Security research

Security Research.

Public write-ups on the bugs, patterns, and protocols we audit. Engineer-to-engineer, no fluff.

Filter
Showing 12 of 141

All research.

Safeguard: Analysis of Customer Agent Orchestration System
Adversarial & AI SecurityApr 12, 2026·26 min

Safeguard: Analysis of Customer Agent Orchestration System

Understand the Architecture and Security Layers of a Customer Agent Orchestration System

Read
Layer 2 security under the hood: proof systems, upgrade keys, and what actually protects your funds
Smart Contract SecurityApr 9, 2026·17 min

Layer 2 security under the hood: proof systems, upgrade keys, and what actually protects your funds

Compare Arbitrum, Optimism, and Polygon zkEVM security models. Fraud proofs, ZK validity proofs, upgrade multisigs, and sequencer risks — a data-driven L2 guide.

Read
Why AI security needs pentesting, red teaming, and audits together
Adversarial & AI SecurityApr 7, 2026·20 min

Why AI security needs pentesting, red teaming, and audits together

Pentesting finds bugs, red teaming tests defenses, audits prove compliance. Learn why AI security demands all three integrated into one TEVV lifecycle.

Read
How to Harden an MCP Server Before It Becomes a Master Key to Your Infrastructure
Adversarial & AI SecurityApr 1, 2026·21 min

How to Harden an MCP Server Before It Becomes a Master Key to Your Infrastructure

Secure your MCP servers against prompt injection, credential theft, and supply chain attacks. A practical hardening guide for identity, transport, and runtime.

Read
AI trading bot security: 5 critical attack vectors in DeFi
Adversarial & AI SecurityMar 30, 2026·21 min

AI trading bot security: 5 critical attack vectors in DeFi

Five systemic vectors targeting AI trading bots — adversarial ML, data poisoning, prompt injection, API exploits, supply chain compromise — with strategic mitigation.

Read
When AI controls DeFi vaults, prompt injection becomes remote code execution
Adversarial & AI SecurityMar 25, 2026·16 min

When AI controls DeFi vaults, prompt injection becomes remote code execution

How prompt injection drains AI-controlled DeFi vaults. Freysa and AiXBT exploits analyzed, EVMbench data, and defense architecture for autonomous agents.

Read
DAO governance attacks: how flash loans and vote manipulation drain treasuries
Web3 Attack VectorsMar 23, 2026·21 min

DAO governance attacks: how flash loans and vote manipulation drain treasuries

How attackers exploit DAO governance with flash loans, EVM opcode injection, and quorum exhaustion — plus audit strategies and defense architectures.

Read
EthCC 2026 Cannes: Security Guide for Web3 Builders
Industry and ComplianceMar 19, 2026·9 min

EthCC 2026 Cannes: Security Guide for Web3 Builders

Your complete guide to EthCC 2026 in Cannes. Key dates, side events, networking tips, and how Web3 builders can make the most of the conference.

Read
Oracle manipulation in DeFi: how price feeds become attack vectors
Web3 Attack VectorsMar 18, 2026·11 min

Oracle manipulation in DeFi: how price feeds become attack vectors

How attackers exploit oracle price feeds in DeFi using flash loans, AMM imbalances, and governance subversion — with defense patterns for protocol architects.

Read
How to protect your DeFi protocol from MEV: A full-stack defense guide
Web3 Attack VectorsMar 16, 2026·12 min

How to protect your DeFi protocol from MEV: A full-stack defense guide

Learn how to defend your DeFi protocol from sandwich attacks and MEV extraction with PBS, encrypted mempools, intent architectures, and Uniswap v4 hooks.

Read
ERC-4337 Smart Accounts: Six Failure Modes We're Already Seeing in Audits
Smart Contract SecurityMar 12, 2026·14 min

ERC-4337 Smart Accounts: Six Failure Modes We're Already Seeing in Audits

ERC-4337 account abstraction introduces programmable trust boundaries that break assumptions baked into decades of wallet security thinking. Here's where teams get it wrong.

Read
EthCC[9] in Cannes: Which Security Tracks Actually Matter for Protocol Teams
Industry and ComplianceMar 11, 2026·14 min

EthCC[9] in Cannes: Which Security Tracks Actually Matter for Protocol Teams

A developer-focused guide to EthCC[9] in Cannes — which security tracks, ZK sessions, and side events matter most for protocol teams shipping on EVM and Solana.

Read