
Scaling Long-Horizon Coding Agents on Apple and Coinbase Repositories
Three-day diary of a long-horizon coding agent deployed against Apple and Coinbase repositories.
Technical deep dives, product updates, and real-world case studies from the KAI team.

Three-day diary of a long-horizon coding agent deployed against Apple and Coinbase repositories.

Kai Agent discovered a high-severity access control bypass in StakedUSDeV2 allowing blacklisted users to withdraw funds

Kai discovered two medium-severity vulnerabilities in Morpho Vault V2: an access control bypass in forceDeallocate and a revoke liveness issue when curator is set to zero.

Kai Agent discovered two vulnerabilities in the Tempo protocol: a high-severity missing expiry check in AccountKeychain and a low-severity front-running issue in ValidatorConfig.

Discover how AI-powered security agents are changing the game for smart contract auditing, finding vulnerabilities faster and more accurately than traditional methods.

A deep dive into how security invariants work and why they're the key to finding the most dangerous smart contract vulnerabilities.

Learn how AI security agents go beyond detection to generate working proof-of-concept exploits, eliminating false positives.

Understanding the financial incentives behind blockchain attacks and how proper security investment protects your protocol.

Best practices for integrating security into every stage of your smart contract development lifecycle.
The performance ceiling of your software is way higher than you think.
Kai scored 64.2% Detect Recall on OpenAI's EVMBench, 19 points ahead of the next best system, with no Solidity-specific tuning.
Connect Claude Desktop, Cursor, VS Code, or any MCP client to scan code, review vulnerabilities, run evolutions, and manage your workspace.
A critical ERC-6492 verification flaw that lets attackers forge payment authorizations, confirmed as a valid finding by Coinbase's bug bounty.
Kanban cards and exploit details now surface what matters most.
A step-by-step wizard to set up your workspace, connect integrations, and start scanning.
Import GitHub repos, choose your scan depth, and manage everything from the dashboard.
See exactly what KAI's agents are doing while they scan your code.
See which LLM configurations find the most vulnerabilities in real smart contract bounties.
An XSS vulnerability found by KAI has been patched in Apple's open-source tooling, reviewed and merged by Apple staff.
Generate shareable audit reports from any completed scan.
Export findings directly to Linear alongside GitHub and Jira.
Get notified when your security scans finish.
KAI now connects directly to your issue tracker.
We shipped intelligent deduplication for KAI's security findings.
Triage vulnerabilities the way you manage tasks.