Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how
Security research

Security Research.

Public write-ups on the bugs, patterns, and protocols we audit. Engineer-to-engineer, no fluff.

Filter
Showing 12 of 164

All research.

Cursor IDE MCP CVEs: MCPoison & CurXecute Explained
Adversarial & AI SecurityMay 22, 2026·11 min

Cursor IDE MCP CVEs: MCPoison & CurXecute Explained

CVE-2025-54136 (MCPoison) and CVE-2025-54135 (CurXecute): tool descriptor injection and workspace-file-write RCE in Cursor IDE's MCP layer. Mechanism, impact, fixes.

Read
The Web2 blind spot: Why audited smart contracts get hacked
Adversarial & AI SecurityMay 22, 2026·27 min

The Web2 blind spot: Why audited smart contracts get hacked

Bybit, BadgerDAO, Curve — all audited, all drained off-chain. How DNS hijacks, CDN compromises, and signing-flow attacks bypass smart contract audits.

Read
Zealynx Academy vs Cyfrin Updraft, Alchemy University, and LearnWeb3: Honest Comparison
May 21, 2026·13 min

Zealynx Academy vs Cyfrin Updraft, Alchemy University, and LearnWeb3: Honest Comparison

Honest comparison of Web3 education platforms: Zealynx Academy, Cyfrin Updraft, Alchemy University, LearnWeb3, and CryptoZombies. Pick the right one for your stage and goals.

Read
AI Agent Outbound Authority: Audit Checks
Adversarial & AI SecurityMay 20, 2026·13 min

AI Agent Outbound Authority: Audit Checks

Why email, messaging, and webhook tools need destination-level controls in AI agents. Practical audit checks for exfiltration and approval bypass.

Read
Hyperliquid Security Checklist for Builders: HyperBFT, HyperCore, HyperEVM Risks Before Mainnet
Smart Contract SecurityMay 20, 2026·13 min

Hyperliquid Security Checklist for Builders: HyperBFT, HyperCore, HyperEVM Risks Before Mainnet

A builder focused Hyperliquid security checklist covering HyperBFT assumptions, HyperCore integrations, HyperEVM deployment risks, and pre audit launch gates before mainnet.

Read
Hyperliquid Security Checklist for Builders: HyperBFT, HyperCore, HyperEVM
Smart Contract SecurityMay 20, 2026·13 min

Hyperliquid Security Checklist for Builders: HyperBFT, HyperCore, HyperEVM

A builder focused Hyperliquid security checklist covering HyperBFT, HyperCore, HyperEVM, order flow, liquidation, oracle, bridge, and pre audit risks before launch.

Read
OWASP ASI02 Explained: AI Agent Tool Misuse Attacks
May 19, 2026·12 min

OWASP ASI02 Explained: AI Agent Tool Misuse Attacks

OWASP ASI02 (Tool Misuse and Exploitation) explained: over-privileged tools, descriptor poisoning, cross-tool chaining attacks. Real CVEs and mitigations.

Read
EIP-7702 wallet security: what auditors check after Pectra
Smart Contract SecurityMay 18, 2026·26 min

EIP-7702 wallet security: what auditors check after Pectra

EIP-7702 lets EOAs become smart contracts with one signature. Here are the 4 attack surfaces — phishing, delegate bugs, replay, ERC-4337 — auditors now check.

Read
Gamified Learning in Web3: Why Ranks, Leaderboards, and Lynx Actually Work
Smart Contract SecurityMay 18, 2026·11 min

Gamified Learning in Web3: Why Ranks, Leaderboards, and Lynx Actually Work

Gamification in learning often feels hollow. Here's why Zealynx Academy's rank and leaderboard system is different — and why it produces verifiable reputation, not points for points' sake.

Read
Indirect prompt injection: the Web3 agent attack chain
Adversarial & AI SecurityMay 15, 2026·26 min

Indirect prompt injection: the Web3 agent attack chain

How indirect prompt injection drains Web3 agent wallets, poisons AI audits, and abuses MCP servers. Bankrbot case study and the auditor's 12-point checklist.

Read
Anthropic MCP SDK Vulnerability (April 2026): Full Analysis
Adversarial & AI SecurityMay 15, 2026·12 min

Anthropic MCP SDK Vulnerability (April 2026): Full Analysis

Inside the April 2026 Anthropic MCP SDK design flaw: STDIO transport allows config-to-command-execution across Python, TypeScript, Java, Rust SDKs — by design.

Read
Inside the ETHSecurity Badge: Recognition from TheDAO Fund and What It Means
Zealynx NewsMay 14, 2026·10 min

Inside the ETHSecurity Badge: Recognition from TheDAO Fund and What It Means

TheDAO Security Fund awarded the ETHSecurity Badge to Ethereum security contributors. Holders get 4x matching impact in the Ethereum Security QF round, open through May 14, 2026.

Read