Security research

Security Research.

Public write-ups on the bugs, patterns, and protocols we audit. Engineer-to-engineer, no fluff.

Filter
Showing 12 of 141

All research.

The Weakest Link in DeFi Isn't the Smart Contract — It's the Web App
Adversarial & AI SecurityFeb 28, 2026·15 min

The Weakest Link in DeFi Isn't the Smart Contract — It's the Web App

DNS hijacks, supply chain attacks, and UI social engineering bypass smart contract security entirely. Learn how attackers exploit web apps to drain DeFi protocols and how to stop them.

Read
Smart Contract Audit Readiness for MiCA: What Your Codebase Needs Before You Apply
Industry and ComplianceFeb 27, 2026·10 min

Smart Contract Audit Readiness for MiCA: What Your Codebase Needs Before You Apply

MiCA enforcement is live and NCAs are issuing licenses now. If your codebase isn't audit-ready, your CASP application isn't ready either. Here's exactly what you need to fix before you request a quote.

Read
What Smart Contract Audits Actually Cost (2026 Data)
Audit OperationsFeb 26, 2026·5 min

What Smart Contract Audits Actually Cost (2026 Data)

Real pricing from an auditor who sets the quotes. Auditor-day math, what moves your price up or down, and what you actually pay for in a security review.

Read
ERC-3643 vs ERC-1400 for RWA Compliance
DeFi Protocol AnalysisFeb 22, 2026·9 min

ERC-3643 vs ERC-1400 for RWA Compliance

Compare ERC-3643 and ERC-1400 for RWA compliance. See identity checks, partition tradeoffs, ACT risk, forced transfers, and when each token standard fits.

Read
MiCA Forces DeFi to Choose: Comply in 6 Months or Exit the EU Market
Industry and ComplianceFeb 21, 2026·12 min

MiCA Forces DeFi to Choose: Comply in 6 Months or Exit the EU Market

A practical compliance roadmap for DeFi protocols navigating Europe's new regulatory landscape. Learn how MiCA affects decentralized protocols and implement a 6-month compliance strategy.

Read
From EVM to SVM: A senior security researcher's guide to Solana in 2026
Smart Contract SecurityFeb 20, 2026·11 min

From EVM to SVM: A senior security researcher's guide to Solana in 2026

A technical guide for senior EVM security researchers transitioning to Solana's SVM. Covers Rust, Borsh, PDAs, Anchor, and the 2026 Solana security landscape.

Read
How to Start Your First Uniswap V4 Hook: Essentials, Libraries, and Risks
DeFi Protocol AnalysisFeb 19, 2026·13 min

How to Start Your First Uniswap V4 Hook: Essentials, Libraries, and Risks

Step-by-step guide to building your first Uniswap V4 hook. Learn the essential libraries, contract structure, hook permissions, and critical security considerations for DeFi developers.

Read
Uniswap V2 Code Deep Dive: Router, Factory, Pair & Security Risks
DeFi Protocol AnalysisFeb 18, 2026·11 min

Uniswap V2 Code Deep Dive: Router, Factory, Pair & Security Risks

Uniswap V2 code walkthrough: Router, Factory, and Pair contracts dissected. Understand the price oracle, flash swaps, and the reentrancy risks auditors flag — Zealynx.

Read
Beyond Static Checklists: A Defense‑in‑Depth Workflow for Smarter Smart Contract Audits
Audit OperationsFeb 17, 2026·8 min

Beyond Static Checklists: A Defense‑in‑Depth Workflow for Smarter Smart Contract Audits

Transform static security checklists into a defense-in-depth engineering workflow using threat modeling, Slither, and Foundry invariant testing.

Read
When Web2 Infrastructure Breaks DeFi: The Hidden Attack Surface
Adversarial & AI SecurityFeb 16, 2026·13 min

When Web2 Infrastructure Breaks DeFi: The Hidden Attack Surface

DeFi's biggest hacks didn't start in Solidity. DNS hijacking, UI injection, and cloud misconfigurations have drained billions. Learn how Web2 infrastructure failures become on-chain exploits and what your team can do to prevent them.

Read
Why AI Red Teaming Is No Longer Optional in Today's Security Landscape
Adversarial & AI SecurityFeb 15, 2026·9 min

Why AI Red Teaming Is No Longer Optional in Today's Security Landscape

AI systems are now business-critical infrastructure making decisions, triggering actions, and interacting with sensitive data at scale. Traditional security testing approaches are failing to address this expanded attack surface. Learn why AI red teaming has become essential.

Read
GameFi Security Checklist: 55+ Critical P2E Exploit Checks
Smart Contract SecurityFeb 14, 2026·20 min

GameFi Security Checklist: 55+ Critical P2E Exploit Checks

Complete GameFi and Play-to-Earn security checklist with 55+ actionable checks. Learn how to prevent exploits in NFT games, tokenomics, marketplace attacks, and game logic vulnerabilities. Essential guide for GameFi builders, auditors, and gaming protocols.

Read