Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →

Adversarial & AI Security.

AI security, MCP server reviews, and red-team write-ups across smart contracts, dApps, and Web2 infrastructure.

Filter
Showing 12 of 24
Blind Signing: The Bybit $1.5B Lesson in UI Insecurity
Adversarial & AI SecurityJul 7, 2026·9 min

Blind Signing: The Bybit $1.5B Lesson in UI Insecurity

Technical analysis of the largest crypto hack ($1.5B). How compromised frontend infrastructure enabled UI injection that turned blind signing into a total drain.

Read
AI Agents Holding Crypto Wallets: The Security Model
Adversarial & AI SecurityJul 3, 2026·15 min

AI Agents Holding Crypto Wallets: The Security Model

When AI agents can hold keys, sign transactions, and move funds, the security model changes completely. The practical controls auditors now expect.

Read
OWASP ASI10 Explained: Rogue Agents and Misalignment
Adversarial & AI SecurityJun 30, 2026·12 min

OWASP ASI10 Explained: Rogue Agents and Misalignment

OWASP ASI10 (Rogue Agents) explained: misalignment, reward hacking, deceptive behavior, and how agent autonomy turns policy drift into production impact.

Read
OWASP ASI08 Explained: Cascading Failures in Agentic Systems
Adversarial & AI SecurityJun 26, 2026·13 min

OWASP ASI08 Explained: Cascading Failures in Agentic Systems

OWASP ASI08 explained: how small AI agent failures cascade across tools, memories, and approval paths into system-wide incidents.

Read
OWASP ASI07 Explained: Insecure Inter-Agent Communication
Adversarial & AI SecurityJun 23, 2026·13 min

OWASP ASI07 Explained: Insecure Inter-Agent Communication

OWASP ASI07 (Insecure Inter-Agent Communication) explained: how agents trust each other too much, relay malicious instructions, and amplify prompt injection.

Read
OWASP ASI01 Explained: AI Agent Goal Hijacking
Adversarial & AI SecurityJun 2, 2026·12 min

OWASP ASI01 Explained: AI Agent Goal Hijacking

OWASP ASI01 (Agent Goal Hijack) explained: how prompt injection redirects AI agent objectives. Direct, indirect, and tool-mediated patterns with mitigations.

Read
OWASP ASI05 Explained: AI Agent RCE Patterns
Adversarial & AI SecurityMay 26, 2026·12 min

OWASP ASI05 Explained: AI Agent RCE Patterns

OWASP ASI05 (Unexpected Code Execution) explained: how agent-generated code and tool composition produce RCE in agentic systems. Real CVEs and mitigations.

Read
The Web2 blind spot: Why audited smart contracts get hacked
Adversarial & AI SecurityMay 22, 2026·27 min

The Web2 blind spot: Why audited smart contracts get hacked

Bybit, BadgerDAO, Curve — all audited, all drained off-chain. How DNS hijacks, CDN compromises, and signing-flow attacks bypass smart contract audits.

Read
AI Agent Outbound Authority: Audit Checks
Adversarial & AI SecurityMay 20, 2026·13 min

AI Agent Outbound Authority: Audit Checks

Why email, messaging, and webhook tools need destination-level controls in AI agents. Practical audit checks for exfiltration and approval bypass.

Read
Indirect prompt injection: the Web3 agent attack chain
Adversarial & AI SecurityMay 15, 2026·26 min

Indirect prompt injection: the Web3 agent attack chain

How indirect prompt injection drains Web3 agent wallets, poisons AI audits, and abuses MCP servers. Bankrbot case study and the auditor's 12-point checklist.

Read
AI Agent Approval Bypass: Audit Checks
Adversarial & AI SecurityMay 13, 2026·12 min

AI Agent Approval Bypass: Audit Checks

Why human approval fails in AI agents when the model still controls risky parameters. Audit checks for coding agents, long-lived agents, and Agentic DeFi.

Read
Supply Chain Attacks in Web3 — From NPM to Protocol Exploits
Adversarial & AI SecurityMay 6, 2026·12 min

Supply Chain Attacks in Web3 — From NPM to Protocol Exploits

Complete guide to Web3 supply chain attacks with 5 vectors, real incidents, and actionable checklist.

Read