Cryptobriefing GregoAI Discovers Major Blockchain Vulnerability, Earns $250K Bounty
Article Content
- •Grego AI discovered a critical blockchain vulnerability worth $27.7 million.
- •The company earned a $250,000 bounty, the largest for an AI-discovered flaw.
- •Grego AI's technology uses Deep Invariant Analysis to identify vulnerabilities overlooked by humans.
Grego AI, a cybersecurity startup, has autonomously discovered a critical vulnerability in a major blockchain protocol that could have led to a $27.7 million theft. The company utilized its Deep Invariant Analysis method, which involves scanning entire codebases and deploying sandboxed agents to identify weaknesses. This discovery resulted in a $250,000 bug bounty, the largest ever awarded for an AI-discovered flaw without human intervention. The vulnerability was missed by human auditors and traditional tools, highlighting the effectiveness of Grego AI's technology. The startup plans to expand its services beyond Web3 to include conventional software sectors such as finance and healthcare. Grego AI has already reported vulnerabilities in high-profile ecosystems like Ethereum and Chainlink.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Grego AI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…