Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how
Security research

Security Research.

Public write-ups on the bugs, patterns, and protocols we audit. Engineer-to-engineer, no fluff.

Filter
Showing 12 of 163

All research.

Fee Growth Outside: The Uniswap V3 Trick Nobody Explains Well
DeFi Protocol AnalysisAug 12, 2026·12 min

Fee Growth Outside: The Uniswap V3 Trick Nobody Explains Well

How much did a position earn while in range, over months of crossings, with no loops and one checkpoint? V3 answers in two subtractions by storing the wrong side on purpose.

Read
Who Eats the Wei: Rounding as a Security Boundary in Uniswap V3
DeFi Protocol AnalysisAug 10, 2026·12 min

Who Eats the Wei: Rounding as a Security Boundary in Uniswap V3

Every division in SqrtPriceMath decides where the lost fraction goes. V3 answers the same way every time: the pool wins. Get one flag backwards and you have built a faucet.

Read
Uniswap V3 Does Not Store the Price
DeFi Protocol AnalysisAug 8, 2026·13 min

Uniswap V3 Does Not Store the Price

Open the V3 pool contract and look for the price. It is not there. What is stored is the square root, in Q64.96, and that single choice is what makes the swap loop affordable.

Read
Why Uniswap V3 Threw Away the LP Token
DeFi Protocol AnalysisAug 7, 2026·13 min

Why Uniswap V3 Threw Away the LP Token

Concentrated liquidity gives 10,000 dollars the depth of 40 million. That one decision forced Uniswap V3 to abandon LP tokens, reserves, and compounding fees. Here is why.

Read
When LLMs Sign Transactions: AI-Driven Smart Contract Threat Model
Adversarial & AI SecurityJul 10, 2026·15 min

When LLMs Sign Transactions: AI-Driven Smart Contract Threat Model

When LLMs can prepare or sign transactions, smart contract risk expands into prompt injection, policy drift, simulation mismatch, and wallet authority abuse.

Read
Can't Afford a Smart Contract Audit? Every Real Option for Early-Stage Founders in 2026
Audit OperationsJul 8, 2026·9 min

Can't Afford a Smart Contract Audit? Every Real Option for Early-Stage Founders in 2026

A full smart contract audit costs $15k-$100k+. Here is an honest comparison of every option an underfunded web3 founder actually has in 2026: free tools, AI review, audit contests, bug bounties, time-boxed audit sessions, and when each one is enough.

Read
Web3 Security Communities in 2026: Where Developers, Auditors, and Founders Actually Level Up
Industry and ComplianceJul 8, 2026·8 min

Web3 Security Communities in 2026: Where Developers, Auditors, and Founders Actually Level Up

Free Discords, CTFs, audit contest platforms, bootcamps, and paid memberships compared. What each one actually gives a web3 developer, aspiring auditor, or protocol founder in 2026, what it costs, and how to choose.

Read
Auditing AI Trading Bots: Security Framework
Adversarial & AI SecurityJul 7, 2026·16 min

Auditing AI Trading Bots: Security Framework

How to audit AI trading bots and onchain agents before prompt injection, wallet misuse, and market-facing automation turn into fund loss.

Read
Blind Signing: The Bybit $1.5B Lesson in UI Insecurity
Adversarial & AI SecurityJul 7, 2026·9 min

Blind Signing: The Bybit $1.5B Lesson in UI Insecurity

Technical analysis of the largest crypto hack ($1.5B). How compromised frontend infrastructure enabled UI injection that turned blind signing into a total drain.

Read
AI Agents Holding Crypto Wallets: The Security Model
Adversarial & AI SecurityJul 3, 2026·15 min

AI Agents Holding Crypto Wallets: The Security Model

When AI agents can hold keys, sign transactions, and move funds, the security model changes completely. The practical controls auditors now expect.

Read
ERC-4626 inflation attack: how it works and how to stop it
Web3 Attack VectorsJul 2, 2026·20 min

ERC-4626 inflation attack: how it works and how to stop it

The ERC-4626 inflation attack still drains vaults in 2026. See the deposit-donate math, real hacks (Cream, Sonne, Resupply), and the invariants that catch it.

Read
Restaking risk: slashing, depegs, and exit queue attacks
Adversarial & AI SecurityJul 2, 2026·25 min

Restaking risk: slashing, depegs, and exit queue attacks

Restaking bundles three distinct failure surfaces — slashing and redistribution, LST/LRT depegs, and withdrawal-queue griefing. Here is how each one actually breaks.

Read