Research
The vulnerability classes that actually cost money.
Long-form write-ups of the finding classes we see repeatedly, with vulnerable and fixed code, the economics of each attack, and the tests that catch them. Written for engineers who will have to fix this, not for a newsletter.
Nothing on that topic yet.
Why we publish
Reading is how you evaluate an auditor.
You cannot judge a security firm from a logo wall. You can judge one from whether their public writing shows they understand the mechanism — which is why everything here goes to the level of the actual code.
Scan your own code
The free pre-check looks for many of the patterns described in these articles. Runs locally; nothing is uploaded.
A full sample report
How these classes look when written up properly: severity, impact, likelihood, PoC and verified remediation.
The full methodology
Six stages, the severity matrix, the toolchain, and exactly what we need from you before day one.
From reading to reviewing
Want this attention on your codebase?
Same reasoning, applied to your contracts, by the people who wrote these articles.