Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how
Security research

Security Research.

Public write-ups on the bugs, patterns, and protocols we audit. Engineer-to-engineer, no fluff.

Filter
Showing 12 of 158

All research.

When LLMs Sign Transactions: AI-Driven Smart Contract Threat Model
Adversarial & AI SecurityJul 10, 2026·15 min

When LLMs Sign Transactions: AI-Driven Smart Contract Threat Model

When LLMs can prepare or sign transactions, smart contract risk expands into prompt injection, policy drift, simulation mismatch, and wallet authority abuse.

Read
Can't Afford a Smart Contract Audit? Every Real Option for Early-Stage Founders in 2026
Audit OperationsJul 8, 2026·9 min

Can't Afford a Smart Contract Audit? Every Real Option for Early-Stage Founders in 2026

A full smart contract audit costs $15k-$100k+. Here is an honest comparison of every option an underfunded web3 founder actually has in 2026: free tools, AI review, audit contests, bug bounties, time-boxed audit sessions, and when each one is enough.

Read
Web3 Security Communities in 2026: Where Developers, Auditors, and Founders Actually Level Up
Industry and ComplianceJul 8, 2026·8 min

Web3 Security Communities in 2026: Where Developers, Auditors, and Founders Actually Level Up

Free Discords, CTFs, audit contest platforms, bootcamps, and paid memberships compared. What each one actually gives a web3 developer, aspiring auditor, or protocol founder in 2026, what it costs, and how to choose.

Read
Auditing AI Trading Bots: Security Framework
Adversarial & AI SecurityJul 7, 2026·16 min

Auditing AI Trading Bots: Security Framework

How to audit AI trading bots and onchain agents before prompt injection, wallet misuse, and market-facing automation turn into fund loss.

Read
Blind Signing: The Bybit $1.5B Lesson in UI Insecurity
Adversarial & AI SecurityJul 7, 2026·9 min

Blind Signing: The Bybit $1.5B Lesson in UI Insecurity

Technical analysis of the largest crypto hack ($1.5B). How compromised frontend infrastructure enabled UI injection that turned blind signing into a total drain.

Read
AI Agents Holding Crypto Wallets: The Security Model
Adversarial & AI SecurityJul 3, 2026·15 min

AI Agents Holding Crypto Wallets: The Security Model

When AI agents can hold keys, sign transactions, and move funds, the security model changes completely. The practical controls auditors now expect.

Read
ERC-4626 inflation attack: how it works and how to stop it
Web3 Attack VectorsJul 2, 2026·20 min

ERC-4626 inflation attack: how it works and how to stop it

The ERC-4626 inflation attack still drains vaults in 2026. See the deposit-donate math, real hacks (Cream, Sonne, Resupply), and the invariants that catch it.

Read
Restaking risk: slashing, depegs, and exit queue attacks
Adversarial & AI SecurityJul 2, 2026·25 min

Restaking risk: slashing, depegs, and exit queue attacks

Restaking bundles three distinct failure surfaces — slashing and redistribution, LST/LRT depegs, and withdrawal-queue griefing. Here is how each one actually breaks.

Read
New to Web3? The Exact 90-Day Path We'd Give a Complete Beginner
Zealynx NewsJul 1, 2026·14 min

New to Web3? The Exact 90-Day Path We'd Give a Complete Beginner

How to learn Web3 from scratch: the right order to actually understand blockchains, wallets, DeFi, and scams, in a free 90-day path.

Read
Introducing Your First 90 Days in Web3: A Free, Guided Path to Actually Understand the Space
Zealynx NewsJul 1, 2026·16 min

Introducing Your First 90 Days in Web3: A Free, Guided Path to Actually Understand the Space

A free, interactive Zealynx Academy course that teaches you to understand Web3 for real, crypto, DeFi, wallets, DAOs, scams, security, not memorize jargon.

Read
Why a Smart Contract Audit Firm Built a Free Beginner Web3 Course
Zealynx NewsJul 1, 2026·16 min

Why a Smart Contract Audit Firm Built a Free Beginner Web3 Course

After 30+ audits, we kept seeing failures rooted in missing literacy, not missing code skill. So a security firm built a beginner course. Here's why.

Read
OWASP ASI10 Explained: Rogue Agents and Misalignment
Adversarial & AI SecurityJun 30, 2026·12 min

OWASP ASI10 Explained: Rogue Agents and Misalignment

OWASP ASI10 (Rogue Agents) explained: misalignment, reward hacking, deceptive behavior, and how agent autonomy turns policy drift into production impact.

Read