Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how
Security research

Security Research.

Public write-ups on the bugs, patterns, and protocols we audit. Engineer-to-engineer, no fluff.

Filter
Showing 12 of 163

All research.

OWASP ASI01 Explained: AI Agent Goal Hijacking
Adversarial & AI SecurityJun 2, 2026·12 min

OWASP ASI01 Explained: AI Agent Goal Hijacking

OWASP ASI01 (Agent Goal Hijack) explained: how prompt injection redirects AI agent objectives. Direct, indirect, and tool-mediated patterns with mitigations.

Read
Agentic DeFi security: when AI agents control treasury, trading, and liquidations
Adversarial & AI SecurityJun 1, 2026·21 min

Agentic DeFi security: when AI agents control treasury, trading, and liquidations

AI agents now autonomously control DeFi treasuries, execute trades, and trigger liquidations. The cross-layer attack surface that contract audits cannot see.

Read
The Case for Interactive-Only Pedagogy: How Zealynx Academy Teaches Differently
Zealynx NewsJun 1, 2026·14 min

The Case for Interactive-Only Pedagogy: How Zealynx Academy Teaches Differently

Zealynx Academy uses no videos, no slides, no passive content. Every section is interactive. Here's the pedagogical argument for why that works better for Web3 builders — and the specific design patterns behind it.

Read
Token Management: Securing Against Token Waste
Adversarial & AI SecurityMay 30, 2026·6 min

Token Management: Securing Against Token Waste

Understand why it is critical to secure your AI applications from misuse

Read
CVE-2025-49596: Anthropic MCP Inspector RCE Explained
Adversarial & AI SecurityMay 29, 2026·12 min

CVE-2025-49596: Anthropic MCP Inspector RCE Explained

CVE-2025-49596 (CVSS 9.4 Critical): unauthenticated RCE in Anthropic's MCP Inspector. How the proxy architecture failed, the patch (v0.14.1), and lessons for MCP dev tools.

Read
How to Build Compound V2 From Scratch (18 Sections, Line by Line)
DeFi Protocol AnalysisMay 28, 2026·13 min

How to Build Compound V2 From Scratch (18 Sections, Line by Line)

Rebuild Compound V2 from scratch — cTokens, Comptroller, InterestRateModel, and liquidation logic. The second-most-forked DeFi protocol, understood end to end.

Read
Long-Lived Agents: Delayed Execution Risk
Adversarial & AI SecurityMay 27, 2026·14 min

Long-Lived Agents: Delayed Execution Risk

Why long-lived AI agents fail across time, not just prompts. Practical audit checks for delayed execution, stale approvals, and memory-driven authority drift.

Read
OWASP ASI05 Explained: AI Agent RCE Patterns
Adversarial & AI SecurityMay 26, 2026·12 min

OWASP ASI05 Explained: AI Agent RCE Patterns

OWASP ASI05 (Unexpected Code Execution) explained: how agent-generated code and tool composition produce RCE in agentic systems. Real CVEs and mitigations.

Read
Why Learning Web3 by Building Beats Watching Videos
Zealynx NewsMay 25, 2026·12 min

Why Learning Web3 by Building Beats Watching Videos

Most Web3 education is video-heavy. Research shows active construction of knowledge produces meaningful skill faster than passive consumption. Here's why build-first platforms matter.

Read
What Happens During a Smart Contract Audit: Week-by-Week Process
Audit OperationsMay 25, 2026·17 min

What Happens During a Smart Contract Audit: Week-by-Week Process

A senior auditor walks through what actually happens during a smart contract audit, week by week. Pre-audit prep, manual review, findings, fix verification, and final deliverables.

Read
Uniswap v4 hook attacks: 4 exploit patterns with PoCs
DeFi Protocol AnalysisMay 25, 2026·25 min

Uniswap v4 hook attacks: 4 exploit patterns with PoCs

The four Uniswap v4 hook attack patterns that cover every public exploit: reentrancy, flag bypass, donation griefing, accounting drift — with minimal PoCs.

Read
Cursor IDE MCP CVEs: MCPoison & CurXecute Explained
Adversarial & AI SecurityMay 22, 2026·11 min

Cursor IDE MCP CVEs: MCPoison & CurXecute Explained

CVE-2025-54136 (MCPoison) and CVE-2025-54135 (CurXecute): tool descriptor injection and workspace-file-write RCE in Cursor IDE's MCP layer. Mechanism, impact, fixes.

Read