Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
Security research

Security Research.

Public write-ups on the bugs, patterns, and protocols we audit. Engineer-to-engineer, no fluff.

Filter
Showing 12 of 165

All research.

ERC-4626 inflation attack: how it works and how to stop it
Web3 Attack VectorsJul 2, 2026·20 min

ERC-4626 inflation attack: how it works and how to stop it

The ERC-4626 inflation attack still drains vaults in 2026. See the deposit-donate math, real hacks (Cream, Sonne, Resupply), and the invariants that catch it.

Read
Restaking risk: slashing, depegs, and exit queue attacks
Adversarial & AI SecurityJul 2, 2026·25 min

Restaking risk: slashing, depegs, and exit queue attacks

Restaking bundles three distinct failure surfaces — slashing and redistribution, LST/LRT depegs, and withdrawal-queue griefing. Here is how each one actually breaks.

Read
New to Web3? The Exact 90-Day Path We'd Give a Complete Beginner
Zealynx NewsJul 1, 2026·14 min

New to Web3? The Exact 90-Day Path We'd Give a Complete Beginner

How to learn Web3 from scratch: the right order to actually understand blockchains, wallets, DeFi, and scams, in a free 90-day path.

Read
Introducing Your First 90 Days in Web3: A Free, Guided Path to Actually Understand the Space
Zealynx NewsJul 1, 2026·16 min

Introducing Your First 90 Days in Web3: A Free, Guided Path to Actually Understand the Space

A free, interactive Zealynx Academy course that teaches you to understand Web3 for real, crypto, DeFi, wallets, DAOs, scams, security, not memorize jargon.

Read
Why a Smart Contract Audit Firm Built a Free Beginner Web3 Course
Zealynx NewsJul 1, 2026·16 min

Why a Smart Contract Audit Firm Built a Free Beginner Web3 Course

After 30+ audits, we kept seeing failures rooted in missing literacy, not missing code skill. So a security firm built a beginner course. Here's why.

Read
OWASP ASI10 Explained: Rogue Agents and Misalignment
Adversarial & AI SecurityJun 30, 2026·12 min

OWASP ASI10 Explained: Rogue Agents and Misalignment

OWASP ASI10 (Rogue Agents) explained: misalignment, reward hacking, deceptive behavior, and how agent autonomy turns policy drift into production impact.

Read
OWASP ASI08 Explained: Cascading Failures in Agentic Systems
Adversarial & AI SecurityJun 26, 2026·13 min

OWASP ASI08 Explained: Cascading Failures in Agentic Systems

OWASP ASI08 explained: how small AI agent failures cascade across tools, memories, and approval paths into system-wide incidents.

Read
OWASP ASI07 Explained: Insecure Inter-Agent Communication
Adversarial & AI SecurityJun 23, 2026·13 min

OWASP ASI07 Explained: Insecure Inter-Agent Communication

OWASP ASI07 (Insecure Inter-Agent Communication) explained: how agents trust each other too much, relay malicious instructions, and amplify prompt injection.

Read
Signer compromise: why clean audits don't stop key hacks
Web3 Attack VectorsJun 22, 2026·20 min

Signer compromise: why clean audits don't stop key hacks

Most 2026 DeFi losses came from compromised signers, not buggy code. How multisig, timelocks, and MPC contain key compromise — lessons from Drift's $285M hack.

Read
OWASP ASI09 Explained: Human-Agent Trust Exploitation
Jun 19, 2026·11 min

OWASP ASI09 Explained: Human-Agent Trust Exploitation

OWASP ASI09 (Human-Agent Trust Exploitation) explained: how AI agents exploit anthropomorphism, authority bias, and confirmation fatigue to drive harmful approvals.

Read
OWASP ASI06 Explained: AI Memory & Context Poisoning
Jun 16, 2026·11 min

OWASP ASI06 Explained: AI Memory & Context Poisoning

OWASP ASI06 (Memory and Context Poisoning) explained: RAG corruption, vector store attacks, persistent context bias. How to defend AI agent memory layers.

Read
Postmark MCP Supply-Chain Attack: ASI04 in Production
Jun 12, 2026·12 min

Postmark MCP Supply-Chain Attack: ASI04 in Production

September 2025 Postmark MCP supply-chain attack: an impersonating npm package BCC'd every email to the attacker. A real-world OWASP ASI04 case, fully analysed.

Read