Vulnerabilities
Spot and prevent code flaws before they affect your subnet.
Ongoing Monitoring
They reassess your code with every update, ensuring continued security.
Rapid Insights
Receive feedback within a day—no need to wait weeks or months.
Budget-Friendly
Eliminate the need for costly human code audits with our AI-driven solution.
Subnet Incentive Mechanism
Since the testnet phase, they have been assessing subnet incentive mechanisms, categorising findings into critical, high, and medium levels for mainnet. These reports will be published regularly, with summaries shared on X and detailed findings available on their website.
Applications
The subnet incentivises miners to develop models and workflows focused on identifying and fixing code vulnerabilities. Through these applications, paying users can access Bitsec’s network of miners. Here are two examples on the roadmap:
Bitsec Scanner: Users provide a GitHub repository, and a request is sent to our community of miners to identify exploits.
Bitsec Hunter: Engage in active bug bounty programs.
Participants
Why Choose Bitsec?
Identify Expensive Vulnerabilities
Spot and prevent code flaws before they affect your subnet.
Ongoing Monitoring
They reassess your code with every update, ensuring continued security.
Rapid Insights
Receive feedback within a day—no need to wait weeks or months.
Budget-Friendly
Eliminate the need for costly human code audits with our AI-driven solution.
Subnet Incentive Mechanism
Since the testnet phase, they have been assessing subnet incentive mechanisms, categorising findings into critical, high, and medium levels for mainnet. These reports will be published regularly, with summaries shared on X and detailed findings available on their website.
Applications
The subnet incentivises miners to develop models and workflows focused on identifying and fixing code vulnerabilities. Through these applications, paying users can access Bitsec’s network of miners. Here are two examples on the roadmap:
Bitsec Scanner: Users provide a GitHub repository, and a request is sent to our community of miners to identify exploits.
Bitsec Hunter: Engage in active bug bounty programs.
Participants
John Yu – Founder
Greg Schwartz – Senior AI Engineer
John Yu – Founder
Greg Schwartz – Senior AI Engineer
A special thanks to Mark Jeffrey for his amazing Hash Rate series! In this series, he provides valuable insights into Bittensor Subnets and the world of decentralized AI. Be sure to check out the full series on his YouTube channel for more expert analysis and deep dives.
Recorded in June 2026, Mark Jeffrey speaks with John Yu of Bitsec (Subnet 60), a cybersecurity subnet that claims to have outperformed Anthropic’s Fable 5/Mythos in a real client-code security test, finding more than 160 vulnerabilities versus roughly 60 from Fable, including critical and high-severity issues that the frontier model missed while still catching everything it found. John explains that Bitsec operates as an always-on AI security army, using a winner-take-all miner competition where participants build agents capable of finding known high and critical exploits under strict time and cost constraints; the best agents are then added to Bitsec’s production stack and run at far greater scale across client codebases. The commercial model is aimed initially at active blockchain teams, charging roughly $1,000–$5,000 per month compared with traditional audits that can cost tens or hundreds of thousands, with an early sales conversion rate of around 70% and a target of 50 paying customers by year-end. John also discusses his own background, including being hacked while working as a smart-contract developer, which led him to explore whether AI could have found the exploit beforehand. The conversation covers Bitsec’s ability to chain multiple smaller weaknesses into more severe exploit paths, its testing of new frontier models as they appear, and examples such as finding hundreds of issues in OpenClaw and submitting 24 fixes. Looking ahead, John says revenue will be used for alpha-token buybacks to keep miners incentivized and continually push the system toward broader exploit coverage, with the ultimate goal of detecting vulnerabilities before malicious hackers do.
Big shoutout to Gordon Frayne for his incredible work on his TAO Pill podcast! His deep dives into Bittensor Subnets break down the decentralized AI landscape like few others can. Head over to his YouTube channel to catch the full series for top-tier analysis and insights.
Recorded in June 2026. Gordon Frayne speaks with John Yu, founder of Bitsec, Bittensor Subnet 60, about using decentralized AI agents to identify software vulnerabilities before malicious actors can exploit them. John explains how his background in software development and smart contracts, including experiencing a costly exploit firsthand, led him to build security benchmarks for AI and eventually launch Bitsec after discovering there was no strong standardized way to evaluate blockchain-focused security agents. The conversation explores how miners are incentivised to build specialized security agents that search codebases for vulnerabilities, with validators testing those agents against known exploit datasets and rewarding those that uncover issues other tools miss. John discusses how Bitsec has already demonstrated strong performance against leading centralized models, including internal testing where its broader agent stack found significantly more vulnerabilities and higher-severity issues than a frontier model when scanning the same codebase. They also cover Bitsec’s commercial strategy, which initially focuses on Web3 teams that already understand the importance of proactive security, with clients paying recurring subscriptions for continuous scanning as their code evolves and as new AI-powered attack techniques emerge. John outlines plans to expand beyond smart contracts into wider Web2 application security, continue improving benchmarks and agent performance, and use commercial revenue for Subnet 60 alpha buybacks so miner incentives remain directly connected to the product’s success. The broader vision is to create an open, continuously improving security network that can outperform traditional static auditing approaches by harnessing specialized miner intelligence to find vulnerabilities that conventional tools and centralized AI systems fail to detect.
We originally designed our auditing around smart contract code. But it was built to reach further, and it does.
Our founder John Yu will share one application that applies specifically to Bittensor IMs at Exploit 2026.
Subnet founders and team devs, you’ll want to tune in for
An underflow bug let attackers credit their own balance far past what they'd actually deposited, on any chain running Cosmos EVM.
Cosmos Labs opened a fix for it in May. They called it resolved.
It wasn't. Four chains got hit by the same bug in August. No warning reached the
Why did Bitsec outperform Fable at finding security exploits?
On the @twistartups podcast, John explained that models have their own personas. Some are good at finding certain bugs and weaker at others.
Bitsec combines a buffet of models with specialized agents and rigorous
"We’re focused on the high value teams that understand the value of security. Teams that already pay twenty thousand to one hundred thousand dollars for security audits." - John Yu
That’s the sweet spot for us now. We can offer a block of four audits for less than the price they
Bitsec announces our newest client.
Talisman
Sentios audited their new wallet extension update and wallet app.
Welcome to Continuous Auditing
@bitsecai $TAO @wearetalisman
We found a critical remote code execution vulnerability in an open source project. Reported and patched.
If an attacker gets basic access that way, they can run any command directly on the machine with no way to stop them.
Full compromise. Machine and everything on it.
Same