Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →

Adversarial & AI Security.

AI security, MCP server reviews, and red-team write-ups across smart contracts, dApps, and Web2 infrastructure.

Filter
Showing 12 of 43
Long-Lived Agents: Delayed Execution Risk
Adversarial & AI SecurityMay 27, 2026·14 min

Long-Lived Agents: Delayed Execution Risk

Why long-lived AI agents fail across time, not just prompts. Practical audit checks for delayed execution, stale approvals, and memory-driven authority drift.

Read
OWASP ASI05 Explained: AI Agent RCE Patterns
Adversarial & AI SecurityMay 26, 2026·12 min

OWASP ASI05 Explained: AI Agent RCE Patterns

OWASP ASI05 (Unexpected Code Execution) explained: how agent-generated code and tool composition produce RCE in agentic systems. Real CVEs and mitigations.

Read
Cursor IDE MCP CVEs: MCPoison & CurXecute Explained
Adversarial & AI SecurityMay 22, 2026·11 min

Cursor IDE MCP CVEs: MCPoison & CurXecute Explained

CVE-2025-54136 (MCPoison) and CVE-2025-54135 (CurXecute): tool descriptor injection and workspace-file-write RCE in Cursor IDE's MCP layer. Mechanism, impact, fixes.

Read
The Web2 blind spot: Why audited smart contracts get hacked
Adversarial & AI SecurityMay 22, 2026·27 min

The Web2 blind spot: Why audited smart contracts get hacked

Bybit, BadgerDAO, Curve — all audited, all drained off-chain. How DNS hijacks, CDN compromises, and signing-flow attacks bypass smart contract audits.

Read
AI Agent Outbound Authority: Audit Checks
Adversarial & AI SecurityMay 20, 2026·13 min

AI Agent Outbound Authority: Audit Checks

Why email, messaging, and webhook tools need destination-level controls in AI agents. Practical audit checks for exfiltration and approval bypass.

Read
Indirect prompt injection: the Web3 agent attack chain
Adversarial & AI SecurityMay 15, 2026·26 min

Indirect prompt injection: the Web3 agent attack chain

How indirect prompt injection drains Web3 agent wallets, poisons AI audits, and abuses MCP servers. Bankrbot case study and the auditor's 12-point checklist.

Read
Anthropic MCP SDK Vulnerability (April 2026): Full Analysis
Adversarial & AI SecurityMay 15, 2026·12 min

Anthropic MCP SDK Vulnerability (April 2026): Full Analysis

Inside the April 2026 Anthropic MCP SDK design flaw: STDIO transport allows config-to-command-execution across Python, TypeScript, Java, Rust SDKs — by design.

Read
AI Agent Approval Bypass: Audit Checks
Adversarial & AI SecurityMay 13, 2026·12 min

AI Agent Approval Bypass: Audit Checks

Why human approval fails in AI agents when the model still controls risky parameters. Audit checks for coding agents, long-lived agents, and Agentic DeFi.

Read
OWASP ASI04 Explained: Agentic Supply Chain Attacks
Adversarial & AI SecurityMay 12, 2026·12 min

OWASP ASI04 Explained: Agentic Supply Chain Attacks

OWASP ASI04 (Agentic Supply Chain Vulnerabilities) explained: MCP Impersonation, malicious tools, trojanised connectors. Real CVEs, attack patterns, mitigations.

Read
MCP Vulnerabilities 2025-2026: 16+ CVEs & Breach Index
Adversarial & AI SecurityMay 8, 2026·14 min

MCP Vulnerabilities 2025-2026: 16+ CVEs & Breach Index

Complete MCP vulnerability index: 16 disclosed breaches and 14+ CVEs since April 2025 across Anthropic, Cursor, Postmark — with OWASP ASI04 patterns. Updated weekly.

Read
How to Build Your Own AI Auditor Agent (Interactive Guide, Multiple Paths)
Adversarial & AI SecurityMay 7, 2026·15 min

How to Build Your Own AI Auditor Agent (Interactive Guide, Multiple Paths)

Build an AI auditor agent that actually works. Multiple paths modeled after the best existing tools, benchmarked against 118 real Code4rena findings.

Read
Supply Chain Attacks in Web3 — From NPM to Protocol Exploits
Adversarial & AI SecurityMay 6, 2026·12 min

Supply Chain Attacks in Web3 — From NPM to Protocol Exploits

Complete guide to Web3 supply chain attacks with 5 vectors, real incidents, and actionable checklist.

Read