Reference
Questions that take more than a news brief.
The desks file what happened. These explain how something works — the subjects that sit between our three domains, where an answer has to cross all of them to be any use.
Smart contract audits: what a report can and cannot tell you
How to read an audit report, what the severity counts actually measure, and why the scope line matters more than the findings.
Updated 28 Aug 20269 min6 questions answered
A smart contract audit is a time-boxed review of a defined set of files by people who did not write them. It produces a list of findings graded by severity, and a record of which ones the client fixed.
Tokenised treasuries: what is actually being tokenised
A share in a fund holding government debt, issued as a token. What that changes, what it does not, and where the risk moved to.
Updated 28 Aug 20269 min6 questions answered
A tokenised treasury is a share in a fund holding short-dated government debt, recorded as a token rather than in a transfer agent's register. The underlying asset is unchanged; what changes is how ownership is recorded and how quickly it moves.
zkML: proving what a model did, without showing it
Zero-knowledge proofs applied to machine learning — what can be proved today, what it costs, and which of the three promises is actually delivered.
Updated 28 Aug 20269 min6 questions answered
zkML means producing a cryptographic proof that a particular model, run on a particular input, produced a particular output — verifiable by someone who sees neither the model nor the input.
Bandwidth DePIN: renting out the connection you already have
The one decentralised infrastructure category that asks for no hardware — what is sold, what it pays in, and how to judge a network before you join it.
Updated 27 Aug 20269 min7 questions answered
Bandwidth DePIN pays people to share the unused capacity of an ordinary internet connection. Buyers pay for distributed access to the public web, and the largest source of that demand is the collection of current data for training and evaluating AI models.
Agent-to-agent commerce: the full stack
What has to be true before one machine can pay another without a human in the loop — and which layer was actually missing.
Updated 27 Aug 20268 min4 questions answered
For one program to buy from another without a person approving it, four things must hold: the price has to be quoted in a form a machine can read, settlement has to cost less than the thing being bought, the spending limit has to be enforced somewhere the agent cannot reach, and the payment has to be attributable afterwards.
Prompt injection: why it has no clean fix
SQL injection has a solution. This does not, and the reason is structural rather than a matter of effort.
Updated 27 Aug 20267 min4 questions answered
Prompt injection is an attack that puts instructions inside content a language model was asked to process, so the model follows the attacker rather than the operator.
KEV vs CVSS: what to patch first
One score tells you how bad a vulnerability would be. The other tells you which ones are being used right now. Only one of them is a priority order.
Updated 27 Aug 20266 min4 questions answered
CVSS scores how severe a vulnerability would be if it were exploited. KEV — the CISA Known Exploited Vulnerabilities catalogue — records which vulnerabilities are being exploited in the wild.
Machine payments: what a finance function needs before it says yes
The protocol question is settled. These are the questions a controller asks next, and the order they get asked in.
Updated 27 Aug 20267 min4 questions answered
A payment an agent makes that cannot be attributed, categorised and reconciled is not a corporate payment. It is an unexplained debit, and no controller approves a category of those.
How to secure an AI agent that can spend money
A control design, not a list of best practices. The threat model is that the agent will be instructed by an attacker, and the question is what that buys them.
Updated 27 Aug 20268 min4 questions answered
Design on the assumption that the agent will, at some point, follow an attacker's instructions. Prompt injection has no clean fix, so a control that depends on the model resisting instruction is not a control.
The AI supply chain: what actually gets attacked
Four layers can be compromised. Only one of them has produced confirmed incidents at scale, and it is not the one the discussion is about.
Updated 27 Aug 20268 min4 questions answered
An AI system inherits four supply chains: software packages, model weights, training and reference data, and the tools the model calls at runtime.
More are being written. Every figure on these pages comes from something we published with a named source, or it is not there — the rules are on the methodology page.