On-chain. Reconstructed block by block.
You cannot write the report
on code you audited.
Audit firms have mandates. A mandate is a client to protect.
No mandate here. No prior engagement. Only the chain.
The chain doesn't lie.
Post-incident forensic reconstruction. Every finding independently verifiable.
Degenerate BLS operands accepted by on-chain verifier. Identity and null elements caused pairing equality to hold for any message. $9.05M.
LayerZero DVN requiredDVNCount=1 exploited. A single operator approved a fraudulent cross-chain message.
AWS KMS key held by a GitHub contractor. $23.8M drained in ~80 minutes — 17 in the initial mint.
Forty-six incidents. One taxonomy. Every new exploit has a precedent.
Every transaction. Every call stack. Every state change. Root cause identified from on-chain evidence — not inferred from post-mortem summaries.
Every finding carries a reproducible on-chain proof, an Ed25519 signature, and a Merkle anchor. Any analyst can verify independently. Zero speculation published.
Executive summary, financial exposure model, attack chain timeline, open questions declared explicitly. Delivered through a secure access portal. Defensible before claims committees.
One brief per incident — forensic reconstruction, root cause analysis, and attack chain documentation
drawn from a corpus of 46 documented DeFi incidents. Cryptographically signed. Verifiable.
No paywall.
No pitch deck. No discovery call. No forms.
One email.