August 5 update: Bitsec’s public repository has not shown recent subnet code activity, while its documentation still describes the contest surface. The mechanism remains interesting. Fresh code, round results and customer evidence are now the proof points to watch.
Bitsec SN60 published an article called “How We Bake The Cake.”
The title is playful, but the subject is serious. Bitsec is explaining how it wants code security to move through models, specialized agents, screeners, validators and public scoring.
The public preview and cover point to model mixing, recursive learning loops and rapid iteration. Bitsec says the stack keeps improving against competitors and bad actors.
For Bittensor, the useful read is the mechanism underneath the writing.
Bitsec is selling more than the idea of an AI auditor. The sharper read is that it wants security research to behave like a subnet competition. Miners build security programs. Screeners filter unsafe or low quality submissions. Validators run sandboxed evaluations. Scores, logs and submitted code become public after the round.
For a Bittensor news reader, that is a stronger story than another generic claim about AI security.
What Bitsec is building
Bitsec is Subnet 60 on Bittensor.
Its public GitHub repository describes the project as an AI powered code vulnerability detection system. The repository says Bitsec is built to find and fix vulnerabilities in subnet codebases and smart contracts, with plans to expand coverage over time.
The documentation is more specific.
Bitsec says it is building a platform where AI security agents find and fix software exploits. The team frames the first commercial path around SaaS products for blockchain development teams, bug bounty submissions and audit challenges.
The product direction is easy to understand.
Modern teams ship code faster than human review teams can inspect it. AI coding tools make that gap larger. If a subnet can produce security tools that find critical bugs faster, with public benchmarks and repeatable evaluation, the value is easy to understand without learning every corner of dTAO first.
Bittensor needs more subnets with product stories that make sense outside crypto. Bitsec is aiming at a problem normal software teams already pay to solve.
The mechanism behind the story
The Bitsec incentive mechanism is built around rounds.
Miners submit their best security programs during a submission phase. Those submissions are private while the round is open. After that, accepted entries move into evaluation.
The screening layer is important.
Bitsec checks that submitted Python code follows the expected format, exposes the expected agent_main entrypoint and avoids unsafe patterns. The documentation lists checks for malicious execution, hardcoded answers, secret theft, resource exhaustion, inference abuse and obfuscation. It also describes similarity checks and hard steering detection, which are meant to reduce copied or benchmark memorized submissions.
Then validators run the entries inside sandboxed environments.
The evaluation uses SCA Bench style codebases against findings from human auditors. Bitsec currently focuses on critical and high severity findings. The docs say each codebase can be run multiple times because model output can vary, and the platform aggregates validator results to reward reliability.
This part feels Bittensor native.
The subnet asks miners to build software that survives a scoring process, not vague “security content.” If the evaluation keeps improving, the product should get better because the competition gets harder.
Why the stack matters now
The new article is about Bitsec’s stack, not a single benchmark.
Security work will not be solved by picking one model and hoping for magic. A useful system needs model routing, tool use, sandboxing, repeatable evaluation, output parsing, prompt discipline, cost control and protection against miners gaming the test.
Bitsec’s docs show pieces of that stack becoming more explicit.
The inference proxy supports OpenAI compatible calls through Chutes or OpenRouter. It supports tool use, multi turn calls and reasoning model replies. Entries run in a sandbox where internet access is restricted, and external inference goes through the proxy. The platform also exposes submission pages, validator breakdowns, downloadable run data and leaderboard visibility.
The May 2026 changelog says execution time increased from 20 minutes to 30 minutes. It also says emissions switch to a round winner automatically after evaluation closes. Miners can export run data as JSON from the agent detail page.
Those are product details, but they matter editorially.
A subnet that wants to secure code has to prove two things at once. The submissions need to find real issues, and the contest itself has to be difficult to cheat. Bitsec appears to be working on both layers.
The strongest part is the evidence trail
Bitsec’s best product decision may be less glamorous than the agents themselves.
The platform lets miners inspect score summaries, validator breakdowns and project-level results. Run data can be exported as JSON. Proxy summaries expose model attempts, retries, token usage, timing and response status.
That does not make every score correct. It gives researchers something to challenge.
Security benchmarks are vulnerable to memorization, benchmark leakage and agents that produce long lists of weak findings. Bitsec’s screeners try to catch unsafe code, hard steering and similar submissions. Validators run accepted agents against codebases with known findings. The contest limits the number of reported vulnerabilities and focuses scoring on confirmed critical and high severity issues.
The design is promising because failure can become visible. A miner can spend heavily on inference and still lose. An agent can produce hundreds of claims and still score poorly. A validator can disagree with peers and leave a record that the team can inspect.
Cost makes the contest harder to fake
In a July update, Bitsec said submissions in the active round were costing miners roughly $100 to $250 in inference per agent. The team reported 138 submissions from at least three distinct groups.
Those are Bitsec-stated figures, not independently audited costs.
They still matter. A contest with real inference expense discourages unlimited low-effort spam. It forces miners to decide whether a new agent is worth running. Public reveal after each round can then turn the winner into a reference point for the next competition.
This loop is bullish if the benchmark keeps changing. It becomes fragile if miners learn the test faster than they learn security.
The freshness problem
The public GitHub repository linked by Bitsec has not shown recent subnet code pushes. The documentation changelog also stops at the May 2026 v3.1 entry.
That does not prove development stopped. Private infrastructure and product work may exist outside the public repository. It does mean readers should demand a newer evidence trail before treating the early mechanism thesis as current execution strength.
The next update should show a recent round, accepted submission counts, winning code, evaluation data or a customer using the output. A security subnet earns trust by showing what its contest catches.
What still needs proof
The bullish read is simple. Bitsec sits in a category that non crypto users already understand.
Code breaks. Audits are expensive. Human review is slow. AI generated code increases the surface area. Security is a painful budget line, not an abstract AI demo.
The caveat is equally simple.
Bitsec still needs more public proof around real world results. Customer usage, bug bounty wins, audit challenge performance, repeated leaderboard improvement and independent validation of security quality would all strengthen the case. Strong docs help. Buyers will decide how far the case travels.
The most useful next markers are:
- More public round data.
- More visible winning submission code.
- More examples of critical or high severity findings.
- More external users submitting real codebases.
- More evidence that the screener and validator system can resist gaming.
If those markers improve, SN60 becomes one of the easier Bittensor subnets to explain.
The Tao Outsider read is direct. Bitsec is interesting because it turns security into a measurable contest and makes parts of the evaluation downloadable. That is a credible Bittensor shape for AI security.
The bullish case now depends on freshness. SN60 needs to show that the contest is still producing agents, evidence and security findings that software teams would pay to catch. The mechanism deserves attention. The next round of proof deserves a higher standard.
Sources
Bitsec post: How We Bake The Cake
Bitsec post: agent submission costs and round participation
Bitsec documentation: Introduction
Bitsec documentation: Incentive mechanism
Bitsec documentation: Platform
Bitsec documentation: Miner guide
Bitsec documentation: Inference proxy
Bitsec documentation: Changelog
GitHub: Bitsec subnet
Bittensor docs: Understanding subnets
TaoSwap API snapshot: Subnets endpoint
TaoSwap flow data: Rolling trade stats
Tao Outsider archived TaoSwap check: July 4, 2026, 02:12 UTC.
Was this article useful?
One tap feedback helps us improve each post.