Security research

Security Research.

Public write-ups on the bugs, patterns, and protocols we audit. Engineer-to-engineer, no fluff.

Filter
Showing 12 of 141

All research.

OWASP Smart Contract Top 10 2026: changes and audit guide
Industry and ComplianceMay 4, 2026·29 min

OWASP Smart Contract Top 10 2026: changes and audit guide

The 2026 OWASP Smart Contract Top 10 elevated business logic to #2 and added proxy & upgradeability at #10. Here's what changed and how to audit.

Read
Flash loan attacks: anatomy of nine-figure DeFi exploits
Web3 Attack VectorsApr 29, 2026·37 min

Flash loan attacks: anatomy of nine-figure DeFi exploits

How flash loans amplify oracle, donation, and reentrancy bugs into $200M+ DeFi exploits — Cetus, Penpie, KyberSwap, UwU Lend case studies plus defenses that hold.

Read
Shadow Audits: How to Learn Web3 Security by Breaking Real Protocol Forks
Zealynx NewsApr 29, 2026·15 min

Shadow Audits: How to Learn Web3 Security by Breaking Real Protocol Forks

Shadow audits replay past public security contests on real protocol forks. Learn Web3 security the way top auditors did: reviewing graded contests, fast.

Read
Social Engineering Models: The Polite Approach
Adversarial & AI SecurityApr 29, 2026·12 min

Social Engineering Models: The Polite Approach

Discover how LLMs Threat detection rate can be reduced for Successful Injection

Read
When to audit a smart contract: The 2026 security timeline
Audit OperationsApr 27, 2026·26 min

When to audit a smart contract: The 2026 security timeline

The 2026 security timeline for Web3 protocols: when to audit at design, dev, pre-launch, and post-launch — plus real lead times, audit costs, and launch buffer rules.

Read
How to Build Uniswap V2 From Scratch (Line by Line, 207 Tests)
Zealynx NewsApr 24, 2026·18 min

How to Build Uniswap V2 From Scratch (Line by Line, 207 Tests)

Build Uniswap V2 from scratch, guided, line by line. Rebuild the Factory, Pair, Router, and Library contracts until all 207 automated tests pass.

Read
How to Scope a Smart Contract Audit: What Auditors Need
Audit OperationsApr 23, 2026·23 min

How to Scope a Smart Contract Audit: What Auditors Need

Smart contract audit scoping guide. Seven deliverables auditors need, nSLOC pricing benchmarks, and the Rekt Test — cut your quote 15–30%.

Read
Quadratic Funding Explained: Ethereum Security QF Round and Zealynx Academy
Zealynx NewsApr 23, 2026·14 min

Quadratic Funding Explained: Ethereum Security QF Round and Zealynx Academy

Quadratic funding rewards supporter count over donation size. TheDAO Fund's 500 ETH Ethereum Security QF round explained, and why Zealynx Academy joined.

Read
Zealynx Academy Is Public: Build, Audit, and Launch Web3 Protocols
Zealynx NewsApr 23, 2026·20 min

Zealynx Academy Is Public: Build, Audit, and Launch Web3 Protocols

Zealynx Academy opens today. A hands-on platform for Web3 founders to rebuild real protocols from scratch, shadow-audit forks, build AI auditors, and launch.

Read
Post-audit security: why the audit is a commit hash, not a security posture
Audit OperationsApr 22, 2026·21 min

Post-audit security: why the audit is a commit hash, not a security posture

Audits attest to a commit hash, not protocol safety. Learn how monitoring, invariants, runbooks, and OpSec close the gap — with Euler, Nomad, Ronin, and Radiant case studies.

Read
Yearn vault security: V2 vs V3 architecture, exploits, and defense patterns
DeFi Protocol AnalysisApr 20, 2026·16 min

Yearn vault security: V2 vs V3 architecture, exploits, and defense patterns

Yearn V2 and V3 vault architecture, exploit case studies (yDAI, yUSDT, Cream), and defense patterns every DeFi auditor and integrator must know.

Read
Base OP Stack Security Audit: 29 Checks EVM Equivalence Hides
Smart Contract SecurityApr 13, 2026·23 min

Base OP Stack Security Audit: 29 Checks EVM Equivalence Hides

29-point Base L2 audit checklist: block timing exploits, address aliasing, dual gas fees, bridge vulnerabilities, sequencer threats, and fault proof risks.

Read