Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how
Security research

Security Research.

Public write-ups on the bugs, patterns, and protocols we audit. Engineer-to-engineer, no fluff.

Filter
Showing 12 of 163

All research.

New to Web3? The Exact 90-Day Path We'd Give a Complete Beginner
Zealynx NewsJul 1, 2026·14 min

New to Web3? The Exact 90-Day Path We'd Give a Complete Beginner

How to learn Web3 from scratch: the right order to actually understand blockchains, wallets, DeFi, and scams, in a free 90-day path.

Read
Introducing Your First 90 Days in Web3: A Free, Guided Path to Actually Understand the Space
Zealynx NewsJul 1, 2026·16 min

Introducing Your First 90 Days in Web3: A Free, Guided Path to Actually Understand the Space

A free, interactive Zealynx Academy course that teaches you to understand Web3 for real, crypto, DeFi, wallets, DAOs, scams, security, not memorize jargon.

Read
Why a Smart Contract Audit Firm Built a Free Beginner Web3 Course
Zealynx NewsJul 1, 2026·16 min

Why a Smart Contract Audit Firm Built a Free Beginner Web3 Course

After 30+ audits, we kept seeing failures rooted in missing literacy, not missing code skill. So a security firm built a beginner course. Here's why.

Read
OWASP ASI10 Explained: Rogue Agents and Misalignment
Adversarial & AI SecurityJun 30, 2026·12 min

OWASP ASI10 Explained: Rogue Agents and Misalignment

OWASP ASI10 (Rogue Agents) explained: misalignment, reward hacking, deceptive behavior, and how agent autonomy turns policy drift into production impact.

Read
OWASP ASI08 Explained: Cascading Failures in Agentic Systems
Adversarial & AI SecurityJun 26, 2026·13 min

OWASP ASI08 Explained: Cascading Failures in Agentic Systems

OWASP ASI08 explained: how small AI agent failures cascade across tools, memories, and approval paths into system-wide incidents.

Read
OWASP ASI07 Explained: Insecure Inter-Agent Communication
Adversarial & AI SecurityJun 23, 2026·13 min

OWASP ASI07 Explained: Insecure Inter-Agent Communication

OWASP ASI07 (Insecure Inter-Agent Communication) explained: how agents trust each other too much, relay malicious instructions, and amplify prompt injection.

Read
Signer compromise: why clean audits don't stop key hacks
Web3 Attack VectorsJun 22, 2026·20 min

Signer compromise: why clean audits don't stop key hacks

Most 2026 DeFi losses came from compromised signers, not buggy code. How multisig, timelocks, and MPC contain key compromise — lessons from Drift's $285M hack.

Read
OWASP ASI09 Explained: Human-Agent Trust Exploitation
Jun 19, 2026·11 min

OWASP ASI09 Explained: Human-Agent Trust Exploitation

OWASP ASI09 (Human-Agent Trust Exploitation) explained: how AI agents exploit anthropomorphism, authority bias, and confirmation fatigue to drive harmful approvals.

Read
OWASP ASI06 Explained: AI Memory & Context Poisoning
Jun 16, 2026·11 min

OWASP ASI06 Explained: AI Memory & Context Poisoning

OWASP ASI06 (Memory and Context Poisoning) explained: RAG corruption, vector store attacks, persistent context bias. How to defend AI agent memory layers.

Read
Postmark MCP Supply-Chain Attack: ASI04 in Production
Jun 12, 2026·12 min

Postmark MCP Supply-Chain Attack: ASI04 in Production

September 2025 Postmark MCP supply-chain attack: an impersonating npm package BCC'd every email to the attacker. A real-world OWASP ASI04 case, fully analysed.

Read
OWASP ASI03 Explained: AI Agent Identity & Privilege
Jun 9, 2026·10 min

OWASP ASI03 Explained: AI Agent Identity & Privilege

OWASP ASI03 (Identity and Privilege Abuse) explained: how AI agents inherit, share, and escalate authority. Real CVEs, multi-tenant bypasses, and mitigations.

Read
EscapeRoute Explained: Anthropic Filesystem MCP CVEs
Jun 5, 2026·13 min

EscapeRoute Explained: Anthropic Filesystem MCP CVEs

CVE-2025-53109 & CVE-2025-53110 (EscapeRoute): symlink and path-prefix bypass in Anthropic's Filesystem MCP. Mechanism, impact, sandbox lessons.

Read