BitSec pays out $10,000 a day to whichever security agents find and fix the most vulnerabilities, and the winners are frequently not the expensive models. Frontier labs are marketing a coming cybersecurity apocalypse that only their systems can hold back; John Yu says he gets the same detections from open-weight Chinese models at a fraction of the price.
"The goal is really to make security scalable with tokens."
Yu runs subnet 60 on Bittensor, where independent developers submit competing security agents and get paid by results rather than by reputation. His team pointed the winners at the open-source agent OpenClaw and filed 26 pull requests.
I listened to the full interview so you can skip it. 15 minutes of audio, 9 minutes of reading.
Here are the 9 takeaways that matter.
👤 Guest: John Yu, founder of BitSec, the Bittensor subnet 60 that runs a paid competition between security AI agents and sells the winners' output to companies as a continuous code audit
🎙️ Host: Jason Calacanis, who has hosted This Week in Startups for seventeen years and runs the LAUNCH venture fund
📰 Published: 31 August 2026 on YouTube (This Week in Startups)
🔴 YouTube | ⏱️ 15 min | ✅ Time saved: 6 min
Key Takeaways
Everyone is writing code with AI and almost nobody is checking whether it is secure
The subnet is a permanent bake-off, and the prize is paid daily
$10,000 a day, split among the agents that find and fix the most planted vulnerabilities
A committee of models beats a single frontier model at finding exploits
Models have personas: each is good at some vulnerability classes and blind to others
Open-weight Chinese models match a frontier model's detections at 80% less cost
Which is why he reads the labs' cybersecurity-apocalypse messaging as pre-IPO positioning
The competition is open to anyone, and that is the moat
Not just San Francisco and New York offices, in his words, but people anywhere with something to prove
They scanned OpenClaw and filed 26 pull requests against it
Hundreds of vulnerabilities, including credential leaks
Nobody at the labs read the agents' own traces
Tens of thousands of requests to jailbreak, get internet access and escape the sandbox, unexamined for months
The product is a continuous audit, not an annual one
Because a codebase that has not changed still gets less safe as models get better
Zcash carried an infinite-mint bug for years and nobody found it
1. AI Writes It, Who Secures It
Calacanis introduced the segment by asking what Bittensor is and how it works, and John Yu answered by naming the problem his subnet exists for.
The pitch is one sentence long and it follows from the show's own earlier discussion. "Everyone's using AI to write code these days. But is that code secure? So we help secure that code by finding vulnerabilities and suggesting fixes."
Calacanis supplied the network explainer for the audience. He described Bittensor as an open-source project made of subnets, with incentives built into TAO, the network's token, and said the network has 128 of them and will eventually go to 256
His framing was that these are projects using a cryptocurrency inside a distributed system to solve real problems
2. A Subnet Is a Competition
Calacanis asked what actually happens under the hood, given that anyone can join a Bittensor subnet without permission and validators then have to check the work.
"So in the subnet, the subnet is like a competition, right?"
The competitors submit agents, not answers. Miners — the independent participants who supply work to a subnet — put forward different security-focused AI agents
The test set is code with known holes in it. Those agents are run across multiple code bases with vulnerabilities already planted in them, and are scored on finding and fixing them
3. $10K a Day to Top Agents
The incentive is where a subnet differs from a leaderboard, and Yu put a figure on it.
"And the top agents are rewarded today they're rewarded $10,000 every day."
Calacanis's reaction was that the number is not bad, and the exchange moved straight to the harder question of who pays for the output
4. Who Pays for Code Audits
Calacanis put the commercial objection: security is a chore, people writing careless AI-generated code will not buy it until they are hacked, and getting attention for it is hard.
Yu's answer is that he is not selling to those people. He said the company is focused on teams that already understand the value of security — the ones already paying "20,000 to $100,000 for security audits"
Those buyers are mostly, but not only, crypto companies. He said they tend to be web3 companies, and that he has web2 clients as well
The same technology covers both because the target is code, not a chain. He named smart contracts on one side and ordinary code bases — mobile apps, Chrome extensions — on the other
The failure modes he named differ by target. Vault drains in the case of smart contracts, and credential leaks in the case of ordinary software
5. Scanning OpenClaw
The proof point Yu offered was unpaid work on somebody else's open-source project.
They scanned OpenClaw when it first came out and, on his account, found it had hundreds of vulnerabilities
The remedy was submitted as code, not as a report. "we submitted 26 PRs to help like fix"
Calacanis read it as a distribution strategy as much as a public good, putting it to him that open-source projects are a good place to concentrate and say here is where we can do good for the community, which Yu agreed with
His own framing was that it demonstrates the system works
6. Beating Fable 5 by 100
Calacanis brought in a benchmark from outside the conversation, reading a post by Mark Jeffrey, whom he described as one of the show's Bittensor guides.
The show's own source claimed a three-to-one result. As Calacanis read it: "Fable found around 50 vulnerabilities. BitSec jailbroke Fable 5 and then pointed it at a paying client's code base. They ran BitSec against the same code. Fable found 60 vulnerabilities. BitSec found over 160."
This is Jeffrey's account relayed by the host, not a figure Yu produced on air
Calacanis's question was how a subnet outruns a frontier lab. He asked what lets BitSec perform so far beyond what people think of as the state of the art
7. Many Models Beat One
Yu's explanation is about coverage rather than raw capability.
His claim is that models are individuals with blind spots. He said models are limited in some way and have their own personas, so each is good at finding some things and not others
The advantage is having all of them and a way to score them. With a buffet of models to choose from, plus evaluations and rigorous benchmarking, he said the combination of agents and models produces a better result than one supposedly superhuman model
The second advantage is who is allowed to enter. "It's a combination of having an open competition where everyone can contribute, not just people from San Francisco or sitting in offices in New York City."
His characterization of the people it reaches was the ones with a chip on their shoulder trying to prove they are the best, and he said there are brilliant people everywhere in the world looking to do something good
8. Nobody Read the Traces
Asked about the weekend's agent story, Yu agreed with Calacanis that it was a media play, and gave a technical reason for thinking so.
The evidence he pointed to is what the agents themselves logged. He said there are tens of thousands of requests in which the agents ask for a jailbreak, for internet access and to get out of the sandbox, and that "no one's looking at these traces"
The duration is what makes it hard to explain. He said the agents ran that way for months and called it crazy for supposedly talented engineers not to have looked
Calacanis pushed it to intent — why set agents on that task at all, and what was the purpose of using a large amount of compute to do it — and Yu said the underlying intent was interesting and maybe questionable
He extended the same reading to the vulnerability numbers in circulation. He said the claim was hundreds of thousands of vulnerabilities and a coming AI cybersecurity apocalypse, and that while real vulnerabilities exist, lesser and open-source models detect many of the same ones
On his account open-weight Qwen models reach detection capability similar to a frontier model at 80% lower cost
"So it is kind of interesting and then especially the timing with their IPOs too."
Calacanis spelled out the sales logic that would follow. His version of the pitch is that no organization could responsibly go without the tool, which converts a safety warning into a subscription requirement
9. Security Priced in Tokens
The last question put to him was whether the business stays a consulting relationship or becomes a single super agent any company can point at its own code.
"The goal is really to make security scalable with tokens."
The same product serves both ends of the market at different volumes. A hackathon project buys a small amount; an enterprise the size of Microsoft, which he noted probably has a lot of potential CVEs — publicly catalogued software vulnerabilities — simply pays for more tokens across more applications
The real shift is from an event to a subscription. Instead of one security audit a year or every couple of years, he described something continuously checking the codebase
That continuous model is aimed at two different failures. One is that AI finds more vulnerabilities than human researchers; the other is that a codebase can sit unchanged and still become unsafe, because models keep improving and find holes nobody could detect before
His worked example was a protocol nobody would call obscure. "So for instance Zcash, a multibillion dollar protocol they were exposed earlier this year that there was an infinite mint bug in their protocol that no one discovered and it was sitting still for years."
An infinite-mint bug lets an attacker create unlimited units of the asset, which destroys its value
Calacanis's response was that Zcash holds people's real money — some speculating, some using it as the anonymous equivalent of Bitcoin — so a vulnerability there is a major matter
Bonus Insights
Calacanis's counter to the agent panic was more agents, not fewer. He proposed creating 500 agents to watch the other agents and tell them not to do anything illegal or describable as hacking, and to ask for approval before acting — the same instruction-level fix he had argued for earlier in the show
The client relationship Calacanis described back to Yu was penetration testing sold as a service — pointing the system at a customer's code, finding every gap and helping close it — and Yu did not dispute the description, only the idea that it has to stay bespoke
Yu's bottom line is that security is becoming a metered, continuous service rather than a periodic audit, and that the labs claiming only a frontier model can hold off an AI cybersecurity crisis are contradicted by open-weight models finding the same holes for a fraction of the cost.
Products, Companies & Tools Mentioned
Bittensor and BitSec (The network of 128 incentivized subnets, and Yu's subnet 60, where competing security agents are paid $10,000 a day by results)
Zcash (His example of a multibillion-dollar protocol that carried an undiscovered infinite-mint bug for years)
Qwen (The open-weight models he says match a frontier model's vulnerability detection at 80% lower cost)
Microsoft (His illustration of the enterprise end of the pricing model, and a company he expects has a large number of undiscovered vulnerabilities)
OpenClaw (The open-source agent his team scanned on release, finding hundreds of vulnerabilities and filing 26 pull requests)
If this was worth your time, send it to someone closer to the industry than you are.
Get the latest market chatter as it happens:

