Dev.to
7/4/2026

We open-sourced our security audit
Short summary
MarketNow, an AI agent commerce platform, published a security audit revealing 4 critical vulnerabilities in its USDC payment system—mandate bypass, transaction reuse, amount validation, and sender validation—all discovered before launch and fixed. The team open-sourced the audit methodology (Sentinel L1.5/L1.6/L2), passed load tests at 200 concurrent users with 0% errors, and commits to independent third-party review and smart contract escrow by Q1 2027.
- •MarketNow patched 4 critical payment vulnerabilities before launch: mandate spend bypass, USDC txHash reuse, amount range-check flaw, missing sender validation
- •Full audit, fixes, and security methodology (Sentinel L1.5/L1.6/L2) open-sourced; zero errors at 200 concurrent requests, zero npm vulnerabilities
- •Principles codified: fail-closed over fail-open, exact-match over range-check, validate sender identity; third-party audit and on-chain escrow on roadmap
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



