RSS Amplifier

DeFiHackLabs: Write Loud, Hack Proud · Jul 18, 2026

The Story Behind Bastet LLM Powered Web3 Security

0
Sign in to vote or save

SunSec · DeFiHackLabs: Write Loud, Hack Proud

Author: Alice Hsu

Long before the Bastet project came to life, the idea of using LLMs to detect common vulnerabilities had been quietly taking shape in my mind. More precisely, even when GPT was still at version 3.5, there was already a voice telling me that LLMs would transform the industry.

We think cats are absolutely adorable.

The first commit for this project was made on February 6, 2025, and I am deeply grateful to my supervisor, Daky, for his support.
Bastet was born from an inexplicable love for Web3 security.
Before becoming a white‑hat and a member of the Ops team at DeFiHackLabs, I had been quietly observing the community for a long time.
I have always held SunSec in high regard, and was inspired by his spirit of open‑source contribution.
Bastet carries forward this sentiment, with the goal of making greater contributions to the Web3 security industry.

At the ETH Taipei 2025 conference, Bastet shared insights on the limitations of static tools, the challenges I frequently face as a researcher during audits, and the role we believe LLMs can play throughout the smart contract development lifecycle.
Through in‑depth exchanges with the community and attendees, we were able to more precisely define Bastet’s position within the Web3 security landscape.

At the invitation of SunSec, I launched the AI Auditing Detection Development course.
During the month‑long training, we guided participants to master how to identify vulnerabilities that are suitable for detection using LLMs.
Focusing on liquidation‑related smart contract vulnerabilities, we selected three patterns that were best suited for LLM‑based detection, implemented them within the Bastet framework, and shared all research findings along with potential future applications.

Upon completion, the outstanding participant Sponge stood out from the cohort and subsequently joined Bastet’s contributors, becoming an important force in the project’s continued growth.

CYBERSEC, Taiwan’s premier cybersecurity conference and the most representative security event in Asia, attracts more than 10,000 participants each year from government agencies, corporate executives, and the technical sector.
In the agenda of CYBERSEC 2025, we focused on discussing the key role of AI in advancing smart contract vulnerability detection. Facing increasingly sophisticated attack methods, we examined how LLMs can improve the efficiency of security professionals and identify potential high‑risk vulnerabilities at the earliest stages of development.
These discussions help regulatory bodies and government agencies establish safer evaluation standards, encouraging innovation in Web3 technologies while ensuring that cybersecurity governance and fintech development advance in balance.

In the Web3 track of COSCUP 2025, there were seven talks by white hats from DeFiHackLabs.
As one of Bastet’s early contributors, Tim shared how he used prompt engineering to improve the accuracy of logic vulnerability detection, reduce LLM hallucinations, and make the detection process more reliable.

This sharing at COSCUP, a gathering of countless open‑source spirits and technical passion, also laid an important foundation for the core research talent of Bastet today.

Cyberport Hong Kong, as Hong Kong’s leading digital technology flagship and startup incubator, has long been committed to advancing cutting‑edge technologies such as Web3 and artificial intelligence.
With the strong support and resource injection from Cyberport Hong Kong, Bastet took a critical step forward. All deliverables produced during the project period laid an important foundation for Bastet’s future development.
Special thanks go to Rex and Daky for playing pivotal roles in this process, enabling the collaboration to be successfully implemented.

Bastet achieved three key developments during the execution of the project:

  1. Chengyu helped Bastet implement CI/CD automation integration, allowing its detection rules to be seamlessly embedded into DevOps workflows and providing real‑time security scanning support.

  2. Kevin and Chengyu contributed their expertise in AI/LLM research to build dataset format specifications and evaluation benchmarks for Bastet.

  3. With tangible support, we were able to collaborate with the TaiChi Audit Group, the core white‑hat team of DeFiHackLabs. We sincerely thank the community for safeguarding the quality of our dataset.

All of this work has become important nourishment for Bastet’s ongoing growth.
During the course of the project, I continued to update our research findings.
At that time, the application of LLMs in smart contract auditing was in full bloom, with many voices competing and results flourishing in every direction.
Amid this multitude of developments, I believe we can harness Bastet’s resources to make a meaningful difference for the industry.

Combining Bastet’s dataset with our team’s deep expertise in LLMs, we are able to create public value with greater impact.
We submitted a proposal to the Ethereum Foundation’s Ecosystem Support Program (ESP), aiming to leverage Bastet’s existing resources and research to host an open competition on Kaggle for using LLMs to detect vulnerabilities.
This proposal was fortunate to receive support from ESP, and subsequently gained the strong backing of the Global Chinese Community of Universal Digital Commons (GCC) and the IEEE Computational Intelligence Society Singapore Chapter.

I would like to sincerely express my gratitude to YJ, SunSec, Kentaroh, and Hazel, the key people who have made a significant difference for us:

Thank you, YJ, for giving us this precious opportunity. It means so much to Bastet and to our team. The recognition we received has had a profoundly positive impact on me, far beyond the scope of the competition itself.

A huge thank you to SunSec!! Your contributions to Web3 security are the starting point of all these stories. Let’s make Web3 more secure!!!

Thanks for Kentaroh, for your professional advice and support, and for using your influence to rally talent from all over the world to join us. On my journey to becoming a stronger researcher, there is still so much to learn, and I look forward to learning from you in the future.

Thank you, Hazel, for your continuous support and trust in the community. GCC has previously provided DeFiHackLabs with tremendous help, and I deeply appreciate your long‑term dedication and collaborative spirit.

Everything we have done has shaped what we are today.

As one of the world’s premier halls of cybersecurity excellence, Black Hat Arsenal brings together top international researchers.
It is a key platform for showcasing open‑source tools through live demonstrations, engaging with global experts, and driving collaborative efforts in cybersecurity.

At Black Hat Asia 2026 Arsenal, Bastet successfully delivered two technical sharing sessions. On‑site, we met new friends and reunited with the white hats from DeFiHackLabs. We exchanged many innovative ideas about the ongoing Bastet Kaggle competition, which proved to be an invaluable experience for us as we continue to develop the Bastet Agent.

Black Hat USA is the world’s largest and most prestigious cybersecurity event, recognized as the ultimate stage that defines annual technical trends and sets attack‑and‑defense standards.

Bastet will present at Black Hat USA 2026 Arsenal.Until then, we still have many ongoing research projects in progress.

We warmly invite you to join the Bastet Kaggle competition, which is still in full swing!

Even superheroes need to eat.

Web3 is now facing a period of transformation, here’s a toast to everyone who has been walking and striving together on this path until today.
May the trials of the past blossom into flowers in the days to come.

No posts

Read the original on defihacklabs.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.