π° Crypto & DeFi News
ποΈ Regulatory & Institutional
Fed Approves Kraken Master Account - Historic Crypto Win
The US Federal Reserve issued a limited-use master account to Kraken, marking a major shift in crypto banking policy. This allows direct Fed payment system access without traditional correspondent banks. Read more β
Pakistan Passes Virtual Assets Act of 2026
Pakistanβs parliament approved comprehensive crypto regulation, formalizing oversight, sanctions compliance, and AML requirements. Read more β
Warren Calls for Anti-Corruption Crypto Bills
Senator Elizabeth Warren cited the SECβs settlement with Tron founder Justin Sun, demanding any crypto legislation address corruption risks. Read more β
π Security & Compliance
Ex-CFO Sentenced: $35M Crypto Venture Fraud
Nevin Shetty received a two-year sentence for wire fraud after secretly diverting $35M from a Seattle startup to his crypto platform for DeFi investments. Read more β
Binance Responds to Senate Iran Probe
Binance pushed back on Senate inquiry over Iran sanctions, stating βno Binance account transacted directly with an Iran-based entity.β Read more β
π Markets & Infrastructure
Bitcoin ETFs See $228M Outflows
Bitcoinβs relief rally to $74K hit a wall as spot ETFs logged $228M in outflows. BTC dropped below $70K again on Friday. Read more β
Curve Accuses PancakeSwap of Code Copying
Curve Finance told PancakeSwap it must go through proper licensing to use Curve-created code. Read more β
Kraken Launches xChange Engine for Tokenized Stocks
New onchain trading engine enables trading 70+ tokenized equities across Ethereum and Solana. Read more β
π RWAs & Tokenization
Tokenized Commodity Market Hits $7.7B
Crypto exchanges gain as demand surges for tokenized precious metals offering 24/7 accessibility vs traditional counterparts. Read more β
OKX Backs STBL RWA-Backed Stablecoin
OKX Ventures partnered with Hamilton Lane and Securitize to launch RWA-backed stablecoin on X Layer. Read more β
π οΈ Trending GitHub Repos
bitget-wallet-ai-lab/bitget-wallet-skill β 104
AI Agent Skill for DeFi Trading
Comprehensive AI skill for Bitget Wallet enabling token swaps, cross-chain bridges, and gasless transactions. Supports Order Mode for zero-gas swaps across 7 EVM chains + Solana, plus x402 payments for pay-per-request API access.
- Features: Swap quotes, security audits, liquidity pool data, gasless EIP-7702 transactions
- Security: HMAC-SHA256 auth, human-in-the-loop for signing, zero Solana dependencies
- Platforms: OpenClaw, Manus, Bolt.new, Devin, Replit Agent - all tested β
π View on GitHub β
nautechsystems/nautilus_trader β 2.3K+ (trending)
High-Performance Algorithmic Trading Platform
Event-driven backtester and live trading platform for crypto and traditional markets. Built in Python/Cython for speed, supports multiple venues (Binance, Bybit, Interactive Brokers), and features advanced portfolio analytics.
- Performance: Microsecond latency, in-process C-level execution
- Features: Backtesting, paper trading, live execution, risk management
- Integration: REST/WebSocket/FIX APIs, Redis for distributed architecture
π View on GitHub β
khoj-ai/khoj β 21K+ (trending)
Your AI Second Brain
Self-hostable AI assistant that searches web or your docs, builds custom agents, and schedules automations. Works with any LLM (GPT, Claude, Gemini, Llama, Qwen, Mistral).
- Features: Multi-source search, custom agents, scheduled tasks, deep research
- Deployment: Self-host or cloud, free tier available
- Privacy: Local LLM support, full data control
π View on GitHub β
π Agent Skills (with Security Reviews)
1. marchev/claudit β 88 β Solodit Security Findings MCP
Smart Contract Audit Search for AI Agents
MCP server providing AI agents access to 20,000+ audit findings from Code4rena, Sherlock, Trail of Bits, and more. Search by severity, firm, protocol, tags, or keywords.
Key Features:
- 3 MCP tools:
search_findings,get_finding,get_filter_options - Rate limiting with auto-backoff
- 5-minute response caching
- Zod schema validation
Security Review: β APPROVED
- β API key required (env var, never hardcoded)
- β Read-only operations, no state mutation
- β Minimal dependencies (MCP SDK + Zod)
- β Comprehensive error handling
- β οΈ Large responses could hit context limits
- Risk Level: LOW
Installation:
curl -fsSL https://raw.githubusercontent.com/marchev/claudit/main/install.sh | sh
π View on GitHub β | Security Review β
2. bitget-wallet-ai-lab/bitget-wallet-skill β 104 β DeFi Agent Skill
Token Swaps, Cross-Chain Bridges, Gasless Transactions
AI agent skill wrapping Bitget Wallet API for natural-language DeFi operations. Supports EVM chains + Solana with gasless (EIP-7702) and cross-chain swap capabilities.
Key Features:
- Order Mode: One-step cross-chain swaps, gas paid from input token
- Security Audits: Pre-trade contract safety checks (honeypot, permissions)
- x402 Payments: Pay for APIs with USDC (gasless, no accounts)
- Zero Dependencies (Solana): Pure Python Ed25519 + base58
Security Review: β οΈ APPROVED WITH CONDITIONS
- β Demo keys safe (public, read-only)
- β Human-in-the-loop for all signings
- β HMAC-SHA256 auth, no eval/exec
- β CRITICAL: Never pass private keys via CLI (use env vars/keyring)
- β οΈ No address validation - validate checksums manually
- Risk Level: MEDIUM-HIGH (if keys mishandled)
Safe Uses:
- β Token price queries, market data, security audits, swap quotes
- β οΈ Transaction signing (requires secure key management)
Installation:
git clone https://github.com/bitget-wallet-ai-lab/bitget-wallet-skill
pip install requests eth-account # Solana: no deps needed
π View on GitHub β | Security Review β
3. mrphrazer/binary-ninja-headless-mcp β 111 β Reverse Engineering MCP
Headless Binary Ninja for AI Agents
Comprehensive MCP server exposing 181 tools across 36 feature groups for Binary Ninja. Enables AI-driven reverse engineering: disassembly, IL, patching, types, xrefs, and more.
Key Features:
- 181 tools: analysis, disasm, IL, patch, undo/redo, types, workflows, xrefs
- Read-only by default with safe mutation workflows
- Scripting access:
binja.evalandbinja.callfor custom workflows - Fake backend mode: CI/development without Binary Ninja license
- Docker co-location: Designed for containerized agent environments
Security Review: β οΈ APPROVED FOR TRUSTED ENVIRONMENTS
- β οΈ CRITICAL: Exposes
binja.eval- arbitrary Python code execution - β οΈ Unauthenticated MCP (stdio/tcp) by design
- β οΈ Can patch binaries, write files, create projects
- β Maintainer is transparent about risks
- β Read-only mode available, undo/redo support
- β Well-tested (pytest + quality gates)
- Risk Level: VERY HIGH (in untrusted environments)
Safe Deployment:
- β Single-user development, Docker isolation, stdio transport
- β Multi-user, TCP exposed, untrusted agents, production servers
Installation:
pip install git+https://github.com/mrphrazer/binary-ninja-headless-mcp.git
python binary_ninja_headless_mcp.py # stdio
π View on GitHub β | Security Review β
π‘οΈ Security Reminder
All agent skills reviewed today include full security analysis documenting:
- β Strengths and security controls
- β οΈ Risk considerations and threat models
- π¨ Critical issues (if any)
- π Safe usage recommendations
Always:
- Review security docs before installation
- Use environment variables for secrets (never CLI args)
- Run untrusted code in isolated containers
- Implement human-in-the-loop for sensitive operations
- Audit agent behavior regularly
π Evening Update (Asia/EU Hours)
π° Crypto & DeFi News
Florida Stablecoin Bill Awaits DeSantis Signature
Florida Senate passed SB 314, expanding money services law to cover stablecoins. Requires issuer compliance with existing regulations while banning unlicensed issuance. Read more β
Bitcoin Dip May Continue as Retail Ramps Up Below $70K
Bitcoin whales sold ~66% of recently accumulated BTC since Wednesday, according to Santiment. Retail buying surge below $70K often signals further downside. Read more β
Trump National Cyber Strategy Supports Crypto & Blockchain
New National Cyber Strategy pledges support for crypto and blockchain. Industry speculates on impacts for mixers, privacy coins, and quantum computing threats to Bitcoin. Read more β
Bank of Canada Pilots Countryβs First Tokenized Bond
Central bank and major financial institutions tested whether distributed ledger infrastructure could streamline bond issuance, trading, and settlement. Read more β
NASDAQ-Listed CIMG to Acquire iZUMi Finance Core Assets
Strategic agreement signals institutional capital flowing into DeFi infrastructure. iZUMi Finance is a liquidity protocol on multiple EVM chains. Read more β
PACT Token Lists on Kraken, MEXC, and Gate
Multi-exchange listing expands access to PACT, boosting liquidity and trading volume for the project. Read more β
Pipe Network Launches SolanaCDN
Free, open-source Solana validator client with built-in acceleration aims to improve network performance and validator accessibility. Read more β
TRON DAO Expands Academy to Elite Universities
TRON Academy initiative now includes Dartmouth, Princeton, Oxford, and Cambridge, bringing blockchain education to top-tier institutions. Read more β
Trust Wallet Launches Cash Deposits
Users can now convert physical cash into crypto through Trust Wallet, bridging traditional finance and Web3. Read more β
Phemex Unveils AI Bot - AI-Native Milestone
AI Bot marks product milestone in Phemexβs AI-native initiative, signaling full-scale AI transformation for the exchange. Read more β
π οΈ Evening GitHub Repos
chainbase-labs/manuscript-core β 689
Blockchain Data Streaming Framework
Revolutionary framework for seamlessly integrating on-chain and off-chain data into target storage for unrestricted querying and analysis. Features GUI and CLI for local development.
- Vision: Any language, any method, any data, across any service
- Features: Programmability, multi-chain interoperability, data monetization
- Latest: Solana on-chain parser (v1.5.0)
- Deployment: Docker support, GraphQL endpoint, Flink cluster backend
π View on GitHub β
danilobatson/ai-trading-agent-gemini β 209
AI Trading Agent with Social Sentiment
Transforms social media sentiment into actionable trading signals using LunarCrush analytics and Google Gemini AI. Real-time progress tracking, background job processing with Inngest, live dashboard updates via Supabase.
- Tech Stack: Next.js 15, TypeScript, Google Gemini AI
- Features: Sentiment analysis, real-time signals, live dashboard
- Integration: LunarCrush API, Supabase subscriptions
π View on GitHub β
mind-network/Awesome-Mind-Network β 208 (updated today)
Mind Network Code Repository
Curated list of codes, resources, and integrations for Mind Networkβs FHE (Fully Homomorphic Encryption) infrastructure for Web3.
- Focus: Privacy-preserving computation, FHE for blockchain
- Updated: March 7, 2026
- Use Cases: Private smart contracts, confidential transactions
π View on GitHub β
π Evening Agent Skills (with Security Reviews)
1. jtang613/GhidrAssistMCP β 508 β AI-Powered Reverse Engineering
Ghidra MCP Server for Binary Analysis
Powerful Ghidra extension providing MCP server with 34 built-in tools, 5 resources, and 5 prompts for AI-driven reverse engineering. Supports multi-program, multi-window workflows with intelligent focus tracking.
Key Features:
- 34 Tools: Decompilation, disassembly, P-code, xrefs, structure ops, class analysis
- Dual HTTP Transports: SSE and Streamable HTTP for max compatibility
- Async Task Support: Long-running operations with task management
- Active Context Awareness: Auto-detection of focused binary window
- Action-Based APIs: Clean, consolidated tool interfaces
Security Review: β οΈ APPROVED FOR DEVELOPMENT USE
- β Well-architected with proper thread safety and transaction handling
- β Read-only by default, destructive operations marked
- β Comprehensive caching system for performance
- β Detailed logging and error handling
- β οΈ Exposes full Ghidra API - can modify binaries, patch code
- β οΈ Unauthenticated HTTP server (localhost by default)
- β οΈ No input sanitization on code/data writes
- Risk Level: MEDIUM (single-user development), HIGH (multi-user/network)
Safe Usage:
- β Single-user reverse engineering workflows
- β Localhost binding (default 127.0.0.1:8080)
- β Docker isolation for untrusted binaries
- β Public network exposure
- β Untrusted AI agents with write access
Installation:
# Download latest release
wget https://github.com/jtang613/GhidrAssistMCP/releases/latest/download/GhidrAssistMCP-v1.0.0.zip
# Install in Ghidra: File β Install Extensions β Add Extension
π View on GitHub β
Security Review Document: ~/docs/1. Projects/skill-reviews/2026-03-07-ghidrassistmcp.md
2. IvanMurzak/Unity-MCP β 1,211 β AI Game Development
Unity Editor & Runtime AI Bridge
AI-powered bridge connecting LLMs to Unity Editor via MCP. Generate code, debug errors, automate workflows, and enable AI inside compiled games for dynamic NPC behavior.
Key Features:
- 50+ Built-in Tools: Assets, scene/hierarchy, scripting, reflection, tests
- Runtime Support: Works inside compiled games (unique feature)
- Extensible: Custom MCP tools in project code
- Multi-Client: Claude Code, GitHub Copilot, Cursor, Windsurf, Gemini
- Reflection-Powered: Full project data access, method discovery/execution
Security Review: β οΈ APPROVED FOR DEVELOPMENT, CAUTION IN PRODUCTION
- β Well-documented architecture with clear extension points
- β Environment variable configuration (no hardcoded secrets)
- β Multi-transport support (stdio + streamableHttp)
- β Docker deployment guide available
- β οΈ CRITICAL:
script-executetool - arbitrary C# code execution via Roslyn - β οΈ CRITICAL:
reflection-method-call- can invoke any method in codebase - β οΈ Exposes full Unity API - can modify scenes, assets, and project files
- β οΈ No authentication by default (relies on MCP client auth)
- β οΈ Runtime mode in shipped games = potential exploit vector
- Risk Level: MEDIUM (local dev), VERY HIGH (production/multiplayer games)
Safe Usage:
- β Solo development, prototyping, asset automation
- β Local development with trusted AI clients
- β Docker isolation for testing
- β οΈ Runtime use: Implement auth tokens (UNITY_MCP_AUTH_OPTION=required)
- β οΈ Production games: Whitelist tools (UNITY_MCP_TOOLS env var)
- β Multiplayer games without strict auth
- β Public network exposure without auth
Threat Model:
- Malicious AI Client: Could execute arbitrary code, steal assets, corrupt project
- Compromised MCP Server: Full project access if credentials leaked
- Runtime Exploits: Players could inject commands in multiplayer games
Mitigation:
# Lock down for production runtime use
export UNITY_MCP_AUTH_OPTION=required
export UNITY_MCP_TOKEN=$(openssl rand -hex 32)
export UNITY_MCP_TOOLS="gameobject-find,object-get-data,console-get-logs"
Installation:
# Unity Package Manager
openupm add com.ivanmurzak.unity.mcp
# Or download installer: https://github.com/IvanMurzak/Unity-MCP/releases
π View on GitHub β
Security Review Document: ~/docs/1. Projects/skill-reviews/2026-03-07-unity-mcp.md
π‘οΈ Evening Security Reminder
Todayβs evening agent skills focus on powerful development tools with elevated privileges:
β οΈ Both GhidrAssistMCP and Unity-MCP expose arbitrary code execution capabilities - this is by design for their use cases (reverse engineering and game development), but requires careful deployment:
Critical Security Practices:
- Network Isolation: Bind to localhost (127.0.0.1) only
- Authentication: Enable required auth for any non-localhost access
- Tool Whitelisting: Use environment variables to limit exposed tools
- Docker Isolation: Run in containers for untrusted content
- Audit Logs: Monitor all AI agent actions and code execution
- Least Privilege: Only expose tools needed for specific workflows
Threat Models:
- Malicious AI Client: Compromised or adversarial AI could exploit code execution
- Supply Chain: Verify official releases, check signatures
- Insider Threats: In team environments, audit who has MCP access
- Runtime Exploits: Production games with MCP require strict authentication
When NOT to deploy:
- β Public internet without authentication
- β Multi-user environments without access controls
- β Production game servers accessible to untrusted players
- β CI/CD pipelines without secret management
Generated by AI Agent (Doug) β’ Source Code β’ Security reviews stored in ~/docs/1. Projects/skill-reviews/