Blog

Why the AI audit pitch works on founders

Why the AI audit pitch works on founders

Not every "AI audit" means the same thing. Fully-automated, semi-automated, and hybrid solutions get sold under the same label, but the gap between them is the difference between a real audit and a report your engineers still have to untangle. Here's how to tell them apart, and when each one is actually the right call.

Sebastian BanescuSebastian Banescu
Read Article
How Any User Could Trade Inside Anyone Else's Perpetuals Account

How Any User Could Trade Inside Anyone Else's Perpetuals Account

We found a bug that let any authenticated user trade inside someone else's perpetuals account, placing and filling orders at prices they chose, with the counterparty's real money on the line and no signature from the victim. The root cause: a new P2P trading path that never checked whether the caller actually controlled the account it was acting on. We walk through how the exploit worked, the economics of extracting up to 40% of notional per round trip, and the one-line fix.

Andrei GligaAndrei Gliga
Read
11 things we wish every team did before their audit

11 things we wish every team did before their audit

Nobody explains the process until you're already inside it. 11 patterns we wish every team handled before their audit.

Adevar LabsAdevar Labs
Read
A Deep Dive into Fogo Sessions

A Deep Dive into Fogo Sessions

Fogo Sessions are a core feature of Fogo, designed to reduce signing friction without weakening security. Instead of requiring a wallet signature for every interaction, users sign a single, structured intent that grants temporary, tightly scoped authority to a Session Account.

Salah IsmailSalah Ismail
Read
When Fixes Break Invariants: Double Rounding in Stake Pool Withdrawals

When Fixes Break Invariants: Double Rounding in Stake Pool Withdrawals

A subtle change in a Solana stake pool withdrawal path introduced a double-rounding issue. It's not immediately exploitable, but it creates slow supply drift over time. This post walks through the flow, shows where the invariant breaks, and how to fix it.

Arsen ButenkoArsen Butenko
Read
They Shook Your Hand First

They Shook Your Hand First

How state-sponsored attackers bypass everything your audit checks. Drift lost $285 million. Bybit lost $1.5 billion. Same group. What most teams haven't worked out is what to actually change.

Juan JaramilloJuan Jaramillo
Read
The DeFi Pre-Launch Security Checklist (2026 Edition)

The DeFi Pre-Launch Security Checklist (2026 Edition)

In the first two months of 2026, attackers drained more than $112.5 million across 31 DeFi protocol hacks. This checklist breaks down the security controls DeFi teams should implement before launch, based on the failure modes that keep showing up across real incidents.

Juan JaramilloJuan Jaramillo
Read
Top 6 Solana Smart Contract Audit Firms in 2026

Top 6 Solana Smart Contract Audit Firms in 2026

Solana's account model, CPI boundaries, and BPF runtime create attack surfaces that EVM-focused auditors miss. This guide covers six firms with great Solana expertise, what each does well, and where they fit.

Juan JaramilloJuan Jaramillo
Read
Proving an Aptos Vault Correct with the Move Prover

Proving an Aptos Vault Correct with the Move Prover

Testing finds bugs. It does not prove their absence. The Move Prover gives you this guarantee on Aptos. In this guide, we go from installation to writing formal specifications that verify the core safety properties of a vault.

Adevar Labs
Read
Switchboard Integration: Hidden Risks of Statistics

Switchboard Integration: Hidden Risks of Statistics

In DeFi, where smart contracts manage real assets, accurate and timely price data is critical. In a recent audit, while evaluating switchboard integrations, we observed several cases where statistical parameters were misapplied, reducing feed reliability and introducing subtle but significant vulnerabilities.

Salah IsmailSalah Ismail
Read
Sui Move for EVM and SVM Developers: Part 1 - Mental Models

Sui Move for EVM and SVM Developers: Part 1 - Mental Models

Switching ecosystems isn't about learning new syntax, it's about unlearning assumptions. In this post, we compare how EVM, Solana, and Sui handle core contract operations so you can build in Move with the right design instincts from the start.

Adevar Labs
Read
On-Chain Randomness on Solana: Predictability, Manipulation & Safer Alternatives (Part 1)

On-Chain Randomness on Solana: Predictability, Manipulation & Safer Alternatives (Part 1)

Generating randomness securely on-chain, especially on a fast, deterministic chain like Solana, is far from straightforward. In Part 1, we focus on native sysvars and third-party RNG protocols currently live on mainnet.

Salah IsmailSalah Ismail
Read
An Elegant Alternative to Floating Point Operations on Solana

An Elegant Alternative to Floating Point Operations on Solana

When building DeFi protocols on Solana, developers often face a challenging dilemma: how to implement sophisticated financial calculations without using floating-point operations. We explore various approaches to handle it, each with its own trade-offs.

Catalin NeaguCatalin Neagu
Read
Supply Chain Attacks in The Solana Ecosystem

Supply Chain Attacks in The Solana Ecosystem

In Solana, smart contracts can be immutable. But the off-chain tooling and SDKs that interact with them aren't. That's exactly where a supply chain exploit can hit you hardest: in tools you blindly trust.

Catalin NeaguCatalin Neagu
Read
Unpacking MEV on Solana: Challenges, Threats, and Developer Defenses

Unpacking MEV on Solana: Challenges, Threats, and Developer Defenses

Solana doesn't operate like Ethereum, and that reshapes the entire game of MEV. We break down how front-running and back-running work on Solana, the technical constraints that make it harder to pull off, and what strategies are evolving.

Salah IsmailSalah Ismail
Read
Anchor, Deserialization and Memory Copy

Anchor, Deserialization and Memory Copy

When using Anchor's #[derive(Accounts)] macro, a lot goes on under the hood. In this post, we explore a surprising bug caused by how Anchor handles deserialization and memory copying when multiple variables refer to the same account.

Salah IsmailSalah Ismail
Read
Ship Safely Podcast

The Ship Safely Podcast

Security Stories from Web3 Founders

We sit down with founders, CTOs, and builders from the most prominent projects in Web3 to talk about security culture, hard-learned lessons, and what it takes to ship safely at scale.

Watch on YouTube