Blog
Real vulnerabilities found and disclosed by our team, plus the occasional company update.
A Technical Breakdown of Jolt's Cryptography (and the exploit) The mathematics of the missing Dory commitments behind the Jolt exploit. How Veria AI Found an Arbitrary Proof Forgery in Aleo How a weak Fiat-Shamir transcript allowed arbitrary transaction forgery on Aleo, and earned us a $65,000 bounty. Pwning Pydantic's Monty: A $5K Sandbox Escape Pydantic offered $5,000 to escape Monty, their Rust-built Python sandbox for AI agents. We chained two GC bugs into a use-after-free and walked away with the bounty. Securing Open Source Part 2: Cracking Kraken Malicious dApps can impersonate trusted apps and disguise Solana transactions as harmless message signatures, allowing potential fund theft when chained together. Securing Open Source Part 1: Goose 1-Click RCE We found a 1-click RCE in Block's Goose AI agent: any website could silently execute commands on your machine. Announcing our $3.2M Seed Round We spun out of the #1 hacking team in the US and raised a $3.2M seed to make getting hacked a thing of the past. Breaking FRI in Eigen's zkVM How missing index checks in FRI allow full proof forgery in Eigen's zkVM. From MCP to Shell How MCP authentication flaws enable RCE in Claude Code, Gemini CLI, and more.