Methodology
Every report is built from primary, externally verifiable evidence: on-chain traces, contract bytecode and storage, protocol post-mortems, and the cryptographic record of the event. Where a claim cannot be reconstructed from observable data, it is not made.
The chain proceeds in four stages. Observation — the incident is reconstructed transaction by transaction, block heights and call traces preserved as the evidentiary spine. Classification — each incident is assigned to the Forensic Capital Vulnerability Class Taxonomy, by failure mechanism, not by headline. An event reported as one class of failure often resolves, on inspection, into another — and the distinction changes who is exposed. Scoring — severity, defensibility, recovery probability, and blast radius, assessed against fixed anchors, so two analysts reach comparable figures. Corroboration — findings cross-checked against independent sources before release.
Frameworks are grounded in external standards: CVSS for severity, MITRE where failure mechanisms map, recognized industry baselines for loss and recovery context.
The defensibility score is central. It measures how completely a finding can be reproduced from public and forensic data alone — no privileged access, no unverifiable testimony. A high-tier report is one a reasonable reviewer could reconstruct independently and reach the same conclusion.
We do not disclose private methods, proprietary tooling, or sources. We disclose the standard every report is held to: evidence that is observable, classification that is consistent, conclusions defensible on their own terms.