Security Capabilities

Contract Auditor
DFS-based multi-agent Solidity audit with adversarial validation
Solidity
Client Auditor
7-stage orchestrated audit for blockchain node codebases (Go, Rust, C/C++)
Go / Rust / C++
Exploit Investigator
Multi-agent pipeline for on-chain attack analysis with Analyst-Validator debate loop
7 Chains

Exploit Analysis Reports

Hyperbridge ISMP Forged Proof DOT Mint

On April 13, 2026 at 03:55:23 UTC, a helper contract deployed by the attacker used Hyperbridge's Ethereum-side ISMP message path to deliver a forged governance-style `PostRequest` into `TokenGateway`. The exploit is best classified as an access-control failure at the …

2026-04-13 ·  Ethereum · 108.2 ETH (~237K USD) · Forged Proof Access Control · Artifacts

SubQuery Settings Access Control Staking Drain

On April 12, 2026, SubQuery Network, a staking protocol on Base, (block 44,590,469) suffered an access-control exploit that drained approximately **218.29M SQT** (about **$131.2K**) from the protocol's Staking contract. The attacker deployed two ephemeral contracts, abused the …

2026-04-12 ·  Base · 218.3M SQT (~131K USD) · Access Control · Artifacts

Denaria Finance Virtual AMM Manipulation

On April 5, 2026, Denaria Finance, a perpetual DEX on Linea, (block 30,067,821) suffered a virtual AMM manipulation attack that drained approximately **165,618 USDC** from the protocol's Vault. The attacker flash-loaned 60,000 USDC from Aave V3, deployed pairs of ephemeral LP and …

2026-04-05 ·  Linea · 165,618 USDC · AMM State Manipulation · Artifacts

InfinitySix TWAP Stale Price

Two compounding flaws in InfinitySix's (`$i6`) BSC staking contract were chained to extract **273,802 USDT** in block 89,703,286. The contract credits referral bonuses to a sponsor's withdrawable balance immediately upon the referral's `invest()` call; separately, its TWAP oracle …

2026-03-31 ·  BSC · 273,802 USDT · Stale TWAP Price · Artifacts

LML APower Reward-Claim Price Manipulation

On March 31, 2026 at 20:39:02 UTC, the attacker used flash-loaned capital on BNB Chain to manipulate the LML/USDT market, then batch-triggered reward claims for pre-seeded accounts through APower and immediately sold the resulting LML back into the distorted pool. The primary …

2026-03-31 ·  BSC · ~310K USDT · Price Manipulation · Artifacts

WhaleBit CES/IGT Staking Oracle Manipulation

On March 31, 2026 at 22:56:21 UTC (Polygon block `84938872`), an attacker exploited WhaleBit's unverified staking system through a **same-transaction spot-oracle manipulation** funded by a flash loan. The attacker EOA `0xe66b37de57b65691b9f4ac48de2c2b7be53c5c6f` used helper …

2026-03-31 ·  Polygon · 10,506 CES · Flash Loan · Artifacts

VTSwapHook Pricing Error

On 2026-03-28, the VTSwapHook contract (`0xbf4b4a83708474528a93c123f817e7f2a0637a88`) deployed on Arbitrum was exploited through a **logic error** in its custom pricing formula. The hook implements a nonlinear (logarithm-based) price curve but approximates execution price using a …

2026-03-28 ·  Arbitrum · ~2M ATH + ~4.5M vATH · Flash Loan · Artifacts

EST BNBDeposit Claim Manipulation

On 2026-03-27, the EST / BNBDeposit system on BNB Smart Chain was exploited through a **flash-loan-assisted reward-accounting flaw** in `BNBDeposit`, amplified by **fee-exempt routing and pair-state manipulation** in EST. The attacker borrowed `250,000 WBNB`, built a temporary …

2026-03-27 ·  BSC · 154.571495162546593567 WBNB · Claim Manipulation · Artifacts

Cyrus Price Manipulation

On March 22, 2026, the CyrusTreasury protocol on BNB Chain was exploited through a price manipulation attack against its `withdrawUSDTFromAny` function, which is called internally by `exit()`. The vulnerable contract (`CyrusTreasury`, `0xb042ea7b35826e6e537a63bb9fc9fb06b50ae10b`) …

2026-03-22 ·  BSC · 28.14 ETH · Flash Loan · Artifacts

Escrow Overflow

An unverified escrow-like contract at `0xf0a105d93eec8781e15222ad754fcf1264568c97` on Ethereum Mainnet was fully drained in block 24,707,679 (timestamp 2026-03-22 UTC) through an **integer overflow** in its deposit function `0x317de4f6`. The deposit function accumulates entry …

2026-03-22 ·  Ethereum · 97,812.92 USDT · Integer Overflow · Artifacts