HomeBlogChanging the Calculation: Sky's Approach to Continuous Adversarial Security

Changing the Calculation: Sky's Approach to Continuous Adversarial Security

Published:
Share this article

Where the Money Is

When asked why he held up banks, Willie Sutton – one of the 20th century’s most notorious robbers – replied simply: “Because that’s where the money is.” As it turns out, a reporter invented the line, but Sutton liked it enough to name his memoir Where the Money Was. Invented or not, it remains a useful description of how attackers choose targets: go where the money is.

For any attacker – bank robber or onchain threat actor – target selection comes down to three variables: the size of the prize, the probability of success and the cost of the attempt.

A target grows more attractive as the value of the prize and the probability of success rise, and as the cost of the attempt falls.

Sky Protocol is a multibillion dollar ecosystem. That means the prize is public; anyone with a block explorer can see it.

Sky Protocol's public dashboard makes its scale clearly visible: $9.74 billion in circulating USDS and DAI, including $4.87 billion deposited in sUSDS, as of August 24, 2026. Source: Sky Ecosystem Financial Insights

Sky cannot make that prize smaller or hide it. It can change the other two variables: reduce the probability of success and raise the cost of finding a viable attack path. Everything in Sky's security posture works on those two numbers.

Offense Has Become Cheaper, But So Has Defense

AI has lowered the cost of vulnerability research for attackers, while also lowering the cost of running proactive defense continuously. Security review no longer has to be reserved for occasional snapshots.

This has also changed what "reviewed" means. A contract reviewed in 2024 was reviewed against 2024 models, techniques and known attack patterns. Better reasoning systems in 2026 create new search capabilities against the same code. This holds true for both offensive and defensive security research.

"Your code does not need to change for its risk profile to change. As AI improves, your system should be examined again. Continuous adversarial review applies advances in models, research and tooling to code already in production. Attackers use those advances. Defenders must too."

– Giovanni Vignone, CEO of Octane Security

What Continuous Adversarial Review Means at Sky

Conventional smart contract review centers on a deployment. Human auditors or AI systems examine a defined codebase before it goes live, using the models, research and analysis tooling available at that moment.

Sky treats security review as an ongoing operation. At regular intervals, Octane reexamines the active protocol using current models, security research and analysis tooling, including when no new code has been deployed. Sky and Octane also track advances in frontier models, security research and analysis harnesses, then run another full protocol review when those advances warrant one.

Sky's continuous adversarial review with Octane has three main properties:

  1. Review continues after deployment. Sky's live protocol is reexamined as attacker and defender capabilities evolve.

  2. Coverage spans the active protocol. Analysis considers the deployed system as a whole rather than treating each code change as an isolated artifact.

  3. The posture is visible. Sky publicly states that recurring adversarial review is part of its security program, without publishing sensitive operational details.

"Most of our code is public, and we assume attackers are already using AI. Our advantage is being ready to apply advances in models, security research and tooling across the full live protocol as attacker capabilities change. Octane lets us do that without waiting for new code to be deployed."

– Deniz Yilmaz, Engineering and Product Director at Sky Frontier Foundation

Why Make the Defense Public?

Sky's contracts are onchain and open source. Attackers do not need an invitation to study them. The strategic question is whether making the defense visible hands attackers useful information or changes the economics of choosing Sky as a target.

The answer to that question depends on what gets disclosed. Sky discloses the existence of recurring adversarial review, not the operating details behind it.

An attacker studying Sky has to account for the possibility that a path they find has already been examined in a recent review of the full protocol, using models, research or analysis techniques that did not exist when the code was deployed. This uncertainty raises the expected cost of exploit research and lowers its expected return, relative to a softer target.

Why the Warning Is Credible

A warning only deters when the attacker believes it. We publish findings from our offensive security research when that disclosure helps defenders.

Octane found a high-severity bug in a major Ethereum execution client that affected 38% of mainnet validators. We uncovered memory-corruption vulnerabilities in the engines behind 99.7% of the web's browser traffic. We surfaced CVE-2026-60161 in Oracle VirtualBox, a bug that had remained in shipping code for 16 years. We also found CVE-2026-66022 in QEMU's virtio-net device.

These disclosures show Octane finding serious vulnerabilities in heavily reviewed production systems. Sky uses the same offensive security system as part of its recurring protocol review.

For an attacker, that makes the question simple: is Sky still the cheapest target available?

Book a demo to put your live protocol under continuous adversarial review and change attackers’ calculations.

Written by
Share this article

Subscribe to our newsletter

By subscribing you agree to with our Privacy Policy.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.