Latest Hacking a16z: Breaking Jolt and Dory Cayden How our agent found a full proof forgery in Jolt, a16z's zkVM.
A Technical Breakdown of Jolt's Cryptography (and the exploit) The mathematics of the missing Dory commitments behind the Jolt exploit. Cayden #zkvm#cryptography How Veria AI Found an Arbitrary Proof Forgery in Aleo How a weak Fiat-Shamir transcript allowed arbitrary transaction forgery on Aleo, and earned us a $65,000 bounty. Cayden #zkvm#cryptography#bug-bounty Pwning Pydantic's Monty: A $5K Sandbox Escape Pydantic offered $5,000 to escape Monty, their Rust-built Python sandbox for AI agents. We chained two GC bugs into a use-after-free and walked away with the bounty. Owen Kwan #bug-bounty Securing Open Source Part 2: Cracking Kraken Malicious dApps can impersonate trusted apps and disguise Solana transactions as harmless message signatures, allowing potential fund theft when chained together. Cayden #open-source Securing Open Source Part 1: Goose 1-Click RCE We found a 1-click RCE in Block's Goose AI agent: any website could silently execute commands on your machine. Jayden #open-source#rce Announcing our $3.2M Seed Round We spun out of the #1 hacking team in the US and raised a $3.2M seed to make getting hacked a thing of the past. Stephen Breaking FRI in Eigen's zkVM How missing index checks in FRI allow full proof forgery in Eigen's zkVM. Cayden #zkvm#cryptography From MCP to Shell How MCP authentication flaws enable RCE in Claude Code, Gemini CLI, and more. Raymond #rce#bug-bounty